UPDATED 14:28 EDT / DECEMBER 28 2018

INFRA

This attitude adjustment makes security profitable, slays regulation monster

Waiting around for legislatures to throw a two-inch-thick book of data-compliance laws at the company? Sitting by with patching and remediation tools on hand for after a breach occurs? Maybe an attitude adjustment is due. Maybe it’s time to befriend security, blend it into the business, and make it a profit-driving competitive advantage.

“We view security as a driver of business, not just a cost center,” said Seth Morrell (pictured, left), vice president of enterprise architecture and design at Hub International Ltd. “It’s a way that we can add to the bottom line and be able to generate revenue for the business by being able to show our customers that we really care about their data.”

The insurance broker has revamped its security architecture with technologies like Slunk Inc.’s machine-learning data platform in the Amazon Web Services Inc. cloud. It also uses security information management for collecting, monitoring and analyzing logs on security data. 

Morrell and Jeremy Embalabala (pictured, right), director of security architecture and engineering at Hub International, spoke with John Walls (@JohnWalls21), host of theCUBE, SiliconANGLE Media’s mobile livestreaming studio, and guest host Justin Warren (@jpwarren), chief analyst at PivotNine Pty Ltd, during AWS re:Invent in Las Vegas. They discussed Splunk on AWS, SIM, and the payoffs of built-in rather than bolted-on security. (* Disclosure below.)

Extra-mile security prevents compliance headaches

Advanced SIM isn’t easy to manage, according to Embalabala. 

“They’re tricky to implement, they’re generally very costly, and they require a lot of tuning, a lot of love, care and feeding in order for it to be effective,” he said. “Quite frankly, if you don’t get that right, they can actually be detrimental to your  security program.”

But the security upgrade it — and other extra-mile security measures — provides is worth it.

When scary legislations like the General Data Protection Regulation comes to town, those that embrace security and compliance day-in-day-out will be ready, Embalabala and Morrell pointed out.

“We’ll be 95 percent of the way there by just building the right controls into our environment at a foundational level,” Embalabala said. “Then we have to spend our efforts aligning ourselves with the other five percent that vary from regulation to regulation.”

Watch the complete video interview below, and be sure to check out more of SiliconANGLE’s and theCUBE’s coverage of AWS re:Invent.

Photo: SiliconANGLE

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.