Lloyd’s of London will invest £300m in digital transformation doctrine


Roland Moore-Colyer

12 Dec, 2019

Lloyd’s of London has secured £300 million to fund a digital transformation overhaul to cut its costs and streamline its processes.

A major part of this overhaul, dubbed Blueprint One, will involve the creation of new digital platforms.

A “digital end-to-end platform” will be used to create a portal and a suite of services for handling complex risks in the insurance and reinsurance market, with the goal of supplementing face-to-face negotiations.

APIs will also be used to help connect the platform to insurance brokers’ own systems, while centralised tools such as a tax calculator and compliance checker will help simplify processes. The platform will be supported with information taken from a common data platform.

A digital Lloyd’s risk exchange will also be created for handling less complex risk agreements at high volumes, allowing for brokers to easily create and purchase policies, while also accessing Lloyd’s products and services. To speed up the placement of risks and reduce their costs, algorithms will automatically rate the risks. Again, a centralised tax calculator, compliance checker, and data platform will help ensure risks are created effectively and above board.

“The risk exchange will build on the market’s current investment in e-trading platforms and other technologies to digitise the placement of less complex risks. It will not replace these systems, but will integrate them so they are compatible,” explained the Blueprint One document. “This will benefit market participants by giving them access to a wider customer base, enabling them to leverage the Lloyd’s brand, its global distribution network, economies of scale and lower costs.” 

A suite of other proposed changes, which will be funded by debt rather than charges made on the market’s members, come in response to poor performance and complaints around the high cost of doing business with Lloyd’s of London. 

As such, the digital transformation process, which will enter its first phase next year, is not just a way for Lloyd’s of London to improve internally but to also help bolster its insurance market. 

“This first Future at Lloyd’s blueprint marks an exciting new chapter for Lloyd’s. It sets out how we are going to combine data, technology and new ways of working with our existing strengths to transform the culture we work in and everything we do – from placing risks and paying claims to attracting capital and developing new products,” said Lloyd’s of London’s CEO John Neal. 

This is yet another example of a long-established organisation undergoing a digital transformation doctrine. But such projects vary in scale, with Lloyd’s of London’s Blueprint One being a major undertaking, while other projects can be of a smaller scale, such as the Department for Transport’s goal to create a digital transport data mapping tool

Some projects can be rather different altogether, such as Massachusetts Police’s use of Boston Dynamic robot dogs to sniff out bombs and explore hazardous areas.

Yet regardless of size and scope, there’s a healthy appetite for digital transformation in all manner of organisations and industries, with the goal of taking the latest technology and using it to streamline or redefine how an organisation operates.

Kubernetes as a service: What is it – and do you really need it?

We have seen that, with the acquisition of Heptio, how Kubernetes is well integrated into product stacks of VMware and launched new commercial and open source solutions. 

VMware’s motive is to shift to container based infrastructure powered with Kubernetes and participate in the competitive data centre market. Additionally, Kubernetes has been well received by public cloud and other leading tech vendors by showing full-stack support to manage containers either on bare metal or the cloud.

We are now in the era where every technology backend, infrastructure or platform is being sold in the form of an ‘as a service’ model, Kubernetes is adopted by more than 30 solution providers to offer bundled, managed and customised Kubernetes as a service (KaaS).

But investment, deployment and later management of Kubernetes might raise risks and challenges to organisations that want the rapid transformation to modern infrastructure to support dynamic needs by consumers. KaaS solution providers are coming up with an end-to-end solution that will save them from dead investment and time consumption, plugin most secure way. Let’s understand what KaaS is and what are its benefits and features.

What is Kubernetes as a service (KaaS)?

Kubernetes as a service is a type of expertise offered by a solution or product engineering provider companies, to help customers to shift to cloud-native enabled Kubernetes based platform and manage the lifecycle of K8s clusters.

This can include migration of workloads to Kubernetes clusters; deployment, management, and sustenance of Kubernetes clusters on the customer's data centre. KaaS mainly handles day one and day two operations while moving to Kubernetes native infrastructure, along with features like self service, zero-touch provisioning, scaling and multi-cloud portability.

Why do organisations need KaaS?

In the roadmap of digital transformation to gain a competitive edge in the market, companies are shifting their workloads to containers and integrating container orchestration platforms to manage their containerised workloads. Now, workloads might be applications decomposed into microservices (hosted by containers), backends, API servers, storage units, or so on. To accomplish this procedure, organisations may need expert resources and time to implement the transition. Later on, the sustenance team needs to deal with intermittent issues like scaling, upgrades of K8s stacks, policy changes, and more. 

Organisations cannot afford to spend time as well as money in this transformation as the pace of innovation is rapid. This is where Kubernetes as a service comes in to rescue organisations offering customised solutions based on organisations' existing requirements and scale of the data centre, keeping budget constraints in mind. Some of the benefits of KaaS are:

  • Security: Deployment of the Kubernetes cluster can be easy once we understand the service delivery ecosystem and data centre configuration. But this can lead to open tunnels for external malicious attacks. With KaaS, we can have policy-based user management so that users of infrastructure get proper permission to access the environment based on their business needs. Also, KaaS providers follow security policies that can prohibit most of the security attacks similar to the network firewall.

    Normal Kubernetes implementation exposes API server to the internet, inviting attackers to break into servers. With KaaS, some vendors enable the best VPN options to hide the Kubernetes API server
     

  • Saving in investment for resources: Customised KaaS allows organisations to procrastinate requirements for investment for resources, be it a team to handle KaaS terminals or physical resources to handle storage and networking component within infrastructure. Organisations get a better overview while KaaS is in place
     
  • Scaling of infrastructure: With KaaS in place, IT infrastructure can scale rapidly. It is possible due to high-level automation provided with KaaS. This saves a lot of time and bandwidth of the admin team

What do you get exactly?

Effective day two operations: This includes patching, upgrading, security hardening, scaling, and public cloud IaaS integration. These are all important as container-based workload management comes into the picture. And, when we consider Kubernetes, it may still not fit use cases of the data centre for particular organisations as most of the best practices are still evolving to match up innovation. 

Additionally, if we apply containers in infrastructure positive results should be expected rather than backtracking of strategies. KaaS have predefined policies and procedures that can be customised for organisations to meet ever-changing demands of organisations with Kubernetes.

Multi-cloud portable: Multi-cloud is new trend emerged in 2019 wherein containerised applications will be portable across different public and private cloud. Also, access to existing applications will be shared in a multi-cloud environment. In this case, having KaaS will be useful so that developers can focus on building applications without worrying about the underlying infrastructure. With KaaS, managing and portability will be with the KaaS provider.

Central management: KaaS gives admins to create and manage Kubernetes clusters from a single UI terminal. Admin has better visibility of all components within overall clusters and performs continuous health monitoring using tools like Prometheus and Grafana. Admins can upgrade the Kubernetes stack along with different frameworks used in the setup. 

It is also possible to remotely monitor Kubernetes clusters, check for any glitches in configuration, and send alerts. Additionally, the KaaS admin can apply patches to clusters if they find any security vulnerability associated with the technology stack deployed within clusters. Admin can reach out to any pods or containers in a network of the different clusters using a single pane of glass provided with KaaS.

Conclusion

Implementing Kubernetes is not just a solution, but it might create several issues that can cause security as well as resource consumption. Kubernetes as a service offerings are a breather for enterprises and organisations ranging from large scale to small scale who already have shifted workloads to a containerised model or are planning to do so. 

KaaS can increase the deployment speed of the Kubernetes cluster along with a raise in the performance of containerised infrastructure. With KaaS, organisations get single-handed support for their infrastructure which will allow them to focus on the services layer.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Google reveals UK’s most searched for terms in 2019


Roland Moore-Colyer

11 Dec, 2019

Google has revealed the most searched for terms and questions in 2019, with its Year in Search, with the UK taking a bigger interest in the Rugby World Cup than Brexit.

The most searched for term in the UK for 2019 was the aforementioned Rugby World Cup, followed by the Cricket World Cup, and then Game of Thrones.

The search results are largely explained by a strong British showing in both tournaments, while the incredibly popular HBO series Game of Throne came to an end after eight seasons in May, with tensions and plotlines ramping up.

However, both the term Chernobyl and Thanos took the fourth and fifth positions respectively. Those results are a little more surprising, as, given the heavy media coverage of Brexit and other governmental machinations, one could be forgiven for thinking that ‘Brexit’ would be a highly searched term, but in the end, it failed to even make the top ten list for Google searches in the UK.

In fact, no political terms made it into the top 10 list, with the likes of the iPhone 11 and Caitlyn Jenner proving more popular than Boris Johnson or Jeremy Corby. Neither did Extinction Rebellion get a look in, despite the protests and demonstrations in the year gaining high-profile coverage, as well as support and equal measures of condemnation.

When it came to the most searched for news events, ‘revoke Article 50 petition’ came in third place, behind the ‘iPhone 11’ and ‘Notre Dame’ at the top spot.

As for the questions being asked by the Google Search users in the UK, ‘how to watch Champions League Final’, ‘how to watch Game of Thrones’ and ‘how to floss dance’ took the first, second, and third positions respectively.

‘How to register to vote’, seemingly pertinent given the General Election on Thursday 12 December, came in eighth place, being beaten by ‘how to eat a pineapple’.

While IT Pro endeavours to bring you the latest IT news and its effect on the UK public sector, politics and society, it would appear that many of Britain’s Google Search users are more interested in finding out about subjects that matter to them in the here and now, rather than longer-term effects of politics and technological change.

1. Rugby World Cup
2. Cricket World Cup
3. Game of Thrones
4. Chernobyl
5. Thanos
6. Notre Dame
7. Avengers Endgame
8. iPhone 11
9. Caitlyn Jenner
10. Joker

Ericsson shells out $1bn to settle bribery charge


Nicole Kobie

10 Dec, 2019

Swedish telecoms giant Ericsson has settled with US authorities on charges including bribery, shelling out more than $1 billion (£759m) to avoid prosecution – one of the largest such settlements to date.

The US Department of Justice (DoJ) was investigating Ericsson under the Foreign Corrupt Practices Act (FCPA) that bans companies listed on US stock exchanges from bribing foreign officials, accusing it of making and improperly recording tens of millions of dollars in «improper payments» around the world.

Ericsson admitted that from 2000 and 2016 employees paid bribes to government officials to help win contracts in five countries – Djibouti, China, Vietnam, Indonesia and Kuwait – covering up that activity via false accounting records, sham contracts and fake invoices.

An Ericsson subsidiary pleaded guilty to bribery as part of the deal.

«Today, Swedish telecom giant Ericsson has admitted to a years-long campaign of corruption in five countries to solidify its grip on telecommunications business,» said U.S. Attorney Geoffrey S. Berman of the Southern District of New York. «Through slush funds, bribes, gifts, and graft, Ericsson conducted telecom business with the guiding principle that ‘money talks.’ Today’s guilty plea and surrender of over a billion dollars in combined penalties should communicate clearly to all corporate actors that doing business this way will not be tolerated.»

According to the DoJ, between 2010 and 2014, Ericsson paid $2.1 million in bribes in Djibouti to help the company win a contract worth €20.3 million to modernise the state-owned telecoms company. The money was sent via a consulting company – the owner of which was married to a government official – and hidden via fake invoices. A similar system was used to pay $450,000 to help it win a contract in Kuwait worth $182 million between 2011 and 2013.

In Vietnam, again according to the DoJ, Ericsson’s subsidiaries paid $4.8 million to a third-party consulting firm to set up a slush fund to pay off companies that the company wouldn’t be able to directly hire because of the company’s due diligence processes; the money was «mischaracterised» in the company’s books. A similar system was used in Indonesia to set up a $45 million slush fund, the investigators said.

And in China, between 2000 and 2016, Ericsson’s subsidiaries paid tens of millions for travel and entertainment for government officials, including some that worked at state-owned telcos, and also made payments for sham contracts with providers in the country for «services that were never performed».

Don Fort, the chief of criminal investigation at the Internal Revenue Service tax agency, said a lack of compliance and internal controls at the company made it easier for executives and other employees at Ericsson to offer bribes and falsify accounting records.

«Ericsson’s corrupt conduct involved high-level executives and spanned 17 years and at least five countries, all in a misguided effort to increase profits,» said Assistant Attorney General Brian A. Benczkowski of the Justice Department’s Criminal Division, adding that the «strong response from law enforcement» should deter other companies from doing the same.

Under the agreement, the DoJ will defer prosecution of Ericsson and dismiss all charges after three years if the company complies with the rest of the conditions, which include reforming its compliance and submitting to an independent compliance monitor. As part of the deal, Ericsson Egypt pleaded guilty to the Djibouti bribery charges.

The company noted that the payment of $1.06 billion is fully covered by $1.2 billion set aside in the third quarter of 2019. Half of that bill is a criminal fine, the DoJ said, while the other half will be paid to the US Securities and Exchange Commission for related civil charges.

The DoJ noted that the criminal penalty half of the fine had a 15% reduction because Ericsson had partially cooperated with the investigation – though it was criticised for failing to disclose allegations of corruption, not producing materials in a timely manner, and failing to «take adequate disciplinary measures with respect to certain employees involved in the misconduct».

According to reports, in a conference call CEO Borje Ekholm said the company wanted to move forward. «Certain employees in some markets, some of whom were executives in those markets, acted in bad faith and knowingly failed to implement sufficient controls,» Ekholm said. «I view what has happened as a completely unacceptable and hugely upsetting chapter of our history.»

The SEC has previously fined a wide range of companies under the FCPA, including a $6.3 million settlement with Barclays over hiring practices in Asia, $11.7 million from Juniper Networks to «resolve violations» of accounting and recordkeeping in China and Russia, and $1.78 billion from Petroleo Brasileiro over a bribery and bid-rigging incident.

This exploit could give users free Windows 7 updates beyond 2020


Keumars Afifi-Sabet

10 Dec, 2019

Members of an online forum have developed a tool that could be used to bypass eligibility checks for Windows 7 extended support and receive free updates after the OS reaches end-of-life.

Only a handful of Windows 7 users can continue to receive updates from Microsoft through its paid-for Extended Support Updates (ESU) programme after 14 January, through to January 2023.

This scheme was first introduced for enterprise customers in August and later extended to SMB users after Microsoft identified “challenges in today’s economy”.

The ESU programme is not available to all businesses, however. Users on tech support platform My Digital Life have therefore developed a prototype tool that could theoretically allow ineligible businesses to continue to receive free updates beyond 14 January.

Before ESU patches are beamed to eligible machines, Windows 7 performs a check to determine whether or not users can receive these updates. This involves the installation and activation of an ESU license key. The created tool bypasses this eligibility check, which is only performed during installation, so users would, in theory, continue to receive Windows 7 updates for free through the ESU scheme without paying an ESU subscription.

The bypass was tested on the Windows 7 update KB4528069, a dummy update which was issued to users in November so they could verify whether or not they were eligible for extended support after 14 January.

Although the tool has worked on the test patch, its creators urged My Digital Life forum members to consider this as a prototype, and not a fully-fledged workaround, as things may change by February 2020.

Microsoft will be keen to ensure there aren’t any ways to undermine the ESU scheme once Windows 7 reaches end-of-life due to the sums it’s charging eligible businesses, and an ultimate desire to shift machines to Windows 10.

The firm is likely to change the way the eligibility check is performed given how simple it’s been proven to bypass.

It’s certainly not a tool that Microsoft is likely to condone, but it does demonstrate the extent to which Windows 7 is still popular as users are trying to retain undisrupted access to the legacy OS.

Businesses have just weeks to upgrade their devices running Windows 7 and Windows XP or face restrictions on accessing critical security updates.

Microsoft launches Office 365 phishing campaign tracker


Keumars Afifi-Sabet

10 Dec, 2019

Microsoft has devised a phishing campaign dashboard for its Office 365 Advanced Threat Protection (ATP) module to give customers a broader overview of phishing threats beyond just individual attacks.

The newly-announced ‘campaign views’ tool provides additional context and visibility around phishing campaigns. This aims to give businesses under constant threat from phishing attempts a fuller story of how attackers came to target an organisation, and how well attempts were resisted. 

Security teams with access to the dashboard can see summary details about a broader campaign, including when it started, any activity patterns and a timeline, as well as how far-reaching the campaign was and how many victims it claimed. 

The ‘Campaign views’ tool also provides a list of IP addresses and senders used to orchestrate the attack, as well as the URLs manifested in the attack. Moreover, security staff will be able to assess which messages were blocked, delivered to junk or quarantine, or allowed into an inbox.

“It’s no secret that most cyberattacks are initiated over an email. But it’s not just one email – it’s typically a swarm of email designed to maximize the impact of the attack,” said Microsoft group program manager with Office 365 security Girish Chander. 

“The common pattern or template across these waves of email defines their attack ‘campaign’, and attackers are getting better and better at morphing attacks quickly to evade detection and prevention. 

“Being able to spot the forest for the trees – or in this case the entire email campaign over individual messages – is critical to ensuring comprehensive protection for the organization and users as it allows security teams to spot weaknesses in defenses quicker, identify vulnerable users and take remediation steps faster, and harvest attacker intelligence to track and thwart future attacks.”

Office 365’s ATP tool is an email filtration system that safeguards an organisation against malicious threats posed by email messages, links and any collaboration tools. 

With the additional information at hand, Microsoft is hoping that security teams within organisations can more effectively help compromised users, and improve the overall security setup by eliminating any configuration flaws. 

Related campaigns to those targeting the organisation can also be investigated, and the teams can help hunt down threats that use the same indicators of compromise.

The ‘campaign views’ dashboards are available to customers with a suite of Office 365 plans including ATP Plan 2, Office 365 E5, Microsoft 365 E5 Security, and Microsoft 365 E5.

These new features have started rollout out into public preview, with Microsoft suggesting the features are expected to be available more generally over the next few days and weeks.

Why cybersecurity needs to focus more on customer endpoints going forward

  • Cloud-based endpoint protection platforms (EPP) are proliferating across enterprises today as CIOs and CISOs prioritise greater resiliency in their endpoint security strategies going into 2020
  • Gartner predicts that global information security and risk management end-user spending is forecast to grow at a five-year CAGR of 9.2% to reach $174.5 billion in 2022, with approximately $50bn spent on endpoint security
  • Endpoint security tools are 24% of all IT security spending, and by 2020 global IT security spending will reach $128bn according to Morgan Stanley Research
  • 70% of all breaches still originate at endpoints, despite the increased IT spending on this threat surface, according to IDC

There’s a surge of activity happening right now in enterprises that are prioritising more resiliency in their endpoint security strategies going into 2020. The factors motivating CIOs, CISOs, IT, and practice directors to prioritise endpoint resiliency include more effective asset management based on real-time data while securing and ensuring every endpoint can heal itself using designed-in regenerative software at the BIOS level of every device.

CIOs say the real-time monitoring helps reduce asset management operating expense, a big plus many of them appreciate give their tight budgets. Sean Maxwell, chief commercial officer at Absolute, says, “Trust is at the centre of every endpoint discussion today as CIOs, CISOs and their teams want the assurance every endpoint will be able to heal itself and keep functioning.”

The endpoint market is heating up going into 2020

Over thirty vendors are competing in the endpoint security market right now. A few of the most interesting are Absolute Software, Microsoft, Palo Alto Networks, and others who are seeing a surge of activity from enterprises based on discussions with CIOs and CISOs.

Absolute Software’s Persistence self-healing endpoint security technology is embedded in the firmware of more than 500 million devices and gives CIOs, CISOs and their team’s complete visibility and control over devices and data. Absolute is the leading visibility and control platform that provides enterprises with tamper-proof resilience and protection of all devices, data, and applications.

Like Absolute, Microsoft is unique in how they are the only vendor to provide built-in endpoint protection at the device level, with the core focus being on the OS. Windows 10 has Windows Defender Antivirus now integrated at the OS level, the same System Center Endpoint Protection delivers in Windows 7 and 8 OS. Microsoft Defender Advanced Threat Protection (ATP) incident response console aggregates alerts and incident response activities across Microsoft Defender ATP, Office 365 ATP, Azure ATP, and Active Directory, in addition to Azure.

Further evidence of how enterprise customers are placing a high priority on endpoint security is the increase in valuations of key providers in this market, including Absolute Software (TSE: ABT) and others. Absolute’s stock price has jumped 13% in just a month, following their latest earnings announcement on November 12th with a transcript of their earnings call here.

Absolute’s CEO Christy Wyatt commented during the company’s most recent earnings call that, “The ability to utilise near real-time data from the endpoint to… to deliver actionable insights to IT about where controls are failing and the ability to apply resilience to self-heal and reinforce those security controls will become a critical skill for every one of our customers. This is the essence of Absolute’s platform, which adds resiliency to our customer’s operations.” It’s evident from what CIOs and CISOs are saying that resiliency is transforming endpoint security today and will accelerate in 2020.

Key takeaways from conversations with enterprise cybersecurity leaders

The conversations with CIOs, CISOs, and IT Directors provided valuable insights into why resiliency is becoming a high priority for endpoint security strategies today. The following are key takeaways from the conversations:

  • Known humorously as the “fun button” cybersecurity teams enjoy being able to brick any device any time while monitoring the activity happening on it in real-time. One CIO told the story of how their laptops had been given to a service provider who was supposed to destroy them to stay in compliance with the Health Insurance Portability and Accountability Act (HIPAA), and one had been resold on the back market, ending up in a 3rd world nation. As the hacker attempted to rebuild the machine, the security team watched as each new image was loaded, at which time they would promptly brick the machine. After 19 tries, the hacker gave up and called the image re-build “brick me"
     
  • IT budgets for 2020 are flat or slightly up, with many CIOs being given the goal of reducing asset management operating expenses, making resiliency ideal for better managing device costs. The more effectively assets are managed, the more secure an organization becomes. That’s another motivating factor motivating enterprises to adopt resiliency as a core part of the endpoint security strategies
     
  • One CIO was adamant they had nine software agents on every endpoint, but Absolute’s Resilience platform found 16, saving the enterprise from potential security gaps. The gold image an enterprise IT team was using had inadvertently captured only a subset of the total number of software endpoints active on their networks. Absolute’s Resilience offering and Persistence technology enabled the CIO to discover gaps in endpoint security the team didn’t know existed before
     
  • Endpoints enabled with Resiliency have proven their ability to autonomously self-heal themselves, earning the trust of CIOs and CISOs, who are adopting Absolute to alleviate costly network interruptions and potential breaches in the process. 19% of endpoints across a typical IT network require at least one client or patch management repair monthly, according to Absolute’s 2019 Endpoint Security Trends Report. The report also found that increasing security spending on protecting endpoints doesn’t increase an organizations’ safety – and in some instances, reduces it. Having a systematic, design-in solution to these challenges gives CIOs, CISO, and their teams greater peace of mind and reduces expensive interruptions and potential breaches that impede their organizations’ growth.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Box Business Plus review: Cloud storage that’s very hard to beat


Dave Mitchell

10 Dec, 2019

Business cloud collaboration at its best, with unlimited storage, tight security and great management features

Price 
£19

Box is one of the most capable file-sharing services on the market, offering a great range of cloud collaboration features. Those come at a price, mind you: the Business Plus version on review costs £20 per user each month, with a modest 5% discount if you pay yearly.

Still, we can’t complain too much when every user gets a classy selection of file-sharing and syncing services, and unlimited cloud storage. Or, to be precise, there’s no limit on total usage; – there’s a 5GB limit on the size of each uploaded item, which is a long way short of Citrix ShareFile’s 100GB cap, but for the average small business that won’t be a problem at all. 

Administrators, meanwhile, get a wealth of management tools, with features including user activity tracking and enhanced reporting. If your business has data residency requirements, you can take advantage of the Box Zones add-on, which lets you choose precisely where your files will be stored. Options include AWS in London and Azure in Cardiff, with pricing starting at £4 per month – although you should note that Box Zones is only available to customers with a minimum of ten users.

To set users up on Box, you simply send each one an email invitation from the Box admin portal. After they have accepted, they will be able to log in to their personal cloud portal, view their cloud folders, create new ones and invite colleagues to share their contents. Box lets you finely specify exactly what sort of access each collaborator should have, with seven permission levels ranging from view-only to co-owner.

It’s also possible to securely share files with collaborators outside of the company, by enabling the Share Link option and sending an email. If you want to receive a file from someone else, you can generate a secure link that allows them to upload a file directly to your cloud folder. 

One aspect of Box that’s a bit confusing is the way it presents a choice of two different client apps to download. Box Sync provides standard syncing services between a user’s local folder and their cloud repository to ensure all versions are kept up to date, while Box Drive aims to save local hard disk space by keeping all your folders in the cloud – although you can select specific files and folders for offline access. It may not be obvious to a user which one they should install, and the two apps won’t coexist on the same system so a little support might be necessary to help people get the right client. 

You might also be disappointed to discover that, although you can grant folder access to an unlimited number of collaborators – including those outside of your organisation – each one needs their own Box account to access the share.

On the plus side, Box can do some very clever and useful things. File versioning is included as standard: Starter subscriptions get access to 25 old versions, while Business Plus customers get 50 versions and the Enterprise tier ups the limit to 100. The free Box Tools utility lets you edit documents in the cloud, too – a clever trick, although it’s a bit annoying that Microsoft Edge isn’t currently supported.

Then there’s the free Box Relay Lite automation tool, which lets you create simple workflows that can, for example, move newly uploaded files from one folder to another, or ask another user for approval. On top of all this, the Business Plus subscription also supports up to three SaaS integrations with external apps, such as Slack and Salesforce

The choice of desktop apps may confuse users, but overall Box is an excellent package of cloud file-sharing and collaboration services. The Business Plus plan is expensive, but if you want top-notch security, an insight into user activity and the ability to choose where their data resides, it’s very hard to beat. 

IDC picks Trend Micro as the top vendor in SDC workload protection

Cybersecurity solutions provider Trend Micro has been named as the number one vendor in Software-Defined Compute (SDC) workload protection in IDC’s latest report.

Trend Micro company achieved a market share lead of 35.5% in 2018. Steve Quane, Trend Micro’s network defence and hybrid cloud security executive VP, said: “We predicted a decade ago that organisations would need multi-layered security to protect their cloud environments and software-defined data centres.”

Frank Dickson, IDC’s security and trust program vice president said: “For years, Trend Micro has steadily built out its SDC workload protection capabilities for virtual, public cloud and container environments, offering tight integration with AWS, Azure and Google Cloud Platform.”

"Although the future has not been written, Trend Micro is the dominant player in this market," he added.

Real-time security has been embedded into running applications over this time and Trend Micro has made sure that it focuses on security-as-code and automation in order to seamlessly build protection into DevOps pipelines, including pre-runtime scanning of container images. This carries on with the launch of XDR in the month of August.

XDR plays an important role in correlating data across network, server, email, endpoint, and cloud workloads in order to identify spiteful activity which might otherwise go unnoticed.

In the month of October, Trend Micro further built on these capabilities by its move to acquire Cloud Conformity, a leader in security posture management. The firm announced the launch of its cloud security services program called Trend Micro Cloud One to address security challenges faced by customers around storage, data centre, IaaS, serverless architectures and containers.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Winning the IT availability war: How to combat costly downtime

Analysts predict global enterprises will spend nearly $2 trillion on digital transformation by 20221. With digital initiatives and technology becoming ubiquitous with business today, one would think that companies would be more than ready for a world where virtually every touchpoint with customers is digital. Unfortunately, the fact that Target, British Airways, Facebook and Twitter all experienced major IT outages in 2019 suggests there is still work left to do to keep services and an optimal customer experience up and running smoothly.

To explore precisely what enterprises are doing to detect, mitigate and hopefully prevent outages LogicMonitor commissioned an IT Outage Impact Study. The independent study surveyed 300 IT decision makers at organisations in the US, Canada, UK, Australia and New Zealand to discover whether or not IT leadership is concerned about “keeping the lights on” for their businesses. The research revealed a stark reality at odds with today’s omnipresent digitisation: IT teams are concerned about their ability to avoid costly outages, mitigate downtime, and reliably provide the 24/7 availability that customers and partners demand.

Are outages inevitable?

IT teams worldwide agree on two things: performance and availability are top priorities for their department. These two mission-critical priorities, in fact, beat out security and cost, which is surprising considering how much attention security gets in today’s data-breach heavy environment.

Yet IT’s intense focus on keeping the network up and running at peak performance has not prevented downtime. In fact, 96% of survey respondents report experiencing at least one IT outage in the past three years, which is bad news if performance and availability are considered make or break areas for modern organisations.

Common causes of downtime include network failure, surges in usage, human error, software malfunction and infrastructure that fails. What is surprising, however, is that enterprises report that more than half of the downtime they experience could have been prevented.

Worryingly, IT decision makers are pessimistic when it comes to their ability to influence all-important availability. More than half (53%) of the 300 IT professionals surveyed say they expect to experience a brownout or outage so severe that the national media will cover the story, and the same percentage said someone in their organisation will lose his or her job as a result of a severe outage.

This begs the question: if even the most skilled technical experts in IT can’t prevent outages, who (or what) can?

The true costs of downtime

Negative media coverage and career impacts aside, downtime comes with additional costs for organisations. Survey respondents identify lost revenue, lost productivity and compliance-related costs as other factors associated with IT outages and brownouts (periods of dramatically reduced or slowed service). And these costs add-up quickly. Organisations with frequent outages and brownouts experience:

  • 16 times higher costs associated with mitigating downtime than organisations with few or zero outages
  • Nearly two times the number of team members to troubleshoot problems related to downtime
  • Two times as long to troubleshoot problems related to downtime

How to win the availability war

If more than half of outages and brownouts are avoidable, according to 300 global IT experts, then every organisation should be taking proactive steps to prevent these disruptive events. The best-performing organisations are already working to prevent costly downtime. Consider taking the following actions to do the same:

  • Embrace comprehensive monitoring. In today’s digital world, many companies operate in a hybrid IT environment with infrastructure both on-premises and in the cloud. Trying to spot trends using siloed monitoring tools for each platform is inefficient and prone to error.

    Identify and implement software that comprehensively monitors infrastructures, allowing the team to view IT systems through a single pane of glass. Consider extensibility and scalability during the selection process as well to ensure the platform integrates with all technologies – present and future
     

  • Use a monitoring solution that provides early visibility into trends that could signify trouble ahead. Data forecasting can proactively identify future failures and ultimately prevent an outage before it impacts the business. Teams should build a high level of redundancy into their monitoring systems as an additional method to prevent downtime and focus on eliminating single points of failure that might cause a system to go down
     
  • Don’t wait to create an IT outage response plan. Hopefully it will never be needed, but it’s critical to have a defined process for handling outages from escalation and remediation to communication and root cause analysis. Set a plan on who to involve (and when) to ensure IT can respond quickly if an outage does occur

While the 2019 LogicMonitor’s 2019 Outage Impact Study revealed that downtime is surprisingly common, it also showed that top-performing organisations are able to banish downtime from their day-to-day operations through advanced planning and comprehensive monitoring software. In the end, it is possible to win the IT availability war, with the right combination of skilled team members and powerful SaaS monitoring technology. But every minute of downtime is pricey – so there’s no time to waste.

Read more: Most outages can potentially be avoided, argues IT – yet the business side is pessimistic

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.