IBM Call for Code starter kits focus on coronavirus


Sarah Brennan

31 Mar, 2020

IBM has officially deployed an accelerated timeline for its coronavirus Call for Code and published three coronavirus-related Call for Code starter kits.

Each starter kit includes a comprehensive guide to help developers create apps to alleviate the problems people and communities are facing during the COVID-19 pandemic.

“We have learned how passionate developers are about solving the world’s most pressing issues, and how Call for Code’s infrastructure gives developers, data scientists, students, and subject matter experts the infrastructure they need to move from ideation through implementation,” said Daniel Krook, CTO of Call for Code. “Publishing developer-friendly starter kits has been key to help get developers up-and-running fast.”

Introducing three coronavirus starter kits

IBM has officially deployed an accelerated timeline for its coronavirus Call for Code and published three coronavirus-related Call for Code starter kits.

Each starter kit includes a comprehensive guide to help developers create apps to alleviate the problems people and communities are facing during the COVID-19 pandemic.

“We have learned how passionate developers are about solving the world’s most pressing issues, and how Call for Code’s infrastructure gives developers, data scientists, students, and subject matter experts the infrastructure they need to move from ideation through implementation,” said Daniel Krook, CTO of Call for Code. “Publishing developer-friendly starter kits has been key to help get developers up-and-running fast.”

Introducing three coronavirus starter kits

Crisis communication: Coronavirus has prompted many people to seek answers about symptoms, testing sites and the status of their communities. This starter kit comes equipped with a preloaded virtual assistant that understands and responds to common COVID-19 questions and scans COVID-19 news articles using Watson Discovery.

Remote education: While we may be in the midst of a pandemic, the edification of our youth must continue. Many schools and universities nationwide have shifted to online instruction to ensure the safety of themselves and their students. The remote education kit provides a set of IBM Cloud- and Watson Services-backed open-source tools related to remote education.

Community cooperation: We may be practising social distancing, but there is a growing interest in enabling cooperation among communities. More than ever, neighbours are offering to combine grocery runs and assist those around them. This kit enables the rapid deployment of applications that empower communities to continue working together.

IBM is continuing to develop a wide ecosystem of partners and tech providers in hopes of helping participants round out their solutions. Some of these partners include Altran and Bank of China.

Tarush Verma, client leader and AVP at Altran, said: “Altran will help fight this pandemic by creating innovative solutions for the Call for Code Global Challenge including chatbots and other applications based on the new COVID-19 developer starter kits.”

IBM reported it’s received upward of 1,000 registrations in a single day. Many of those applicants were individuals on the front lines, at-risk individuals and experienced coders who want to share their experiences and contribute to creating meaningful solutions. 

The initial submission deadline for this year’s Call for Code is now April 27. IBM will announce the three best solutions on May 5. Those teams will then work alongside IBM to have their solutions released into the “real world.”

To participate in this year’s Call for Code, visit the Call for Code site here

AWS launches Amazon Detective for investigating security incidents

1 Apr, 2020

AWS has announced the general availability of Amazon Detective, the company’s automated security service. 

Amazon Detective works with machine learning and statistical analysis to build visualised maps of security threats in a customer’s cloud. Rather than a security team compiling all the relevant data to analyse and conduct a lengthy investigation, it automatically pulls data from services like CloudTrail and customer logs. 

The information is then run through AWS GuardDuty which compiles a graph that details all interactions across the customer’s infrastructure. Everything is run from the Amazon Management Console and, according to AWS, in just a few clicks your IT team can have a detailed report of the problem and where it has come from. 

The graph model is also continuously updated as new data becomes available from the customer’s AWS resources, allowing security teams to spend less time looking through constantly changing data sources and freeing them up to work on remediation. 

The service is being offered with no upfront fees but customers will pay if they need to upload data from AWS CloudTrail and other AWS services they use. 

«Even when customers tell us their security teams have the tools and information to confidently detect and remediate issues, they often say they need help when it comes to understanding what caused the issues in the first place,» said Dan Plastina, VP for security services at AWS. 

«Gathering the information necessary to conduct effective security investigations has traditionally been a burdensome process, which can put crucial in-depth analysis out of reach for smaller organisations and strain resources for larger teams. Amazon Detective takes all of that extra work off of the customer’s plate, allowing them to focus on finding the root cause of an issue and ensuring it doesn’t happen again.»

The service is available from today in Europe, the US, South America and parts of Asia, with more regions coming soon, the company confirmed. 

Marriott reported another data breach: Why cyber risk assessment is important

Marriott International — the multinational hospitality company behind the third-largest hotel brand in the world — reported a major data breach on March 31 2020, marking its second major data breach in the last two years. This data breach is expected to leak the information of 5.2 million guests worldwide.

“Marriott said Tuesday approximately 5.2 million guests worldwide may have been affected. The information taken may have included names, addresses, phone numbers, birthdays, loyalty information for linked companies like airlines and room preferences. Marriott said it’s still investigating but it doesn’t believe credit card information, passport numbers or driver’s license information was accessed,” reported ABC News. In February-end, Marriott found a massive amount of guest information was being accessed using two of its employees’ user credentials.

After an initial investigation, Marriott believed that the data breach probably started in mid-January. It blocked those login credentials, and now, it is assessing the situation and assisting the relevant authorities for investigating the data breach. Though Marriott is doing everything to fix the problem now, it is no good news seeing it suffered two major data breaches in less than two years.

In November 2018, Marriott reported the first major data breach, which leaked the personal information of 383 million people. So, the combined amount of data that got leaked in these two data breaches totals to 388.2 million. Moreover, after the last major data breach, it was expected that Marriott will harden its cybersecurity infrastructure, train its security teams, and upgrade its systems. However, the latest data breach raises questions on its efforts to fight threats.

This brings us to the question: how does an organisation check and validate its security infrastructure? The answer: cybersecurity risk assessment.

Let’s learn more about it and how it helps organisations to test their security postures.

Cybersecurity risk assessment is the risk assessment of cyber or digital threats. It has become increasingly important since every organisation — nowadays — implements and relies on information technology and systems for running its business. Since it heavily relies on these digital systems, a small breach, hack, or malfunction may pose high risks.

As risk assessments are necessary for every organisation for getting informed and preparing for unexpected issues or risks like industrial malfunctioning and manufacturing defects and deaths, cybersecurity risk assessments are critical for knowing and preparing for unexpected cyber threats. The list of threats includes but is not limited to data breaches, insider or online attacks, etc.

“Risk assessments are used to identify, estimate, and prioritise risk to organisational operations (such as mission, functions, image, and reputation), organisational assets, individuals, other organisations, and the Nation, resulting from the operation and use of information systems. The purpose of risk assessments is to inform decision makers and support risk responses by identifying: (i) relevant threats to organisations or threats directed through organisations against other organisations; (ii) vulnerabilities both internal and external to organisations;(iii) impact (i.e., harm) to organisations that may occur given the potential for threats exploiting vulnerabilities; and (iv) likelihood that harm will occur,” according to NIST’s Guide for Conducting Risk Assessments.

Similarly, cyber risk assessment— is the term defining the process of assessing the cyber or digital risks facing your business or organisation. Its primary goal is to help the board members and decision-makers to understand the organisation’s cybersecurity infrastructure and install and support the best risk mitigation processes for fighting off — or at least decreasing the cyber risks of — both online as well as offline threats.

There are numerous examples and reasons that prove the importance of cyber risk assessments. The data breaches reported by Marriott International are great examples; if Marriott’s security infrastructure was attack-proof, it might not have suffered the data breach — at least the second one. Every customer (guest) making a reservation at Marriott after the first breach in November 2018 must have believed in its promise of hardening its security infrastructure. However, it failed — super hard — at keeping its promise. Though the investigation is still in progress for the second breach, Marriott had — probably — a gap in their security posture that led to the data breach. What could have been done?

Even if the two employees — whose login credentials were used for the second data breach — were involved in the breach, its security systems should have detected and reported massive data requests coming from systems at a single location or origin. And if detected and reported, its security teams should have checked the issue and identified the data breach earlier — ideally. However, it is evident that they did not detect or find the massive breach until recently.

That said, every organisation must perform cybersecurity risk assessments on a regular basis. It helps the organisation to identify its security weaknesses, inform the security teams as well as decision-makers, and harden or install the necessary cybersecurity processes and products to improve the overall security. Moreover, it reduces the long-term costs, provides awareness on the installed processes and systems, helps avoid data breaches and security incidents, and helps meet the legal and regulatory cybersecurity requirements. These, in turn, helps strengthen your brand and avoid unnecessary costs or risks. Also, it builds trust in your present and future customers for your organisation.

Picture credit: "Marriott Hotel", by José Carlos Cortizo Pérez, used under CC BY 2.0

AWS makes Amazon Detective generally available for greater security awareness

Amazon Web Services (AWS) has announced the general availability of Amazon Detective, a new offering which aims to help customers remediate security issues across their AWS workloads more easily.

Amazon Detective, which was launched in preview at re:Invent last year, automatically collects log data from a customer's resources and uses machine learning and statistical analysis to build interactive visualisations which customers can use to deduce security anomalies.

Sebastien Stormacq, Amazon senior developer advocate, noted in a blog post how customer demands had changed from five years ago, when AWS released a solution which automatically analysed AWS CloudTrail data to generate alerts around sensitive API usage.

"Today, when a security issue is detected, such as compromised credentials or unauthorised access to a resource, security analysts cross-analyse several data logs to understand the root cause of the issue and its impact on the environment," wrote Stormacq. "In-depth analysis often requires scripting and ETL to connect the dots between data generated by multiple siloed systems.

"To further complicate matters, new AWS accounts, and new applications are constantly introduced, forcing analysts to constantly reestablish baselines of normal behaviour, and to understand new patterns of activities every time they evaluate a new security issue," added Stormacq.

Among the customers rolling out with Detective are T-Systems and Warner Media, with the product available in 14 AWS regions upon launch. There are no additional charges or upfront commitments to customers, the company added.

This can be seen as another step in the largest cloud vendors giving customers a helping hand around the ever-thorny issue of security. Yet the element of give-and-take has to remain. Take the launch of Amazon S3 Block Public Access in late 2018, which enabled extra controls to ensure S3 buckets did not become misconfigured. The year before, the company updated its dashboard so public buckets were signified with bright orange indicators. As cloud workloads become more complex, security needs to adapt with it – which is what AWS is aiming for here.

You can read the full blog post here.

Photo by Agence Olloweb on Unsplash

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Zoom admits meetings don’t use end-to-end encryption


Bobby Hellard

1 Apr, 2020

Video conferencing app Zoom does not use end-to-end encryption, according to reports, despite specifically stating that it does on its website.

Though Zoom offers users the option to “enable an end-to-end (E2E) encrypted meeting,” and provides a green padlock that claims “Zoom is using an end to end encrypted connection,” the company this week admitted that offers no such thing.

A spokesperson for the company told The Intercept that, despite its claims, it was «currently not possible» to enable end-to-end encryption for its video meetings.

Instead, the spokesperson revealed, the service uses Transport Layer Security (TLS) which encrypts data between user’s meetings and Zoom’s servers. End-to-end refers to data encrypted between calls, blocking out third parties – which includes the service provider. As a result, the company can see and use the data for things like targeted ads. 

«When we use the phrase ‘End to End’ in our other literature, it is in reference to the connection being encrypted from Zoom end point to Zoom end point,” the spokesperson added.

Like a number of video conferencing services, Zoom is currently benefiting from the coronavirus lockdown. Its usage in the US is reportedly three times as much as Microsoft Teams, which is fairly impressive for an app that was almost unheard of this time last year. 

Given the rapid rise of Zoom, Microsoft recently singled out the service in a partner video, suggesting that it’s a threat to its business model as it can be used in tandem with rivals like Slack and Google’s G Suite, unlike Teams.

Part of Zoom’s appeal to organisations is its simplicity and the fact it can be used for free, albeit without any premium features, which lets businesses try it out before forking out any money.
 
«Video conferencing is a fantastic necessity in times like these but it is vitally important to understand the security and privacy concerns that go in parallel with this increasingly popular form of communication,» said Jake Moore, a cyber security specialist for ESET.
 
«For social and light business meetings they are fine as long as users realise what data is being shared by Zoom to third parties. I certainly wouldn’t recommend using free software for sensitive or private meetings.»

On Tuesday, Boris Johnson tweeted a picture of his cabinet’s «first digital meeting» and, comically, left the ID number visible. This security blunder will not have gone down well with the Ministery of Defence, which has reportedly banned Zoom due to security concerns. 

Zoom told The Intercept that it only collects user data to improve the service and that it never allows its employees to access specific content in meetings and doesn’t sell any kind of user data. However, the company did confirm that it could hand over data from meetings if it was compelled to for legal proceedings. 

IT Pro 20/20: Turning to the cloud in a crisis


Cloud Pro

31 Mar, 2020

Welcome to the third issue of IT Pro 20/20, our brand-new digital magazine that brings all of the month’s most important tech issues into clear view.

Each month, we will shine a spotlight on the content that we feel every IT professional should be aware of, only in a condensed version that can be read on the go, at a time that suits you.

This month we’re taking a look at how cloud innovation is helping to support the technology industry and wider society through a global pandemic. Now that most of us are working remotely, it’s important you have the best tools in place to keep employees secure and productive, and so we’ve highlighted a number of areas where the cloud is helping to drive this effort. From free software and remote working tips, to industry leadership and changing technology paradigms, the cloud is behind it all.

We also take a look at the growing trend of screenless content and provide some tips for helping your organisation develop a much-needed audio strategy, as well as the growth of AI as a service, both of which are exclusive to this month’s issue.

As ever, you’ll also find a roundup of the four biggest stories of the month that are likely to reverberate throughout 2020.

DOWNLOAD THE MARCH ISSUE OF IT PRO 20/20 HERE

We hope you enjoy reading this month’s issue. If you would like to receive each issue in your inbox as they release, you can subscribe to our mailing list here.

The next IT Pro 20/20 will be available on 30 April. Previous issues can be found here.

Oracle cloud courses are free during coronavirus lockdown


Bobby Hellard

31 Mar, 2020

Oracle has announced it’s offering free access to its online learning content and cloud certifications while swathes of workers are in coronavirus lockdown. 

The aim is to help IT professionals gain highly sought after skills while the coronavirus pandemic enforces remote or reduced working, according to Oracle.

The courses and certifications cover Oracle Cloud Infrastructure and Oracle Autonomous Database and will be available until 15 May. There are seven learning paths that users can access with an Oracle Single-Sign-On account, which is also free.

Oracle users, developers, technical professionals, architects, students and professors will have access to more than 50 hours of online training and six certification exams, according to Raghu Viswanathan, the VP of education products and delivery at Oracle University.

«As our customers adapt to a rapidly evolving digital landscape, Oracle is stepping up its efforts to help build critical technical cloud skills they need to ramp up innovation,» Viswanathan said in a statement.

«We believe that certifications help professionals develop in-demand skills, shorten turnaround times for customer projects, enhance their expertise and advance their careers while improving their overall job performance.»

The free access will include an extensive library of materials for Oracle’s Cloud Infrastructure and Autonomous Database, as well as content on topics like machine learning, data science and multi-cloud environments, which includes integrations with Microsoft Azure.

With these courses, the company is also going to offer access to high-quality video content, experts and recorded demos of hands-on labs, all of which will be available anywhere and anytime. This will include machine learning translations for Chinese, Japanese, Korean, Portuguese and Spanish speaking countries.

Like Oracle, a number of tech companies have offered some services for free while the coronavirus outback drastically changes the way we live and work. Companies like Microsoft, which has offered Teams as a free service to the NHS and RingVPN, which has made the first 90 days of its service free of charge.

How Covid-19 will impact IT and tech spending for 2020 and beyond

The human tragedy the COVID-19 pandemic has inflicted on the world is incalculable and continues to grow. Every human life is priceless and deserves the care needed to sustain it. COVID-19 is also impacting entire industries, causing them to randomly move in unpredictable ways, directly impacting IT and tech spending.

COVID-19’s impact on industries

Computer Economics in collaboration with their parent company Avasant published their Coronavirus Impact Index by Industry that looks at how COVID-19 is affecting 11 major industry sectors in four dimensions: personnel, operations, supply chain, and revenue. Please see the Coronavirus Impact Index by Industry by Tom Dunlap, Dave Wagner, and Frank Scavo of Computer Economics for additional information and analysis.  The resulting index is an overall rating of the impact of the pandemic on each industry and is shown below:

COVID-19's Impact On Tech Spending This Year

Computer Economics and Avasant predict major disruption to High Tech & Telecommunications based on the industry’s heavy reliance on Chinese supply chains, which were severely impacted by COVID-19.

Based on conversations with U.S.-based high tech manufacturers, I’ve learned that a few are struggling to make deliveries to leading department stores and discount chains due to parts shortages and allocations from their Chinese suppliers. North American electronics suppliers aren’t an option due to their prices being higher than their Chinese competitors. Leading department stores and discount chains openly encourage high tech device manufacturers to compete with each other on supplier availability and delivery date performance.

In contrast to the parts shortage and unpredictability of supply chains dragging down the industry, software is a growth catalyst. The study notes that Zoom, Slack, GoToMyPC, Zoho Remotely, Microsoft Office365, Atlassian, and others are already seeing increased demand as companies increase their remote-working capabilities.

COVID-19’s impact on IT spending  

Further supporting the Coronavirus Impact Index by Industry analysis, Andrew Bartels, VP & Principal Analyst at Forrester, published his latest forecast of tech growth today in the post, The Odds of a Tech Market Decline In 2020 Have Just Gone Up To 50%.

Mr. Bartels is referencing the market forecasts shown in the following forecast published last month, New Forrester Forecast Shows That Global Tech Market Growth Will Slip To 3% In 2020 And 2021 and shown below:

COVID-19's Impact On Tech Spending This Year

Key insights from Forrester’s latest IT spending forecast and predictions are shown below:

  • Forrester is revising its tech forecast downward, predicting the US and global tech market growth slowing to around 2% in 2020. Bartels mentions that this assumes the US and other major economies have declined in the first half of 2020 but manage to recover in the second half
  • If a full-fledged recession hits, there is a 50% probability that US and global tech markets will decline by 2% or more in 2020
  • In either a second-half 2020 recovery or recession, Forrester predicts computer and communications equipment spending will be weakest, with potential declines of 5% to 10%
  • Tech consulting and systems integration services spending will be flat in a temporary slowdown and could be down by up to 5% if firms cut back on new tech projects
  • Software spending growth will slow to the 2% to 4% range in the best case and will post no growth in the worst case of a recession
  • The only positive signs from the latest Forrester IT spending forecast is the continued growth in demand for cloud infrastructure services and potential increases in spending on specialised software. Forrester also predicts communications equipment, and telecom services for remote work and education as organisations encourage workers to work from home and schools move to online courses

Conclusion

Every industry is economically hurting already from the COVID-19 pandemic. Now is the time for enterprise software providers to go the extra mile for their customers across all industries and help them recover and grow again. Strengthening customers in their time of need by freely providing remote collaboration tools, secure endpoint solutions, cloud-based storage, and CRM systems is an investment in the community that every software company needs to make it through this pandemic too.

Photo by Micheile Henderson on Unsplash

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Azure services up 775% as Microsoft scrambles to add more capacity


Bobby Hellard

30 Mar, 2020

Microsoft’s cloud services have seen a 775% spike in usage in areas where social distancing measures and lockdowns have been enforced.

Azure services such as Microsoft Teams, Windows Virtual Desktop and Power BI have all seen increases of users in March as more and more have been forced to work from home or stay indoors.

The company recently announced it would prioritise capacity provisions for critical health and safety organisations to ensure the relevant remote workers can stay up and running during the coronavirus pandemic. However, with demand for cloud services surging in lockdown areas, the company has said it will «expedite» the creation of new capacity.

«We’re implementing a few temporary restrictions designed to balance the best possible experience for all of our customers,» the company wrote on its blog. «We have placed limits on free offers to prioritise capacity for existing customers.

«We are expediting the addition of significant new capacity that will be available in the weeks ahead. Concurrently, we monitor support requests and, if needed, encourage customers to consider alternative regions or alternative resource types, depending on their timeline and requirements. If the implementation of these efforts to alleviate demand is not sufficient, customers may experience intermittent deployment-related issues.»

So far, the only issue with Azure has been a two-hour outage for Microsoft Teams in Europe. The service went down on the first Monday of remote working as it saw a spike in usage.

Later it was revealed that Teams had seen 12 million more users in March, taking the number of daily active users to 44 million. Windows Virtual Desktop also trebled in usage and Microsoft’s business analytics service, Power BI, saw a 42% increase in just one week.

In addition, Microsoft also said its been in regular contact with ISPs around the world and is actively working with them to «argument» capacity as needed.

«We’ve been in discussions with several ISPs that are taking measures to reduce bandwidth from video sources in order to enable their networks to be performant during the workday,» the company said.

Microsoft to acquire Affirmed Networks to get onto AWS’ wavelength

Microsoft has announced it is to acquire Affirmed Networks, a provider of network functions virtualisation (NFV) software – as the telecoms space heats up for the biggest cloud players. 

As 5G is becoming more of a reality, cloud vendors see their role as enabling telecom operators to deploy and maintain next-generation networks more efficiently.  

“At Microsoft, we intend to empower the telecommunications industry as it continues its move to 5G and support both network equipment manufacturers and operators in their efforts to find solutions that are faster, easier and cost effective,” wrote Yousef Khalidi, corporate vice president for Azure networking in a blog post. “This acquisition will allow us to evolve our work with the telecommunications industry, building on our secure and trusted cloud platform for operators. 

“With Affirmed Networks, we will be able to offer new and innovative solutions tailored to the unique needs of operators, including managing their network workloads in the cloud,” Khalidi added. 

Anand Krishnamurthy, president and CEO of Affirmed Networks – who only became CEO earlier this month – said the company had delivered on its vision. “Working together, we have created a model for mobile networks of the future that is open, cloud-native and capable of being web-scale, all at 70% of the cost of traditional networks,” wrote Krishnamurthy. “We have been their partner of choice as they prepare for fifth generation (5G) networks and infrastructure.  

“Now, the combined technologies of Microsoft and Affirmed will further accelerate this momentous shift.” 

This move makes for an interesting comparison with what Amazon Web Services (AWS) is doing with its Wavelength project. The initiative is an edge play which embeds AWS’ compute and storage services on the edge of operators’ 5G networks, enabling the delivery of ultra-low latency applications. 

At re:Invent back in December, in what was seen as the biggest item of the main keynotes – or in other words, the last item – Verizon CEO Hans Vestberg joined AWS chief Andy Jassy on stage to discuss the collaboration between the two companies. Jassy noted the most exciting applications to be ushered in, such as autonomous industrial equipment, or applications for smart cities, can’t wait that long.  

“If you want to have the types of applications that have that last mile connectivity, but actually do something meaningful, those applications need a certain amount of compute and a certain amount of storage,” he said. “What [developers] really want is AWS to be embedded somehow in these 5G edge locations.” 

For Microsoft’s part, the company said it was looking at extending ‘deep, strong partnerships’ and ensuring interoperability to ensure cloud-based software-defined networking (SDN) fits into the 5G landscape. The company’s partnership with AT&T, beefed up in November, is seen by many in the industry to be a particularly interesting one in the space. 

Financial terms of the deal were not disclosed. You can read the full announcement of the acquisition here. 

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.