On-premise security doesn’t make sense

1 May 2014 Information Security

IT Security has become a complex challenge for companies of all shapes and sizes. With the range of threats to corporate data coming from the Web, social media, via e-mail, and internally, most companies typically address each channel with multiple best-of-breed solutions to ensure optimal effectiveness.

Richard Broeke, Securicom
Richard Broeke, Securicom

“This prioritisation of product effectiveness over simplicity and ease-of-management comes with a high cost for businesses because buying and managing various point security solutions is expensive business. What makes this approach so expensive are the initial acquisition costs, the cost of IT labour to manage the systems on an ongoing basis, software licensing and maintenance costs, and the cost of any hardware that is needed to run the software,” says Richard Broeke, an IT security expert at Securicom.

Though using separate best-of-breed, on-premise solutions for different security problems remains the dominant approach for deploying IT security, recent research by Osterman Research shows that companies would prefer a single or cloud-based approach.

For example, Osterman Research found that 35% of the organisations it surveyed have on-premises, best-of-breed solutions in place, but only 16% cited this as their preferred security delivery approach. The study also found that while only 14% use a cloud-based and centrally managed security solution with a single interface, 24% actually prefer this model.

Broeke agrees: “There is a noticeable shift towards cloud-based security solutions in South Africa. Over time, we can expect to see more companies moving to cloud-based anti-malware, anti-spam and Web security solutions.

“We are definitely seeing a faster move to cloud-based services for email security and anti-spam than for other cloud-based services such as Web security. Our hosted email security and content filtering solution, ePurifier, grew more than 20% in 2013. Local companies are really starting to see the value in catching and stopping spam and malicious email content before it hits their networks.”

The fact is that IT security is rarely a core function. If the internal management of e-mail, Web and social media security as well as other parts of the IT infrastructure is not a core competency that is central to the success of a business, Broeke says it doesn’t make business sense to keep it in-house.

“Without a doubt, a cloud-based approach has potential to significantly reduce the administration, complexity, and overhead of IT security. The more predictable nature of cloud services costs makes them far more cost-effective than deploying and maintaining countless point solutions. If using internal resources to manage expensive, best-of-breed security solutions doesn’t add to the bottom line, why do it?” he questions.

To determine whether or not to use cloud-based security solutions, he says decision-makers need to understand the true cost of ownership of managing their current, on-premise infrastructure. They also need to understand the risks facing the business from an IT perspective.

“Very often, they come to the conclusion that their security is no better because it is on-premise. I have yet to see a case of a small to mid-sized company where hosting e-mail in-house is worth it from either a cost, security or uptime perspective.

He concludes: “Cloud based security is coming into its own as companies begin to see that outsourcing IT security functions such as e-mail and Web security gives them access to best-of-breed technologies and access to security experts without costly technology acquisitions or employing skilled resources. While there will always be business cases for on-premise or hybrid solutions, cloud-based services are set to become the norm.”

For more information contact Securicom at www.securicom.co.za





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

The dangers of parked domains
Information Security
Kaspersky warns that fraudsters are exploiting so-called ‘parked domains’ to harvest sensitive personal data from unsuspecting users. These deceptive sites often masquerade as error pages or ad-filled placeholders, exposing users to privacy breaches and potential identity theft.

Read more...
Security has an identity problem
Access Control & Identity Management Information Security
Cybersecurity discussions have mainly focused on defence, including stronger firewalls, tighter network controls, and better endpoint security. However, in today's world, those traditional defences have become less relevant.

Read more...
Buying more security tools is not building a defence
Information Security
Sophisticated attacks are specifically engineered to bypass individual security tools, and companies absorbing the damage are those who have confused procurement with protection, says Richard Frost from Armata Cyber Security.

Read more...
Modernising ‘smart’ ports
IoT & Automation Information Security Transport (Industry) Logistics (Industry)
A modern port is part of a much larger digital trade ecosystem where all systems need to work together. If one part of that ecosystem is disrupted, the impact can quickly move through the supply chain.

Read more...
Reinventing cybersecurity
NEC XON News & Events Information Security Commercial (Industry)
NEC XON helps a workforce solutions leader reinvent cybersecurity with an AI-enhanced XDR solution to keep pace with increasingly devious cyberattack techniques, including fileless malware, lateral movement, and credential misuse.

Read more...
Hold the line
BlueVision Information Security Editor's Choice
While most businesses are still focused on guarding the wall, the perimeter today has moved to the login screen, according to Christo Coetzer, founder and managing director of BlueVision Technologies.

Read more...
Attackers are turning AI to their advantage
Information Security AI & Data Analytics
ESET's H1 2026 Threat Report analysed around 900 000 AI skills and found more than 3000 to be outright malicious, exposing a fast-growing attack surface for organisations experimenting with AI.

Read more...
BlueVision launches Fusion Cloud
BlueVision Information Security Products & Solutions
Most businesses have moved to the cloud, including Microsoft 365, Azure, AWS and more, and in doing so assume they're protected because they're using a reputable platform; however, the reality is somewhat different.

Read more...
Tools detect threats: Cyber resilience protects businesses
Information Security
If your cybersecurity strategy is built around buying Managed Detection and Response (MDR), deploying an Endpoint Detection and Response (EDR) agent, and calling it ‘done’, then someone has sold you a story, not a strategy.

Read more...
Compressing cyberattack timelines and targeting ungoverned AI identities
Information Security News & Events
Sophos AI Security 2026 report finds attackers are moving beyond experimentation and operationalising AI for attacks using identity as the primary initial access vector, rather than inventing new attack types.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.