Why embracing the cloud means preparing for problems you can’t control

Cloud computing. Cloud-native computing. Software as a service. They're all secure and reliable. Except when they're not.

Recently, we've seen Microsoft Azure suffer an extended outage and Docker Hub get hacked. Organisations deploying SaaS applications often assume the vendor provides adequate data protection and they neglect the need for backup. However, the last few years have seen massive outages among some of the major cloud and SaaS providers that seem to have brought down the internet; service outages that might or might not have halted productivity within thousands of companies; and any number of SaaS start-ups shutting down, getting hacked or simply just losing data.

Higher standards of customer experience are driving demand among end-users for always-on services. As a result, end-user tolerance for disruption is at an all-time-low. Simultaneously, end-users now have the power to publicly vent their frustrations with disrupted organisations via social media, thus exacerbating the overall reputational damage of service outages.

Combined with the threat of disruption causing a breach of regulatory compliance and landing organisations with huge penalties such as those stipulated in the GDPR, it is understandable why some organisational leads may hesitate when migrating operational infrastructure to the cloud.

But, of course, clinging to the past would be crazy for any company that actually wants to remain competitive by using and building cutting-edge applications. For all but a small handful of companies (some of which actually run public clouds), there is no realistic vision of a successful future that doesn't involve some combination of clouds, containers and SaaS – probably all three.

The trick is adopting these things intelligently and accounting for the very real possibility that something will, at some point, go wrong. To support any cloud hosted applications, an effective back-up strategy needs to be put in place. The same goes for each SaaS application.

What the best solutions look like will vary widely based on the company, although it seems logical to settle for nothing less than cloud-native best practices around high availability and automated security patching. That means building resilience into the compute, storage and networking tiers, designing apps that tolerate component failure, and sometimes using multi-cloud platforms.

And while container security is a newer concern than, say, VM security, there are a lot of tools-from start-ups, large IT vendors and even open source communities-that can provide peace of mind. A SaaS application that doesn't let you export your data is probably not a SaaS application worth using, but the good news is there's no shortage of SaaS applications.

For example, application components can be automatically patched and upgraded, while application infrastructure should regularly be re-paved in order to expunge any system-level malware or advanced persistent threats. At the application level, a growing number of organisations are adopting tools that automatically scan code for vulnerabilities and offer guidance on how to remedy them.

Ultimately, the process of SaaS backup is similar to backing up a standard but complex on-premise application. Look at the whole service and ensure all the components and dependencies are covered in the back-up plan. When managing a SaaS application, the nature of the business is providing services to consumers, not internal staff. The stakes – in terms of both reputation and financial impact – can be significant. It is essential that, as a provider, any disruptive issues around providing the service are mitigated as much as possible. Backup is part of that continuity planning.

What businesses can't do is let fear and uncertainty get in the way of progress, which is what cloud computing, however defined and in all its forms, ultimately delivers. Getting things like security and reliability right might require spending a little more time and money on software, engineers, and maybe even lawyers, but the payoff over the long term should make up for any early investments many times over.

In today’s business environment, settling for the status quo isn't a viable option, thinking ahead is a much better option than rushing into the cloud and ending up on the receiving end of an outage, breach or other large-scale incident that could have been avoided with just a little forethought.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Cloud security woes strike again – and it’s double trouble for multi-cloud users, research finds

A survey of C-suite executives from Nominet has found that, for more than half of respondents, cloud security remains a concern – which becomes even more critical when multi-cloud comes in.

The study, which polled 274 CISOs, CIOs and CTOs, found 52% were at least moderately concerned about security with regards to cloud adoption. One in five respondents said they were ‘very’ concerned, compared to one in 10 who said they were not at all concerned.

Almost half (48%) of those polled said their organisation had a multi-cloud approach. Yet respondents using a multi-cloud approach were significantly more likely to have suffered a data breach – 52% affirmed this compared with only 24% of hybrid cloud users.

When it came to the specific threats organisations face, respondents were most concerned over exposure of customer data, increased threat surfaces, and improving cybercriminal sophistication.

Almost two thirds (63%) of those polled said they already outsourced certain security services to managed providers. CNI, hospitality and transport were industries less likely to outsource some of their security operations. “Most organisations are happy to outsource when it comes to security, and appear to believe the practice improves their security profile,” the report notes.

The report naturally went through the rigmaroles of cloud adoption statistics, of which a selection is presented herein. The most interesting aspect was that Google Cloud proved the most popular choice of the big clouds, with 56% saying they used it. AWS (32%), perhaps even more interestingly, finished flat last, behind Azure (36%), Oracle (44%) and IBM (49%).

88% of survey respondents said their organisation was either currently engaged in, or planning to, adopt cloud and software as a service (SaaS). 71% overall said they had adopted SaaS, compared with IaaS (60%), PaaS (30%) and business process as a service (BPaaS – 30%). A quarter of respondents said they had function as a service (FaaS) installed.

“The maturity of the cloud means that not only are businesses willing to use it for the delivery of operations and IT services, they are also embracing it for security tools and managed services,” the report notes. “And as businesses look at how the cloud can help make them more secure, ease of integration is top of mind – whether that’s with on-premise applications or other cloud services.

“The move to the cloud won’t be an all-encompassing migration,” the report adds. “Businesses will want to make the most of existing investments and only adopt cloud alternatives once these have reached the end of their product lifecycle.

“Organisations today therefore need cloud security tools that are flexible enough to secure the enterprise as it is today, and as it will be tomorrow.”

You can read the full Nominet report here (email required).

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

CISOs now say cloud technology is ‘just as safe’ as on-prem


Keumars Afifi-Sabet

4 Sep, 2019

The majority of security professionals now consider single-cloud technology to be just as safe, if not safer, than on-premise storage – while multi-cloud environments are deemed the riskiest setups, according to research. 

Cloud technology has seen an explosion in adoption rates among businesses in recent years but has been traditionally considered a riskier option for businesses than on-premise storage.

The majority (61%) of chief information security officers (CISOs), however, have indicated that while security concerns remain, businesses running single-cloud configurations are at no more risk than they would be powering their organisations through on-premise data centres.

There’s also a strong appetite for cloud adoption, with 88% of respondents to a Nominet survey reporting their organisations are either currently engaging in, or have plans to, adopting Software as a Service (SaaS) products.

The research questioned almost 300 CISOs, CTOs and CIOs from large organisations with more than 2,500 employees directly responsible for overseeing cyber security practices.

Some 71% of respondents said they were either moderately, very or extremely concerned with the risk of cyber attack in cloud technology, but these concerns are generally matched by anxieties with on-premise systems.

Interestingly, US respondents were almost twice as likely than CISOs based in the UK to suggest they were «extremely concerned» – 21% versus 13%. This could be based on a host of reasons, including differing compliance regimes, threat landscapes and media coverage of security breaches, the report suggested.

«Security has traditionally always been cited as a barrier to cloud adoption, so it is significant that the perceived risk gap between cloud and on-premise has disappeared,» said Stuart Reed Nominet’s vice president of cyber security.

«It is evident that security concerns are no longer an insurmountable barrier to cloud deployments given the high adoption rate of cloud services.»


Cloud infrastructure is becoming a major funding priority as IT leaders strive towards organisational change. Find out why in this whitepaper.

Download now


He added: «And, as we move into the ‘cloud era’, arguably security teams need to channel their concern into finding solutions that work with the cloud, just as they have been doing in an on-premise environment.»

Adopting a multi-cloud approach, meanwhile, is generally seen as more risk than hybrid and single-cloud approaches.

CISOs adopting such a configuration within their organisations were twice as likely to have suffered a data breach over the past 12 months; 52% versus 24% of single-cloud and hybrid-cloud users.

Organisations adopting a multi-cloud approach were also found to generally suffer a greater number of data breaches, with 69% of respondents reporting 11-30 breaches compared with 19% for single-cloud adopters and 13% for hybrid cloud adopters.

«When it comes to ensuring resilience and being able to source ‘best-in-class’ services, using multiple vendors makes sense,» Reed continued.

«However, from a security perspective, the muti-cloud approach also increases exposure to risk as there are a greater number of parties handling an organisation’s sensitive data.

«This is exactly why an eye must be kept on integration and a concerted effort be made to gain the visibility needed to counter threats across all different types of environments.»

There is a downturn in cloud and data centre infrastructure spending – and China is causing it

Any regular reader of this publication will have noted the regularity in which the largest cloud players – Amazon Web Services (AWS), Microsoft Azure, Google Cloud et al – post solid quarterly financial results. While Wall Street may not have been happy with all of the postings, growth has remained, albeit dipping from the three figure climbs in previous years.

This hyperscaler growth has often been backed up with strong spending across hardware assets. Yet two research companies have noted a decline in the most recent quarters across their industry segments. Both have blamed downturns in China for the change, although it will by no means be an irreversible decline.

Synergy Research, a long-time cloud infrastructure market analyst, noted in August that hyperscaler capex was down 2% based on year-by-year figures. The most recent quarter saw more than $28 billion in spending.  The first quarter of this year, although nearer $25bn, followed a similar pattern. Q118’s figure was still above it, even accounting for the one-off spend of Google buying Manhattan real estate for $2.4bn.

China’s expenditure declined by 37% year on year in Q2, Synergy noted, with Alibaba, Tencent, JD.com and Baidu all reluctant to spend. All other areas saw nominal increases; the US saw the most with 5% yearly, ahead of EMEA (3%) and the rest of APAC (2%). Taking China out of the mix would see overall figures jump 4% year on year.

Synergy’s figures come from the data centre and capex footprint of 20 of the world’s largest cloud and internet service firms. The ‘big five’, in this instance Google, Amazon, Microsoft, Facebook and Apple, usually dominate.

“Usually it is the big five that dictate the scale and trends in hyperscale capex, but the drop-off in spending in China has been so marked that an otherwise strong worldwide growth story has been transformed into a modest capex decline,” said John Dinsdale, a chief analyst at Synergy.

This situation is echoed when it comes to data centre switches. According to telecom and network analyst Dell’Oro Group, ‘weakness in China’ suppressed data centre switch market growth in Q219. The decline was the first seen in five years, down to both a slowdown in spending from cloud service providers and enterprise, as well as continued uncertainty over Huawei.

“In contrast, data centre switch market revenue in North America managed to grow despite a slowdown in spending by major cloud service providers,” said Sameh Boujelbene, Dell’Oro Group senior director. “Most of the slowdown was driven by reduced server purchases while data centre switches performance well. Large enterprises also contributed to the growth in North America as they accelerated their 100 GER adoption and helped Cisco emerge as the new leader in 100 GE revenue in Q219.”

“The situation in China is likely to be a short-term phenomenon, however, as the four Chinese hyperscale operators continue to grow revenues more rapidly than their US-headquartered counterparts,” Dinsdale added. “After some short-term financial belt-tightening, we expect to see Chinese capex rise strongly once again.”

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Firefox now blocks third-party trackers by default


Keumars Afifi-Sabet

3 Sep, 2019

The desktop version of Firefox will block cookies and cryptocurrency mining by default as part of sweeping changes to the web browser aimed at safeguarding user privacy.

Mozilla will enforce Enhanced Tracking Protection (ETP) as standard practice for all users as part of the default Firefox configuration, from today, and will block known third-party tracking cookies, the company has announced.

The cookies will be cross-referenced with the ‘Disconnect’ list of known third-party trackers that comprise websites that collect and retain data regarding users’ activity across multiple sites or applications.

This feature has been widely-anticipated since Mozilla outlined its plans in January, and has been available for new users since June this year. The feature now, however, concerns a fresh approach to anti-tracking the firm outlined recently based on testing and revision.

Mozilla also previously teased a subscription-based version of Firefox with additional privacy-centric features, which also reportedly featured ETP available as standard.

«Currently over 20% of Firefox users have Enhanced Tracking Protection on. With today’s release, we expect to provide protection for 100% of our users by default,» Mozilla said.

«Enhanced Tracking Protection works behind-the-scenes to keep a company from forming a profile of you based on their tracking of your browsing behaviour across websites – often without your knowledge or consent.

«Those profiles and the information they contain may then be sold and used for purposes you never knew or intended. Enhanced Tracking Protection helps to mitigate this threat and puts you back in control of your online experience.»

The ETP functionality will also work in the background to prevent illicit cryptocurrency mining scripts from draining users’ CPU usage and battery power on their devices. This feature has existed in previous beta versions of Firefox but is now available as standard to all.

Users will know ETP is switched on by the appearance of a purple shield icon in the far-left corner of their address bar. This will show when users visit websites on which third-party tracking cookies are being actively blocked.

Firefox will also block fingerprinting scripts – which harvest a sampling of details from users’ devices when visiting a particular website – by default. This snapshot of information can then be used to track users across the web.

Users can block fingerprinting scripts if they turn on ‘strict mode’, with Mozilla also suggesting this protection will be bundled into the default settings in future releases.

Putting data security at the heart of digital transformation – from culture to code

In the new digital economy, data is the most valuable asset a company possesses. However, according to a recent survey by IDC, the spending ceiling for data security is as low as six per cent of the total security budget. Understandably, many information security professionals are feeling the pinch – and increasingly burning out and leaving the industry according to Goldsmiths, University of London – and companies aren’t spending enough on data security to prevent bad attackers from swiping the family silver.

At the same time, large-scale digital transformation projects continue to be high-profile news. The IDC report also found that 97 per cent of respondents were using sensitive data on new technologies as part of digital transformations, but fewer than 30 per cent were using tools, such as encryption, to keep that data secure within these environments.

This lack of security is a worrying trend when security should be included by design in digital transformation projects and implemented as early as possible in this new approach to the software development lifecycle.

Securing software

Software is eating the world; Marc Andreessen’s famous description of the need for every company to become a software business has been devoured by enterprises, but this rapid process of change has given many organisations indigestion and security headaches to boot. These investments are strategic ones, but they can often move ahead far faster than security teams can get involved.

Behind these changes, there are some bigger IT adoption trends taking place too. For example, environments have changed; many enterprises have moved from private cloud to hybrid cloud and are now embarking on multi-cloud. Our own  Modern App Report found that multi-cloud adoption had doubled year on year to around 10 per cent of companies.

Similarly, application architectures have shifted from the traditional three-tier, client-server approach to new microservices-based approaches. The technology stack is now shifting to containerised applications that are orchestrated by the likes of popular open source platforms such as Kubernetes. The responsive, flexible and scalable capabilities of these technologies has yielded significant performance and efficiency gains but it has added greater complexity.

The ephemeral nature of technologies, such as Docker and Kubernetes, has meant that the security tools used to collate data from these applications like security incident and event management (SIEM) are unable to keep pace with the rate of change taking place. Without this data and insight into your company’s applications and data, it’s simply not possible to gain insight into your security posture.

Planning out any digital transformation project should requires a thorough security needs assessment too. If done correctly, this provides a complete overview of your operating conditions and how processes operate, and it helps meet the business demands that digital transformation projects require.

Implementing a data-driven baseline as part of this process is also a vital way of protecting your enterprise. Using machine data – all the data created by all the applications, infrastructure components, cloud services and more – should supply more meaningful insights from metrics, logs and thresholds that you can evaluate in the current infrastructure and assess again once the project is live and running. 

The right DevSecOps tools

Getting this visibility around the cloud can help development, security and operations teams converge their approaches. This convergence – commonly called DevSecOps – involves making security into a continuous process that is part of the development lifecycle. This convergence can help maintain the speed of digital transformation while also ensuring security rules get followed from the start.

A DevSecOps approach differs to old delivery pipeline methods in that traditional software development priorities have not tended to address software vulnerabilities from the start. When software development relies on integrating third party programme components or publicly available images to create these services, this supply chain element becomes more important for all the teams involved.

Alongside this, there is a common assumption that DevSecOps is only about making sure that your security teams are working with developers and IT Ops teams. However, DevSecOps should go deeper than that in order to be successful. It’s an approach that sees security as code, building data protection and privacy thinking into the code itself from all stages: starting in design and architecture through to development, QA, pre-production and into production.

In practice, this means working with development teams on code is delivered in small updates and building security checks into the process so that any vulnerabilities can be spotted quickly before they go into production. This involves taking a more proactive approach that sees compliance monitoring baked in as well. This effectively positions your organisation in a constant state of audit readiness.

As you may have guessed, time-consuming manual security analysis and auditing will slow down the frequency and speed of software delivery. Automation is therefore integral to the success of DevSecOps, as areas such as threat investigation must be ongoing for any emerging threats and vulnerabilities as they are identified with code analysis. Using automated scans and analysis of data across the application, DevSecOps teams can concentrate on where they can provide the most value rather than on spending time on manual correlation of potential issues.

Empowering IT teams

The DevSecOps principles should not be seen as a silver bullet for digital projects; indeed, they are only effective with the right tools and data to power them. Implementing DevSecOps has to be based on a common approach to the applications and services involved. There will be too many interactions taking place to decipher without a unified approach for monitoring and fine-tuning operations.

Making security the responsibility of everyone across IT does mean having to manage different levels of experience around software and security. Generally, software developers don’t have the same history in looking through alerts to discern which ones are serious and should be investigated as risks, while they do have more expertise in new application design practices and how to put services together. Providing the right level of data – and making sure it can be made actionable and relevant for each team – is, therefore, something to consider as you implement your DevSecOps processes.

In a fast-paced environment, security tools that generate too many false positives can be as serious a problem as sticking with manual security testing. If too many issues come through, it can lead to “alert fatigue” and serious issues can be then be missed. By developing a baseline and monitoring alert levels, IT teams can avoid this problem. Similarly, you can automate common responses to potential conditions or threats. At the same time, data can help teams to interact in real time around real risks or potential threats in software systems as they are discovered.

Digital transformation is still gathering pace – more and more organisations are looking at how to improve their agility and keep up with competitors. However, this should not come at the cost of security. In the same way that DevOps is a fundamentally different approach to developing and delivering software, DevSecOps represents a completely different approach to making software secure. This approach is necessary if companies want to get all the potential value of their digital investments and avoid unnecessary risks.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

How Abbots Care gained greater assurances around data security with a revamped DR and backup strategy

Case study All data is equal, but for some industries, data is more equal than others. As a result, great care needs to be taken when it comes to keeping that data secure, whether in the cloud or anywhere else.

Healthcare, across its various channels, is a classic example. Some healthcare organisations are moving with less trepidation towards the cloud. In February, for instance, a study from Nutanix found that, by 2021, more than one in three healthcare organisations polled said they would be deploying hybrid cloud solutions. At the start of this year, pharmaceutical giant Walgreens Boots Alliance selected Microsoft as its primary cloud provider, with the majority of its infrastructure moving across to Azure.

Regardless of where it is hosted, the non-negotiables for healthcare providers are that the data can be accessed to its demands and that it is unimpeachable.

Abbots Care, a home care company based in Hertfordshire, is like any responsible UK provider under the regulatory jurisdiction of the Care Quality Commission. As managing director Camille Leavold puts it, one data breach could mean the company’s licence is taken away.

Leavold therefore wanted more assurance of how secure her company’s data was – and as a result she turned to managed IT services provider Fifosys.

“About two years ago, we were at a stage where we had quite a lot of data,” Leavold tells CloudTech. “Although we were using a company that said our data was secure and safe, we actually didn’t have any way of being able to evidence that.

“Obviously we’re quite in a compliant sector, and we needed to be able to evidence it. That started us looking,” she adds. “We were also looking for a company that was 24/7, because we are too.”

Mitesh Patel, managing director of Fifosys, went through the standard detailed audit when the work originally went out to tender. Basic questions around the backing up of data, recovery times and sign-off process highlighted risks which ‘weren’t acceptable’ to Leavold, as Patel puts it. Fifosys’ solution ties in to the company’s partnership with business continuity provider Datto, whose technology, according to Fifosys technical director James Moss, is ‘effectively a mini-DR test every day.’

Fifosys runs two official recovery tests a year, with the results sent to Leavold who can then present them to the board. “It’s no longer something hidden where you’ve gone ‘okay, there’s a vendor dealing with it, we’re going to be blind to it,” Patel tells CloudTech. “The recovery process… they get a report, that’s discussed – is this timeframe acceptable? – [and] are there any tests they want to do outside of this?”

Like many healthcare providers, Abbots Care also needs a good ERP system to ensure all its strands are tied up – particularly with care workers out in the field, checking on their tablets and devices which patients they need to see, their medication, and the service which needs to be provided at that time. "There's a lot for Abbots Care that they need to have up and running, and when you're scheduling so many people out in the field, these systems need to be up," says Patel.

Another consoling aspect is that the company’s backup and disaster recovery is all in one place. “[If] you can’t answer the [audit] questions and you’ve got five or six different vendors involved in delivering your backup, your continuity, applications, recovery… it’s fine you’ve got these vendors in, but your recovery time is extended continuously,” explains Patel. “Who’s actually responsible? Whose neck is on the line in the event that something does happen?”

Outages are unfortunately a fact of life, as even the largest cloud providers will testify, but can be mitigated with the right continuity processes in place. “Continuity was a big, big part for them, and then it’s all in terms of protecting the data and having versions of it,” explains Patel.

“There are organisations who say they’ve got four sites, and [they’re] just going to replicate across those four sites and invest in the same infrastructure on all four. That’s very difficult to maintain, administer and manage,” Patel adds. “When you are testing, you find people are only testing one of their sites rather than all four.

“You should be doing four tests at least twice a year – but the time involved in doing that, many people underestimate [it] and then start compromising.”

You can find out more about the case study by visiting here.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Why adaptability is critical to meet future data centre demands

The next wave of technology innovation is already here with new applications transforming the way we live, work and travel. With the emergence of the Internet of Things (IoT), artificial intelligence (AI), cloud-based services, 4K videos and 5G networks, data centre operators must provide more data capacity and higher computing power if they hope to keep up with the unprecedented demands.

The sheer scale and scope of the gap the industry faces, demand that network operators rethink the way they have traditionally organised the design and deployment of networks and data centres.

According to Gartner, by 2025, the number of micro data centres will quadruple, due to technological advances such as 5G, new batteries, hyperconverged infrastructure (HCI) and various software-defined systems (SDx). By the same year, enterprise data centres will have five times more computational capacity per physical area than today.

With demands for data increasing at such an unprecedented rate worldwide, operators are under mounting pressure to develop and build data centres that can handle the increased connectivity and bandwidth demands that these new technologies bring. Data centres are being forced to adapt to the demands of their ever-changing environments and in order for to prepare for future demands, operators need to invest in technology that will grow alongside them.

Change needs to happen in order to be prepared for the future

With the continuing advancement of technologies at a rapid rate, the availability of computing and storage with ultra-low latency needs to be at the forefront of operators’ minds. Downtime of data centres carries enormous cost implications to an operator, making it crucial that there are fibre management solutions in place that make day-to-day operations as seamless as possible. 

If data demands continue at the current rate, it is predicted that hyperscale data centres would need to be upgraded every two years to keep up with the bandwidth and storage demands. The cost and time implications for operators to overhaul the entire system every couple of years would be astronomical. Instead, operators need to be doing all they can to invest in technology that future-proofs their investments.

The evolution of data centre infrastructure starts with simplification. Data centre infrastructures are changing from predominantly complex or proprietary systems to repeatable and predictable, standardised around Commercial Off-the-Shelf (COTS) infrastructures. In addition, fast-paced adoptions of new advances with systems such as hyperconvergence, software-defined and composable infrastructures are adding resources for standardisation, rationalisation and consolidation initiatives.

Cabling is critical to the future of data centres

Fibre management systems are crucial in organising the cabling in a clear and concise way, reducing the risk of damage and downtime. With such large costs associated with inaccessible data, downtime is simply not a possibility for a data centre operator. With hyperscale data centres containing hundreds of servers, it is absolutely crucial that there is no error when it comes to moves, adds and changes (MACs) of fibre connectivity.

Due to the complexity of fibre cabling and the implications that can occur through error, operators need to deploy flexible, comprehensive fibre management systems that can be managed with ultimate ease and maximum efficiency.

In order to achieve the ultimate level of protection and maximum ease, operators should install fibre optic systems in the meet-me-room (MMR) or main distribution area (MDA) that are high-density with a clear demarcation point. Selecting a dense cross-connect fibre management system is best. By having all the connections in one location, there are fewer reasons for someone to interact with the active equipment in the data centre and subsequently cause an error.

With its market leading modular LISA Double Access fibre management system, HUBER+SUHNER has revolutionised how structured cabling in data centres work worldwide. In the future, such a short time-to-market turn around will be required. With ever-increasing bandwidth and connectivity demands, it is critical to adapt quickly and select a fibre management system with interchangeable modules that can be easily installed, exchanged and removed.

This modular approach makes the cabling structure in a data centre incredibly flexible. The fibre management system can be installed in a multitude of positions whether that be against a wall, the end of a row or back to back in a row. With a variety of layouts possible, the system can easily be implemented in the main distribution area (MDA) but also in the horizontal distribution area (HDA).

With the pressure on data centres only set to increase in the future, operators need to consider all options available to them and remain flexible and ready for any eventualities that may arise. There are many options on the market for operators to consider when selecting a fibre management system, but by using a fibre management system with a modular pay-as-you-grow infrastructure, data centres have the capability to continuously evolve and adapt to reflect the ever-increasing future demands.

Preparing for the unknown

Over the last fifty years, enterprise data centres have been responsible for storing and processing critical business information and have evolved gradually and conservatively during that time. However, traditional data centres are now feeling the impact of disruption from cloud, edge computing, advances in colocation and hosting services. In addition, advances in the areas of power, cooling, telecommunications, AI, operations, hardware and software are transforming enterprise data centres as never before. Traditional on-premises data centre models must evolve to play a role in modern enterprise information management.

In order for data centre operators to be in with a good shot of keeping up with the unprecedented demands they need to take advantage of the systems that enable them to do their jobs effectively. As technological innovation continues, the pressure on data centres is only going to mount further. Simple, high-density fibre management systems with easy handling designs that clearly demonstrate the incoming and outgoing connectivity, will be critical to the future of data centres.

Picture credit: HUBER+SUHNER

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

View From the Airport: VMworld US 2019


Adam Shepherd

30 Aug, 2019

I think it’s fairly safe to say that I picked a good year to visit VMworld US for the first time. While I’ve been to its European equivalent, this was the first year I went to the main event and it was something of a doozy.

Not only did we get a nice bit of pre-conference sizzle with the news that VMware is acquiring Carbon Black and Pivotal, but the entire show was also a festival of product updates and previews. More than anything else, it felt like a statement of intent from Gelsinger and his comrades, setting out the company’s stall for the future.

The big focus of the show – and of VMware’s main announcements – was Kubernetes. The company is betting big on the container technology as the future of application development, with plans to weave it into vSphere with Project Pacific, and use Pivotal and Bitnami’s technology to make VMware even more attractive to Kubernetes developers. Virtually every main-stage announcement featured Kubernetes in some capacity, and VMware veteran Ray O’Farrell is being put in charge of getting that side of the business (including the forthcoming Pivotal integrations) running smoothly.

All the new Kubernetes-based products – Project Pacific, Tanzu and the like – are still in tech preview with no release date in sight and, honestly, that’s probably a good thing. I’m really not sure how many of VMware’s customers are ready to start deploying containers at scale. Mind you, making Kubernetes management a core part of VMware’s capabilities may well go a long way towards encouraging adoption.

It feels like a future-proofing measure more than anything else. Gelsinger is a sharp guy and when he says that containers are the future, he’s not wrong. It may not have reached mass adoption yet, but it’s growing fast, which isn’t surprising given the technology’s proven benefits. This isn’t a pivot though; VMs aren’t going anywhere, as Gelsinger himself has been quick to point out. He notes that all the companies operating Kubernetes at scale – Google, Microsoft, Amazon, et cetera – operate them inside VMs. More to the point, it’ll be a long time yet before Kubernetes gets anywhere close to rivalling VMs in terms of the number of production workloads.

Between the new possibilities promised by Project Pacific, the increasing focus on multi-cloud infrastructures and the forthcoming integration of Carbon Black’s technology into the product line, VMware looks like a company at the absolute top of its game, cementing its dominance of the virtualisation market and paving the way for that dominance to continue long into the future. If Gelsinger, O’Farrell and the rest of the team can pull off everything they’ve promised, then customers and admins have a lot to look forward to.

The continuing rise of Kubernetes analysed: Security struggles and lifecycle learnings

Analysis The rapid adoption of container technology, DevOps practices, and microservices application architectures are three of the key drivers of modern digital transformation. Whether built in the cloud, on-premises, or in hybrid environments, containerisation has proved to be significantly more advantageous in terms of scalability, portability, and continuous development and improvement.

More recently, organisations have began to standardise on Kubernetes as their container orchestrator. Tinder recently announced the company is moving their infrastructure to Kubernetes. Soon after, Twitter announced its own migration from Mesos to Kubernetes.

While the reasons behind such a rapid adoption of Kubernetes has been well documented, security issues remain one of the biggest concerns for organisations. When you ignore your container and Kubernetes security, you might find yourself in the headlines for all the wrong reasons—just ask Tesla.

To better understand the trends in container and Kubernetes security and adoption, we conducted a survey of over 200 IT security and operations decision makers in November of 2018. We recently repeated the survey across nearly 400 individuals in security, DevOps, and product teams to gain additional insights into how organisations are adopting container technologies and how their security concerns have evolved.

The results are aligned with the prediction from Gartner that by 2022 more than 75% of global organisations will be running containerised applications in production – a significant increase from fewer than 30% today.

Kubernetes adoption grows by 50% in first half of 2019

Originally built by Google—based on the lessons learned from the Borg and Omega projects—Kubernetes was open-sourced in 2014 as a platform for automating deployment, scaling, and management of containerised applications. Google partnered with the Linux Foundation to form the Cloud Native Computing Foundation (CNCF) to manage the Kubernetes open-source project.

In an early sign of Kubernetes going mainstream, in 2016 Niantic released the massively popular mobile game Pokémon Go, which was built on Kubernetes and deployed in Google Container Engine. At launch, the game experienced usability issues caused by a massive user interest in U.S—the number of users logging in ended up being 50x the original estimation, and 10x the prediction for worst case scenario. By using the inherent scalability advantages of Kubernetes, Pokémon Go went on to successfully launch in Japan two weeks later despite traffic tripling what was experienced during the U.S launch.

Since then, Kubernetes usage has taken off. In our original survey conducted in November of 2018, 57% of respondents said they were orchestrating their containers with Kubernetes, which was at the time already more than any other orchestrator in the market. When we conducted the survey again in July 2019, the percentage of survey respondents who said they use Kubernetes as their orchestrator grew from 57% to 86% – a 50% increase.

And despite the fact that all major cloud providers offer their versions of managed Kubernetes service—with a primary value prop of being easier use—a sizeable portion of Kubernetes users opt for self managing their clusters. This is because self-managed Kubernetes provides greater flexibility to porting an existing Kubernetes application to another environment that’s using Kubernetes.

Kubernetes and container security concerns increase in lockstep with adoption

Security concerns continue to be one of the primary constraints for using containers and Kubernetes. 2019 saw the discovery of several high-severity container and Kubernetes vulnerabilities, including the runC vuln, a k8s privilege escalation flaw, a DoS vuln, and several other vulns that were announced earlier this month as part  of a CNCF audit.

Most respondents identify inadequate investment in security as their biggest concern about their company’s container strategy. Moving to a containerised/microservices architecture introduces several new container and Kubernetes security considerations, and existing security tooling isn’t suitable to address them.

Organisations need dedicated security controls purpose-built for containers, Kubernetes, and microservices, to meet their security and compliance obligations. For example, unlike traditional waterfall method of application development, modern app dev methodologies rely on continuous integration and continuous delivery (CI/CD) where security controls must be deeply embedded in the CI/CD pipeline for it to be effective.

Once again, respondents identified runtime as the life cycle phase that organisations are most worried about; however, most organisations understand that runtime failures are a function of missed security best practices during the build and deploy phases. Not surprisingly, more than half (57%) of respondents are more worried about what happens during the build and deploy phases. In other words, users realise they must "shift left" in their application of security best practices to build it right the first time.

Containers and Kubernetes are running everywhere

One of the interesting findings of the survey report was how diverse container and Kubernetes environments tend to be. While 70% of respondents run at least some of their containers on-premises, 75% of those running on-premises are also running some in the cloud, which means that any workable security solution has to span both environments.

Today, more than half of respondents (53%) are running in hybrid mode compared to 40% at the end of 2018. As a result, the percentage of organisations running containers only on-premises has dropped nearly in half (from 31% to just 17%), while cloud-only deployments have remained steady.

As expected, AWS continues its market dominance in container deployments, followed by Azure. Google comes in third but has gained considerable market share, growing from 18% to 28% over six months.

DevSecOps – not just a catchy term

Traditional security processes can become a barrier when building software using DevOps principals. The increasing complexity of security threats facing enterprises is leading to DevSecOps playing a crucial role.

Across all operations roles, the allocation of management responsibility by role remained consistent, but the jump in those citing DevSecOps as the responsible operator for container security is significant.

When isolating only those survey respondents who are in a security or compliance role, there is an even larger jump in allocation of responsibility to DevSecOps – 42% of respondents in a security or compliance role view DevSecOps as the right organisation to run container security programs.

Final thoughts

Despite the fact that container security is a significant hurdle, containerisation is not slowing down. The advantages of leveraging containers and Kubernetes—allowing engineers and DevOps teams to move fast, deploy software efficiently, and operate at unprecedented scale—is clearly overcoming the anxiety of security concerns.

Organisations are charging ahead with moving their containers to production. The percentage of organisations with more than 50% of their containers running in production environments has increased from 13% to 22% – a growth rate of 70%. In the same six months, those running less than 10% of their containers in production has fallen from 52% to 39%.

Organisations shouldn’t treat security as an afterthought. Unlocking the benefits of cloud-native technologies while maintaining strong security for mission critical application development infrastructure requires protecting the full container life cycle – across build, deploy and runtime phases.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.