For better or for worse: Why your brand reputation is hitched to your ability to manage and protect data

The potential benefits of technology to change and improve lives are clear for all to see. At an individual level, wearable devices can help better manage health, home sensors can reduce your energy use and costs, and analytics can hone services to meet your every need. At an organisational level, digital transformation can not only boost efficiency and productivity, but it can change the way that whole industries operate and allow organisations (including governments) to deliver new kinds of services for citizens and consumers.

Organisations, however, need to be conscious of the kind of impact they (and their use of technology) are having on all aspects of society. This can include public concerns about the environmental impact of energy use, the societal impact of jobs lost to automation, the economic impact of online retail over bricks and mortar, and even the personal impact of indiscriminate data collection and mismanagement.

Many organisations employ corporate social responsibility (CSR) programs in order to benefit society while also seeking to boost their own brands. By embarking on philanthropy or volunteering they are not only able to promote worthy agendas or causes, but are also able to gain positive brand association.

In recent years the main issues that CSR programs have focused on are issues such as climate change and diversity, but a new issue has emerged in recent months that has eclipsed all others in the minds of consumers … privacy. For software and technology companies, the link between data privacy and corporate responsibility is relatively straightforward. Even in non-tech industries, however, privacy has become a major issue.

No matter what industry you work in, more products are becoming connected. Mattel released a Wi-Fi-connected Hello Barbie in 2015 and researchers promptly uncovered several vulnerabilities that showed it could be hacked into a secret listening device. At the same time companies from all industries process and store both customer and employee data that must be kept secure. Not only have customer data breaches grabbed headlines, but regulations now mandate prompt disclosure of data protection failures and companies can be liable for massive fines – or even worse, they can be told that they are no longer allowed to process customer data. On top of this, the reputational damage of such an incident can be monumental.

For the very first time, industry analyst firm Gartner has listed digital ethics and data privacy as one of the top 10 tech trends for the year ahead. On top of this, research by FleishmanHillardFishburn has shown that the issues that consumers currently care most about are data security and privacy. It is these issues that consumers now want brands to be talking about, rather than their diversity or sustainability efforts.

For better or for worse…?

So how open should brands be about their CSR efforts in the good times – explaining their support for digital ethics and data privacy when things are going well – at the risk of a backlash in the bad times – when they invoke crisis management plans in the event of a data breach?

As Nick Andrews, senior partner for EMEA reputation lead commented in the FleishmanHillardFishburn report: “In an increasingly hashtag driven world, though, do you support the movement and risk a backlash, or stay quiet and disappoint? Only companies with a clear sense of purpose, who use this as a yardstick against which to measure their actions, will demonstrate the consistency and clarity of view which people expect. For those that do, the rewards will be great.”

There are essentially three possible courses of action with organisations falling into one of the three following groups:

Group 1: Business as usual, with no real emphasis on digital ethics and data privacy: 80% of UK consumers surveyed by FleishmanHillardFishburn have stopped using the products and services of a company because the company’s response to an issue does not support their personal views.

With digital ethics and data privacy topping the list of issues that consumers currently care most about, your brand is going to be at a competitive disadvantage to your Group 2 rivals that advocate strong support for digital ethics. And without making data privacy and security a strategic priority, you’re going to be more likely than Group 3 rivals to suffer a data breach and be impacted by the consequent reputational damage.

Group 2: Strong support for digital ethics and data privacy, without any real cultural change: If you aren’t genuinely committed to privacy, you’re going to be more likely than Group 3 rivals to suffer a data breach and be impacted by the consequent reputational damage. In addition, the reputational damage will be amplified as your claims of strong support for digital ethics and data privacy will be shown to have been inauthentic, and you risk being accused of ‘greenwashing’ or ‘astroturfing’.

Group 3: Wholehearted adoption of digital ethics and data privacy as a strategic priority: There are expectation among consumers that companies will take these issues seriously and enact robust data privacy measures above and beyond the legal requirements. Realising this Group3 firms will see it as an imperative to act now and maintain strong leadership in this field, or else risk the consequences of consumer discontent. Only if digital ethics and data privacy are made a strategic priority that leads to true cultural change throughout the company will this be possible.

Let’s not forget that GDPR affects any organisation handling the personal data of EU citizens no matter where company is located, meaning that even U.S. companies which process the personal data of individuals residing in the EU have to comply. And if regulatory compliance with the threat of massive fines were not motive enough, the fact that privacy is now the number one issue for customers across all sectors means that not aiming to be in Group 3 here is sheer folly.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Corporate data at greater risk in the cloud than thought, report warns


Keumars Afifi-Sabet

1 Nov, 2018

Organisations are putting too much faith in cloud service providers’ ability to keep data secure without applying their own controls, researchers claim.

Companies sustain on average 14 misconfigured infrastructure-as-a-service (IaaS) instances at any given time, leading to 2,269 misconfiguration incidents per month, according to a report released this week.

McAfee’s ‘Cloud Adoption & Risk’ paper highlighted several concerning facets of cloud security, including the fact that sensitive corporate and personal data held and shared in the cloud is rising in conjunction with the number of security incidents.

The report found that 21% of files held in the cloud contain sensitive data – a rise from 17% in the past two years. Cloud threats, meanwhile, have risen in tandem – from 20.4 security incidents per month in 2016, to 24.5 in 2017, to 31.3 per month this year.

«As we all take advantage of the cloud, there’s one thing we can’t forget – our data,» the report said. «Even when using a SaaS service we are still responsible for the security of our data in the service and need to ensure it is only accessed appropriately.

«When using an IaaS/PaaS service, we additionally are responsible for the security of our workloads in the service and need to ensure that we are configuring the underlying application and infrastructure components appropriately.»

AWS leading the pack

The report pinpointed Amazon Web Services (AWS) S3 buckets as being culpable in the security gaps of many organisations, with an estimated 5.5% of all S3 buckets in use misconfigured to be publicly readable.

This chimes with findings published earlier this year that showed misconfigured S3 buckets play a significant role in 12,000 terabytes of publicly-exposed sensitive corporate data found online by researchers.

AWS «absolutely leads the pack» in terms of its popularity with organisations, playing host to 94% of all access events – although 78% of organisations use AWS in conjunction with Azure, typically as part of a multi-cloud strategy.

McAfee also stressed the dangers with misconfiguration come down to the data, with organisations deploying data loss prevention (DLP) strategies experiencing 1,527 DLP incidents per month on average.

Among the most common AWS misconfigurations seen are unrestricted outbound access, unused security groups discovered, and S3 bucket encryption not turned on.

‘The perception gap is shocking’

McAfee’s report also highlighted a number of glaring perception gaps with cloud security, including a total lack of awareness over the number of cloud services that employees believe are in use in their organisation.

A previous survey published in April showed that the average response when asked how many cloud services are deployed across an organisation was 31. The security firm’s latest findings show the reality is 1,935, on average.

«The perception gap is shocking,» the report said, «meaning that 98% of cloud services are not known to IT – leading to obvious cloud risk.»

Asked whether they trust their cloud providers to keep data secure, 69% of respondents to the previous survey said they did, while 12% claimed the service provider bears sole responsibility for securing their data.

But «cloud security is a shared responsibility» according to McAfee’s report, «and no cloud provider delivers 100% security (including data loss prevention (DLP), access control, collaboration control, user behaviour analytics (UBA), etc.)».

«It’s likely therefore that organisations are underestimating the risk they are entering by trusting cloud providers without applying their own set of controls,» it continued.

The insider threat

Senior site reliability engineer at IT management firm Claranet Steve Smith said the concerns raised aren’t as hinged on the services themselves, as they are on their users.

«The cloud security challenges highlighted in this report have little to do with the platform itself, but everything to do with the people using it and, in our experience, people are the biggest weakness here,» he said.

He added the major cloud providers, such as AWS, have a series of default settings designed to support configuration, but it’s easy to get things wrong without knowledge as to how to use the platform.

«We’ve seen many AWS configurations that end-user businesses have developed themselves or have worked with partners that don’t have the right experience, and, frankly, the configurations can be all over the place.

«A click of a button or slight configuration change can have a major impact on your security posture, so it’s important to get a firm grip of the access controls and have safeguards in place to catch mistakes before they hit the production environment.»

McAfee’s report revealed the majority of cloud security incidents – 14.8 of the 31.3 experienced on average per month – are insider threats. These may include straightforward but significant mistakes such as sharing a spreadsheet with sensitive personal data, or malicious activity such as a sales employee downloading a full contact list before leaving for a rival firm.

The research found 94.3% of organisations experience at least one such incident per month, which is true for 58.2% of organisations with privileged user threats – such as an administrator accessing data in an executive’s account.

Mitigating cloud risks

The security company issued three core recommendations as to how businesses and organisations can bolster their strategy, including routine audits, understanding where sensitive data is held, and locking down sharing.

Leading IaaS and PaaS configurations, such as AWS, Azure, and Google Cloud Platform are a rapidly-growing alternative to on-prem infrastructure, the report said, and so need to be regularly audited to get ahead of misconfigurations before «they open a major hole» in security outlays.

Some of the most sensitive data, meanwhile, is held on platforms such as Office 365 and Box. McAfee recommended in its report that organisations grasp where their most sensitive data is held in order to reduce exposure to risk, and extending DLP policies.

Controlling how data is shared, moreover, and implementing collaboration restrictions on documents can mitigate the risk of inadvertent exposure – for example by configuring share settings to «anyone with a link», or by sending documents to personal email addresses.

How Confused.com enabled staff to take ownership of its digital transformation


Bobby Hellard

31 Oct, 2018

Despite being an internet company, Confused.com still needed to undergo a digital transformation.

Such is the rapid rise of AI and cloud computing, the 16-year-old price comparison website only adopted a cloud service five years ago. And the tricky part was not about introducing new technology to the business, it was about introducing it to the workforce.

«We have always been tech geeks at heart and we make sure we are using technology to help customers,» says Louise O’Shea, Confused.com’s CEO. «I hate this idea that if we have contractors in or we outsource something, then where is the knowledge share? Where is the ownership?

«You want your team that’s with you every day to feel proper ownership of what is going on, you don’t want them to think ‘oh that’s something that is going on over there and I don’t need to know about it’ or think that someone else is doing all the sexy exciting things. That’s not fair.»

Those doing the «sexy exciting» things, were engineers from Microsoft Azure who helped to migrate the comparison site’s data to the cloud. But rather than gawp in amazement from afar, or just accept the new tech would be Microsoft’s problem, O’Shea and the Confused.com management team, wanted the staff to take ownership and sought to educate them.

Confused.com is a small organisation which employs 200 people, all of whom work in Cardiff, South Wales. Only a third of its staff have technology-based roles and earlier in the year the company launched a school of tech.

«I was very clear with the staff,» says O’Shea. «I said: ‘look, as an employer, it is my responsibility to make sure you guys are educated in technology because it’s changing what we do as a business and changing what you do in your day to day job, very, very quickly’. I wanted to make sure that they had the skills while they were at Confused.com or if they left, to succeed in the future.»

«We wanted them to understand what the technology can do and the possibilities, because they are the ones that will spot where they can use it in their own day to day job. The engineers in the business know how this works, but you’ve got to bring these two parties together.»


When it comes to digital transformation, a CIO with an innovative mindset – and the right team – is ideally positioned to take the reins. Discover why in this whitepaper.

Download now


Part of the learning curve was to partnering the staff with an engineer to both understand the technology and take away any fear.

«They are the ones that are close to what they are doing every day and can see the opportunities. If they can understand what the engineers do, then they can spot those opportunities easier. We’ve already had some successes with 20% of our staff going through that program,» noted O’Shea. 

«Ownership is really important. If people don’t own it, they are just going to say’ it’s someone else’s thing, so I’m not going to touch it’.»

How Confused.com enabled staff to take ownership of its digital transformation


Bobby Hellard

31 Oct, 2018

Despite being an internet company, Confused.com still needed to undergo a digital transformation.

Such is the rapid rise of AI and cloud computing, the 16-year-old price comparison website only adopted a cloud service five years ago. And the tricky part was not about introducing new technology to the business, it was about introducing it to the workforce.

«We have always been tech geeks at heart and we make sure we are using technology to help customers,» says Louise O’Shea, Confused.com’s CEO. «I hate this idea that if we have contractors in or we outsource something, then where is the knowledge share? Where is the ownership?

«You want your team that’s with you every day to feel proper ownership of what is going on, you don’t want them to think ‘oh that’s something that is going on over there and I don’t need to know about it’ or think that someone else is doing all the sexy exciting things. That’s not fair.»

Those doing the «sexy exciting» things, were engineers from Microsoft Azure who helped to migrate the comparison site’s data to the cloud. But rather than gawp in amazement from afar, or just accept the new tech would be Microsoft’s problem, O’Shea and the Confused.com management team, wanted the staff to take ownership and sought to educate them.

Confused.com is a small organisation which employs 200 people, all of whom work in Cardiff, South Wales. Only a third of its staff have technology-based roles and earlier in the year the company launched a school of tech.

«I was very clear with the staff,» says O’Shea. «I said: ‘look, as an employer, it is my responsibility to make sure you guys are educated in technology because it’s changing what we do as a business and changing what you do in your day to day job, very, very quickly’. I wanted to make sure that they had the skills while they were at Confused.com or if they left, to succeed in the future.»

«We wanted them to understand what the technology can do and the possibilities, because they are the ones that will spot where they can use it in their own day to day job. The engineers in the business know how this works, but you’ve got to bring these two parties together.»

Part of the learning curve was to partnering the staff with an engineer to both understand the technology and take away any fear.

«They are the ones that are close to what they are doing every day and can see the opportunities. If they can understand what the engineers do, then they can spot those opportunities easier. We’ve already had some successes with 20% of our staff going through that program,» noted O’Shea. 

«Ownership is really important. If people don’t own it, they are just going to say’ it’s someone else’s thing, so I’m not going to touch it’.»

Microsoft Future Decoded: The three forces driving the AI revolution


Bobby Hellard

31 Oct, 2018

The theme for this year’s Microsoft Future Decoded is AI, and specifically, how it can transform your business faster than any technology before it.

But artificial intelligence is not new; It’s been around since Alan Turing was cracking codes in World War II. So, what is actually accelerating this revolution?

According to Cindy Rose, Microsoft’s UK CEO, there are three reasons why and she outlined them on stage during her keynote speech to open this year’s event.

«Firstly, it’s the explosive growth of data,» she said. «These connected consumer devices and IoT [internet of things] sensors are producing more data today then humans can possibly make sense out of.»

Indeed, using AI for data processing is a necessity as she gave an estimate that 2.5 quintillion bytes of data are being created every day. That’s more than 15 million text messages and 100 million spam emails every minute.

«It is also the power and pervasiveness of cloud,» she added. «Cloud is what enables the efficient and rapid analysis of all this data. Microsoft is investing billions of dollars in a global cloud infrastructure to make sure we can deploy AI, quickly and at scale.

This «explosive» growth of data and the capabilities within cloud computing, combined, are enabling the development of increasingly powerful algorithms — ones «we’ve never seen before», according to Rose. It’s indisputable, the two need to be combined because the sheer volume of data we now generate cannot be processed by a human.

This speed of processing is Rose’s third reason for the sharp rise in the AI revolution. This is what makes it a far more game-changing technology than anything that has gone before it.

«It’s taken us nearly four decades to put a PC on every desk and a smartphone in every pocket,» added Rose. «But the pace of AI deployment will be much faster and its impact more profound.

«And the pace the of change of these dynamics is why we believe that the time to embrace AI in your organisation is right now.»

Microsoft Future Decoded: The three forces driving the AI revolution


Bobby Hellard

31 Oct, 2018

The theme for this year’s Microsoft Future Decoded is AI, and specifically, how it can transform your business faster than any technology before it.

But artificial intelligence is not new; It’s been around since Alan Turing was cracking codes in World War II. So, what is actually accelerating this revolution?

According to Cindy Rose, Microsoft’s UK CEO, there are three reasons why and she outlined them on stage during her keynote speech to open this year’s event.

«Firstly, it’s the explosive growth of data,» she said. «These connected consumer devices and IoT [internet of things] sensors are producing more data today then humans can possibly make sense out of.»

Indeed, using AI for data processing is a necessity as she gave an estimate that 2.5 quintillion bytes of data are being created every day. That’s more than 15 million text messages and 100 million spam emails every minute.

«It is also the power and pervasiveness of cloud,» she added. «Cloud is what enables the efficient and rapid analysis of all this data. Microsoft is investing billions of dollars in a global cloud infrastructure to make sure we can deploy AI, quickly and at scale.

This «explosive» growth of data and the capabilities within cloud computing, combined, are enabling the development of increasingly powerful algorithms — ones «we’ve never seen before», according to Rose. It’s indisputable, the two need to be combined because the sheer volume of data we now generate cannot be processed by a human.

This speed of processing is Rose’s third reason for the sharp rise in the AI revolution. This is what makes it a far more game-changing technology than anything that has gone before it.

«It’s taken us nearly four decades to put a PC on every desk and a smartphone in every pocket,» added Rose. «But the pace of AI deployment will be much faster and its impact more profound.

«And the pace the of change of these dynamics is why we believe that the time to embrace AI in your organisation is right now.»

Why it’s time to fight back against cyber risk to cloud computing and virtual machines

Cloud computing is now a primary driver of the world’s digital economy. Governments, large corporations and small businesses are increasingly implementing cloud-based infrastructures and solutions to store their sensitive data and manage their operations.

While the cloud offers lower costs, scalability and flexibility, it also expands a company’s risk profile exponentially. In fact, attackers are continually refining their techniques to take advantage of the millions of identical binary templates for virtual environments (aka golden images) that power those cloud and Virtual Machine (VM) benefits.

Cloud and VM environments share parallels with Genetically Modified (GM) crops – yields are extremely high around carefully developed identical DNA sequences, but a single bug or virus can scale to destroy not just one, but all crops in a monoculture since there is no natural diversity to protect them. In a cloud context, a zero-day attack can take down all production systems and disaster recovery systems, disrupting business continuity and prompting financial loss.

Because traditional cybersecurity protections such as encryption, firewalls, intrusion prevention, and endpoint protection have been historically successful, adversaries have introduced new zero-day techniques to bypass them. Such modern techniques include memory corruption, return/jump oriented programming (ROP/JOP), and compromised supply chain attacks. The White House described the recent NotPetya supply chain attack as the “the most destructive and costly cyber-attack in history.”   

Growing risks in cloud computing

One of the greatest unintended consequences of both the cloud and VMs is that they expand the attack surface. Whenever data is stored across remote servers and VMs, risk is not just involved, but elevated. While a company may know its own source code, configurations, equipment, personnel and processes, cloud computing introduces the vulnerabilities of globally sourced third-party hardware, software and configurations that surround, penetrate, and bind the remote environment altogether.

Unfortunately, zero-days are not conveniently located in easy to inspect areas but can instead spread between components and layers in the network, storage, and server stack, from firmware, to bootloaders, hypervisors, containers, operating systems, middleware, libraries, and frameworks, and apps. A report by the Ponemon Institute found that “fileless” (memory-based) malware attacks are now almost ten times more likely to succeed in infecting a machine than traditional file-based attacks. These attacks evade detection by using a system’s own trusted files to obtain access.

Supply chain attacks are also on the rise and grew by more than 200 percent in 2017, according to Symantec's annual Internet Security Report. And so far in 2018, the Zero Day Initiative noted a 275 percent spike in virtualisation software bugs that offer the possibility of compromising within or across VMs.

Even in the physical world, examples of massively replicated golden images exist. In 2015, hackers compromised one Jeep truck, forcing manufacturer FCA Group to recall 1.4 million vehicles for updates – the world’s first vehicle cybersecurity recall. And in 2017, the FDA recalled nearly 500,000 pacemakers for firmware updates when it discovered lax cybersecurity could allow the devices to be hacked.

Why once successful security tools now fail

Traditional perimeter security tools no longer offer full protection in this complex and connected environment. The cybersecurity paradigm over the last 40 years has been one of increasingly clever detection via patterns, rules, analytics, and artificial intelligence rather than on preventing attacks from happening in the first place.  Zero-day is another name for the increasing numbers of attacks detection engines miss, inadvertently adding an organisation’s name to yet another “wall of victim logos” slide for the next cybersecurity forensics and after-action reporting conference.

There is already a growing chorus for stronger security. The Department of Defense says cyber defence must move beyond “just the networks,” and the National Security Agency notes adversaries are increasingly turning to supply chain exploitation.  Security standards and common defence can differ from provider to provider. Many strive to meet the standards of their industry, whether that be FedRAMP for government or PCI for finance. But even being compliant with standards, rules and regulations sometimes isn’t enough.

The problem is that most standards focus on detection and after-action reporting with limited attention to newer fileless or supply chain attacks.  A common hope is that strong encryption will somehow catch new types of attacks, However, there is actually no effect on memory corruption or compromised supply chain attacks that can come hidden in correctly signed and encrypted updates, or simply be pre-positioned within third party infrastructure.

Adding a deeper layer of defence

RASP is a term initially coined in a 2012 Gartner report titled, “Runtime Application Self Protection:  A Must-Have, Emerging Security Technology.” It’s a technology that is linked or built into an application or application runtime environment that is capable of controlling runtime execution and detecting and preventing real-time attacks. Forrester notes that RASP tools are used as a deeper layer of application defence by using insider information of the applications they protect to help more effectively detect and deflect malicious attacks. RASP techniques are enjoying widespread adoption – so much so that the RASP market is forecast to grow at a CAGR of 48% between 2018 and 2022 by ResearchandMarkets.com.

An implementation of RASP can bridge the growing security gap in the cloud. It can stop attacks and attack scaling rather than simply remediating symptoms. RASP offers built-in security to prevent real-time attacks with techniques such as binary stirring, control flow integrity, and stack frame randomization, reducing the attack surface and rendering zero-days built on memory corruption and supply chain attacks inert.

Early attempts at RASP added too much overhead to the code, were too limited in scope or perturbed functionality by trying to graft agents onto code. Others also had impractical requirements like the need for access to source code and recompilation, or the need for new hardware, new software or new services that made them impractical to use. But those limitations have now been overcome. Modern RASP can be added to existing or new binaries quickly, easily and economically.

RASP is also not a replacement for current tools since all the traditional attack vectors still occur; but it represents a new layer of protection that can quickly and easily integrate with existing on-premises, cloud, or web-based development deployments and update processes.

At a time when cloud-based applications and virtual machines are critical to the operations of government institutions and private enterprises, we can no longer put all of our security in the perimeter security and detection tools basket. Utilising RASP technology might just be our best chance for society to stay one step ahead of attackers, and prevent scaling, memory and compromised supply chain attacks from executing.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Days-long Microsoft outage leaving users unable to login to Office 365


Keumars Afifi-Sabet

31 Oct, 2018

Microsoft is investigating the cause of a lengthy Office 365 outage that has persisted for several days, with business customers, predominantly based in the UK, experiencing difficulties signing in to their accounts.

Users have been reporting problems with logging in to their Office 365 accounts across social media since Friday 26 October, with system information site DownDetector also seeing a spike in user complaints.

These complaints receded over the weekend, but resumed again on Monday 29 October, and have been peaking during working hours since. The issue appears to be predominantly affecting users in the UK.

The issue manifests as additional login prompts appearing after users have entered their details into the username and password fields. The appearance of a second «security prompt» means many business users have been unable to access critical services.

Microsoft confirmed yesterday it was investigating the issue, adding a handful of recently-made changes were rolled back in an attempt to resolve the symptoms.

«We rolled back recent changes that were made in the environment and some customers are reporting that impact has been mitigated for SP152610 and EX152471. The source of the issue remains under investigation,» Microsoft tweeted.

«If you have a user that is actively experiencing impact, please reply to us or contact support so we can gather additional information to assist with our investigation.»

further update, released by Microsoft at 13.00 GMT today, suggested no additional reports of disruption had been received, and that the «impact was remediated on Tuesday, October 30» late in the evening.

But a handful of customers replying to Microsoft’s tweet have suggested this is not correct, with one user John Gardner admitting he still had at least three users still affected.

The frequency of users registering Office 365 complaints in the last few days on DownDetector

This issue, which has persisted for more than three working days, is the latest in a series of high-profile outages that Microsoft has sustained in recent months.

Microsoft Azure and some Office 365 services suffered disruption for more than 24 hours in September following a «severe weather event» that knocked an entire data centre offline.

Customers in the US, and a host of European countries were unable to access a number of cloud-based apps after lightning strikes caused a power surge to Microsoft’s San Antonio, Texas-based data centre.

In April meanwhile, a similar but less severe Office 365 outage meant users for were unable to login to their accounts for a short period, affecting customers in the UK, France, the Netherlands and Belgium.

A map of the areas affected by the latest Office 365 outage, taken on Monday 29 October from DownDetector

«The continuity of business critical systems is vital for organisations today to maintain productivity and effective customer service,» said cyber resilience expert at Mimecast, Pete Banham.

«This Office 365 issue is a clear reminder that in the cloud age, it’s often down to individual organisations to ensure they have a plan B.»

«Employees can also create security and compliance risks during downtime when using unsanctioned or consumer IT services to get the job done.

«We are urging organisations to consider a cyber resilience strategy that assures the ability to recover and continue with business as usual.»

Asked to assess the increasingly cloud-centric business ecosystem, in light of recent outages, Banham told Cloud Pro it’s a balancing act between bottom-line cost reduction, and putting faith into potentially unreliable third parties.

«The merit of this approach is most likely to be a bottom line cost reduction on paper, but the true cost of a single outage could negate this entirely.

«An ecosystem where businesses wholly depend on the reliability of cloud hosting services is unlikely to be sustainable. After all, few organisations can tolerate lengthy or frequent disruption to their IT services.

«There should always be a backup plan that assures the ability to recover and continue with business as usual despite an outage. This particular incident is another reminder that relying on a single cloud service isn’t the most effective cyber resilience strategy.»

Cloud Pro approached Microsoft for further comment, and for details as to how the issue arose. The company did not respond at the time of writing.

Days-long Microsoft outage leaving users unable to login to Office 365


Keumars Afifi-Sabet

31 Oct, 2018

Microsoft is investigating the cause of a lengthy Office 365 outage that has persisted for several days, with business customers, predominantly based in the UK, experiencing difficulties signing in to their accounts.

Users have been reporting problems with logging in to their Office 365 accounts across social media since Friday 26 October, with system information site DownDetector also seeing a spike in user complaints.

These complaints receded over the weekend, but resumed again on Monday 29 October, and have been peaking during working hours since. The issue appears to be predominantly affecting users in the UK.

The issue manifests as additional login prompts appearing after users have entered their details into the username and password fields. The appearance of a second «security prompt» means many business users have been unable to access critical services.

Microsoft confirmed yesterday it was investigating the issue, adding a handful of recently-made changes were rolled back in an attempt to resolve the symptoms.

«We rolled back recent changes that were made in the environment and some customers are reporting that impact has been mitigated for SP152610 and EX152471. The source of the issue remains under investigation,» Microsoft tweeted.

«If you have a user that is actively experiencing impact, please reply to us or contact support so we can gather additional information to assist with our investigation.»

The frequency of users registering Office 365 complaints in the last few days on DownDetector

This issue, which has persisted for more than three working days, is the latest in a series of high-profile outages that Microsoft has sustained in recent months.

Microsoft Azure and some Office 365 services suffered disruption for more than 24 hours in September following a «severe weather event» that knocked an entire data centre offline.

Customers in the US, and a host of European countries were unable to access a number of cloud-based apps after lightning strikes caused a power surge to Microsoft’s San Antonio, Texas-based data centre.

In April meanwhile, a similar but less severe Office 365 outage meant users for were unable to login to their accounts for a short period, affecting customers in the UK, France, the Netherlands and Belgium.

A map of the areas affected by the latest Office 365 outage, taken on Monday 30 October from DownDetector

«The continuity of business critical systems is vital for organisations today to maintain productivity and effective customer service,» said cyber resilience expert at Mimecast, Pete Banham.

«This Office 365 issue is a clear reminder that in the cloud age, it’s often down to individual organisations to ensure they have a plan B.»

«Employees can also create security and compliance risks during downtime when using unsanctioned or consumer IT services to get the job done.

«We are urging organisations to consider a cyber resilience strategy that assures the ability to recover and continue with business as usual.»

IT Pro approached Microsoft for further comment, and for details as to how the issue arose. The company did not respond at the time of writing but tweeted that it would provide a further update at 13.00 GMT today.

Pakistan Government Harasses @ExpoDX, CIA-Affiliated Event to Take Place at Its @RooseveltNYC Property in New York City

DX WorldExpo LLC Leased space at the hotel to present its 22nd International event on November 12-13, 2018. Two weeks before the event the event producer received two separate proforma invoices with fictional charges which do not appear in the contract. The second invoice sent to the event producer by Pakisan government owned hotel demanded a payment of $473,616.35 within 24 hours or Pakisan would release the contracted space due to «breach of contract» clause. The show producer DX World EXPO LLC to present government sessions at the event. In previous conferences, the company presented keynotes by the CIA and by National Reconnaissance Office. Roosevelt Hotel in New York City is run by Managing Director Najeeb Samie on behalf of the Pakistan government.

read more