The compliance conundrum: Why hybrid cloud is key with GDPR around the corner

With the Global Data Protection Regulation (GDPR) on the horizon, businesses that wish to operate in the European Union are having to spend more time than ever thinking about compliance.

Not only does all personally identifiable customer data need to be accounted for – a task that is easier said than done for many organisations – internal processes also have to be updated and employees need to be educated to ensure the compliance deadline of May 25 2018 is met.

Of course, GDPR is just one legislative challenge facing businesses. Financial services firms, for example, have a revamped version of the Markets in Financial Instruments Directive (also known as MiFID II) to respond to, while the UK telco industry is facing the prospect of new legislations being enforced after Brexit.

And as falling foul of industry regulations has the potential to result in massive financial penalties, as well as the threats of reputational damage and a loss of customers, organisations simply can’t afford to be complacent.

However, fear of the complexity of managing compliance in new infrastructure as well as the effort already involved in ensuring existing systems are ready to go, is prompting many businesses to shy away from cloud, despite the many benefits such services offer. Concerns are primarily due to a misconception that cloud platforms, with data held by third parties on shared systems, will be a more difficult undertaking than traditional in-house systems and potentially less secure, but the truth is very different.

Public cloud services can be extremely secure and often can be a more secure option than in-house systems. So, what exactly is behind this misconception and why should businesses be trusting public cloud services with their compliance needs?

Privacy please

On the face of things, it’s easy to see why many people would assume on-premise infrastructure is more secure and easy to manage. In theory, businesses know exactly where their data is being stored and who has access to it, both of which provide comfort for organisations.

They can also design the architecture to suit their own specific needs and preferences, as well as reducing the risk of data loss if a public cloud provider goes out of business. One could argue that such a setup would be particularly appealing to businesses operating in highly regulated industries, such as healthcare and financial services, which need to have greater visibility and control over how their data is managed.

However, firms would be wise to remember that operating their own private cloud places the responsibility of security and compliance squarely on their shoulders. Businesses are at the mercy of the whims of nature and the resilience of their local power grid, potentially leaving them helpless if something goes wrong.

It also leaves them vulnerable to disgruntled employees and internal data theft. Employees may have easy access to confidential data, sometimes with very little to stop them from stealing corporate information simply by pulling a disk from a server and leaving the building with it. Often employees can also connect USB drives which have been used in home systems and may contain malware or viruses. Huge faith is placed in the firewall as an effective means of keeping intruders out, yet backdoors may well exist in the form of legacy and unsecured modem connections, as well as poor access control processes that leave user credentials in place long after the relevant employee has left the company.

So just because infrastructure is in your data centre doesn’t mean it is inherently more secure, resilient or suitable to meet the needs of regulatory compliance than public cloud.

Going public

While some businesses may feel more comfortable knowing their data is being stored within their own walls, data location is only one small aspect of security and compliance.

Along with the provision of innovative new services to enable business growth, it is the job of public cloud providers to protect their customer’s data. A central component of their value proposition, therefore, is the delivery of systems, tools and continuity plans that make their cloud infrastructure safe and secure.

This applies to both virtual and physical means of protection. Corporate data will be stored in a secure facility with multiple layers of physical security that are often not present if businesses opt to run their cloud infrastructure in-house.

And, with competition in the market continuing to increase at a rapid rate, ensuring compliance is not only a valuable competitive advantage for those businesses offering public cloud services, but also essential to gaining customer trust and in turn, loyalty. In this respect, smart cloud providers such as City Cloud are leading the way with a value proposition focused very much around regulatory compliance

Public cloud providers are also likely to carry out software patching on a more regular basis which is essential to manage compliance. Businesses running their own private clouds will generally be slower to patch security gaps, leaving themselves exposed to potential data breaches and compliance holes. The recent Spectre and Meltdown vulnerabilities are a great example of this, with Google, Microsoft and Amazon all patching their system quickly after the problems became public. Meanwhile many businesses will still be trying to determine what systems they need to patch and how they go about doing it.

Furthermore, public cloud providers tend to have highly skilled and experienced IT teams, which isn’t something that can be said for all businesses. The skills gap issue is an extremely prevalent one in the cloud world and businesses are finding it harder than ever to attract talented developers. This is causing problems when it comes to addressing the more technical compliance challenges, which could be solved using third-party infrastructure.

Add in the fact that businesses will not be alone when defending against attacks and the skills argument provides compelling support for the merits of using third-party providers to ensure legislative compliance.

The combination of these factors means that in many cases public cloud can actually be a better option than a private cloud for systems with high security and compliance requirements. It can certainly be a less complicated option for businesses and help to give them peace of mind amidst shifting regulatory landscapes.

As end users become far more sensitive to security of their personal data and initiatives like Open Banking come into effect, the challenges are only going to grow. That’s why organisations today, rather than shying away from public infrastructure, should be embracing them as part of a hybrid cloud offering on their journey to compliance. 

Cisco announces intention to acquire Skyport Systems in hyperconverged play

Cisco has announced its intent to acquire Skyport Systems, a provider of hyperconverged infrastructure (HPI) and cloud-managed secure virtualisation.

The company, based out of Mountain View, has an offering which aims to converge security and infrastructure and be secure by design. The company claims its ‘continuously validated’ security platform enforces capabilities needed to avoid 85% of targeted cyber-attacks.

In a brief statement, Rob Salvagno, head of Cisco’s M&A and venture investment team, said the acquisition “will enable Cisco to utilise Skyport’s intellectual property, seasoned software and network expertise to accelerate priority areas across multiple Cisco portfolios.”

The move highlights the importance of venture capital arms within companies. Skyport has raised in total $67 million (£47m) in funding, with the most recent, a $30m series C in March 2016, involving Cisco Investments.

Cisco has been particularly busy on the acquisitions front, with the most recent of interest being the buying of Cmpute.io, a cloud application optimisation provider, in December. Among the company’s other acquisitions in 2017 were Viptela, a provider of SD-WAN technologies, and cloud collaboration software provider BroadSoft.

The Skyport team will join the data centre-computing systems product group, as well as the service provider-networking group at Cisco.

Financial details of the acquisition were not disclosed.

Parallels Mac Management: Prerequisites Checker Wizard

Every IT administrator who needs to deploy Parallels® Mac Management for Microsoft® SCCM for the first time faces a question: Is my Microsoft SCCM environment ready for Parallels Mac Management deployment? The Administrators’ Guide contains all the necessary information and requirements, but who reads documentation? Last December, we released Prerequisites Checker Wizard for Parallels Mac […]

The post Parallels Mac Management: Prerequisites Checker Wizard appeared first on Parallels Blog.

The future of careers in cloud computing – and the skills you need to have

The migration towards cloud computing in business has grown exponentially over the last 12 months, with new installation of public and private cloud network infrastructure becoming a key area of successful business operation.

Partnering this successful adoption of cloud technology is the positive development of both core and non-core careers in the sector, which in turn has led to an increased demand for skilled professionals and a boost in the number of available jobs.

We initially saw an increased demand for those skills that focused primarily on the implementation and support of cloud platforms such as Amazon Web Services (AWS), Microsoft Azure and Google Cloud.

Now, however, with protection against cyber security threats fast becoming a primary concern for businesses following the recent ransomware attacks, and the impending introduction of the General Data Protection Regulation (GDPR) in the EU also becoming a priority, the cloud computing sector has seen a major shift in the demand for non-core professionals such as cybersecurity.

These experts have a strong knowledge of security and specialise in cloud network protection, in particular, penetration testers or ethical hackers, who are tasked with ensuring the complete safety of a system and network infrastructure so it has the capability to withstand infiltration. These are the first line of defence against a cyber-attack.

Given the authorisation to simulate white hat attacks on a secure network or system, the role of a penetration tester or ethical hacker is to evaluate the security of a network and test for unknown vulnerabilities.

Utilising a targeted pen test strategy to legally break into a computer, each test will be formulated to replicate a specific type of already-known attack, and will focus on identifying, exploring, testing and exploiting the main access points to a network. If the performed tests do unearth a vulnerability, pen testers will then comb the remainder of the network and work with the rest of the security team to eliminate the vulnerability.

Our experience tells us that in one in five UK IT vacancies, candidates are expected to have some experience of cloud computing, with many also stipulating the need for knowledge of data protection and security.

In order to service our clients more effectively, particularly with regards to cloud vacancies, we created  FRG Technology Consulting, which is our cloud specific recruitment brand.

As it stands, the majority of cloud professionals are self-taught or have learnt their skills throughout their time in the industry, ultimately meaning they lack the necessary experience to perform the role of an ethical hacker. And while experience in another IT field can offer some career progression and fills the gaps created by the current skills shortage, it will only curb the pressure on the marketplace for a short period of time.

There has however been a shift towards a route of natural progression into cloud computing and cybersecurity careers, which will not only provide a secure future for careers in the sector but also offer a comfortable alleviation on the skills shortage, and that is through the university education.

Numerous universities across the UK have backed the trend of modern cloud computing by moving away from the generic computer science degrees and offering BSC and MSC qualifications specifically in cloud computing. Allowing graduates to find a career in Cloud Operations if they take a non-specialised route, many establishments also offer a specific Cyber Security degree where students are taught to become penetrations testers while also learning the fundamentals of network security and advanced information security techniques.

Over the next 12 months, the investment from businesses into the cloud and security infrastructure is expected to systematically increase to accommodate the number of cloud professionals needed to successfully cope with the internal adoption of cloud platforms, storage and infrastructure. These investments should theoretically secure the future of careers in the sector, particularly with the inundation of new graduates continually adding different expertise to the sector, and the evolution of the technology providing equally as many opportunities to find your ideal cloud computing career.

Cloud outages could cost US businesses $15 billion, says Lloyd’s of London

Here’s an interesting statistic to illustrate how much influence the major cloud providers have: according to Lloyd’s of London, US businesses could lose $15 billion if a leading vendor experienced downtime of at least three days.

According to the insurer, working in partnership with risk modelling firm AIR Worldwide in its ‘Cloud Down’ report, an ‘extreme cyber incident’ which took a top cloud provider offline for three to six days would also result in insured losses of $3bn alongside the $15bn economic losses.

Businesses outside of the Fortune 1000 – who the report argues are more likely to be users of cloud services – are as a result placed at a higher risk. The companies say these businesses would carry 63% share of economic losses and 57% of insured losses.

The report also assessed how different industries would be impacted. If a large cloud provider went down for days, manufacturing would bear the brunt, with direct economic losses of $8.6bn. This compares against wholesale and retail trade ($3.6bn), information sectors ($847 million), finance and insurance ($447m) and transportation and warehousing ($439m).

Cloud providers’ services can go down for various reasons; whether it is weather-related, bug-related, or simply a case of fat fingers. Earlier this month, a study from Syncsort found that a majority of organisations had to deploy their disaster recovery solution at least once in the past year, with many not sure as to the specifics of their availability plans.

“A major cloud failure would significantly impact the insurance industry, and our research has shown that such an event is plausible,” said Scott Stransky, assistant vice president and principal scientist at AIR Worldwide. “We hope the report will help raise awareness across the industry as to how significant losses could be, how likely they are, and provide an opportunity for insurers to better understand and manage cyber risk.”

You can find out more about the report here.

How to use the Alt key on a Mac keyboard

Windows vs Mac—there are so many differences. A lot of our customers have used a PC before and then decide they want to switch to Mac for better performance, nicer design, or for better security. However, they were afraid they would have a hard time getting used to the macOS keyboard. We hear questions like, […]

The post How to use the Alt key on a Mac keyboard appeared first on Parallels Blog.

Building blockchain application development expertise: A guide

A cryptocurrency is a digital asset designed to work as a medium of exchange that uses cryptography to secure its transactions, to control the creation of additional units, and to verify the transfer of assets. The quest to discover meaningful commercial applications for blockchain, beyond cryptography apps, has begun across the globe.

451 Research revealed that 28 percent of enterprises are now evaluating or using blockchain, although fewer than 3 percent have any production applications.

Blockchain market development

According to the study, 20 percent of organizations surveyed are using blockchain in a discovery or evaluation phase, 4 percent running trials or pilots, 2 percent in test and development environments, 2 percent undertaking initial implementations of production applications and less than 1 percent have broad implementation of production applications.

Furthermore, the market is rife with vendor misrepresentation about blockchain apps, and there is little understanding about how enterprise leaders can deploy blockchain profitably while navigating a market with thousands of vendors and hundreds of consortia vying for mind-share.

The 451 Research blockchain codex systematically decodes this market, pursuing the goal of replacing confusion and complexity with an examination of the technology components and guidance on first steps.

451 Research analysts believe blockchain has the potential to be the active ingredient for establishing universal trust among parties through clever code and peer-to-peer consensus.

In the enterprise sector, where smart contracts will dictate terms and cloud-tasking using multiple providers is the norm, there will be a need for transparency and an immutable system of record.

At the edge, IoT devices could take advantage of blockchain for authentication and to store and share interactions and data. Numerous other commercial applications will evolve over time.

"Blockchain will do for transactions what the Internet has done for information. It promises to disrupt business models and entire industries. It allows for increased trust and efficiency, and is pushing us to challenge how we define and exchange value and reward participation," said Csilla Zsigri, senior analyst at 451 Research.

Outlook for blockchain application development

With a scarcity of skills in blockchain technology and potential applications, there is a tremendous opportunity for third-party expertise that can help define and support proof of concepts and initial deployments.

More CIOs and CTOs seek information and guidance to gain an understanding of what blockchain is, how it works and how it can be applied in use cases. They're also eager to learn what those organizations and industries at the forefront of this nascent distributed ledger technology have accomplished, thus far.

Read more: IBM ends revenue decline, says it has strengthened cloud and blockchain leadership

Digital Realty to add direct access for Oracle cloud infrastructure across the US

Digital Realty has announced it will offer dedicated and private access to Oracle Cloud in 14 major metropolitan areas, boosting its relationship and connectivity with the Redwood giant.

According to the press materials, access to Oracle Cloud Infrastructure FastConnect – a product launched by Oracle in 2016 to help customers connect their data centre to the cloud more easily – will be made available through Digital Realty’s Service Exchange in Ashburn, Atlanta, Boston, Chicago, Dallas, London, Los Angeles, Miami, New York, Phoenix, Portland, San Francisco, Seattle, and Silicon Valley.

In total, 59 Digital Realty data centres support private connections to Oracle’s infrastructure as a service, the company added.

“Customers require seamless connectivity from their data centres and networks to Oracle Cloud for their most demanding workloads and applications,” said Don Johnson, Oracle Cloud Infrastructure senior vice president for product development. “With Oracle’s FastConnect service via Digital Realty, customers can provision the dedicated and private connections they need today and easily scale with their growing business demands.”

“Our direct connections to Oracle Cloud Infrastructure build upon our commitment to ensure that our customers have interconnected access to the critical IT resources they need to drive business success,” said Chris Sharp, Digital Realty CTO. “The rapid growth of Oracle Cloud is a testament to its strength in the marketplace, and we are extremely pleased to be working closely with Oracle to accelerate its momentum.”

According to figures from Synergy Research in June, Digital Realty and Equinix remain the primary players in the colocation market, extending their lead over the competition thanks to – in the former’s case – merging with DuPont Fabros. As for Oracle, the company posted strong financial results in mid-December, and boosted its Australian operations by announcing the acquisition of Aconex in the same week.

Why cloud storage, DRaaS, multi-cloud and data security will all be key cloud drivers in 2018

It's that time of year when industry commentators are weighing in with their predictions and projections for the year ahead.

While the subject of cloud computing is a big topic, probably one of the most pressing subjects hitting the headlines in 2018 is increasing regulations relating to GDPR.  However, there are a few other cloud-related topics that I would like to put the spotlight on as we look at the anticipated growth areas for cloud service providers in the year ahead. In particular, I’d like to focus on cloud storage, DRaaS, multi-cloud, and data security.

Growth of cloud storage

Cisco estimates that the total cloud storage market will increase from 370EB in 2017 to 1.1ZB in 2018 which reinforces that this will be a particular growth area for cloud service providers. Increased regulation has driven requirements for several copies of backup data – on-premises, off-site or in the cloud and in certain industries, legislation requires longer term retention of data, often up to 10 years.

According to a 2017 Gartner survey, 42% of respondents said they would be looking to implement cloud backup in the next year, while 13% said they were already doing so. Increased availability of high-speed fibre broadband, as well as FTTP and MPLS circuits, means backup to the cloud has become much more accessible for small to medium sized businesses.

Over the last year, we have seen massive growth in the take-up of cloud backup offerings. Cloud backup is probably one of the easiest cloud services to test and adopt. For example, it takes only a few clicks within the Veeam Backup and Recovery console to add iland as a service provider and start sending backup or copy jobs to the cloud.

Growth of disaster recovery as a service

Statistics from Gartner indicate that the DRaaS market is set to grow from $2.01B in 2017 to $3.7B by 2021.  The fact that 2017 has seen a great deal of natural disasters around the world, from hurricanes and floods to wild fires, has exacerbated this. As a result we have seen customers rushing to buy DRaaS services, and existing customers invoke their DRaaS for real. One organisation in Florida was able to go from having no disaster recovery to having a fully replicated and tested solution within five days as Hurricane Irma swept in.

Aside from natural disasters, the rise of ransomware has been another important driver for DRaaS. The very low RPOs often make DRaaS a better solution than backing up and recovering data on a daily basis. As with cloud backup, the increased availability of high-speed fibre broadband has made DRaaS replication across the internet much more achievable for most customers.

Multi-cloud strategies are taking off

It’s hard to deny the massive shift that is taking place among businesses in favour of multiple cloud environments, including public and private clouds, as well as on-premises infrastructure. As businesses deploy new applications and move critical workloads to save money and boost agility, it's safe to say that the trend of mixing and matching cloud environments will only accelerate.

According to Gartner, the IaaS market grew 31.4% in 2016. While the hyper-scale providers accounted for the lion’s share of this figure, others in the market saw a 13.2% growth. 451 Research predicts that IaaS will continue to grow from an estimated $16B in 2017 to $30B in 2021.

Cloud lock-in is seen as an issue with many hyper-scale cloud service providers. There is concern that many businesses lack contingency plans should they wish to switch from one provider to another, likewise they may want to stagger the risk and use more than one cloud provider. For example, in heavily regulated industries organisations are strongly advised not to put all of their eggs in one basket.

GDPR compliance and security

For many years security was seen as a hindrance to cloud adoption. Now, in most cases, security is covered by the cloud provider and their vendor partners.

GDPR has created increased requirements for security and compliance around data ownership, access, and deletion, and, importantly, who is responsible for the data.

From the outset, the iland secure cloud has been built to provide all the aspects of security and compliance that an enterprise customer would require. This includes Trend Micro Deep Security to protect the virtual machines running in the customer's virtual data centres, as well as Tenable Nessus to monitor and protect VMs exposed to the internet.

From a compliance perspective, iland has a dedicated team of professionals to ensure that we are at the forefront of compliance initiatives such as ISO 27001, CSA Star, SOC, HIPAA, PCI and GCloud.

GDPR will bring in a whole set of new requirements around data privacy, and iland is constantly improving processes and procedures, as well as offering services to enable customers to understand their commitments around data protection.

As a cloud service provider, we continue to invest in our DRaaS offering to help businesses prepare for natural disasters, ransomware attacks, and other potential threats to data. We have also seen increased usage of our cloud backup offering, based on Veeam Cloud Connect. Understanding that a multi-cloud solution is something that businesses will increasingly seek, we aim to help our customers diversify their cloud strategy in the year ahead.

451 Research posits ‘new IT world order’ with many enterprises moving off-prem by 2019

Three in five enterprises will move the majority of their IT away from enterprise data centres and onto public cloud infrastructure and software as a service (SaaS), according to a new report from 451 Research.

The study, the analyst firm’s inaugural Voice of the Enterprise Digital Pulse survey, polled more than 1,000 IT professionals worldwide, finding the largest spending increase for IT teams this year is for ‘as a service’ delivery.

Naturally, providers such as Microsoft and Amazon Web Services (AWS) are emerging as likely strategic technology suppliers for enterprises. One in three enterprises already consider Microsoft in this role, with the number expected to rise to 35% by 2019, while 17% will opt for AWS in 2019 compared with 7% today.

Business intelligence and analytics was the main IT priority in 2018, according to 45% of respondents, ahead of machine learning and artificial intelligence (29%), big data (28%), and software-defined networking (25%). The figures are interesting when considering all of the emerging technologies interesting CIOs and CTOs alike. Machine learning and AI polled well, but interest in blockchain – cited by 12% of respondents – and fog and edge computing (7%) was not as significant.

Ultimately, the research does suggest a trend; that of data-centric technologies. “The survey suggests that many – but certainly not all – organisations are finally reaching the point where they can focus on endeavours that help differentiate the business, instead of merely keeping the lights on,” said Melanie Posey, research vice president at 451 Research. “In 2018 we expect to see much of this effort focused around a new set of approaches to data optimisation and analysis.”

Back in July, the analyst firm said that ‘everything as a service’ was rising towards the mainstream, thanks to the increased demand for managed security, disaster recovery, and networking.

You can find out more about the report here (subscription required).

The cloud news categorized.