Microsoft Teams goes down at start of mass remote working


Bobby Hellard

16 Mar, 2020

Microsoft Teams went down across Europe for two hours on Monday, causing mass frustration for the many remote workers now increasingly dependent on the service.

Users experienced issues signing into the service and also trouble sending messages. 

Although Microsoft managed to fix the problem within two hours, the timing could not be worse as millions of people across the country began remote working amind the outbreak of COVID-19

As users from various European countries began reporting issues, Microsoft tweeted that it was looking into the problem.

«We’re investigating messaging-related functionality problems within Microsoft Teams. Please refer to TM206544 in your admin centre for further details,» the company said. 

This is the second major outage to hit Microsoft in as many years after Office 365 went offline in 2018. There is a suggestion that Monday’s faults could be due to more people using the services as businesses encourage workers to stay home.

Just a week ago, Microsoft offered a six-month free trial for Teams, according to Businesses Insider, to help those soon to be self-isolating. Google has also offered up parts of its remote working services in a bid to work around the coronavirus outbreak. 

Microsoft’s outage is a poor start to what could be a big opportunity for cloud computing.

With mass remote working and many business events going «virtual», video linkups, VR and other similar technologies will become a crucial element of everyday life. 

Outages and service disruptions are common occurrences with new technologies, but as the world begins what looks like a prolonged period of self-isolation, it’s these kinds of services that will keep many industries ticking along.

Add to that, the need for us all to stay connected to one another during a pandemic and Microsoft Team’s and services like it have suddenly become vital. 

 

IDC finds how organisations investing in cloud-based quantum computing seek to gain competitive edge

IDC, in its recent study titled ‘Quantum Computing Adoption Trends: 2020 Survey Findings’ has found that organisations currently investing in cloud-based quantum computing technologies are expecting to see improved AI capabilities, accelerated business intelligence, and increased productivity and efficiency.

During its initial stage, the study indicated that as cloud-based quantum computing is still at its nascent stage and the allotted funding for its initiatives is limited – somewhere between 0%-2% – the end-users are very much positive that they will realise a competitive advantage owing to early investment. At present, the manufacturing, finance, and security industries are at the forefront as they are experimenting with more potential use cases, developing advanced prototypes, and implementing the technology.

Limited skills, lack of available resources, complex technology, and cost are some of the factors that discourage some organisations from investing in quantum computing. However, these strands, combined with a large interdisciplinary interest, have compelled vendors of quantum computing to develop the technology that addresses multiple end-user needs and skill levels.

Last year, researchers at Google claimed that their quantum computer has solved a problem in some minutes that would otherwise take even the very best conventional machine thousands of years to crack. They termed this milestone as ‘quantum supremacy’, as it took a very long time to realise the immense potential of quantum computers. On the other hand, IBM has criticised the claim stating that the same problem can be solved by its machine in 2.5 days with sophisticated classical programming, arguing that Google has not yet reached the milestone in actuality. 

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

What is cyber insurance truly worth? Analysing the risks and responses

Analysis Cyber risk has overtaken financial risk as the greatest threat that we all face, according to PwC’s 2019 global crisis survey. There are also concerning parallels between the global financial crisis of 2009, and the current cyber threat landscape

The question is, to what extent is cyber insurance the answer?

Currently most companies don’t have any cyber insurance. Coverage is only 40% in the US, and 10% in the UK. Elsewhere, it’s even lower. Many cyber insurers boast that they can provide an insurance quote in under an hour. If they are able to provide cover for such a complex policy in such a short period of time then this should ring alarm bells. You should be concerned with their ability not only to accurately assess your risk position, but also to price the policy accurately.

Some insurers base their risk assessment on cyber security risk ratings. Some of these ratings are produced by firms that use web crawlers that check externally facing endpoints for known vulnerabilities. This is a fairly crude method, but it’s probably still the best way to address the mass market at low cost. The problem is, it’s a bit like evaluating fire-safety risk by looking at a photograph of a building taken from across the street. You can get an idea of the building’s shape and size, but you can’t tell if there’s flammable material inside, or if the building is equipped with fire alarms, or sprinkler systems. A photo like this is better than nothing; but it still provides only a basic, limited idea of the real risk.

The reason that some insurers can probably afford to base premiums on such crude risk metrics is that cyber insurance policies often include a host of provisions and exclusions that in effect make it impossible to claim for almost any incident of any kind. If they want to refuse to pay out, they're probably going to find a way of justifying this. Indeed almost the only reason they would pay out at all is to encourage other clients to sign up.

So if there is a global cyber crisis they may well refuse to pay out on any policies and consider withdrawing from the market entirely.

Examples of common cyber insurance terms or exclusions are as follows:

  • Policies tend to only cover 'a hacker who specifically targets you alone'. Unfortunately, cyberattacks are rarely focused on a single victim. Often either the same attack vector is used on many victims in a scattergun approach (phishing attacks) or malware is used that is contagious in nature (WannaCry)
     
  • Policies tend not to cover 'any failure…by a cloud/infrastructure provider…unless you own the hardware and software'. Unfortunately, this would not only exclude almost all cloud use, but also exclude almost anything other than hosted services which exclusively use kit you own
     
  • Policies tend not to cover incidents involving a 'third party…not unduly restricted or financially limited by any term in any of your contracts'. This is meant to ensure that the insurer is able to pursue any third party involved for unlimited damages. Unfortunately, this excludes almost all service providers as they themselves tend to specify some limitation to damages in their contracts, such as damages being limited to the value of the contract. No service providers these days offers unlimited liability
     
  • Policies tend not to cover incidents involving 'any individual hacker within the definition of you'. Unfortunately, this would exclude all insider threats
     
  • Policies tend not to cover 'the use by you of any software or systems that are unsupported by the developer'. This clause rarely specifies that the unsupported software needs to be part of the attack vector, which means that you could be excluded if you had a single instance of something like Windows XP on your technology estate, even if this was not part of the attack at all
     
  • Policies tend not to cover incidents 'attributable to any failure…by the Internet Service Provider (ISP) that hosts your website, unless such infrastructure is under your operational control'. Unfortunately, this would exclude all incidents involving any ISP as it is unheard of for ISP infrastructure to be under your operational control
     
  • Policies tend not to cover 'acts of foreign enemies, terrorism, hostilities or warlike operations (whether war is declared or not)'
     
  • Policies tend not to cover 'any error or omission arising out of the provision of negligent professional advice or design'. Unfortunately, if at any time you have tested or assessed your security (as is required under GDPR), but then failed to implement all the resulting recommendations then your cover could be void. So, if you have had penetration testing or certification audits (for ISO 27001 or PCI say) then you need to address every single recommended revision or recommendation or you risk voiding your cover
     
  • Policies tend not to cover 'anything likely to lead to a claim, loss or other liability under this section, which you knew or ought reasonably to have known about before we agreed to insure you'. This is the pre-existing condition provision. This means that if in any business case that your team make for adopting cyber insurance, you cite potential vulnerabilities as reasons for this adoption, then these very vulnerabilities could then be excluded from any cover

For these reasons we have already seen that some claims are not being paid. For example, several major insurers have declined to pay for damages caused by the NotPetya ransomware attack a few years ago. They say it was a “hostile or warlike action” and therefore not covered.

On top of this other claims have only been paid in part. For example, Norsk Hydro received an insurance payout of $3.6 million. That’s only about 6% of the overall damage that was estimated to be as much as $71 million. It covered the cost of the technical fix, but that was it.

Cyber insurance, while important, simply isn’t a substitute for prevention or for crisis preparedness. You need to have all three.

Here are a few measures to consider:

We need increased adoption of cyber insurance cover, with organisations being far more discerning about the policies they adopt:

  • Clients need to understand their risk appetite – you could spend an almost infinite amount on cybersecurity, but you don’t necessarily need to do so
     
  • They need to be far more aware of the exclusions in the policies on offer and to base their choice on the nature of the cover rather than purely on price – there’s no point in paying for a cheap policy that won’t pay out
     
  • They need to choose policies that are appropriate for their business and for their risk position – specialist brokers can help you find a policy that is right for you
     
  • They also need to consider separate specialist incident response cover if this is not included in their cyber insurance policy (most don’t include it) – while an elite team could save you from disaster, the wrong team won’t just fail to fix the problem, they could actually make it worse

What we tend to find is those organisations who have incident response cover tend to call in the experts straight away, while those without it often attempt a DIY fix before calling for help. By the time they do call for help though it’s often too late – the impact and exposure have magnified significantly – and they call in the wrong people, not having time to accurately select the right experts.

Almost worse than a policy that won’t pay out is one that won’t provide top quality incident response. Whether your insurer is footing the bill or you are, here’s what you will really need:

  • The technical fix: Get expert help from a specialist security response team to identify and the fix problem(s), and do forensics to diagnose the cause and full scope. Getting an immediate fix to resolve the problem, stem any data loss and recover any systems is essential. Any delay will magnify the impact of the incident and damages incurred
     
  • The legal defence: Seek expert advice in cyber and data law to rapidly develop a legal strategy and a legally defensible narrative based on the forensics. Having the right legal strategy and narrative are both essential to limit legal and regulatory exposure
     
  • The brand defence: Get expert cyber comms support to help your internal and agency teams deal with the added complexity and enhanced comms workload. The standard PR approach to crisis management simply won’t work in a cyber incident and may even make things worse
     
  • Social response: Get top global privacy/security influencers to act as trusted voices to counter misinformation with authority and hysteria with reach and credibility. To counter misinformation and hysteria when your own credibility is at an all-time low, you’ll need the support of authoritative opinion leaders in privacy and security

Part of the reason that you need specialists is the fact that traditional crisis tactics don’t work in a cyber crisis.

In a conventional crisis, you need to understand that with most crises or crimes, the criminals get the blame and the company and customers are seen as victims. The conventional PR tactics in a crisis scenario are to contain any issue until it becomes public and then to show empathy for your customers in order to gain sympathy from the press and general public for both you and the clients. It tends to work well.

A cyber incident is different. You’re likely to be on the back foot: a cyber incident could well be public before you even become aware yourselves. What’s more, cyber incidents aren’t instantaneous: the average breach occurs long before it is detected.

Unfortunately, cybercrime is about the only crime where the victim gets the blame. However much you spent on cybersecurity, the press and public will blame you and not the hackers. You need to be prepared to face the regulators, a hostile press and inevitable hysteria and misinformation.  Containment is not possible due to GDPR disclosure obligations and showing empathy won’t gain you any sympathy. It’ll simply put your executives in the firing line.

Crisis preparedness is also critical. Scenario planning and realistic simulation exercises are essential for preparedness, and indeed testing and assessment are mandated under GDPR. So if companies don’t do it, and they then have an incident – the regulatory action will be far harsher.

For companies of any size, it’s probably not a matter of ‘if’ they’ll get hit, but ‘when’. And since the average breach takes more than six months to detect, it may well already have happened.

If ever there was a time to make a case to the board for the need for cyber insurance and crisis preparedness, it is now – with a looming pandemic. The last crisis may have been financial, the current one may be health related, but the chances are that the next one with be a cyber crisis. We all need to be prepared for this.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

How businesses can make the most of flexible working


Sandra Vogel

17 Mar, 2020

The ability to work in any location that’s appropriate, from the office base to client premises to your own home, cafés, the beach and any other place that feels like the right place, has always been possible. But advances in technology make it easier to do more from a wider range of locations: If you’ve got a laptop and an internet connection, you’re all set.

This is a kind of mantra, but how do organisations really manage flexible working, what role does technology play, and what’s the mix between financial gains and supporting the wellbeing of the workforce? Cloud Pro asked a range of organisations these questions, and came up with some very compelling answers. 

Size is not a factor

While flexible working is sometimes seen as a luxury afforded only to those working in large companies that can afford to support it, the truth is businesses of all sizes can do it successfully. Indeed, Cloud Pro spoke to large and small organisations about their use of flexible working, and their size was not a factor in their choice.

Vestd, a regulated share scheme & equity management platform for SMBs employs just 14 full time staff. It doesn’t have a fixed office, instead the entire team works remotely, with occasional meetups in co-working hubs in London or Brighton. At the other end of the spectrum, Poly (formerly Plantronics/Polycom), employs around 7,500 staff across the globe. Paul Clark, Senior Vice President and EMEA Managing Director tells Cloud Pro: “At any given time, people may be collaborating from a home office or an office site, based on the task at hand.”

Technology smooths the path

Technology not only makes flexible working easier, it can also deliver entirely new ways of working as a team. For Vestd, technology allows them to operate without an office base, but they still need to get together as a team and for this video calling is vital. Co-founder and CEO Ifty Nasir tells Cloud Pro “Every morning we have a daily video call, with the whole team present.” 

It doesn’t need a great deal of imagination to see how technologies can change the ways in which we collaborate. Paul Clark expanded on how this is achieved at Poly, saying: “Meetings are no longer about talking, but sharing documents, screens and working on ideas as a team. Once on a call, participants want to be able to collaborate, be able to view and annotate the same files together in real-time, rather than waiting for an email to arrive with files to edit locally.”

The bottom line

The financial savings from flexible working can be very significant, too, and benefit both clients and the business itself. Edinburgh-based Prospect Community Housing manages around 1,000 homes and has 33 staff (a mix of full and part time). Director Brendan Fowler tells Cloud Pro that since going live with a bespoke housing management solution that caters for flexible working, staff costs are down £30,000 a year and more staff can spend more time in the community with tenants.

Vestd’s Nasir adds: “In a business like Vestd’s, an office would commonly be the largest cost after salaries.

“[Remote working] means that our fees can be dropped to a more competitive level. Companies that don’t work remotely may soon struggle to compete against those that do.”

Still, at a time when there is a growing feeling that we should be moving away from a five day working week towards four days a week, and there’s increased support for flexible hours across a whole range of sectors, the benefits of flexible working are for many organisations about more than headline financial savings.

Wellbeing matters

Personal wellbeing is increasingly recognised as being both good for the individual and good for businesses. Paul Clark from Poly says: “Work shouldn’t stop if you are away from your desk or outside the office building. This eventually allows for a better work-life balance and the much-needed time to relax anyone would take to trade off driving during rush hour or sitting on a train.”

Ifty Nasir puts it succinctly: “Avoiding the drudgery of a daily commute is very good for the soul, not to mention the back pocket.” He adds that employees save around £6,000 a year on average as a result – without even including any potential childcare costs.

Planning and buying agency MediaCom finds productivity and wellbeing benefits go hand in hand. Elaine Bremner, Chief HR and Talent Officer explains: “The key reason we offer our employees flexibility is to give them a working experience that allows them to also focus on travel, family and health and passions outside of work. This is important in creating an inclusive working culture and by giving people the ability to have ownership over their hours it increases their productivity when they are in work. By making your workforce as comfortable as possible in their work, you get the best results out of them.”

With increasing pressures on public transport systems, a growing awareness of the need to reduce car use, and an ever rising understanding of the health and wellbeing benefits of flexible working, in a way it’s surprising that there are any organisations that are not using technology to support it. Certainly those that have taken the plunge seem to find multiple benefits.

SolarWinds NPM 2019.4 review: A monitoring masterclass


Dave Mitchell

23 Mar, 2020

A great set of monitoring and performance tools, presented in a slick and customisable web console

Price 
£2,275 exc VAT

SolarWinds Network Performance Monitor (NPM) is a well-featured monitoring solution – and it will particularly appeal if you’re already using other SolarWinds products, as it integrates into SolarWind’s central Orion web console.

New features in the latest release include a graphical view of usage and status details for Cisco Catalyst 2960 and Juniper EX-series switches. You can also now view real-time graphs of CPU, memory and interface usage for any node, while the addition of widgets to the page settings screen makes it easier to customise views for individual devices.

The Orion web server has been updated to improve performance. Having experienced issues ourselves with the speed of previous versions, we’re happy to say that pages now load noticeably more quickly.

Setting up NPM isn’t quite as swift as with some other products – it took us around 90 minutes from start to finish – but it’s very easy, with the installer automatically downloading all required components. The first time you visit the web console you’re greeted by a discovery wizard, which prompted us to enter our IP address ranges and subnets, along with details of our AD domain controllers and system credentials – and invited us to schedule regular re-runs of the discovery procedure.

Once the various items on your network have all been identified, colour-coded icons highlight device issues. The console’s Alerts & Activity tab provides an overview, from which you can focus in on the details to see exactly what the problem is. The Message Center, meanwhile, provides extensive search facilities, and alerts can be linked to actions such as sending SMS messages and emails.

One feature of NPM that we rate particularly highly is its customisable dashboards. When you first access the console you might feel overwhelmed by an avalanche of information, but a dashboard can be quickly modified by adding or removing columns and moving resource views around. If you run out of room, you can set up a big-screen NOC view that rotates through multiple dashboard views at predefined intervals.

Application monitoring is another strength: the Quality of Experience dashboard can identify, categorise and analyse traffic from over 1,500 applications. Sensors simply need to be connected to a switch mirror port, and if you install them on hosts already being monitored by NPM, they won’t consume an extra node licence.

Then there’s the NetPath feature. This probes external web locations and presents live maps showing latency and packet loss details for each hop, making it easy to pinpoint cloud service performance issues. Windows and Linux remote agents can securely monitor cloud servers or you can use Amazon AWS and Microsoft Azure APIs which don’t require any NPM licenses.

And one of NPM’s cleverest features is PerfStack, which can help pinpoint the root cause of complex network problems by comparing a range of metrics from multiple systems. You can set these up using simple drag and drop manoeuvres, and choose a common time frame that makes it easy to compare metrics such as CPU or memory usage and identify which system is misbehaving.

The standard NPM package is more limited when it comes to VMware and Hyper-V hosts, with only basic availability monitoring included. If you want more, the optional Virtualisation Manager module adds datastore usage and capacity planning reports. 

Mobile support is comparatively weak, too: to access the console from our iPad, we had to install SolarWind’s separate Mobile Admin Server, which costs £533 – and, after linking the iOS app to it, we found the minimal information provided didn’t remotely justify the expense.

Although NPM has its shortcomings, its monitoring and troubleshooting tools can’t be faulted – and the web console is a pleasure to use, putting everything at your fingertips to ensure you don’t miss out on important information and issues.

ManageEngine OpManager Plus 12.4 review: Ideal for VM monitoring


Dave Mitchell

20 Mar, 2020

Simple licensing and a good set of built-in features make this a fine monitoring choice that’s easy to manage

Price 
£2,920 exc VAT

If you want to keep your licensing simple, OpManager is sure to appeal: pricing is based solely on the number of monitored devices, regardless of how many interfaces or elements each one has, and it starts at just £188 for a perpetual ten-device licence. There’s also an annually licensed option, which includes the NetFlow, IP service-level agreement and deep packet inspection add-ons (which must otherwise be purchased separately). Whichever licensing model you pick, VMware, Hyper-V, XenServer and Nutanix host monitoring come as standard.

This latest version of OpManager also supports Windows Server 2019 systems and improves integration with enterprise storage systems from the likes of Dell EMC and NetApp. Deployment is simpler than ever, thanks to over 8,000 predefined device templates, while dashboards can now be personalised for specific users, and alerting options include Slack and ServiceNow.

The software itself is quite light, so you don’t need to dedicate a host to its use. We had it up and running on a Windows 10 desktop in 15 minutes, and all it added was a single service and a default PostgreSQL database.

On first launch a discovery wizard steps you through entering IP address ranges, providing credentials and setting a schedule for future discovery runs. It took around ten minutes to then scan the lab network.

With this done, it’s time to turn to the OpManager web console. This can be accessed directly on the host or remotely and opens with a smart dashboard view. You can customise this with your choice of over 100 widgets, although you can’t tweak the total number of columns shown – this is determined by the size of the widgets and where you position them.

We found it a breeze to set up multiple dashboards showing details such as CPU and memory usage for individual devices, plus Active Directory availability and alarm summaries. The heatmap widget provides a grid of coloured blocks representing each device and their status, with quick links to each one, and you can set up multiple dashboard views with large-print displays, suitable for support departments.

All features are accessible from a clear ribbon menu across the top so we were quickly able to find and inspect our switches, printersWindows servers and Linux-based NAS appliances. The virtualisation dashboard presented plenty of detail about our VMware ESXi and Hyper-V hosts too, and you can drill down to examine host storage devices and resource usage. The VM sprawl display, meanwhile, shows idle VMs, and those with over and under-provisioned CPU and RAM resources.

While there are a lot of features included in the price, one extra that’s worth considering is the Application Performance Management add-in, which adds details of an impressive range of applications, databases and cloud services. It snaps into the main OpManager web console, and we found it handy for keeping a close eye on our Amazon S3 cloud storage.

As for alerts, you don’t necessarily have to lift a finger: preset warning thresholds are assigned to all devices, and for the next release ManageEngine is working on adaptive thresholds that use AI and ML algorithms. If you want to get more hands-on, you can set up automated responses to specified conditions: the console’s Workflow Builder tool makes it easy to drag and drop conditions and actions, and apply them to critical devices.

Easy to deploy and simple to licence, ManageEngine’s OpManager Plus is a great choice for those who want to keep their management burden to a minimum – and its built-in virtualisation monitoring makes it tempting value.

Getting started with Kubernetes


Danny Bradbury

19 Mar, 2020

Container systems like Docker are a popular way to build ‘cloud native’ applications designed for cloud environments from the beginning. You can have thousands of containers in a typical enterprise deployment, and they’re often even more ephemeral than virtual machines, appearing and disappearing in seconds. The problem with containers is that they’re difficult to manage at scale, load balancing and updating them in turn via the command line. It’s like trying to herd a bunch of sheep by dealing with each animal individually.

Enter Kubernetes. If containers are sheep, then Kubernetes is your sheepdog. You can use it to handle tasks across lots of containers and keep them in line. Google created Kubernetes in 2014 and then launched the Cloud Native Computing Foundation (CNCF) in partnership with the Linux Computing Foundation to offer it as an open project for the community. Kubernetes can work with different container systems, but the most common is Docker.

One problem that Kubernetes solves is IP address management. Docker manages its own IP addresses when creating containers, independently of the host virtual server’s IP in a cloud environment. Containers on different nodes may even have the same IP address as each other. This makes it difficult for containers on different nodes to communicate with each other, and because containers on the same host share the same host IP address space, they can’t use the same ports. Two computers on the same node can’t each expose a service over port 80, for example.

Understanding Kubernetes pods and clusters

Kubernetes solves problems like this by grouping containers into pods. Each container in a pod has the same IP address, and they can communicate with each other on localhost. It exposes these pods as services (an example might be a database or a web app). Collections of pods and the nodes they run on are known as clusters, and each container in a clustered pod can talk to containers in other pods using Kubernetes’ built-in name resolution.

You can have multiple pods running on a node (a physical or virtual server). Each node runs its own Kubelet, which ensures that a cluster is in the correct state, along with a kube-proxy, which handles network communication for the pods. Nodes work together to form a cluster.

Kubernetes manages all this using several components. The first is the network overlay, which handles networking between different pods. You can install a variety with a range of capabilities, including advanced ones like the Istio service mesh.

The second component is etcd, which is a database for all the objects in the cluster, storing their details as a series of key:value pairs. etcd runs on a master node, which is a machine used to administer all the worker nodes in the cluster. The master node contains an API server that acts as an interface for all components in the cluster.

A node controller running on the master node handles when nodes go down, while a service controller manages accounts and access tokens so that pods can authenticate and access each other’s services. A replication controller creates running copies of pods across different nodes that run the same services, sharing workloads and acting as backups.

Installing and running Kubernetes

Installing Kubernetes will be different on each machine. It runs not just on Linux, but also on Windows and macOS. In summary, you’ll install your container system (usually Docker) on your master and worker nodes. You’ll also install Kubernetes on each of these nodes, which means installing these tools: kubeadm for cluster setup, kubectl for cluster control, and kubelet, which registers each node with the Kubernetes API controller.

You’ll enable your kubelet service on each of these nodes so that it’s ready to talk to the API. Then initialise your cluster using the kubeadm command kubeadmin init for your master node. This will give you a custom kubeadm join command that you can copy and use to join each worker node to the cluster.

After this, you can create a pod. You define the pod’s characteristic using a configuration file known as a PodSpec. This is often written in YAML («YAML ain’t markup language»), which is a human- and machine-readable configuration format. Your YAML file will define the name space that your pod exists in (you can name Kubernetes clusters differently so that you can run multiple clusters on the same physical machine). 

The PodSpec also defines the details for each container inside the pod, including the Docker images on which they’re based. This file can define a pod-based volume for them in the same pod so that they can store data on disk and share it. You can create a pod using a single command – kubectl create – passing it the name of your YAML file.

Running copies of a pod for resilience and workload sharing is known as replication, and a collection of replicated pods is called a replica set. While you can handle replica sets directly, you’ll often control them using another kind of Kubernetes object known as a deployment. These are objects in the Kubernetes cluster that you use to create and update replica sets, and clear them away when you’re done with them. Replica sets can contain many pods, and a deployment gives you a strategy to update them all (adding a new version, say).

A YAML-based deployment file also contains a PodSpec. After creating a deployment (and therefore its replica pods) using a simple kubectl create command, you can then update the whole deployment by changing the version of the container image it’s using. Do this using kubectl set image, passing it a new version number for the image. The deployment now updates all the pods with the new specification behind the scenes, taking care to keep a percentage of pods running at all times so that the service keeps working.

This is all great, but how do we actually talk to and reference these pods? If we have, say, ten web server pods in a replica set, we don’t want to work out which one’s IP to visit. That’s where Kubernetes’ services come in. We define a service that exposes that replica set using a single IP address and a service name like ‘marketing-server’. You can connect to the service’s IP address or the service name (using Kubernetes’ DNS service) and the service interacts with the pods behind the scenes to deliver what you need.

That’s a short introduction to Kubernetes. As you can imagine, there’s plenty more to learn. If you’re hoping to manage native cloud services in any significant way, you’re going to bump up against it frequently, so it pays to invest the time in grokking this innovative open source technology as much as you can. With Kubernetes now running on both Amazon Web Services and Azure alongside Google’s cloud service, it’s already behind many of the cloud services that people use today.

Paessler PRTG Network Monitor 19.4 review: Outstanding cloud monitoring


Dave Mitchell

18 Mar, 2020

An affordable and feature-rich monitoring solution that will keep an eye on just about anything on your network

Price 
£3,832 exc VAT

If you have a diverse range of hardware and systems to keep an eye on, Paessler’s PRTG Network Monitor could be the perfect solution. It supports no fewer than 257 sensor types – all of which are included in the standard package – so there’s a good chance it will work with everything on your network.

When we say everything, we mean it. PRTG can keep tabs on servers, switches, routers, Hyper-V, VMware and Citrix XenServer hosts, and plenty of cloud services, business apps and storage providers. And since the software updates itself automatically, you’ll get access to new capabilities as soon as they become available: the latest release brings a new health sensor for Fujitsu’s iRMC server management controller, and even expands into Internet of Things territory with a sensor that collects data from IoT-type devices.

Despite all this, you don’t need a powerful server to install the software. You can run PRTG locally on a modestly specified system, or let Paessler host it in the cloud for you. You don’t need to pay for more features than you need, either, thanks to Paessler’s sensor-based licensing. At first you might be alarmed to see how quickly your sensor count gets eaten up, but this is because when PRTG runs its first discovery, it automatically assigns a range of sensors to each device if finds: our Hyper-V server alone accounted for 51 sensors. Happily, it was easy to review these and delete the ones we didn’t require so they were available for use elsewhere. 

The discovery process also sets default alert triggers for each sensor, with alerting options that include mobile push notifications, email, Slack and Microsoft Teams. You can also set alerts to trigger actions such as restarting a service.

The main web console presents not only a complete status overview of your network, but a helpful tree view with all systems tidily organised into hierarchical groups. Moving devices between groups causes them to automatically inherit settings such as discovery schedules and login credentials. 

Spotting problems is easy, as sensors are colour-coded to indicate whether they’re in up, down, paused or warning states and you can instantly drill down into them for more detail. You can also pull up views of the top ten sensors for uptime, downtime, CPU usage, fastest website responses and more.

Cloud support is a real strength of PRTG. It includes seven different Amazon CloudWatch sensors, plus others for Google DriveDropbox and OneDrive, while the SaaS sensor keeps an eye on cloud application platforms such as Office 365Server hardware gets plenty of attention, too: along with a global IPMI sensor, PRTG can directly monitor Dell’s iDRAC controllers and report on physical storage devices and power.

As an alternative to using the web console, PRTG also comes with native Windows and macOS desktop apps, which replace the older PRTG Enterprise console. Alongside full device tree views, the Windows app allowed us to manage sensors, edit multiple objects, drag and drop devices into new groups and enable system tray alerts. The free Android and iOS apps are excellent, giving you convenient remote access to the PRTG server and all sensor data. With the app loaded on our iPad, we had no problem connecting to the core PRTG server, pulling up sensor data on selected systems and receiving push notifications when sensor thresholds were breached.

Businesses that want to monitor everything on their network without having to worry about extra costs or unsupported devices will find Paessler’s PRTG Network Monitor a fine choice. It dishes out sensors a bit more liberally than you’ll probably want, but these can be easily moved to where they’re needed, resulting in a monitoring solution that’s not only highly capable but good value.

Panda Adaptive Defense 360 review: Security in black and white


Dave Mitchell

17 Mar, 2020

Panda’s innovative cloud endpoint protection service fills the gaps other security solutions leave behind

Price 
2147 exc VAT

Panda’s Adaptive Defense 360 (AD360) takes cloud-hosted security to the next level, combining a wealth of endpoint protection features with data control, encryption and patch management tools. This makes it appealing to businesses with GDPR compliance on their minds, as they can protect endpoints from malware, keep them updated with the latest patches and stop data containing PII (personally identifiable information) from leaking, all with a single tool.

AD360’s advanced protection module analyses and classifies every application being run on Windows endpoints and only blocks those it doesn’t know about. It doesn’t stop them from running permanently though; Panda’s cloud service checks the app’s security posture in the background and, if it’s deemed to be safe, will instruct the endpoint client to allow it through.

AD360’s endpoint protection features are extensive, including file, email and web antivirus, a firewall, web filtering and removable device controls for Windows systems. Exchange servers are supported too, and AD360 provides separate antivirus, antispam and attachment content filtering components.

The data protection module scans protected endpoints using machine learning algorithms and regular expressions to detect PII content in a wide range of file formats. It keeps track of all activity and can tell you what each user has been doing with these files such as opening, editing and renaming them, sending and receiving them via email or copying them to removable media.

Panda Adaptive Defense 360 review: Deployment

Deployment is undemanding, thanks to endpoint agents for Windows, macOS, Linux and Android, which can be downloaded from the portal or emailed as a web link. A quicker option for installation on the LAN is to install the agent on one machine first and designate it as a discovery computer.

This scans the network and presents a list of all discovered devices, where you select them and push the agent out remotely. Either way, it only took us a minute to load it on each of our Windows 10 clients after which it contacted the cloud service and applied all our predefined settings. 

All endpoints are dropped into a default group with a base security profile for immediate protection but you can easily create your own groups, each with a set of custom profiles. These are used to define active security services, firewall rules and update frequency while web filtering offers over 60 categories to block or allow and can use daily schedules to determine when it was active.

Initially, you run the advanced protection in ‘audit’ mode where it gathers information about your everyday apps. When you’re ready, you can set it to ‘hardening’ mode which will block unknown external programs until they’ve been assessed, while the ‘lock’ mode includes all local apps as well.

Panda Adaptive Defense 360 review: Patch management

Patch management is an optional feature and requires the endpoint protection or adaptive defense components to be licensed. As with Avast’s Business Patch Management (BPM), it can’t be run on its own but Panda has made a far more professional job of implementing it.

Panda requires Windows automatic updates to be disabled and, unlike Avast’s BPM, it’s all done for you. When creating a patch management policy, you can request automatic updates to be disabled and we found it worked perfectly on all our Windows 10 test clients with no manual intervention required.

Profiles determine a scan frequency of between one hour and once a day and after scanning all our clients, Panda created a list of available updates separated into five criticality levels along with non-security related and service pack groups. Tasks are used to deploy patches and include client groups, a schedule, selected patch groups and third-party products from the software inventory that you also want patched.

Panda then just gets on with the job of patching and provides a task status view that shows which clients are patched and those in progress. If users try to reboot their system during this process, they’ll receive a pop-up message advising them that patching is in progress.

Panda Adaptive Defense 360 review: Data control

The data control component is fully integrated into the web portal and uses profiles to determine what it should search for. To scan and index Office documents, each Windows endpoint requires the Microsoft Filter Pack 2.0 installed which we downloaded straight from the AD360 portal.

You can choose to index only text files but if you opt to index everything on each client, the first run will take many hours and possibly a day. Even so, it’s worth the wait as Panda came back with a heap of valuable information about files residing on our clients that contained PII.

The portal separates them into groups such as personal ID, passport, credit card and phone numbers, email addresses plus bank account details and clicking on a graph category takes you to a list of clients with details of the exact file locations. We could run advanced searches on selected clients to look for keywords and phrases in a range of file types and use the portal to remotely delete unwanted files.

The advanced visualization tool takes this further as it’ll tell you what actions have been carried on these files and when, the application that accessed them, the user responsible and exfiltration risk levels. It provides a lot more information than this though, as it can present detailed reports and graphs on security incidents, malware detections and app controls.

Panda Adaptive Defense 360 review: Verdict

Panda’s Adaptive Defense 360 is a clever cloud security solution that delivers a wealth of endpoint protection features at a great price. It’s easy to deploy and manage, offers sophisticated data control features and whereas other security vendors stumble with patch management, Panda has perfected it.

1&1 Ionos HiDrive Business Pro review: Simple but unsophisticated


Dave Mitchell

13 Mar, 2020

Good, simple cloud file sharing – but administrative controls are minimal and it’s comparatively pricey

Price 
£20 exc VAT per month

One of Europe’s largest hosting companies, 1&1 Ionos is a relative newcomer to the file-sharing party, with its HiDrive service offering a simple cloud file syncing and collaboration solution.

Three plans are available: we tested the top-dog Pro option, which starts at ten users and dishes up 2TB of cloud storage for £20 per month on a one-year contract. That may sound like a bargain, but note that your 2TB isn’t per user, but a total that’s shared across all users.

One notable thing about HiDrive is that it includes a backup service that creates copies of all of your cloud data and retains them for up to a year. This isn’t as smart as the file versioning systems offered by many competitors, but it can be run as often as every four hours, and lets users easily download selected backups from the cloud. The only catch is that these backups count against your storage allocation.

Adding new members to your team is a breeze: invitations can be emailed from the cloud portal and you can choose whether or not each account gets administrative privileges. On opening the invitation, new users will find a link to the web portal, from which they can download the HiDrive desktop app for Windows and choose which cloud folders they want synced to their desktop. Cloud folders can also be conveniently mapped to a local password-protected drive letter. 

If your office runs entirely on Windows, this is great – but be aware that there’s no desktop client for Mac and Linux users, so they will need to use the web portal to get at their data. Alternatively, the administrator can enable access via various protocols, including CIFS/SMB, WebDAV, FTP, SFTP and rsync. Another option is to use the HiDrive mobile apps: the iOS version, running on our iPad, let us view all our cloud data, upload and share files, use the camera to scan documents to the cloud and back the device up.

Another limitation of HiDrive is that it doesn’t give users the ability to share their own personal folders with other team members – something that most competing solutions allow. It does, however, provide a general-access Public folder, which you can make available to all users, and which everyone can optionally synchronise to their desktop like a personal folder. 

While users can’t share folders, they can securely send file links to others – including those without a HiDrive account – directly from either the web portal or Windows Explorer. It’s good to see that, when creating a link, you’re prompted to apply password protection, a download limit and an expiry date. You can also send email requests to non-HiDrive users inviting them to upload files to a password-protected folder.

All data is secured in transit using SSL and encrypted on the HiDrive cloud servers; if you choose the Pro plan then there’s also an end-to-end encryption option, although, surprisingly, it’s actually left to the user to choose whether to apply this and to manage their own encryption keys – something we suspect administrators won’t be delighted about.

The Pro plan also includes a scheduled device backup function, allowing users to have selected local folders automatically copied up to the cloud. Data can be restored from the desktop app or from the portal; again, though, administrators have no control over these processes.

At £20 per month for a shared 2TB of cloud storage, HiDrive Business Pro isn’t the cheapest cloud file-sharing solution out there, and we would be happier if managers were able to take full control of user activities. It is easy to use, though, making it a good fit for smaller businesses seeking uncomplicated file-sharing and syncing services for Windows.