Singapore overtakes Hong Kong to become strongest Asia Pacific cloud nation

Singapore has overtaken Hong Kong to be the number one cloud-ready Asia Pacific nation, according to the latest report from the Asia Cloud Computing Association (ACCA).

The two regions have swapped places since the previous analysis two years ago, with New Zealand retaining bronze medal position, and Japan and Taiwan overtaking Australia. While the latter has slipped a couple of places in the rankings, ACCA said it was still a ‘strong regional contender’ which performed well in most areas but was ‘weighed down by its relatively poor cloud infrastructure.’

Singapore scored particularly strongly in broadband quality, cybersecurity, regulation and business sophistication while Hong Kong top scored in international connectivity and privacy. A study from SolarWinds published last week found cloud and hybrid IT was the most important technology and management tool for organisations in Hong Kong, albeit with plenty to do – 61% of respondents said their IT environment was not performing at its optimal level.

There was no change in the bottom half of the rankings compared with 2016, with Vietnam, China and India propping up the table.

China’s continued poor ranking comes amidst a series of improvements over recent years. According to IDC in February the country will – apart from Japan – be the biggest public cloud spender in the Asia Pacific region. The continued growth of Alibaba’s cloud operations, as this publication has frequently reported, was also apparent. The eCommerce giant was ranked third in public cloud IaaS by Gartner last year and announced plans for European expansion at this year’s Mobile World Congress.

The ACCA report noted China had made progress across ‘several parameters’, but had struggled in power sustainability and broadband quality, reflecting issues with the logistics in getting country-wide adoption. “The Chinese government continues to devote considerable fiscal resources to the development and improvement of infrastructure, a move that will undoubtedly pay off in the next few years,” the report explained.

For the region overall, the report sends a message of strengthened cloud capabilities, but with a caveat. “The fact that the eight highest ranking economies remain unchanged between the 2014 and 2018 [reports] suggests that the cloud divide may already be deeply entrenched,” ACCA said. “Without further intervention, this divide could widen despite the efforts being made by emerging markets to leverage the smart technologies that enable sustainable digital economies.”

You can read the full report here (pdf).

Research dampens claims cloud providers are GDPR-ready


Keumars Afifi-Sabet

16 Apr, 2018

Only half of organisations say all their cloud providers have a plan for GDPR compliance ahead of the 25 May deadline to comply with the new data protection legislation, a report has found.

Surveying 1,400 CISOs and IT managers around the world, McAfee’s The State of Cloud Security report also found a direct link between an organisation’s confidence in their provider’s state of GDPR readiness and the level of investment they are willing to commit to cloud services.

Despite over 80% of organisations in a previous survey indicating they expected help from their service providers to achieve regulatory compliance, McAfee’s latest findings showed only half of respondents said that all their cloud suppliers had a plan in place ahead of the deadline to comply with GDPR, which sets out tougher penalties for organisations that misuse EU residents’ data, and hands more control to people over how their information is used.

Organisations more confident in their cloud providers’ GDPR readiness were more likely to spend more on cloud services in the coming year, with those lacking confidence more likely to keep investment at the same level.


Not all cloud solutions support the same level of security, so what should you look for before committing to a cloud service? Learn more in ‘Demystifying Cloud Security’.

Download now


Just under half of respondents anticipated increased investment in light of GDPR, while 44% of organisations said they expected spending to remain flat. Less than 10% of organisations anticipated decreasing their investment in their cloud services, again contrasting with the findings of McAfee’s Beyond the General Data Protection Regulation (GDPR) which found organisations were projected to reduce investment by $85,000 on average as a result.

«The implementation of the incoming GDPR, due to come into force in just over a month’s time, will affect cloud users around the world,» said Nigel Hawthorn, data privacy expert in McAfee’s cloud security business unit.

«Becoming GDPR compliant requires a combination of knowledge, processes, policies, technology and training, as well as detailed understanding of data flows to and from third parties and cloud services. With this in mind, it is concerning that only half of the respondents stated that all of their cloud providers have a plan in place for GDPR compliance.»

Cloud Pro has previously warned against relying on third-parties to ensure compliance with GDPR.

Skills shortages underline wider issues

The latest edition of McAfee’s annual report on the current state and future plans for cloud adoption and security also shed light on cloud adoption progress, as well as the main concerns proving obstacles for some organisations.

A quarter of respondents highlighted a lack of staff with skills to manage security for cloud applications, and only 24% of organisations reported that they suffered no skills shortage, while the research found 40% of IT leaders reported they were slowing their organisation’s cloud adoption.

Data theft, however, was ranked as the greatest concern, with 56% of professionals saying they had tracked a malware infection back to a cloud application, up from 52% the previous year.

Lack of visibility, meanwhile, was cited as one of the most commonly experienced issues – spanning users creating cloud workloads outside of an organisation’s IT department (shadow IT), a lack of transparency around what data is stored in the cloud, and an inability to monitor cloud workloads.

UK organisations slowest to adopt, and most cautious

Organisations in the UK were the slowest to adopt cloud services of those surveyed, while they were also found to be the most cautious over storing sensitive data.

When asked how many months organisations would take for their IT infrastructure to be 80% cloud-based, respondents in the UK answered 19 months, versus an average of 14 months.

Moreover, organisations in the UK were also found to be the least likely to store all of their sensitive data in the public cloud – only 10% versus an average of 25% – while a quarter of UK organisations said they stored no sensitive data in the cloud, the joint-highest with Germany.

Personal customer information comprised the majority of sensitive data, with 61% of organisations keeping such data in the public cloud, followed by payment card information, internal documents, and employee information.


What should you look for in a cloud solution to ensure that your corporate data can be kept safe? Learn more in this whitepaper on cloud security.

Download now


Visibility underpins secure cloud adoption

The report pinpointed a lack of visibility as the key factor hindering organisations from securing their cloud services, concluding visibility-driven organisations, regardless of whether they have adopted a cloud-first strategy or not, have a better awareness of shadow IT and take direct responsibility for the security of their cloud data.

«Poor visibility has a bigger impact on navigation than any single control or capability. After all, you cannot steer around what you cannot see,» the report concluded.

«The leading adopters of cloud services understand this axiom and are integrating cloud visibility into their IT operations to accelerate business. Better cloud visibility enables an organisation to adopt transformative cloud applications sooner, respond more quickly to security threats, and reap the cost savings that virtualisation provides.»

How machine learning quantifies trust and improves employee experiences

By enabling enterprises to scale security with user behaviour-based, contextual intelligence, next-gen access strategies are delivering Zero Trust Security (ZTS) enterprise-wide, enabling the fastest companies to keep growing strong.

Every digital business is facing a security paradox today created by their proliferating amount of applications, endpoints and infrastructure on the one hand and the need to scale enterprise security without reducing the quality of user experiences on the other. Businesses face a continual series of challenges to growth, the majority of which are scale-based. Scaling security takes a multidimensional approach that accurately interprets user behavior, risk and threat predictions, and assesses data use and access patterns.

How enterprises are solving the security paradox with next-gen access

Security defies simple, scale-based solutions because its processes are ingrained in many different systems across a company. Each of the many systems security relies on and protects have their cadence, speed, and scale. When a company is growing fast, core systems including accounting, CRM, finance, pricing, sales, services, supply chain and human resources become security-constrained. It’s common for companies experiencing high growth to choose expediency over security. 32% of enterprises are sacrificing security for expediency and business performance, leaving many areas of their core infrastructure unsecured according to the Verizon Mobile Security Index 2018 Report.

The hard reality for any growing business is the faster they grow; the more sophisticated and strong they need to become at security. Protecting intellectual property (IP), all data assets and eradicating threats assures uninterrupted, profitable growth. Adding new suppliers, sales teams, distribution partners and service centers can’t be slowed down by legacy-based approaches to user authentication and system access.  The challenge is the faster a business is growing, the slower its legacy approaches to security reacts, slowing down sales cycles, supplier qualifications, and pipelines.

Next-gen access solves the security paradox of fast-growing businesses, enabling Zero Trust Security (ZTS) enterprise-wide by solving the following major challenges of a high growth business:

Quit relying on brute-force multi-factor authentication (MFA) techniques that deliver mediocre user experiences and slow down productivity

Any company can still attain Zero Trust Security (ZTS) without reverting to brute-force approaches to MFA. Get away from the idea of having MFA challenges be for every user on every device they use to access every resource. Instead look to next-gen access (NGA) to quantify context, device, and behavioral patterns and derive risk scores for each user.

Begin to rely on next-gen access, risk-aware MFA, and risk scores to quantify trust and set the foundation of a Zero Trust Security (ZTS) enterprise-wide strategies

The goal is to keep growth going strong, uninterrupted by any security event or breach. Next-Gen Access (NGA) provides behavioral, contextual intelligence indexed as a risk score for each user, enabling more secure and efficient user experiences. NGA is built on a platform that includes identity as a service (IDaaS), enterprise mobility management (EMM) and privileged access management (PAM). They are also the essential components for creating and fine-tuning Zero Trust Security (ZTS) across fast-growing businesses. Taken together in a concerted strategy, ZTS delivers greater control and visibility over every resource in a company.

Identify potential security risks on a per-user basis to the device level and limiting access while asking for identity verification without impacting user experiences

NGA takes contextual and user intelligence into account when deciding which resources will be available to a given user based on their previous login and system use actions and behaviors quantified in their risk score. Machine learning algorithms are used to find patterns in user behavior that could signal a potential security risk. Based on the risk score, conditional access is provided or not. All of this is done in seconds and doesn’t impact the user experience.

Rely on more NGA that learns users' behavioural patterns over time and improves the user experience, scaling Zero Trust Security enterprise-wide

Solving the paradox of scaling security in fast-growing companies needs to start with a machine learning-based approach to finding and acting on user’s behavioral and contextual activity. As NGA “learns” how valid users interact with security, updating risk scores and performing identity verification, the quality of a user’s experience improves. In fast-growing companies adding new employees, partners, and suppliers, this is invaluable as every new user will generate a risk score. Quantifying trust using NGA, the foundation of any ZTS strategy makes fast, secure profitable growth possible.

The era of ZTS has arrived, and it is accentuating the importance of partnering with security providers who excel at offering next-gen access solutions

ZTS will continue to revolutionise every aspect of an organisation’s security strategy, enabling digital businesses to grow faster and more securely over time. Next-Gen Access solutions are the foundations enabling enterprises to scale ZTS strategies across their businesses. Key Next-Gen access providers enabling the era of ZTS include Palo Alto Networks for firewalls and Centrify for Access. Over the next 18 months, ZTS will redefine the cybersecurity landscape as digital businesses look to Next-Gen Access solutions to securely scale their companies and grow.

Are You Thinking About Big Data When Doing IoT? | @ThingsExpo @CloudTP #IoT #IIoT #BigData

When talking IoT we often focus on the devices, the sensors, the hardware itself. The new smart appliances, the new smart or self-driving cars (which are amalgamations of many ‘things’). When we are looking at the world of IoT, we should take a step back, look at the big picture. What value are these devices providing? IoT is not about the devices, it’s about the data consumed and generated. The devices are tools, mechanisms, conduits.
In his session at Internet of Things at Cloud Expo | DXWorld Expo, Ed Featherston, VP, Principal Architect at Cloud Technology Partners, will discuss the considerations when dealing with the massive amount of information associated with these devices.

read more

Microsoft Azure is best for developers, says Forrester


Clare Hopping

16 Apr, 2018

Forrester has announced Microsoft Azure and AWS offer customers the best PaaS experiences in its latest Wave Report.

The company pitted the world’s 11 leading PaaS vendors, including Alibaba, Amazon Web Services (AWS), CenturyLink, Google, IBM, Microsoft, Oracle, Pivotal Software, Red Hat, Salesforce and SAP against each other across a range of different factors, with Microsoft and AWS’ platforms offering the best user experience across the board.

Microsoft was the overall winner, with the analyst firm praising its range of services such as database tools (referring to the Azure Cosmos DB) and integrations, with lots of support for developers via preconfigured resources that help businesses get up and running quickly.

«Overall operational tools and features are strong; Microsoft also operates a leading data-center network and offers Azure Stack for on-premises deployment,» the firm noted. «Microsoft offers a range of AI services on Azure, but only Azure ML is distinctive.»

However, there are some drawbacks to Microsoft’s platform, such as natural language processing, limitations of its function as a service (FaaS) and releasing features without the proper documentation. In these areas, AWS ranked better, putting its suite of PaaS services in second place. 

AWS also generates three times as much revenue as Microsoft’s cloud platform and offers much more to the developer community, with more preconfigured services and service bundles putting it hot on Microsoft’s tail. 

Google came in at third place, helping developers build apps quickly with its «zero-configuration infrastructure» and backing of open-source platforms such as Kubernetes and TensorFlow. it also offers a range of fully managed services, which puts it only slightly behind Microsoft and AWS.

Oracle, IBM and Salesforce were all noted as strong performers, while SAP, Alibaba, Red Hat and Pivotal were ranked as contenders. CenturyLink came in at the bottom of the leaderboard as a challenger.

IoT Workshop at @ExpoDX New York | @CHarrold303 #AI #IoT #IIoT #SmartCities #DigitalTransformation

IoT is rapidly becoming mainstream as more and more investments are made into the platforms and technology. As this movement continues to expand and gain momentum it creates a massive wall of noise that can be difficult to sift through. Unfortunately, this inevitably makes IoT less approachable for people to get started with and can hamper efforts to integrate this key technology into your own portfolio. There are so many connected products already in place today with many hundreds more on the horizon, that we already run the risk as enablers and supporters of not being able to effectively understand and develop these complex and multi-disciplined solutions on our own. That understanding, of the basics of circuits, sensors, and how those things work together and with software is the key to being able to understand, engineer, and support IoT solutions in your own environment.

read more

Julio Villarreal Pelegrino Joins @CloudEXPO Faculty | @RedHat #CloudNative #OpenStack #DevOps #DigitalTransformation

In this presentation, you will learn first hand what works and what doesn’t while architecting and deploying OpenStack. Some of the topics will include:- best practices for creating repeatable deployments of OpenStack- multi-site considerations- how to customize OpenStack to integrate with your existing systems and security best practices.

read more

Why trust and transparency are key for companies complying with new EBA cloud guidance

New guidance from official regulators should be music to the ears of anyone involved in compliance. Clarification, reference points and approved examples make the business of compliance that much more straightforward and are generally welcomed by compliance experts. In that spirit, it was with the best intentions – to clear the pathway to cloud adoption for financial services companies – that the European Banking Authority issued the guidance with which the financial sector must comply by 1 July this year.

Still, compliance experts on both sides of the cloud service provider (CSP)/customer divide might be forgiven for scratching their heads when it comes to interpreting the new directions in a real-world scenario. 

The EBA has opted for a principles-based, technology neutral approach to the guidance. In some ways this makes sense – technology is evolving at an astonishing rate and being too prescriptive could risk limiting the ability to make the most of the next exciting innovation. However, I feel that financial services companies require some more prescriptive standards, certifications and best-practice examples to provide greater clarity and help them unlock the benefits of cloud computing. As a cloud compliance specialist, here is my take on some of the key elements of the EBA guidance and how financial companies and CSPs will need to work together to comply with its principles.  

Third party oversight offers verifiable, auditable trust

The guidance requires that financial organisations seek full understanding of the risks associated with their cloud outsourcing operations and the level of data and system security that CSPs will deliver. Therefore, the initial priority for a financial organisation is to establish that its cloud service provider – or prospective provider – has identified and is operating their risk, security and personal information management systems to a standard that will satisfy the guidance. This is not a small hurdle: the guidance does not specify which of the available standards is acceptable so there is a degree of subjectivity involved in deciding what constitutes a sufficiently rigorous approach. This will likely lead to a longer due diligence and discovery phase. Organisations should look for CSPs that are ISO 27001-certified for information security management as a minimum, but for cloud-specific aspects of security, the Cloud Security Alliance (CSA) Star certification programme provides auditable ongoing assurance that the provider is meeting and sustaining the highest standards.

When it comes to personal information security the forthcoming EU General Data Protection Regulation (GDPR) has prompted some CSPs who are leading the market in cloud compliance to certify to BS 10012:2017, which ensures they are operating best practice systems for data protection under the GDPR and should meet the level of assurance required by the guidance.

Third party oversight and validation from certifications such as CSA Star and BS10012:2017 plus transparency into the policies and processes of the cloud provider allow financial institutions deep insight into the operations and procedures of their cloud partners. The key mantra here should be verifiable trust and transparency.

It’s important to note, also, that standards continue to evolve alongside the environment they relate to and CSPs have to work continuously to achieve ongoing certification. Including references to industry standards in the EBA’s guidelines like the ones I’ve mentioned above will provide useful signposts towards the route that financial organisations should take to achieve compliance.

Best practice SLA and monitoring relationships

The ability to continuously monitor the security and risk of cloud service provision is a key axiom of the guidance and will be critical to the success and compliance of the cloud outsourcing relationship. To achieve this it’s vital that the CSP and the financial organisation’s risk and monitoring programmes are aligned. If you have to decipher and translate risk and monitoring programmes between entities, confusion and disconnects will arise. Again, standards offer a solution: if both entities are aligned to ISO 27001 there is a common approach on which to build an effective monitoring strategy.

A best-practice service level agreement and monitoring relationship should be instigated at executive level within both organisations, reflecting its importance to both parties. A strong and transparent working partnership between the risk and compliance teams on both sides should underpin the regular cycle of audit, reporting and assurance. Look for a cloud service provider that provides visibility into your cloud resources and the associated security settings and compliance postures as well as a straight-forward means of getting the reporting you need for auditing purposes.

Chain outsourcing: Overcoming the financial sector’s Achilles heel

Outsourcing of any kind has historically been a major challenge and strictly regulated in the financial sector. In recognition of the flexible and collaborative nature of cloud service providers, the new guidance sets out the terms and processes under which chain outsourcing – a cloud provider outsourcing an element of its provision to a third party – is acceptable. As with most aspects of the guidance, strong emphasis is placed on ongoing risk management and transparency between the CSP and financial organisation. CSPs must agree to notify the financial institution should they subcontract an element of their service to another provider and must ensure that the subcontracted company meets the same standards set out in the original agreement between the CSP and its customer. Consent from the financial institution is not required, however, as this is deemed impractical. It is the responsibility of the financial organisation to determine whether the third party outsourced arrangement now constitutes unacceptable risk.

Throughout all aspects of the EBA guidelines it is abundantly clear that the relationship between financial organisations and their CSPs needs to be extremely close and transparent, and conducted at a senior level. Verifiable trust through certification is the linchpin of the whole relationship and the partnership will be dysfunctional (and potentially inviable) without this cornerstone in place.

In future guidance, I would like to see the EBA put more definition around the exact standards and best practices it expects to see in financial sector cloud outsourcing projects, but in their absence I hope that financial companies will discover that CSPs themselves can offer the consultative expertise needed to help them unlock the many benefits of the cloud.       

Hong Kong analysis shows importance of cloud technologies in improving productivity and ROI

Cloud technologies are key to Hong Kong businesses according to a new report from SolarWinds – but containers, blockchain and robotics still have a fair way to go yet.

The findings appear in the company’s latest IT trends report, ‘The Intersection of Hype and Performance.’ The research polled 75 IT practitioners, managers and directors in Hong Kong – with the overall research quizzing more than 800 respondents across four continents – and found cloud and hybrid IT was the most important technology and management tool for organisations’ strategy today, cited by 92% of those polled.

Big data and analytics, cited by 77% of respondents, was also a key tool, ahead of automation (71%), software-defined everything (SDx) (52%), and the Internet of Things (51%). Containers scored 29%, while blockchain (11%) and robotics (9%) fared poorly.

Worryingly, 61% said their IT environment was not performing at its optimal level, compared with only 19% who said it was. In something of an anomaly, 38% of mid-sized businesses said their IT was at optimal level, compared with only 11% for SMBs and enterprises respectively.

Cloud ranked highly in the vast majority of questions asked. Almost half (49%) of overall respondents said it had the best potential to deliver highest ROI, alongside big data (49%) and automation (47%). 52% of overall respondents – rising to 67% for smaller businesses – said cloud had the greatest potential to deliver further productivity, while 73% identified it as a ‘transformational’ technology, albeit behind big data analytics (85%).

The report notes the importance of automation as forming the next generation of cloud services – a trend this publication has reported on frequently this year. “Where the C-suite considers AI, ML, and deep learning to be fundamental elements of digital transformation, IT professionals are looking toward the technology and processes that underpin continuous integration and delivery – which ultimately enable enhanced performance and digital experience in today’s environments,” the report explains.

Hong Kong is one of the most advanced cloud nations, hitting top spot in the most recent analysis from the Asia Cloud Computing Association (ACCA). The region was praised specifically for its ‘tradition of robust future planning and a strong tech industry… ensuring [its] infrastructure is primed for fast, reliable and secure cloud offerings targeting the entire region.’

“In 2018 more than ever, IT professionals have an opportunity to continue identifying ways to optimise the digital experience for end users in hybrid IT environments while prioritising investments in technologies that will deliver business value visible well beyond IT,” the report concludes. “IT must also be the convening voice in business discussions, showcasing the ongoing value of IT professionals as the partners to the business, supplying expertise and experience on the technologies that will enable the business to deliver digital transformation success.”

You can read the full report here (pdf).

Data centres and cloud networks: Security in the modern context

Traditionally, companies have sought to create a hardened IT network perimeter that kept all potential cyber threats out and to protect organisations through the use of network security platforms such as firewalls. In the modern context, however, this has become a restrictive and dangerous approach and I will explain why. 

What we think of as traditional firewalls are only really able to inspect unencrypted traffic. This means that attackers will use encrypted communications to exploit and maintain control over assets. Attackers have also moved to exploit changes in application design and implementation, and use network paths between application components that traverse internal data centre and cloud networks. 

While traditional network security appliances, such as firewalls and Intrusion Prevention Systems (IPS), are still useful for creating choke points in conventional networks, their utility declines rapidly in cloud and distributed networks. This is because the traditional model of network security was based on the assumption that the majority of traffic would be passing from the perimeter “south” towards monolithic service pods, with little traffic propagating across the data centre.  We also assumed that the majority of our services would be hosted in data centres that enterprises would own and deploy themselves. 

In contrast, modern application architecture now takes advantage of highly automated cloud and hosted data centre solutions based on multiple layers of virtualisation. The rise of containerisation and the move towards micro-service architectures has also lead to a proliferation of network traffic between workloads within, and across, data centre and cloud networks. Now much of this traffic moves east – west rather than north – south, meaning that the adequacy of traditional security appliances is vastly reduced.  It also leads to a reduction in our visibility into the traffic flows between application components. The automation and orchestration functions within these applications can make it difficult to predict how and where data will transit across the network, and whether the network will be entirely under our control.

To protect these modern application architectures we need to be able to apply security policy to east – west traffic in a way that is consistent with the automation and orchestration tools available within the enterprise. Conventional network security tools typically integrate poorly with these systems – although vendors continue to improve this situation through the implementation of configuration APIs (application programming interfaces) and the general move to Software Defined Networking (SDN) – which leads to delays in the implementation of new services and the creation of unwelcome blockers in the management of service infrastructures. 

One approach taken by conventional network security vendors has been to create virtual appliance versions of their existing platforms, with the intention that these can be deployed in cloud and virtualised networks in a way that mirrors traditional distributions. Unfortunately, this does nothing to alleviate the key issues with the legacy model of deploying network security, resulting in a broken model that fails to address the crucial requirements of the modern network. A new model for delivering network security is required.

In modern environments, we need network security functions to be heavily automated and capable of integrating with the standard toolsets available to operational teams. New toolsets should devolve network security functions down to the endpoint and/or workload, whilst still providing centralised programmatic methods for configuration. This requirement has led to the development of micro- or nano-segmentation. The approach is based on the need to apply security policies to network traffic regardless of where services are physically deployed, and allows the distribution of fine-grained security policies, usually at the workload or container level. This ensures that traffic between them is still subject to inspection and the application of policy, even if it never leaves the physical host that they are running on.

This is a vital point: traditional network security approaches cannot do this since they require the traffic to break out of the physical host at some point. In the past, attempts to meet this requirement have led to the implementation of highly complex and fragile routing configurations that often lead to the loss of key advantages for virtualised networks. These “work around” solutions have often been exploited by attackers to persist within a compromised network and can enable lateral movement within a service – something that micro-segmentation technology is explicitly designed to prevent.

A nice side-effect of the centralised management of network security policy on workloads is that through logging and other forms of telemetry, it is possible to passively detect and map out application data flows, which is an invaluable feature in highly automated networks spanning multiple data centres and cloud services. This can be combined with active application performance management systems that hook into orchestration and automation platforms to dynamically adjust network configurations and optimise service delivery.

The modern enterprise is heavily reliant on the use of cloud and virtualised network services, and it would be foolish to try to shoehorn these services into a traditional network security model that is simply incapable of supporting them fully. Modern enterprises should be deploying new security architectures that support their application infrastructure and can adapt in step with the requirements of consistent service performance and business requirements. 

A key component of this is the deployment of micro-segmentation technology. This ensures that application data flows are adequately protected in a way that is easy to integrate with highly adaptable automation and orchestration tools. The end result is that enterprises can limit their exposure to threats that exploit brittle and low yield traditional security architectures and gain valuable insight into their application infrastructure through passive and active network telemetry.