Automation is turning manual or repetitive IT tasks into a thing of the past-including in the datacenter. Nutanix not only provides a world-class user interface, but also a comprehensive set of APIs to allow the automation of provisioning, data collection, and other tasks. In this session, you’ll explore Nutanix APIs-from provisioning to other Day 0, Day 1 operations. Come learn about how you can easily leverage Nutanix APIs for orchestration and automation of infrastructure, VMs, networking, and even backup/DR. We’ll review available APIs and conduct live demonstrations of integrations and the automating common IT tasks.
Understanding the cloud security conundrum: What is the answer?

Name an online cloud storage service provider and you’ll have no problem at all finding reports for a breach. Recently, we’ve seen frequent incidents reported in the press involving companies leaking data through misconfigurations involving the cloud, as well as headlines reporting on user inexperience leading to weak security in cloud deployments.
But user error, complexity and misconfiguration surrounding cloud storage resources are only the tip of the iceberg when it comes to common cloud security issues – the reality is that cloud security is a multi-faceted issue involving not only technology, but also how companies look to approach cloud transition.
To truly understand and implement effective cloud security we first must understand the nature of the threats and the value of what’s stored, the significance of the cloud migration and transition processes, and the most effective way of protecting our assets.
Understanding data: A priceless asset
So why are we seeing so many headlines involving leaking data from misconfigured clouds, particularly AWS S3 buckets? Firstly, it’s not fair to say that the main problem is AWS S3 buckets. It’s probably fair to say that they are most frequently targeted, and that this is likely down to the fact that they are used mainly by high end enterprise clients that hold extremely valuable data.
Today, data is often considered more valuable than intellectual property or physical infrastructure because it has value in so many ways, especially when the wrong people manage to get a hold of it. Think about it: data can be misused for gaining direct financial gain, privileges and identity impersonation. It also has great “resale” value on the dark market, and, because it is typically extremely valuable to its owner, it can be used as a powerful ransom subject. We’re also seeing incidents of data being used for political and ideological crime.
Understanding the cloud transition
Complexity and misconfiguration of online storage resources are definitely to blame when it comes to the data leaks we’ve been hearing about, but companies need to dig deeper to see if there are more fundamental issues.
Frequently the problem starts with companies approaching cloud transition as yet another extension to their datacenter. While in an ideal world this is the most compelling selling point of a cloud solution, companies should also be thoroughly re-thinking their internal procedures before taking this significant plunge. For example, have you reviewed creating your DevOps resources in a different way to consider cloud deployment, and is your QA team set to test the multitude of new factors, like bucket configuration, that are potential points where serious leaks could happen?
While the cloud brings fantastic flexibility, it’s important to recognize that the cloud transition time is an opportunity to take advantage of all the tools available to run secure software deployments, and to flag if functionality may be underused or plainly unused.
Here are a few things to consider during the cloud transition stage:
- Can you implement a stricter separation of duties within the enterprise? For example, the security department – not developers – should be setting up the permissions on the public bucket. Beyond this, a third entity should approve them for publishing
- Are you creating standard configurations and images? The cloud is really good at repeating, and if the base is sound the results will be sound as well – or at least they will all fail predictably and in the same way
- Are you using adaptive internal process (depending on the criticality of data stored?)
- Are you using AI and machine learning to evaluate the criticality of data stored on publicly available data stores? Critical data may have been stored there unknowingly or considered a temporary upload for example
Understanding cloud service providers
Cloud service providers are doing really good job in providing security services and better ways to secure data than any of the existing on premise implementations. The reason behind this is that security and data privacy are always on the top of the list of perceived road blocks for adopting cloud. In addition, the unprecedented automation capabilities of the cloud can be largely used for stepping up the security of any infrastructure to the next level of maturity.
On the other hand, the market competition for a place under the cloud drives service providers into a frenzy of providing new services in order to gain better position at the market. This unfortunately brings complexity, which is the top issue they need to address.
Tools like Zelkova automated reasoning for security controls and Tiros, which can help define the exposure footprint, are more than welcome, but they have to be implemented in the simplest possible way so as not to create additional complexity. It’s all about final implementation and how the complex processes will be presented to the end user.
Understanding the past and the future
The online storage and archival space has been one of the first widely adopted cloud services, way before the invention of the ‘aaS’ acronyms, and it’s come a long way. It’s apparent that cloud service providers are doing what they can to address security issues, and as long as they make every effort to address complexity, a move to the cloud will continue to be a comparatively safe option in comparison to on premise storage solutions.
And while most businesses understand the value of what they seek to store in the cloud, it’s high time they put the cloud transition stage under a microscope to address development, operations, QA and security roles in order to run the most secure deployments possible.
Interested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.
CloudEXPO Silicon Valley To Present 200-Booth Expo Floor | @CloudEXPO #Serverless #Cloud #CIO #IoT #DevOps #ArtificialIntelligence #Blockchain
CloudEXPO | DevOpsSUMMIT | DXWorldEXPO Silicon Valley 2019 will cover all of these tools, with the most comprehensive program and with 222 rockstar speakers throughout our industry presenting 22 Keynotes and General Sessions, 250 Breakout Sessions along 10 Tracks, as well as our signature Power Panels. Our Expo Floor will bring together the leading global 200 companies throughout the world of Cloud Computing, DevOps, IoT, Smart Cities, FinTech, Digital Transformation, and all they entail.
Amid various privacy scares – yes, you can collaborate and communicate securely in the cloud

Last week, Facebook announced the launch of Portal, a voice-activated smart home camera device. Considering the recent data breach the company suffered, the tech press response to Portal ranged from bafflement to incredulity.
In response, Facebook senior exec Andrew Bosworth insisted< all processing was done locally on the device – so no information was uploaded to the cloud, or stored on Facebook servers. But is this sensible policy or scaremongering?
This article will argue it is a bit of both; going through various data breaches and scandals, privacy fears around the cloud, and how using tools like VPNs – albeit with a degree of caution– add an extra layer of security to the cloud computing equation.
Cloud data breaches and scandals
Data breaches are common occurrences in today’s information-driven world. Although a lot of these breaches involved server-hosted companies, cloud-hosted companies have had their fair share as well.
Facebook’s data breach is the latest in this lineup. It happened in September of this year when Facebook’s engineers noticed a sudden spike in the site’s user activity.
This led them to scramble for a solution until they concluded that their site had in fact been compromised. Recent reports state that the hackers may have had unrestricted access to over 50 million records.
Earlier this year, Data firm LocalBox was in the news for its controversial building of detailed profiles by scraping publicly-accessible social media data of millions of individuals which left 48 million people’s records on an exposed server.
Last year, conservative data firm Deep Root Analytics exposed 198 million voter records.
In the same year, Kromtech Security Center discovered that healthcare services company Patient Home Monitoring had left 150,000 patient records unsecured. These records included PDF files and sensitive medical data.
With all of these data breaches and scandals, it’s no wonder why many businesses have doubts about the cloud’s security. But these fears are actually ungrounded.
Why?
Most privacy fears around the cloud don’t actually involve the cloud
Privacy and security in the cloud are the primary concerns for many executives and IT managers. Such concerns are understandable given that you’re pretty much entrusting your data to someone else.
Fanning the flames of these concerns are the various data breaches involving the cloud. But what a lot of people don’t realize is that most breaches don’t involve a lack of security in the cloud provider itself.
In fact, a recent Cloud Security Report by Cybersecurity Insiders shows that three out of the four biggest cloud security threats don’t actually involve the cloud service itself.
The four biggest cloud security threats being:
- Misconfiguration of the cloud platform
- Unauthorized access through misuse of employee credentials and improper access controls
- Insecure interfaces/APIs
- Hijacking of accounts, services, or traffic
Human error is actually the cause for most of the recent cloud data breaches including the ones involving World Wrestling Entertainment and Verizon.
Misconfiguration happens when professionals used to the local infrastructure attempt to recreate their local solutions in the cloud without taking into account the intricacies of the cloud provider’s particular features.
Unauthorized access through misuse of employee credentials and improper access controls is, again, not attributable to the cloud provider itself but instead to a client’s employee(s).
The problem with this is that they’re difficult to detect and investigate. This threat can be caused either by an employee intentionally stealing and using someone else’s credentials or by obtaining them by mistake.
Hijacking is a process in which an attacker steals an individual or organization’s cloud account, usually an email account or other credentials. This is a common tactic in schemes involving identity theft where the attacker conducts malicious or unauthorized activity by using the stolen account information.
Hijacking was what caused the whole Apple iCloud debacle. This is why Apple, along with implementing other security features, suggested that users strengthen their passwords.
This all means that while the cloud may suffer a lot of data breaches, the truth is most of these breaches are caused by external factors and not factors inherent in the cloud itself.
Tools to improve cloud security
So you’ve learned that, by itself, the cloud is secure for the most part. That said, in a data-driven economy, organizations will stand to benefit from utilizing certain tools to maintain an adequate level of security for workloads in the cloud.
In fact, the Cybersecurity report showed that 54% of respondents saw network encryption to be an effective way to protect data in the cloud. Perhaps the easiest tool for network encryption is the humble VPN.
The best VPNs protect your cloud data by utilizing military-grade AES 256-bit encryption. This is the same encryption standard used by Apple, Microsoft, and even the U.S. military. Add to that the fact that a VPN masks your IP address and you’ve got a tool that not only secures your data but also prevents it being traced back to you.
Now, there has been recent news about major security flaws found in the top VPN providers but they’ve since been fixed. That said, the same security flaw may still be present in some VPNs so some caution is still required when looking for the right VPN for your organization.
If you’d like to compare the best VPNs available on the market today, check out my reviews for the best VPN services.
SAP breaks €5bn in quarterly cloud and software revenue – but profits see slight dip

SAP has claimed it is the ‘fastest growing cloud company at scale’ in enterprise software applications after breaking the €5 billion barrier for quarterly cloud and software revenues.
The figure of €5.01bn (£4.4bn) represents an increase of 7.5% on this time last year, and an increase of 1.3% on the previous quarter. Total revenues for the company were at €6.02bn, meaning cloud and software was at 83% of all earnings for the quarter.
Speaking to analysts following the announcement, SAP CEO Bill McDermott said the company was in the position it needed to be. “With 41% cloud revenue growth in Q3, SAP has the fastest cloud growth of any peer at scale in the enterprise applications software industry,” said McDermott.
“Three years ago we said that cloud revenue would overtake license revenue in 2018. Today the fast adoption of our cloud solutions and business networks has accelerated this positive development,” McDermott added. “The resilience of our license business remains ever steady even as we grow the cloud beyond expectations.
“Cloud has a higher lifetime value, drive[s] faster consumption of innovation and has higher predictability going forward. We planned for this transition – we guided for it and we are delivering it.”
This publication duly reported SAP’s prediction that cloud profits would exceed software license revenues by 2018 back in January 2015 – and it appears to be on track for that side. That said, it is never fully clear cut to tell; apart from Amazon, which puts AWS revenues in a clear segment, virtually every other primary vendor obfuscates its figures to some degree. Microsoft, for instance, reveals a percentage point increase for Azure but hides its overall numbers in two buckets. For SAP, describing those revenues as ‘cloud and software’ makes sense in this context.
SAP raised its 2018 outlook for the third time this year – but despite this, profits were slightly down, with operating profit declining 6%, from €1.3bn to €1.2bn.
Chief financial officer Luka Mucic reiterated that cloud was ‘where the long-term value was’ and that SAP’s ‘intelligent enterprise strategy’ was ‘resonating broadly and propelling strong adoption of [their] suite in the cloud.’ Responding to an analyst question around license performance and support revenue, Mucic added that “the market needs to expect a gentle decline in growth rates of support revenues.”
You can read SAP’s full financial results here.
Picture credit: SAP
Interested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.
Agility from Technology | @DevOpsSUMMIT @Nutanix @rtpChris #DevOps #Serverless #APM #Monitoring #Microservices
In today’s always-on world, customer expectations have changed. Competitive differentiation is delivered through rapid software innovations, the ability to respond to issues quickly and by releasing high-quality code with minimal interruptions. DevOps isn’t some far off goal; it’s methodologies and practices are a response to this demand. The demand to go faster. The demand for more uptime. The demand to innovate. In this keynote, we will cover the Nutanix Developer Stack. Built from the foundation of software-defined infrastructure, Nutanix has rapidly expanded into full application lifecycle management across any infrastructure or cloud .Join us as we delve into how the Nutanix Developer Stack makes it easy to build hybrid cloud applications by weaving DBaaS, micro segmentation, event driven lifecycle operations, and both financial and cloud governance together into a single unified stack.
UK third-party data centre market is largest in Europe
The UK’s third-party data centre market is now the largest in Europe, according to DataCentrePricing.Com (DCP)’s latest report into data centre take-up around the world.
The UK’s data centres cover 840,000 sqm – that’s a substantial amount more than Germany’s with 509,000 sqm.
And this is set to increase every year, with DCP predicting an additional 40,000 sqm of data centres being added to the total every 12 months. Over the next year, for example, there are big plans to expand floor space at the Slough Data Centre, London, Farnborough and Cardiff clusters.
At present, Sloughs facility comprises 107,000 sqm, second only to London and the inner M25 area, which currently boasts 260,000 sqm dedicated to data centres.
New data centres are also planned, in major cities such as Edinburgh, Leeds and Newcastle, that will further highlight the UK as a European leader.
Although the UK has the largest data centre facilities in the whole of Europe, the cost of space is not the most expensive and this is why it’s so attractive to businesses. Average UK rack space rates are around €1,000, with Switzerland and Ireland charging higher premiums for space in their data centres
Unsurprisingly, these rates vary a lot across the UK, with those in London and within the M25 an average of 42% higher than Leeds and Newcastle.
“Increasingly, Data Centre Providers are competing to provide cloud connectivity to the key Cloud Service Providers via a cloud exchange aiming to attract the enterprise customer to the facility – which is driving the Data Centre clusters’ status as a connectivity hub,“ the report explained. “And the amount of connectivity available from a Data Centre facility helps determine whether a price premium can be charged – the more connectivity available the higher the price premium.”
UK third-party data centre market is largest in Europe
The UK’s third-party data centre market is now the largest in Europe, according to DataCentrePricing.Com (DCP)’s latest report into data centre take-up around the world.
The UK’s data centres cover 840,000 sqm – that’s a substantial amount more than Germany’s with 509,000 sqm.
And this is set to increase every year, with DCP predicting an additional 40,000 sqm of data centres being added to the total every 12 months. Over the next year, for example, there are big plans to expand floor space at the Slough Data Centre, London, Farnborough and Cardiff clusters.
At present, Sloughs facility comprises 107,000 sqm, second only to London and the inner M25 area, which currently boasts 260,000 sqm dedicated to data centres.
New data centres are also planned, in major cities such as Edinburgh, Leeds and Newcastle, that will further highlight the UK as a European leader.
Although the UK has the largest data centre facilities in the whole of Europe, the cost of space is not the most expensive and this is why it’s so attractive to businesses. Average UK rack space rates are around €1,000, with Switzerland and Ireland charging higher premiums for space in their data centres
Unsurprisingly, these rates vary a lot across the UK, with those in London and within the M25 an average of 42% higher than Leeds and Newcastle.
“Increasingly, Data Centre Providers are competing to provide cloud connectivity to the key Cloud Service Providers via a cloud exchange aiming to attract the enterprise customer to the facility – which is driving the Data Centre clusters’ status as a connectivity hub,“ the report explained. “And the amount of connectivity available from a Data Centre facility helps determine whether a price premium can be charged – the more connectivity available the higher the price premium.”
Atlassian’s Jira software cloud is now generally available
Atlassian has launched its revamped Jira project management software with a completely overhauled user experience.
The company built the software from the ground up, including the architecture. Although there will still be a cloud version and a self-hosted version, they’ve now been split up into two separate version, each addressing the specific tools businesses need when developing apps for each environment.
Highlights of the Jira update include giving more autonomy to teams, rather than just focusing on the admins, lessening the pressure on those managing projects. Of course, admins are able to switch off features they don’t want their teams to access or change, but that’s pretty standard.
But just because Jira looks and works differently to its original version, doesn’t mean those who love the software as it is will be put off. In fact, Atlassian understands that the classic version of Jira is very important exactly how it always has been for many.
“It’s important to note that the next-gen experience will not replace our classic experience, which millions of users are happily using,” Jake Brereton, head of marketing for Jira Software Cloud, told TechCrunch.
“The next-gen experience and the associated project type will be available in addition to the classic projects that users have always had access to. We have no plans to remove or sunset any of the classic functionality in Jira Cloud.”
He added that the acquisition of Trello has had a real bearing on the way Jira has evolved. Buying the project management platform meant that Atlassian could understand how a wider net of users are managing projects, implementing the simplicity to its platform.
Cards can now be dragged and dropped across columns and columns themselves can be created much more easily than was previously possible. And like Trello, there are more integrations, including with Github, Bitbucket, InVision, Slack, Gmail and Facebook for Work.
The roadmaps features make it easy for teams to see where the project is going and that can be easily changed too, just by moving work around.
Crosscode To Exhibit and Present at @CloudEXPO New York | @CrosscodeCEO #Cloud #CIO #DevOps #DigitalTransformation
Crosscode Panoptics Automated Enterprise Architecture Software.
Application Discovery and Dependency Mapping. Automatically generate a powerful enterprise-wide map of your organization’s IT assets down to the code level.
Enterprise Impact Assessment. Automatically analyze the impact, to every asset in the enterprise down to the code level.
Automated IT Governance Software. Create rules and alerts based on code level insights, including security issues, to automate governance.
Enterprise Audit Trail. Auditors can independently identify all changes made to the environment.