[panel] #DevOps & #DX | @DevOpsSummit @AndiMann #DigitalTransformation

New competitors, disruptive technologies, and growing expectations are pushing every business to both adopt and deliver new digital services. This ‘Digital Transformation’ demands rapid delivery and continuous iteration of new competitive services via multiple channels, which in turn demands new service delivery techniques – including DevOps. In this power panel at @DevOpsSummit 20th Cloud Expo, moderated by DevOps Conference Co-Chair Andi Mann, panelists will examine how DevOps helps to meet the demands of Digital Transformation – including accelerating application delivery, closing feedback loops, enabling multi-channel delivery, empowering collaborative decisions, improving user experience, and ultimately meeting (and exceeding) business goals.

read more

Puppet DevOps report shows wide gap between higher and lower performing firms

A new report from Puppet on the DevOps landscape has found a significant gap in productivity and results between the highest and lowest rating organisations.

The study, put together in conjunction with DevOps Research and Assessment (DORA) and which polled 3,200 respondents across multiple industries and with organisations of all sizes, found the highest performing organisations have automated 72% of all configuration management processes, spending 28% of their time in manual configuration processes. In contrast, lower performers can spend almost half (46%) of their time on manual configuration.

When it came to lead time for changes – in other words, moving from code commit to code successfully running in production, the highest performers have it down to less than one hour, with the rest managing between one week and one month on average. A big discrepancy there – and it shows again with deployment frequency as well as mean time to recover.

Medium performers, however, were distinguished between the lowest rubric in terms of change failure rate. For high and medium IT performers, the percentage of changes made which subsequently requires remediation is both between 0% and 15% on average, while for low IT performers the number rises to 31%-45%.

The research also examined how leadership affects performance, with high performing outfits sharing leaders with ‘vision’, ‘inspirational communication’, ‘intellectual stimulation’, ‘supportive leadership’, and ‘personal recognition’.

No surprises on the surface there, but the report notes how leadership is not enough to differentiate at the highest level. Teams whose leaders were in the top 10% were not the highest performers as a group, instead displaying varying performance. “Leaders cannot achieve DevOps outcomes on their own,” the report notes. “DevOps success also depends on a suitable architecture, good technical practices, [and] use of lean management principles.”

“The results of the 2017 State of DevOps Report show that high-performing IT teams are deploying more frequently and recovering faster than ever before, yet the automation gap between high and low performing teams continues to grow,” said Nigel Kersten, Puppet chief technical strategist. “The report will help organisations understand how to identify their own inhibitors and embrace change on their DevOps journey.”

“This year’s results clearly demonstrate that DevOps teams are achieving tremendous success by moving towards a culture of shared accountability and trust,” said Cameron Deatsch, head of enterprise growth at Atlassian. “Shifting an organisation’s culture can be difficult and requires the right knowledge, guidance and tools that encourage collaboration and visibility across teams.

“Thousands of customers rely on Atlassian as the foundation of their DevOps practices, providing collaboration across teams, a dedicated marketplace of integrations with leading DevOps tools, and most importantly, accelerating the evolution of their team’s culture.”

Puppet has been busy of late. The company said in May that it had added more than 250 new enterprise customers over the past 12 months, as well as announcing new offices opened in Singapore and Seattle, as well as an updated facility in Sydney. A recent report from Enterprise Management Associates (EMA) found that more than 90% of organisations are using DevOps practices in some capacity, but support production applications only a third of the time.

You can read the full Puppet report here (free, email required).

[session] Business Transformation in Banking and Financial Organizations | @ThingsExpo #IoT #M2M #FinTech

In his session at @ThingsExpo, Arvind Radhakrishnen will discuss how IoT offers new business models in banking and financial services organizations with the capability to revolutionize products, payments, channels, business processes and asset management built on strong architectural foundation.
The following topics will be covered:
How IoT stands to impact various business parameters including customer experience, cost and risk management within BFS organizations.

read more

Netskope Raises Another $100 Million

Netskope, a cloud access security broker, has raised $100 million in new funding. The Series E funding was led by its previous investors such as Lightspeed Venture Partners and Accel Partners. Along with these two investment firms, Social Capital and Iconiq Capital also participated. In addition, two new investors who had not participated in any Netskope’s previous rounds of funding also contributed and they are Sapphire Ventures and Geodesic Capital.

According to a statement released by the company’s founder and CEO, Sanjay Beri, this additional round of funding would be used to building its customer base. In the previous round, Netskope released $938 million, thereby bringing the total money raised to $231.4 million

Netskope has been fairly successful in raising money for its activities, with the first round coming in 2013 and worth just a paltry $21 million. These funding rounds reflect the rapid strides Netskope has made over the last five years.

One of the biggest reasons could be the fact that cloud security is a booming industry. With growing use of devices, the many access points for an application is greatly increased. For example, let’s say you use an internal app to log in to your workplace and maybe even log time to it. You’re likely to see it from your desktop at work, your laptop at home and maybe even from your smartphone and tablet while on the move. This means, there are four access points to that app and a security vulnerability can come from any of it.

These multiple access points are one of the important reasons for the many hacking incidents we’ve seen over the last few years or so. Also, the emergence of different services such as SaaS, PaaS, IaaS and IDaaS are adding to security problems. To tackle the growing complexity of security head-on, Netskope has been working on a standalone security platform.

Existing systems and security practices don’t work well with cloud simply because it’s growing and becoming more integrated and complex by the day. This is why Netskope has come up with a unique principle that’s called “privacy by design.” This principle gives you the flexibility to track and identify specifically what you want such as a set of specific apps or documents instead of analyzing every bit of information that passes through your network, which is truly impossible. You can set keywords and create other security policies that will allow you to have a better control over your network and that’s exactly what Netskope aims to achieve with its platform. It has already secured this idea with more than a hundred patents.

That said, Netskope is not yet profitable and continues to depend on investors for its everyday operations. So, it’ll be interesting to see how much it’s able to translate its ideas into monetary value when it finally releases its platform to the world.

Until then, it’s a wait and watch game for investors and for the general public. There is also some skepticism in the industry circles about security products because none of them have really made the impact they claim to make. Let’s hope Netskope can change this barrier.

The post Netskope Raises Another $100 Million appeared first on Cloud News Daily.

Netskope raises $100m in series E round, aims to move security platform beyond the cloud

Cloud security provider Netskope has announced the close of a $100 million (£77.5m) series E funding round to press ahead with its go to market strategy as well as explore new ventures.

The round, which brings Netskope’s total funding to $231.4 million, was led by Lightspeed Venture Partners and included contributions from existing investors Social Capital and Iconiq Capital, as well as new participation from Sapphire Ventures and Geodesic Capital.

Among the upcoming projects for the company, best known for its cloud assess security broker (CASB) software, includes the first public mention of what is being described as ‘Netskope for Web’, an advancement of the security platform beyond the cloud aimed at being pushed out later this year.

“This announcement really is just a reinforcement of the notion of building the definitive leading cloud security platform,” Sanjay Beri, Netskope CEO, told CloudTech. “The fact [the round] is led by existing investors is a great thing. It was oversubscribed, and for us, we haven’t gone out fundraising per se ever – we’ve had the luxury of a lot of external folks wanting to invest in the company.”

Netskope’s modus operandi is around offering a different solution to securing assets and data in the cloud. Beri describes it as delivering ‘the absolute best architecture and product that would allow enterprises to tackle the problem the way it should be’. To paraphrase the adage about lipstick and porcine creatures, if you put lipstick on legacy security tools, it’s still not going to understand the language of the cloud, or APIs.

Whether it’s the SaaS of Salesforce, Box, Office 365 et al, to the primary IaaS and PaaS of AWS, Google and Microsoft, Netskope aims to have organisations covered through data loss and threat protection, encryption, and more. The company’s next plan is to advance it from the cloud to the whole web. “[It’s] the ability and savviness to understand the way that people work now and the way that applications are built now bringing it to the entire web, not just the cloud,” said Beri, “so one of the things this funding continues to fuel us to do is advance that platform to continue to realise the vision of the definitive cloud security platform.”

Netskope says that it had seen an uptick in 2016 of ‘leading enterprise customers in the retail, financial services, manufacturing, energy, and healthcare verticals’. With customers including Toyota, Genomic Health, and the City of San Diego on the books, Beri mused on where different industries are in their cloud journeys.

“I think you should cut at it two ways – geography and then vertical,” he said. “As the market has moved, what you see now is the largest healthcare, life science companies in the world all using cloud.

“Healthcare is definitely a strong vertical,” Beri added. “When you look beyond retail, most every single retail company in the world is leveraging cloud. They want to focus on their core business and they don’t want to build infrastructure. The cloud lets them enable that remote working, large distributed workforce, and yet they’re worried about protecting customer data, protecting financial data and so on.

“[It’s] the same thing with financial and insurance – you think they’d be the laggards but some of the largest financial institutions in the world are Netskope customers, and they’re leveraging cloud, not only because their end users want, but because it’s a corporate strategy now. It’s a competitive advantage, if you can leverage these properly.”

The geographical discussion naturally beget a look at GDPR, of which the one year countdown for compliance passed last month. Netskope has previously warned companies to get their act together – fines of €10 million or 2% of annual turnover – while Beri calls the process a ‘seesaw’.

“For anybody who wasn’t taking it seriously, it’s going to hurt your business if you don’t now, and I think what a lot of enterprises are realising is that with GDPR coming, they need the next level of visibility and ability to control where their data goes, who uses it, and how it’s exposed,” he said. “One of the keys we focus on at Netskope is how you enable companies to move forward, be productive, leverage the applications that they want, yet at the same time, how you put guard rails around their usage so you’re not going to be able to for example leak EU customer data, or put yourself at risk of violating GDPR.”

It’s a good analogy for their whole ethos. 

[session] Open Analytics | @CloudExpo @ProgressSW #AI #ML #DX #Analytics

Cloud applications are seeing a deluge of requests to support the exploding advanced analytics market. “Open analytics” is the emerging strategy to deliver that data through an open data access layer, in the cloud, to be directly consumed by external analytics tools and popular programming languages. An increasing number of data engineers and data scientists use a variety of platforms and advanced analytics languages such as SAS, R, Python and Java, as well as frameworks such as Hadoop and Spark. Cloud APIs are commonly designed to support application integration representing a disconnect with the analytics ecosystem. These combined trends create significant demand for a “bring-your-own-analytics” (BYOA) capability for cloud applications.

read more

A deeper dive into cloud security as a service: Advantages and issues

In a recent article which focused on cloud security I presented a comparison between security-as-a-service and traditional style security tooling in the cloud. This installment is a deeper dive into the security as a service (SECaaS) paradigm.

It would seem to me that a natural outgrowth of the cloud computing and ‘everything as a service’ paradigm that the technology world is undergoing, would be that the tools and services we use to manage and secure our cloud environments also move into an ‘as a service’ mode.

In much the way one would expect, SECaaS works under the principle of a small agent controlled from an external service provider. It is not so different conceptually from controlling a number of firewalls (virtual or physical) from an external management console.

Here’s how it works. A security administrator sets the policy for the service in the SECaaS provider cloud, using online management tools, and sets what policy or policies applies to a group of VMs classified by any number of criteria.

Then, the SECaaS services governs the security activity within and around the VM via a lightweight, generic, agent installed within the VM. When a new VM is created out of a template the agent is included in the image.

Finally, the agent executes various security functions according to the direction/policy communicated from within the provider’s cloud environment.

For example, the security administrator creates a segmentation policy that all webserver VMs will only accept traffic on ports 80 and 443. The administrator creates a policy in the SECaaS cloud which is transmitted to the agents on all webserver VMs in the environment. The agent then acts to block and/or allow traffic as per this and other policies that apply to this type of VM.

Advantages

The advantages of using a SECaaS solution include:

  • Increased agility. As the number of VMs expands contracts or moves (between physical facilities, and possibly cloud providers) the security level is maintained. This is because SECaaS agents are generally configured to reach back to the ‘mothership’ on activation.
  • Reduced complexity. No need to deploy lots of different security tools into the environment and thereby add complexity.
  • Security staff. In 2016, according to ESG Research, 46% of organizations reported a shortage of cyber security skills in their staff. SECaaS solutions can help to increase the skill sets of junior security administrators by providing a single pane of glass view of the security functions within the environment. SECaaS providers are working towards making policy setting tools more intuitive, thus making it easier for a limited size and/or skilled staff to be more effective.
  • Consolidated control. Offloading of security policy creation and security management to a consolidated management point, that itself is managed and secured by a trusted external partner. This requires that trust and partnership be present in the relationship with the SECaaS provider. 

Issues

  • Most SECaaS providers offer services that control a limited set of security functions such as identity and access management (IAM), segmentation, threat detection, anti-virus, vulnerability analysis, and compliance checking. Issues can arise when multiple providers are selected for parts of an overall solution. This leaves the VM stuffed with various distinct agents, reintroducing complexity, lowering agility as well as lowering manageability. The solution to this issue is to seek out those few providers that are reaching for a comprehensive approach. For example CloudPassage Halo  and TrendMicro AWS Defender provide much more comprehensive solutions than many others.   
  • Currently no SECaaS services that I have found provide support for serverless or micro-services environments. With the rapid rise in these types of cloud application hosting environments this will become a critical distinguishing factor in an organisation’s decision to use SECaaS technologies. As more providers enter the SECaaS market it is assumed that the needs of these types of environments will be addressed.

Conclusion

As more organisations continue to adopt and move to the public cloud it becomes even more critical to secure those environments, applications and services. SECaaS providers continue to enhance their offerings and continue to add specific security services to their portfolios. As SECaaS matures it becomes an even more viable option for securing enterprise public and hybrid cloud deployments.

Read more: Cloud security best practice: Security as a service or cloud security tooling?

[session] @VodafoneIoT to Present at @ThingsExpo NY | #AI #DX #IoT #M2M

In order to meet the rapidly changing demands of today’s customers, companies are continually forced to redefine their business strategies in order to meet these needs, stay relevant and continue to see profitable growth. IoT deployment and development is integral in this transformation, and today businesses are increasingly seeing the value of investing their resources into IoT deployments. These technologies are able increase ROI through projects such as connecting supply chains or enabling smart office capabilities for employees.

read more

Why Cloud Backup?

Losing data due to a system failure is probably each one of our worst nightmares. How many times have we worried if our data will be safe for us to continue working the next day? How many sleepless nights have we spent worrying about it?

Well, technology, specially cloud, is our savior again.

Cloud backup is a service that allows us to store our data in a public or private cloud, located far away from our physical premises. There are many advantages that come with it, some of which are:

  • Automatic – This is one of the biggest advantages of cloud backup, as the backup process happens automatically without any intervention from your end.
  • Protection against natural disasters – When a disaster strikes your city and your infrastructure is unfortunately damaged, you can rest assured that your data is safe because it’s stored in a different location, sometimes even in a different continent.
  • Affordable – Cloud backup is a lot cheaper than on-premise data centers that require heavy investment, right from setup to everyday maintenance.
  • Anytime access – With cloud backup, your employees can access data at anytime and from anywhere, as long as they have Internet connection.
  • Simple and hassle-free – Cloud backup is a simple and hassle-free process. It requires no prior technical knowledge and works well for all kinds of employees.

These advantages have made cloud backup one of the most preferred backup options today.

Let’s now look at a few subscription-based cloud backup options available today.

Acronis

Acronis, headquartered in Switzerland, is a company that specializes in cloud software for backup, disaster recovery, data access and file share. Last week, it announced the release of its latest version, Acronis Backup 12.5.

The company believes that Acronis Backup 12.5 is one of the fastest, reliable and most economical solutions in the market now, thereby giving customers excellent value for their money.

With a unified web interface, family data protection, support for local and cloud storage, rescue bootable media, support for six hypervisors, SAN storage snapshots, backup validation and more, Acronis Backup 12.5 is definitely one of the top contenders in the cloud backup industry.

Crashplan

Crashplan is another good choice that comes with good security options and virtually unlimited versioning. Probably, the most salient feature of this service is its slick and user-friendly interface that makes it super easy to backup all your content.

Backblaze

Backblaze is an economical cloud-based backup solution that’s easy to setup and offers unlimited backup storage with little to no input from you. Once you configure the services, it runs in the background automatically and you can simply forget about it.

SpiderOak

For privacy enthusiasts, SpiderOak is a good choice as all your data is encrypted and only you have the keys to decrypt it. Also called as zero-knowledge provider, this offers complete protection, besides other cool features.

Carbonite

If you’re looking for a backup solution with well developed mobile apps, Carbonite is a good choice. It’s continuous backup feature combined with good security features make it a popular choice.

Regardless of which service you choose, make sure you back up your data to avoid sleepless nights.

The post Why Cloud Backup? appeared first on Cloud News Daily.

90% of firms using DevOps in some capacity – but production applications well down

More than 90% of organisations polled by Enterprise Management Associates (EMA) say they are using DevOps practices in some capacity, yet they only support production applications only a third of the time.

The study, titled ‘DevOps/Continuous Delivery Tooling: Launchpad for the Digital Enterprise’, looks at the current state of software delivery and related tooling and summarises the results. The company argues that integrating and sharing metrics and data between diverse toolsets, via APIs, integration hubs, or both – need to be central to making product selections.

The primary focus areas for digital business initiatives include customer satisfaction, ‘using technology to match competitors’ digital presence’, and ‘faster time to innovation’, according to the report, although there were ‘significant’ differences in responses among small, medium and enterprise businesses.

The rubric sets out the rationale for the report. “Yesterday’s toolsets and support practices – in which tools relied heavily on human expertise and manual processes – are no longer viable,” the company notes. “At the same time, designing, developing, deploying and supporting complex modern application environments requires collaborative decision-making supported by a new level of cross-functional skills, knowledge, and judgment.

“Surmounting these challenges to embrace the requirements of a new era requires changes to mindsets, skill sets, and tooling.”

This aligns with various pieces of research around DevOps. According to a study from Sumo Logic back in March, more than two thirds of enterprises either plan to adopt DevOps or are already doing so, while in the same month Quali found that almost half of applications in traditional environments were considered complex for cloud.

“As the pace of business continues to accelerate, coordination across DevOps processes, practices, and tools becomes increasingly important,” said Julie Craig, research director of application management at EMA. “This research provides valuable insights into the ways in which high performing IT organisations are accelerating delivery of key business services and, in doing so, impacting the business bottom line.”