Why attaining hybrid IT nirvana means a mix of digital growth and ‘digital trust’

In many organisations today, IT is more than a utility: it has become an essential platform for their ongoing business development. Therefore, they crave a superior IT experience for their employees and other key stakeholders. For most, cloud computing is a fundamental ingredient of the digital transformation agenda.

The common commercial use cases for public cloud services have already been exploited by many organisations. Front-office applications, such as customer relationship management, online commerce, and numerous consumer-facing apps, constitute the bulk of the workloads that reside on cloud service provider shared infrastructure.

These initial use cases have validated the proven benefits of cloud computing architectures that are appealing to software developers – including speed of deployment, dynamic resource acquisition, application elasticity, and service reuse across workloads.

Leveraging the inherent benefits of cloud service offerings, organisations are now focused on the potential of utilising IT infrastructure for innovation, process improvement, streamlined operations, entering new markets, and the creation of a preemptive response to potential disruption by new tech startups.

According to the latest worldwide market study by the IBM Institute for Business Value (IBV), organisations report success with public cloud initiatives, especially those forward-looking business transformation projects related to digital growth.

Meanwhile, mission-critical, security-dependent applications — such as customer databases, transaction processing, finance and accounting, supply chain, and manufacturing — are somewhat less likely to reside on a public cloud service provider’s platform.

This is particularly true for highly regulated industries, such as financial services and healthcare, where the greatest proportion of their online business processes have yet to move to a cloud service delivery model.

In many cases, these computing and storage workloads are better suited to the private cloud — or a mixture of public, private, and non-cloud traditional IT infrastructure.

In order for the next phase of cloud computing benefits to be realised, an open and adaptable approach to IT infrastructure architecture is required to address the multitude of use cases.

The evolution of cloud services adoption

The hybrid IT model permits public clouds, private clouds, and on-premises non-cloud IT infrastructure to connect across all three standardised technology interfaces: Linux OS, Open Container Initiative, and Kubernetes. These technologies enable developers to innovate with scale and agility, improving responsiveness and constraining cost, despite growing complexity.

Hybrid IT enables workloads to be deployed on the optimal compute and storage environment.

  • Public clouds are well suited for many front-office workloads.
  • Private clouds are well suited for many of the mission-critical workloads where the benefits of cloud are desirable — but the security and assurance of a private environment are preferred.
  • And traditional IT environments are suited for workloads that don’t inherently take advantage of cloud benefits — and demand the dedication of computing resources.

According to the IBM IBV assessment, as hybrid cloud solutions become widespread, there will be more variations of cloud service adoption across all industries. However, in the more regulated industries, the cloud service mix will tilt toward private cloud adoption, rather than public cloud. In the less regulated industries, the cloud service mix will likely tilt the other way.

In all cases, there’s a universal need to interoperate between public, private and traditional IT.

Hybrid cloud’s intrinsic interoperability and portability can mean that organisations are less likely to become locked in to a proprietary environment or to one particular public cloud service provider. Savvy CIOs and CTOs will choose to place their workloads on the best-fit platform and maintain interoperability between IT environments and between different public cloud service providers.

Why freedom to choose matters

Hybrid cloud can also help to address security concerns and other potential barriers to an otherwise successful cloud service deployment. The IBM IBV research study findings indicate that IT security and governance are the two top reasons cited as justification to keep enterprise workloads on-premises.

Armed with hybrid cloud solutions, organisations can run applications and store data in the specific IT environments best aligned with security, regulatory, and governance requirements.

Hybrid cloud also allows enterprises to manage their cloud transition dynamically, selecting acceptable levels of downtime and overcoming the possibility of operational constraints.

The next chapter in the evolving cloud computing story is about gaining access to enhanced capabilities – in particular, the cloud-enablement of complex mission-critical software apps.

The IBM IBV outlined key steps toward the hybrid cloud model:

Architect the destination: Think open, multi-cloud, hybrid cloud. Your organisation will live with the decisions you make today for years. Think through which of your workloads fit best in the public cloud, private cloud, and traditional IT environments. Avoid both environment lock-in (to only one of the three) and vendor lock-in, and reassess approaches that might not survive as standards and technologies evolve.

Sequence the journey: Avoid “ready, fire, aim” approaches. Layout a careful, clear roadmap of what you want to do and in what order. You may experience pressure to skip ahead without building a solid, open foundation. Resist it.

Mobilise the right skills and assets: Draw upon talent within and outside your enterprise. It’s important to develop and maintain in-house skills, but working with trusted third-party services providers, enabled by greater interoperability, can help bridge short-term gaps while reducing fixed costs.

Manage to create clear outcomes: Establish meaningful qualitative and quantitative measurements and be tenacious in holding to them. Remain flexible and incorporate new technologies as they emerge. Always stay true to your business, architectural, and technical principles.

The hybrid IT strategy questions to ask include:

  • To what extent do your people understand the implications and opportunities of next-generation cloud on your business and your competitive environment?
  • How is your organisation, and your competition, taking advantage of hybrid cloud, particularly data and processes that, until recently, have been difficult to move?
  • What adjustments have you made in hiring and training to have the right people at the right time working on the right things in dynamic ecosystems powered by hybrid cloud?

The quest for hybrid IT nirvana

In summary, organisations will continue to seek the essential benefits of a hybrid model because it offers them the freedom of choice that forward-thinking CIOs and CTOs require. Put simply, they’ll need the flexibility and agility of a Hybrid IT environment to achieve their bold goals for digital transformation.

From the C-suite perspective, this quest isn’t about technology. Rather, it’s about applied IT enabling strategic business outcomes. The goal: deliver a unified experience across platforms that abstracts the underlying IT infrastructure. The ‘everything-as-a-service’ platform accelerates the achievement of commercial objectives. It also reduces the risk of cyber threats by assuring digital trust.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

ZMcare LLC’s Zakia Miami Argan Oil and Castor Oil and Their Benefits

It is derived from the plant Ricinus communis, also called the castor oil plant. Castor beans get pressed into a versatile, pale-yellow vegetable oil with a very distinct flavor and smell. As mentioned, it has immense moisturizing benefits, so it can soften flaky skin and infuse life into it. It can also provide a barrier on the skin and protect against moisture loss. For hair, it acts as a lubricant, coating and conditioning strands to improve smoothness and shine. To put it in a nutshell, you must add it to your beauty regimen immediately.

read more

How delivering seamless UX and improving business outcomes will dovetail in 2020

The way that consumers and end-users interact with businesses and their services has changed dramatically in the last decade. Today, nearly every transaction is supported by applications, meaning the role of IT has evolved from being a back-office function to a strategic enabler that makes the difference between success and failure for everyone in the business. 

If organisations want to succeed in 2020 and beyond, they need to deliver seamless user experiences. The only way to achieve this is with a multidisciplinary view of user experience and digital services across the organisation. Digital business application owners, IT and DevOps teams need to understand the direct link between user experience, application performance and business outcomes.

Struggling with tunnel vision

However, while the data to unlock that insight is already flowing through the business and being analysed, it’s usually siloed across disparate tools. This makes it nigh on impossible to understand data in context and turn it into actionable answers that can improve business outcomes.

These silos have evolved as different teams within the organisation have adopted their own tools for a variety of use cases. These tools all provide important information, but their siloed nature leaves individual teams with tunnel vision, as they are unable to see the wider context of what each set of data means for the business as a whole.

As a result, it is very difficult to determine the impact IT performance has on business outcomes without a lot of manual correlation. That takes time and in some cases is nearly impossible to do at all given the dynamic and complex nature of modern cloud environments. As such, it fails to provide actionable answers when they’re needed most – in real-time.

Looking at the bigger picture

To make more informed decisions and prioritise efforts to optimise digital services based on the impact on business outcomes, organisations need access to software intelligence that provides context. For example, IT teams and application owners could use business and application performance data to prioritise initiatives to improve customer journeys based on how revenues and conversions are being affected. This can only be achieved by breaking down the silos between tools and implementing a common data model that ties user experience, customer behaviour and application performance data together with business metrics.

If that data model is combined with deterministic AI, which provides precise insights into the root cause of anomalies, it’s possible to analyse the vast quantities of data flowing through the organisation and uncover real-time answers to business questions. In some cases, these answers can be used to automate remediation, so teams within the business don’t even need to manually intervene and resources can be used more effectively to provide better outcomes for the organisation.

Getting ahead of the game

Ultimately, today’s businesses live or die based on the ability to deliver perfect software and seamless digital journeys. In such an environment, it’s crucial that everyone in the organisation has access to real-time answers that reveal how business outcomes are being impacted by application performance. That’s impossible to achieve if everyone is just looking at their own piece of the puzzle.

Digital business application owners, IT and DevOps teams need to put their heads together and work collaboratively to see the full picture of what’s happening. By breaking down the walls between tools and taking a new, multidisciplinary approach to how they run the business, organisations can leap ahead of their competitors in 2020, by unlocking the answers they need to improve business outcomes.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Goodbye 2019, hello 2020: The year in cloud reviewed – and what is on the horizon

To say 2019 was a busy year for cloud would be no surprise. Yet the past 12 months has seen innovation, expansion, and drama which represents a poke in the eye for those who dismiss the industry as being consolidated and saturated.

Without any further ado, here is CloudTech’s traditional look back on the year in focus – and what the following 12 months will have in store for industry players and watchers alike.

The new hybrid cloud: Outposts leads and others follow

It was the hottest topic as 2018 drew to a close; the launch of AWS Outposts, with VMware as partner in crime, which promised to deliver a ‘truly consistent hybrid experience’ to ‘virtually any’ on-premises facility.

Naturally, as Microsoft and Google’s big events rolled around in 2019, attention turned to this area above all others. Google Cloud Next in April saw the launch of cloud services platform Anthos. Or, rather, it was a relaunch: to ‘build and manage modern hybrid applications across environments’, as well as accommodate AWS and Azure. In November, Microsoft launched Azure Arc, and outlined its theory of ‘hybrid 2.0’. Hybrid capabilities ‘must enable apps to run seamlessly across on-premises, multi-cloud and edge devices’, as Azure CVP Julia White noted at the time.

This means that the three largest cloud vendors are in a state of ‘collaborative détente’ right now, in the words of Pivot3 CMO Bruce Milne. Speaking to CloudTech at VMworld in August, Milne noted of the ‘obvious strategic tension’ to “watch this space because that friction is sure to generate sparks eventually.”

Kurian’s busy year as Google’s cloud chief

Another area industry watchers pencilled in for 2019 was how Thomas Kurian would take over the mantle left behind by Diane Greene as Google Cloud’s CEO. Among the in-tray items for the new boss were expansion and enterprise sales – or in the case of the latter, at least talking a good game.

This was exemplified in Kurian’s debut speaking slot as chief executive. At a Goldman Sachs conference in February, the former Oracle executive told delegates that old-school sales tactics were key to pushing Google’s message of differentiation. How has that gone? It’s hard to say; while Google still remains shy when it comes to revealing specific cloud figures, the overall soundbites have been solid around customer momentum and partnerships, while Anthos was well received.

As far as 2019 went, Google was the busiest hyperscaler in terms of acquisitions. While AWS had CloudEndure at the start of the year and Microsoft moved for Movere in September, Google’s shopping list had four items in total. Alongside Looker, the biggest deal, were moves for enterprise data pipeline provider Alooma, storage firm Elastifile, and VMware workload runner CloudSimple. New expansion areas included Poland, Switzerland, and Japan.

Open source providers open a can of worms

Maintaining your open ethos and turning a profit is frequently an area of tension, particularly for companies who deal in cloud and big data software. Indeed, 2019 was set to be a vital year for open source development in this context; the IBM-Red Hat acquisition hinted at it.

So it proved. In February, Redis Labs modified its licensing terms with this in mind, before having to change them again to appease open source and developer communities. The change meant developers were free to use the software, modify the source code et al – which they of course were always allowed to do – stipulating that the end result could not be a database, caching, search, indexing or stream processing engine, or anything to do with machine learning, deep learning, or artificial intelligence.

The month before, Confluent secured a $2.5 billion valuation having undergone a license change of its own. At the time, co-founder Jay Kreps maintained that the way forward building fundamental infrastructure layers was with open code. “As workloads move to the cloud we need a mechanism for preserving that freedom while also enabling a cycle of investment, and this is our motivation for the licensing change,” he wrote.

Speaking to CloudTech at the time of the change, Redis CEO Ofer Bengal said that, aside from AWS – frequently cited as the primary culprit for this behaviour – ‘the mood [was] trying to change’ between the big clouds and open source software providers. The proof of this theory was borne out in April, when Google Cloud announced at Next what it described the ‘first integrated open source ecosystem’ with seven vendors. Confluent and Redis Labs were both part of this group, with Bengal joining Kurian on stage to announce the deal.

Trump’s turn: Microsoft pips AWS to JEDI contract in shock decision

For the vast majority of 2019, the common consensus was that Amazon Web Services would secure the $10 billion JEDI (Joint Enterprise Defense Infrastructure) cloud contract. Yet many were not banking on the intervention of the US President. In July, around the time Oracle’s legal challenge was running out of gas, President Trump announced he was looking at the procurement process, citing complaints from multiple rivals.

In October, the Department of Defense announced Microsoft had won the contract. Many industry pundits took to link the stormy relationship between the president and Jeff Bezos to explain the decision; a book from former secretary of defence James Mattis alleged that President Trump told him to ‘screw Amazon’ out of the contract.

AWS has, not surprisingly, sought to appeal the ruling. Aside from the procurement process itself, this publication explored the definition of multi-cloud in a federal context. The award was, and always had been, for a single provider – a bone of contention in itself. Yet given AWS has been running the CIA’s cloud for years, what does this mean? “The DoD argued [it needed] one supplier simply because [they] need the level of tight integration and security,” cloud pundit Bill Mew told CloudTech in October. “I totally buy that if that’s their argument – but then why are they not going to the same supplier the CIA has?”

2019’s major cloud mergers and acquisitions

October: Digital Realty acquires Interxion for $8.4bn in biggest data centre deal of them all
August: VMware moves in for Pivotal and Carbon Black at combined $4.8bn
June: Google Cloud looks to Looker in $2.6bn all-cash deal for greater multi-cloud analytics
June: Salesforce to acquire Tableau for $15.7bn to combine AI with BI bulk (link to MarketingTech)

2020 outlook

Henrik Nilsson, vice president EMEA, Apptio

As seen in other software industries, overly aggressive price wars would likely upset the cloud market. As a result, AWS, Azure and Google Cloud Platform will all continue to enhance their specialities in 2020 – for instance focusing on scale, or a specific sector, or AI capabilities – to provide differentiation.

This will have a knock-on effect on costs. Apples to apples comparisons of pricings is already difficult, but moving forward businesses will have to do a much better job of tying value to cloud to make the right decisions for their business needs. In 2020 companies will need to establish a cloud centre of excellence and a ‘FinOps’ mindset, whereby all areas of the business have greater understanding of, and accountability for, cloud spend.

Dave Chapman, head of customer transformations, Cloudreach

The new era of enterprise cloud adoption will be among ‘cloud-native businesses’; organisations built directly with the cloud’s scalability and efficiency in mind. We’ve already seen how valuable it can be to have this agility built into a company’s DNA – look no further than the behemoth that is Netflix – so in 2020, expect to see more organisations migrating workloads to the cloud in an effort to meet the growing demands of today’s digital businesses.

Sanjay Castelino, chief product officer, Snow Software

Today’s cloud infrastructure is relatively easy to understand compared to what it will look like in 2020 and beyond. For example, when provisioning a cloud instance today, a user only needs a basic idea of how it operates and what it will cost. But when new cloud approaches like serverless become more popular, cloud usage will be managed by the people writing code.

In serverless computing, the code drives the cost to deliver the service, and businesses are not yet prepared to deal with these new consumption models. In the next year, companies need to priorities understanding consumption models because those models will have a significant impact on their business.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

The scariest security horror stories of 2019


Cloud Pro

27 Dec, 2019

In what has become a regular feature here at IT Pro, we’re back again to take a look at some of the year’s most dramatic security stories, many of which were scarily similar to those we saw in 2018.

What’s clear is that businesses continue to face the same old threats, although you’ll see from our picks that there are plenty of examples of attackers using ingenious methods to breach systems.

Here’s our pick of 2019’s scariest security stories.

VFEmail’s nightmare year

The first entry on our list, and one of the earliest of 2019, involved an attack on US email provider VFEmail. In what was described as a catastrophic breach on VFEmail’s systems in February, the company’s infrastructure had been virtually wiped out overnight, with every disk on every server, including its backups, being destroyed.

Perhaps the most chilling part of the story is that there appeared to be no apparent motive behind the attack and that VFEmail may have been targetted randomly. No ransom was ever offered in exchange for the data, nor was there any evidence that the attacker was even interested in stealing the data.

Despite the loss, VFEmail remained committed to staying operational, although the company would come under repeated attack throughout the rest of 2019. Customers would face phishing attacks over the following few months, only for the main service to be hit by three consecutive DDoS attacks in late October and early November. To date, work is still ongoing to restore full functionality to its services.

NASA narrowly averts catastrophe

Next up we have one of our most widely read stories from the year, and an example of how the miss-handling of relatively new hardware can pose a serious threat to legacy systems. In June, NASA revealed that a Raspberry Pi device had been blamed for a 2018 data breach that saw the theft of 500MB of mission system data.

An employee was said to have brought a Raspberry Pi into work without permission and connected it to NASA’s Jet Propulsion Laboratory network, which a hacker later targetted to gain access to adjoining systems.

The incident sparked a wider investigation into the organisation’s systems and networks, which found myriad flaws in its database management techniques and methods used to track devices and applications using internal networks. It was ruled that the JPL network was, in fact, incapable of detecting whether an unauthorised or unsecured device was attached to its network.

The report issued ten urgent recommendations for fixing NASA systems, all but one of which were implemented immediately. NASA was fortunate in this instance, as the relatively minor security incident revealed far greater problems plaguing its systems, which were mercifully fixed before disaster could strike.

Hackers at the door

For our next entry, we fast forward to November, where a vulnerability in Amazon’s Ring doorbells was discovered that could allow hackers to intercept their owner’s Wi-Fi passwords.

Researchers at Bitdefender discovered that by accessing a Wi-Fi network’s credentials, criminals could launch much larger and far more sophisticated attacks against a household. This was possible as the device stored passwords in plain text which were then communicated between a smartphone app and the doorbell using HTTP rather than the far more secure HTTPS.

The news prompted further calls for tougher legislation around the manufacture of connected devices, particularly when they are destined for the home.

King’s Cross, we barely recognise you

In what will likely set a precedent for the use of cutting-edge technology in public spaces, August saw an investigation by the Information Commissioner’s Office into the use of facial recognition technology at King’s Cross.

Private owners of the 67-acre site, which houses 50 buildings and is home to major companies such as Google, said they had introduced facial recognition technology alongside their CCTV system to improve the on-site public experience. However, both campaign groups and the Mayor of London Sadiq Khan criticised the decision as it was unclear precisely how the technology was being used. It also raised serious concerns about the capturing of personal data without consent.

The technology was eventually scrapped at the site, however, the owners have not ruled out the possibility of the technology returning at a later date.

The Collection Folders

What’s unusual about 2019 is that it only took 17 days before we saw what would be one of the largest data leaks of the year. Between late January and early February, a group of researchers determined that around 600GB worth of personal data had been leaked and was circulating online in caches known as «Collection» folders.

The initial discovery of the Collection #1 folder unearthed 773 million unique email addresses and 22 million passwords, figures that were then dwarfed when Collection folders 2 through 5 were then found. In total, it’s believed that around 2.2 billion emails and passwords were in the complete cache, now being shared around hacking forums.

It’s also believed that the data is an amalgamation of various leaks sourced from high profile data breaches, such as the enormous Yahoo hacks of 2013 and 2014. Despite the age of the data, security experts believe that criminals have relied on a lax approach to password hygiene and that many of the email and password pairs could still be exploited.

Citrix vs IRIDIUM

In March, Citrix revealed that it was working with the FBI to look into a breach on its systems after a number of documents had been reported stolen. Initial reports were light on detail, mainly as only very brief statements were issued by the company, and it would only be through the release of a report by cyber security firm Resecurity that we’d learn that around 6TB of data had been swiped in the raid.

The company had a number of high-profile customers at the time, including large corporations and both the US military and government.

Resecurity had traced the attack back to an Iranian hacking group known as IRIDIUM, which had bombarded a number of Citrix accounts with commonly used passwords, known as password spraying, before gaining a foothold. After this, the group was then able to methodically bypass each additional security layer, including two-factor authentication.

The IRIDIUM group had reportedly targetted hundreds of thousands of people at more than 200 companies during the previous two years leading up to the hack on Citrix, according to figures provided by Microsoft.

Microsoft: «We told you so…»

One of our most-read stories of the year actually surfaced at the beginning of December.

According to Microsoft threat researchers, 44 million of its customers were still using passwords that had been compromised in the past by large scale data breaches. This included both general users of Microsoft Service Accounts, as well as Azure Active Directory accounts owned by businesses.

Following a check on a database of three billion credentials sourced from public accounts and law enforcement, it was found that the 44 million customers were using the same compromised passwords across a number of online services.

The discovery forced Microsoft to issue a password reset to all affected customers, including an alert to business admins to reset user credentials. The company also urged customers to turn on multi-factor authentication.

Despite the shocking figure, the news potentially served as a great PR for Microsoft – the company has long been attempting to move customers away from passwords onto more secure passwordless authentication. The company revealed to IT Pro in November that it had managed to move 100 million customers to biometric authentication, although it would take at least three more years to move the remaining 700 million users.

XSS the most widely-used attack method of 2019


Keumars Afifi-Sabet

23 Dec, 2019

The most widely-used cyber attack method used to breach large companies in 2019 was cross-site scripting (XSS), according to research. 

The hacking technique, in which cyber criminals inject malicious scripts into trusted websites, was used in 39% of cyber incidents this year.

This was followed by SQL injection and Fuzzing, which were used in 14% and 8% of incidents respectively. Among other widely-used methods are information gathering, and business logic, although both were used in less than 7% of incidents.

With 75% of large companies targeted over the last 12 months, the report by Precise Security also revealed the key motivation behind cyber crime has been the opportunity for hackers to learn.

Almost 60% of hackers conducted cyber attacks in 2019 due to the fact it presents a challenge. Other prominent reasons for hacking a company’s systems include to test the security team’s responsiveness, and to win the minimum bug bounty offered. ‘Recognition’ ranked sixth in the list of motivations, and was cited by just 25% of hackers. Bizarrely, 40% also said that they preferred to target companies that they liked.

Digging into industry-specific insights, additional research published this month also revealed the most prominent attack method faced by sectors within the UK economy.

The most prevalent hacking technique in the business, finance and legal sectors, for example, was macro malware embedded into documents, according to statistics compiled by Specops Software. 

Retail and hospitality firms, meanwhile, suffered mostly from burrowing malware, present in 51% of attacks, as did governmental organisations, registering 37% of incidents.

The healthcare industry was susceptible mostly to man-in-the-middle attacks, in which communications between two computer systems are intercepted by a third-party. 

Distributed denial of service (DDoS) attacks were the most common form of attack faced by the technical services industry, with 58% of incidents using this method.

As for how these attacks are conducted specifically, the Precise Security report showed that 72% of platforms used as a springboard for cyber crime are websites. WordPress, for example, is a prime target due to the massive userbase, with 90% of hacked CMS sites in 2018, for instance, powered by the blogging platform.

Application programme interfaces (APIs) were the second-most targeted platforms in 2019, being at the heart of 6.8% of incidents, with statistics showing Android smartphones are usually involved in such attacks.

How to improve cloud management through a cloud resource tagging policy

Good cloud governance relies on good tag hygiene: a disciplined, well-designed approach to tagging.

In the multi-cloud environments that enterprises are embracing, implementing enterprise-grade cloud governance platforms is the key to successful management of highly complex pricing structures and evolving cloud services. Using automation to maintain good tag hygiene will support critical governance initiatives for cloud security, cloud cost reporting, and cloud cost optimisation.

Applying a consistent set of tags—specifically for governance—globally across all of your resources will add metadata specific to your organisation. This can help improve categorisation of each of your cloud resources for cost allocation, reporting, chargeback and showback, cost optimisation, compliance, and security. Once implemented, a robust tagging policy will enable your organisation to optimise costs across all cloud providers and guarantee that your company has access to all of the cloud services it requires.

Understand tagging policy

In the absence of a tagging policy, it’s all too common for individuals or teams to use variations of the same tag. When this happens, accurate reporting becomes extremely difficult. To avoid these complications, and to ensure that tags are used effectively for governance and reporting purposes, having a tagging policy is absolutely critical.

A well-defined tagging policy incorporates:

  • Global tags, including how they will be applied consistently by all applications and teams in the organisation. The first table below provides recommended global tags; use this as a starting point from which your organisation can customise with specific tags and naming conventions.
  • Each cloud provider’s tags. As each cloud provider has different limits and restrictions on tags, your tagging policy must accommodate these parameters. The second table below identifies tags for AWS, Azure, and Google Cloud (GCP).
  • Guidelines for how individual teams or applications may add additional tags for their specific needs.
  • Consistent naming conventions, including spacing, uppercase/lowercase conventions, and spacing.

Automation is key to implementing tags. For example, if you are using a cloud management platform for provisioning, all templates should be set up to attach the appropriate tags.

Implement and monitor your tagging policy

Create a staged rollout process for your tagging policy. This will help ensure effective implementation and monitoring, aided by buy-in from all relevant parties.

  • Stage 1: Define the tagging policy: Have your cloud governance team lead a process to define a global tagging policy. The team should work with key stakeholders to get feedback and buy-in. Once this team specifies the required global tags, development teams and resource owners should be responsible for adding the global tags. Central IT may assist with scripts and tools
     
  • Stage 2: Reporting: The cloud governance team creates reports that show the current state; track improvements in tag coverage; and identify the level of coverage for global tags, by team or group. Distribute these reports weekly
     
  • Stage 3: Alerting: Your cloud governance team sets up daily automated alert emails about resources that are missing the required tags. (An organisation may choose to stop at Stage 3 if it has achieved the desired adoption of global tags)
     
  • Stage 4 (optional): Alerting with automated termination or escalation: The cloud governance and central IT teams should also set up automated “tag checking” to alert on missing tags and enforce the use of tags. Alerts on untagged resources specify a defined window (e.g. 24 hours) to tag resources. Enforcement could include sending an escalation to managers or, in some cases, adding default tags or even terminating instances that aren’t tagged correctly (only for non-production workloads)

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Google services knocked offline after fibre cables cut


Bobby Hellard

20 Dec, 2019

Fibre optic cables in two separate areas were cut at the same time on Thursday morning, leaving parts of Eastern Europe, Iran and Turkey without internet access.

The severing of cables belonging to a third-party telecommunications provider resulted in a loss of connectivity for Google between Bulgaria and the rest of its production network. The issue lasted for two hours and took down Google’s services in those regions.

Sadjad Bonabi, a director at Iran’s Communications Infrastructure Company, told the BBC that two cuts happened at once: one between Iran and Bucharest and the other on a line to Munich.

Multiple cuts to fibre optic cables happening at the same time is a very rare occurrence, according to Google, which also said it has now launched an investigation into the incident.

«The issue with multiple simultaneous fibre cuts affecting traffic routed through Google’s network in Bulgaria has been resolved for all affected users as of 2019-12-19 2:36 US/Pacific,» Google Cloud’s status dashboard said. «Google services were not reachable for users who were accessing these Google services primarily through our Bulgaria network point of presence.»

«We have identified the root cause and routed affected traffic around the impacted parts of our network. We are conducting an internal investigation and will provide a detailed public incident summary at a later date.»

The UK has also experienced a number of incidents involving cable theft or damage throughout 2019. In August and September a spate of attacks on broadband cabling in Cambridgeshire left 4,000 homes and businesses without internet access, with 500 metres of copper wiring stolen as a result.

Amazon criticises New York Times’ reporting of open source theft concerns

AWS vice president Andi Gutmans has penned a scathing response to an article highlighting concerns that Amazon is stealing the innovations of startups.

New York Times journalist Daisuke Wakabayashi wrote an article titled Prime Leverage: How Amazon Wields Power in the Technology World in which he highlighted several cases where Amazon is said to have "strip-mined" (as startups have coined it) open source technology.

The main example is of Amsterdam-based startup Elastic that was rapidly expanding and whose product, ElasticSearch, was already available for AWS. In 2015, Amazon said it was going to copy the freely-available ElasticSearch and make it a paid service.

Amazon began making more cash than Elastic by offering deeper integration with its own products. Elastic responded by making premium features which Amazon then reportedly copied and made free.

Elastic is now suing Amazon for violating its trademark by calling their own product ElasticSearch. In the complaint, Elastic stated that Amazon "misleads customers". The court case is still pending.

Wakabayashi goes on to highlight other cases where Amazon is accused of the aforementioned strip-mining. One is MongoDB, which Amazon is said to have copied the “look-and-feel” of an older version. Furthermore, when AWS customers search for "MongoDB" from the management console, they are provided with Amazon's own alternative which states that it's “compatible with MongoDB.”

During a dinner which MongoDB's chief executive Dev Ittycheria had with the heads of six other tech firms, the conversation reportedly switched to whether to publicly accuse Amazon of behaving like a monopoly.

Wakabayashi even sourced comments from people who actively decided against making their products open source due to fear that Amazon would copy them.

"The journalist largely ignores the many positive comments he got from partners because it’s not as salacious copy for him," Gutmans said in a blog post.

However, not all of the cases highlighted by Wakabayashi were negative. Databricks' chief executive Ali Ghodsi said that AWS salespeople lifted the sales of his company's products and that he doesn't "see them using shenanigans to stop us."

Gutmans insisted that Amazon "contributes mightily to open source projects" and that "AWS has not copied anybody’s software or services."

It must be reiterated that Elastic is not suing Amazon for copying its product as it was open source. Executives from MongoDB, on the other hand, suggested to SiliconAngle earlier this year that they believe Amazon's DocumentDB is a copy of their product that's “based on MongoDB code from two years ago.”

Rightly or wrongly, it's clear there are serious concerns within the industry about how Amazon is wielding its power. Reaching out to understand why executives from these companies hold such concerns would be a more productive approach than criticising journalists for reporting them.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.