SQL Server high availability and disaster recovery for AWS, Azure and GCP: A guide

The public cloud offers a myriad of options for providing high availability and disaster recovery protections for SQL Server database applications. Conversely, some of the options available in a private cloud are not available in the public cloud. Given the many choices and limitations, the challenge faced by system and database administrators is determining the best available options for each application running in hybrid and purely public clouds.

All cloud service providers (CSPs) have service level agreements (SLAs) with money-back guarantees for when uptime falls below specified levels, usually ranging from 95.00% to 99.99%. Four-nine’s of uptime is generally accepted as constituting HA, and to be eligible for these 99.99% SLAs, the configurations need to meet certain requirements.

But be forewarned: The SLAs only guarantee “dial tone” at the server level, and explicitly excluded many causes of downtime at the database and application levels. These exclusions inevitably include natural disasters, the customer’s actions (or inactions), and the customer’s system or application software. There may also be a separate SLA for storage that is lower than the one for servers. So while it is advantageous to leverage various aspects of a CSP’s infrastructure, additional provisions are needed to ensure adequate uptime for mission-critical SQL Server databases.

Differences between HA and DR

Properly leveraging the cloud’s resilient infrastructure requires understanding key differences between “failures” and “disasters” because those differences affect the choice of provisions used for HA and DR protections. Failures are small in scale and short in duration, affecting a server, rack, or the power or cooling in a single datacenter. Disasters have more widespread and enduring impacts, and can affect multiple datacenters in ways that preclude rapid recovery.

The most consequential effect involves the location of the redundant resources (systems, software and data), which can be local—on a Local Area Network—for recovering from a localized failure. By contrast, the redundant resources required to recover from a widespread disaster must span a Wide Area Network.

For database applications that require high transactional throughput performance, the ability to replicate the active instance’s data synchronously across the LAN enables the standby instance to be “hot” and ready to take over immediately in the event of a failure. Such rapid recovery should be the goal of all HA provisions.

Data must be replicated asynchronously in DR configurations to prevent the latency inherent in the WAN from adversely impacting on the throughput performance in the active instance. This means that updates being made to the standby instance always lag behind updates being made to the active instance, making it “warm” and resulting in an unavoidable delay during the manual recovery process.

All three major CSPs accommodate these differences with redundancies both within and across datacenters. Of particular interest is the variously named “availability zone” that makes it possible to combine the synchronous replication available on a LAN with the geographical separation afforded by the WAN. These zones connect two or more regional datacenters via a low-latency, high-throughput network to facilitate synchronous data replication. With latencies around one millisecond, the use of multi-zone configurations has become a best practice for HA.

For DR, all CSPs have offerings that span multiple regions to afford additional protection against major disasters that could affect multiple zones. For example, Google has what could be called DIY (Do-It-Yourself) DR guided by templates, cookbooks and other tools. Microsoft and Amazon have managed DR-as-a-Service (DRaaS) offerings: Azure Site Recovery and CloudEndure Disaster Recovery, respectively.

For all three CSPs it is important to note that data replication across regions must be asynchronous, so the recovery will need to be performed manually to ensure minimal or no data loss. The resulting delay in recoveries is tolerable, however, because region-wide disasters are rare.

Making SQL Server “always on”

SQL Server offers two of its own HA/DR features: Always On Failover Cluster Instances and Always On Availability Groups. FCIs afford three notable advantages: inclusion in the less expensive Standard Edition; protection of the entire SQL Server instance; and support in all versions since SQL Server 7. A significant disadvantage is the need for a storage area network (SAN) or other form of shared storage, which is unavailable in the cloud. The lack of shared storage was addressed in Windows Server 2016 Datacenter Edition with the introduction of Storage Spaces Direct. But S2D also has limitations; most notably its inability to span availability zones.

SQL Server’s other HA/DR feature, Always On Availability Groups, is a more robust solution capable of providing rapid recoveries with no data loss. Among its other advantages are inclusion in SQL Server 2017 for Linux, no need for shared storage, and readable secondaries for queries (with appropriate licensing). But for Windows it requires licensing the substantially more expensive Enterprise Edition and it lacks protection for the entire SQL Server instance.

It is worth noting that SQL Server also offers a Basic Availability Groups feature, but it supports only a single database per Availability Group, making it suitable for only the smallest of environments.

The limitations associated with both options have created a need for third-party failover clustering solutions purpose-built to provide HA/DR protections for virtually all Windows and Linux applications in private, public and hybrid cloud environments. These software-only solutions facilitate, at a minimum, real-time data replication, continuous monitoring able to detect failures at the application level, and configurable policies for failover and failback. Most also offer a variety of value-added capabilities, including some specific to popular applications like SQL Server.

Failover clustering offerings afford two major advantages: SANless operation that overcomes the lack of shared storage in the cloud and application-agnosticism that eliminates the need to have different HA/DR provisions for different applications.

Editor’s note: More detailed information about the operation and benefits of SANless failover clustering is available in How to make Amazon Web Services highly available for SQL Server.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Schneider Electric launches wall-mounted micro data centre for those tricky edge deployments


Dale Walker

3 Oct, 2019

Schneider Electric has launched a first of its kind wall-mounted micro data centre designed to support large edge servers in smaller environments or those without robust physical security measures.

The 6U unit is the latest in the company’s EcoStruxure Data Centre range and is designed as a self-contained single-rack enclosure that incorporates remote monitoring, management services, an uninterrupted power supply, and cooling systems inside a low profile cabinet.

This can then be either mounted onto a wall out of the reach of potential interference or placed on the ground, depending on the size and requirements of a room. With this, the company said  smaller businesses, or those with offices and factory floors that are generally not optimised for IT equipment, are still able to put their networking technology nearer to their employees or customers.

The 6U wall-mounted unit also comes with a security camera to monitor for physical security threats

«With the EcoStruxure Micro Data Center 6U Wall Mount’s creative design and functionality, we are able to open up new possibilities to deploy resilient IT at the edge, making digital transformation a reality,» Jim Simonelli, SVP of Emerging Businesses at Schneider Electric’s Secure Power division, told delegates at the company’s Innovation Summit.

Schneider said it’s best used in those environments that want to deploy modern digital systems closer to their customer base, such as a supermarket using the unit to power its point of sale systems.

«No one else can provide the full, standardised IT infrastructure solutions that Schneider can along with the partner ecosystem to ensure simplified deployment and compatibility. A fully integrated EcoStruxure Data Center Solution, including EcoStruxure IT and Asset Advisor 24/7 remote monitoring and services, ensures resiliency in the cloud and at the edge.»

The unit designed to be self-contained and requires very little maintenance once deployed

The 6U Micro Data Centre unit also comes with pre-installed dust filters and fan ventilation, making it suitable for light industrial environments, the company explained. It’s also shock-resistant and can, therefore, be safely shipped to multiple partners who can then install components before it reaches the end customer. This means that businesses are able to use pre-configured units to standardise the rollout of edge technology tailored to their specific requirements.

Although it is sold as a 6U unit, the company explained to IT Pro that it could be deployed as a modular system, provided the wall that they are attached to can support the weight. It’s possible to route cables into multiple units to share power and network traffic, therefore potentially doubling or tripling the available rack space.

The unit is also yet to make use of any liquid cooling, although the company suggested that it would be compatible with its next-gen liquid cooling system, currently in development, once it becomes available.

S-Series, C-Series and R-Series versions of the unit are available offering varying configuration options.

Alongside the new unit, the company also revealed its Device Security Vulnerability Assessment tool, available as part of the EcoStruxure IT Expert cloud software suite. The assessment tool is designed to help with the rollout of edge networks by helping administrators monitor the various devices connected to the network and reduce the possibility of data loss or downtime. Vulnerabilities, security policies, ongoing regulatory compliance checks, firmware versions, device age and device performance can all be monitored from a single dashboard.

Box announces new data compliance and security features


Bobby Hellard

3 Oct, 2019

Box and IBM have revealed a slew of integrations to help customers deal with strict data regulations.

With legislation like the GDPR and the soon to be implemented California Consumer Privacy Act changing data regulations, both companies are looking to enable greater compliance when it comes to sensitive data. As such, updates have been made to Watson Knowledge Catalog and integration of IBM X-force with Box Shield.

«IBM and Box have a history of partnering to bring clients greater collaborative and data capabilities,» said Rob Thomas, GM of IBM Data and AI, as Box’s annual Boxworks conference in San Francisco. «Today, we’re extending that work further to integrate a new Watson technology that automates the process of identifying sensitive data, helping to speed compliance and provide Box users greater trust in the data.»

For Box customers, the company says that IBM’s Watson Knowledge Catalog InstaScan tool will give them the ability to identify sensitive data throughout their Box folders. InstaScan lets them set parameters for what type of data is allowed based on corporate policy, enabling them to run risk assessments and check folders are compliant with data regulations.

There are also plans to integrate IBM X-Force threat intelligence and QRadar with Box Shield for advanced threat intelligence, investigation, and response. According to Box, these integrations will help detect abnormal file access and transfers as well as flag techniques used by known cyber criminals.

IBM is not the only beneficiary of new Box announcements as the company has announced more integrations with Slack and Microsoft Teams.

For Slack, the integration will provide contextual information on shared files with content cards and the ability to set file permissions within the comms app to provide users with access and enforce Box permissions in Slack with granular controls.

For Microsoft Teams, the integration will enable users to share Box content or local content directly to Channels and Chats, automate folder and permission mapping, and enable previews and edits in all Channel files in one central place.

Which cloud services are right for your organisation?


Cloud Pro

7 Oct, 2019

It’s safe to say that the cloud is one of the most important innovations in modern IT, with a huge number of organisations moving to take advantage of benefits such as flexibility, cost savings and ease of deployment. Fittingly enough, however, ‘the cloud’ is a broad and somewhat woolly term that encompasses myriad technologies, all of which serve slightly different purposes.

For organisations looking at cloud adoption, it’s important to know exactly what ‘cloud’ means to you. Migrating to the cloud without a firm understanding of your objectives can lead to over-investment in services which may not be necessary for achieving them – which can, in turn, result in the costly repatriation of workloads later down the line.

When is a cloud not a cloud?

First things first – when most people talk about the cloud, they’re generally talking about the three major public cloud platforms – Amazon Web Services, Google Cloud Platform and Microsoft Azure. These specialise in platform as a service (PaaS) and infrastructure as a service (IaaS) offerings, and are most commonly used for building and running applications. They essentially allow companies to command a virtual data centre, where the company is responsible for building and maintaining the software elements, and the provider takes care of the physical hardware they run on.

This is incredibly useful for any company that develops software (whether for internal or external use), but that’s not all they do. Public cloud platforms can also be used to host instances of business apps such as CRM systems, websites, mail servers and databases. These platforms are incredibly versatile, but the downside is that they generally require a relatively high level of configuration and management, with a complex set of skills needed to do so.

“It’s not as easy as people make it out to be. If you go to Amazon’s website, they tell you that you can be consuming cloud services immediately, just with a credit card,” says Lee Wynne, CDW’s public cloud architecture practice lead, “and you can’t. You just put your credit card details in and away you go, and that’s great if you’re a sole trader and you just want to do a couple of little things. If you’re a big organisation and you’re security conscious, then there’s quite a lot of design work required just around the account structure before you get anywhere near infrastructure. Then on top of that, you have good platform architecture – what regions are you going to use, what availability zones, what’s going to have access to the internet, what isn’t, subnets, all those types of things.”

File-sharing platforms, on the other hand, are much more user-friendly. These services – typified by the likes of Box, Dropbox and Google Drive – used to be known as ‘cloud storage’ services, but their growing feature-set has rendered that definition somewhat unhelpful. Although they still act as a cloud-based central repository for business files and folders, most providers now offer features beyond basic storage, typically geared towards enabling greater efficiency and collaboration within the business.

Common features of file-sharing platforms include the ability to leave comments on files, integrations with other SaaS tools (which we’ll talk more about later) and thorough version histories and audit logs, as well as in-depth permission settings to ensure that no-one has access to anything they shouldn’t. File-sharing is an essential tool for any organisation; not only does it help protect files from accidental loss in the event of a hardware failure, it also allows staff to access them from any location or device, improving mobility and enabling flexible or remote working.

It’s important to note that while file-sharing services can be used to back up documents and provide similar functionality to that of a backup service, the two are not interchangeable. Unlike storage platforms, backup providers focus on keeping a complete archive of all of your data, rather than just files and documents. This includes things like databases, server configurations and emails, to ensure that if anything disastrous (such as a ransomware infection or a flood) happens to your IT systems, you can quickly and easily restore them to their state before the incident.

There are many different backup options available depending on your needs; some specialise in server or VM-level backups, some focus on endpoint devices and others cover the full range of tasks. Dedicated backup services tend to concentrate on what’s known in the industry as ‘cold storage’ – meaning data that isn’t intended to be accessed on a regular basis. For this reason, many use snapshots to restore affected systems to a specific point in time. Backup platforms are an excellent disaster recovery tool to ensure you can get operational again as quickly as possible should the worst happen, but they’re also helpful for meeting regulatory and compliance requirements.

Collaboration station

Gone are the days when organisations were forced to rely on lengthy email chains to share knowledge and files with each other. Now, cloud-based collaboration platforms and communication services help employees to stay in touch. Instant messaging apps are among the most popular examples of this, with Slack and Microsoft Teams being leaders in the field. Combining the functionalities of a message board, a chat app and a digital workspace, collaboration apps support direct messages, private group chats, public channels and company-wide forums, allowing communication across many levels.

These services often include telephony tools like basic audio and video calling, but they also integrate directly with popular third-party conferencing tools like Zoom and BlueJeans for those that need more features. File-sharing, communication and collaboration tools are also frequently cross-compatible, allowing employees to, for example, share relevant files without leaving a video call.

Outside of the tools and services highlighted above, there are various types of standalone SaaS software to suit businesses specific needs; virtually every breed of business application has a cloud-based equivalent, whether it’s a CRM system, accounting package or database management tool. Organisations can cherry-pick which applications they need to build their ideal software stack, and many feature cross-compatibilities and integrations with other services to enable different workflows.

Some cloud services will suit every organisation. There are few organisations, for example, that wouldn’t benefit from the increased mobility and flexibility offered by a good file-sharing service. However, the combination of different cloud services is where businesses can unlock real value. We’ve already covered the way file-sharing, collaboration and unified comms services can work well together – a particularly effective mix for creative-driven organisations like marketing or design firms – but there are configurations to suit every organisation.

Any organisation that has a substantial software development practice, for example, would be well-served by adopting a cloud platform such as Microsoft Azure and combining it with comprehensive VM backup and code-sharing tools – allowing them to develop and deploy applications rapidly and at scale without the risk of sudden loss of work.

“Things like core productivity tools complement themselves well with some business analytics in terms of data sharing,” Wynne says. “So PowerBI, for example, on Microsoft Office 365. All those things are very complementary in terms of providing people key data within the business so they can make good decisions.”

Finding the right blend of cloud services – as well as the best way to combine them for maximum efficiency and cost savings – can be a real challenge for organisations looking to start exploring the world of cloud. By partnering with CDW, organisations can get a helping hand with this complex and often daunting process, giving them access to a trusted advisor with the expertise to accelerate their journey to the cloud.

To find out more about CDW visit www.cdw.com

Is performance engineering still needed when it comes to cloud?

Opinion Now that cloud vendors are delivering features constantly, which are backed with hard data and with good specs, the question which comes to mind is: shall we continue to measure, as we did in the days of the data centre, or shall we blindly trust the vendor and save ourselves plenty of time and duplicated effort?

This is a question I asked myself some time ago – and it has taken me some time to come up with an answer I’m happy with.

Round one: The beginning

A few months ago, I was invited to a meeting in which the aim was decide and weight the ‘need’ of measuring performance versus not in the company cloud. The reason I was invited was two-fold: one, it is part of my role and within my circle of competence, and two, I am all for cloud-native philosophy, methodology and application, and I have been using it for many years before Oracle Cloud infrastructure was born.

The meeting started with some attendees asking my team to perform measurements and find out if the infrastructure will or will not support our set of applications with the current network architecture. My response was: do we need to? In cloud, we need to trust our vendor. We usually must not over-measure and stress test a platform that is given to us with clear features and metrics. There are SLIs/SLOs/SLAs in place to assure the client – us – that the systems will perform adequately.

So far, this meant performance engineering was not needed for this task. We agreed on that and we called it a day. It was something the vendor made clear in terms of specs, and we were clear in terms of what we’ve got, from how many VM cores and how much memory per VM, to load balancing bandwidth and latency, and so on. In conclusion, with all these specs in place, there is no need to go overboard doing stress tests, smoke tests et al, in the same way we were – and still are – in a data centre.

Round two: The revelation

After that meeting, some performance tasks we were used to were less necessary, especially as different clouds kept adding features and guaranteeing they will perform up to the levels expected. After all, it’s their responsibility.

But a few weeks back, I was required in a different situation. The aim this time was not to ‘confirm’ what the vendor was saying; it was basically using the skillset, to go the extra mile the vendor couldn’t or wasn’t within the scope.

In this case, it wasn’t to measure networking specs but to compare native versus paravirtualization launch modes, and other related areas. Although the vendor is saying that it will be better or faster, nothing indicates how much better, or how much faster, and opinions can be very subjective, especially when dealing with many components in a complex architecture. This case was justified, as metrics were unclear, there was a grey area, and things got subjective quickly.

Round three: The conclusion

This means with cloud things are simplified, as they were meant to be, and we shouldn’t complicate things if we have a trusted vendor, because all those tasks were already carried by them.

That being said, there are situations in which the vendor was not able to, or not meant to run some performance tasks. These are very particular situations that may appear, and performance engineering will still be needed.

Now, my circle was closed and I understood when it was a good time for investment and when wasn’t. However, in some situations, two things happen. Firstly, we might want to have that extra assurance that the specs are valid. There’s nothing wrong with that, we just need to pick those situations well to avoid wasting gunpowder. Secondly, management wants to do it; and even though engineers sometimes know better, occasionally the business just wins.

Performance engineering is far from death, particularly so with new approaches such as failure injection, chaos engineering, and intuition engineering. New techniques, knowledge and tools are being created all the time – we just need to be able to leave pride to the side and acknowledge when that part of our role is not needed.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

What to expect from Boxworks 2019


Bobby Hellard

2 Oct, 2019

Some 6,000 IT professionals are descending on San Francisco this week for Box’s annual conference, where digital transformation and collaboration are on the agenda.

Marking its ninth year in the city, delegates and speakers at the conference will explore how enterprises can transform their business by streamlining operations. The event, hosted at the Moscone Centre, will kick off with a keynote from CEO Aaron Levie, who will be waxing lyrical about the future of work and how cloud management powers intelligent enterprise.

Joining him on stage will be IBM’s CEO, Ginni Rometty, who will be talking about all things content and digital transformation. Big Blue is a regular fixture at Boxworks and it’s highly likely there will be announcements and details about work the two companies are looking to get into in 2020.

Levie will also be joined by award-winning director Ryan Coolger. Nothing has been announced and the reason for his attendance is shrouded in secrecy, but I have fingers crossed for some Black Panther 2 details/footage – that would be marvellous!

Box will have a second celebrity on site, too, with football star Abby Wambach attending the Women’s networking luncheon. As well as being the all-time leading international goalscorer (that’s for men and women), she is also an activist for equality and inclusion.

Taking it back to tech, there’s a real focus on communication platforms this year with the CEOs of both Slack and Zoom attending. Stuart Butterfield, who co-founded Slack, has enjoyed a rapid rise over the last few years thanks to his company’s popularity with startups. It’s been heavily linked to the «always-on» culture, with suggestions that it enables unhealthy work habits, but but its popularity also highlights well received the platform has been by businesses.

Zoom, on the other hand, is a little less well known, but still very popular with startups. CEO Eric Yuan will be attending as a speaker and we assume he’ll be discussing the latest innovations his video conferencing platform has to offer.

Many of the 6,000 or so attendees will be riding across the Golden Gate Bridge in an Uber for the conference and the ride sharing app will have a representative at the event. Head of information technology, Shobhana Ahluwalia will be speaking at the event, presumably discussing the recent changes to the company’s app, which is now an integrated platform for both the transport and food delivery services.

This is likely what we can really expect from Boxworks over the next two days; discussions about simplifying services in the cloud from those that have done it.

Schneider Electric partnership to develop liquid cooling for power-hungry data centres


Dale Walker

2 Oct, 2019

Schneider Electric has said it has entered into a strategic partnership that will see the company collaborate on the development of cutting-edge data centre liquid cooling technology.

The energy and automation giant will work alongside Iceotope, a company known for its chassis-level liquid cooling technology, and Avnet, a global technology services provider that will help deliver the products to market.

The aim is to produce chassis-level liquid cooling that’s able to keep pace with the increased use of high-power graphical processing units within data centres, which are by far the most efficient processors for powering AI, IoT and big data analytics but often overheat when paired with traditional air cooling systems.

«Compute intensive applications like AI and IoT are driving the need for better chip performance,» explained Kevin Brown, CTO and SVP of Innovation in Schneider Electric’s Secure Power division.

«Our quantitative analysis and testing of liquid cooling approaches shows significant benefits to the market. This partnership is the next step in solution development and we are excited to be working with Avnet and Iceotope.»

In closed testing, early analysis of the proposed liquid cooling technologies produced CapEx savings of around 15% and energy savings of at least 10%, when compared with traditional air-cooled systems. If deployed, this would lead to total cost of ownership savings of over 11% over a 20-year period, the company claimed.

Schneider has invested directly into Iceotope through its SE Ventures investment arm, which historically has overseen agreements with Habiteo, Element Analytics, Sense and Qmerit. The agreement will essentially see Iceotopes’ current liquid cooling technology, which is already in use across the IT stack, including cloud and edge deployments, brought to the data centre environment for the first time.

Schneider said it was increasingly finding that the sort of GPU chips required for AI and edge deployments often came with thermal design power ratings of 400 watts or more, making air cooling too expensive and inefficient to use extensively.

To combat this, Schneider said it would work towards creating systems capable of being partially submerged in a dielectric fluid. This, it claims, will make cooling systems entirely silent and drastically reduce the form factor, making it also suitable for less power-intensive systems, although it’s unclear how much up-front investment will be required to make this feasible.

David Craig, CEO of Iceotope, said his company was eager to work with Schneider and Avnet to create a product that is able to deliver on the promise of liquid cooling for the data centre.

«Working with great partners that share the same passion for innovation, solution-focused thinking and quality is a pleasure,» said Craig. «Our ability to bring our IP to combined solutions that manage the pressing challenges of chip density, energy and water consumption, space and location challenges and the ever more complex issues relating to harsh environment and climate will be game-changing in the industry.»

Schneider Electric revealed the news at its annual Innovation Summit, held this year in Barcelona.

Microsoft unveils new Teams features in September update


Jane McCallion

2 Oct, 2019

Microsoft has made several updates to its flagship Teams collaboration platform, including new third-party software integrations and improvements to calls and meetings.

A common complaint about enterprise collaboration and chat platforms – such as Slack, Facebook Workplace and others – is that they can be disruptive to workflow, with instant messaging fostering a feeling that users are obliged to provide an instant reply.

Microsoft seems to have taken this issue onboard with the September Teams update.

In a blog post, the company debuted selective muting for channels. Users can mute specific conversations within a given channel if they need to concentrate, with the ability to turn notifications back on when they’re ready. Similarly, if they’ve hidden or muted a channel, they can opt to receive notifications from a particular conversation in it without reactivating the entire thing.

There’s also new activity filters in Chat. For example, a user can search for a colleague’s name and they will be presented with every group and meeting they have in common, as well as one-to-one chats. They can then add additional filters, such as unread messages only. The same type of filtering can also be applied to group chats and the teams list.

There are also several new features in calling and meetings. Users can now send incoming calls directly to Cloud Voicemail, and also make calls through Chrome if they’re using Teams on the web rather than through the app.

There’s also the ability to start a meeting instantly, rather than schedule it ahead of time, and a lightweight ‘meeting join’ capability for people using Internet Explorer, Safari and Firefox.

There’s good news for Lucidchart users too, with the data visualisation company’s app now supporting messaging extensions, link unfurling and collaboration permissions in Teams. This builds upon last year’s release of a Lucidchart app that made document editing and sharing possible within Teams. More details on the enhancements can be found on the Microsoft Teams blog.

Notable by its absence, however, is cross channel posting. This was teased in July, with the promise it would be «coming soon», however it seems that soon is not yet now.

Sainsbury’s looks to Google Cloud for machine learning as retail cloud case studies continue to climb

UK supermarket chain Sainsbury’s is collaborating with Google Cloud on machine learning for greater customer insights – in another example of a cloud partnership among major retailers.

The company is looking at building machine learning solutions on Google Cloud Platform (GCP), in association with Accenture, to ‘provide new insights on what customers want and the trends driving their eating habits’, in the words of Alan Coad, Google Cloud managing director UKI in a blog post.

While that phrasing could be construed as peculiar, the overall goal, of building stronger customer profiles and providing greater value to customers through big data crunching, is one which resonates.

Sainsbury’s analyses data from various structured and unstructured sources, and is looking to Google to clean up the data, classify it, and deliver insights in real-time. Predictive analytics models have been deployed by the supermarket chain to sense trends and adjust inventory as a result. Google Cloud’s retail page outlines a five-step process to data nirvana: scaling infrastructure, developing new applications, unifying data streams and using collaborative tools to get insights faster.

“The grocery market continues to change rapidly. We know our customers want high quality at great value and that finding innovative and distinctive products is increasingly important to them,” said Phil Jordan, group CIO of Sainsbury’s. “With the help of Google Cloud Platform, we are generating new insights into how the world eats and lives, to help us stay ahead of market trends and provide an even better shopping experience for our customers.”

“The food sector is experiencing significant, rapid disruption, and this new cloud-based insights platform will help Sainsbury’s identify trends much earlier and adapt their product assortment in a faster, more informed way – all for the benefit of customers,” added Adrian Bertschinger, managing director for retail at Accenture.

Analysis

The rise in retailers partnering with the largest cloud providers is a trend which has been covered variously by this publication. In particular, the choice of cloud has frequently raised eyebrows. At the start of this year, US grocer Albertsons signed a three-year deal to make Microsoft Azure its preferred public cloud. Pharmaceutical giant Walgreens Boots Alliance signed a similar deal – albeit for seven years – in the same month.

This momentum, alongside a long-running saga last year where Walmart firmly placed its flag on terra Azure, led some to question whether top tier retailers were moving away from Amazon Web Services (AWS), the largest public cloud provider, whose parent company happens to be a rather large retailer. Indeed, according to the most recent Forbes Global 2000 list in May, Amazon surpassed Walmart as the leading retailer for the first time.

While it makes for a nice headline, this trend may be something of a red herring. AWS’ retail customers include Ocado, Under Armour and River Island. Perhaps its biggest customer is itself. Amazon had been gradually moving away from Oracle, and AWS chief executive Andy Jassy announced at the end of last year that Amazon’s consumer arm was now running the vast majority of critical system databases on AWS.

Speaking to CloudTech in April Jean Atelsek, digital economics unit analyst at 451 Research, dispelled the myth. “It’s easy to get the impression that retailers are fleeing AWS,” said Atelsek. “Microsoft’s big cloud partnership with Walmart seems to be the example that everyone wants to universalise to the entire cloud space. However since a lot of retailers also sell through/on AWS, they’re less likely than Walmart to see Amazon (and by extension AWS) as the devil.”

As the Sainsbury’s example shows, organisations across verticals are looking to utilise more mature machine learning models and techniques through the biggest cloud vendors. Even taking into account the buzzword factor, this year has seen an explosion of companies citing ML as a key factor, from media companies for content archiving (The Globe and Mail) to sporting brands for quicker insights (Formula 1), to both (NASCAR).

According to Kantar figures earlier this year, Sainsbury’s fell to third place in terms of the largest UK supermarkets, slipping behind Asda. The collaboration with Google Cloud will look to give the company a foot up; as Coad noted, the company’s vision is to ‘be the most trusted retailer’ and ‘make customers’ lives easier, by offering great quality and service at fair prices.’

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Cisco WebEx and Zoom video hit by security flaw


Nicole Kobie

1 Oct, 2019

Security researchers have uncovered a way for attackers to snoop on video conferences run on the Cisco WebEx and Zoom platforms.

Dubbed «Prying Eye», the flaw spotted by Cequence Security is a weakness in web conferencing APIs that would allow attackers to use an enumeration attack to find open calls or meetings.

Enumeration attacks refer to the practice of using brute force to guess ID numbers – in this case, for meetings or calls. If the attacker guesses the right meeting ID number, and it isn’t password-protected, they have instant access.

That attack technique could work on any application that uses numbers as identifiers, but Cequence notes that it’s common practice to disable basic security such as passwords for web conferences in order to reduce friction for meeting participants. The flaw could be particularly troublesome for anyone who reuses meeting IDs, letting an attacker snoop on all future calls or conferences.

«In targeting an API instead of a web form fill, bad actors are able to leverage the same benefits of ease of use and flexibility that APIs bring to the development community,» said Shreyans Mehta, Cequence Security CTO and co-founder. «In the case of the Prying-Eye vulnerability, users should embrace the shared responsibility model and take advantage of the web conferencing vendors’ security features to not only protect their meetings but also take the extra step of confirming the attendee identities.»

Cequence alerted both companies to the vulnerability in July before taking it public today, giving Cisco and Zoom time to address the flaw. Cisco and Zoom have responded by altering default security settings and issuing advice to customers to help them avoid the vulnerability.

«Notably, the most effective step to strengthen the security of all meetings is to require a password – which is enabled by default for all WebEx meetings,» Cisco’s security team said in a statement provided by Cequence.

Richard Farley, CISO of Zoom Video Communications, said: «Zoom has improved our server protections to make it much harder for bad actors or malicious bots to troll for access into Zoom meetings.»

Farley added that passwords are now enabled by default, but stressed it was still possible to lighten such security settings to whatever is appropriate for different users. He said that, «as is true of other security options, meeting hosts are free to choose security settings that are most appropriate to the sensitivity of their meetings.»

Cequence Security added that it had not tested all other web conference vendors, so others may be at risk as well. The flaw can be avoided by requiring a password on sensitive conference calls or videos, and by confirming the identity of all attendees on a call.

The latest vulnerability comes just under a year after the discovery of a remote code execution flaw in WebEx’s update service, in which hackers could invoke a Windows update service tool which grants the ability to execute commands with system-level privileges.