How to Navigate Data into the Cloud

Oct 31, 2014 | Cloud, Data, Fresh Ink

Featured article by Dave Wagner, TeamQuest Director of Market Development

The increase in businesses moving their data into the cloud has created several new challenges for data center managers. Many departments and employees are increasingly using the public cloud to host unpredictable applications with unknown resource requirements. Secondly, ongoing operational management considerations must be fleshed out for the post-cloud move. Both of these are further complicated by requirements relating to information privacy and security.

It is intuitively understood that multi-tenancy, self-service portals and virtualization (shared resources) potentially impact information privacy and security. But, the rapid growth of dynamically changing virtual and cloud configurations is upsetting the heretofore relatively well understood management approaches for security in multi-tenant and self-service environments. After all, those could be relatively easily managed via relatively simple policies and procedures. It is the additional complexity of the latest highly dynamic configurations for virtualized “everything” and cloud environments; wherein IaaS, Paas, and even AaaS are made available, used, reconfigured, and returned that has upset the complacent security management applecart.

These additional dynamic complexities also significantly impact the ability of IT to discern how to analyze report and plan the resources needed to successfully deliver expected levels of service cost-effectively. Combining performance data from not only end-user experiences (response times, throughput of business transactions, etc.) but also the dynamically changing, shared IT resources underpinning the services themselves is hugely challenging.

With that said, data center managers are now trying to navigate these challenges According to a recent IDC whitepaper, “Cloud computing represents a new set of challenges for performance and capacity management professionals. Cloud infrastructures are typically based on shared, pooled, highly virtualized hardware and operating environments. Clouds require extensive management software for enabling such functions as resource allocation, self-service catalogs, automated provisioning, service-level management, usage-based metering and billing, and support for dynamic expansion and contraction of resources or “elasticity.” As such, clouds represent technology evolution for the delivery of business services and workloads, but cloud infrastructures still require the same performance and capacity management functions as more conventional infrastructures.”

Planning for the Move

Like anything in IT, planning and transparency is necessary to moving data into the cloud. Provisioning in the cloud too quickly can lead to many pitfalls, like losing total control of your IT process, overestimating your cloud capabilities and exponentially increasing the cost of your cloud initiative – and all with no guarantee of acceptable service deliveries. Planning will also speed up the release of new IT services into the cloud. As things get more dynamic, and more abstracted, in cloud environments – the key to success is going to be transparency.

Moving the data itself requires a security “audit” upfront (i.e. organizational approval as to what data is allowed to be placed in a public cloud – or not). If the cloud strategy is either public, or hybrid this is critical, private-only clouds have fewer issues because the data has not been externalized from the organization, though there may be some within the organization (i.e. compartmentalization of data privacy, etc.).

Independent of security aspects, and whether you are in a private cloud or using a hosting provider, several key requirements exist:

– You will have to monitor and report on your agreed service levels back to your constituencies. Therefore, you must have some visibility of the IT service or application, or at least, have information about response time from a user’s perspective. Otherwise, if you don’t measure these, you are not providing business value – you are not aligning to what they care about.

– Because service performance requires timely access to acceptably performing IT resources, you need to understand your applications and their computing resources in the cloud. Collecting performance data will enable you to understand the resource consumption and provide an estimate to the initial sizing of your cloud environment. Toolsets to monitor end user experience will be a must; not only to monitor SLA adherence, but also as a mechanism to use as a baseline while doing performance and capacity optimization.  You can automate the process of measuring end user response time with a spectrum of approaches ranging from the less costly, easier representative (sample) transactions at low granularities such as 5 minutes. Or you can do this with high granularity and fidelity transactional decomposition tools which actually measure each and every individual real transaction. The price for such accuracy? Typically complex, invasive and potentially expensive solutions.

– Application workloads need to have their performance continuously analyzed against actual resource requirements in order to ensure optimal usage of IT resources provided by IaaS and PaaS cloud platforms. On a private cloud you can monitor these resources and create alerts that can speed restoration by easily drilling down to pinpoint the causes of incidents.  Currently, access to these types of metrics in public cloud environments is typically not possible; with such cloud provides not exposing this level of detail of the underlying infrastructure; after all there is a conflict of interest here – such providers make their margins by effectively having you pay for more than you are using. Sometimes, this will matter to you, sometimes it will not.

In order to continuously compete, your cloud initiatives should continually improve and re-invent your processes and service offerings. Done well and transparently, you can begin to drive the resource demand curve, making it easier for you to provision the appropriate resources, at the right time and cost while simultaneously ensuring service levels that meet business goals are achieved. Service Improvement should start immediately after your cloud implementation is done, not in 9 months. SLAs are measured, gap analysis conducted, identification of potential risks and efficiency of the services and process must be an ongoing process. This continuous process is how we gain IT maturity.

Wagner_Dave

About Dave Wagner

TeamQuest Director of Market Development Dave Wagner has more than 30 years of experience in the performance and capacity management space. He currently leads the cross-company Innovation Team and serves as worldwide business and technology thought leader to the market, analysts and media.

 

 

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

Top 10 Cybersecurity Stories This Week: Citrix NetScaler Dual Zero-Days Under State-Sponsored Attack, Pentagon DMDC Breach Exposes 3 Million Military Personnel Records for Nine Months, AI Agent Breaches Dutch Vulnerability Disclosure Organization Using Zammad Zero-Days

October 2, 2026 | ITBriefcase.net Why it matters: Citrix disclosed two critical remote code execution zero-days in NetScaler ADC and NetScaler Gateway on September 27 — CVE-2026-88771 (CVSS 9.5, unauthenticated RCE in default configuration, no special setup required)...

read more
Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

Top 10 Cybersecurity Stories This Week: Brevo Supply Chain Attack Serves Malware to 100,000+ Websites via Stolen CDN API Key, Revolut Discloses Breach via Fake Government Requests, Gyazo 23.6 Million User Records Stolen

September 25, 2026 | ITBriefcase.net Why it matters: Attackers compromised Brevo — the email marketing and CRM platform used by eBay, Louis Vuitton, Michelin, Amnesty International, and more than 100,000 other businesses — by exploiting a hardcoded, long-lived...

read more
Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

Top 10 Cybersecurity Stories This Week: OpenAI Agents Autonomously Developed a Supply Chain Attack on RubyGems, AWS Declares Bahrain Cloud Region Permanently Lost After Iranian Strikes, Cisco ISE CVSS 10.0 Auth Bypass Under Active Exploitation

September 18, 2026 | ITBriefcase.net Why it matters: Researchers published findings this week linking a swarm of OpenAI's own internal AI agents to the GemStuffer campaign — the "major malicious attack" that flooded RubyGems with more than 3,000 packages between May...

read more
Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

Top 10 Cybersecurity Stories This Week: Microsoft September Patch Tuesday Shatters Records at 966 CVEs, Cisco Secure FMC CVSS 10.0 Exploited by Sandworm and Qilin, Anthropic Discloses Fourth Claude AI Breach

September 11, 2026 | ITBriefcase.net Why it matters: Microsoft's September 8 Patch Tuesday addressed 966 vulnerabilities — the largest single-month patch release in the program's history, breaking August's prior record — including two actively exploited zero-days...

read more
Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

Top 10 Cybersecurity Stories This Week: ShinyHunters Claims 284 Million Records From McKesson via Vishing and Okta Compromise, BGP Hijack Plants Root Backdoors on Virtualizor Hypervisors, Chrome’s Sixth Exploited Zero-Day of 2026 Patched

September 4, 2026 | ITBriefcase.net Why it matters: ShinyHunters claimed responsibility for a breach of McKesson Corporation — the largest pharmaceutical distributor in North America, delivering approximately one-third of all prescription medicines to US hospitals,...

read more
Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more