Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

What the software defined data centre means for IT security

by The Gurus
February 25, 2015
in Opinions & Analysis
Share on FacebookShare on Twitter

It’s no secret that the data centre industry is evolving rapidly. Large scale, inflexible and expensive physical hosting solutions are no longer common thanks to virtualisation and we’ve all bought into cloud – so today’s forward thinkers are now looking to the Software Defined Data Centre (SDDC) to further transform the way they utilise data resources.
This change presents its own interesting challenges for security and SDDC, users need to be aware of the virtues, challenges and pitfalls of this emerging technology.
Security is about protection and defense, but it is also about assurance – giving your customers (both internal and external) the confidence that their data and systems are safe. To deliver either requires a thorough understanding of the technology – and in the case of the SDDC, the market is currently confused.
Disagreement about its definition is widespread. A recent survey by Adapt has revealed that although three out of five respondents (61%) claimed to be familiar with the SDDC concept, the majority were unable to explain its principal benefits: 13 per cent thought it was all about performance, 20 per cent said centralised management and 17 per cent admitted they were unaware of its benefits.
If professionals are struggling to understand the SDDC, what hope do they have of managing it securely? The SDDC is really about controlling storage, security, networking and compute from within software. Put simply, it’s is a way of making the most economic use of traditional data centre resources.
A software layer controls and manages infrastructure consumption, process and operation down to component level without human intervention. This enables applications to move seamlessly between environments, in and out of the cloud, from low to high performance without having to touch a single piece of hardware. It is this flexibility that will really make the SDDC the data centre of the future.
So, what does this mean for security? Our prediction is a more holistic approach with higher technical automation. As ‘software-defined’ gathers momentum, new methods for managing and enforcing security policies will emerge with it. The security admininistrator will need to define policies which allow the benefits of the SDDC to be realised while ensuring flexibility keeps within the bounds of security requirements. Removing the human element is only beneficial if the rules and policies defined are solid AND the right level of audit and review is in place.
We can expect to see a continued blend of hardware and software-based security, but a decreasing reliance on security hardware as access controls travel up the stack. The move towards this type of security is also about enabling devices and solutions to be driven by software.
As a day-to-day example, instead of making changes to specific firewall rules to enable a new web server to be visible, the process of requesting a new web server will intrinsically cover the application, operating system, virtual server, storage, data protection and security changes in a single business operation.
There’s no doubt the SDDC is the next big thing in IT. It is certainly due to replace “cloud” as the industry’s favourite buzzword. However, it is clear from Adapt’s research that the IT industry is still confused about the concept. We also see that security standards have not really catered for the concept of SDDC and this is not likely to change any time soon, given that ISO 27001 and PCI DSS v3.0 have only recently been revised.
However, security professionals, whilst dealing with the threat landscape that currently exists, really need to get to grips with the concept of the SDDC so they are prepared to manage future business requirements.
Service providers play a key role in supporting the education required, as only when SDDC is fully understood will security professionals be able to leverage its capabilities to support threat mitigation activity, reduce overall risk profile and deliver increased value to the business. Ultimately, the SDDC has the potential to make security more intrinsic and integrated within the IT estate, but there will still be a need for strong governance, control, testing and human accountability.
This feels like familiar ground – and it is certainly not without precedent. The perceived risk and security fears that initially held back cloud adoption, despite its long list of benefits, are equally applicable to the SDDC – it is the role and duty of service providers to erode skepticism with education and demonstrable results to achieve a wider market understanding and acceptance.
 
Kevin Linsell_Headshot_ August 2014_1 jpg
Kevin Linsell is head of service development at Adapt

Tags: Data CentreSoftware
ShareTweet
Previous Post

Time to detect breaches improves, but only a third self-detect

Next Post

Gemalto confirms NSA and GCHQ infiltration, but no major theft of SIM keys

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol