Announcing @10ZiGTechnology to Exhibit at @CloudEXPO | @CitrixReady #ThinClient #ZeroClient #Cloud #Citrix #VDI #DataCenter

10ZiG Technology is a leading provider of endpoints for a Virtual Desktop Infrastructure environment. Our fast and reliable hardware is VMware, Citrix and Microsoft ready and designed to handle all ranges of usage – from task-based to sophisticated CAD/CAM users.

10ZiG prides itself in being one of the only companies whose sole focus is in Thin Clients and Zero Clients for VDI. This focus allows us to provide a truly unique level of personal service and customization that is a rare find in the industry. We offer a multitude of custom embedding options and hardware configurations to ensure our devices are tailor-made to fit seamlessly into the environments of our customers.

read more

Android phones become Google’s most secure form of MFA


Connor Jones

10 Apr, 2019

Google Cloud has revealed that Android devices can now be used as a Titan authentication key in what’s seen as a major push to protect user accounts from online scams.

Working much like Google’s Titan key, which is built in accordance with FIDO standards, your phone can now act as the most secure version of multi-factor authentication (MFA) yet.

Other MFA methods, such as confirmation texts and mobile apps, have come under scrutiny as they can still be exploited by phishers who can trick users into helping them access their accounts.

The key is able to keep a log of phishing websites that Google is aware of and, if you visit one, the security key built into your Android phone will block you from handing over login credentials to phishers.

Google calls the new security standard ‘phone-as-a-security-key’ (PaaSK); the phone connects to your device via the Google-built standard, which itself is built on top of Bluetooth to create a three-pronged layer of protection.

The security also works through proximity, and so long as your phone is connected to your device, say a laptop, then the device will recognise you as both the user attempting to log in and the owner of the account’s corresponding security key. Instead of waiting for a text, a security screen will automatically appear on your phone requiring you to either hold down a volume button if using a Google phone or press an on-screen button for any other Android device.

The advantage of this is that although attackers can get you to hand over your phone number to access an SMS-based 2FA protection barrier, an attacker would find it much harder to get their hands on your phone and stay in close proximity to your computer.

Google has said that only Android devices running version 7.0 or later will support the new PaaSK platform at launch, but it can be used on all major computer operating systems including Windows, MacOSX, and Chrome OS.

“We’re focussed on Android first, but it’s not out of the realms of possibility that in the future there will be something for iOS, at least for Google accounts,” said Sam Srinivas, product management director at Google Cloud.

You’ll be able to associate as many Google accounts with the PaaSK as you wish but the user must be logged into the correct key on the phone first before making the login attempt on a browser.

Although Google says it blocks 99.9% of all fraudulent log-in attempts on its users’ accounts, there is still a 0.1% issue regarding cases of phishing, keylogging and data breaches – cases where the attacker has the correct password, making it difficult to differentiate between a genuine and fraudulent attempt.

Google chose to implement FIDO in its most recent push against phishing attacks because out of all the other MFA methods, namely SMS/voice, backup code and authenticator apps, FIDO has proved the only phishing-resistant method.

According to Google’s own assessments, user accounts becomes 10x more vulnerable if credentials are used in a data breach, 40x more vulnerable when threatened by keylogging, and 500x more vulnerable if compromised by a phishing scam.

Google Cloud doubles down on security at Next


Connor Jones

10 Apr, 2019

Google has announced 30 security features for its Google Cloud Platform (GCP) at Google Cloud Next 2019, building on a two-year-long commitment to making its platforms more robust.

Prior to today’s announcement, Google Cloud had invested heavily into its security systems, launching more than 70 products and services in 2018 and with it now adding to that tally.

The company split its announcements over three different sectors:

  • Security of the cloud: referring to the infrastructure that keeps GCP secure such as datacentres, network cables and its Titan chip
  • Security in the cloud: features that allow customers to build secure applications for their businesses in their cloud environment e.g. encryption key management
  • Security services: direct security-as-a-service solutions that Google is starting to provide

Security of the cloud

«One of the things we deeply believe in at Google is that transparency breeds trust,» said Michael Aiello, product management director at Google Cloud, adding that Google wants to reduce the number of mechanisms that customers have to trust Google with.

Access Transparency has been in GCP for some time now but it’s now released in beta for G-suite. This involves providing the customer with near real-time logs whenever a Google engineer authorises access to their environment to correct an issue they reported. Previously, a Google engineer, in this case, could self-authorise access to the environment but now they must get authorisation from the customer.

Security in the cloud

According to Gartner, 95% of all cloud security breaches are caused by customer misconfigurations such as firewalls with misconfigured buckets. Just last week a massive data trove was found to be left exposed because of an improperly configured AWS S3 bucket. The WWE, Accenture and even the NSA have fallen victim to this type of security incident and Google has recognised that.

Google’s Cloud Security Command Centre will now go to general availability (GA) after a successful beta phase. It’s a single app that provides a complete overview of your organisation’s cloud resources and the security threats that are presented to them.

Using machine learning, the app learns all the different access attempts over time and uses that intelligence to grant permissions and make smart recommendations on cloud configurations to increase overall security.

«It will give you a full rundown of all of your assets and from there you can apply security analytics and threat intelligence to best protect your GCP environment,» said Jess Leroy, product management director at Google Cloud.

After some customer requests from the beta phase, the command centre will now feature more export options to Docs and Sheets and even a custom export option for Splunk Web. New threat intelligence integrations with third-parties such as Tenable and McAfee will also be supported in the GA release.

G-suite also gets a security makeover with advanced phishing and malware protection – something Google dedicated lots of resources to. Among other things such as new controls being made available to admins against phishing attacks such as domain spoofing, Gmail will be getting a sandbox mode.

The sandbox mode aims to tackle the threat of malware spread over email and because the only way to see what a malicious program does is to run it. As such, virtual environments will now be embedded into Gmail so you can know with certainty what an executable program does before downloading it.

Security services

Aside from security features added to GCP specifically for GCP customers, Google announced a set of services that can be used on other platforms such as AWS or Azure as well as its own cloud platform.

One of the most common ways that companies will discover threats is by scanning through all of the logs in their environments. Event Threat Detection is a service that scans logs for suspicious activity and can consolidate logs from private clouds, traditional datacentres, even from other cloud platforms into GCP.

After the logs have been consolidated, they will be scanned and fed through the command centre to find vulnerabilities and users can then remediate them and even manipulate the data through BigQuery.

Security has been quite the theme here at Next – Google also announced that Android phones can now become a user’s Titan key, the only phish-resistant method of multi-factor authentication.

CFP Deadline For @DXWorldEXPO Silicon Valley | #HybridCloud #CIO #Blockchain #AI #AIOps #MachineLearning #DigitalTransformation

Now is the time for a truly global DX event, to bring together the leading minds from the technology world in a conversation about Digital Transformation. DX encompasses the continuing technology revolution, and is addressing society’s most important issues throughout the entire $78 trillion 21st-century global economy.

DXWorldEXPO® has organized these issues along 10 tracks, 22 keynotes and general sessions, and a faculty of 222 of the world’s top speakers.

read more

Google Cloud Next: Cloud Run stateless cloud environment enters beta stage


Connor Jones

9 Apr, 2019

Google Cloud’s serverless compute platform Cloud Run has entered a beta phase and aims to prevent the vendor lock-in problem faced by enterprises looking to go serverless.

Revealed at Google Cloud Next 2019 in San Francisco, the Cloud Run environment is stateless, which will tackle the issue that developers face when making the choice between the ease of serverless or the flexibility of containers.

With a serverless environment, developers need not worry about configuring the underlying infrastructure and how much resources they will need to power their applications. 

As such, with a stateless environment, enterprises can commit to a vendor for some of their serverless products, let’s say Dell, but not have to worry about being restricted only to the vendor’s software partners.

Cloud Run is fully serverless and automatically scales up or down with your website’s traffic within seconds, meaning that you’ll only pay for the resources that you need.

«What’s beautiful about the system is that you’re paying by the hundred-millisecond for what you use only and it scales up horizontally to many, many thousands of cores in just a few seconds,» said Oren Teich, director product management at Google Cloud.

It’s already and being deployed by some of the world’s biggest firms. Veolia, the waste management giant praises the ease and cost-effectiveness of the new environment.

«Cloud Run removes the barriers of managed platforms by giving us the freedom to run our custom workloads at lower cost on a fast, scalable, and fully managed infrastructure,» said Hervé Dumas, group CTO at Veolia. «Our development team benefits from a great developer experience without limits and without having to worry about anything.»

The Cloud Run environment can be used on its own or integrated with your company’s existing Kubernetes cluster; merging the two will also offer you some specific enhancements to your stack.

Using Cloud Run on Kubernetes grants access to Google’s other cloud products such as Custom Machine Types on its Compute Engine networks, which provides users with the ability to create scalable virtual machines tailored for each process that are configurable for optimal pricing.

Cloud Run on Kubernetes, the industry standard for container management, also allows you to run side-by-side with other networks deployed in the same cluster. Airbus Aerial, the aerospace company’s satellite imagery arm is already using Cloud Run on Kubernetes to process and stream aerial images.

«With Cloud Run on GKE, we are able to run lots of compute operations for processing and streaming cloud-optimized aerial images into web maps without worrying about library dependencies, auto-scaling or latency issues,» said Madhav Desetty, chief software architect at Airbus Aerial.

Cloud Run is also based on Google’s Knative open API which lets users run workloads on Google Cloud Platform, on a Google Kubernetes Engine (GKE) cluster or on a company’s own self-managed Kubernetes cluster. The underlying Knative API makes it easier for businesses to start on Cloud Run and then move to Cloud Run on GKE later on.

There are some operational constraints to Cloud Run which Teich detailed in a press conference. It runs at a maximum of 1Gb memory size instance, you get a single core per instance so it’s horizontal scale and not vertical scale. Each process must also respond to an HTTP 1.1 request in a maximum time of 15 minutes.

SUSE to Present at @KubeSUMMIT | @SUSE #CloudNative #DevOps #AIOps #Serverless #OpenStack #Docker #Kubernetes

Take advantage of autoscaling, and high availability for Kubernetes with no worry about infrastructure. Be the Rockstar and avoid all the hurdles of deploying Kubernetes. So Why not take Heat and automate the setup of your Kubernetes cluster? Why not give project owners a Heat Stack to deploy Kubernetes whenever they want to?

Hoping to share how anyone can use Heat to deploy Kubernetes on OpenStack and customize to their liking.

This is a tried and true method that I’ve used on my OpenStack clusters and I will share the benefits, bumps along the way and the lessons learned.

read more

How to Sponsor @DevOpsSUMMIT | #CloudNative #Serverless #DevOps #APM #DataCenter #Monitoring #Kubernetes

Cloud-Native thinking and Serverless Computing are now the norm in financial services, manufacturing, telco, healthcare, transportation, energy, media, entertainment, retail and other consumer industries, as well as the public sector.

The widespread success of cloud computing is driving the DevOps revolution in enterprise IT. Now as never before, development teams must communicate and collaborate in a dynamic, 24/7/365 environment. There is no time to wait for long development cycles that produce software that is obsolete at launch. DevOps may be disruptive, but it is essential.

DevOpsSUMMIT at CloudEXPO expands the DevOps community, enable a wide sharing of knowledge, and educate delegates and technology providers alike.

read more

Bitglass secures $70m series D funding to further enhance CASB space

Cloud access security broker (CASB) Bitglass has announced a $70 million (£53.6m) funding round aimed at consolidating its leadership of the CASB and cloud security market.

The round, a series D, included a new investor in the shape of Quadrille Capital, as well as existing investors Future Fund, New Enterprise Associates (NEA), Norwest, and Singtel Innov8. NEA, as regular readers of this publication will be aware, is a regular investor in the cloud space, with previous bets including Cloudflare, Databricks and Datrium among others.

The role of CASBs is to essentially sit between an organisation’s on-premises infrastructure and a cloud provider’s infrastructure, thereby taking the strain of cloud security away from the client. As TechTarget puts it, it ‘acts as a gatekeeper, allowing the organisation to extend the reach of their security policies beyond their own infrastructure.’

The need for an CASB has significantly increased as organisations continue to not hold up their end of the ‘shared responsibility’ bargain for cloud security. The oft-repeated – yet not oft-heeded – mantra is that cloud vendors were responsible for security of the cloud, while the customer is responsible for security in the cloud, such as data, applications, and identity and access management. Only last week the disclosure by UpGuard of Facebook user data being exposed to the public internet led to more questions.

As a result, last November saw analyst firm Gartner issue its first Magic Quadrant for the area. Bitglass, alongside McAfee, Netskope and Symantec – the latter all worth noting as much wider-purpose security providers – was placed as a leader. This was a point Gartner alluded to in its analysis; while Bitglass’ technical expertise was widely praised, the company did not come up as often as the other leaders in clients’ enquiries.

Writing for this publication in August, Hatem Naguib, SVP security at Barracuda Networks, noted his belief that many organisations continued to misunderstand the shared responsibility model. “The organisations benefiting the most from public cloud are those that understand their public cloud provider is not responsible for securing data or applications, and are augmenting security with support from third party vendors,” Naguib wrote.

“Cloud adoption is disruptive of incumbents securing networks, servers and other infrastructure,” said Nat Kausik, CEO of Bitglass in a statement. “Our next-gen CASB uniquely secures against data leakage and threats without installing more hardware and software.”

Total funding for the company now stands at just over $150 million.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Anand Akela Named Tech Chair of DevOpsSUMMIT & ServerlessSummit | @CloudEXPO @AAkela #AI #AIOps #DevOps #DevSecOps #Monitoring #ContinuousTesting

Anand Akela is the Tech Chair of DevOpsSUMMIT | ServerlessSUMMIT. Prior to his current role, Anand was Sr. Director of Product Marketing for DevOps and Cloud Solutions at CA Technologies.
Earlier Anand worked at AppDynamics, Oracle and HP in various product marketing, product management, and engineering roles in the systems management, servers, data center energy efficiency and enterprise software areas.

Anand has more than 20 years of experience in product marketing, product management, strategic planning and software development. Anand received his MBA from The Fuqua School of Business, Duke University and a B.S. in Computer Science from Pune University in India. You can follow Anand on twitter at https://twitter.com/aakela

read more

The five key things every executive needs to know about identity and access management

  • For new digital business models to succeed, customers’ privacy preferences need to be secure, and that begins by treating every identity as a new security perimeter.
  • Organisations need to recognise that perimeter-based security, which focuses on securing endpoints, firewalls, and networks, provides no protection against identity and credential-based threats. Until they start implementing identity-centric security measures, account compromise attacks will continue to provide a perfect camouflage for data breaches.
  • 74% of data breaches start with privileged credential abuse that could have been averted if the organisations had adopted a privileged access management (PAM) strategy, according to a recent Centrify survey.
  • Just 48% of organisations have a password vault, and only 21% have multi-factor authentication (MFA) implemented for privileged administrative access.

New digital business models are redefining organisations’ growth trajectories and enabling startups to thrive, all driven by customer trust. Gaining and strengthening customer trust starts with a security strategy that can scale quickly to secure every identity and threat surface a new business model creates. 

Centrify’s recent survey, Privileged Access Management in the Modern Threatscape, found 74% of data breaches begin with privileged credential abuse. The survey also found that the most important areas of IT infrastructure that new digital business models rely on to succeed — including big data repositories, cloud platform access, containers, and DevOps — are among the most vulnerable. The most urgent challenges executives are facing include protecting their business, securing customer data, and finding new ways to add value to their business’ operations.

Why executives need to know about identity and access management now  

Executives have a strong sense of urgency to improve identity and access management (IAM) today to assure the right individuals access the right resources at the right times and for the right reasons.

IAM components like access management, single sign-on, customer identity and access management (CIAM), advanced authentication, identity governance and administration (IGA), IoT-driven IAM, and privileged access management address the need to ensure appropriate access to resources across an organisation’s entire attack surface and to meet compliance requirements.

Considering that privileged access abuse is the leading cause of today’s breaches, they’re especially prioritising privileged account management as part of their broader cybersecurity strategies to secure the “keys to their kingdom.” Gartner supports this view by placing a high priority on privileged account management, including it in its Gartner Top 10 Security Projects for 2018, and again in 2019.

During a recent conversation with insurance and financial services executives, I learned why privileged access management is such an urgent, high priority today. Privileged access abuse is the leading attack vector, where they see the majority of breach attempts to access the company’s most sensitive systems and data. It’s also where they can improve customer data security while also making employees more productive by giving them access systems and platforms faster. All of them know instances of hackers and state-sponsored hacking groups offering bitcoin payments in exchange for administrative-level logins and passwords to their financial systems.

Several of the executives I spoke with are also evaluating Zero Trust as the foundation for their cybersecurity strategy. As their new digital business models grow, all of them are focused on discarding the outdated, “trust, but verify” mindset and replacing it with Zero Trust, which mandates a “never trust, always verify” approach. They’re also using a least privilege access approach to minimise each attack surface and improve audit and compliance visibility while reducing risk, complexity, and costs.

The following are the five things every executive needs to know about identity and access management to address a reality that every company and consumer must recognise exists today. Attackers no longer “hack” in, they log in.

Designing in the ability to manage access rights and all digital identities of privileged users require privileged access management (PAM) and identity governance and administration (IGA) systems be integrated as part of an IAM strategy

For digital business initiatives’ security strategies to scale, they need to support access requests, entitlement management, and user credential attestation for governance purposes. With identities being the new security perimeter, provisioning least privileged access to suppliers, distributors, and service organisations is also a must-have to scale any new business model. Natively, IGA is dealing only with end users – not privileged users. Therefore integration with PAM systems is required to bring in privileged user data and gain a holistic view of access entitlements.

IAM is a proven approach to securing valuable Intellectual Property (IP), patents, and attaining regulatory compliance, including GDPR

The fascinating digital businesses emerging today also function as patent and IP foundries. A byproduct of their operations is an entirely new business, product and process ideas. Executives spoken with are prioritising how they secure intellectual property and patents using an Identity and Access Management strategy.

Knowing with confidence the identity of every user is what makes every aspect of an IAM strategy work

Having multi-factor authentication (MFA) enabled for every access session, and threat surface is one of the main processes that make an IAM strategy succeed. It’s a best practice to reinforce Zero Trust principles through multi-factor authentication enforcement on each computer that cannot be circumvented (or bypassed) by malware.

Designing in transaction verification now for future eCommerce digital business models is worth it

Think of your IAM initiative as a platform to create ongoing customer trust with. As all digital business initiatives rely on multi-channel selling, designing in transaction verification as part of an IAM strategy is essential. Organisations are combining verification and MFA to thwart breaches and the abuse of credential access abuse.

In defining any IAM strategy focus on how privileged access management (PAM) needs to be tailored to your specific business needs

PAM is the foundational element that turns the investments made in security into business value. It’s a catalyst for ensuring customer trust turns into revenue. Many organisations equate PAM with a password vault.

But in a modern threatscape where humans, machines, applications, and services dynamically require access to a broadening range of attack surfaces such as cloud, IoT, big data, and containers, that outdated legacy approach won’t effectively secure the leading attack vector: privileged access abuse. Vendors such as Centrify and others are looking beyond the vault and offering Zero Trust solutions for PAM that address these modern access requestors and attack surfaces.

Conclusion

Insurance and financial services executives realise, and even predict, that there’s going to be an increase in the number and intensity of efforts to break into their systems using compromised credentials. Prioritising privileged access management as part of the IAM toolkit is proving to be an effective cybersecurity strategy for protecting their businesses and customers’ data while also making a valuable contribution to its growth.

The bottom line is that identity and access management is the cornerstone of any effective Zero Trust-based strategy, and taking an aggressive, pre-emptive approach to privileged access management is the new normal for organisations’ cybersecurity strategies.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.