Run Plexus Wallet on Mac with Parallels Desktop for Secure Cryptocurrency Management

Parallels Desktop® for Mac is the #1 award-winning virtualization software in the world. Why? The secret to our success lies with our incredible users who accomplish the unexpected every day, running Windows, Linux, and other popular OSes on their Mac® without rebooting. “Unexpected” needs come in many forms with our users. Millions of them all […]

The post Run Plexus Wallet on Mac with Parallels Desktop for Secure Cryptocurrency Management appeared first on Parallels Blog.

The end of an era: Why it’s time to ditch the big four in ITOM – and what it means for IT leaders

In July 2018, Broadcom announced its plan to acquire CA Technologies for almost $19 billion. While analysts have furiously debated the merits of a chip manufacturer buying an enterprise software company, the CA acquisition heralds a momentous shift in the $25 billion IT operations management (ITOM) software market.

For more than two decades, four technology vendors – BMC, CA, IBM and HP – have dominated the ITOM software market. In 2012, these big four collectively accounted for 55% of the ITOM software industry. By 2017, their market share had declined to less than 30% (Gartner).

More crucially, the CA acquisition means that the big four as you’ve known them no longer exist. Here is how the big four lost their way – and why IT leaders need to start working with a new breed of insurgents that are transforming IT operations management.

A quick history lesson: How four incumbents lost their way

A decade ago, most ITOM startups expected to scale and then sell out to a big four provider at some point in their journey. Today, most startups begin with a business plan that’s all about stealing market share from a big four product suite. Here’s a synopsis of where these four companies stand today.

BMC: BMC Software started life as a mainframe management tools company in 1980. By 2013, it was clear that the company had run out of steam. BMC’s annual revenues from 2010-2013 showed a tepid CAGR growth of 0.78% – $1.91bn in 2010 versus $1.97bn in 2013. In May 2013, private equity players Bain Capital and Golden Gate Capital acquired a majority stake in BMC for $6.9bn. Five years later, another private equity firm, KKR, agreed to buy BMC from its previous investors for $8.5bn. In 2018, BMC’s annual revenues were still stuck at $2bn, despite significant product and go-to-market investments over the last five years.

CA Technologies: CA was the dominant mainframe utility software company of the 1980s. A serial acquirer, CA was well known for buying companies and milking customers for maintenance fees. In recent years, CA experienced the same problems of stagnant products and stalled growth. The company registered a negative CAGR of 0.18%, with revenues marginally declining from $4.26bn in 2015 to $4.23bn in 2018. With all options exhausted, CA sold itself to Broadcom last month.

IBM: IBM Tivoli started in 1989 as a systems management vendor for IBM mainframe hardware. In 1996, IBM bought out Tivoli and folded over thirty acquisitions into the Tivoli division. By 2012, IBM Tivoli was the leading ITOM software player with $3.2bn in annual revenues. However, IBM made few actual investments in upgrading the Tivoli architecture to meet the demands of a new generation of ITOM buyers. In 2016, IBM signed a 15-year deal with HCL Technologies for offloading the development and maintenance of Tivoli products. Today, the best mention you get to the venerable Tivoli brand on IBM’s website is deep in its Cloud & Smarter Infrastructure division.

HP: HP launched its OpenView family of IT management tools in the early 1990s. After acquiring Peregrine, Mercury Interactive, and Opsware in the last decade, HP grew its OpenView portfolio to more than $1bn in annual revenues. However, with all the troubles that HP experienced after the Autonomy deal, it sold its entire ITOM software portfolio to Micro Focus in 2016. Reacting to the HPE-Micro Focus $8.8bn merger, The Register pointed out that “Micro Focus is considered by some to be something of a retirement home for software businesses that have seen better days.”

The big four are (mostly) dead – here’s why

So why did the big four players lose their way? A distinct absence of innovation, a strong dependence on legacy portfolios and maintenance revenues, and unwieldy product suites sealed the fate of the big four. Here are our top three reasons for their decline:

Reason #1: Acquisitions are not a substitute for organic innovation

A big reason for the fall of the legacy ITOM software providers was an over-reliance on acquisitions. The big four executives spent all their time pursuing deals and acquiring the hottest technology startups – instead of keeping their product stacks modern and relevant. The playbook was simple: fold the latest acquisition into an existing division and incentivise armies of salespeople to bundle and sell the new solution. Here’s a quick timeline of some notable acquisitions made by the big four since 2000:

  • BMC Software has splurged on companies like Remedy (IT service management), ProactiveNet (performance management), RealOps (runbook automation), BladeLogic (data centre automation), Cordiant (application performance monitoring), and Numara (IT service management) to bolster its ITOM software portfolio
  • CA Technologies built its monitoring portfolio with acquisitions like Wily Technology, Nimsoft, WatchMouse, and RunScope while Arcot, Xceedium and IdMLogic helped shape its identity management solutions
  • IBM Tivoli acquired CIMS Lab (IT asset utilisation), Micromuse (event correlation), Collation (discovery), BigFix (patch management), and Intelliden (network automation) to keep its Tivoli division growing every year
  • HP bought companies like Peregrine Systems (IT service management), Trustgenix (identity management), Mercury Interactive (IT service delivery), Bristol Technology (business transaction monitoring), Opsware (data centre monitoring), and ArcSight (security) to extend the capabilities of its OpenView suite

Reason #2: How legacy software and maintenance fees propped up big four revenues

If there’s one technology that embodies legacy, it is mainframes. The dirty secret of the big four was their addiction to mainframe monitoring and management for revenue generation. If you look at CA’s revenues (excluding services) in 2018, mainframe solutions accounted for 55% of revenues and 64% of segment operating margins. In contrast, enterprise solutions drove only 45% of revenues and just 9% of its segment operating margins. Similarly, for BMC, mainframe tools brought in 43% of overall revenues in 2013 – the last year in which the company reported financial results before selling itself.

Another factor that prevented the big four from embracing innovation, in the form of SaaS delivery models, is maintenance fees. At BMC, maintenance revenues accounted for 52% ($1.12bn), 50% ($1.08bn), and 50% ($1.02bn) of overall revenues in 2013, 2012 and 2011. Micro Focus made 67% ($720.7m) and 66% ($754.5m) of its revenues from maintenance fees in 2017 and 2016.

Reason #3: Big four suites: Bloated, disjointed, and out of touch with market realities

When you analyse any big four solution, you find suites like HP OpenView are built on legacy tools like Operations Manager i and Network Node Manager i. Even BMC’s recent Cognitive Service Management sits on age-old solutions like Remedy and Discovery. The big four resorted to buying and folding different products into their ITOM portfolios to keep flagship suites like Tivoli and TrueSight relevant. Sales teams then sold the mantra of a single pane of glass for enhanced visibility and control across your IT infrastructure.

Most big four suites would take several quarters to implement, along with the need for expensive third-party professional services. Besides the time and cost overruns, the process of consolidating disparate products into a single framework was a Herculean challenge. Most big four suite implementations failed to deliver the efficiency, simplicity, and scalability that was originally promised during the sale.

Don’t fear change – embrace it

What’s next for DevOps and IT operations teams? New players have emerged to fill the vacuum created by the exit of the big four. Cutting-edge, cloud-based technologies are taking the place of tool suites. And business consolidation, including the likes of Splunk/VictorOps, VMware/CloudHealth, are presenting new challengers to old technology. The future is agile, modular and flexible. As business blazes a new trail forward, it’s time for technology to transform along with it.

Tresorit raises €11.5 million in series B funding to help promote secure cloud collaboration

Tresorit, a European provider of cloud security and collaboration software, has announced it has raised €11.5 million (£10.4m) in series B funding to help accelerate growth and scale marketing and sales operations.

The company, which sits in the enterprise file and sync space, offers products focused at the legal, healthcare and HR departments around encrypted storage and secure file sharing, as well as GDPR-compliant solutions. Tresorit already has more than 17,000 customers, with recurring revenue growing on average by three times each year for the past three years.

Funding for the series B, which takes the company’s total funding to €15m, included contributions from 3TS Capital Partners, who led the round, and PorfoLion.

Like others in the space, such as Egnyte, Tresorit’s particular focus on the enterprise side of the market – and with one eye looking at the continually rising number of data breaches – has stood the company in good stead.

The company said it saw growing interest in its service particularly in the months leading up to GDPR. “More and more businesses realise that the cloud is a convenient way to store and share files, but are afraid to make the switch due to security and compliance concerns,” Tresorit spokesperson Katalin Jakucs told CloudTech. “With security guaranteed by Tresorit’s end-to-end encryption and various data control features, businesses don’t have to worry about achieving compliance in the cloud.”

Writing in a blog post following the announcement, Tresorit CEO Istvan Lam said future plans included product enhancements, such as control features and password recovery, as well as the launch of Tresorit Send, a standalone file sharing offering. “With the help of the new investment, we aim to enable many more organisations to keep control over their data online,” wrote Lam.

“Tresorit’s service is critically important for customers in light of the growing number of data breaches reported on a daily basis,” said Jozsef Kover, partner at 3TS in a statement. “The management team has a clear vision on how the company will further expand its reach, especially among enterprise and SMB clients.

“The company has already established itself as a leader in its market and is experiencing strong, consistent growth,” added Kover. “We look forward to support the management on their journey to further expansion and global scale.”

Kover will join the board of Tresorit as part of the move.

Global public cloud computing revenue trends: How hybrid and multi-cloud will dominate

The global public cloud computing market continues its predictable growth trend. By and large, it's viewed as an IT commodity, where customers have no loyalty to cloud service providers that follow a 'race to the bottom' mindset — providing the lowest price at a given moment in time. That said, everything about this business model seems somewhat tentative.

The worldwide cloud infrastructure as a service (IaaS) market grew 29.5 percent in 2017 to reach a total revenue of $23.5 billion — that's up from $18.2 billion in 2016, according to the latest market study by Gartner. Moreover, Amazon was the leading vendor in the IaaS market during 2017, followed by Microsoft, Alibaba, Google and IBM.

Cloud IaaS market development

"The top four providers have strong IaaS offerings and saw healthy growth as IaaS adoption is being fully embraced by mainstream organizations and as cloud availability expands into new regions and countries," said Sid Nag, research director at Gartner. "Cloud-directed IT spending now constitutes more than 20 percent of the total IT budget for organizations using cloud. Many of these organizations are now using cloud to support production environments and business-critical operations."

In the IaaS market, the competitive landscape is consolidating around the current leaders. The top four providers are all hyperscale IaaS providers and represent approximately 73 percent of the total IaaS market and 47 percent of the combined IaaS and infrastructure utility services (IUS) market.

Amazon is the clear leader in the worldwide IaaS market with an estimated $12.2 billion revenue in 2017 — that's up 25 percent from 2016. Growth in 2017 was driven not only by customers that are migrating from traditional data centers to cloud IaaS, but also by customers implementing digital transformation projects, reflecting a broad range of use cases.

According to the Gartner assessment, Microsoft has secured the number two position in the IaaS market with growth of more than 98 percent on its IaaS offering, with revenue surpassing $3.1 billion in 2017. Microsoft delivers its IaaS capabilities through its Microsoft Azure offering, which is a collection of infrastructure and platform services.

In the third position, China's Alibaba growth in 2017 of 63 percent reflects the company's successful investment in research and development (R&D). Alibaba has the financial capability to continue this trend and invest in global expansion, giving them the potential to become an alternative to the leading global hyperscale cloud providers in select regions. Alibaba could disrupt the current cloud incumbents.

Outlook for cloud service adoption and growth

"This reflects a fundamental change in what and how organizations are consuming technology. Some legacy infrastructure offerings, such as IUS, are seeing lower and slower uptake that impacts the combined IaaS and IUS market," Mr. Nag said. "Additionally, a groundswell of demand for cloud-skilled personnel is forcing technology providers to change how they compete to meet this exploding demand."

There is no doubt that the IT infrastructure future will be driven by increased cloud computing adoption within on-premises data centers and in public cloud service platforms. A broad variety of hybrid cloud combinations and multi-cloud vendor deployments will be commonplace. What's unclear is the viability of cloud providers that are unable to maintain their ROI, as the competitive battle evolves over time.

Michael Yamnitsky, Work-Bench: On enterprise machine learning and why ‘it’s a good time to be a mega cloud’

The future of enterprise software will be in some part automated, with machine learning (ML) and artificial intelligence (AI) technologies really starting to come to the fore. For all the actors cast in this fascinating drama – from the largest cloud vendors to startups, and from business analysts to data scientists – it’s time to either start learning their lines or, in some cases, rip up the script altogether.

The script in question? The Empire Strikes Back.

Work-Bench, a New York-based venture capital firm focusing on enterprise technologies, released its 2018 Enterprise Almanac report last month with that very title. The reason relates to the culmination of a long-standing trend. 10 years ago, it was a clear fight between the on-prem empire and the ‘cloud rebel alliance’, as the report puts it. Today’s rebel alliances have to fight not just the on-prem overlords, but the cloud hypervendors – Amazon, Microsoft, Google et al.

This is a trend that is not going away any time soon. Michael Yamnitsky, venture partner at Work-Bench and author of the report (left), jokes that next year’s report will most likely be titled Return of the Jedi. Yet as the report asserts, large technology companies are ‘#winning’ – the report’s hashtag – at AI. Not only are the largest cloud vendors releasing various toolkits – Amazon with SageMaker and Lex, Azure with Machine Learning Studio – they’re also hoovering up the best AI talent.

Work-Bench’s vision is ‘hoping that new talent gets excited about the enterprise’ – and as this publication put it when covering the original report, the promises of AI and ML will give plenty of reason to get excited in the coming years.

In an email conversation with CloudTech, Yamnitsky gives his verdict on what has changed in the industry over the past 12 months, the rise of Salesforce as an AI force, and what the biggest cloud players and BI vendors will do from here.

CloudTech: How much has changed in the enterprise software industry between this year’s and last year’s reports?

Michael Yamnitsky: A lot! The industry is constantly evolving. That’s what makes early stage venture so much fun. Building a new company in a highly dynamic, competitive market means you always need to play mental chess to figure out the right moats and pockets of value you can monetise.

CT: The report touches on the shift of moving natural language processing to business reports. There are companies looking to do this, but is this ‘democratisation of data’ really going to change things at the executive level?

MY: It will – but it will take time. The promise of products like Salesforce Einstein are to allow anyone to find insights in data without prior knowledge of the underlying data structures. Executives are certainly not precluded from this shift.

CT: Is it wanted from all sides – and what does this mean for data scientists? Is it similar to citizen developer initiatives from a few years ago, or will this take food off their table?

MY: That’s an interesting question and it comes down to culture. Some data scientists embrace democratisation, while others want to keep the lid shut so their work – and position of power – in the company remains stable.

CT: You focus on Salesforce as someone to keep an eye on for AI with its Einstein suite – could you elaborate a bit more on why that is, compared with other companies?

MY: Salesforce Einstein is based on a product built by BeyondCore, a startup Salesforce bought a few years ago. The product is very impressive. Salesforce just doesn’t have mindshare in the BI space. People do not know much about it. Salesforce has a good eye for marketing and I’m [sure] will have no problem catching up.

There are some stealth early-stage companies trying to emulate Salesforce Einstein functionality with standalone products and Tableau seems eager to compete in this area – but otherwise Salesforce has a highly differentiated product in the market.

CT: If you are a more traditional BI vendor reading this report, what do you have to do?

MY: Traditional BI vendors certainly understand this shift and seem to know what to do about it given the recent developments and M&A we see in the market.

CT: What do the next 18 months or so hold for the ‘mega clouds’, as you call them in the report? Market share remains stellar and capex continues to climb – and they seem to be leaning on their huge growing shares in infrastructure to particularly explore ML tools. Will that last?

MY: The mega clouds continue to surprise us. We assumed last year they would stick to building developer tools. That’s certainly the case for Microsoft and Amazon, but Google seems eager to build vertical AI applications starting with customer service.

I would not disqualify the other two from pursuing a similar strategy, or from pursuing any other product-market extension for that matter. It’s a good time to be a mega cloud.

Cloud Native Computing Foundation to fully operate Kubernetes – with help of Google Cloud grant

Google Cloud is cutting the umbilical cord further when it comes to Kubernetes. The company is helping fund the move to transfer ownership and management of the technology’s resources to the Cloud Native Computing Foundation (CNCF) with the help of a $9 million grant.

The move will see the CNCF, as well as Kubernetes community members, taking responsibility for all day-to-day project operations. This will include testing and builds, as well as maintenance and operations for Kubernetes’ distribution.

Kubernetes was first released by Google in 2014, and was moved over to the CNCF, a neutral arbiter of cloud development technologies, shortly after its inception in 2015. The technology officially became the first to ‘graduate’ from the foundation in March, a sign that it had reached mature levels of governance and adoption. Last month Prometheus, an open source systems monitoring technology, became the second to graduate.

“With the rapid growth of Kubernetes, and broad participation from organisations, cloud providers and users alike, we’re thrilled to see Google Cloud hand over ownership of Kubernetes CI/CD to the community that helped build it into one of the highest velocity projects of all times,” said Dan Kohn, CNCF executive director.

“Google Cloud’s generous contribution is an important step in empowering the Kubernetes community to take ownership of its management and sustainability – all for the benefit of the project’s ever-growing user base,” Kohn added.

“Developing Kubernetes in the open with a community of contributors has resulted in a much stronger and more feature-rich project,” wrote William Denniss, product manager for Google Kubernetes Engine in a blog post. “By sharing the operational responsibilities for Kubernetes with contributors to the project, we look forward to seeing the new ideas and efficiencies that all Kubernetes contributors bring to the project’s operations.”

At the Open Source Summit in Vancouver last week, the CNCF announced 38 new members had joined the foundation. Among the companies readers of this publication will recognise include hosting firm OVH, SQL database provider Cockroach Labs, and consulting firm InfraCloud Technologies.

OpenStack ‘Rocky’ makes it easier to deploy on bare metal

Open source cloud platform OpenStack now powers 75+ public cloud data centres and thousands of private cloud services at a scale of more than 10 million compute cores.

Earlier versions of the platform were difficult to upgrade from one version to another. Moreover, it has been hard to deploy on bare metal. But now, these problems have been resolved with OpenStack 'Rocky' — the platform’s 18th version.

OpenStack has always run on a variety of hardware architectures. However, bare metal has always been a bit complicated.

The platform's new bare metal provisioning module, Ironic, simplifies deployment by bringing more advanced and management and automation capabilities to the bare metal infrastructure.

OpenStack Nova, which manages large networks of VMs, now also supports bare-metal servers. This means that the platform also supports multi-tenancy so that users can manage physical infrastructure in the same way they manage VMs.

There are other new features of the Ironic, which includes: User-managed BIOS settings, conductor groups, and RAM Disk deployment interface.

Julia Kreger, Red Hat principal software engineer and OpenStack Ironic project team lead, said:

“OpenStack Ironic provides bare metal cloud services, bringing the automation and speed of provisioning normally associated with virtual machines to physical servers.

This powerful foundation lets you run VMs and containers in one infrastructure platform, and that's what operators are looking for.”

Oath’s IaaS architect James Penick said that OpenStack is already in use in his company to manage thousands of bare metal in the company’s data centres. There were significant changes made to Oath’s supply chain process using OpenStack, fulfilling common bare metal quota requests within minutes, he said.

“We are looking forward to deploying the Rocky release to take advantage of its numerous enhancements such as BIOS management, which will further streamline how we maintain, manage and deploy our infrastructure,” adds Penick.

Upgrading the OpenStack platform is a bit difficult, but OpenStack Rocky’s Fast Forward Upgrade (FFU) feature can help users to seamlessly complete the upgrading process and get on newer releases of OpenStack faster.

What are your thoughts on OpenStack's latest release? Let us know in the comments.

Staying competitive and resilient in a multi-cloud world ​​​​​​​

Today’s businesses don’t have it easy. They are constantly challenged to stay resilient during a time of unprecedented disruption, change, and unforeseen adversity. That means ensuring critical applications and data are always available, to keep the business ticking along no matter what may be thrown at it.

With cyber attacks on the rise and more employees choosing flexible working practices, that becomes increasingly difficult. Having the right IT infrastructure in place to help face this challenge is vital for business resilience. It is for that reason that businesses are looking at how digital technologies can help transform their operations, practices, working environment and security. 

It’s predicted that worldwide spending on digital transformation technologies is expected to reach nearly $1.3 trillion this year. Adopting new and emerging technologies – from cloud-based applications to online collaborative working – allows organisations to increase productivity, develop new revenue streams and improve communications with internal and external parties. But how can it improve overall business resiliency and ultimately, the business’ bottom line?

This was the topic of discussion at a roundtable event that I recently spoke at. Hosted by the Cloud Industry Forum, the event also included case studies from logistics and aviation business Menzies, and Dell EMC – who both shared their thoughts on how their own technology transformation programmes have been essential for facilitating data processing, supporting global growth and bolstering their overall resilience strategy.  

What are the common challenges?

No business is the same and therefore every organisation faces its own unique challenges. Because of that, they will require tailored solutions when it comes to technology adoption and transformation. A business could have ambitious plans for growth, be transitioning from on-premise infrastructure to Software as a Service (SaaS) or be consolidating public and private cloud systems.  Whatever the case, these competing priorities shouldn’t be achieved at the risk of keeping business resilience front of mind.

Whether you are grappling with legacy technologies or hybrid IT environments, it’s essential that you keep the wheels turning and maintain business as usual.

What’s the right approach?

There’s no simple answer to this question. Every digital transformation project is different and will require a unique approach to execution. There will be roadblocks along the way, but the secret to success is being as flexible and adaptable as possible.

However, despite this, organisations should not negate the importance of having a strategy in place beforehand. This will change, certainly – but establishing an initial plan of attack, and understanding that this will need to be executed in small steps and adapted at each pitstop, is crucial to the success of any rollout. 

Key performance traits  

IT leaders are the chauffeurs in the success of a rollout and can have a transformative effect on projects. Heading up an internal technology change a is a tough job – so what are the characteristics for success?

  • Flexibility: having a solid vision is important – but being willing to listen, learn and adapt in the face of headwinds is imperative.
  • A risk-taker: those with a risk-appetite are often those who come out on top; however, paired with a willingness to embrace risk in the adoption of new technologies, they will need risk-management capabilities – to build their overall resilience.
  • Managing employee expectations: organisations need to be sensitive to the fact that employees may feel their role is threatened by new technologies or are worried they have the right skill set for new digital tools. Our recent research reveals that only 32 percent of employees are kept up to date with the businesses digital roadmap; which shows that businesses really are running the risk of alienating their employees. 

Getting employee buy-in for roll-outs will guarantee project success, so organisations will need to be prepared to address their concerns at every stage.

Transforming for success

For all the hardships organisations face on the route to digital transformation, those showing clarity and focus are the ones that will stay on course and end up on top. Digital initiatives and improvements should be the cornerstone of your resilience strategy and in the long-term will help you respond to the risks that come with the digital age. They can also have a direct positive impact on share price and profitability, placing you ahead of the competition.

It’s clear that constant innovation in an uncertain climate is no easy feat, and the transition process is still very much in process for most organisations across all industries. But, it’s a journey we’re all going on together, and by equipping ourselves and our people for the challenges ahead, we can identify strategic gaps to be addressed to reduce complexity and risk – and accelerate our success.

Why data sovereignty is the only truly safe path to avoid Privacy Shield turmoil

Privacy is not just a legal obligation, it is an ethical commitment and a demonstration that you care about your customers’ privacy as much as they do.

Many people will be surprised to hear that although the EU General Data Protection Regulation (GDPR) took effect on May 25, many companies are not yet GDPR-compliant. The regulation  requires organisations to comply, and our Information Commissioner has signalled that  organisations need to be actively continuing efforts to achieve (and maintain) compliance.

Of course, those organisations that have an ethical commitment to privacy and that wish to demonstrate that they care about their customers’ privacy as much as they do, will be among the cohort that are already compliant. And they will do everything in their power to remain compliant.

Potential fines for violating the GDPR are significant. They include up to four percent of an organisations’ annual profits or €20 million (approximately $23 million) – whichever is greater. The fines are not the only thing to worry about though. The Information Commissioner’s office (ICO) can also revoke an organisations’ right to process data, a sanction that could be crippling. And then there is the reputational damage associated with any data breach. Ethical, customer-centric organisations will be acutely aware of customer opinion and loyalty, and this will be foremost in the minds – far ahead of the actual fines.

The data sovereignty dilemma

A storm on the horizon is the current status of the data sharing framework between the EU and the US called Privacy Shield. This is used by many organisations to demonstrate adequate levels of personal data protection, permitting transfer of such data between the EU and the US.

Privacy Shield was adopted in July 2016 as a replacement to Safe Harbor. In a 2015 decision by the European Court of Justice, Safe Harbor was determined to provide inadequate privacy protection.

The EU and US authorities then quickly introduced Privacy Shield as a replacement legal framework. Under the Privacy Shield certification process, companies must self-certify their commitment to compliance with the Privacy Shield requirements. Oversight has been somewhat more rigorous in the EU, where privacy is seen as a human right, than in the US where there has been minimal commitment to enforcing the framework.

Numerous concerns, including the abuse exposed by the Cambridge Analytica scandal, have led European privacy organisations and agencies to call for the suspension and/or outright revocation of Privacy Shield. Similar concerns and challenges have been levelled against the “Standard Contractual Clauses”, which are another mechanism to ensure the compliant transfer of EU personal data out of the EEA to jurisdictions that the European Commission has not deemed to be “adequate”.

The continuing legal uncertainty about transferring personal data out of the EU has led many global companies, in particular those from the US, to establish data processing and storage capabilities within the EU, and in some cases specifically within the UK.

This enables the global giants to avoid the data transfer issues but does not in itself address concerns about data jurisdiction. Foreign sovereign powers can and do demand access to data if the company holding that data is subject to the foreign jurisdiction. In the absence of any specific agreements between the EU and US about these kinds of data transfers, question marks remain over GDPR compliance, and there are further serious implications for Privacy Shield’s future.

How should ethical, customer-centric organisations respond?

All organisations operating in the EU and holding or processing personal data will need to be actively continuing efforts to achieve (and maintain) GDPR compliance. Those that also transfer data across the Atlantic and currently relying on Privacy Shield to demonstrate adequate data transfer protections, will also need to monitor developments regarding Privacy Shield and consider additional and alternative methods of proving compliance. Those organisations that pride themselves in being particularly ethical and customer-centric may want to take further provisions, such as ensuring data sovereignty for all personal data.

Example: the NHS

Guidance from NHS Digital on the off-shoring and the use of public cloud services states that:

NHS and Social care providers may use cloud computing services for NHS data. Data must only be hosted within the European Economic Area (EEA), a country deemed adequate by the European Commission, or in the US where covered by Privacy Shield.

With the risks of revocation or suspension of Privacy Shield now escalating, reliance on Privacy Shield alone is inadvisable. Trusts could consider the use of the EU Standard Contractual Clauses, although these are also being challenged in the European courts, or prepare for whatever other methods are approved by the EU regulatory authorities following the Privacy Shield review. A more certain (risk-free) course of action would be to opt for complete data sovereignty for patient data by retaining the data in the UK and using a UK-based service provider for these workloads.

Firms that operate in the US are subject to US law, including FISA and the CLOUD Act, neither of which will easily be incorporated into the next version of Privacy Shield. While they can offer a level of data residency (offering to keep your data in the UK), the CLOUD Act eliminates protection for data stored overseas, and provides them with no legal recourse to withhold data from the NSA and other US law enforcement bodies, meaning that they cannot guarantee data sovereignty.

Recent research by the Corsham Institute highlighted increasing patient awareness of data privacy issues with a growing public desire for more information on data storage in the NHS. 88% of adults said that it is important to know where and how their patient data is stored and 80% said that it is important to know whether patient data is hosted by companies whose headquarters are outside of the UK.

While public confidence in the NHS is currently high, the significant increase in privacy awareness means that there’s a real risk that any incidents, such as a repeat of the Wannacry malware, could expose weaknesses in sovereignty, efficiency and data security, leading to a potential patient backlash. Further details of the Corsham Institute research can be found here.

With many Trusts already opting to ensure data sovereignty by placing patient data and workloads with UK-based cloud service providers, there is no reason that other Trusts should not follow suit. After all there is no real need to move patient data offshore or to use foreign service providers. Nor the need for trusts to expose themselves to risks relating to the potential revocation or suspension of Privacy Shield and no real need to expose themselves to a potential patient backlash in the event of future incidents.

Other customer-centric organisations might also be wise to follow the example of these Trusts and accelerate their move to the cloud in order to enhance operational efficiency, but do so without neglecting data sovereignty.

More organisations moving from proof of concept to initial SD-WAN projects

One in five global companies has implemented an initial software-defined wide area networking (SD-WAN) project, while many more are at the proof of concept stage.

This is according to survey results from Teneo, an ‘as a service’ technology provider. The study, conducted alongside Sapio Research and which polled 200 senior IT and networking managers in the US and UK, found that increasing pressure on company resources and budgets is making companies examine the potential of SD-WAN, with increasing network complexity also cited.

More than a third of organisations’ IT budget is spent with upkeep tasks, according to the report, with another third adding they were using ‘as a service’ models to keep on top of maintenance. What’s more, companies are ‘shrewdly blending connectivity options’ to help beef up their network performance, with 38% of respondents wanting more MPLS, 22% wanting more Internet connectivity, and 20% wanting Internet and MPLS combined.

SD-WAN is being seen as a viable option therefore. 39% of companies polled said they were looking at global networking vendors for their implementations, while 24% are looking at telecoms providers and management consultancies respectively. Only 8% of those polled said they were looking for a specialist SD-WAN vendor.

“Network managers are looking at SD-WAN strategies to run multiple networking environments in standardised ways – whether the underlying motivation is greater simplicity, cost efficiency or transforming critical applications’ performance across their company’s operations,” said Marc Sollars, CTO of Teneo.

“Many firms are clearly putting a toe in the water on SD-WAN, or doing a proof of concept, but it’s still very hard to say when this test phase will start to translate into enterprise-level implementations,” added Sollars. “In many ways, the broad range of choice that SD-WAN brings is what’s causing companies to hesitate over their decisions.”

According to a study from IDC earlier this month, the overall SD-WAN infrastructure market will be worth $4.5 billion by 2022, describing it as ‘one of the fastest industry transformations seen in years.’