Ask the Experts: Creating a Security and Compliance Strategy

Welcome to Ask the Experts, brought to you by CloudServicesUniversity.com. In this video, Intelisys’ SVP Cloud Transformation Andrew Pryfogle discusses key details to keep in mind when creating a security and compliance strategy for your customers with CenturyLink’s former Product Manager, Jared Ruckle. Find out more about compliance and security from the CenturyLink team here: https://cloudservicesuniversity.com/supplier-directory/centurylink/

Andrew: Okay. Let’s plow ahead with another Ask the Experts session. We’ve been talking a lot about compliance, and the requirements around compliance, and why that’s becoming such a huge pain point for many enterprise customers. We’ve invited the studios here today Jared Ruckle, who is the Product Manager for CenturyLink. Jared, welcome back, man.
Jared: Thanks. Great to be here with you, Andrew.
Andrew: Good deal. I want to talk to you about compliance. It’s a hot topic right now. It seems like it’s an enormous burden on a lot of IT leaders to try to figure out how to make their network and systems, their applications, their data compliant. Whether it be PCI or HIPAA, or others. I want to get your take on that. If you had to boil it down, what are the top two or three, four, things that customers must do when considering compliance and their network and security strategy? Talk about it.
Jared: I think that there’s a couple different things that immediately jump to mind. You really have to think about the security and compliance thing first. If you try and layer on compliance or layer on security provisions after the fact, you’re fighting an uphill battle. Think about how you’re securing data at the API layer, at the network layer, around the perimeter. What type of security and compliance you can get in the control plane of your systems that you’re using. Think about what the compliance architecture looks like up front. Don’t try and just tack on a couple things here and there.
I’d also say have a very open mind about where your data is going to live. A lot of times people will say, “Oh, we’ve got compliance needs and we’re very highly regulated, so I can’t use the public cloud, for example. We’ve got to be able to go on premises.” That was probably true, or at least partially true, five or six years ago. But public cloud providers out there have really advanced their offerings dramatically over time. And if you need that sort of self-service agility of public cloud, there’s a very good chance you can meet a lot of compliance requirements based on some of the add-on virtual appliances and other isolation options offered by cloud vendors today. Absolutely have an open mind about where you can go, and what you actually need that compliant environment and application to do.
Andrew: Got it. Love it. There’s two I heard there: The first is start the conversation early. Have the compliance conversation at the foundational design level of a cloud solution. Is that a fair restatement?
Jared: Yeah, I think so. And I think you also have to look at this from the security point of view. Another thing that I would suggest that you have to do in compliance and security is assume you will be hacked. There are two types of companies out there that I like to say: those that have been hacked, and those that will be. Once you accept this reality, you’re able to get more comfortable about designing things from the ground up, with security being front and center. And what you do and how you can secure data with APIs, and really lock it down at the service level.
Andrew: That is true and a little depressing. Thank you, Jared.
Jared: Sure thing.
Andrew: But absolutely. The foundational planning very early on. Let’s work the compliance piece into the design from the very get-go. The open mind, I think that’s really smart. I would even argue that moving to a public or perhaps even a hybrid cloud solution could be far more secure than what you could ever create at your own prem. When it comes to compliance, it’s perhaps even easier to achieve that leaning on the engineering resources of companies like a CenturyLink.
Jared: Absolutely. The reality is we have a lot of engineers on staff that do this for our platform across all customers. So it’s really, in essence, a shared feature and a shared attribute of the platform. Customers of these cloud services get a lot of this built-in as part of just having VMs or even bare metal servers inside of the platform.
Then with these add-on things, like we talked a little bit earlier, all these capabilities advancing. It’s really easy to add in encryption where you need it. It’s really easy to build in virtual appliances and some of these really advanced firewalls. A lot of those network topologies that IT loved on their on-prem data center, to really meet those security and compliance needs, can be done in the public cloud just with virtual appliances as opposed to dedicated things. That’s why it’s really important to stay on top of what’s happening.
I think when it comes to compliance and security, it’s all about the data. Think about the data that you’re trying to access and lock down, and secure, and have controlled access to. If you need that data to go into, say, new systems for a mobile application, you have to think creatively about how you want to surface that data with APIs. And even looking at platform services like Cloud Foundry that can give you a lot of security for free at the API layer. It’s also about how you want that data to be moved and manipulated around–that’s an important consideration.
Andrew: Very cool. Really, really important stuff to think about because, like you said, if you haven’t been hacked, you’re about to be.
Jared: Right.
Andrew: All right. Very cool. Hey, Jared, thanks for jumping in, man. Really, really good stuff. Great insights. Thank you.
Jared: Enjoyed it. Cheers.
Andrew: Guys, that’s Jared Ruckle. He’s the Product Manager for CenturyLink, one of our go-to smart guys for all things cloud. Do check out the learning center for CenturyLink. They’ve got lots of great information there. They’ve got a really, really robust public and hybrid cloud solution that can help you close big deals. Check it out. We’re big fans. You should be, too. Good selling.

Ken Mills

President

Ken Mills serves as President of Intelisys and is committed to driving growth for Intelisys and our partners. As a distinguished technology executive with over two decades of experience, Ken has previously held leadership roles at EPIC iO, Dell Technologies and Cisco, and served as a fellow with the U.S. Department of State. His strategic mindset has been an integral part of launching innovative products and solutions in the fields of AI, IoT, and 5G. Ken is driven by his curiosity and passion for groundbreaking technology and complex problems, and constantly explores new frontiers in the world of technology.

Monica Lutes

Manager, People & Culture, ScanSource, Inc. and Intelisys

As Manager, People & Culture, Monica has worked closely with Intelisys employees and leaders since 2018 and has worked with ScanSource companies since 2016. A Human Resources professional with 11 years of experience encompassing all areas of HR, especially employee relations, recruiting, compliance, and training, Monica approaches her role as Manager, People & Culture from a consultative perspective. Her goal is to provide advice and guidance to leaders so they can focus on growing the best teams for the business while also supporting employees’ goals.

Ansley Hoke

SVP Marketing, ScanSource, Inc. and Intelisys

Ansley Hoke is the Senior Vice President of Marketing at ScanSource, Inc., a role she has held since 2019, and extended her leadership to include Intelisys in 2023. She joined the company in 2001, serving in merchandising leadership roles for ScanSource POS and Barcode, including acting Vice President of Merchandising and then later VP of Merchandising for ScanSource Catalyst and overall VP of ScanSource Catalyst. She oversaw sales, supplier relations, and services. Known for her pivotal role in creating effective marketing strategies, Ansley has been integral in driving demand, enhancing partner programs, and significantly contributing to the company’s revenue growth and channel relationships.

Mike Baur

CEO of ScanSource, Inc. and Interim President of Intelisys

Mike Baur serves as Chairman and Chief Executive Officer at ScanSource. Mike has served as the Company’s President or CEO since its inception, as a director since December 1995, and as Chairman of the Board since February 2019. Mike has developed a deep institutional knowledge and perspective regarding ScanSource’s strengths, challenges and opportunities. He has more than 30 years of experience in the IT industry, having served in various leadership and senior management roles in the technology and distribution industries before joining ScanSource. Mike brings strong leadership, entrepreneurial, business building and development skills and experience to the Board.

Stephanie Bouras

Regional Vice President, Southeast

Driven by a partner-first philosophy and a passion for innovation, Bouras embodies a leadership style that’s both compassionate and data-driven. As the Regional Vice President, Southeast, at Intelisys, she’s leveraged her extensive marketing and sales experience to propel her team to new heights. A firm believer in aligning herself with her partners, she sees herself as a collaborator and an integral part of their business. This perspective has allowed her to forge deep connections and drive success. A Florida native, Stephanie’s attention to detail and unwavering commitment to her partners have been key factors in her success.

Michael Raspanti

Regional Vice President, Northeast

Michael joined Intelisys in June of 2020, as a long-time channel veteran. He is responsible for leading the Northeast Region, helping continue the tremendous momentum in one of our strongest markets while also recruiting new up and coming partners that will be the growth engine of our future success.

Kristy Thomas

Vice President, Partner Experience and Enablement

Thomas is responsible for Sales Partner enablement and education for all our technology segments, including CX, managed security, mobility, and connectivity. With over 20 years of executive background in telephony, UCaaS, CCaaS and Cloud services, Kristy enables her customers to think broader and deeper as she guides them through their decision journey. Some of the biggest deals in the channel have become a reality thanks to the expertise and humble excellence Kristy brings to her client’s projects.