In 2015, just before Christmas, the lights started going out in Ukraine. There was a cyber attack on its power grid, plunging entire neighbourhoods into darkness. Unlike conventional wars, cyber attacks offer dictators the option of plausible deniability. The IT infrastructure can become a source of vulnerability.
What makes one’s environment susceptible to hackers?
Unlike popular perception, 99% of our software vulnerabilities come not from the code that we write. They are embedded in the software supply chains that we created. Software supply chains are the outcome of the abstractions we create as the industry matures over time.
The evolution of computing can be seen as a trend towards abstraction. We first went from a physical machine to a virtual machine, where a piece of software abstracted parts of a physical machine. The operating system abstracts the underlying virtual machine and offers us and the applications a neat interface to work with. More abstraction allows us to buy targeted softwares. Our code is eventually the top most layer in a complex interaction between several layers until it reaches the physical bits and bytes.
Think of it like a car. I interact with the steering wheel, the gas and the brake pedal. Whatever happens below the gas pedal is abstracted away, so that I can focus on the traffic.
Unlike the automobile industry, the technology world is still nascent. Standards continue to evolve rapidly. Older, outdated standards become a vulnerability as time progresses.
The cloud can help in the following ways.
Buy everything as a service
If you are a small company, buy everything as a service. You write your own code if you need to customize it, but beyond that, you do not have to worry about the supply chain vulnerability.
Back up in the cloud
If you have a legacy infrastructure, you can create an alternative, relatively clean infrastructure in the cloud for the most critical operations.
Use the cloud organization policies to control your vulnerabilities
In the cloud, you can write your infrastructure as a piece of code. You can set policies that prohibit the use of softwares with known vulnerabilities.
Make updates less risky
It is not laziness but fear that stops organizations from regularly updating their infrastructure and legacy applications. The applications are interconnected. There is little visibility of their interdependencies. Hence the maxim “If it ain’t broken, don’t fix it”. The cloud can offer a parallel “training ground” for you to test your update and the interdependencies before you implement it.

Leave a Reply