IBM’s 2018 data breach study shows why we’re in a Zero Trust world now

  • Digital businesses that lost less than 1% of their customers due to a data breach incurred a cost of $2.8M, and if 4% or more were lost the cost soared to $6M.
  • U.S. based breaches are the most expensive globally, costing on average $7.91M with the highest global notification cost as well, $740,000.
  • A typical data breach costs a company $3.86M, up 6.4% from $3.62M last year.
  • Digital businesses that have security automation can minimize the costs of breaches by $1.55M versus those businesses who are not ($2.88M versus $4.43M).
  • 48% of all breaches are initiated by malicious or criminal attacks.
  • Mean-time-to-identify (MTTI) a breach is 197 days, and the mean-time-to-contain (MTTC) is 69 days.

These and many other insights into the escalating costs of security breaches are from the 2018 Cost of a Data Breach Study sponsored by IBM Security with research independently conducted by Ponemon Institute LLC. The report is downloadable here (PDF, 47 pp. no opt-in).

The study is based on interviews with more than 2,200 compliance, data protection and IT professionals from 477 companies located in 15 countries and regions globally who have experienced a data breach in the last 12 months. This is the first year the use of Internet of Things (IoT) technologies and security automation are included in the study. The study also defines mega breaches as those involving over 1 million records and costing $40M or more. Please see pages 5, 6 and 7 of the study for specifics on the methodology.

The report is a quick read and the data provided is fascinating. One can’t help but reflect on how legacy security technologies designed to protect digital businesses decades ago isn’t keeping up with the scale, speed and sophistication of today’s breach attempts. The most common threat surface attacked is compromised privileged credential access. 81% of all breaches exploit identity according to an excellent study from Centrify and Dow Jones Customer Intelligence, CEO Disconnect is Weakening Cybersecurity (31 pp, PDF, opt-in).

The bottom line from the IBM, Centrify and many other studies is that we’re in a Zero Trust Security (ZTS) world now and the sooner a digital business can excel at it, the more protected they will be from security threats. ZTS begins with Next-Gen Access (NGA) by recognizing that every employee’s identity is the new security perimeter for any digital business.

Key takeaways from the study include the following:

US-based breaches are the most expensive globally, costing on average $7.91m, more than double the global average of $3.86m

Nations in the Middle East have the second-most expensive breaches globally, averaging $5.31M, followed by Canada, where the average breach costs a digital business $4.74M. Globally a breach costs a digital business $3.86M this year, up from $3.62M last year. With the costs of breaches escalating so quickly and the cost of a breach in the U.S. leading all nations and outdistancing the global average 2X, it’s time for more digital businesses to consider a Zero Trust Security strategy. See Forrester Principal Analyst Chase Cunningham’s recent blog post What ZTX Means For Vendors And Users, from the Forrester Research blog for where to get started.

The number of breached records is soaring in the US, the third leading nation of breached records, 6,850 records above the global average

The Ponemon Institute found that the average size of a data breach increased 2.2% this year, with the U.S. leading all nations in breached records. It now takes an average of 266 days to identify and contain a breach (Mean-time-to-identify (MTTI) a breach is 197 days and the mean-time-to-contain (MTTC) is 69 days), so more digital businesses in the Middle East, India, and the U.S. should consider reorienting their security strategies to a Zero Trust Security Model.

French and US digital businesses pay a heavy price in customer churn when a breach happens, among the highest in the world 

The following graphic compares abnormally high customer churn rates, the size of the data breach, average total cost, and per capita costs by country.

US companies lead the world in lost business caused by a security breach with $4.2m lost per incident, over $2m more than digital businesses from the Middle East

Ponemon found that U.S. digitally-based businesses pay an exceptionally high cost for customer churn caused by a data breaches. Factors contributing to the high cost of lost business include abnormally high turnover of customers, the high costs of acquiring new customers in the U.S., loss of brand reputation and goodwill. U.S. customers also have a myriad of competitive options and their loyalty is more difficult to preserve. The study finds that thanks to current notification laws, customers have a greater awareness of data breaches and have higher expectations regarding how the companies they are loyal to will protect customer records and data.

Conclusion

The IBM study foreshadows an increasing level of speed, scale, and sophistication when it comes to how breaches are orchestrated. With the average breach globally costing $4.36M and breach costs and lost customer revenue soaring in the U.S,. it’s clear we’re living in a world where Zero Trust should be the new mandate.

Zero Trust Security starts with Next-Gen Access to secure every endpoint and attack surface a digital business relies on for daily operations, and limit access and privilege to protect the “keys to the kingdom,” which gives hackers the most leverage. Security software providers including Centrify are applying advanced analytics and machine learning to thwart breaches and many other forms of attacks that seek to exploit weak credentials and too much privilege. Zero Trust is a proven way to stay at parity or ahead of escalating threats.

Samsung Heavy Industries chooses AWS to help take shipbuilding into the cloud

Another example of cloud computing infiltrating key enterprises; shipbuilding firm Samsung Heavy Industries is moving to Amazon Web Services (AWS) as its preferred cloud provider.

The company says it wants to be seen as a ‘cloud-first maritime business’, with Samsung using a variety of AWS’ services. These include EC2 and S3, naturally, alongside Amazon’s relational database, RDS, AWS Key Management, and governance and compliance tool CloudTrail.

By putting sensors in a variety of devices and crunching the data the systems generate, all backed up by cloud technologies, organisations in the shipping and maritime sector can make significant changes in efficiency and productivity. Take the Port of Rotterdam as an example. In February the port, Europe’s largest by cargo tonnage, said it was signing up with IBM to provider greater insights on water and weather conditions, as well as manage traffic and reduce waiting times at the port.

“We’re digitising our shipping fleet by using the most advanced technologies in the world to enhance our approaches to shipbuilding, operations, and delivery, and chose AWS as our preferred cloud provider to help us quickly transform Samsung Heavy Industries into a cloud-first maritime business,” said Dongyeon Lee, Samsung Heavy Industries director of ship and offshore performance research centre.

“By leveraging AWS, we’ve successfully released several smart shipping systems so that our customers can manage their ships and fleets more efficiently, and we continue to test new capabilities for ocean-bound vessel navigation and automation,” added Lee. “AWS delivers a highly flexible environment, with the broadest and deepest portfolio of cloud services, that is ideal for accelerating research and development across the company, and it has enabled our developers and data scientists to bring new ideas to market at an unprecedented pace.”

AWS, whose revenues went up 49% year over year to $6.1 billion, according to the most recent quarter’s financial report, has been issuing a flurry of recent customer wins. Alongside Samsung, Formula 1, Ryanair, and Major League Baseball were all confirmed as AWS users over the past three months.

Sponsorship Opportunities at @EXPOFinTech NY Opens | #FinTech #Blockchain #Hyperledger #IoT #SmartCities #DigitalTransformation

FinTech Is Now Part of the CloudEXPO New York Program. Financial enterprises in New York City, London, Singapore, and other world financial capitals are embracing a new generation of smart, automated FinTech that eliminates many cumbersome, slow, and expensive intermediate processes from their businesses. Accordingly, attendees at the upcoming 22nd CloudEXPO | DXWorldEXPO November 12-13, 2018 in New York City will find fresh new content in two new tracks called: FinTechEXPO New York Blockchain Event which will incorporate FinTech and Blockchain, as well as machine learning, artificial intelligence and deep learning in these two distinct tracks. FinTech brings efficiency as well as the ability to deliver new services and a much improved customer experience throughout the global financial services industry. FinTech is a natural fit with cloud computing, as new services are quickly developed, deployed, and scaled on public, private, and hybrid clouds. More than US$20 billion in venture capital is being invested in FinTech this year. We’re pleased to bring you the latest FinTech developments as an integral part of our program.

read more

Oracle marks ‘major milestone’ in autonomous strategy as Ellison takes more swipes at AWS

Oracle’s CTO and executive chairman Larry Ellison announced the launch of the company’s latest autonomous database service around transaction processing (ATP) last night – but a recent report around claims by Amazon also caught his eye.

At an event in California, Ellison responded to a story, originally broken by CNBC, which claimed that Amazon was planning to move completely away from Oracle’s databases by 2020.

Responding to an analyst question around customers moving off Oracle on the company’s Q218 earnings call back in December, Ellison said: “Let me tell you who’s not moving off of Oracle – a company you’ve heard of that gave us another $50 million this quarter. That company is Amazon. Our competitors, who have no reason to like us very much, continue to invest in and run their entire business on Oracle.”

Ellison reiterated the $50m price and told attendees of his doubt that Amazon would reach its reported target. “They don’t like being our best reference,” he said. “They think of themselves as a competitor, so it’s kind of embarrassing when Amazon uses Oracle, but they want you to use Aurora and Redshift.”

Aurora and Redshift, of course, are Amazon’s primary database products around relational database and data warehousing respectively. Ellison also took the opportunity to tout Oracle’s greater performance when compared to its rival (below) – 12 times faster than Aurora for its autonomous transaction processing database for pure transaction processing, and more than 100 times faster for a mixed workload.

Oracle’s press materials accompanying the ATP release described it as ‘a major milestone in the company’s autonomous strategy’, and Ellison did not hold back in his praise of a technology he described as ‘revolutionary’ at last year’s OpenWorld.

“This machine learning-based technology not only can optimise itself for queries, for data warehouses and data marts, but it also optimises itself for transactions,” said Ellison. “It can run batch programs, reporting, Internet of Things, simple transactions, complex transactions, and mixed workloads. Between these two systems [for data warehousing and transaction processing], the Oracle autonomous database now handles all of your workloads.”

Another barb at Amazon – and it’s worth noting that Andy Jassy is not averse to firing shots back during his keynote speeches – came when Ellison described Oracle’s autonomous database as ‘truly elastic’. It was truly pay as you go, with automatic provisioning and scaling, adding and deleting servers while running, and being serverless when not running.

“Amazon’s databases can’t do that,” he told the audience. “They can’t dynamically add a server when the system is running, they can’t dynamically add network capacity, they can’t dynamically take a server away when there is not demand and it’s not serverless when it’s idle. [Oracle] is a truly elastic system – you only pay for the infrastructure that you use.”

Ellison added that full autonomy – ‘nothing to learn, nothing to do’ became something of a mantra during the presentation – meant Oracle was “as simple to use as the simplest databases on the planet.”

CloudTech has reached out to AWS for comment and will update this piece accordingly.

Picture credits: Oracle/Screenshot

Hammering home public cloud shared security obligations: The importance of education

Public cloud customers need to become clearer on what their responsibility is for securing their data and applications hosted by public cloud providers. I believe there is a misunderstanding on how much responsibility the likes of AWS, Azure, and Google Cloud Platform have for securing their customers. Their platforms are definitely secure and migrating workloads into the cloud can be much more secure than on premise data centers, however organisations do have a responsibility in securing their workloads applications, and operating systems.

Even though every customer’s journey to the cloud is unique, and there are different levels of understanding this model, I hear some very common questions repeatedly. “Why do I need to put my own security in the cloud? I thought it was already secure?” “Why can’t I just move my virtual security appliances in the cloud?” “What does this mean for my network firewall? How do I ensure connectivity and access for my employees?” “How do I secure a cloud application? Aren’t Office 365 and Salesforce already secure?”

If you find yourself asking questions like this, you may want to talk with an experienced partner to help with your migration. Until then, here are some considerations that can help clear things up.

Shared responsibility

The public cloud operates on a shared responsibility model. This means that the cloud providers give you the responsibility and flexibility to secure what you bring to the cloud. Therefore, without question, as a customer your responsibility is to configure, patch and layer security on applications, workloads and operating systems you spin up. Configuration includes identity management, access levels, and security groups. Customers are also responsible for data protection and availability of workloads.

Public cloud providers are only responsible for the physical security, global and regional connectivity, and power and cooling of the data centers that they own.

This model maintains the highest possible efficiencies for the cloud provider, and relieves the customer of the burden of providing the infrastructure such as a data centre or the server hardware that provides scalability on demand.

The model also enables customers to customise their cloud security to meet the needs of their unique workloads. Application and data security are in the hands of the people who know them best, rather than being left to a public cloud provider to provide a cookie cutter protocol.

Public cloud providers work with vendors to ensure that the solutions available will operate properly on their platforms. AWS, Azure, and GCP partnership programs ensure that vendors have access to tools and specifications needed to design their products for optimum performance on each platform. Once the vendor's products have met the standards set by the provider, a certification or competency is awarded. This shows customers that the solution is part of the fabric of the public cloud.

The public cloud fabric

When we talk about the public cloud fabric, we are talking about native integration into the platform. Consider this: the model for shared security means that the cloud provider owns the infrastructure for security. All aspects to visibility, monitoring, remediation, and protection, are all substantiated in the public cloud through APIs and tools like CloudWatch and Insights. These are the things that constitute the fabric of the public cloud.

Native integration into a cloud platform requires that a solution be built on a cloud-centric architecture and engineered specifically for that public cloud. While it may be tempting to use a virtualised version of your on-premises security in the cloud, these VMs simply aren't designed to take advantage of what you're buying.

They may seem to work, but they lack certain functionality. Some common questions I hear are: can the VM auto-scale for performance and capacity? Can it be provisioned and deployed within minutes, on either AWS or Azure? Does it offer pay as you go, metered billing, and other flexible consumption models? Is it built on a cloud-centric architecture?

These are the features that will distinguish an on-premises solution from a 'cloud ready' solution. To take full advantage of what the cloud has to offer, you will need to have a solution that is part of the cloud fabric.

The numbers don’t lie

My belief that many organisations misunderstand this shared responsibility model is supported by recent research of the public cloud customer market. In a recent study conducted by research firm Vanson Bourne, Public Cloud – Benefits, Strategies, Challenges, and Solutions, 77 percent of organisations reported the belief that public cloud providers are responsible for securing customer data in the cloud. 68 percent of decision makers are under the impression that cloud providers are responsible for securing customer applications as well. More concerning in this study is that a nearly a third (30 percent) of organisations have not added additional security layers to their public cloud deployments.

More secure than on premise

Many organisations realise that their cloud deployments can be inherently more secure than on premise deployments because cloud providers are collectively investing more into security controls than they could on their own. However, the organisations benefiting the most from public cloud are those that understand that their public cloud provider is not responsible for securing data or applications and are augmenting security with support from third party vendors.

Google Cloud secures support for NVIDIA’s Tesla P4 GPUs with more machine learning goodness

Google has announced its support for NVIDIA’s Tesla P4 GPUs to help customers with graphics-intensive and machine learning applications.

The Tesla P4, according to NVIDIA’s data sheet, is ‘purpose-built to boost efficiency for scale-out servers running deep learning workloads, enabling smart responsive AI-based services.’ The P4, which is run on NVIDIA’s Pascal architecture, has a GPU memory of 8GB, and memory bandwidth of 192 GB per second.

While not at the same performance level as the V100, run on Volta instead of Pascal architecture, Google said the P4 accelerators, which are now in beta, represent a ‘good balance of price/performance for remote display applications and real-time machine learning inference.’

“Graphics-intensive applications that run in the cloud benefit greatly from workstation-class GPUs,” wrote Ari Liberman, Google Cloud product manager in a blog post. “We now support virtual workstations with NVIDIA GRID on the P4 and P100, allowing you to turn any instance with one or more GPUs into a high-end workstation optimised for graphics-accelerated use cases.

“Now, artists, architects and engineers can create breathtaking 3D scenes for their next blockbuster film, or design a computer-aided photorealistic composition,” Liberman added.

As is often the case with these announcements, a brand new, shiny customer was rolled out to explain how Google’s services had improved their operations. Except this one wasn’t quite as new; regular readers of this publication may remember oilfield services provider Schlumberger from Google’s GPU price reduction news back in November. The company said it was using Google’s workstations, powered by NVIDIA GPUs, to help visualise oil and gas scenarios for its customers.

The link with machine learning capabilities is again an irresistible one, with Google saying the P4 is ideal for use cases such as visual search, interactive speech, and video recommendations.

Whither NVIDIA, however? The big cloud providers are certainly a key opportunity for the graphics processor. Speaking at the end of last year, the company said its V100 GPU had been chosen by every major cloud firm, saying the applications for GPU servers had ‘now grown to many markets.’

Why Is My Mac Running Slow? 5 Quick Tips to Speed Up Your Mac!

Trying to figure out why your precious Mac® is running slow and want to learn how to make it run faster? Mac troubleshooting can lead you down a rabbit hole of problem-solving that takes hours to diagnose and even days to resolve. We’re here to help address the top five issues that cause Mac performance […]

The post Why Is My Mac Running Slow? 5 Quick Tips to Speed Up Your Mac! appeared first on Parallels Blog.

Registration for @UltanKinahan Session at @CloudEXPO NY Opens | @MSCloud @Azure #Cloud #DigitalTransformation

Provide an overview of the capabilities of Azure Stack allowing you or your customers to adopt truly consistent Hybrid Cloud capabilities to deliver greater productivity in your cloud world. Ultan Kinahan is on a member of the Global Black Belt team at Microsoft with a focus on Azure Stack Hybrid Cloud. Ultan has been in the Azure team since the beginning, Has held roles in Engineering, Sales and now consults with both small to medium size business and the worlds largest organizations on how to incorporate Hybrid into their own digital transformations.

read more

Sponsorships Open at @DevOpsSUMMIT NY and CA | #CloudNative #Serverless #DevOps #APM #Monitoring #Docker #Kubernetes

DevOpsSUMMIT at CloudEXPO will expand the DevOps community, enable a wide sharing of knowledge, and educate delegates and technology providers alike. Recent research has shown that DevOps dramatically reduces development time, the amount of enterprise IT professionals put out fires, and support time generally. Time spent on infrastructure development is significantly increased, and DevOps practitioners report more software releases and higher quality. Sponsors of DevOpsSUMMIT at CloudEXPO will benefit from unmatched branding, profile building and lead generation opportunities.

read more

Google and Alibaba focus on Southeast Asia in latest infrastructure expansion

The largest players in cloud computing are looking to Asia for further expansion – Google has announced it is building a new data centre in Singapore, while Alibaba Cloud has announced a second infrastructure zone in Malaysia.

Google’s expansion will take the company up to three data centres in Singapore, taking its overall investment in the country to $850 million. The facilities will also be built in line with Google’s environmental policy; back in April the company announced it had achieved its long-standing goal of becoming 100% renewable.

According to Google’s location map, the company now operates 61 open and provisional zones across 20 regions and five continents. Singapore is joined in Asia Pacific by Japan – an open facility in Tokyo and a future region in Osaka – Mumbai, Taiwan, Sydney, and another future facility in Hong Kong. “We’re looking forward to growing our small team at the data centres here, as well as expanding our ties with the local community,” wrote Joe Kava, VP data centres in a blog post.

Alibaba, meanwhile, is launching a second availability zone in Malaysia to expand its cloud footprint in the country. Among the new products to arrive are DDoS protection, as well as elastic computing, database, networking and monitoring services. In line with Alibaba’s recent partnership with SAP, the zone will also be certified for SAP hosting.

“The success of our trade on a global platform with assistance of companies like Alibaba Cloud depends on an efficient Internet environment,” said Gobind Singh Deo, Malaysia minister of communications and multimedia. “The advanced technology afforded by Alibaba Cloud opens new opportunities, which I believe will quite substantially benefit Malaysia in its efforts to raise competition and efficiency in this new industry.”

There is a major audience for cloud technologies in Southeast Asia – indeed, Google said that in three years more than 70 million people had gotten online for the first time. This has been reflected in recent industry research into the area.

According to the most recent study from the Asia Cloud Computing Association (ACCA), out of 14 Asia Pacific countries, Singapore was considered the most ‘cloud ready’. The country was praised for its broadband quality, cybersecurity and levels of business sophistication. Malaysia was ranked at #8, noting the government’s cloud-first strategy as a potential indicator of future success.