10 years of DevOps: With the hype cycle moving on – what’s next?

This year marks 10 years since the term DevOps was first coined, during a now legendary presentation at a Toronto tech conference.

Anyone who’s seen the 90s brawler film Fight Club will know—the first rule of Fight Club is: you don’t talk about Fight Club. All those years ago, IT professionals weren’t part of Fight Club—but a small number formed their own underground DevOps club. But even though the first rule of DevOps Club is, “always talk about DevOps,” it’s taken a decade to catch on in a significant way.

Finally, DevOps doesn’t seem so underground. And like many actually-good-for-you approaches, the small movement of IT professionals pursuing a better vision for operations management, is being consumed by the vendor hype cycle. Capitalising on this, many vendors have plastered their websites with DevOps SEO terms to market a multitude of dubious DevOps-in-a-box solutions.

Those truly familiar with the process will already know—DevOps needs to be initiated internally. Its success doesn’t lie in third-party solutions; it lies in people and culture shifts. Despite lots of companies today claiming they’re “doing DevOps,” many still experience the problems solved by agile ways of working. In SolarWinds' 2018 IT Trends Report, IT pros named inadequate infrastructure and organisational strategy as the top two barriers to achieving optimal IT performance.

The good news is, hype cycles around trendy IT terms and solutions inevitably come to an end. In the next few years, when vendors and commentators have shifted their attention to the next buzzword, DevOps will be given room to grow organically and reach its true potential.

The waiting game

Once industry commentators have had their field day and moved on from DevOps, the developers who created the concept for themselves in the first place can own it once again. It’s these developers who, from firsthand experience, know about the IT challenges and goals today’s enterprises face. Once DevOps is aligned to address these common problems, it’ll become a concept you can better apply in IT environments.

All enterprises must understand, however, DevOps—real DevOps—will take time. Developers and Ops work in fundamentally different ways, which could spark arguments and disagreements in the first days, even months, of DevOps working. Management should hold their nerve and let these initial difficulties run their course—because once they have, these teams will be well on the way to DevOps nirvana.

DevOps is a process made by technologists, for technologists—external pressures will only hinder the process. Let’s take virtualisation as a case in point. Virtualisation was once the “cool” new concept every enterprise wanted to adopt. Like the situation today, vendors were putting pressure on data centre professionals to prematurely introduce virtualisation with subpar software and servers. Technologists resisted and waited until they were ready—these wholesale technological shifts aren’t simply “bolt-on” solutions. Now we can’t think of IT operations without virtualisation.

Despite its uniquely transformative potential, the adoption of DevOps is ultimately following the same blueprint as many new approaches before it. There’s been the successful early adopters, and increasingly (some) enterprises have taken up the charge. The suggests we’re moving closer to the hype decline phase, where even late adopters may finally get to enjoy the same longer weekends and faster change rates of the early adherents a decade ago.

The new standard

But where should DevOps be for you? And what would that look like?

In the next five years, traditional operations teams will discover at least a few DevOps practices help solve complex problems thrown up by new technologies. Better, it’s not necessary to accept the full dogma of DevOps or Agile to see systems benefits and new ways of working like DevOps.

The benefits of these remodeled IT environments are only growing in popularity. A 2018 survey of 2,400 developers and general IT professionals, conducted by the Cloud Native Computing Foundation, found the use of serverless technology had grown 22% in one year. As enterprises look to reap the benefits of digital transformation and cloud native technologies, the adoption rate of DevOps will only grow.

It’s not surprising cloud native and serverless environments are where DevOps have shown significant early results. Automation of standard tasks and the breaking down of data silos is precisely what’s needed to speed up delivery time and render critical problems easier to solve. Once enterprises begin to witness the impact of DevOps in these high-visibility scenarios—they’re likely to see value and want to extend DevOps ways into other areas of IT.

As adoption picks up, IT professionals and developers will increasingly expect all of their tools and technologies to be totally compatible with DevOps. The runaway success of tools like Gradle, Git, and Jenkins reflects the growing numbers of IT professionals who are prioritising tools speeding up deployment times and facilitate the collaborative ways of working that are fundamental to DevOps.      

It’s not too soon for vendors to start catering to DevOps—in fact, it’s high time they did. The annual Google Cloud Accelerate State of DevOps report analyses data from thousands of IT pros to provide a health check of the DevOps industry. This year’s report found the self-reported number of what Google classes as “elite DevOps performers” has almost tripled, now at 20% of all organisations.

All of these organisations in part identify by tools that compliment how their teams work. The rise of DevOps isn’t just inevitable—it’s evident. Vendors need to stop using “DevOps” as SEO juice and manfully incorporate DevOps-friendly features, especially for established enterprise technologies.

Give and take

Bringing about the future of DevOps will require IT professionals to make some unnatural adjustments. They need to learn and embrace automated deployment pipelines and learn at least the basics of code. But fundamentally, IT professionals need to come to terms with their own reservations about automation and experiment. That’s the path to understanding the value that DevOps brings.

Many hype-weary IT professionals might feel threatened by the automated solutions accompanying DevOps, and understandably so. But checking with peers, most discover even just the automation techniques of DevOps presents greater career opportunities. Increasingly, IT professionals are becoming accustomed to automating their “work” and realise the skills benefits of doing so. Some even report they’d never go back to waterfall operations again. Perhaps it’s just the reduction of overnight and weekend maintenance windows.

The hype cycle engulfing DevOps is finally subsiding, and this is a Great Thing. One by one, developers and operations engineers are discovering DevOps isn’t yet another overlay requirement like ISO, but a set of culture and process changes that realigns IT to meet the goals of today’s businesses. When we see a vendor slide mention CDV (Continuously Delivered Value™) we’ll know we’re on the way. IT teams have always understood this, and who doesn’t like tools increasing speed to market, greater innovation, and being associated with services users appreciate.

Read more: DevOps learnings: Why every successful marriage requires a solid foundation

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Google’s cloud remains on a solid course – even if Alphabet earnings missed expectations

Alphabet posted earnings which missed analyst expectations – yet as the company’s ‘other revenues’ bucket continues to grow, the word on Google Cloud remained positive from the executives.

Other revenues, of which Google Cloud is a part – the company continues to not show its full hand – reached $6.42 billion (£5.01bn) for Q319, an increase of 38.5% year on year and a rise of almost 4% from the previous quarter.

Profit for the overall business declined 23%, with the earnings of $10.12 per share falling well below Wall Street expectations of $12.42. However, total revenues of $40.5bn were seen as positive, with advertising revenues up 17% from this time last year.

Google Cloud’s highlights in Q3 were varied and legion. In terms of product and footprint, the company continued its European expansion with a launch in Poland last month, while the release of Dataproc on Kubernetes in the same month solidified Google’s leadership at container management for an enterprise level. On the partnership front, deals were struck in August with VMware, extending the companies’ collaboration, as well as with enterprise blockchain provider Cypherium.

Alphabet CEO Sundar Pichai was keen to evangelise the gains made by Google Cloud, particularly noting ‘customer momentum across multiple areas on [Google Cloud CEO] Thomas [Kurian’s] leadership’ to analysts.

Pichai elaborated on how Google Cloud customers fit in to other emerging areas when fielding an analyst question around quantum computing, an area in which Google declared ‘supremacy’ last month. “This is an important tool in the arsenal,” said Pichai. “While quantum will take many years to really start making a difference, we want to be at the cutting edge of driving it.

“I do think over time for sure, we do see a lot of interest from Cloud customers, particularly in cutting-edge verticals about quantum computing – so that’s an area where I think [we] will participate in as a business,” added Pichai.

Analysts had previously been asking Google to disclose specific figures around its Cloud business. In Q1, Goldman Sachs analyst Heather Bellini posed that very question, only to get a committed non-committal in response. This is understandable; as each of the cloud infrastructure giants count their beans with different methods, specific numbers may be seen as an apples versus oranges comparison. Microsoft continues to give Azure revenues in terms of percentages rather than an exact number, while AWS – which does give specifics – hit almost $9bn in its most recent quarter.

You can read the full Alphabet earnings release here.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Cloud investments dent Google’s Alphabet earnings


Bobby Hellard

29 Oct, 2019

Google parent Alphabet’s quarterly earnings were dented by heavy investment in its cloud computing business.

The tech giant missed analysts estimates for third-quarter profit by about $1.7 billion, though it beat revenue estimates by about $175 million.

Google is the world’s leading provider of internet search, advertising and video services, but Google Cloud is a key segment of its overall business. Currently, this part of its operation is a distant third to rivals AWS and Microsoft’s Azure.

The company has said it will continue to spend on cloud, AI and consumer hardware as it looks to compete in these «new areas».

«Our businesses delivered another quarter of strong performance, with revenues of $40.5 billion, up 20% versus the third quarter of 2018 and up 22% on a constant currency basis,» said Ruth Porat, CFO of Alphabet and Google. «We continue to invest thoughtfully in talent and infrastructure to support our growth, particularly in newer areas like Cloud and machine learning.»

Net income in Q3 was $7.1 billion, or $10.12 a share, down from $9.2 billion, or $13.06 a share, in the same period a year earlier, the company reported on Monday. According to data compiled by Bloomberg, analysts expected $12.35 a share.

Google has been building data centres, buying equipment and recruiting engineers and salespeople to support its cloud unit. CEO Thomas Kurian was hired at the end of 2018 from Oracle to help in this regard.

Quarterly estimates for the other major cloud providers have seen the opposite; cloud computing has boosted revenue. Leading the way, AWS has annually recorded increased earnings for the last five years.

Establishing itself in second, Microsoft has invested heavily in Azure, making a number of shrewd acquisitions this year, and announced that Azure’s 73% growth had pushed Microsoft up to a market cap of $1 trillion, in April.

«In many of these areas we are the new entrant and we create competition, and sometimes the competitive pressures can lead to concerns from others,» CEO Sundar Pichai said.

How to avoid the big upcoming cloud storage problem – which could run you down

When organisations migrate to the cloud they have an application problem: deciding which apps to migrate and in what order as well as which ones to reconfigure as cloud-native. 
Once in the cloud they have a data problem: budgets that are flat or in decline and data volumes that are growing exponentially.

Where people go wrong is thinking ONLY about the application problem in advance. All too often when we cross the road we look left or right when we should be looking both left AND right.

It is wrong to think of cloud as a commodity. Cloud price wars have eased and the pace of decline in prices for cloud compute and storage has slowed almost to a halt. The reason for this shift is market maturity, with people having more faith in the cloud model than they once did. 451 Research analysts have said that the cloud has not yet become a commodity and as such, the cloud market is "not highly price-sensitive" at the moment, despite businesses wanting to get the best deals they possibly can.

CIOs are often overly focused on the cost of compute, where the cost of compute is not decelerating as fast as it did during the height of the price war. However, they should also be focusing on the cost of object and block storage. Prices for storage may have more scope to fall than for compute, but if you’re being charged for data and your data is growing exponentially then you have a problem.

Few, if any, organisations are throwing away any of their old data and new data is being added at an exponential rate – a rate that will only increase with 5G and IoT. This exponential explosion in the volume of data is a real problem.

Many of us are some way down the cloud path. Most of the initial gains that we experienced from moving to the cloud came from the low hanging fruit. Such gains came from transformational projects that could deliver immediate improvements in service or reductions in cost, or that addressed the most immediate challenges at hand.

Typically, though, we put off the biggest challenges, those that would require either organisational transformation, including interdepartmental collaboration and structural reform, or technological transformation, including re-engineering or refactoring applications from the ground up. 

For many organisations, the easy gains have already been realised and the real challenges lie ahead.

Indeed, many of the easy gains came from virtualised applications that could easily be ‘lifted and shifted’ to the cloud and connected to cloud-based block storage. Now with budgets that are flat or in decline and data volumes that continue to grow, there is a looming crisis relating not only to the ongoing cost of data storage, but also to the cost of both ingress and egress [The cost of moving data and applications into the cloud (ingress) or move anything out of the cloud (egress) or even moving it between regions].

Things should be fine for those that ‘looked both ways’ and ensured that such costs were calculated in advance and built into the business case. However, those that ‘only looked left’ will have been hit from the right by unexpected costs that are outpacing the growth of their budgets. Indeed, all too many CIOs have gone from being unintelligent in their use of data in legacy environments to unintelligent in their use of data in the cloud.

If you, like many, have been overly focused on the cost of infrastructure and compute, but as quickly as savings have already been realised (and the easy ones have all been realised already), you have started experiencing exponential data growth and with it cost, and you’re locked in by egress charges, then you’ve got a BIG problem. Even if you are using existing commercial infrastructure or commodity cloud services to cap infrastructure costs, if your data use is unintelligent or is growing fast, both of which are true in many organisations, then your costs will be spiralling in the wrong direction.

The only way out is to 1) rationalize your data and 2) find an intelligent longer-term solution for your data storage that doesn’t lock you in to a single cloud provider and doesn’t include egress or ingress charges.

Thankfully there are multi-cloud storage solutions, like HPE’s new Cloud Volumes service, that not only include AI to maximise the intelligence with which you manage your storage, but provide a direct link to both your own on prem systems as well as all the public cloud providers, but are also free of ingress and egress charges (once you bitten the bullet and met the initial one-off charge from your current cloud provider of moving any existing data onto this new platform).

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Microsoft beats AWS to $10bn JEDI contract: Defining multi-cloud and analysing administrative influence

Analysis The announcement from the Department of Defense (DoD) on Friday that Microsoft had been awarded the long-detailed $10 billion JEDI (Joint Enterprise Defense Infrastructure) cloud computing contract elicited responses of surprise from many in the industry.

The release confirming the contract to Microsoft made for interesting reading. Transparency was the name of the game: the award was ‘conducted in accordance with applicable laws and regulations’, it ‘cleared review by the GAO and Court of Federal Claims’, with all bids ‘treated fairly and evaluated consistently with the solicitation’s stated evaluation criteria.’

Yet one paragraph up, the DoD notes that the award ‘continues [its] strategy of a multi-vendor, multi-cloud environment… as the department’s needs are diverse and cannot be met by any single supplier.’

Arguably the biggest point of discussion around the entire procurement focused on the single or multi-cloud approach. Writing for this publication in August, David Friend, CEO of cloud storage provider Wasabi, made his opinions on multi-cloud clear.

“We will see the cloud market become increasingly decentralised in the years to come, as more specialist vendors spring up to meet specific customer needs at better prices,” wrote Friend. “We just have to hope the JEDI contract doesn’t feed the giant at the expense of the competition being able to grow.”

The contract award has potentially done that, though perhaps not in the way Friend intended. Noting Amazon’s market leadership in cloud infrastructure, an argument can be made that, on business terms, giving this award to a strong, entrenched second player – as Microsoft is – would facilitate a continued competitive market.

The question remains, however: is this single cloud or multi-cloud? AWS has been running the CIA’s cloud for the better part of half a decade; confirmation arrived in February 2015 that it was running on ‘final operational capability.’

Cloud pundit Bill Mew sees it as the latter given AWS’ other commitment – but criticised the procurement process. “A lot of people were arguing that it should be a multi-cloud bid and therefore open up to a number of different competitors,” Mew told CloudTech. “The DoD argued the reverse – we need one supplier simply because we need the level of tight integration and security.

“I totally buy that if that’s their argument – but then why are they not going to the same supplier the CIA have?” Mew added. “There are going to be hundreds of other government sector contracts coming up. You have to think at an overall strategic level within government – is the single cloud approach the one we’re taking or are we actually going to ascribe a multi-cloud approach where we want a healthy market? And if so, why didn’t we set out right at the outset what the interoperability standards are within that environment?”

Rumour and conjecture has been rife regarding the process behind the contract award. Around the time Oracle’s initial legal challenge around its exit from the process was dismissed, President Trump announced he was looking into the contract, citing – as reported by CNBC – “tremendous complaints from other companies.” According to the same publication on Saturday, former secretary of defence James Mattis claims in a new book that President Trump told him to ‘screw Amazon’ out of the contract.

Mew argues that, should AWS challenge this award – the Washington Post cites one legal analyst who said it was a ‘virtual guarantee’ – its case will be ‘far stronger’ than Oracle’s.

“I’m normally somebody who trusts the system, but there’s already been so much of a mess in terms of this procurement, and we have an administration here who have shown themselves to be not entirely unopen to bias,” he said. “One has to have a level of cynicism. I think it will all come out in time.”

One other fact to consider is around the contract itself. $10 billion is a naturally eye-catching number – Microsoft noted in its financials last week ‘material growth’ in $10 million Azure deals – but the contract has plenty of wiggle room. DoD official communications note a two-year base contract period with $1m guaranteed.

“This is an enormous vouch of credibility for Microsoft and Azure – there’s no taking away from how important this is to them,” said Mew. “However, if you look at the contract, it doesn’t mandate that $1bn is spent every year, it is a very flexible framework.”

A statement from AWS read: “We’re surprised about this conclusion. AWS is the clear leader in cloud computing, and a detailed assessment purely on the comparative offerings clearly lead to a different conclusion. We remain deploy committed to continuing to innovate for the new digital battlefield where security, efficiency, resiliency, and scalability of resources can be the difference between success and failure.”

When asked about plans to appeal, AWS did not return comment at publication time.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Hosting online banking in the public cloud a ‘source of systemic risk’ amid rising IT failures


Keumars Afifi-Sabet

28 Oct, 2019

The financial services industry is not doing enough to mitigate a rising volume of IT failures, spurred on by a reluctance to upgrade legacy technology, a parliamentary inquiry has found.

Regulators, such as the Financial Conduct Authority (FCA), are also not doing enough to clamp down on management failures within UK banks, which often use cost or difficulty as «excuses» not to make vital upgrades to legacy systems.

With online banking rising in popularity, the severity of system failures and service outages has also seen an «unacceptable» rise, according to findings published by the House of Commons’ Treasury Select Committee.

The report concluded the impact of these failures range from an inconvenience to customer harm, and even threats to a business’ viability. The lack of consistent and accurate recording of data on such incidents is also concerning.

«The number of IT failures that have occurred in the financial services sector, including TSB, Visa and Barclays, and the harm caused to consumers is unacceptable,» said the inquiry’s lead member Steve Baker MP.

«The regulators must take action to improve the operational resilience of financial services sector firms. They should increase the financial sector levies if greater resources are required, ensure individuals and firms are held to account for their role in IT failures, and ensure that firms resolve customer complaints and award compensation quickly.

«For too long, financial institutions issue hollow words after their systems have failed, which is of no help to customers left cashless and cut-off. And for too long, we have waited for a comprehensive account of what happened during the TSB IT failure.»

MPs launched this inquiry to examine the cause behind such incidents, reasons for their frequency, and what regulators can do to mitigate the damage.

As the report identified, TSB’s IT meltdown during 2018 is the most prominent example of an online banking outage in recent years.

The major incident, which lasted several days, was caused by a major transfer of 1.3 billion customer records to a new IT system. A post-mortem analysis by IBM subsequently showed the bank did not carry out rigorous enough testing.

TSB has not been the only institution to have suffered banking outages, with figures compiled by the consumer watchdog Which? showing customers with major banks suffered outages 302 incidents in the last nine months of 2018. Another example of a prominent incident saw NatWest, RBS and Ulster Bank hit by website outages in August this year.

Beyond the work banks must do to ensure their systems are resilient, the MPs found that regulators must do far more to hold industry giants to account when failures do occur. Poor management and short-sightedness, for example, are key reasons why regulators must intervene to ensure banks aren’t exposing customers to risk due to legacy systems.

When companies embrace new technology, poor management of the transitions required is one of the major causes of IT failure, the report added, with time and cost pressures leading banks to «cut corners».

Banks themselves, moreover, must adopt an attitude to ensure robust procedures are in place when incidents do occur, treating them not as a possibility but a probability.


Data protection and GDPR compliance are primary goals for major firms. Learn about the security features that will help you achieve and sustain compliance in this whitepaper.

Download now


Meanwhile, the use of third-party providers has also come under scrutiny, with the select committee urging regulators to highlight the risks of using services such as cloud providers.

The report highlighted Bank of England statistics that show a quarter of major banks, and a third of payment activity, is hosted on the public cloud. This means banks and regulators must think about the implications for concentrating operations in the hands of just a few platforms.

The risks to services of a major operational incident at cloud providers like Amazon Web Services (AWS) or Google Cloud Platform (GCP) could be significant, with the market posing a «systemic risk». There should, therefore, be a case for regulating these cloud service providers to ensure high standards of operational resilience.

The report listed a number of suggestions for mitigating the risk of concentration, but conceded the market is already saturated and there was «probably nothing the Government or Regulators can do» to reduce this in the short-term.

Some measures, such as establishing channels of communication with suppliers during an incident, and building applications that can substitute a critical supplier with another, could go towards mitigating damage.

«This call for regulation and financial levies is a step in the right direction towards holding banks accountable for their actions,» said Ivanti’s VP for EMEA Andy Baldin.

«Some calls to action have already been taken to restrict how long banking services are allowed to be down for without consequence, such as last year’s initiative to restrict maximum outage time to two days. However, the stakes are constantly increasing and soon even this will become unacceptable.

«Banks must adopt new processes and tools that leverage the very best of the systems utilised in industries such as military and infrastructure. These systems have the capability to reduce the two-day maximum to a matter of minutes in the next few years – working towards a new model of virtually zero-downtime.»

Microsoft beats Amazon to win $10m US JEDI contract


Bobby Hellard

28 Oct, 2019

The Pentagon has awarded its $10 billion cloud computing contract to Microsoft, instead of Amazon, which received criticism from President Donald Trump and rivals. 

Amazon’s AMS was seen as the front runner for most of the bidding process and said it was «surprised» by the decision.

The contract, known as the Joint Enterprise Defence Infrastructure (JEDI), pitted some of the world’s biggest tech companies against each other with the ultimate prize being to upgrade the US defence department’s IT systems.

The project has been marred in controversy and complaint, particularly over the decision to offer it to a single vendor. This resulted in legal action and also caught the attention of the President, Donald Trump.

End of the JEDI saga

The JEDI project is about replacing the Department of Defences (DoD) ageing computer networks with a single cloud system.

As winners of the contract, Microsoft will provide AI-based analysis and store classified military information, as well as a host of other computer services. A big reason for the project is to give the military better access to data and the cloud from battlefields, which also proved to be to big a concern.

That was the case for Google who was the first to drop out of the JEDI race in October 2018. The decision followed its announcement that it would not renew another military contract called Project Maven after protests from its employees.

«We are not bidding on the JEDI contract because first, we couldn’t be assured that it would align with our AI Principles,» a Google spokesman said in a statement. «And second, we determined that there were portions of the contract that were out of scope with our current government certifications.»

The parts of the contract that Google cited were also issues for both IBM and Oracle who filed lawsuits against the DoD in December last year, arguing that there were conflicts of interest between former Pentagon and AWS employees.

Oracle was removed from the bidding process in April, before the ruling from that lawsuit, when it failed to meet the requirement of having three data centres with FedRAMP Moderate ‘Authorised’ support.

AWS Trumped

IBM was also ruled out, not long after, leaving Microsoft to battle it out with the favourite, AWS. However, in August, the bidding caught the attention of President Trump, who has had a long public spat with Amazon CEO Jeff Bezos.

A year before, it was reported that Trump called his Pentagon Secretary James Mattis and directed him to «screw Amazon» out of a chance to bid on the JEDI contract. This is according to Mattis’ forthcoming book «Holding The Line: Inside Trump’s Pentagon with Secretary Mattis.» The account was written by Guy Snodgrass, who served as a speechwriter for Mattis.

The official line from the Pentagon is that it weighed up the bidding fairly and that Microsoft was the rightful winner. But reports of Trump’s involvement cast some doubt over those statements; Amazon said it was «surprised about this conclusion».

«AWS is the clear leader in cloud computing, and a detailed assessment purely on the comparative offerings clearly lead to a different conclusion,» said an AWS spokesperson. «We remain deeply committed to continuing to innovate for the new digital battlefield where security, efficiency, resiliency, and scalability of resources can be the difference between success and failure.»

AWS reports $8.99bn in revenues for Q319 – yet slowing growth concerns analysts

Amazon Web Services (AWS) announced revenues of almost $9 billion for the most recent quarter – but growth fell on last year's totals meaning a more subdued outlook.

AWS posted $8.99bn (£7bn) for Q319 at a growth of 35% year on year – however this compares with 37% growth for Q219, and a 46% growth rate for this time last year. Amazon's cloud arm now represents 12.8% of Amazon's overall revenues, compared with 11.8% for the previous year's quarter.

Naturally, many of the analyst questions focused on the performance of AWS. Stephen Ju, of Credit Suisse, enquired around the long-term potential margins, saying it 'pretty much sold itself' to begin with and noting the sales and marketing increases with potential engineering hire downturns.

Brian Olsavsky, Amazon chief financial officer, noted the increasing importance of long-term commitment in terms of pricing. "Our margins expectations are that we will price competitively and continue to pass along pricing reductions to customers, both in the form of absolute price reductions and also in the form of new products that will in effect cannibalise the old ones," said Olsavsky.

Various new products were launched among the highlights for AWS in the most recent quarter. AWS Lake Formation, a service which helps customers build data lakes, and fully managed machine learning product Amazon Forecast were the biggest releases. In terms of news, the announcement of Amazon migrating all of its consumer databases from Oracle to AWS – complete with celebrations – earlier this month was of greatest interest.

In the previous quarter, this publication noted that large expectations accompanied large numbers. Growth had again dipped for AWS, which naturally saw pessimism from the analysts. Yet as long-time industry watcher Synergy Research noted, more than 100% growth rates could not carry on forever.

This time round, a note from Synergy was in similar tones. "I've seen some comments expressing worrries over the gradual reduction in annual growth rates but this is not a real concern," wrote John Dinsdale, Synergy chief analyst and research director. "It is a truism that as great scale is achieved, then growth rates will decline. The sequential growth in cloud service spending was around $1.5 billion in Q3, in line with the growth seen in the first two quarters of the year.

"Did someone say the market is weakening? I don't think so," added Dinsdale. "The cloud market is in rude good health."

While Amazon's results were being reported, AWS was under from a DDoS attack which took its S3 storage service, and others, offline for up to eight hours. According to an AWS status at the time: "Between 10:30 AM and 6:30 PM PDT, we experienced intermittent errors with resolution of some AWS DNS nsames. Beginning at 5:16 PM, a very small number of specific DNS names experienced a higher error rate. These issues have been resolved."

You can read Amazon's full financial report here.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

If your enterprise is still on the fence around cloud – here’s what you need to know today

Cloud infrastructure services are rapidly becoming the de facto choice for enterprise IT workloads. According to Gartner, the 2019 worldwide revenue from public cloud IT services is expected to grow by 17.5% and will become a $330 billion dollar industry by 2022. Cloud-based technology is no longer an emerging trend, it’s mainstream, with 69% of enterprises moving business-critical workloads to the cloud.

What is the appeal of the cloud?

Cloud technology enables an agile working environment that can drive successful business transformation initiatives. In most cloud solutions, all a user requires is an active internet connection and login credentials to consume enterprise workloads. An Agile workplace helps to facilitate team collaboration, hot-desking, and home working initiatives that can boost productivity and enhance working relationships.

In cloud computing, everything is bigger, and the sheer scale of major cloud provider’s technical solutions is staggering, harnessing this scalability is another major appeal of the cloud. Cloud products are horizontally and vertically scalable, meaning users can scale out their applications using multiples of efficient compute nodes, and scale up (and down) dynamically adding or removing compute resources to individual systems.

As businesses grow, there may be a surge in capacity requirements, including a faster network and the extra demand for storage. Onsite enterprise data centers are expensive to maintain, and purchasing new hardware is heavy on the wallet. With the cloud, petabytes of storage are available at the click of a button, and you only pay for what you consume. Cybersecurity is always a top agenda item in any company boardroom, and cloud computing enables users to consume security as a service.

Cloud security is primarily about protecting against the user's data being compromised (destroyed or stolen), and users experiencing a service outage (denial of service). Cloud platforms designed from the ground up to be secure, and as threats are increasing in scale and severity, many enterprise organizations are choosing the cloud to mitigate the security risk.

Cloud infrastructure has backup and redundancy capabilities at its core. All cloud providers offer some type of backup-as-a-service, and the system architecture is created to be redundant, so that all data is protected, all of the time. Offsite copies of data are stored regionally specific, and most cloud providers offer disaster recovery services as standard, giving the user the capability to seamlessly fail over services to another region/country if major system issues are experienced.

One other major appeal of the cloud is the expectation of cost savings, although the costs will take time to reduce, over time, the capital expenditure will decrease significantly as businesses switch away from a local data center model, buying and leasing servers, and all the associated costs and complexities of licensing.

Making preparations

The jump to the cloud requires significant planning and preparation to reap the wealth of benefits available. Even if a business chooses to outsource this responsibility, we recommend all organizations have a grip on what cloud services they want and how they want to consume them.

Multitudes of technical activities are required for successful cloud migration. Creating Service Level Objectives (SLO) is an essential task to help define how the service should perform. Setting Service Level

Indicators (SLI) will allow you to measure the attributes of the service, such as system availability or the overall performance of the service. Together, these will help determine if a cloud solution is fit for purpose. Google Cloud suggest the next steps are the creation of a presentation layer (network) that handles the flow of information through the cloud service, a Business logic layer (compute) that manipulates the data to make it useful for the user, and the data layer (Storage) to store or retrieve the digital information.

Each cloud design must be resilient, horizontally and vertically scalable, and disaster recovery capable. A distributed design adds resiliency for geographic scaling and failover. Many businesses experience a “peak season” where system usage ramps up for a period of time, scalability of compute resources and being able to increase the number of compute nodes adds an elastic computing capability.

Cloud services are secure, future-proofed and cost-optimized. In a traditional data center, physical or virtual computing assets are purchased in advance, often sitting idle, wasting money, resources, and power. On-Demand compute fixes this capacity planning problem.

Additional services such as automated deployment (DevOps), monitoring, alerting and incident response are an inherent design of the cloud. Stateless design drives SLI, SLO and SLA objectives and your enterprise will be able to grow exponentially, both financially and geographically, with the benefits of uptime, scalability and future expansion being readily available.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

The rise of obfuscated VPN servers and their use cases: A guide

VPNs continue to be used extensively as tools to protect data security and user privacy. Yet, as to be expected, there are many providers available, and many options within those providers – so buyer confusion can reign.

A virtual private network, by itself, is the secure, private connection between your device and your intended destination. When dealing with VPN servers, the options start to broaden. There are a number of server categories to choose from; standard servers, double VPN servers, where the traffic is encrypted twice, ‘Onion over VPN’, which involves the Onion network, dedicated IP servers, P2P servers, and obfuscated servers.

Increasingly, obfuscated VPN servers are becoming a useful tool, particularly for users in countries with limited internet access. So what are obfuscated VPN servers? How do they work? And what are your options?

What is an obfuscated VPN server?

An obfuscated server can bypass internet restrictions such as network firewalls. In countries with restricted access, these types of servers are recommended. Why is this necessary? Although many people feel as if the internet should be free to roam and use as they wish, that’s not always the case. Consider VPN blocks – they aren’t just for government entities. You will find VPN blocks like ISPs, streaming services, universities and schools that also prevent the use of VPNs.

Obfuscation, also known as OBFU, restricts reverse engineering in programs, making it hard for hackers to access metadata. In other words, this VPN helps take data and makes it look like a jumbled mess.

An example of VPN obfuscation

Some people may refer to this as “stealth” or “camouflage” mode. VPN providers can’t physically put their VPN servers in countries that have strict censorship rules, so they use virtual servers with obfuscation to bypass their firewalls. It disguises data passing through the VPN app to look like regular HTTPS traffic.

Here’s a good example of an obfuscated VPN server and how it can be used. Consider Netflix and how it distributes shows among regions at different costs. In Australia the service may be $7.10, while in Australia that same service could cost $11.90. The server levels the playing field, allowing the user to get the $7.10 deal instead of having to pay $11.90. For online gamers, this is gold. If their ISP is charging more for gaming but a lesser price for general browsing, the VPN traffic can be altered to look like the user is just browsing the web. While the ethics of this can be questioned, there is no doubt that this trend helps drive VPN usage.

Banned VPN countries

Even with the ability to use an obfuscated VPN server, a handful of countries have banned the use of VPNs or have otherwise made them illegal. Here are those countries and why:

China: China has the Great Firewall (GFW) that was designed to filter and block restricted websites and services. It is one of the largest and most intricated technologies designed for censoring and mass surveillance. China passed CL97 legislation that not only criminalizes cybercrime, but people found to use VPNs in some parts of China can be fined or worse. Some of the websites blocked from mainland China include Google, Gmail, Instagram, Pinterest, YouTube, Dropbox, The New York Times, Facebook and Twitter.

Russia: Russia is another country that bans the use of VPNs to restrict the spread of extremist and unlawful conduct. The Russian government wants to restrict what content can be accessed in the country. Anyone found using an VPN can be fined up to $5,100, and VPN providers can be fined up to $12,000.

Iran: Iran has given harsh penalties to anyone using a VPN in their country since 2013. There are a few government-approved VPNs regulated by the government that are allowed. If caught using a VPN, the user can face up to one year in prison.

UAE: The United Arab Emirates also considers VPN usage a federal offense or crime. If found using a VPN, the user can be fined between $136,000 to $544,000 U.S. dollars. This ban is only imposed on individuals using VPNs for personal use. Banks and other institutions can freely use VPNs. Law No 5 of 2012 states local residents can only use state-owned VPNs and can face life imprisonment.

Are there providers that offer an obfuscated VPN?

With countries continuing to block VPN servers, there are only a few providers which offer this type of functionality:

Surfshark: Surfshark currently has 1040+ servers in over 61 countries, including Russia and the UAE. Known for its privacy, speed and performance, it has outstanding customer support and features.

VyprVPN: VyprVPN has developed their own proprietary VPN protocol called the Chameleon. It effectively obfuscates 256-bit OpenVPN encrypted traffic and transmits it using the port 443. The Chameleon protocol has been said to bypass restrictions in China, Russia, India, Turkey, Iran and Syria. It is available for all major platforms including Windows, Mac, iOS, and Android, along with features such as VPN kill-switch, NAT protection and Smart VPN.

NordVPN: NordVPN effectively bypasses regional firewalls like the GFW and passes all regional geo-restrictions. They have 5000+ servers and offer a dedicated list of obfuscated servers. They also have features such as Kill Switch, Smart play, double VPN and military encryption.

ExpressVPN: This provider does not log user data and users can obfuscate their network traffic to bypass the China GFW. They operate at very super-fast speeds and have a server park of 2000+ servers around the world. Their MediaStreamer technology works as a Smart DNS serve to help unblock geo-even the most heavily restricted content.

IPVanish: IPVanish does not have a dedicated obfuscation mode but makes it very simple to obfuscate traffic with the flip of a toggle switch. Additionally, obfuscation can be enabled on both desktop and mobile applications. They have 1,300+ servers in 75+ locations around the world.

How VPN obfuscation works

Most of the time, when connecting to an obfuscated server, a mechanism steps in that makes it impossible to block the VPN tunnel. Then, OpenVPN data packets with a Header and Payload work together to activate the encryption. XOR Obfuscation then removes all the metadata from the packet header, transforming it into meaningless information which prevents the identification of a VPN protocol. That VPN data then becomes HTTPS encrypted web traffic and the data packets go through a second layer of encryption with SSL or TLS protocols. Then the VPN data is assigned to port #443.

There is another method of obfuscation developed by the TOR Network called Obfsproxy where data is wrapped into an obfuscation layer that used pluggable transports. These scramble the VPN traffic, allowing users to bypass firewalls and geo-restrictions while protecting users from VPN detection and blockages.

When considering which type of VPN would be most useful, the obfuscated VPN server works well in instances where communications may be filtered or blocked. Businesses could benefit from using this type of VPN server when communicating with employees who may be traveling to those areas that have severe restrictions in place. Completely different from a standard VPN, it's important to outline the reasons and usage of this type of VPN server.

It is also important to determine whether there will be a record of activities, especially if the goal is to keep an identity anonymous. With cyber crime being so prevalent around the world, taking all steps to ensure the safety of data and sensitive information is key. If searching for complete online privacy, a secure connection, and safe content accessibility anywhere in the world, it's worth a deeper look to figure out which provider offers the most features and security.

Obfuscated or not, the value of a VPN goes beyond price, but offers a level of security most people need when surfing the web or conducting transactions. Taking into account data privacy laws, restrictions and new regulations that continue to hinder online activities, putting this type of protection in place for personal or business reasons should work to mitigate some potential risks that could stop productivity and other essential functions.

Editor's note: This article is brought to you in association with Surfshark.