Cloud Adoption & Risk Report   3,000,000+ users Q3 2013

advertisement
Cloud Adoption & Risk Report Q3 2013
Based on data from
3,000,000+ users
Representing the following industries:
Financial Services
Healthcare
High Tech
Media
Manufacturing
Services
Table of Contents
The Cloud Adoption and Risk Report is based on data from more than 3 million users across more than 100 companies spanning
financial services, healthcare, high technology, manufacturing, media, and services industries. The top ten and twenty services lists
are based on users of the service. The risk of each service is based on Skyhigh CloudRiskTM, which assigns a 1-to-10 risk rating
based on detailed, objective, and weighted assessment of more than 30 attributes across data risk, user risk, device risk, service risk,
business risk, and legal risk.
In This Report
Executive Summary
3
Familiar vs. High Risk Services
11
Content Sharing Services
19
Users and Services per Company
4
Total Services by Industry
12
Back-Up & Archiving Services
20
Top 20 Cloud Services
5
High-Risk Services by Industry
13
Social Media Services
21
Highest Volume Services
6
Services by Category
14
CRM Services
22
Most Blocked Services
7
File Sharing Services
15
About Skyhigh Networks
23
Blocking Rate by Service Risk Level
8
Development Services
16
Blocking Rate by Category
9
Collaboration Services
17
Blocking Rate by Industry
10
Tracking Services
18
Cloud Adoption & Risk Report
|
2
Executive Summary
Cloud is the New Wild Wild West
Data from more than 100 organizations suggests broad and rampant use of cloud services. 2,204 cloud services are in use across more than
3 million users. 545 cloud services are in use by an organization on average, and the highest number of cloud services in use by an
organization is 1,769.
It’s Not a Popularity Contest – It’s Risky Business
Corporate security measures are based on concerns related to productivity and bandwidth, or on the familiarity with the service as opposed to
the risk of the service. Low-risk services are blocked 40% more than high-risk services. At 9%, tracking is the least blocked category despite
the fact that tracking services deliver zero business benefit and expose the organization to watering hole attacks.
Cloud-Based Code Repositories Gain Momentum – Develop Responsibly
In the development category, cloud-based code repositories have gained momentum. The shift to open source cloud-based code repositories
presents security challenges as some sites are known to host malicious backdoors. GitHub is blocked 21% of the time but Codehaus, a highrisk service, is blocked only 1% of the time.
Microsoft – A Not-So-Sleeping Giant
While Microsoft may be falling out of favor with new users, it is too early to count them out. The 3rd most used file sharing cloud service is
SkyDrive. The software giant dominates in collaboration with Office 365, Skype, and Yammer in the top 10 of the most used services in this
category.
File Sharing Side Effects – Risk and Confusion
File sharing is the most used and most misunderstood category by IT professionals. 19 file sharing cloud services are used by an organization
on average, which impedes collaboration and increases security and compliance risks. 4 of the top 10 most used file sharing services are highrisk. Box is blocked 34% of the time, but RapidGator, a high-risk service, is blocked only 1% of the time.
Cloud Adoption & Risk Report
|
3
Users and Services per Company
Users
3M+
Min
Average
502
25,590
Max
200,000+
Services
2,204
Cloud Adoption & Risk Report
|
4
Min
Average
83
545
Max
1,769
Collaboration, Social Media, and File Sharing
Dominate with 14 of Top 20 Services
Top 20 Services
Percentage by Service Type
1
Facebook
11
Tumblr
2
Twitter
12
Apple iCloud
3
Amazon Web Services
13
Salesforce
4
YouTube
14
Dropbox
5
LinkedIn
15
ServiceNow
6
Pinterest
16
Skype
7
Office 365
17
Yahoo! Mail
8
Cisco WebEx
18
ADP
9
Gmail
19
Google Drive
10
Google Docs
20
SkyDrive
Top Services based on number of users
Cloud Adoption & Risk Report
|
5
Content Sharing and Social Media are the
Largest Consumers of Bandwidth
Highest Volume Services
Percentage by Service Type
1
YouTube
11
Office 365
2
Mozy
12
ServiceNow
3
Cisco WebEx
13
Tumblr
4
Pandora
14
Twitter
5
Salesforce
15
SoundCloud
6
Facebook
16
Dropbox
7
Amazon Web Services
17
Box
8
Gmail
18
LinkedIn
9
Grooveshark
19
Pinterest
10
Vimeo
20
SourceForge
Cloud Adoption & Risk Report
|
6
Across Top 100 Services
IT Blocking Services Based on Productivity
Loss Rather than Risk
Most Blocked Services
Percentage by Service Type
1
Netflix: 46%
11
Facebook: 21%
2
Foursquare: 45%
12
GitHub: 21%
3
Apple iCloud: 39%
13
Zendesk: 21%
4
Gmail: 31%
14
Pinterest: 21%
5
Skype: 31%
15
Twitter: 20%
6
Amazon Web Services: 31%
16
Constant Contact: 18%
7
Batanga: 29%
17
ExactTarget: 17%
8
Dropbox: 29%
18
Docstoc: 17%
9
KISSmetrics: 27%
19
ShareThis: 16%
10
Photobucket: 22%
20
HubSpot: 16%
Cloud Adoption & Risk Report
|
7
Low Risk Services Blocked 40% More Than
High-Risk Services
High Risk Services
Medium Risk Services
Low Risk Services
8%
92%
14%
86%
11%
89%
BLOCKED
ALLOWED
BLOCKED
ALLOWED
BLOCKED
ALLOWED
The risk of each service is based on Skyhigh CloudRiskTM, which assigns a 1-to-10 risk rating based on a detailed, objective, and
weighted assessment of more than 30 attributes across data risk, user risk, device risk, service risk, business risk and legal risk.
Cloud Adoption & Risk Report
|
8
IT Unaware of Risks Presented by
Development and Tracking Services
Back-Up & Archiving
|
9
Social Media
67%
78%
80%
ALLOWED
ALLOWED
ALLOWED
33%
22%
20%
BLOCKED
BLOCKED
BLOCKED
Development
Cloud Adoption & Risk Report
File Sharing
Content Sharing
Tracking
90%
91%
93%
ALLOWED
ALLOWED
ALLOWED
10%
9%
7%
BLOCKED
BLOCKED
BLOCKED
Familiar Services Blocked More Often than
High-Risk Services
Familiar
High-Risk
Financial Services
95%
Apple iCloud
93%
Skype
89%
High Tech
Healthcare
100%
89%
Google Drive
88%
35%
SugarSync
23%
Dropbox
14%
Memeo
Skype
Google Drive
Dropbox
SendSpace
1%
4shared
1%
SkyPath
2%
Codehaus
0%
WeTransfer
0%
ZippyShare
0%
CloudApp
0%
Hostingbulk
0%
RapidGator
7%
Services
27%
StumbleUpon
26%
bitly
24%
Media
Manufacturing
82%
65%
Google Drive
41%
42%
WatchDox
Force.com
Box
PayPal
18%
Cisco WebEx
17%
Apple iCloud
0%
authorSTREAM
1%
CloudApp
0%
MovShare
0%
FileFactory
0%
SockShare
0%
myCapture
0%
Minus
0%
RapidGator
0%
Uploaded
Cloud Adoption & Risk Report
| 10
Financial Services Firms have the Highest
Blocking Rate; Manufacturing the Lowest
30%
26%
25%
20%
15%
9%
10%
9%
7%
5%
2%
.4%
0%
Financial Services
Cloud Adoption & Risk Report
| 11
Services
Media
Healthcare
High Tech
Manufacturing
Use of Cloud Services is Pervasive Across
all Verticals
2000
1871
1800
1616
1614
1600
1425
1400
1200
1006
1000
863
800
600
584
400
548
INDUSTRY
AVERAGE
INDUSTRY
AVERAGE
602
525
INDUSTRY
AVERAGE
INDUSTRY
AVERAGE
447
INDUSTRY
AVERAGE
200
516
INDUSTRY
AVERAGE
0
Manufacturing
Cloud Adoption & Risk Report
| 12
Financial Services
High
Tech
HighTech
Media
Healthcare
Services
Use of High-Risk Services is also Pervasive
Across all Verticals
140
120
116
95
100
93
91
80
65
61
60
40
20
0
Manufacturing
Cloud Adoption & Risk Report
| 13
Media
Financial Services
High Tech
Healthcare
Services
Collaboration, Development, and File
Sharing are Fastest Growing Categories
264
COLLABORATION
24
TRACKING
129
DEVELOPMENT
46
SOCIAL
MEDIA
49
Number of Services
by Category
105
FILE SHARING
BACK-UP &
ARCHIVING
92
79
CRM
86
CONTENT
SHARING
Cloud Adoption & Risk Report
| 14
BUSINESS
INTELLIGENCE
145 TOTAL FILE SHARING SERVICES
40% of the Top 10 File Sharing
Services are High-Risk
Top 10 File Sharing Services
5 MOST BLOCKED SERVICES
1
Dropbox
2
Google Drive
3
SkyDrive
4
Box
5
Hightail
6
CloudApp
7
Citrix ShareFile
8
RapidGator
9
Zippyshare
10
Uploaded
Box
Zippyshare
Dropbox
4Shared
Top 10 Risk Distribution
40%
HIGH-RISK
Cloud Adoption & Risk Report
Uploaded
| 15
30%
MEDIUM-RISK
30%
LOW-RISK
129 TOTAL DEVELOPMENT SERVICES
Cloud-Based Code Repositories Become
Mainstream
Top 10 Development Services
5 MOST BLOCKED SERVICES
1
MSDN
2
GitHub
3
SourceForge
4
Atlassian OnDemand
5
Apple Developer
6
Zend Server
7
Hortonworks Data Platform
8
CollabNet
9
Apache Maven Repository
10
Codehaus
Cloud Adoption & Risk Report
| 16
Force.com
Atlassian OnDemand
SourceForge
Hortonworks
GitHub
264 TOTAL COLLABORATION SERVICES
Microsoft Owns 3 of the Top 10
Collaboration Services
Top 10 Collaboration Services
5 MOST BLOCKED SERVICES
1
Office 365
2
Cisco WebEx
3
Gmail
4
Google Docs
5
Skype
6
Yahoo! Mail
7
AOL
8
SlideShare
9
Evernote
10
Yammer
Cloud Adoption & Risk Report
Groupme
ProofHQ
Gmail
| 17
Asana
GoToMeeting
24 TOTAL TRACKING SERVICES
Tracking Services Provide No Business Value
but Create Vulnerability to Watering Hole Attacks
Top 10 Tracking Services
5 MOST BLOCKED SERVICES
1
Google Analytics
2
AddThis
3
Chartbeat
4
Gigya
5
Mixpanel
6
Clicky
7
KISSmetrics
8
Feedjit
9
Woopra
10
GoSquared
Cloud Adoption & Risk Report
Kampyle
KISSmetrics
Gigya
| 18
Flag Counter
Clicky
86 TOTAL CONTENT SHARING SERVICES
Content Sharing Services are the Largest
Consumers of Bandwidth
Top 10 Content Sharing Services
5 MOST BLOCKED SERVICES
1
YouTube
2
Pinterest
3
Vimeo
4
Photobucket
5
Flickr
6
SkyPath
7
Instagram
8
SmugMug
9
Panoramio
10
SoundCloud
Cloud Adoption & Risk Report
Minus
SkyPath
Photobucket
| 19
SoundCloud
Pinterest
49 TOTAL BACK-UP & ARCHIVING SERVICES
Back-Up & Archiving is the Most Blocked
Category (33% Blocked)
Top 10 Back-Up & Archiving Services
5 MOST BLOCKED SERVICES
1
Apple iCloud
2
Mozy
3
Sonian
4
SafeCopy Backup
5
Iron Mountain
6
AVG LiveKive
7
Norton Online Backup
8
Cloudfinder
9
Carbonite
10
DataSafe
Cloud Adoption & Risk Report
| 20
Carbonite
Apple iCloud
Norton Online
Backup
MyPC Backup
SOS Online Backup
46 TOTAL SOCIAL MEDIA SERVICES
The Big 3 (Facebook, Twitter, LinkedIn) Used More
than the Next 7 Social Media Services Combined
Top 10 Social Media Services
5 MOST BLOCKED SERVICES
1
Facebook
2
Twitter
3
LinkedIn
4
Tumblr
5
Digg
6
Foursquare
7
Ning
8
Delicious
9
LiveJournal
10
Meetup
Cloud Adoption & Risk Report
Renren
Foursquare
Twitter
| 21
Facebook
yfrog Social
79 TOTAL CRM SERVICES
Salesforce Dominates the CRM Services
Category with Over 60% User Share
Top 10 CRM Services
5 MOST BLOCKED SERVICES
1
Salesforce
2
Marketo Sales Insight
3
NetSuite
4
Lithium Social Support
5
Infor Epiphany Enterprise
6
Sage SalesLogix Today
7
Pega Sales Force Automation
8
InsideView
9
IdeaScale
10
InsideSales
Cloud Adoption & Risk Report
| 22
Pega Sales Force
Automation
NetSuite
Inside View
Marketo Sales
Insight
Lithium Social
Support
About Skyhigh Networks
Skyhigh Networks, the cloud access security company, enables companies to
embrace cloud services with appropriate levels of security, compliance, and
governance while lowering overall risk and cost. With customers in financial
services, healthcare, high technology, media, manufacturing, and legal verticals, the
company was a finalist for the RSA Conference 2013 Most Innovative Company
award and was recently named a “Cool Vendor” by Gartner, Inc. Headquartered in
Cupertino, Calif., Skyhigh Networks is led by an experienced team and is venturebacked by Greylock Partners and Sequoia Capital.
Visit us at http://www.skyhighnetworks.com
or follow us on Twitter @skyhighnetworks
Cloud Adoption & Risk Report
| 23
Download