Fast-paced changes in the business landscape demand enterprises to rethink their existing business models and add innovative capabilities keeping in mind the new imperatives. One among them is the focus on Digital transformation. In the retail industry, growth is measured in terms of increased sales and value addition to existing products while keeping customer expectations in mind. This is where a digital focus is important to remain competitive.
Why analytics and good identity hygiene are key to cloud security

As cloud computing has matured, the benefits it delivers to organisations of all sizes are undeniable. Companies are enjoying agility, scale and speed like never before.
And cloud adoption shows no signs of slowing. Gartner earlier this year forecasted that the worldwide public cloud services market would grow 18 percent in 2017, and Forrester said global cloud services revenues totalled £100 billion in 2016, up from £50 billion just two years ago — that’s annual growth of 30 percent.
With this huge growth in cloud adoption and the recent rash of cyberattacks targeting organisations across all industries, effective security in the cloud is paramount.
Exposed APIs
One way the cloud introduces new security risks to organisations is the underlying infrastructure that makes the cloud and cloud applications run, which consists of publicly exposed APIs.
Why is that an important distinction? Because, essentially, what makes APIs useful also makes them exploitable. APIs are built with fully exposed controls to support orchestration, management, automation and integration between solutions and applications.
This level of exposure makes them a rich target for exploitation, and can introduce another dimension of security challenges for businesses, as it expands the boundaries that were not part of traditional on-premise perimeters that enterprises are used to.
It’s often noted that attackers will take the path of least resistance, and employees – sometimes even those in IT organisations – will unwittingly help them, often by using lax identity practices.
Identity weakness is an open door
There will always be employees who fall prey to phishing attempts, surf exploited websites, use unsecured free Wi-Fi networks in public and download other sketchy material. All of this behaviour opens the door to potential attackers.
At the same time, common infrastructure weaknesses are seen by attackers as the exploit of choice to land a beachhead within an organisation, such as using a SQL query to find cached credentials or finding an unpatched, publicly exposed server to exploit.
And, of course, you have bad identity and password practices that are always enticing to threat actors – and there’s no shortage of employees who fall back to first initial-last name or password1234 as their password of choice.
Identity weakness can also open the door to full control of the API.
Identity hygiene
There’s no 100 percent ironclad way to prevent intrusion through exploiting identity, but you can slow them down. How? Through good identity hygiene. Some ways to implement this in your organisation include:
Multi-factor authentication
Time was, a password was the only necessary way to authenticate to a network or applications. That worked well for a while. Not anymore. Additional layers of defence are imperative. Threat actors can easily crack passwords, so the use of additional types of authentication, such as biometrics and tokens ensure tighter security.
Passphrases over passwords
We’ve seen time and time again where weak passwords are cracked. A passphrase, however, makes it more difficult. Where a password is typically up to 10 letters, numbers and symbols, a passphrase, however, has a much longer character length to stymie possible attackers and commonly contains underscores to separate words in the phrase. Passphrases don’t have to be grammatically correct and they can also use numbers and symbols to make cracking them that much harder. Mamma Mia! Your passphrase can be your favourite Abba lyric, if that’s your thing.
Depreciate expired employee accounts
Leaving accounts open for former employees or for services no longer in use opens a hole that is easily exploited. A good rule of thumb is to shut down expired employee accounts immediately to dramatically reduce the chance of a disgruntled former employee access the network.
Monitor access logs
It sounds like a no-brainer, but knowing who accesses what and when can avoid catastrophe. Monitor access logs frequently for anomalies and to ensure end-users have the correct levels of access.
The industry is currently making improvements in identity by implementing multi-context analysis strategies that include time of access, country of origin, host computer in use and other behavioural analyses to add weight to identity. For example, in his keynote at the AFCEA Defence Cyber Operations Symposium (DCOS), Lt. Gen. Alan Lynn, director of the Defence Information Systems Agency (DISA) and commander of the Joint Force Headquarters–Department of Defence Information Network (JFHQ-DODIN), outlined how assured identity will be critical to cloud and network security and access.
Lynn said assured identity goes beyond traditional common access cards for authentication and access and leverages biometric authentication such as facial and voice recognition, fingerprint, eye scanning and gait; and behavioural authentication, including travel patterns, location by time, device handling, speech patterns and keystroke cadence.
“When you start getting all of that data…your identity score goes up and it will determine how much access you have to different portions of the network,” Lynn said. “So the future I see will be not only a network that’s mobile that you’re bringing devices into your building, but it will determine what’s your level of access based on the amount of identity that’s been provided to your device. That’s a future we’re currently working on.”
Analytics to detect anomalies
Analytics and the ability to detect security anomalies in the cloud are also imperative. Having a strong understanding of how applications are performing and their security posture can provide insight into levels of access and potentially flag a possible security issue before it wreaks havoc.
Integrated, rich, per-app analytics let you quickly understand your application’s performance and security posture so you can take immediate action if there is an anomaly.
Per-app analytics and security data coupled with strong identity hygiene will help ensure your cloud and cloud applications are both high-performing and secure.
Execs concerned at missing out on latest cloud advancements, survey warns

More than four in five respondents to a survey from Commvault and CITO Research say they are at least ‘very concerned’ about missing out on new advancements in cloud technology.
The fear of missing out (FOMO) in this space is real. Of the 100 IT leaders polled, more than two thirds said they were worried about keeping up to date with the latest products and iterations across the primary cloud providers. The most popular methods of keeping up to date were through reading tech publications and networking, cited by three out of five respondents. Interestingly, only one in three said they read vendor websites themselves.
A quarter (24%) of those polled said they were a ‘cloud only’ organisation, while 32% said they are ‘cloud first’ with plans to become cloud only, and only 6% said they did not have a specific migration plan. When asked to sum up their cloud journeys in one word, only one respondent proffered the term ‘frustrating’; ‘innovative’ (51%) and ‘exciting’ (35%) were the most popular.
When it came to the biggest barriers in moving apps and data to the cloud, the sheer volume of data was the primary concern, cited by 68% of respondents. This was followed by developing staff skills and acquiring talent (65%) and managing policies across cloud and on-prem data (55%). As one participant in a CTO panel put it: “The number one barrier to moving to the cloud is staff. That is what I hear from everyone. It’s the culture of moving to the cloud.”
“Cloud is changing the essential elements of the way we do business, and changing it for the better,” the report notes. “As cloud advancements continue, keeping up with those developments is important. But it’s equally important to pay attention to fundamentals.”
You can read the full report here (no registration required).
[slides] #IoT and Medical Device Safety | @ThingsExpo #AI #DX #SmartCities
Consumers increasingly expect their electronic «things» to be connected to smart phones, tablets and the Internet. When that thing happens to be a medical device, the risks and benefits of connectivity must be carefully weighed. Once the decision is made that connecting the device is beneficial, medical device manufacturers must design their products to maintain patient safety and prevent compromised personal health information in the face of cybersecurity threats.
In his session at @ThingsExpo, Clark Fortney, Software Engineer at Battelle, discussed how designing safe connected medical devices begins with systematically analyzing cyber threats against desired functionality and making smart hardware/software architectural choices accordingly. Memory protection strategies, functional isolation, runtime checks, programming oversight, and vulnerability assessment testing are some of the key methods to increase the cybersecurity of a medical device, or any connected device that performs important functions.
Blockchain: Does Your Proof of Concept = Success? | @CloudExpo #Cloud #FinTech #Blockchain
We get it. If your company isn’t up on blockchain, your future is doomed. At least, that’s the general vibe industry leaders are putting out – scrambling to understand and utilize a framework that is more frequently associated with cryptocurrencies like bitcoin. In other words, block chain is, generally, poorly understood. So, should your company stand back and let it mature, or wade into the fray and hope for the best?
10 Secrets of @CloudExpo’s #DigitalTransformation Sponsors | #AI #DX #IoT #DevOps #FinTech
The best way to leverage your Cloud Expo presence as a sponsor and exhibitor is to plan your news announcements around our events. The press covering Cloud Expo and @ThingsExpo will have access to these releases and will amplify your news announcements. More than two dozen Cloud companies either set deals at our shows or have announced their mergers and acquisitions at Cloud Expo. Product announcements during our show provide your company with the most reach through our targeted audiences.
AWS aims at enterprise data migration with Migration Hub and Glue launches

At the AWS Summit in New York, Amazon Web Services focused predominantly around enterprise migration – and launched two new products aimed at taking the difficulty out of data analysis and transfer.
The cloud infrastructure giant announced the launch of AWS Migration Hub, a tool which aims to help organisations migrate their assets from on-prem data centres to Amazon’s cloud, as well as the general availability of AWS Glue, a product first announced in December last year which eases the process of moving data between data stores.
“Companies want to be able to fly from some of the constraints and break free from lock-in, and some of the relationships they have,” Adrian Cockcroft, AWS VP of cloud architecture, told attendees. “What we’ve been hearing from our customers is they want the freedom to build things quickly, unshackle from current database vendors, drive costs down, and have good ways to migrate out.”
This begat a discussion around relational database engine Aurora, AWS’ fastest growing product, which was launched in 2014. This time last year, AWS managed services partner Logicworks, writing for this publication, explained the reason for its success. “As cloud adoption matures, expect more companies to make a (slow) migration over to cloud-native systems,” the company wrote. “Because in the end, it is not just about licensing costs. It is about removing management burden from IT – and choosing to focus engineering talent on what really matters.”
More than 34,000 databases (below) have been migrated since the product’s launch; Cockcroft mentioned that he had given this talk a few times this year, and the number was continually being updated. An example of a company using Aurora to its advantage was Expedia, who performs 300 million writes a day on the engine, tracking how many hotel rooms are available across every hotel in the world.

When it comes to taking everything from a data centre – not just the greenfield apps, not even the mission-critical apps – then that was what AWS Migration Hub was for, Cockcroft added. The product is generally available today, hosted on AWS’ US West 2 zone in Oregon, but with a global reach.
Glue, on the other hand, is positioned as a fully managed data catalogue and ETL (extract, transform, load) service to take the fuss out of those “ubiquitous, and extremely tedious” workloads, as Dr. Matt Wood, general manager for artificial intelligence at AWS, put it.
Wood first riffed on the importance of AWS’ plethora of data handling tools, from the previously mentioned Aurora, to ElastiCache, to Redshift. “This approach, where we have a broad set of tools, each with a deep set of functionality, allows you to find the right tool for the job,” he said. “You don’t see Formula 1 engineers try and fix Formula 1 cars with Swiss Army knives.”
An example from Redshift Spectrum, which enables running SQL queries against exabytes of data in Amazon S3 was presented to the audience (below). Running a complex query against an exabyte dataset took Hive, running a 1000 node cluster, five years – obviously they made some estimates instead of letting it run its course – whereas Spectrum took just over two and a half minutes.

Wood said that up to three quarters of data scientists’ and data warehouse managers’ time was spent running ETL workloads. “Nobody goes to work in the morning and wants to write another ETL script,” he added. Through Glue, and its entirely serverless system and what Wood described as “by far the simplest UI [he had] ever shown to an audience of this size”, AWS aims for that to be a thing of the past.
Wood also discussed the machine learning projects being undertaken on AWS’ infrastructure. “The reason [machine learning] has started to stick in this iteration is that the cloud has enabled machine learning and customers to overcome the single largest point of friction, which is almost always around scale,” he explained. “Much like we did in the early days of AWS… we want to put this magical technology into the hands of every developer.”
Among the most interesting examples of the many companies exploring machine learning (below) were Stanford, who trained a deep learning model to help prevent diabetic blindness, Arterys, who has put together the first FDA-approved use of neural networks in medical imaging, and Wolfram Alpha. The latter, best known as the company to which Siri refers if she is stumped by a question, uses machine learning on AWS to build a computational knowledge engine. “When we’re talking about the challenges of handling inference at scale, with complicated deep learning models, this is the sort of scale you can achieve today through AWS,” said Wood.

Elsewhere, AWS announced a new customer in the shape of Hulu. The media company is moving away from its previous strategy of managing its own infrastructure and data centres – “everything we have, you name it, we built it” as the company put it to attendees – to help cover its various bets, from streaming content, to subscription systems, to live television.
“While we’ve experimented with cloud before, this became our first large scale production deployment,” said Rafael Soltanovich, VP of software development at Hulu.
“Building live TV is really hard, especially when you’re trying to do it in a radically different way,” he added, giving an example of just one of the issues Hulu had to sort out when rebuilding its entire tech stack. Take the Avengers film series based on the Marvel comic book characters, and the unrelated series of the same name, a 1998 film and the 1960s UK TV series. Having the right name, and the right image for each product, is vital to capture the attention of the viewer, Soltanovich said.

The recent Game of Thrones premiere was another example of Hulu’s nimble infrastructure in action; balancing between video on demand and live streams, between data centre and cloud, the company was able to normalise the load on its infrastructure to keep up with ‘massive’ user demand.
You can find out more about AWS Migration Hub here.
Picture credits: AWS/Screenshots
[slides] #IoT and Digitizing Operations | @ThingsExpo @RedHatNews @GHaff #AI #DX
Internet-of-Things discussions can end up either going down the consumer gadget rabbit hole or focused on the sort of data logging that industrial manufacturers have been doing forever. However, in fact, companies today are already using IoT data both to optimize their operational technology and to improve the experience of customer interactions in novel ways. In his session at @ThingsExpo, Gordon Haff, Red Hat Technology Evangelist, shared examples from a wide range of industries – including energy, transportation, and retail – of using IoT to create new business opportunities and improve efficiency.
Assessing the key reasons behind a multi-cloud strategy

Everyone who follows cloud computing agrees that we are starting to see more businesses utilise a multi-cloud strategy. The question this raises is: why is a multi-cloud strategy important from a functional standpoint, and why are enterprises deploying this strategy?
To answer this, let’s define “multi-cloud” since it means different things to different people. I personally like this one, as seen on TechTarget:
“the concomitant use of two or more cloud services to minimise the risk of widespread data loss or downtime due to a localised component failure in a cloud computing environment… a multi-cloud strategy can also improve overall enterprise performance by avoiding “vendor lock-in” and using different infrastructures to meet the needs of diverse partners and customers”
From my conversations with some cloud gurus and our customers, a multi-cloud strategy boils down to:
- Risk mitigation – low priority
- Managing vendor lock-in (price protection) – medium priority
- Optimising where you place your workloads – high priority
Let’s look at each one.
Risk mitigation
Looking at our own infrastructure at ParkMyCloud, we use AWS and other AWS services including RDS, Route 53, SNS and SES. In a risk mitigation exercise, would we look for those like services in Azure, and try to go through the technical work of mapping a 1:1 fit and building a hot failover in Azure? Or would we simply use a different AWS region – which uses fewer resources and less time?
You don’t actually need multi-cloud to do hot failovers, as you can instead use different regions within a single cloud provider. But that’s betting on the fact that those regions won’t go down simultaneously. In our case we would have major problems if multiple AWS regions went down simultaneously, but if that happens we certainly won’t be the only one in that boat.
Furthermore, to do a hot failover from one cloud provider to another (say, between AWS and Google), would require a degree of working between the cloud providers and infrastructure and application integration that is not widely available today.
Ultimately, risk mitigation just isn’t the most significant driver for multi-cloud.
Vendor lock-in
What happens when your cloud provider changes their pricing? Or your CIO says we will never be beholden to one IT infrastructure vendor, like Cisco on the network, or HP in the data centre? In that case, you lose your negotiating leverage on price and support.
On the other hand, look at Salesforce. How many enterprises use multiple CRMs?
Do you then have to design and build your applications to undertake a multi-cloud strategy from the get-go, so that transitioning everything to a different cloud provider will be a relatively simple undertaking? The complexity of moving your applications across clouds over a couple of months is nothing compared to the complexity of doing a real-time hot failover when your service is down. For enterprises this might be doable, given enough resources and time. Frankly, we don’t see much of this.
Instead, I see customers using a multi-cloud strategy to design and build applications in the clouds best suited for optimising their applications. By the way — you can then use this leverage to help prevent vendor lock-in.
Workload optimisation
Hot failovers may come to mind first when considering why you would want to go multi-cloud, but what about normal operations when your infrastructure is running smoothly? Having access to multiple cloud providers lets your engineers pick the one that is the most appropriate for the workload they want to deploy. By avoiding the “all or nothing’ approach,” IT leaders gain greater control over their different cloud services. They can pick and choose the product, service or platform that best fits their requirements, in terms of time-to-market or cost effectiveness – then integrate those services. Also, this approach may help in avoiding problems that arise when a single provider runs into trouble.
A multi-cloud strategy addresses several inter-related problems. It’s not just a technical avenue for hot failover. It includes vendor relationship management and the ability optimise your workloads based on the strengths of your teams and that CSP’s infrastructure.
By the way — when you deploy your multi-cloud strategy, make sure you have a management plan in place upfront. Too often, I hear from companies who deploy on multiple clouds but don’t have a way to see or compare them in one place. So, make sure you have a multi-cloud dashboard in place to provide visibility that spans across cloud providers, their locations and your resources, for proper governance and control. This will help you can get the most benefit out of a multi-cloud infrastructure.
Embracing Conflict to Fuel Digital Innovation | @ThingsExpo #DX #IoT #M2M #BigData
When talking to clients about their business goals, most business executives are pretty clear as to what they want to accomplish, such as reducing customer churn or reducing inventory costs or improving quality of care or improving product line profitability. But these “one dimensional” business initiatives really don’t push the organization’s innovative thinking. For example, I can easily reduce marketing costs if I significantly reduce advertising and promotional spending. Or I can easily improve product line profitability by cutting all marketing and advertising spending and laying off anyone not directly related to manufacturing and sell products.
The post Embracing Conflict to Fuel Digital Innovation appeared first on InFocus Blog | Dell EMC Services.