Learning from the masters of DevSecOps: Getting security right at scale

With the relentless 24/7 nature of the digital economy, many customers I talk to are under pressure to continually release and update their apps. Making this happen is a challenge in itself. But keeping those apps secure can be even more problematic – especially when security is left to the end of the development cycle.

That may seem an unlikely approach in today’s heightened IT security climate. But in my experience, it’s all too common. Under pressure to get their apps out fast, firms often compromise security.

It’s an issue underlined by research on app security, carried out by Freeform Dynamics with executives in large global businesses.

Only 20 percent of them strongly agree that their security testing is up to the demands of continual app development. And only 25 percent strongly agree they have a robust approach to continuously testing for security vulnerabilities.

At the same time, the threats due to mobile and web-based apps continues to grow – 74 percent say security threats due to software/code issues is a growing concern

The era of DevSecOps

So what is the path forward? Given the enormous security threats we now face, organisations must embed security into the very DNA of their software development processes. That means weaving it into every step of the development process: design, coding, release, operation and updating.

Ironically, business leaders know this. Almost all of them (91 percent) agree that making security a more integrated part of software development is a key priority. Some 76 percent believe it’s critical to integrate security practices earlier in the software development lifecycle. 

The evolving process for doing this, DevSecOps, however, it is not as straight-forward to implement as we’d all like.

As the name suggests, DevSecOps means “shifting left” and bringing security into the DevOps fold, so that security testing becomes a natural part of the development process. This puts pressure on an organisation’s people, processes and tools.

That probably explains why only about a third of executives (32 percent) say their IT function is “very effective” at integrating security into the software development cycle early on. And why only 24 percent strongly agree their firm’s culture and practices support the necessary collaboration between development, operations and security.

Most troubling: there may also be a lack of support for implementing DevSecOps at the top. Only 24 percent of respondents strongly agree that senior management understands the importance of not compromising security in favor of speed-to-market. This is truly an alarming statistic, and very surprising in this era of growing security breaches associated with mobile and web-based apps.

Look to the masters

Despite these barriers, the research identified a group of businesses that excel at DevSecOps practices. These ‘Software Security Masters’ represent about 34 percent of the businesses surveyed, globally.

Not only do these firms make security an implicit part of how they work, they take a much broader view of security than their peers. A full 45 percent of the masters strongly agree that security is an enabler of new business opportunities in addition to helping protect a company’s data and systems, versus only 19 percent of their peers in the “mainstream”. As an executive at one such organisation explains: “We work with security early on, so that we’re not architecting in security flaws.”

Not surprisingly, the study found that the masters are also seeing significant business benefits as compared to the mainstream:

  • Accelerated time-to-market: Masters are 2.6x more likely to say their security testing can keep up with the demand to release frequent app updates
  • Improved competitive advantage: Masters are 2.5x more likely to say they are moving fast enough to out-pace their competitors
  • Healthier top and bottom lines:  Masters have a 40 percent higher rate of revenue growth and a 50 percent higher rate of profit growth than their peers in the mainstream

The business case for DevSecOps couldn’t be clearer. It drives business performance because, in the words of another of our masters, “security cannot be an afterthought”.

Five ways machine learning can save your company from a security breach meltdown

  • $86bn was spent on security in 2017, yet 66% of companies have still been breached an average of five or more times.
  • Just 55% of CEOs say their organizations have experienced a breach, while 79% of CTOs acknowledge breaches have occurred. One in approximately four CEOs (24%) aren’t aware if their companies have even had a security breach.
  • 62% of CEOs inaccurately cite malware as the primary threat to cybersecurity.
  • 68% of executives whose companies experienced significant breaches in hindsight believe that the breach could have been prevented by implementing more mature identity and access management strategies.

These and many other fascinating findings are from the recently released Centrify and Dow Jones Customer Intelligence study, CEO Disconnect is Weakening Cybersecurity (31 pp, PDF, opt-in).

One of the most valuable findings from the study is how CEOs can reduce the risk of a security breach meltdown by rethinking their core cyber defense strategy by maturing their identity and access management strategies.

However, 62% of CEOs have the impression that multi-factor authentication is difficult to manage. Thus, their primary security concern is primarily driven by how to avoid delivering poor user experiences. In this context, machine learning can assist in strengthening the foundation of a multi-factor authentication platform to increase effectiveness while streamlining user experiences.

Five ways machine learning saves companies from security breach meltdowns

Machine learning is solving the security paradox all enterprises face today. Spending millions of dollars on security solutions yet still having breaches occur that are crippling their ability to compete and grow, enterprises need to confront this paradox now. There are many ways machine learning can be used to improve enterprise security. With identity being the primary point of attacks, the following are five ways machine learning can be leveraged in the context of identity and access management to minimize the risk of falling victim to a data breach.

Thwarting compromised credential attacks by using risk-based models that validate user identity based on behavioral pattern matching and analysis

Machine learning excels at using constraint-based and pattern matching algorithms, which makes them ideal for analyzing behavioral patterns of people signing in to systems that hold sensitive information. Compromised credentials are the most common and lethal type of breach. Applying machine learning to this challenge by using a risk-based model that “learns’ behavior over time is stopping security breaches today.

Attaining Zero Trust Security (ZTS) enterprise-wide using risk scoring models that flex to a businesses’ changing requirements

Machine learning enables Zero Trust Security (ZTS) frameworks to scale enterprise-wide, providing threat assessments and graphs that scale across every location. These score models are invaluable in planning and executing growth strategies quickly across broad geographic regions. CEOs need to see multi-factor authentication as a key foundation of ZTS frameworks that can help them grow faster. Machine learning enables IT to accelerate the development of Zero Trust Security (ZTS) frameworks and scale them globally. Removing security-based roadblocks that get in the way of future growth needs to be the highest priority CEOs address. A strong ZTS framework is as much a contributor to revenue as is any distribution or selling channel.

Streamlining security access for new employees by having persona-based risk model profiles that can be quickly customized by IT for specific needs

CEOs most worry about security’s poor user experience and its impacts on productivity. The good news is that the early multi-factor authentication workflows that caused poor user experiences are being redefined with contextual insights and intelligence based on more precise persona-based risk scoring models. As the models “learn” the behaviors of employees regarding access, the level of authentication changes and the experience improves. By learning new behavior patterns over time, machine learning is accelerating how quickly employees can gain access to secured services and systems.

Provide predictive analytics and insights into which are the most probable sources of threats, what their profiles are and what priority to assign to them

CIOs and the security teams they manage need to have enterprise-wide visibility of all potential threats, ideally prioritized by potential severity. Machine learning algorithms are doing this today, providing threat assessments and defining which are the highest priority threats that CIOs and their teams need to address.

Stop malware-based breaches by learning how hackers modify the code bases in an attempt to bypass multi-factor authentication

One of the favourite techniques for hackers to penetrate an enterprise network is to use impersonation-based logins and passwords to pass malware onto corporate servers. Malware breaches can be extremely challenging to track. One approach that is working is when enterprises implement a ZTS framework and create specific scenarios to trap, stop and destroy suspicious malware activity.

UK Cloud Awards 2018 shortlist announced


Cloud Pro

9 Apr, 2018

The UK Cloud Awards 2018 judging process has now finished and the shortlist of contenders for the accolades have been unveiled.

The awards, which are designed to recognise talent, achievement and innovation in the UK cloud industry, are now in their fifth year.

Winners will be announced at the awards ceremony, which will take place at County Hall, London on 16 May.

Alex Hilton, CEO of CIF, said: «This is the fifth year we have run the UK Cloud Awards and we are delighted to announce that we had a record number of entries this year, confirming our belief that the UK Cloud Awards are now a recognised feature of the technology industry’s awards calendar.

«Over the past decade we have witnessed phenomenal innovation and the truly transformational use of cloud services. The depth, strength and maturity of the cloud industry in the UK is apparent. It’s going to be extremely difficult to pick the winners in each and every category and we would like to congratulate everyone that has got this far. I would like to take the opportunity to wish everyone that has made the cut the best of luck on the night.»

The shortlist for the UK Cloud Awards 2018 is as follows:

BEST IN CLASS

Security Solution of the Year

Alienvault USM Anywhere by Alienvault
Amazon GuardDuty by AWS
CipherTrust Cloud Key Manager by Thales eSecurity
Darktrace Cloud by Darktrace
Verify by Aspect Software

Storage Solution of the Year

Ceph Storage 3 by Red Hat
FlashBlade by Pure Storage
Rubrik
Scality RING7 by Scality

Collaboration Solution of the Year

BlueJeans with Dolby Voice
Freshdesk
Lifesize App by Lifesize

Business Continuity Solution of the Year

Druva Cloud Platform
iland Secure DRaaS by iland Cloud
SolarWinds Backup by Solarwinds MSP

Most Innovative Enterprise Product

Adaptive Insights Business Planning Cloud
Apttus »Max» by Apttus
Boomi by DELL
Interoute Edge by Interoute
iPortalis Control Portal
New Relic by New Relic
Rubrik
Silver Peak Unity EdgeConnect SD-WAN solution

Most Innovative SMB Product

Advanced Voice Services by Natterbox
CloudMigrator Go by Cloud Technology Solutions
GoSimpleTax by GoSimple Software Limited

Unified Communications Product of the Year

Advanced Voice Services by Natterbox
Global Office by RingCentral
storm DTA by Content Guru

Fintech Solution of the Year

AccountsIQ
Expenses by Selenity
FreeAgent
GoSimple Tax by GoSimple Software Limited
Mambu
Sage Business Cloud Financials (formerly known as Sage Live

Cloud Platform Solution of the Year

Anypoint Platform
Crowd Release by MuleSoft
Boomi by DELL
Cloud Platform Solution by Box
Cloud Protection Manager by N2W Software
OpenShift Container Platform 3.7 by Red Hat
Spotinst
ThousandEyes

BEST DIGITAL TRANSFORMATION PROJECTS

Best Public Sector Project

CityVerve supported by Chime-Tech
Health and Social Care digital meal planning with Kafoodle Kare
Manchester City Council supported by Cloud Technology Solutions
NHS in association with Kahootz
storm® Citizen Engagement Hub with Content Guru

Best Private Sector Project (SMB)

Brother International Europe supported by Ensono
Stephen James Group supported by Charterhouse Voice & Data

Best Private Sector Project(Enterprise)

Big Data European Concept Platform (UK) supported by ANS
Nuffield Health supported by Silver Peak
The Lidl UK Winebot supported by Aspect Software
SYNLAB Laboratory Services and Ancoris
Ubisoft supported by Aspect

Most Innovative Emerging Technology

Project Freq by Amido
Pulse by FinancialForce

CLOUD SERVICE PROVIDER

Best Cloud Managed Service Provider (MSP)

4D Data Centres
CenturyLink
Claranet
Databarracks
Ensono

Best Cloud Service Provider (CSP)

CSI Limited
Content Guru
Ingram Micro Cloud
Interoute
Sesui Ltd
TechQuarters
UKCloud Ltd

Best G-Cloud Public Sector Provider

Kahootz
UKCloud Ltd

ACHIEVEMENT AWARDS

Cloud Visionary of the Year

Apay Obang-Oyway,Ingram Micro
Craig Joseph,intY
Simon Ratcliffe,Ensono

Cloud Entrepreneur of the Year

Geoffroy De Cooman, Proxyclick
Mitchell Feldman, RedPixie
Simon Hansford, UKCloud Ltd

Internet Explorer for Mac

Globally, there are millions of users who are required to use Microsoft Internet Explorer for banking, human resources, tax systems, and many other corporate intranets. Google Chrome, Mozilla Firefox, Opera, and even Microsoft Edge are free browsers that are more stable and secure than IE. However, Internet Explorer is still the second most popular web […]

The post Internet Explorer for Mac appeared first on Parallels Blog.

Google Cloud hits 100% renewable energy goal


Clare Hopping

9 Apr, 2018

Google has announced it’s achieved its goal of running all of its clouds on renewable energy – a mission it set out to complete just over a year ago.

In fact, the company has generated more green energy than it needs to power its data centres and offices from renewable sources including solar and wind power.

“Over the course of 2017, across the globe, for every kilowatt hour of electricity we consumed, we purchased a kilowatt hour of renewable energy from a wind or solar farm that was built specifically for Google,” Urs Hölzle, Google’s senior vice president of Technical Infrastructure said in a blog post. “This makes us the first public Cloud, and company of our size, to have achieved this feat.”

Hölzle went on to explain the company is taking its responsibilities even further, entering into contracts to buy a further three gigawatts of power from renewable sources.

Not only does its investment in green energy sources mean it’s making a conscious effort to reduce its carbon footprint significantly, it’s also financing the green energy economy, with current contracts contributing more than $3 billion in new capital investment around the world.

However, there’s still some way to go until Google is 100% run on renewable energy sources.

Although Hölzle explained the company adds a kilowatt hour of energy to the grid for every hour it spends, that may not be used to directly power its own data centres or offices, because the projects it supports may be in different geographical areas to its facilities, or the power generated at a different time.

“What’s important to us is that we are adding new clean energy sources to the electrical system, and that we’re buying that renewable energy in the same amount as what we’re consuming, globally and on an annual basis,” he said.

The company explained it will continue to invest in new energy sources as demand for its products grow. It will also stay on the lookout for new opportunities to help markets where it’s not currently operating renewable energy sources.

“This program has always been a first step for us, but it is an important milestone in our race to a carbon-free future,” Hölzle finished. “We do want to get to a point where renewables and other carbon-free energy sources actually power our operations every hour of every day. It will take a combination of technology, policy and new deal structures to get there, but we’re excited for the challenge. We can’t wait to get back to work.”

Image: Google’s Eemshaven data centre, The Netherlands, courtesy of Google

Meet 30 Japanese DX Exhibitors | @ExpoDX @JETROUSA #AI #IoT #SmartCities #ArtificialIntelligence #DigitalTransformation

JETRO showcased Japan Digital Transformation Pavilion at SYS-CON’s 21st International Cloud Expo® at the Santa Clara Convention Center in Santa Clara, CA. The Japan External Trade Organization (JETRO) is a non-profit organization that provides business support services to companies expanding to Japan. With the support of JETRO’s dedicated staff, clients can incorporate their business; receive visa, immigration, and HR support; find dedicated office space; identify local government subsidies; get tailored market studies; and more.

read more

Jumpstart to #DigitalTransformation | @CloudExpo @EARPintegration #AI #FinTech #IoT #IIoT #SmartCities

«We are still a relatively small software house and we are focusing on certain industries like FinTech, med tech, energy and utilities. We help our customers with their digital transformation,» noted Piotr Stawinski, Founder and CEO of EARP Integration, in this SYS-CON.tv interview at 20th Cloud Expo, held June 6-8 in New York City, NY.

read more

Secrets of Our Sponsors | @ExpoDX #IoT #DevOps #FinTech #SmartCities #ArtificialIntelligence #DigitalTransformation

The best way to leverage your CloudEXPO | DXWorldEXPO presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering CloudEXPO | DXWorldEXPO will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at CloudEXPO. Product announcements during our show provide your company with the most reach through our targeted audiences.

read more