Stories by Puneet Kukreja

Establishing a Cloud Broker Model – Part 2

By Puneet Kukreja | 04 June, 2013 10:44

In 1973 Peter Drucker in his book “Management Tasks and Responsibilities” defined strategic planning as: “The continuous process of making present entrepreneurial (risk-taking) decisions systematically and with the greatest knowledge of their futurity..."

Establishing a Cloud Broker Model – Part 1

By Puneet Kukreja | 15 March, 2013 16:34 | 1 Comment

Information Security, IT Security, Technology Security, IT Risk and Security and IT Risk Services are all names that organisations use to define a functional unit within their enterprise that is responsible for the security, integrity and operational assurance of their information assets and operating environment.

Three Facts of Data Security Legislation for the Cloud

By Puneet Kukreja | 19 December, 2012 12:49

Over the last 2-3 years cloud computing has promised, and in many instances delivered, a lower total cost of ownership. This has helped organisations return the focus of operation to their core activities—reducing the effort spent on managing IT infrastructure and applications.

Think cloud, think Patriot Act

By Puneet Kukreja | 17 October, 2012 16:23 | 1 Comment

In theory at least, there is the promise of saving money, faster turnaround time, no lengthy requirements gathering, purchasing of equipment, following project management life-cycle, no architects getting in the way debating good design, lengthy hardware and software procurement cycles just basic business requirements and a PO, in other words Credit Card IT. Sounds familiar, sounds easy, excellent.

Think cloud – think strategy – think "Sun Tzu"

By Puneet Kukreja | 31 August, 2012 12:29 | 2 Comments

The steady rise of cloud over the last few years across the software, infrastructure and platform domains has forced most technology business leaders to stop and take note. The voracity with which the perceived value and adoption of cloud computing and cloud Services has grown should be viewed and actioned as a strategic initiative and not a tactical undertaking with short term goals and limited benefits. To move things along and provide context I turn to Sun Tzu's "The Art of War", that helps identify strategy elements required by executives and senior management grappling with the challenge of cloud.

Cloud contracts – check your SLAs

By Puneet Kukreja | 30 July, 2012 09:48

As the world of cloud computing grows and becomes part of organisational growth strategies, procurement of cloud computing services has also reached front of mind.

Cloud contracts – the Devil is in the detail

By Puneet Kukreja | 30 May, 2012 17:03 | 1 Comment

Cloud computing today is no longer a buzzword associated with universities or advanced technology organisations at the bleeding edge of innovation. It is now a mainstream sourcing model that most organisations are looking to as part of their broader IT strategy.

Cloud governance – manage the cloud challenge

By Puneet Kukreja | 30 April, 2012 14:16

The word governance derives from the Greek verb κυβερνάω [kubernáo], which means to steer, and was used for the first time in a metaphorical sense by Plato (according to Wikipedia). Wikipedia further expands on the term, rightly calling it “the act of governing”. Governance relates to decisions that define expectations, grant power, or verify performance.

Embracing the Cloud – A Decision Framework

By Puneet Kukreja | 19 March, 2012 13:47

With major restrictions and inherent limitations in most IT environments, it’s become an attractive option for businesses. Concerns such as spending restrictions; immature capacity management; uncertain demand forecasting; duplication of capability; slow delivery of infrastructure and slow business application delivery all lead businesses to look wistfully at cloud computing.

To Cloud or Not To Cloud

By Puneet Kukreja | 14 February, 2012 09:36 | 2 Comments

In today’s uncertain times, cost-savings are a primary focus for executives. Cloud services do seem to offer a silver bullet solution when it comes to infrastructure and ancillary IT services.

5 principles of selling security initiatives to executives

By Puneet Kukreja | 11 January, 2012 09:18

In the world of data leaks and cybercrime, why is it that selling information security is considered a hard task? Is it because information security is pitched as a tool—buy software and it will fix everything—or is there a lack of understanding about what a healthy information security posture will achieve for an organisation.

Security Operations the Final Frontier – Part III

By Puneet Kukreja | 20 December, 2011 11:48

Security Operations, as a capability, was discussed in the first article of this series: Security Operations the Final Frontier. This was a response to media coverage of a other operations in which information was compromised and data assets were stolen - Operation Shady RAT, Operation Aurora and Operation Night Dragon.

Auditing Cloud Services

By Puneet Kukreja | 25 October, 2011 11:54 | 1 Comment

Business agility and the demand for quick turnaround to infrastructure and application requirements to service organisational growth have fuelled the rise of cloud services. For organisations that have had their IT system requirements held back by traditional sourcing and project based delivery of information technology, cloud seems to be the answer.

Security Operations the Final Frontier – Part II

By Puneet Kukreja | 13 September, 2011 12:38 | 1 Comment

I have created my own interpretation of what a good pragmatic Security Operations Model (SOM) would look like. This has been adapted from a number of Security Frameworks and Industry Good Practices like ITIL, COBIT, NIST, OCTAVE, OWASP and the ever present ISO 27001/2 all of which have an input into the structure and makeup of an effective security operations framework or security operations model.

Security Operations the Final Frontier

By Puneet Kukreja | 31 August, 2011 19:57

Operations Shady RAT, Operation Aurora, Operation Night Dragon sounds like names out of a WikiLeaks memo or even more a Hollywood action blockbuster. Sadly not, these are the three names that have done the rounds in the last 2 – 3 years where information security defenses of organizations were not only breached but data assets were stolen for sure.

CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

NetIQ iSeries Security

The NetIQ iSeries Security Solutions helps you eliminate security risks and maintain business continuity

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.