Skybox and Zscaler team up for stronger cloud firewall integration

If there is one thing safer than a cloud security provider, it is two cloud security providers – in theory, at least. Zscaler and Skybox Security are coming together to connect two of their products for greater end-to-end protection.

The two companies will combine Zscaler’s Cloud Firewall product with the Skybox Security Suite, which encompasses visibility, vulnerability control, as well as firewall and network assurance for enterprise use cases. Zscaler policy information will feed directly into the firewall and network assurance modules. The data will help inform Skybox’s visual model for hybrid networks.

Customers of Zscaler Cloud Firewall will be able to ensure they are adhering to policies more easily, as well as automatically flagging violations.  

“Organisations need a seamless way to deliver a consistent and compliant policy on or of network,” said Punit Minocha, SVP of business and corporate development at Zscaler in a statement. “Zscaler cloud platform’s fast and secure policy-based access connects the right user to the right service or application.

“Combined with the Skybox security policy management solution, we simplify management and allow customers to transition their access policies to a modern cloud architecture,” added Minocha.

Last week Skybox issued its mid-year report on vulnerability and threat trends which argued, among others, that cloud container vulnerabilities were on a steady upturn. Vulnerabilities in container software had increased by 46% in the first half of 2019 compared with the year previously, the company noted.

The overriding theme was of good news and bad news. While it was good that only a ‘small fraction’ of vulnerabilities published will have an exploit, increasing network complexity makes it much tougher to understand what goes where.

“It’s critical that customers have a way to spot vulnerabilities even as their environment may be changing frequently,” said Amrit Williams, Skybox VP products at the time. “They also need to assess those vulnerabilities’ exploitability and exposure within the hybrid network and prioritise them alongside vulnerabilities from the rest of the environment – on-prem, virtual networks and other clouds.”

Getting a greater handle on whether vulnerabilities are infiltrating the enterprise network is naturally key – and it is a cornerstone of the Zscaler and Skybox partnership. You can find out more about the collaboration here.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Office 365 ban in German schools ‘temporarily’ lifted


Dale Walker

2 Aug, 2019

A ban on the use of Office 365 products in German schools has been temporarily lifted following a series of talks between Microsoft and the Hessian Data Protection Commissioner, according to an updated statement released today.

The German state of Hesse imposed restrictions on the use of Microsoft software in July after ruling Office 365 exposed information on students and teachers to potential access from US officials, and was therefore in breach of the EU’s General Data Protection Regulation.

The decision followed several years of debate around whether German public authorities should use such cloud software at all, given that a large chunk of data is funnelled back to the US.

Office 365 was largely tolerated so long as Microsoft continued to invest in a local German cloud service, removing the need to send data back to the US. However, last August the company decided to shutter this service, leading officials to eventually conclude last month that Office 365 use no longer complied with data laws.

Yet, in another twist, the Hessian Data Protection Commissioner, Professor Michael Ronellenfitsch has now decided to «provisionally tolerate» the use of Office 365 in German schools, provided a series of conditions are met.

«The legality of using Office 365 is not yet fully understood,» said Ronellenfitsch, in a statement. «In my opinion dated 09.07.2019 I have drawn the conclusion and explained that according to the state of the checks, the use of Office 365 in Hessian schools can not be tolerated.

«Since then, there have been intensive discussions with Microsoft about the privacy compliance of Office 365’s use in the school, which has led to a privacy-related assessment and has invalidated a significant proportion of the concerns.»

The ruling allows schools that have already purchased version 1904 of Office 365 and its various apps to continue using the software «until further notice».

However, those schools are also required block the transmission of any kind of diagnostic data themselves, although Microsoft is required to provide support with this – that is until the data protection authorities are able to provide a more permanent solution.

The Hessian data authority has also promised to conduct an audit of the current arrangement over the next few months, and will deliver a more permanent data protection assessment for the school sector, the statement added.

The decision appears to be something of an attempt to limit any potential disruption an outright Office 365 ban might have. However, it’s likely that the ban will return unless Microsoft comes up with a way of preventing diagnostic data from leaving the country.

David Friend, Wasabi CEO: Cloud storage will be a commodity – and clever vendors can make the most of it

Boston-based Wasabi Technologies has a clear business strategy. “We only do storage,” CEO David Friend tells CloudTech. “We don’t do compute, we’re not going to buy supermarkets, or make movies or TV shows – we just do storage and we’re very good at it.”

This will be the first, but not the last, veiled reference to a certain Seattle-based cloud storage provider. In some ways it is a legitimate concern. Amazon Web Services (AWS) has the largest share across infrastructure by a distance – between a third and half, depending on who you believe – but it also has plenty of offerings around software.

In fact, Amazon has just about everything. Across its 23 categories, there are a grand total of 183 products under the AWS banner, with management and governance, as well as machine learning, top of the tree with 19 each. Wasabi, by contrast, has just one. It’s a complexity thing, Friend argues.

“Our vision is that cloud storage will just become a commodity,” says Friend. “We don’t believe in having all these goofy tiers, because Wasabi is faster than [Amazon] S3 and cheaper than Glacier. So you don’t need six tiers of storage in between with all the complexity that implies and the consultants you have to hire in order to figure out what data to go in what tier.”

Whereas Glacier is cold storage, cheaper for workloads accessed once in a blue moon, Wasabi focuses on the opposite. The clue is in the name, with the company having been called BlueArchive in a previous life. Wasabi’s pricing model is simple: $5.99 per terabyte per month, translating to $0.0059 per gigabyte, with no additional charges for egress or API requests.

Maslow’s hierarchy of needs is often crudely bastardised to add ‘Wi-Fi’ or ‘internet’ to the bottom tier; with commoditisation, perhaps storage needs to be added beneath it. Things have come a long way from when Steve Jobs rebuked Dropbox as being merely a ‘feature’, after Drew Houston turned down the Apple chief’s acquisition offer.

Friend, alongside Thomas Koulopoulos, penned an eBook published earlier this year around the concept of the ‘bottomless cloud’, and spoke on the topic at the recent Cyber Security & Cloud Expo event in Amsterdam.

“We were talking about changing the mindset from thinking of data as sort of a scarcity to more a mindset of data abundance,” says Friend. “The idea that data storage gets to be so cheap that it’s not worth deleting anything.

“The people who are throwing away their data because they don’t see any immediate need for it… five, 10 years from now they’re going to look back and say ‘wow, with all the analytical tools we have today, I wish we had saved that data because we could be using it to gain competitive advantage, gain insights into what our customers are doing and what they want,’” adds Friend

“That’s the mindset that we have to change. We have to think about data as something which has probably got future value that’s in excess of what we think it might have today; we need to think of cloud storage the same way we think of electricity or bandwidth.”

Naturally, if you’re going to take on AWS the battle cannot be won alone. Wasabi has emboldened its approach in recent months with expanded geography to Europe and a channel strategy; the former saw a data centre open in Amsterdam in March, while the latter included partnerships with Veeam and Pax8 among others.

“In Europe particularly, we’re going all-channel for practical purposes,” explains Friend, albeit adding users could still sign up for storage directly. “When you look at Veeam’s new cloud-enabled backup product, there’s a dropdown menu. You can pick Amazon storage, Google storage, Microsoft, IBM, and Wasabi. So we’ve broken into the ranks of the top storage vendors now, and that’s clearly where we want to be.”

As far as managed service providers (MSPs) are concerned more generally, Friend notes that the move to the cloud – and the recurring revenue which results – reaps its own rewards. “We’re teaching the MSPs how to make money in this,” he says. “Instead of getting a one-time pop for a box, you get a revenue stream that goes on and on year after year. If you’re the person selling this cloud storage, every year they’re paying for what they’re using, and it just grows.

“It’s an opportunity for the MSPs to really get on the bandwagon and get in front of the cloud migration curve.”

Even though the hyperscalers are hogging public cloud infrastructure, plenty of innovation can still be found. Friend cites Stackpath, a content delivery network (CDN) and edge computing provider, and fellow CDN-er Limelight as companies ‘flourishing off picking pieces’ of the cloud.

“What the MSPs can do is learn how to put these things together and make money,” Friend adds. “That’s the part that we’re playing. Right now we’re the big guys in independent cloud storage, and we can provide the MSP with a great revenue stream.”

Picture credit: Wasabi Technologies

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

VMware extends Google Cloud deal, positions as hybrid partner of choice for the hyperscalers

VMware and Google Cloud have extended their partnership with the launch of a new offering which enables organisations to run their VMware workloads in Google Cloud Platform (GCP).

The product, the snappily titled Google Cloud VMware Solution by CloudSimple – the latter being a verified VMware cloud partner – will give customers the opportunity to run VMware workloads on-prem, in the cloud, or as part of a hybrid architecture.

Both sides naturally came across as agreeable in the soundbites. “With VMware on Google Cloud Platform, customers will be able to leverage all of the familiarity and investment protection of VMware tools and training as they execute on their cloud strategies, and rapidly bring new services to market and operate them seamlessly and more securely across a hybrid cloud environment,” said VMware COO Sanjay Poonen.

Google Cloud CEO Thomas Kurian noted similarly in a blog post confirming the news. “Customers have asked us to provide broad support for VMware, and now with Google Cloud VMware Solution by CloudSimple, our customers will be able to run VMware vSphere-based workloads in GCP,” wrote Kurian. “This brings customers a wide breadth of choices for how to run their VMware workloads in a hybrid deployment, from modern containerised applications with Anthos to VM-based applications with VMware in GCP.”

The move – as Poonen noted – meant VMware now supported the five largest clouds, in this instance AWS, Azure, Alibaba and IBM alongside Google. VMware’s dealings with AWS are better known; the launch of AWS Outposts last November all-but brought the house down at re:Invent when CEO Pat Gelsinger took to the stage. Outposts enables organisations to deliver a ‘truly consistent hybrid experience’, in the company’s words, either AWS-native or running VMware Cloud on AWS.

VMware’s positioning as a partner has been long in coming and is coming to a head now. In February 2015, this publication put out an op-ed titled ‘Here’s why VMware hasn’t left it too late with its hybrid cloud push.’ Back then, VMware’s move to cloud was relatively late, having previously had a long-standing heritage in virtualisation. Many companies had their aborted attempts to move into the public cloud – CenturyLink and Verizon to name two in the telco space – yet VMware evidently saw two apparent trends.

Enterprises were not only going to focus on a handful of primary players for their public cloud infrastructure – and not focus on just one vendor but go multi-cloud – but they were also not going to give up certain on-prem assets.

You can read the full Google Cloud blog here.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

VMware extends Google Cloud deal, positions as hybrid partner of choice for the hyperscalers

VMware and Google Cloud have extended their partnership with the launch of a new offering which enables organisations to run their VMware workloads in Google Cloud Platform (GCP).

The product, the snappily titled Google Cloud VMware Solution by CloudSimple – the latter being a verified VMware cloud partner – will give customers the opportunity to run VMware workloads on-prem, in the cloud, or as part of a hybrid architecture.

Both sides naturally came across as agreeable in the soundbites. “With VMware on Google Cloud Platform, customers will be able to leverage all of the familiarity and investment protection of VMware tools and training as they execute on their cloud strategies, and rapidly bring new services to market and operate them seamlessly and more securely across a hybrid cloud environment,” said VMware COO Sanjay Poonen.

Google Cloud CEO Thomas Kurian noted similarly in a blog post confirming the news. “Customers have asked us to provide broad support for VMware, and now with Google Cloud VMware Solution by CloudSimple, our customers will be able to run VMware vSphere-based workloads in GCP,” wrote Kurian. “This brings customers a wide breadth of choices for how to run their VMware workloads in a hybrid deployment, from modern containerised applications with Anthos to VM-based applications with VMware in GCP.”

The move – as Poonen noted – meant VMware now supported the five largest clouds, in this instance AWS, Azure, Alibaba and IBM alongside Google. VMware’s dealings with AWS are better known; the launch of AWS Outposts last November all-but brought the house down at re:Invent when CEO Pat Gelsinger took to the stage. Outposts enables organisations to deliver a ‘truly consistent hybrid experience’, in the company’s words, either AWS-native or running VMware Cloud on AWS.

VMware’s positioning as a partner has been long in coming and is coming to a head now. In February 2015, this publication put out an op-ed titled ‘Here’s why VMware hasn’t left it too late with its hybrid cloud push.’ Back then, VMware’s move to cloud was relatively late, having previously had a long-standing heritage in virtualisation. Many companies had their aborted attempts to move into the public cloud – CenturyLink and Verizon to name two in the telco space – yet VMware evidently saw two apparent trends.

Enterprises were not only going to focus on a handful of primary players for their public cloud infrastructure – and not focus on just one vendor but go multi-cloud – but they were also not going to give up certain on-prem assets.

You can read the full Google Cloud blog here.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

JEDI contract put on hold after intense lobbying efforts


Connor Jones

2 Aug, 2019

The $10 billion JEDI contract to supply cloud computing services to the Pentagon has been halted after an aggressive lobbying campaign from rival tech companies.

According to CNN, which first reported the story, an inside campaign was allegedly carried out to dissuade President Trump from choosing Amazon’s AWS as the winner of the contract.

Amazon and Microsoft are currently the only two companies in the race after Oracle and IBM were knocked out of the running months ago, but a one-page document was given to Trump which appears to visually outline Amazon’s ten-year plan for cloud monopolisation.

The document is identical to one created by Oracle’s top Washington lobbyist, Kenneth Glueck, an executive vice president with the company, Glueck told CNN.

CNN remarked that the document delivered to Trump, which may have been the deciding factor in delaying the JEDI contract due to be announced this month, was designed to play up to the feud between Trump and Amazon CEO Jeff Bezos.

«So sorry to hear the news about Jeff Bozo being taken down by a competitor whose reporting, I understand, is far more accurate than the reporting in his lobbyist newspaper, the Amazon Washington Post,» tweeted Trump in relation to Bezos’ divorce at the time. «Hopefully the paper will soon be placed in better & more responsible hands!»

Defence Secretary Mark Esper is currently investigating allegations of unfairness in the awarding of the contract, according to Pentagon spokeswoman Elissa Smith.

«Keeping his promise to Members of Congress and the American public, Secretary Esper is looking at the Joint Enterprise Defense Infrastructure (JEDI) program,» Smith said in a statement on Thursday to Reuters. «No decision will be made on the program until he has completed his examination.»

Speculation surrounding the treatment of AWS in the contract’s bidding process has raged on for months, some have argued that the nature of the contract itself favours AWS and the services it offers.

Reports also suggest that Senator Mark Rubio penned a letter to national security advisor John Bolton requesting the contract be delayed.

«I respectfully request that you direct the delay of an award until all efforts are concluded in addition to evaluating all bids in a fair and open process in order to provide the competition necessary to obtain the best cost and best technology for its cloud computing needs,» Rubio reportedly wrote.

The Joint Enterprise Defence Infrastructure (JEDI) contract is worth $10 billion and the project to renovate the Pentagon’s IT infrastructure into a contemporary cloud-based one could span 10 years.

IBM goes cloud-native with Red Hat OpenShift


Jane McCallion

1 Aug, 2019

IBM has wasted no time incorporating Red Hat into its portfolio, announcing today that its full software offering has been «transformed… to be cloud-native».

This, the company claims, will allow customers to build mission-critical apps once and then run them on most public clouds, including AWS, Azure, Google Cloud Platform, Alibaba and, of course, its own IBM Cloud.

The move comes just three weeks after IBM was given regulatory approval to acquire open source stalwart Red Hat and it’s no coincidence that this initiative is «optimised» to run on the OpenShift containerisation platform.

In its cloud-native form, IBM’s software will be offered as pre-integrated, containerised modules called IBM Cloud Paks.

The first five of these Paks – for Data, for Applications, for Integration, for Automation, and for Multicloud Management – are available today. More will be forthcoming, it seems, but no timeframe or number has yet been given.

In addition to Cloud Paks, IBM made three other Red Hat-centred announcements today.

The first is Red Hat OpenShift on IBM Cloud, a «flexible, fully-managed service» that the company claims will «help enterprises modernise and migrate to a hybrid cloud infrastructure».

The second is the news that Red Hat OpenShift is now available for IBM Z and LinuxONE, having previously only been available on Power Systems and Storage.

Finally, there are new consultancy and technology services available from IBM for Red Hat.

Arvind Krishna, senior vice president of cloud and cognitive software at IBM, said: «This will further position IBM as an industry leader in the more than $1 trillion dollar hybrid cloud opportunity.

«We are providing the essential tools we think enterprises need to make their multi-year journey to cloud on common, open standards that can reach across clouds, across applications and across vendors with Red Hat.»

IT operations in 2020: Five things to prepare for – from AIOps to multi-cloud and more

The threat of digital disruption has forced senior executives and technology leaders to rethink business models, data assets, and distribution channels, to create more innovative products and services that will delight customers and overcome more nimbler competitors. Over the last decade, enterprises have completely transformed the way they build, deploy, manage, and maintain mission-critical services as a response to increasing digitisation.

Developers have responded to the enterprise transformation challenge by adopting innovative technologies and practices including the consumption of public cloud services, the embrace of agile and DevOps for rapid software delivery, the shift from monolithic development patterns to microservices development, and machine learning models for process innovation.

IT operations teams have historically ensured the availability and performance of enterprise workloads by minimising change and avoiding disruption. Given the demands of digital business, digital operations teams will need to take advantage of established and emerging technology trends to drive product momentum, deliver compelling customer experiences, and ensure long-term corporate survival.

In 2020, IT operations teams will need to embrace these five shifts to scale up innovation and respond effectively to digital disruption:  

How IT operations can stay relevant in a DevOps world

At the 2009 Velocity conference, a session on 10+ Deploys Per Day: Dev and Ops Cooperation at Flickr by John Allspaw and Paul Hammond showed how enterprises could accelerate release velocity with automated infrastructure tooling, continuous integration and deployment processes, and shared metrics. This Velocity talk ignited the DevOps movement, calling for a new model of trust, collaboration, and accountability between Dev and Operations teams.

A decade later, DevOps has broad mainstream adoption, with site reliability engineers and DevOps specialists being the top earners in Stack Overflow’s 2019 Developer Survey. DevOps is key to enabling business agility and minimising friction, with Gartner predicting that 90 percent of the top 100 global companies will slash operational inefficiencies with DevOps practices by 2020. Meanwhile, a recent McKinsey study found that few business executives believe “their IT functions make meaningful contributions in areas that promote strong business performance.”

These trends might ensure that DevOps teams are the ones calling the shots with active participation in digital experience products leading to larger organisational budgets and greater organisational clout. Does this mean that IT operations will have to stay content managing legacy application and infrastructure portfolios (aka ‘keeping the lights on’)?

Takeaway: IT operations will need to combine their traditional focus on reliability, resilience, security, and efficiency with greater attention to release velocity, continuous improvement, and customer-centricity. Innovations in IT operations can support digital transformation initiatives and assure that the new speed of DevOps won’t put the business at risk.

AIOps: Not such an old-school incident management workflow

A recent IDC study finds that IT operations teams are the biggest buyers of artificial intelligence tools for rapid pattern recognition, seamless incident collaboration, and faster issue resolution. In 2020, it is time to move away from siloed and reactive to proactive and preventive incident management using the power of machine learning and data science. A modern AIOps solution can drastically reduce the human time spent identifying, logging, categorising, prioritising, responding, and closing incidents by:

  • Analysing and processing a wide variety of events across different monitoring tools so that duplicate and noisy alerts are automatically suppressed
  • Using machine data intelligence to get ahead of alert storms, speed up root cause(s) analysis, and reduce service disruptions
  • Sending real-time, contextual alerts to on-call service delivery teams with bidirectional integrations for IT service management tools  
  • Addressing routine incidents at scale using automated remediation so that human operators can focus on high-value business projects

Takeaway. Digital operations teams should start piloting AIOps initiatives to understand how machine learning-powered event management can reduce the human time spent on incident detection, first response, alert prioritisation, and root cause analysis.

New ways to control the chaos of multi-cloud management

Flexera’s 2019 State of the Cloud Report found that 84 percent of IT leaders use five different cloud providers as part of their enterprise cloud strategy. Given that AWS alone has 170+ unique services across 23 product categories, it is no easy task managing different cloud services across leading cloud platforms. So, what are the driving forces behind multi-cloud adoption?

Given the dominance of AWS which has a 35% market share in the cloud infrastructure services market, CIOs are looking to work with other cloud providers like Microsoft and Google to preempt fears of cloud lock-in. The other reason for selecting multi-cloud platforms is 451 Research’s best execution venue strategy of picking the right cloud environment for a specific type of business workload so that IT teams can optimise for both performance and cost.

Here are three factors that cloud teams will need to carefully consider while deploying a multi-cloud enterprise strategy:

  • Resource complexity: Cloud infrastructure teams will need to select the right instance type for their workload requirements across thousands of cloud SKU instances. Picking and optimising right-sized instances is an ongoing task and requires difficult tradeoffs based on architecture, demand, performance, resilience, and cost
     
  • Multi-cloud monitoring: While there are plenty of native monitoring tools like Amazon CloudWatch, Azure Monitor, and Google Stackdriver, these solutions are best employed for cloud-provider specific insights. Enterprises should either invest either in open source tooling (Prometheus/Graphite, Grafana) or third-party monitoring tools that can easily integrate, capture, and present insights from multi-cloud environments
     
  • Embed FinOps thinking in your cloud centre of excellence: Optimising cloud costs across instance types and pricing models (on-demand, dedicated, spot, and reserved) is a complex exercise. The emerging discipline of FinOps helps enterprises better plan and predict cloud budgets by bringing together best practices for optimising cloud spending. FinOps offers a new procurement model that emphasises shared accountability for cloud financial management across technology, finance, and business teams so that enterprises getter a better return for their cloud investments.

Takeaway. Enterprise IT teams should learn from FinOps pioneers on how to make the right tradeoffs between cost, performance, and resilience for cloud services. Cloud architects should experiment with both open source and commercial monitoring tools to understand how they can drive real-time visibility and ensure faster incident response for multi-cloud operations. 

Cloud transforms the enterprise data centre

Corporate data centres are increasingly taking on attributes of public cloud infrastructure with on-demand consumption and pay-per-use pricing models. Here are three trends that are a clear indication of how data centres are evolving in the cloud era:

  • Hybrid cloud models: For a long while, public cloud platforms refused to acknowledge that certain workloads could only operate on-prem due to latency, security, or compliance requirements. Cloud providers have now openly embraced the hybrid cloud value proposition, with Microsoft launching Azure Stack in 2017, followed by AWS Outposts in 2018, and Google Anthos in 2019. Hybrid cloud solutions allow enterprises to run workloads within their data centres and not worry about day-to-day management while letting cloud providers breach the final frontier of data centre gravity  
     
  • Consumption-based infrastructure models: Enterprises can leverage a host of innovative solutions (HPE GreenLake, Dell Flex on Demand, Lenovo TruScale Infrastructure Services, and Cisco Open Pay) that let them tap into flexible payment models for data centre resources. IT teams can defer capital expenditures, work with the latest hardware, track real-time usage, and outsource management to the OEM or a managed service provider, allowing them to purely focus on business outcomes
     
  • Write once, run anywhere with orchestration engines: Container orchestration engines like Kubernetes, Docker Swarm, and Apache Mesos have exploded in popularity as they allow IT teams to run cloud-native services anywhere and offer a consistent management framework for building and scaling distributed applications. Cloud-native services can be deployed across data centre and cloud environments using container orchestration engines, ensuring a high degree of portability, faster release velocity, and better operational control with abstracted infrastructure

Takeaway. Data centres are ripe for disruption and IT teams should outsource the heavy lifting involved in designing, deploying, monitoring, and maintaining mission-critical infrastructure. Data centre managers should work with both hyperscale and OEM providers to tap into the power and flexibility of hybrid cloud and consumption-based utility models.

How to tackle the looming skills crisis

Research firm IDC expects that 30% of IT roles involving emerging technology skills will remain unfilled through 2022. A recent survey found that 94% of IT decision-makers are finding it somewhat difficult, difficult, or very difficult to hire DevOps professionals, cloud native developers, and multi-cloud operators. Disruptive technology trends have ensured that  IT operations teams have to constantly upgrade their skills to remain relevant.

  • The popularity of cloud native infrastructure requires a new set of skills across lifecycle automation and configuration, observability and analysis, and security and compliance for driving reliable and scalable applications
  • The adoption of AIOps solutions needs IT practitioners who are familiar with advanced statistical techniques and can combine data-driven insights and human intuition to reduce application downtime and ensure a faster recovery

Takeaway. CIOs will need to invest heavily in skills development programs to attract and retain employees. IT leaders will use a mix of internally run programs, hands-on learning, and external providers to counteract the skills gap in a competitive job market.

Conclusion

In a world where change is the only constant, IT operations will need to become increasingly proactive and dynamic to meet the needs of the business. Technology operations management will emerge as a renewed discipline, where innovation is only limited by imagination.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

G Suite now offers enhanced security for high-risk users


Keumars Afifi-Sabet

1 Aug, 2019

Google has extended its advanced security programme to enterprise customers using its G Suite, Google Cloud Platform (GCP) and Cloud Identity products, giving IT administrators the ability to set stronger internal controls.

Organisations can enrol senior executives and those employees at high-risk of cyber attacks into Google’s Advanced Protection Program (APP), which will bring their level of security up to the standards of Google’s own employees.

Within the next few days, IT administrators can select the members of their organisation who they assess as needing stronger protections, and Google will automatically apply a set of stricter cyber security policies to their activities.

There are several changes to how those enrolled in the programme can access Google’s products, including enforced FIDO keys, blocking access to non-trusted third-party apps automatically, and enhanced scanning of incoming emails.

These changes will come alongside making Titan security keys, Google’s own FIDO key, available for purchase in Japan, Canada, France and the UK, as well as using machine learning to improve security alerts for IT administrators.

The use of such FIDO keys will be mandatory for those enrolled in the advanced security programme, meaning access to critical Google apps may be disrupted for users without them. Third-party apps will also be automatically blocked for APP users unless explicitly whitelisted.

The use of machine learning, meanwhile, will be directed towards analysing activity within the G Suite to detect unusual behaviour. In practical terms, IT administrators signed up to the service will receive a stream of anomalous activity alerts on a security dashboard.

This raft of added security protections will bolster the security across organisations signed up to Google’s enterprise products by both demanding more of high-risk employees and adding more robust provisions.

However, the majority of these practices can be seen as essential for good cyber security hygiene, regardless, and raise the question as to why they haven’t been introduced to customers up to now. It’s especially pertinent given Google employees have adhered to the APP regime since it was launched two years ago.

Google, at the time of launch, restricted the APP to those at elevated risk of attack and who are also «willing to trade off a bit of convenience for more protection».

There is now, however, no stopping IT administrators from now enrolling their entire organisation to the programme should they deem it the best defence against cyber threats.

Amazon Web Services review: AWS packs in more features than any other cloud service provider


K.G. Orphanides
Andy Webb

2 Aug, 2019

Amazon's one cloud service provider to rule them all isn't always the most economical option for SMEs

Price 
Highly variable

AWS is the big daddy of cloud service providers. It provides the backend infrastructure for half the online services you’ve ever heard of, and it could do the same for your office.

It’s increasingly practical to move small and medium enterprise business networks and servers into the cloud as infrastructure as a service. Unusually – and conspicuously unlike rival platforms from Microsoft and Google – AWS can provide virtualised desktop workstations, as well as core infrastructure.

In this review, we’ll focus on infrastructure and services that can be readily migrated to the cloud – primarily core servers, directory services and a virtual private cloud to both handle virtual networking and provide a VPN endpoint to connect your business’s physical machines to your online infrastructure.

Amazon WorkSpaces cloud desktops could also be of particular value to firms with significant remote workforces. All of these options can represent significant savings on capital expenditure and, particularly with virtual desktops, provide a secure alternative to having staff work from their own PCs.

Amazon says it strives for 99.99% uptime in each AWS region and, if it does go down, provides credits that can be spent on affected services. You can choose which region to host your services in, which can potentially help with both legal compliance and performance for people connecting from that region.

Amazon Web Services review: Deployment

AWS has a frankly dizzying array of features, from machine learning testbeds to augmented reality application development and Internet of Things connection kits, but we’re interested in servers and networking to support a standard office.

For this, you’ll want to deploy a Virtual Private Cloud and, on that, deploy any servers to handle whatever single sign-on, storage and database needs your business has. VPCs are easy to manage if you’re already confident with network infrastructure, but to connect your office to your cloud-based network, you’ll need a fast internet connection and a firewall router powerful enough to handle a high-throughput VPN connection.

When deploying VMs, you can’t just upload an ISO of your choosing and install that – only a rather limited list of Windows and Linux versions are available to install. However, it is possible to upload a VMware, Citrix, Hyper-V or Azure virtual machine image via an Amazon S3 storage bucket or – easier still – via the AWS Server Migration Service and connector software installed on your existing platform.

Amazon Web Services review: Pricing

No matter which data centre region you’re based in, in the world of AWS, everything is in US dollars, right up until the point at which your final bill is calculated in your choice of currency, based on Amazon’s internal exchange rate.

This can be rather annoying, particularly when the pound undergoes major fluctuations due to political events, as it makes your month-to-month costs less consistent than they otherwise would be.

The default option for your AWS deployments is its On-Demand pay-as-you-go pricing. However, as with Microsoft Azure, you can save money if you deploy longer-term reserved instances for any virtual infrastructure that you plan on leaving in operation for an extended period.

Needless to say, the exact costs of any deployments will vary widely depending on your exact needs. To provide a basic example, we use the AWS Simple Monthly Calculator to cost up a single general-purpose virtual machine running Windows Server on a two-core, 8GB VM with a ‘moderate’ connection – estimated by various third party tests at around 300Mbit/sec – costs $152.26 per month, plus $36.60 for a 1024GB HDD.

The speed of that network connection makes a great difference to pricing: two cores and 8GB RAM on an up-to-10GB/sec connection cost $282.56 per month. A little less variably, an Active Directory connector starts at $43.92 and a Virtual PrivateCloud at $36.60 per month for a single connection from your office router.

Critically, the estimation tool – unlike Azure’s – won’t generate a baseline estimate of how much data in and out a business might use every month. You’ll have to estimate that manually: at an estimated 100GB per month in and out (only outbound traffic costs anything in this scenario), we’d pay $17.91 per month.

That adds up to $294.71 (£242.53) per month, including a small free tier discount. For Windows servers, Microsoft’s Azure platform is much more competitive at the moment: £196.68 per month will get you a similar setup.

A lot of that is to do with the cost of licencing Windows, which Microsoft can subsidise for Azure users. Switch that AWS server VM to Linux, and it’ll cost $84.92 per month, rather than $152.26.

Amazon WorkSpaces virtual desktop computers start at $7.25 per month plus $0.17 per hour of active use (or a flat $21 per month) for a Linux desktop system and $7.25 per month and $0.22 per hour (or a flat $25 per month) for a Windows desktop, with one core, 2GB RAM, an 80GB root volume and 10GB of user storage.

AWS can sometimes spring unexpected costs on you, for example by billing hourly for IP addresses that were once attached to a terminated VM. Similarly, leftover key pairs and storage drives associated with virtual machine instances incur charges if they’re not manually deleted when an instance is.

Data throughput and the sometimes arcane relationships between services can also add to the cost of AWS deployments, and you might miss out on its free intra-region data transfer fees if you don’t set everything up correctly.

In the case of a Virtual Private Cloud, you’ll have to create a specific subnet endpoint pointing at the AWS service you’re trying to connect to in order to benefit from free throughput: connecting to a public IP address provided by the service will result in data transfer being billed as though it was going to a location on the wider internet, rather than inside AWS.

Like Microsoft and Google, AWS provides a wide range of free services intended to allow administrators to extensively prototype and test cloud-based systems and services for their business, from short-term free trials to always-free services and free 12-month subscriptions for new AWS subscribers.

In the latter category, new users can run up to 750 hours a month of Linux and Windows EC2 Micro virtual machine instances, 5GB of S3 storage, various Amazon WorkSpaces cloud desktop and AppSteam always-available desktop application streaming bundles, 750 hours of database services and more.

In the Always Free category, you’ll get 10 CloudWatch resource monitoring deployments, 62,000 outbound email messages, 10GB of Glacier cold storage, key and licence management, 100GB of hybrid cloud storage, and Amazon’s Chime unified communications platform among other bits and pieces.

Amazon Web Services review: User interface

The AWS Management Console is a lot nicer to look at and carry out day-to-day management and deployment tasks with than Microsoft’s rival Azure platform. There’s more white space and fewer immediately visible options, which helps to make it feel less cluttered.

Your most recently visited services are front and centre, and you can open a full list of every single one of AWS’ vast catalogue of services. At the top of the page is a search interface, where you can search for services by name or function, so if you search for ‘virtual desktop’, you’ll be directed to WorkSpace and if you search for ‘cold storage’, S3 Glacier pops up.

Below, a range of wizards and tutorials are available to help you deploy and work with popular services such as virtual machines, virtual servers and hosted web apps. Each service has its own management interface which, again, are a little more comfortable to use than Azure’s.

However, there’s a distinct design language at work here that you’ll have to get used to, particularly if you’re primarily familiar with Microsoft’s Server and cloud products. We were pleased to find that free-tier eligible options were clearly marked when we used the VM deployment wizard, which also provides helpful guidance when it comes to keeping your deployments secure, such as locking access to specific IP addresses.

Amazon Web Services review: Verdict

Even compared to its closest competitors, AWS is complex, both in terms of features and pricing, although a well-designed interface does its best to make things simple. When working with AWS, it’s worth using Amazon’s quote generator and cost management tools to ensure that you aren’t running up unexpected expenses, and you’ll have to remember to include data throughput costs in your estimates, as they’re not typically bundled.

AWS’ ubiquity speaks for itself: although its layers upon layers of features are confusing, it’s reliable, highly flexible, can be immensely cost-effective and offers a wider range of services than any of its rivals. However, to make the most of it, your business will need a dedicated expert, either in-house or as contracted support.

By comparison, Microsoft’s Azure isn’t significantly easier to use, but its management interface will feel a bit more familiar to Windows sysadmins and its pricing for Windows-based services is cheaper than AWS’, making it a better option for most office infrastructure migrations.