Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Startup Bromium takes aim at cloud security

The company will use a hypervisor to isolate and protect applications

Simon Crosby, the former CTO of Citrix Systems' data center and cloud business, has formed a startup called Bromium that will aim to solve security problems in a cloud environment.

Crosby founded Bromium along with Guarav Banga, former CTO and senior vice president at Phoenix Technologies, and Ian Pratt, chairman of Xen.org and co-founder of XenSource. Banga will be CEO while Crosby serves as CTO and Pratt will be senior vice president, products.

The company emerged from stealth mode on Tuesday as Crosby announced its mission at the Gigaom Structure conference in San Francisco. Bromium plans to use a hypervisor to provide servers and clients continuous protection from malware, Crosby said.

"We seem to have found a way to allow a hypervisor to do continuous protection of an executable piece of code," Crosby said.

Enterprises are worried about the security of cloud computing but the threat doesn't lie in the cloud, he said.

"The vast majority of attacks on enterprise private clouds happen through unprotected clients. It's you putting your private stuff and your work stuff on a relatively insecure client device," Crosby said.

Access to cloud-based resources from anywhere, on a variety of devices, requires a new approach to security, he said.

Locking down PCs hurts the user experience, and using virtual desktops provides greater security but still leaves enterprises vulnerable to harmful elements such as e-mail attachments, Crosby said. Applications are inherently vulnerable, so securing clients and data centers while giving users freedom requires a different approach, he said.

Bromium's technology will secure application clouds and virtual desktops as well as rich client devices, according to a slide Crosby showed at Structure. It will run on multiple processor platforms, including x86 and ARM, and will be optimized for mobile devices.

According to a press release on Tuesday, Bromium has raised US$9.2 million in venture capital and will introduce a product in the second half of this year. The company is based in Cupertino, California, and Cambridge, U.K.

Stephen Lawson covers mobile, storage and networking technologies for The IDG News Service. Follow Stephen on Twitter at @sdlawsonmedia. Stephen's e-mail address is stephen_lawson@idg.com

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Citrix, Citrix Systems, IDG, Lawson, Phoenix, Phoenix Technologies, Phoenix Technologies, XenSource
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Bromium, business issues, Citrix Systems, cloud computing, internet, personnel, security
Latest Blog Posts
Whitepapers
  • Lower Your IT Costs When You Standardize on Oracle Database 11g
    As business operations become more complex, the demand for change in IT increases, along with the associated risks that must be mitigated. Today’s IT professionals are asked to manage more information and deliver it to their users in a timely manner with ever-increasing quality of service. And in today’s economic climate, IT must also reduce budgets and derive greater value out of existing investments.
    Learn more »
  • Backup and Recovery as we Know it is Changing
    Increasing complexity in the data centre, including the rapid deployment of virtual servers, ever-expanding compliance requirements, and increasing amounts of sensitive data on mobile devices has put more strain on backup and recovery. Read on.
    Learn more »
  • Information Security Policies, Standards and Procedure
    As a result of the adjustments in the way business is conducted, ownership of information does not carry the same clear accountability it once did. Physical and behavioural boundaries used to exist around information management but these can be missing in the modern workplace. Clearly thought-out information security policies, standards and procedures addressing internationally supported standards, will go a long way to addressing the risk exposure these changes have created. In this third paper, “Policies, Standards and Procedures,” we discuss guidelines for effective information security management.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments