Forbes Cloud 100 2018: Stripe holds off Slack to retain top private cloud title

Payments provider Stripe remains the number one privately owned cloud company ahead of social messaging firm Slack, according to the latest rankings from Forbes.

The media firm’s latest Cloud 100 list, celebrating the best private cloud firms – as in, cloud companies who are private – saw Stripe retain top spot with what Forbes calls ‘the online tool kit for digital payments, helping billions in transactions flow back into the economy.’

After Stripe and Slack however – which was third last year – there are significant changes at the top table. Dropbox, DocuSign and Adyen, which all made the top five in 2017’s list, have all since gone public. This publication noted in March, when Dropbox had filed for IPO, that the company had moved away from Amazon Web Services to its own infrastructure – a particularly long process.

The Cloud 100 was put together alongside Salesforce Ventures and Bessemer Venture Partners. The latter, perhaps not uncoincidentally, also produces a yearly report focusing on cloud and enterprise M&A trends. 2017’s most prominent IPO-ers were Cloudera, MongoDB, and Okta – an improvement on the previous year but still below historical averages.

It is too early however to see the VC firm’s primary prediction for this year to bear fruit. The keynote of Bessemer’s State of the Cloud report was that serverless, APIs, and blockchain would shape the cloud landscape in 2018 and beyond. It will take a while however for those biggest players to infiltrate the wider landscape – as the Forbes 100 list continues to be dominated by SaaS firms.

Yet the rise of artificial intelligence (AI) is notable. Among the more interesting companies in this year’s crop are UiPath, Darktrace and Checkr. UiPath, a new entry at #14, is a robotic process automation vendor based in New York, with Forbes admitting the company, with 1,350 companies, “absolutely came out of left field.” San Francisco-based Checkr (#47), meanwhile aims to provide a solution for background checks utilising AI, to better classify records without threatening compliance.

Cybersecurity provider Darktrace (#36), whose team is led by former US and UK researchers and government agents, is one of only two companies holding Britain’s end up in the list. The launch of cyber-AI tool Antigena last year was met with reasonable fanfare; as sister publication IoT News put it at the time, using AI for threat monitoring offers “tangible benefits”, picking up on threats and reacting to them without the need for manual action.

It is worth noting the influence being named on the Cloud 100 holds. Over the past three years, from MuleSoft to Cloudera and many more in between, every major cloud IPO or acquisition has meant a company on the 100 list departs. The publishing of this year’s list will lead some in the industry to ponder over future trajectories. Slack, who topped the list in 2016 before being usurped by Stripe for the past two editions, recently announced series H funding – to put this in perspective, the ‘record’ is series J, which big data firm Palantir Technologies took in 2014 – of $427 million, taking the company’s value to more than $7 billion.

“The 2018 Cloud 100 represents well over $135 billion in private shareholder value – an astonishing figure that reminds us yet again of the power of the cloud,” said Byron Deeter, partner at Bessemer Venture Partners. “The way we do business will be dramatically different as a result of these companies and I am honoured to celebrate the remarkable accomplishments of the founders and teams behind each company on the 2018 Cloud 100.”

The top 10 companies, in descending order, are Stripe, Slack, Zoom Video Communications, Tanium, Procore Technologies, CrowdStrike, Qualtrics, Squarespace, Elastic, and Eventbrite. Take a look at the full Forbes Cloud 100 list here and compare with 2016 and 2017’s verdicts.

How the Cloud Security Alliance Cloud Controls Matrix benefits financial institutions

The self-service and dynamic nature of cloud infrastructure creates challenges for risk and compliance professionals. Tools that worked well in the traditional data centre do not translate to the public cloud.  

Due to these concerns over regulatory compliance and security, as well as the complexity involved in replacing legacy systems, financial institutions are taking a more tentative approach to change – especially when it comes to implementing new technologies that could put compliance at risk.

So how can today’s financial service organisations embrace the many benefits of the cloud without opening up a Pandora’s box of risk relative to compliance and security?

Cloud native frameworks

One way that innovative financial service organisations are addressing this issue is by introducing cloud native frameworks to govern the cloud. The major cloud providers have been hard at work to ensure that there is a fundamental infrastructure for compliance in place, and new tools are available to ensure that the parameters are being followed and that financial institutions are in compliance.

Let’s explore one of these common frameworks and how it maps to the cloud.

Cloud Security Alliance Cloud Controls Matrix (CSA CCM)

The Cloud Security Alliance Cloud Controls Matrix (CSA CCM) framework provides fundamental security principles to guide cloud vendors and assist prospective cloud customers in determining the overall security risk of a cloud provider. The CSA CCM provides a controls framework with a detailed explanation of security concepts and principles that are aligned to the Cloud Security Alliance guidance in 13 domains.

As a framework, the CSA CCM provides organisations with the needed structure, detail, and clarity relating to information security tailored to the cloud industry.  It has also become the generally agreed upon standard of US-based financial services companies on how they will govern their use of the cloud.   Many financial institutions use the CSA CCM because it encompasses multiple security frameworks across multiple organisations and allows them to look at their legacy frameworks and determine which portions are covered.

The CSA CCM strengthens existing information security control environments in a number of ways:

  • It emphasises business information security control requirements;
  • It reduces and identifies consistent security threats and vulnerabilities in the cloud;
  • It provides standardised security and operational risk management; and
  • It seeks to normalise security expectations, cloud taxonomy and terminology, and security measures implemented in the cloud.

One reason it is such a powerful resource is that if you are compliant in one area, it can provide validation that you are compliant with numerous related frameworks. 

For example, the control ID – DIS-03 under the CCM Domain – data security and lifecycle management for eCommerce transactions, requires data related to e-commerce that traverses public networks to be appropriately classified and protected from fraudulent activity, unauthorised disclosure, or modification in such a manner to prevent contract dispute and compromise of data.  If an organisation is in compliance with DIS-03 there is a direct correlation with NIST 800-53 which addresses these same security requirements with controls including:

  • AC-14: Permitting actions without identification or authentication
  • AC-21: Information sharing
  • AC-22: Public Accessible content
  • IA-8: Identification and Authentication (Non-organisational users)
  • AU-10: Non-Repudiation
  • SC-4: Information in shared resources
  • SC-8: Transmission confidentiality and integrity
  • SC-9: Transmission confidentiality

Many financial institutions use the CSA CCM because it encompasses multiple security frameworks across multiple organisations and allows them to look at their legacy frameworks and determine which portions are covered.

CSA CCM and cloud management platforms

CSA CCM has directives AIS-04, BCR-07, BCR-10, BCR-11, IAM-01, IAM-12, IVS-01, and IVS-03.  All of these require that you have Global API Accounting Configured so that it records API calls for your account and delivers log files to you. The recorded information includes the identity of the API caller, the time of the API call, the source IP address of the API caller, the request parameters, and the response elements returned by the specific cloud service. Global API Accounting provides a history of API calls for each account, including API calls made via the management console, SDKs, command line tools, and other cloud services.  Without this, you are in violation of CSA CCM. With a cloud management platform, users can build an automation to remediate. For example, in AWS, this would mean the cloud management platform would use the API to write credentials to turn on AWS CloudTrail for the resource in question.

Embracing cloud automation

The ability to automate the enforcement of best practices and standards will be a game changer for the financial services industry. Cloud automation tools provide organisations with continuous compliance and the ability to take the burden off of the IT department by automatically monitoring applications and identifying and fixing issues on the fly. They continuously scan the virtual infrastructure, identify non-compliant resources and remediate common cloud problems related to security, cost and compliance.

As financial institutions look to reinvent their IT organisations, they must ensure that security, governance and compliance is at the foundation of all decisions.  Regulatory compliance and managing cyber risk do not need to be the enemy of innovation. For such a regulated industry, automated cloud services and frameworks can help financial service organisations advance IT innovation

Datrium secures $60m series D funding to go beyond hyperconverged infrastructure

Datrium, a California-based hybrid cloud infrastructure provider, has raised $60 million (£45.8m) in series D funding, with the aim of helping enterprises ‘overcome major obstacles in data analysis and storage.’

The round was led by Samsung Catalyst Fund, as well as featuring new participation from Icon Ventures. NEA and Lightspeed Venture Partners – who regular readers of this publication would recognise as investors in Netskope, CloudBees and Zscaler among others over the years – also participated in the oversubscribed round.

The company’s primary offerings are based around its DVX product, for cloud and on-premises which promises 10 times the speed and scale of legacy hyperconverged infrastructure, as well as cloud backup and cloud disaster recovery orchestration.

Datium claims it is pioneering the area of 2-layer infrastructure, which represents a step up from traditional hyperconverged infrastructure. As CEO Tim Page recently put it to The Silicon Review, the company provides ‘a single management interface across enterprise data centres and public cloud so IT can administer the hybrid cloud at the virtual machine level supported by real-time analytics and without all the detailed configuration time of traditional data centre infrastructure.’

Customers include Fortune 100 companies across industries such as financial services, healthcare, manufacturing and entertainment.

“We are thrilled to partner with Samsung and Icon Ventures to expand our technical and geographical momentum,” Page said in a statement. “Enterprises globally have the same problems in simplifying compute and data management across on-prem and cloud. Where SANs don’t even have a path to cloud, traditional HCI has too many trade-offs for core data centres – backup requires separate purchasing and administration, and cloud DR automation is seldom guaranteed. Larger enterprises are realising that Datrium software offers them a simpler path.”

The data centre landscape continues to change. Hyperscalers are ruling the roost, with capex continuing to rise. Cloud leads the way – Cisco said in February that cloud traffic will represent 95% of total data centre traffic by 2021 – so it’s a race against time for organisations trying to build through their legacy stacks with one hand while driving towards cloud with the other.

Total funding for Datrium now stands at $170 million.

Puppet State of DevOps 2018: DevOps continues to evolve – but resist temptation to skip steps

There are many paths to success in DevOps, but many more which lead to failure – so it’s important to get the evolution right.

That’s the key finding from Puppet’s recently released 2018 State of DevOps report. The study, which quizzed more than 3,000 global technology professionals, argues there are five key stages for good DevOps practices; having built the foundation, normalise the technology stack, standardise and reduce variability, before expanding DevOps practices, automating infrastructure delivery, and provide self-service capabilities.

Sounds simple, doesn’t it? Yet comparatively few of the companies surveyed were hitting the heights of DevOps-friendliness. The report’s results were based on organisations’ responses to various practices, scored between one and five. These were then grouped into low, medium and highly evolved. Four in five (79%) respondents were categorised as medium, with low and high (10% and 11% respectively) on similar levels.

Despite the desire to get to a higher level of DevOps zen, it is a slow evolutionary process. For the majority of companies polled, in the medium bracket, 14% said they had strong DevOps culture across multiple departments or across a single department. For higher level players, these numbers change to 19% and 9%.

It’s a similar process with automation – indeed, the same number of low-level and high-level companies surveyed (8%) said most of their services were available via self-service. Yet while only 15% of low players said their teams collaborated to automate services for broad use, this number rises for higher players to 37%. “Past experience has shown us that the path from a low degree of IT automation to a high degree isn’t neat or linear,” the report notes.

The report argues that automation is a reasonable yardstick on the CAMS – culture, automation, measurement and sharing – DevOps framework model as it is easily understood by the technical side and has a relatively predictable path. Culture, meanwhile, is more difficult to pin down.

Assuming the foundations have been built around setting company culture, automation et al, step one for teams looking to drive DevOps forward is to reduce the complexity of their tech stack. This means, for new projects, building on set standards, as well as making source code available to other teams. Standardisation follows, which again advocates building on a standard set of technology, as well as a standard operating system, while expansion explores reusing deployment patterns for building apps and services.

The report advises against skipping a few of the earlier steps. “Anecdotally speaking, we have seen organisations start with stage four automation, without having been through normalisation, standardisation and expansion,” it explains. “These organisations do not achieve success – and we believe it’s because they lack a foundation of collaboration and sharing across team boundaries.

“That sharing is critical to defining the problems an organisation faces and coming up with solutions that work for all teams.”

Ultimately, it’s about working at one’s own pace, and getting the building blocks firmly in place for many organisations reading the report.

“While DevOps practices have become far more well known across our industry, organisations continue to struggle to scale pockets of DevOps success more broadly across multiple teams and departments,” said Nigel Kersten, Puppet VP of ecosystem engineering. “This year’s report explores the foundational practices that need to be in place in order to scale DevOps success, and proves that success can only scale when teams are enabled to work across functional boundaries.”

You can read the full report here (email required).

Azure post-mortems, RTOs and RPOs – and what to do with Hurricane Florence on the horizon

The first official post-mortems are starting to come out of Microsoft in regards to the Azure outage that happened last week. While this first post-mortem addresses the Azure DevOps outage specifically (previously known as Visual Studio Team Service, or VSTS), it gives us some additional insight into the breadth and depth of the outage, confirms the cause of the outage, and gives us some insight into the challenges Microsoft faced in getting things back online quickly. It also hints at some some features/functionality Microsoft may consider pursuing to handle this situation better in the future.

As I mentioned in my previous article, features such as the new Availability Zones being rolled out in Azure, might have minimized the impact of this outage. In the post-mortem, Microsoft confirms what I previously said.

The primary solution we are pursuing to improve handling datacenter failures is Availability Zones, and we are exploring the feasibility of asynchronous replication.

Until Availability Zones are rolled out across more regions the only disaster recovery options you have are cross-region, hybrid-cloud or even cross-cloud asynchronous replication. Software based #SANless clustering solutions available today will enable such configurations, providing a very robust RTO and RPO, even when replicating great distances.

When you use SaaS/PaaS solutions you are really depending on the Cloud Service Provider (CSPs) to have an iron clad HA/DR solution in place. In this case, it seems as if a pretty significant deficiency was exposed and we can only hope that it leads all CSPs to take a hard look at their SaaS/PaaS offerings and address any HA/DR gaps that might exist. Until then, it is incumbent upon the consumer to understand the risks and do what they can to mitigate the risks of extended outages, or just choose not to use PaaS/SaaS until the risks are addressed.

The post-mortem really gets to the root of the issue…what do you value more, RTO or RPO?

I fundamentally do not want to decide for customers whether or not to accept data loss. I’ve had customers tell me they would take data loss to get a large team productive again quickly, and other customers have told me they do not want any data loss and would wait on recovery for however long that took.

It will be impossible for a CSP to make that decision for a customer. I can’t see a CSP ever deciding to lose customer data, unless the original data is just completely lost and unrecoverable. In that case, a near real-time async replica is about as good as you are going to get in terms of RPO in an unexpected failure.

However, was this outage really unexpected and without warning? Modern satellite imagery and improvements in weather forecasting probably gave fair warning that there was going to be significant weather related events in the area.

With hurricane Florence bearing down on the Southeast US as I write this post, I certainly hope if your data center is in the path of the hurricane you are taking proactive measures to gracefully move your workloads out of the impacted region. The benefit of a proactive disaster recovery vs a reactive disaster recovery are numerous, including no data loss, ample time to address unexpected issues, and managing human resources such that employees can worry about taking care of their families, rather than spending the night at a keyboard trying to put the pieces back together again.

Again, enacting a proactive disaster recovery would be a hard decision for a CSP to make on behalf of all their customers, as planned migrations across regions will incur some amount of downtime. This decision will have to be put in the hands of the customer.

Hurricane Florence Satellite Image taken from the new GOES-16 Satellite, courtesy of Tropical Tidbits

So what can you do to protect your business critical applications and data? As I discussed in my previous article, cross-region, cross-cloud or hybrid-cloud models with software based #SANless cluster solutions are going to go a long way to address your HA/DR concerns, with an excellent RTO and RPO for cloud based IaaS deployments. Instead of application specific solutions, software based, block level volume replication solutions such SIOS DataKeeper and SIOS Protection Suite replicate all data, providing a data protection solution for both Linux and Windows platforms.

My oldest son just started his undergrad degree in Meteorology at Rutgers University. Can you imagine a day when artificial intelligence (AI) and machine learning (ML) will be used to consume weather related data from NOAA to trigger a planned disaster recovery migration, two days before the storm strikes? I think I just found a perfect topic for his Master’s thesis. Or better yet, have him and his smart friends at the WeatherWatcher LLC get funding for a tech startup that applies AI and ML to weather related data to control proactive disaster recovery events.

I think we are just at the cusp of  IT analytics solutions that apply advanced machine-learning technology to cut the time and effort you need to ensure delivery of your critical application services. SIOS iQ is one of the solutions leading the way in that field.

Batten down the hatches and get ready, Hurricane season is just starting and we are already in for a wild ride.

Apple’s Event 2018: iPhones, iPhones, & one more iPhone.

Grab your black turtlenecks, hotspots, and cold brew because I’m covering the latest Apple event. Our setting is the gorgeous Steve Jobs Theater, named after the co-founder and former CEO of Apple, the is located on the Apple Park Campus in Cupertino, California. It is an underground, 1,000-seat auditorium intended for Apple product launches and […]

The post Apple’s Event 2018: iPhones, iPhones, & one more iPhone. appeared first on Parallels Blog.

Meet Parallels at the Insight Technology Conference

Guest blog post by Ian Appleby, Northern Europe Territory Manager, Cross Platform Solutions at Parallels Over the many years I’ve worked in and around IT in the UK and Europe, I’ve attended a huge number of events of varying quality. Quite rightly, many of these events are now consigned to history. You know the ones I […]

The post Meet Parallels at the Insight Technology Conference appeared first on Parallels Blog.

Data centre infrastructure figures continue to rise – driven by public cloud and enterprise servers

As cloud usage continues to skyrocket, getting prime data centre real estate is a bigger priority than ever. According to the latest figures from analyst firm Synergy Research, over the past two years quarterly spend on data centre hardware and software has grown by 28%.

Total data centre infrastructure equipment revenues, taking into account cloud, non-cloud, hardware and software, hit $38 billion in the second quarter of 2018. Public cloud has gone up 54%, with private cloud going up 45% and the traditional non-cloud base declining 3%.

Original design manufacturers (ODMs) lead the way in the public cloud space, which may not come as much of a surprise. As this publication – and indeed, Synergy – has frequently reported, capital expenditure of the hyperscalers in public cloud continues to rise, building out their data centre empires and speculating to keep accumulating. Aside from the ODMs, Dell EMC leads Cisco and HPE in the public cloud market.

For private cloud, Dell EMC is again on top – the company leads in both server and storage revenues – ahead of Microsoft, HPE and Cisco, while Microsoft leads the declining non-cloud market, ahead of Dell EMC, HPE and Cisco in that order.

“We are seeing cloud service revenues continuing to grow by 50% per year, enterprise SaaS revenues growing by over 30%, search [and] social networking revenues growing by over 25%, and eCommerce revenues growing by over 40%, all of which are driving big increases in spending on public cloud infrastructure,” said John Dinsdale, a chief analyst at Synergy. “That is not a new phenomenon.

“But what has been different over the last three quarters is that enterprise spending on data centre infrastructure has really jumped, driven primarily by hybrid cloud requirements, increased server functionality and higher component costs.”

Microsoft digs down on Azure outage, explores data loss and failover question

Microsoft has put together a post-mortem on what it described as an 'unprecedented' Azure outage – exploring an interesting question of data loss and failover capability.

The outage, which affected customers on the VSTS – or Azure DevOps – service in the South Central US region, required more than 21 hours to recover all facilities, as well as an additional incident regarding a database which went offline taking another two hours to resolve.

As the status page – which originally went down with the rest of the service – noted at the time, the cause was blamed on high storms in the Texas area. With the power swells that resulted, the data centres were able to maintain temperature through a thermal buffer – but when that was depleted, automated shutdown took place after temperatures exceeded safe levels.

At the time, users queried Microsoft's claims that South Central US was the only region affected – but as the company explained, customers globally were affected due to cross-service dependencies.

Writing in a blog post, Buck Hodges, director of engineering for Azure DevOps, apologised to customers and said the company was exploring the feasibility of asynchronous replication. With asynchronous replication, data which did not have time to be copied across the network on the second server is lost if the first server fails. As Hodges explained: "If the asynchronous copy is fast, then under normal conditions, the effect is essentially the same as synchronous replication." Synchronous replication, where data loss is less of an issue, has problems particularly across regions, Hodges added, as the time it takes does not equate to performance, particularly across mission-critical applications.

For the customers themselves, it's not an either-or question. Hodges said that some customers would be happy to take a certain loss of data if it meant getting a large team up and running again, while others would prefer to wait for a full recovery however long it took.

"The only way to satisfy both is to provide customers the ability to choose to fail over their organisations in the event of a region being unavailable," Hodges wrote. "We've started to explore how we might be able to give customers that choice, including an indication of whether the secondary is up to date and possibly provide manual reconciliation once the primary data centre recovers.

"This is really the key to whether or not we should implement asynchronous cross-region fail over," Hodges added. "Since it's something we've only begun to look into, it's too early to know if it will be feasible."

Regardless of the problems outages cause and the frustration they cause to users, whether they be down to natural causes or otherwise, it is interesting to see an introspective exploration from Microsoft here.

Why healthcare providers need Zero Trust Security to boost their digital initiatives

  • 58% of healthcare systems breach attempts involve inside actors, which makes this the leading industry for insider threats today.
  • Ransomware leads all malicious code categories, responsible for 70% of breach attempt incidents.
  • Stealing laptops from medical professionals’ cars to obtain privileged access credentials to gain access and install malware on healthcare networks, exfiltrate valuable data or sabotage systems and applications are all common breach strategies.

These and many other fascinating insights are from Verizon’s 2018 Protected Health Information Data Breach Report (PHIDBR). A copy of the study is available for download here (PDF, 20 pp., no opt-in).  The study is based on 1,368 incidents across 27 countries. Healthcare medical records were the focus of breaches, and the data victims were patients and their medical histories, treatment plans, and identities. The data comprising the report is a subset of Verizon’s Annual Data Breach Investigations Report (DBIR) and spans 2016 and 2017.

Why healthcare needs Zero Trust Security to grow

One of the most compelling insights from the Verizon PHIDBR study is how quickly healthcare is becoming a digitally driven business with strong growth potential. What’s holding its growth back, however, is how porous healthcare digital security is. 66% of internal and external actors are abusing privileged access credentials to access databases and exfiltrate proprietary information, and 58% of breach attempts involve internal actors.

Solving the security challenges healthcare providers face is going to fuel faster growth. Digitally-enabled healthcare providers and fast-growing digital businesses in other industries are standardizing on Zero Trust Security (ZTS), which aims to protect every internal and external endpoint and attack surface. ZTS is based on four pillars, which include verifying the identity of every user, validating every device, limiting access and privilege, and learning and adapting using machine learning to analyze user behavior and gain greater insights from analytics.

Identities need to be every healthcare providers’ new security perimeter

ZTS starts by defining a digital business’ security perimeter as every employees’ and patients’ identity, regardless of their location. Every login attempt, resource request, device operating system, and many other variables are analyzed using machine learning algorithms in real time to produce a risk score, which is used to empower Next-Gen Access (NGA).

The higher the risk score, the more authentication is required before providing access. Multi-Factor Authentication (MFA) is required first, and if a login attempt doesn’t pass, additional screening is requested up to shutting off an account’s access.

NGA is proving to be an effective strategy for thwarting stolen and sold healthcare provider’s privileged access credentials from gaining access to networks and systems, combining Identity-as-a-Service (IDaaS), Enterprise Mobility Management (EMM) and Privileged Access Management (PAM). Centrify is one of the leaders in this field, with expertise in the healthcare industry.

NGA can also assure healthcare providers’ privileged access credentials don’t make the best seller list on the Dark Web. Another recent study from Accenture titled, “Losing the Cyber Culture War in Healthcare: Accenture 2018 Healthcare Workforce Survey on Cybersecurity” found that 18% of healthcare employees are willing to sell confidential data to unauthorized parties for as little as $500 to $1,000. 24% of employees know of someone who has sold privileged credentials to outsiders, according to the survey. By verifying every login attempt from any location, NGA can thwart the many privilege access credentials for sale on the Dark Web.

The following are the key takeaways from Verizon’s 2018 Protected Health Information Data Breach Report (PHIDBR):

58% of healthcare security breach attempts involve inside actors, which makes it the leading industry for insider threats today

External actors are attempting 42% of healthcare breaches. Inside actors rely on their privileged access credentials or steal them from fellow employees to launch breaches the majority of the time. By utilizing NGA, healthcare providers can get this epidemic of internal security breaches under control by forcing verification for every access request, anywhere, on a 24/7 basis.

Most healthcare breaches are motivated by financial gain, with healthcare workers most often using patient data to commit tax return and credit fraud

Verizon found 876 total breach incidents initiated by healthcare insiders in 2017, leading all categories. External actors initiated 523 breach incidents, while partners initiated 109 breach incidents. 496 of all breach attempts are motivated by financial gain across internal, external and partner actors. Internal actors are known for attempting breaches for fun and curiosity-driven by interest in celebrities’ health histories that are accessible from the systems they use daily. When internal actors are collaborating with external actors and partners for financial gain and accessing confidential health records of patients, it’s time for healthcare providers to take a more aggressive stance on securing patient records with a Zero Trust approach.

Abusing privileged access credentials (66%) and abusing credentials and physical access points (17%) to gain unauthorized access comprise 82.9% of all misuse-based breach attempts and incidents

Verizon’s study accentuates that misuse of credentials and the breaching of physical access points with little or no security is intentional, deliberate and driven by financial gain the majority of the time. Internal, external and partner actors acting alone or in collaboration with each other know the easiest attack surface to exploit are accessed credentials, with database access being the goal half of the time. When there’s little to no protection on web application and payment card access points to a network, breaches happen. Shutting down privilege abuse starts with a solid ZTS strategy based on NGA where every login attempt is verified before access is granted and anomalies trigger MFA and further user validation. Please click on the graphic to expand it for easier reading.

70.2% of all hacking attempts are based on stolen privileged access credentials (49.3%) combined with brute force to obtain credentials from POS terminals and controllers (20.9%)

Hackers devise ingenious ways of stealing privileged access credentials, even resorting to hacking a POS terminal or controllers to get them. Healthcare insiders also steal credentials to gain access to mainframes, servers, databases and internal systems. Verizon’s findings below are supported by Accenture’s research showing that 18% of healthcare employees are willing to sell privileged access credentials and confidential data to unauthorized parties for as little as $500 to $1,000. Please click on the graphic to expand it for easier reading.

Hospitals are most often targeted for breaches using privileged access credentials followed by ambulatory health care services, the latter of which is seen as the most penetrable business via hacking and brute force credential acquisition

Verizon compared breach incidents by North American Industry Classification System (NAICS) and found privileged credential misuse is flourishing in hospitals where inside and outside actors seek to access databases and web applications. Internal, external and partner actors are concentrating on hospitals due to the massive scale of sensitive data they can attain with stolen privileged access credentials and quickly sell them or profit from them through fraudulent means. Verizon also says a favorite hacking strategy is to use USB drives to exfiltrate proprietary information and sell it to health professionals intent on launching competing clinics and practices. Please click on the graphic to expand it for easier reading.

Conclusion

With the same intensity they invest in returning patients to health, healthcare providers need to strengthen their digital security, and Zero Trust Security is the best place to start. ZTS begins with Next-Gen Access by not trusting a single device, login attempt, or privileged access credential for every attack surface protected. Every device’s login attempt, resource request, and access credentials are verified through NGA, thwarting the rampant misuse and hacking based on comprised privileged access credentials. The bottom line is, it’s time for healthcare providers to get in better security shape by adopting a Zero Trust approach.

The cloud news categorized.