10 charts that will change your perspective of big data’s growth

  • Worldwide big data market revenues for software and services are projected to increase from $42bn in 2018 to $103bn in 2027, attaining a Compound Annual Growth Rate (CAGR) of 10.48% according to Wikibon
  • Forrester predicts the global big data software market will be worth $31bn this year, growing 14% from the previous year. The entire global software market is forecast to be worth $628bn in revenue, with $302bn from applications
  • According to an Accenture study, 79% of enterprise executives agree that companies that do not embrace big data will lose their competitive position and could face extinction. Even more, 83%, have pursued big data projects to seize a competitive edge
  • 59% of executives say big data at their company would be improved through the use of AI according to PwC

Sales and marketing, research & development (R&D), supply chain management (SCM) including distribution, workplace management and operations are where advanced analytics including big data are making the greatest contributions to revenue growth today. McKinsey Analytics’ study Analytics Comes of Age, published in January 2018 (PDF, 100 pp., no opt-in) is a comprehensive overview of how analytics technologies and big data are enabling entirely new ecosystems, serving as a foundational technology for artificial intelligence (AI).

McKinsey finds that analytics and big data are making the most valuable contributions in the basic materials and high tech industries. The first chart in the following series of ten is from the McKinsey Analytics study, highlighting how analytics and big data are revolutionizing many of the foundational business processes of sales and marketing.

The following ten charts provide insights into big data’s growth:

Nearly 50% of respondents to a recent McKinsey Analytics survey say analytics and Big Data have fundamentally changed business practices in their sales and marketing functions

Also, more than 30% say the same about R&D across industries, with respondents in High Tech and Basic Materials & Energy report the greatest number of functions being transformed by analytics and big data. Source: Analytics Comes of Age, published in January 2018 (PDF, 100 pp., no opt-in).

Worldwide big data market revenues for software and services are projected to increase from $42bn in 2018 to $103bn in 2027, attaining a Compound Annual Growth Rate (CAGR) of 10.48%

As part of this forecast, Wikibon estimates the worldwide big data market is growing at an 11.4% CAGR between 2017 and 2027, growing from $35bn to $103bn. Source: Wikibon and reported by Statista.

According to NewVantage Venture Partners, big data is delivering the most value to enterprises by decreasing expenses (49.2%) and creating new avenues for innovation and disruption (44.3%)

Discovering new opportunities to reduce costs by combining advanced analytics and big data delivers the most measurable results, further leading to this category being the most prevalent in the study. 69.4% have started using big data to create a data-driven culture, with 27.9% reporting results. Source: NewVantage Venture Partners, Big Data Executive Survey 2017 (PDF, 16 pp.)

The Hadoop and big data markets are projected to grow from $17.1bn in 2017 to $99.31bn in 2022 attaining a 28.5% CAGR

The greatest period of projected growth is in 2021 and 2022 when the market is projected to jump $30bn in value in one year. Source: StrategyMRC and reported by Statista.

Big data applications and analytics is projected to grow from $5.3bn in 2018 to $19.4bn in 2026, attaining a CAGR of 15.49%

Big data market worldwide includes Professional Services is projected to grow from $16.5B in 2018 to $21.3B in 2026. Source: Wikibon and reported by Statista.

Comparing the worldwide demand for advanced analytics and big data-related hardware, services and software, the latter category’s dominance becomes clear

The software segment is projected to increase the fastest of all categories, increasing from $14B in 2018 to $46B in 2027 attaining a CAGR of 12.6%. Sources: WikibonSiliconANGLE; Statista estimates and reported by Statista.

Advanced analytics and big data revenue in China are projected to be worth ¥57.8bn ($9bn) by 2020

The Chinese market is predicted to be one of the fastest growing globally, growing at a CAGR of 31.72% in the forecast period. Sources: Social Sciences Academic Press (China) and Statista.

Non-relational analytic data stores are projected to be the fastest growing technology category in big datagrowing at a CAGR of 38.6% between 2015 and 2020

Cognitive software platforms (23.3% CAGR) and Content Analytics (17.3%) round out the top three fastest growing technologies between 2015 and 2020. Source: Statista.

A decentralized general-merchandise retailer that used big data to create performance group clusters saw sales grow 3% to 4%

Big data is the catalyst of a retailing industry makeover, bringing greater precision to localization than has been possible before. Big data is being used today to increase the ROI of endcap promotions, optimize planograms, help to improve upsell and cross-sell sales performance and optimize prices on items that drive the greatest amount of foot traffic. Source: Use Big Data to Give Local Shoppers What They Want, Boston Consulting Group, February 8, 2018.

84% of enterprises have launched advanced analytics and big data initiatives to bring greater accuracy and accelerate their decision-making

Big data initiatives focused on this area also have the greatest success rate (69%) according to the most recent NewVantage Venture Partners Survey. Over a third of enterprises, 36%, say this area is their top priority for advanced analytics and Big Data investment. Sources: NewVantage Venture Partners Survey and Statista.

Additional big data information sources

4 Pain Points of Big Data and how to solve them, Digital McKinsey via Medium, November 10, 2017

53% Of Companies Are Adopting Big Data Analytics, Forbes, December 24, 2017

6 Predictions For The $203 Billion Big Data Analytics Market, Forbes, Gil Press, January 20, 2017

Analytics Comes of Age, McKinsey Analytics, January 2018 (PDF, 100 pp.)

Big Data & Analytics Is The Most Wanted Expertise By 75% Of IoT Providers, Forbes, August 21, 2017

Big Data 2017 – Market Statistics, Use Cases, and Trends, Calsoft (36 pp., PDF)

Big Data and Business Analytics Revenues Forecast to Reach $150.8 Billion This Year, Led by Banking and Manufacturing Investments, According to IDC, March 14, 2017

Big Data Executive Survey 2018, Data and Innovation – How Big Data and AI are Driving Business Innovation, NewVantage Venture Partners, January 2018 (PDF, 18 pp.)

Big Data Tech Hadoop and Spark Get Slow Start in Enterprise, Information Week, March 20, 2018

Big Success With Big Data, Accenture  (PDF, 12 pp.)

Gartner Survey Shows Organizations Are Slow to Advance in Data and Analytics, Gartner, February 5, 2018

How Big Data and AI Are Driving Business Innovation in 2018, MIT Sloan Management Review, February 5, 2018

IDC forecasts big growth for Big Data, Analytics Magazine. April 2018

IDC Worldwide Big Data Technology and Services 2012 – 2015 Forecast, Courtesy of EC Europa (PDF, 34 pp.)

Midyear Global Tech Market Outlook For 2017 To 2018, Forrester, September 25, 2017 (client access reqd.)

Oracle Industry Analyst Reports – Data-rich website of industry analyst reports

Ten Ways Big Data Is Revolutionizing Marketing And Sales, Forbes, May 9, 2016

The Big Data Payoff: Turning Big Data into Business Value, CAP Gemini & Informatica Study, (PDF, 12 pp.)

The Forrester Wave™: Enterprise BI Platforms With Majority Cloud Deployments, Q3 2017 courtesy of Oracle

Haley Fung Joins @DevOpsSUMMIT NY Faculty | @IBMDevOps #Serverless #DevOps #APM #Monitoring #ContinupusDelivery

DevOps with IBMz? You heard right. Maybe you’re wondering what a developer can do to speed up the entire development cycle–coding, testing, source code management, and deployment-? In this session you will learn about how to integrate z application assets into a DevOps pipeline using familiar tools like Jenkins and UrbanCode Deploy, plus z/OSMF workflows, all of which can increase deployment speeds while simultaneously improving reliability. You will also learn how to provision mainframe system as cloud-like service.

read more

Blockchain/Crypto Bubble: Dot-Com Bubble All Over Again? | @CloudEXPO #FinTech #Blockchain #Bitcoin

Today, the entire blockchain/cryptocurrency hairball is itself in a massive bubble. Rather than speculation in cryptos driving the market over the cliff, however, it’s speculative interest in initial coin offerings (ICOs).

This is no mere currency play. Deep pockets with more money than sense are betting on an entire market full of startups, largely because of FOMO – ‘fear of missing out.’

All this hullabaloo is giving me a serious case of déjà vu. I’ve lived through such a bubble before – the dot-com bubble of the turn of the century.

Unlike most of the blockchain/crypto players out there who were children at the time, I saw the craziness of the dot-com runup and bust from the inside. Similarities to the current bubble abound.

Lest we make the mistakes of the past, however, it’s also important to point out the differences. In truth, the two bubbles only have superficial similarities. We can only gain wisdom by understanding both how they are alike – and how they are different.

read more

Designing new cloud architectures: Exploring CI/CD – from data centre to cloud

Today, most companies are using continuous integration and delivery (CI/CD) in one form or another – and this is of significance due to various reasons:

  • It increases the quality of the code base and the testing of that code base
  • It greatly increases team collaboration
  • It reduces the time in which new features reach the production environment
  • It reduces the number of bugs that in turn reach the production environment

Granted, these reasons apply if – and only if – CI/CD is applied with more than 70% correctness. Although there is no single perfect way of doing CI/CD, there are best practices to follow, as well as caveats to avoid in order to prevent unwanted scenarios.

Some of the problems that might arise as a consequence include: the build being broken frequently; the velocity in which new features are pushed creating havoc in the testing teams or even in the client acceptance team; features being pushed to production without proper or sufficient testing; the difficulty in tracking and even the separation of big releases; old school engineers struggling to adapt to the style.

IaaC

A few years ago, the thinking model indicated that CI/CD was only useful for the product itself; that it will only affect the development team and that operation teams were only there to support the development lifecycle. This development-centric approach suddenly came to an end when different technologies appeared, spellbinding the IT market completely. These technologies I am making reference to are those that allow to create infrastructure as code.

CI/CD is no longer exclusive to development teams. Its umbrella has expanded throughout the entirety of engineering teams, software engineers, infrastructure, network, systems engineers, and so forth.

DevOps

Nobody knows what DevOps really is, but if you are not doing, using, breathing, dreaming – being? – DevOps, you’re doing it wrong. All teasing aside, with the advent of DevOps, the gap that existed between development teams and operation teams has become closer, to the extent of some companies mixing the teams. Even so, some of those took a different approach and have multidisciplinary teams where engineers work on the product throughout the lifecycle, coding, testing and deploying – including on occasion security teams as well, now called DevOpsSec.

As the DevOps movement becomes more popular, CI/CD does as well, since it is a major component. Not doing CI/CD means not doing DevOps.

From data centre to cloud

After reducing some terms and concepts, it is clear why CI/CD is so important. Since architectures and abstraction levels change when migrating a product from data centre into the cloud, it has become necessary to evaluate what is needed in the new ecosystem for two reasons:

  • To take advantage of what the cloud has to offer, in terms of the new paradigm and the plethora of options
  • To avoid making the mistake of treating the cloud as a data centre and building everything from scratch

Necessary considerations

The CI/CD implementation to use in the cloud must fulfil the majority of the following:

  • Provided as a service: The cloud is XaaS-centric, and avoiding building things from scratch is a must. In the case of building from scratch, if it is a non in-house component, nor a value-added product feature, I would suggest a review of the architecture in addition to a logical business justification
  • Easy to get in, easy to get out: A non-complicated process of in-out means that the inner workings of the implementation are likely to be non-complicated as well. Also, in case it does not work as expected, an easy way out is always a necessity
  • Portable configuration: This is a nice to have, in order to avoid reinventing the wheel and learning a given implementation details in-depth, it is easier to move from one system to another. Typical configurations are compatible with YAML or JSON formats – however many providers allow the use of familiar language such as Python, Java or JavaScript in order to fit the customer
  • Integration with VCS as a service: This is practically a given. As an example, Bitbucket provides pipelines within a repository. AWS does it differently with CodeCommit, which provides Git repositories as a service within. Different cloud providers will employ different ways and some will integrate with external repositories as well
  • Artifact store: It depends on the type of application, but having an artefact store to store the output of the build is often a good idea. Once the delivery part is done, deploying to production is significantly easier if everything is packaged neatly
  • Statistics and metric visualisation: This is in terms of what is occurring throughout the entire pipeline, which tests are failing, which features are ready, which pipeline is having problems, analogously for the code base, and not to mention the staging/testing/UAT or similar systems prior to production
  • No hidden fees: Although the technological part is important, the financial and economic part will be so too. In cloud, the majority of things turn to OpEx, and things that are running and unused can impact greatly. In terms of pipelines, it is important to focus on the cost of build minutes per month, the cost storage of GB for VCS and artefact store, the cost per parallel pipeline, the cost of the testing infrastructure used for the given purpose, among other things. Being fully aware of minutiae and reading the fine print pays off
  • Alerts and notifications: Mainly in case of failure, but also setting minimum and maximum thresholds for number of commits, for example, can yield substantial information; no-one committing frequently to the code base may mean breaking the DevOps chain
  • Test environments easy to create/destroy: The less manual integration, the better. This needs to be automated and integrated
  • Easy ‘delivery to deployment’ integration: The signoff after the delivery stage will be a manual step, but only to afterwards trigger a set of automated steps. Long gone are the days in which an operator ran a code upgrade manually
  • Fast, error-free rollback: When problems arise after a deployment, the rollback must be easy, fast and, above all, automatic or at least semi-automatic. Human intervention at this stage is a recipe for disaster
  • Branched testing: Having a single pipeline and only performing CI/CD on the master branch is an unpopular idea – not to mention that if that is the case, breaking the build would mean affecting everyone else’s job
  • Extensive testing suite: This may not be necessarily cloud-only, but it is of significance. At minimum, four of the following must exist: unit testing, integration testing, acceptance, smoke, capacity, performance, UI/UX
  • Build environment as a service: Some cloud providers allow for virtualised environments; Bitbucket pipelines allow for integration with Docker and Docker Hub for the build environment

Monitoring, metrics, and continuous tracking of the production environment

The show is not over once deployment happens. It is at that moment, and after, when it is critical to keep track of what is occurring. Any glitch or problem can potentially snowball into an outage; thus it is important to extract as many metrics as possible and monitor as many sensors as possible without loosing track of the important things. By this, I mean establishing priorities to avoid generating chaos between engineers on-call and at desk.

Most cloud providers will provide an XaaS for monitoring, metrics, logs and alerts, plus integration with other external systems. For instance, AWS provides CloudWatch that, in turn, provides everything as a service and integrated. Google Cloud provides Stackdriver, a similar service; Microsoft has a slightly more basic service in Azure Monitor. Another giant, Alibaba, provides Cloud Monitor at a similar level as the competition. Needless to say, every major cloud provides this as a service in one level or another.

This is an essential component and must not go unnoticed – I cannot emphasise this enough. Even if the cloud does not provide a service, it must provide integration with other monitoring services from other cloud-oriented service providers, such as Dynatrace, which integrates with the most popular enterprise cloud providers.

Conclusion

CI/CD is a major component of the technology process. It can make or break your product in the cloud, and in the data centre; however, evaluating the list above when designing a new cloud architecture can save time, money and effort on a significant level.

When designing a cloud architecture, it is fundamentally important to avoid copying the current architecture, and focus the design as if the application is a cloud native application, thinking that it was born to perform in the cloud together with the entire lifecycle. As I have mentioned previously, once a first architecture is proposed and initially peer reviewed, then a list of important caveats must be brought to attention before moving onto a more solid version of the architecture.

As a final comment, doing CI/CD halfway is better than not doing it at all. Some engineers and authors may argue that it is a binary decision – either there is CI/CD or there is not. I rather think that every small improvement gained by adopting CI/CD, CI, or CD only, even in stages, is a win. In racing, whether it is by a mile or a metre, a win is a win.

Happy architecting and let us explore the cloud in depth.

Dell Virtustream gains certified cloud provider status for Australia


Clare Hopping

1 Jun, 2018

The Australian government has presented Dell Virtustream with a place on the Australian Signals Directorate’s (ASD) Certified Cloud Services List (CCSL), meaning it’s now been granted permission to host unclassified dissemination limiting marker (DLM) government information on its cloud service.

The cloud business joins other companies obtaining permission, alongside other tech providers including AWS, IBM, Salesforce, ServiceNow, Sliced Tech and Vault Systems/

However, Dell Virtustream’s Unclassified DLM classification is the second level on the list. Only Dimension Data, Macquarie Government, Microsoft’s Azure and Office 365, Sliced Tech and Vault Systems have “Protected” status, the highest level of accreditation available.

Part of the specification for gaining protected-level status is that data stored within the cloud services is only available to employees in Australia. However, Microsoft’s Azure Cloud service does allow for the transfer of information to other countries.

However, Australia’s Cyber Coordinator Alastair MacGibbon has since reassured doubters that the service does tick all the boxes (although he was non-committal when asked whether the ASD specifies the provider must be based in Australia to be CSSL approved) and no data will be made available outside of the country, as per the rules.

«Data can reside anywhere in the world, you can demand data stay in Australia but it doesn’t always make it more secure that it’s in a particular geography,» he said.

«It’s good that we hold data in Australia, that means that data comes under Australian law, that means that agencies and others have more access to it and other country’s agencies theoretically don’t have access to that data.»

Three ways machine learning is revolutionising zero trust security

Bottom line: Zero Trust Security (ZTS) starts with Next-Gen Access (NGA). Capitalizing on machine learning technology to enable NGA is essential in achieving user adoption, scalability, and agility in securing applications, devices, endpoints, and infrastructure.

How next-gen access and machine learning enable zero trust security

Zero Trust Security provides digital businesses with the security strategy they need to keep growing by scaling across each new perimeter and endpoint created as a result of growth. ZTS in the context of Next-Gen Access is built on four main pillars: (1) verify the user, (2) validate their device, (3) limit access and privilege, and (4) learn and adapt. The fourth pillar heavily relies on machine learning to discover risky user behavior and apply for conditional access without impacting user experience by looking for contextual and behavior patterns in access data.

As ZTS assumes that untrusted users or actors already exist both inside and outside the network, machine learning provides NGA with the capability to assess data about users, their devices, and behavior to allow access, block access, or enforce additional authentication. With machine learning, policies and user profiles can be adjusted automatically and in real-time. While NGA enabled by machine learning is delivering dashboards and alerts, the real-time response to security threats predicated on risk scores is very effective in thwarting breaches before they start.

Building NGA apps based on machine learning technology yields the benefits of being non-intrusive, supporting the productivity of workforce and business partners, and ultimately allowing digital businesses to grow without interruption. For example, Centrify’s rapid advances in machine learning and Next-Gen Access to enable ZTS strategies makes this company one of the most interesting to watch in enterprise security.

The following are three ways machine learning is revolutionizing Zero Trust Security:

  • Machine learning enables enterprises to adopt a risk-based security strategy that can flex with their business as it grows. Many digital businesses have realized that “risk is security’s new compliance,” and therefore are implementing a risk-driven rather than a compliance-driven approach. Relying on machine learning technology to assess user, device, and behavioral data for each access request derives a real-time risk score. This risk score can then be used to determine whether to allow access, block access, or step up authentication. In evaluating each access request, machine learning engines process multiple factors, including the location of the access attempt, browser type, operating system, endpoint device status, user attributes, time of day, and unusual recent privilege change. Machine learning algorithms are also scaling to take into account unusual command runs, unusual resource access histories, and any unusual accounts used, unusual privileges requested and used, and more. This approach helps thwart comprised credential attacks, which make up 81% of all hacking-related data breaches, according to Verizon.
  • Machine learning makes it possible to accomplish security policy alignment at scale. To keep pace with a growing digital business’ need to flex and scale to support new business models, machine learning also assists in automatically adjusting user profiles and access policies based on behavioral patterns. By doing so, the need for IT staffers to review and adjust policies vanishes, freeing them up to focus on things that will grow the business faster and more profitably. On the other hand, end users are not burdened with step-up authentication once a prior abnormal behavior is identified as now typical behavior and therefore both user profile and policies updated.
  • Machine learning brings greater contextual intelligence into authentication, streamlining the experience and increasing user adoption. Ultimately, the best security is transparent and non-intrusive. That’s where the use of risk-based authentication and machine learning technology comes into play. The main impediment to adoption for multi-factor authentication has been the perceived impact on the productivity and agility of end users. A recent study by Dow Jones Customer Intelligence and Centrify revealed that 62% of CEOs state that multi-factor authentication (MFA) is difficult to manage and is not user-friendly, while only 41% of technical officers (CIOs, CTOs, and CISOs) agree with this assessment. For example, having to manually type in a code that has been transmitted via SMS in addition to the already supplied username and password is often seen as cumbersome. Technology advancements are removing some of these objections by offering a more user-friendly experience, like eliminating the need to manually enter a one-time password on the endpoint, by enabling the user to simply click a button on their smartphone. Nonetheless, some users still express frustration with this additional step, even if it is relatively quick and simple. To overcome these remaining barriers to adoption, machine learning technology contributes to minimizing the exposure to step up authentication over time, as the engine learns and adapts to the behavioral patterns.

Conclusion

Zero Trust Security through the power of Next-Gen Access is allowing digital businesses to continue on their path of growth while safeguarding their patented ideas and intellectual property. Relying on machine learning technology for Next-Gen Access results in real-time security, allowing to identify high-risk events and ultimately greatly minimizing the effort required to identify threats across today’s hybrid IT environment.

Microsoft is now more valuable than Google


Vaughn Highfield

31 May, 2018

Microsoft is now more valuable than Google and its listed parent company, Alphabet. For the first time since 2015, the Redmond-based technology company overtook the behemoth that is Google to become the third most valuable company in the world.

Valued at $753 billion (£566 billion), Microsoft sits just ahead of Alphabet’s $739 billion (£556 billion) valuation. Microsoft and Google have been trading places on the rankings since Google first surpassed the company in 2012. However, with this decisive gain, it shows that Microsoft CEO Satya Nadella has really managed to change the company’s image and turn its fortunes around.

Since taking over four years ago, Nadella has helped more than double Microsoft’s stock price, and the business has gone from being a 40-plus-year-old company to a modern tech icon. By focusing Microsoft into product categories like AI and cloud computing, while simultaneously axing failing divisions like the Windows Phone, Microsoft has successfully modernised. The latest ranking shift just goes to show these rather drastic methods of moving away from Windows as its core product have clearly worked.

Microsoft is also hot on the heels of Amazon, the second largest company in the world – sitting at $782 billion (£588 billion). At the top of the pack is Apple – which, with a market valuation of $923 billion (£694 billion), isn’t going anywhere soon. Interestingly, though, Microsoft arguably has a larger portfolio than Apple and that could well be used to its advantage. As The Verge points out, Google generates around 90% of its revenue directly from advertising, and 60% of Apple’s entire revenue is also attributable to iPhone sales which could see billions wiped from its valuation if sales slow.

Microsoft, however, has grown much of its business through hardware, software and services. In its latest earnings report, Microsoft’s Windows, Surface and Xbox divisions chalked up to around 35% of its revenue. Cloud services clocked in at around 30% and Office and productivity solutions at another 30%.

So where next for Microsoft? Morgan Stanley believes that Microsoft will be one of the first companies out there to hit a $1 trillion valuation within the space of a year thanks to the growth of cloud services. If this is the case, Apple certainly has something to be worried about.

Picture: Bigstock

How to Switch Between Mac and Windows on Parallels Desktop

Let’s be honest: to the average person, the idea of running two different operating systems at the same time on one computer is pretty weird. This idea naturally leads to questions like these: How do I know which one I’m using at any one moment? How do I switch between them? Which applications do I […]

The post How to Switch Between Mac and Windows on Parallels Desktop appeared first on Parallels Blog.

Why it’s time for manufacturers to take security in the cloud seriously

Manufacturers deal with sensitive data every day. This includes test and quality data, warranty information, device history records, and especially the engineering specifications for a product that are highly confidential. Trusting that data to a cloud-based application or cloud services provider is a major step, and manufacturers need to fully educate themselves about the security risks and advantages of cloud-based software.

As we prepare to enter the second half of 2018, consider the following three questions as your guide when discussing application infrastructure and operations with cloud providers.

Question #1: How do you keep my data safe?

The answer should be long and multi-faceted. Because no single tool will defend against every kind of attack in any network, cloud providers must deploy multiple layers of defense using: internal systems; protection provided by tier 1 cloud platforms; and security service providers. All of these elements come together to provide complete protection.

Below are some examples of these layers:

  • Physical defence: Cloud platform providers can and should exercise tight control of access to the physical devices on which the software systems reside. In best case scenarios, Independent auditors attest to the safety of this access. This control and documentation must be reviewed on a regular basis.
  • Barriers to entry: Firewalls built into the cloud service can limit access to ports managed by the application. Unneeded ports should be blocked so that they cannot be accessed.
  • Application password protection: the best-designed cloud applications allow your organisation’s identity management system to provide authentication and password management, limiting access to your data and following your internal security policies. This should also support two-factor authentication if your internal policies require it. Some of the more advanced systems can also provide an identity management service as an alternative to your internal solutions, if required.
  • Application firewalls: Most enterprise-class application designs will include a Web Application Firewall service that uses the latest technology to defend against such things as denial of service attacks and other types of malicious access.
  • Activity monitoring: State-of-the-art cloud platform providers continuously monitor for suspicious activity that could be the result of hacking or malware. Again, in best case scenarios, warnings are sent automatically and steps taken to protect the data and the integrity of the platform.
  • Malware monitoring: Both the application provider and the hosting platform provider must run active checks for malicious code to ensure each piece of code that is executed matches the published signature for that code. Be warned: this is a step that many providers have not migrated to yet.
  • Code standards: Good security starts with good code. Security standards must be included in the system development life cycle, governing every aspect of the system. Be sure to review the code standards of the application developer.
  • Third party code scanning: The most advanced application providers use a third-party firm to scan code looking for opportunities to improve security and look for known vulnerabilities with each new version of the application. Ask for details about this, as there are many different levels of scanning available; a once-a-year scan is obviously not as valuable as regularly scheduled scans before each new release of software.
  • Data encryption: Generally accepted practices for data encryption provide different options for data in different modes: data in transit (being communicated within the system or between the database and your user interface) and data at rest (data that resides within the database and is not currently being accessed).

Data in transit can be encrypted using industry standard encryption through the browser. Additionally, APIs that access the data should use encrypted data and include encrypted tokens to increase access control.

Encryption of data at rest protects against accessing data from outside the application’s control. As the physical access to the system is protected and the data is in password protected databases, at-rest encryption may not be essential for every customer – but the question is still worth asking.

Question #2: How do I know that my data can’t be accessed by other customers?

There are many ways to ask this question:

  • Do you mix my data with other companies’ data?
  • Can other people see my data?
  • What’s your data structure for each customer?

The answer to each of these is data separation. The system architecture should ensure separation of customer data by customer organization, usually by individual factory or site. This allows even customer administrative tasks such as assigning roles to be limited in scope. While many applications are multi-tenant (meaning the application is shared across multiple customers), transactional data should still be separated by customer factory, meaning there is no commingling of customer data. In other words, your data will be separated from every other customer, giving the highest level of data separation.

Question #3: How does cloud security compare to on-premise security?

There is a common misperception that a set of servers running on-premise at a corporate office is more secure than a cloud-based application. Owning the hardware and software often gives a false sense of security; most on-premise systems fall far short of the security that the best cloud providers have deployed.

For example, the cloud storage system utilized by my company was designed for 99.999999999% durability and up to 99.99% availability of objects over a given year. That design and those numbers are virtually impossible to duplicate with an on premise solution. In addition, the comprehensive access control described above is nearly impossible to duplicate on-premise. To deploy tools like these in an on-premise environment would require not only large investments in infrastructure, but large teams to manage them too.

Ask yourself:

  • How big is your security team?
  • How much is your budget for security around your manufacturing data?

Then remember, the best application providers and data centers have large, dedicated security teams who have implemented automated threat monitoring systems that operate 24×7. In the end, the best cloud software companies have dedicated more time, resources and budget to securing our systems than most organizations are able to provide themselves.

Office 365 usage goes up and up leaving G Suite behind, says research

Microsoft Office 365 usage continues to accelerate significantly across organisations of all sizes while Google’s G Suite languishes in comparison, according to new figures from Bitglass.

The cloud access security broker (CASB), in its 2018 Cloud Adoption Report, analysed software usage of more than 135,000 companies globally and found Office 365 continues to rule the roost.

56.3% of the more than 135,000 companies analysed were users, compared with only a quarter (24.8%) for G Suite. The latter has actually decreased – admittedly from 24.9% – compared with two years ago, while Office 365 uptake in 2016 was at 34.3%.

In terms of Office 365 and G Suite houses by size, the trend for larger firms to go with Microsoft remains apparent. Regular readers of this publication may remember a 2015 survey from BetterCloud which found companies surveyed who ran Office 365 had IT teams on average five times the size of their Google compatriots.

Bitglass comes to a similar conclusion. Just under half (49.6%) of companies assessed with fewer than 500 employees say they are Office 365 customers, compared with 73.4% for 500-1000 and 73.7% for more than 1000. For G Suite – 24.1%, 24.3% and 25.8% respectively – the figures show little deviation.

Looking across all organisations, 13.8% of companies worldwide are using AWS, with technology (21.5%), education (19.7%) and media (15.3%) firms ahead of the global trend. For larger firms the figures are even more stark; 22.1% of companies with more than 1000 employees use AWS in some capacity, compared with 15.8% for organisations at the 500-1000 range, and 10.8% for those smaller.

For other apps analysed, the general trend is of gradually greater adoption the larger the organisation. More than half of organisations with at least 500 employees are Slack users, compared with 37.8% of smaller businesses. Box is used by 28% of the largest organisations polled compared with 12.7% of companies with fewer than 500 employees, while Salesforce (18.3% and 8.8%) has the same trend.

The dominance of Office 365 is evidently something those at Google have been trying to address. Last month, the company announced the launch of Google One, a premium tier cloud storage offering focused on replacing paid consumer Google Drive plans.

The most interesting aspect which leapt out, however, was around the change of price for 2TB of storage – half of what competitors such as Dropbox and Microsoft charge. As Microsoft bundles storage in with Office 365 subscriptions, this is a not insurmountable hurdle which Google continues to be up against.

Rich Campagna, chief marketing officer at Bitglass, said it was ‘no surprise’ that overall cloud adoption continues to skyrocket. “Organisations worldwide have come to trust platforms like Office 365 and AWS as vendors continue to bolster security and feature sets,” he said.

“Competition between major public cloud players such as Amazon, Google and Microsoft will only increase as they fight to grow market share,” Campagna added. “It remains to be seen which emerging apps will join them to become staples in the enterprise.”

You can find out more and download the report here (email required).