Orange acquires Basefarm to boost European cloud services


Clare Hopping

17 Jul, 2018

Orange has taken a huge step in the business cloud market, acquiring cloud infrastructure and critical application services firm Basefarm to help grow its Orange Business Services division.

While Orange is a strong cloud player in France, it’s looking to diversify the services it provides across Europe, strengthening its hold on the cloud sector.

Basefarm already has a strong presence within Europe, particularly Norway, Sweden, the Netherlands, Austria and Germany, where it offers a range of cloud-based infrastructure and services, management of critical applications and analytics to help businesses get more insight from their usage data. 

“We are very proud to announce the acquisition of Basefarm, which will mark a major milestone in our international development,” Helmut Reisinger, CEO of Orange Business Services, said. “In particular, the company’s integration will enable us to significantly extend our big data and critical application management services on a rapidly consolidating market.

“In addition to our ability to offer access to public or private cloud infrastructure, it is above all our capacity to propose enriched, automated services to our customers, wherever they are in the world, that will enable us to support companies as they transform onto new, digital models based on cloud computing, big data and artificial intelligence.”

The company hasn’t yet announced whether all 550 of Basearm’s staff will join the 1,600 cloud computing experts at Orange Business Services or whether there will be redundancies. But Orange did explain the acquisition will give Basearm the opportunity to develop its products under the Orange umbrella, focusing on data management, big data and multi-cloud services.

The deal is worth 350 million (£310 million) and is due to complete in the third quarter of this year.

Picture: Bigstock

Is AWS about to start selling network switches?


Clare Hopping

17 Jul, 2018

Amazon Web Services (AWS) could be about to break into the world of data centre switches, helping to boost its presence across the entire cloud infrastructure space.

The public cloud giant reportedly wants a piece of the $14 billion switches pie, taking aim at the business networking market. This would put the company up against hardware bigwigs like Cisco, Arista Networks and Juniper Networks, who currently hold the largest market shares in the sector.

A person with direct knowledge of the cloud unit’s plans, and another source briefed on the project, told The Information that what’s key about AWS’s strategy is that it plans to undercut its mainstream competitors, pricing its switches at 70%-80% less than Cisco’s products.

This could mean serious problems for the networking vendor, especially as AWS’s switches would reportedly link seamlessly with AWS’s cloud services, providing a connection between on-premise networks and the company’s cloud services, sending AWS down a hybrid cloud route – something it’s only begun to embrace.

AWS has actually been making switches for its own data centres for some time. This news, if true, just means it would sell them to provide an extra revenue stream outside of its core cloud services.

The switches would comprise open source software and unbranded hardware, although one source said AWS is working with hardware manufacturers including Celestica, Edgecore Networks and Delta Networks to mass produce its white boxes.

The company is currently testing its innovations with a handful of loyal customers and if a hybrid cloud approach works for them, then it’s likely other won’t have to wait too long until they launch onto the open market.

Anne Hungate Joins @DevOpsSUMMIT NY Faculty | @AnneHungate #DevOps #Monitoring #Microservices #ContinuousDelivery

IT organizations that don’t know their risk factors and exposure are likely to make investments in DevOps that don’t matter. After working with several teams that lost their DevOps funding after making automation investments in areas that were not business constraints, Anne Hungate’s “Know Your Numbers” model emerged. Join Anne to learn how to prioritize your DevOps improvements and demonstrate the impact and value you are delivering. After all, DevOps gets traction and funding when teams can show the business impact of doing it, so if you want your DevOps initiative to take off, be prepared to provide some metrics! You’ll discover the five key questions you need to be able to answer to show that your DevOps matters, and leave with seven actions you can start taking as soon as you get back to your desk in order to improve the results of your DevOps efforts.

read more

Torin Sandall Joins @DevOpsSUMMIT NY Faculty | @SomeTorin @OpenPolicyAgent #DevOps #Monitoring #ContinuousDelivery

Authorization of web applications developed in the cloud is a fundamental problem for security, yet companies often build solutions from scratch, which is error prone and impedes time to market. This talk shows developers how they can (instead) build on-top of community-owned projects and frameworks for better security.Whether you build software for enterprises, mobile, or internal microservices, security is important. Standards like SAML, OIDC, and SPIFFE help you solve identity and authentication, but for them authorization is out of scope. When you need to control “who can do what” in your app, you are on your own.

read more

Mike Kavis Joins @DevOpsSUMMIT NY Faculty | @MadGreek65 @Deloitte #AI #IoT #DevOps #Monitoring #SmartCities

Mike is managing director in Deloitte Consulting LLP’s Cloud practice, responsible for helping clients implement cloud strategy and architecture to drive digital transformation. Beyond his technology experience, Mike brings an insightful understanding of how to address the organizational change, process improvement, and talent management challenges associated with digital transformation. Mike brings more than 30 years of experience in software development and architecture to his role. Most recently, he was a principal architect with Cloud Technology Partners. A pioneer in cloud computing, Mike led a team that built the world’s first high-speed transaction network in Amazon’s public cloud and won the 2010 AWS Global Startup Challenge. He has written extensively about cloud technologies and the Internet of Things.

read more

Seven ways to test your online security


Robert Irvine

19 Jul, 2018

You may have all the latest security tools installed, you may follow best practice and avoid suspect emails, and you may never reuse the same password twice, yet there can always be a chink in your cyber security armour.

Sometimes this can be something simple, such as failing to update software, or more intricate, like an open port on your network. Fortunately, there are free tools available online that can deep dive into your defences to see just how robust they are.

The problem is knowing exactly where to go and who to trust – so we put together a list of the some of the best tools and scanners out there to make things easier.

Check if your accounts have been breached

If you suspect you may have fallen victim to a hack, visit Have I Been Pwned? which catalogues all the email addresses and other data taken in high-profile breaches.

Search for your address, and if it’s found in the data dumps, a red warning will appear, revealing what was taken in the hack and recommending you change your password(s) immediately. You can also sign up for notifications of future breaches. At the time of writing, Have I Been Pwned? featured more than 4.7 million ‘pwned’ accounts and 232 ‘pwned’ websites, including MySpace, Adobe and LinkedIn.

Test the strength of your passwords

There are lots of online tools that test the strength of your passwords, but make sure you use one that encrypts what you enter or you could actually be risking your security.

Our favourite it the Dashlane-sponsored How Secure Is My Password, which tells you how long your password would take a hacker to crack. If the answer is only seconds or minutes, you should change the password as soon as possible.

Ensure your security software is working

Don’t let malware infection be the first sign of a security hole The Anti-Malware Testing Standards Organization (AMTSO) offers a Security Features Check that exposes potential weaknesses in your system’s defences.

The check consists of six tests, four of which involve downloading files that your PC should identify as malware and block automatically. These files aren’t actually malicious but are designed to be detected as such, so if your anti-malware program lets one through, then you need to tighten your settings.

Test your firewall for weaknesses

Firewalls generally run quietly in the background, so it’s important to know that they’re working properly. To test yours, try to bypass it using the free online port scanner GRC ShieldsUP.

Ports should be closed by default aside from port 80 (or 443), which is needed for web traffic. You can choose to test either Common Ports (only the most vulnerable ports) or All Service Ports (a thorough scan of 1,056 ports). Green or blue results mean that those ports are secure, while red ones show open ports that need to be closed.

Ensure your plugins are up-to-date

Security holes in Java, Adobe Reader and Flash put your personal data at risk, so ensure your plugins are up to date using Qualys BrowserCheck. This scans your browser and its plug-ins to detect outdated versions and other security problems. Click the Fix It button next to scan results marked as ‘insecure version’ or ‘update available’ to install the required updates. The test works with all major browsers.

Check your Facebook security

Facebook now offers a Security Checkup tool that lets you review and lock down your account. Go here and Facebook will tell you whether you’re still logged into the social network in a browser or app you haven’t used for over a month. You can also set up login alerts to be notified via email when if your account is accessed from an unrecognised device or browser.

Test your own security knowledge

Avoid being the weak link in your PC’s protection by keeping your security knowledge up to scratch. There are lots of online quizzes that test your ability to spot online threats, including BT’s Security Savvy test and the OpenDNS Phishing Quiz.

Image: Shutterstock

Netskope acquires Sift Security for next generation IaaS tools

Netskope is looking to the next generation of cloud security with the acquisition of Sift Security.

The acquisition, which closed in June, will see Sift's infrastructure as a service (IaaS) breach detection and visualisation tool Cloud Hunter move into Netskope's Security Cloud offering.

"By bringing Sift Security into our 'one cloud' architecture, we will take Netskope for IaaS (and as a result, the entire Netskope Security Cloud) to a new level," wrote Sanjay Beri, Netskope CEO, in a blog post confirming the news. "Sift enhances our ability to uniquely gather and visualise the richest set of contextualised data about transactions. This rich contextual data informs nearly all of the services provided by the Netskope Security Cloud.

"Sift Security helped pioneer this for IaaS by ingesting and creating a rich set of data from public cloud infrastructure," added Beri. "This data, which ranges from information around the OS to the networking to the application and user level, enables Sift to correlate, visualise, detect, and remediate threats and incidents in IaaS services."

Neil King, CEO of Sift, will join Netskope's IaaS division to lead product strategy and management. "Four years ago we set out to build a security solution that could detect, correlate, visualise and automatically respond to threats in infrastructure as a service environments like AWS, Azure, and Google Cloud Platform," said King. "We're excited to combine those capabilities into the market-leading Netskope Security Cloud."

The move puts more emphasis on the key trend of automated cloud security tools. While the concept has been around for some time, increasingly complex cloud workloads has made the need for automated 'threat hunting' tools more evident. As a McAfee report put it in April, it's all about visibility and control for admins.

While Netskope is beefing up its cloud and IaaS security credentials with the acquisition of Sift,  the company's ambitions are much wider. As this publication reported last year when Netskope secured a $100 million series E funding round, the next step was to take the cloud platform and bring it to the whole web.

Financial terms of the transaction were not disclosed.

How cryptomining is the attack vector du jour – as hackers increasingly target cloud infrastructure

Cryptojacking is on the way to replacing ransomware as the biggest threat for consumers and enterprises – and new research reveals the size of the effect crypto is having on cloud infrastructures.

Cybersecurity firm Check Point Software, in its 'Cyber Attack Trends: 2018 Mid-Year Report', found that in the first half of this year, the number of organisations impacted by cryptomining malware doubled to 42%, compared with 20.5% from the second half of 2017.

What's more, the top three most common malware variants in the first half of this year were all cryptominers. At the most recent RSA Conference, the SANS Institute presented its list of the five newest dangerous attack vectors; cloud storage, and data leakage and monetisation of compromised systems via cryptominers both made the list.

The report asserts that 'a number of sophisticated techniques and tools' have been deployed against cloud storage services. Many of these attacks come about due to organisations' own poor security practices, but others, such as cryptomining, are leveraging cloud infrastructure leading to much greater profits for threat actors.

There have been examples of the latter this year. In February, security monitoring firm RedLock disclosed that hackers had been running cryptomining scripts on unsecured Kubernetes instances owned by Tesla. As the researchers put it at the time, the focus has changed from stealing data to stealing compute power in organisations' public cloud environments.

The top cryptominers are Coinhive, which has affected 12% of organisations worldwide, Cryptoloot, a JavaScript miner, and JSEcoin, a web-based crypto miner. All three are focused around mining the Monero cryptocurrency.

Maya Horowitz, threat intelligence group manager at Check Point, noted that attacks on cloud infrastructure and cryptomining were the latest generation of cyber attacks, which the company calls 'gen V.' "These multi-vector, fast-moving, large scale Gen V attacks are becoming more and more frequent, and organisations need to adopt a multi-layered cybersecurity strategy that prevents these attacks from taking hold of their networks and data," said Horowitz.

Writing for this publication in May, Paolo Passeri, cyber intelligence principal at Netskope, said that while cryptomining campaigns were becoming bigger and more persistent, organisations could mitigate risk by using several methods. Companies could enforce policies such as scanning all uploads from unmanaged and remote devices to sanctioned cloud applications, to blocking unsanctioned instances of sanctioned cloud apps.

You can read the full report here (email required).

Announcing @DevOpsINST Two-Day Certification Course at @DevOpsSUMMIT NY | #Agile #DevOps #ContinuousDelivery

This sixteen (16) hour course provides an introduction to DevOps, the cultural and professional movement that stresses communication, collaboration, integration and automation in order to improve the flow of work between software developers and IT operations professionals. Improved workflows will result in an improved ability to design, develop, deploy and operate software and services faster.

read more

Why enterprises feel more susceptible to threats than ever before

  • Identities, not systems, are the new security perimeter for any digital business, with 81% of breaches involving weak, default or stolen passwords.
  • 53% of enterprises feel they are more susceptible to threats since 2015.
  • 51% of enterprises suffered at least one breach in the past 12 months and malicious insider incidents increased 11% year-over-year.

These and many other fascinating insights are from SecurIT: the Zero Trust Summit for CIOs and CISOs held last month in San Francisco, CA. CIO and CSO produced the event that included informative discussions and panels on how enterprises are adopting Next-Gen Access (NGA) and enabling Zero Trust Security (ZTS). What made the event noteworthy were the insights gained from presentations and panels where senior IT executives from Akamai, Centrify, Cisco, Cylance, EdgeWise, Fortinet, Intel, Live Nation Entertainment and YapStone shared their key insights and lessons learned from implementing Zero Trust Security.

Zero Trust is a recognized framework developed by Forrester Research in collaboration with the National Institute of Standards and Technology (NIST) and also promoted by Google as BeyondCorp. Zero Trust Security is predicated on the concept that an organization doesn’t trust anything inside or outside its boundaries and instead verifies anything and everything before granting access. The approach works because today’s leading attack vector is weak or compromised credentials according to Verizon’s 2018 Data Breach Investigations Report.

Key takeaways from the Zero Trust Summit include the following:

Identities, not systems, are the new security perimeter for any digital business, with 81% of breaches involving weak, default or stolen passwords

Tom Kemp, Co-Founder, and CEO, Centrify, provided key insights into the current state of enterprise IT security and how existing methods aren’t scaling completely enough to protect every application, endpoint, and infrastructure of any digital business. He illustrated how $86B was spent on cybersecurity, yet a stunning 66% of companies were still breached. Companies targeted for breaches averaged five or more separate breaches already. The following graphic underscores how identities are the new enterprise perimeter, making NGA and ZTS a must-have for any digital business.

53% of enterprises feel they are more susceptible to threats since 2015

Chase Cunningham’s presentation, Zero Trust and Why Does It Matter, provided insights into the threat landscape and a thorough definition of ZTX, which is the application of a Zero Trust framework to an enterprise. Dr. Cunningham is a Principal Analyst at Forrester Research serving security and risk professionals. Forrester found the percentage of enterprises who feel they are more susceptible to threats nearly doubled in two years, jumping from 28% in 2015 to 53% in 2017. Dr. Cunningham provided examples of how breaches have immediate financial implications on the market value of any business with specific focus on the Equifax breach.

Presented by Dr. Cunningham during SecurIT: the Zero Trust Summit for CIOs and CISOs

51% of enterprises suffered at least one breach in the past 12 months and malicious insider incidents increased 11% year-over-year

43% of confirmed breaches in the last 12 months are from an external attack, 24% from internal attacks, 17% are from third-party incidents and 16% from lost or stolen assets. Consistent with Verizon’s 2018 Data Breach Investigations Report use of privileged credential access is a leading cause of breaches today.

Presented by Dr. Cunningham during SecurIT: the Zero Trust Summit for CIOs and CISOs

One of Zero Trust Security’s innate strengths is the ability to flex and protect the perimeter of any growing digital business at the individual level, encompassing workforce, customers, and distributors

Akamai, Cisco, EdgeWise, Fortinet, Intel, Live Nation Entertainment and YapStone each provided examples of how their organizations are relying on NGA to enable ZTS enterprise-wide. Every speaker provided examples of how ZTS delivers several key benefits including the following: First, ZTS reduces the time to breach detection and improves visibility throughout a network. Second, organizations provided examples of how ZTS is reducing capital and operational expenses for security, in addition to reducing the scope and cost of compliance initiatives. All companies presenting at the conference provided examples of how ZTS is enabling greater data awareness and insight, eliminating inter-silo finger-pointing over security responsibilities and for several, enabling digital business transformation. Every organization is also seeing ZTS thwart the exfiltration and destruction of their data.

Conclusion

The SecurIT: the Zero Trust Summit for CIOs and CISOs event encapsulated the latest advances in how NGA is enabling ZTS by having enterprises who are adopting the framework share their insights and lessons learned. It’s fascinating to see how Akamai, Cisco, Intel, Live Nation Entertainment, YapStone, and others are tailoring ZTS to their specific customer-driven goals. Each also shared their plans for growth and how security in general and NGA and ZTS specifically are protecting customer and company data to ensure growth continues, uninterrupted.

The cloud news categorized.