The great telephone switch-off


Barry Collins

21 Sep, 2021

The telephone network that we’ve relied on for decades is coming to an end. The UK’s public switched telephone network (PSTN) is being shut down in 2025, and traditional telephony products will stop being sold in as little as 18 months’ time.

The closure puts on notice everything from your home landline to the office phone system, from burglar alarms to traffic lights. They’ll all need to be migrated to digital technology within the next few years or they’ll stop working. ISDN lines are another casualty.

We’ve spoken to the person responsible for managing the switch-off and other industry experts to find out precisely what effect this will have on businesses – and why you need to start planning now for the great British switch-off.

What’s being switched off?

Although the switch-off hasn’t been widely publicised yet, there’s already some confusing, contradictory and wrong information being distributed about what’s being switched off, so let’s try and get to the bottom of it.

By far the most critical pieces of infrastructure to go are the phone lines. By 2025, every phone line in the country will be IP-based, instead of running over the traditional PSTN. That means the landline phone plugged into the wall will be redundant by 2025 (although some communications providers may offer workarounds, which we’ll come to).

The shutdown won’t only affect phone systems; it’s also going to affect any piece of tech that relies on a traditional phone line, including emergency phones in lifts, panic alarms, information displays, door-entry systems, CCTV and EPOS payment terminals.

“It’s a pretty big challenge,” says James Lilley, director of managed customer migrations at Openreach, who is overseeing the switch-off. “There are all sorts of what we call ‘economy special services’ that hang off that network,” he adds, referring to the devices fitted with telephone lines mentioned above. “They’re the ones that probably give us the biggest challenge in terms of migration and moving them over the coming years.”

Hanging up on the landline

Before we get onto that compendium of tech that hangs off the PSTN, let’s deal with telephones themselves. For home customers, James Lilley says that the providers currently supplying phone and internet services will deliver solutions to allow customers to keep using their existing handsets.

“What we’re seeing most communications providers do now is include analogue converters in their [internet] hubs,” he says. “So, you can take that same handset, and instead of plugging it into the wall, you plug it in the back of your router. Essentially, that will convert you to digital voice over the router.” Existing telephone numbers will be ported to a new VoIP system.

Business telephone systems, however, are a great deal more complicated than home landlines, and few companies have much expertise and experience in upgrading and managing them. After all, it’s perfectly likely that many small businesses had a PBX installed a decade or two ago and have barely touched it since. Some telephone systems will still be based on ISDN lines, which are also facing the chop in 2025.

Research conducted by Zen Internet shows that 72% of businesses are reliant on traditional telephony, more so in large enterprises. Yet the research also found that a third of SMEs were unaware of the future switch-off, with 17% of large businesses still in the dark.

Alex Bloor, general manager at Andrews & Arnold (A&A), says that the PSTN switch-off is a good opportunity for businesses to take advantage of the benefits that IP telephony brings – indeed, most of his company’s customers already have. “Our customers are either businesses with phones on desks, in which case they typically want something designed for purpose – and there are some really great, fairly cheap VoIP handsets by companies like Snom,” he says.

“Or, we have customers who put one of our SIP2SIM cards in a mobile phone,” he adds. SIP2SIM basically allows a customer to insert a SIM card in any mobile phone (not even necessarily a smartphone) and have it work like an office phone that’s tied to your desk. When you call out from the phone, it appears with the firm’s geographical “landline” number.

Zen Internet’s Jon Perkins says the company has stopped selling traditional telephony products to business customers, and is focusing on helping them prepare for the switch. “We’re signalling what’s coming and when, and giving them solutions,” he says. “And we’re often taking a bit of a margin hit, so we’re investing ahead of time to avoid what could be a much bigger risk. There’s a [cost] incentive to move customers off traditional copper-based voice services onto digital.”

That incentive applies to the company’s customers too, says Perkins, with customers able to buy a chunk of call minutes much more cheaply than traditional phone tariffs. “You generally save a lot of money [on calls],” he says.

As for ISDN, that was already a diminishing force in businesses, and the events of the past 18 months have given it a further shove towards obsolescence. Perkins describes his company as “exhibit A” for such a migration, having moved from an ISDN call centre to a hosted VoIP platform when its 200 customer support staff suddenly had to start working from home. “Lots of other call centres and colleagues in the telecoms industry have shared the same experience,” he adds.

ISDN’s diminishing customer base means it will barely be a problem in 2025, but there’s one area where it’s stubbornly clinging to life, and that’s in the “specials” market such as bus shelters, traffic lights and other utility devices that are going to prove more stubborn to shift.

The long tail

This brings us to those hard-to-budge devices we mentioned earlier: the burglar alarms, lift phones, panic alarms, traffic lights and all those other devices that rely on an old-fashioned phone line to call home.

Openreach’s Lilley admits that this huge swathe of non-telephony devices is going to pose the biggest challenge, but measures are in place to ensure a smooth migration. “We’ve got people coming into the tent now from a lot of trade bodies, representing a lot of the industries that use this network – like the alarm industry, the water industry and some of the utilities,” he explains. “They’re increasingly working with us to make sure that they’re messaging out to their suppliers the need to make sure that their equipment is compatible with IP.”

Lilley admits that “there will come a point in time where we need to switch this network off and, if customers haven’t migrated, there will be some tough choices to make”.

“The key thing is when we look at the critical stuff like health pendants, for example… they’re the ones we really, really need to make sure as an industry that we’re identifying and having the right migration policies and support in place for in the coming years.”

Some industries are better prepared than others. Barry Forsyth owns alarms business InstallSmart and points out that his industry has already migrated many alarm systems to either cellular or IP-based systems. “If your alarm was fitted by an accredited installer, they should have been proactive and upgraded those systems to a different signalling path,” he says.

However, he acknowledges that there will still be instances where business owners have ignored messages urging them to upgrade, or where alarm fitters have gone out of business. He’s particularly concerned about fire alarms, as there could obviously be life-or-death implications if they’re not upgraded before PSTN is switched off.

At the same time, Forsyth warns consumers and businesses to be wary of alarm companies using the PSTN switch-off as an excuse to sell an entire new alarm system when only the control box needs replacing. “I can’t think of a product that wouldn’t be upgradable [to cellular or IP signalling],” he says.

One solution for many products still relying on PSTN is similar to what will happen with domestic phone lines – an analogue telephone adapter (ATA) will be used to connect them to the digital network. “I suspect we’ll see a lot of emergency panic-button pendants hastily plugged into ATAs with weeks to spare until the deadline in 2025, and some will work and some might not,” says A&A’s Alex Bloor.

Inevitably, there will be some legacy products that haven’t been upgraded when the switch is finally flicked in 2025. “I strongly suspect there will be cases when someone gets trapped in a lift and stuck there all night… or when an old person trips over and presses the button, and nothing happens,” says Bloor.

“We may well hear some of these stories, but on the other hand, I wouldn’t use that as a stick to beat up BT with. Ultimately, we all knew that the days of PSTN were numbered when VoIP really started to take hold. It’s just one of those things. It’s been a hundred years, for goodness’ sake!”

Five minutes with… Petr Janda, Pleo CTO


Adam Shepherd

14 Sep, 2021

Data is transforming virtually every industry, but arguably it’s the financial services sector that’s most heavily invested in building data-driven decision-making into its processes. For business expense management platform Pleo that’s a core strategy, and it informs much of the company’s IT investment. 

There’s a lot of investment to inform, too. The company recently broke records with a $150 million Series C funding round, the biggest in the history of its native Denmark. We asked CTO Petr Janda why data is such a priority for Pleo, and what challenges the organisation is hoping to overcome with it. 

What does your core infrastructure currently look like?

We’re leaning into a multi-cloud strategy. What that means is that we have a combination of different vendors: our core operation systems are running in Amazon Web Services, and we complement this with a data ecosystem from Google Cloud, so we’re operating across the two.

When it comes to going a step deeper, we’re staying away from bare metal, or even virtual machines: everything we deploy is containerised and managed by Kubernetes, which is standardised across all the back-end systems. That means that we offload a lot of management of the system onto cloud providers, and focus a lot more on the individual pieces of code we ship into them

On top of that, we’re very keen to make sure that we offload management of state. Anything that stores data, we ideally don’t want to host ourselves, even within our clusters. We make use of the solutions the cloud vendors have for us, be it managed Postgres databases or Google’s BigQuery. If something bad happens, we hope that these big tech companies with thousands of engineers should be able to solve it very quickly.

What’s your biggest priority within the business?

It’s the same as everyone else in the C-suite: we all focus on the customer, and how we can solve for them. For me, it’s about how we build a technology organisation that’s able to ship solutions and put products in front of the customer at a healthy pace. What I mean by that is, we can innovate as a company this year, but we have to be able to keep up a similar pace in a year or two, or three years from now. 

This, of course, is not trivial. If we focus too much on today’s world, we might be making things harder for the future. On the other hand, if you optimise too much for the future, you might be over-investing in areas where it’s not necessarily needed. We try to find a good rhythm, of innovating our current products whilst also building a long-term platform or infrastructure. At the core of that is balancing technology investments: I spend a lot of time focusing on how we design the organisation, and choosing the right initiatives to maintain this ability.

Which piece of technology would you say is most critical to achieving this?

I don’t think there’s a single piece which allows us to do that. It’s almost like, how does this system holistically work? How can we design a portfolio of services and a platform which allows us to build these products on top of that?

I guess one way to look at it is that, because we’re a financial institution, there’s quite a lot we have to do just to get the product in front of our customer. On one side, you have the parts of the platform that deliver the experience to the user, from the mobile app to a variety of web interfaces. But behind the scenes there is also a lot of infrastructure that has to integrate with the wider payment ecosystem, so we can effectively move money.

And behind all that there are additional building blocks: we have to comply with all the regulations, which are getting stricter as we go, and can differ across different markets. So there’s a lot of technology solutions and integrations we have to do to empower that. None of these pieces are crucial in isolation; solving in all these different levels is what allows us to innovate.

Do you have any preferred technology vendors that you especially invest in?

Enfuce is our payment processing provider – essentially our integration point between Pleo and the card networks, which is, of course, a central part of what we do. For anything else, we go in with an open mind. You can almost always find a solution from Amazon and Google – they have such a vast portfolio of products, servicing a very broad range of use cases. But we might also try to find more specialised vendors who have a deeper focus on the particular problem.

In a sense, we don’t really have a preference. We look at it as, okay, this is a problem, we need to solve it. Who are companies who play really well in this field? And how can we leverage that to push the product forward?

What’s the biggest IT challenge you’re currently facing?

Almost every company goes through a journey. When you’re an early-stage startup founder with, let’s say, a team of 10-15 engineers, you can get the sense of everything and manage that team as one. But as you scale beyond that point, you have to start to organise it more, and break it into smaller teams, which ship on a variety of different work streams.

That’s what Pleo has done. We have our portfolio of products, which we’re releasing to the market, and about 80 engineers, working across a number of teams. We’re now thinking more about how we can essentially create a platform on top of which all these things work.

One way you can look at it, of course, is the cloud infrastructure provided by Amazon and Google, and a layer of management on top of that, which we’ve already built inside of our team. But what I’m especially looking into is, how can we layer more reusable services on top of that, so they’re available to any team out there building Pleo’s applications?

What I see as the biggest challenge is that there’s about 13 teams running really fast, iterating and shipping to the market, and we kind of want to slot this platform under all of them as we go. There is no “let’s stop for six months, do this and then continue”. We want to find good initiatives, good technology solutions and good projects to take us towards that vision, while continuing to ship at a very fast pace, all the time. That is a big challenge for me.

Which part of your IT estate are you proudest of?

It’s hard to pick, but one thing worth mentioning, is our compliance solution, which gained us recognition from by one of the banks in Denmark – Danske Bank, I believe.

Essentially, when we onboard customers we’re required to disclose quite a lot about the client, such as the ownership structure of companies. Many fintechs handle this through partnerships and integrations with external parties, and there are a lot of great solutions out there. But doing it this way locks you a little bit into their way of thinking, and shapes the experience you can have on top of it. 

Early in Pleo, it was decided that compliance would be a key piece of our in-house tech estate. We built our own system which connects to a number of company registries, and helps us to model the compliance process and requirements into the technology stack. This then lets us build a different experience when working with the company going through onboarding.

Essentially, the idea is to minimise the work and input needed from clients, and from our employees inside Pleo. We lean into the technology, promoting the image of a company with automated data systems behind the scenes. And we believe it’s paying off, with stronger and more productised onboarding journeys. It’s definitely something we’re very happy with.  

What’s the next big project you’re planning?

This platform is a little bit of a moving target. We draw inspiration from companies like Spotify and their Backstage product, which essentially looks like an app for engineering teams, allowing you to spin up new services and infrastructure as needed. It almost feels like a product itself.

But if I had to point to one specific step we’re taking in this direction, it would probably be focusing on data. The organisation is growing very quickly, and without conscious effort we risk losing track of what is going on in the company, and how the different corners of the company relate to each other.

We see our data as the key to solving that. Data helps us to convey context from one side of the organisation to the other. We have a number of teams interacting with the customer on their journey to Pleo – from marketing, sales and customer success to the product and support teams – and we really want them to have a singular view of the customer, to provide the right data points to the relevant teams as they are interacting with the customer.

I see that as part of this overall platform – a big building block which is essentially our data ecosystem. We’re adopting this trend of a modern data stack, which essentially means building a platform which is provided as infrastructure to the rest of the organisation. The goal is to enable everyone to ingest data to the central data warehouse, which makes it interoperable, and there’s a number of discovery and quality aspects we’ve built on top of that. We basically allow a group of analysts to model the business and then distribute data back to different corners of the organisation.

If we nail this platform our teams will be able to work in a much more unified way, because they can look at the data and understand where this customer is coming from. “What just happened for them 30 seconds ago within the product, and how can I help them?”

Are you a Windows, Mac or Linux user?

My computer at home is a Mac, and I interact with Linux on our servers in one way or another. I’m trying to remember when I last used Windows… it’s probably 15 years ago, which I guess gives you the answer.

In the last ten years, what technology has made the biggest impact on the IT industry, and why?

I recall a time when I was building some systems for a customer, and I had to open an FTP terminal and move the files to the server. Looking back, it wasn’t the greatest experience. When I think of what we do today, shipping very large and complex systems relatively easily, I see it all as a massive journey. We have everything we need literally at our fingertips, and it’s powering innovation, because any company who adopts these cloud solutions has an almost endlessly scalable environment in which to operate.

If I dive one step deeper, I’m very passionate about data systems. Our cloud data warehouse, first starting with Redshift on AWS and later being pushed forward with BigQuery, feels almost like magic: I throw a lot of data in, and I start querying, and there are no indexes, no management of “how do I start today?”

I see data as the next wave, pushing the boundary of how much easier it’s becoming for companies to work without large teams of data engineers and custom pipelines between tools. That ecosystem is growing really quickly. And if you combine the cloud itself with the data aspects of solutions that are built on top of that, it’s a very interesting playground where products can be built far faster than 10 years ago.

Oracle launches free cloud training


Danny Bradbury

9 Sep, 2021

Oracle is offering free worldwide training and certification in its Oracle Cloud Infrastructure. Learners now have free access to the company’s entire learning curriculum across all skill levels. 

The training catalog includes courses at all levels across a range of IT roles, the company said. It includes preparation courses and practice exams to prepare people for testing and gives learners access to live sessions and personalised feedback. Career resources will also help people to secure jobs with their Oracle Cloud Infrastructure skills. 

The online courses are available on demand in 13 languages. They include hands-on labs so learners can test their skills in a simulated production environment. 

While the cloud training is available at no cost indefinitely, there is a time limit on the free certification. Learners can only get certified from the Oracle University for free until December 31. 

Launched in 2016, Oracle Cloud Infrastructure is the company’s cloud computing service. It offers infrastructure, platform, and software as a service (SaaS) options. It also offers Oracle Data Cloud, which offers analytics services. 

The company’s cloud service hasn’t seen the same traction as its competitors. Gartner placed the company in the “niche players” section of its latest public cloud infrastructure magic quadrant behind Alibaba Cloud. Google, Microsoft, and Amazon Web Services sat in the “leaders”’ section. Synergy Research Group placed the company eighth in market share terms based on its Q2 2021 research.

Oracle also lost its bid for the Pentagon’s since-disbanded JEDI cloud computing contract. 

Last year, German company Union Asset Management AG sued the software giant for allegedly misleading the market on its cloud revenues and bullying customers into cloud migrations with a strategy called Audit, Bargain, Close. 

This isn’t the first time Oracle has run free training. It also offered free Oracle cloud courses in spring 2020. 

​

Azure Container Instances users urged to ​​revoke privileged credentials after flaw discovery


Sabina Weston

9 Sep, 2021

Microsoft’s security team has urged Azure Container Instances (ACI) users to revoke any privileged credentials deployed to the platform prior to 31 August.

The advice comes as Palo Alto Networks discovered a vulnerability, which has since been fixed, within ACI which made it possible for hackers to ​​obtain user data.

Dubbed Azurescape, due to the escape method being uncovered in Microsoft’s Azure container as a service (CaaS) platform, said a spokesperson for Palo Alto Networks.

“This type of cross-account takeover represents a new attack vector that hackers can use to target cloud services. We expect that more vulnerabilities will be discovered that enable cross-account takeover,” the spokesperson told IT Pro.

Azurescape was discovered by Unit 42 researcher Yuval Avrahami, who reported it to Microsoft and was awarded “two bug bounties” for an undisclosed amount.

No evidence was found suggesting that the flaw was exploited, according to the Microsoft Security Response Center team.

“There is no indication any customer data was accessed due to this vulnerability. Out of an abundance of caution, notifications were sent to customers potentially affected by the researcher activities, advising they revoke any privileged credential that were deployed to the platform before August 31, 2021,” they stated.

However, lack of evidence doesn’t exclude the chances that a data breach happened. Microsoft didn’t confirm whether it was confident no data had been accessed, according to Reuters.

The tech giant told ACI customers that if they hadn’t been notified, “no action is required”.

“If you are unsure whether your subscription or organisation has received a notification, please contact Azure Support. If you have any concerns, rotating privileged credentials is a good periodic security practice and would be an effective precautionary measure,” it added.

The advisory comes weeks after thousands of its Azure customers had their main databases compromised. Affected customers included some of the world’s largest companies, according to cyber security researcher Wiz, and was dubbed “the worst cloud vulnerability you can imagine”.

Microsoft had since fixed the vulnerability, at the time saying that there was no evidence the flaw had been exploited. The tech giant had reportedly agreed to pay the security researchers $40,000 for finding the flaw and reporting it.

IBM unveils next-gen Power10 server for hybrid cloud


Bobby Hellard

8 Sep, 2021

IBM has announced a new Power E1080 server, the first in a new family of servers based on its 7nm-developed Power10 processor that has been specifically designed for hybrid cloud environments.

The IBM E1080 server has been engineered to be one of the most secure server platforms, according to IBM, with an architecture to help users operate a frictionless hybrid cloud experience across their IT infrastructure.  

«When we were designing the E1080, we had to be cognizant of how the pandemic was changing not only consumer behaviour, but also our customer’s behaviour and needs from their IT infrastructure,» said Dylan Boday, VP of product management for AI and hybrid cloud. 

«The E1080 is IBM’s first system designed from the silicon up for hybrid cloud environments, a system tailor-built to serve as the foundation for our vision of a dynamic and secure, frictionless hybrid cloud experience.»

The E1080 has several «key» features, which includes by-the-minute metering of Red Hat OpenShift and Red Hat Enterprise Linux with architectural consistency and cloud-like flexibility across the entire hybrid cloud environment.

There are also hardware-driven performance improvements that deliver up to 50% more performance and scalability than its predecessor the IBM Power E980, according to IBM. 

It also features new security tools, such as transparent memory encryption that requires no additional management setup, a robust ecosystem of ISVs, business partners and security software for every level of system stack. IBM is also launching a tiered «Power Expert Care» service to help clients as they protect their systems against the latest cyber security threats.

«Our collaboration with IBM on Power10 will serve as a continuation of this commitment to support a broad range of architectures,» said Stefanie Chiras, senior vice president of Red Hat’s platforms business group.

«As an architectural foundation for Red Hat Enterprise Linux and Red Hat OpenShift deployments on-premises metering, IBM Power will offer the scale and flexibility to help customers realise the benefits of open hybrid cloud.»

Automated hiring systems are rejecting qualified candidates


Zach Marzouk

7 Sep, 2021

Automated hiring systems filter out qualified high skilled workers, according to a Harvard Business School report focused on how leaders can improve hiring practices to uncover missed talent pools and close skills gaps. 

Researchers found that inflexibly configured automated recruiting systems, which are “designed to maximize the efficiency of the process”, tend to hone in on candidates using very specific parameters to minimise the number of applicants that are actively considered by an organisation.

“For example, most use proxies (such as a college degree or possession of precisely described skills) for attributes such as skills, work ethic, and self-efficacy,” researchers stated in the report. “Most also use a failure to meet certain criteria (such as a gap in full-time employment) as a basis for excluding a candidate from consideration irrespective of their other qualifications.”

As a result, this excludes from consideration viable candidates whose resumes do not match the criteria “but who could perform at a high level with training”. 88% of employers who took part in the survey agreed with this statement, admitting that qualified high skilled candidates are vetted out of the process as they don’t match the exact criteria established by the job description. The number rose to 94% in the case of “middle-skill” workers.

Researchers found that automated systems represent the “foundation of the hiring process” in the majority of organisations, with 90% of employers in the survey using automated systems to “initially filter or rank potential middle-skills (94%) and high-skills (92%) candidates”.

The report also found that the rapid pace of change in many occupations, driven in large part by advancing technologies, has made it “extremely difficult for workers to obtain relevant skills”. 

“The evolution in job content has outstripped the capacity of traditional skills providers, such as education systems and other workforce intermediaries, to adapt,” said the report, highlighting that to develop the capabilities employers seek increasingly requires the candidate to be employed.

To deal with these problems, the report recommended refreshing job descriptions, shifting from “negative” to “affirmative” filters in automated recruiting systems, establishing new metrics for evaluating talent acquisition, and enlisting a senior leader to champion, direct, and monitor the evolution of hiring and onboarding practices.

HBS’s global study included a survey of over 8,000 “hidden” workers, those who miss hours, unemployed and seeking work, or those who are not working or seeking employment but are willing to work under the right circumstances, as well as over 2,250 executives across the US, UK, and Germany. Researchers also found that the situation, although it has worsened over the pandemic, has been growing over recent decades.

“A single data point made the intractability of the problem apparent—just under half (44%) of middle-skill “hidden workers” reported that finding work was just as hard pre-COVID-19 as it was during our 2020 survey period,” stated the report.

How the cloud is helping Currensea create a more sustainable future


Sabina Weston

7 Sep, 2021

Many startups dream of the day they get their Big Break, but not all of them pause to consider whether they will actually be able to handle the rapid increase in demand for their services. 

For Currensea, their Big Break was delivered by their appearance on Channel Five’s long-running consumer technology series The Gadget Show.

“We didn’t know how this was going to play out,” recounts Craig Goulding, who co-founded Currensea in 2018 with fellow former JPMorgan employee James Lynn.

“When it aired, things went absolutely berzerk, traffic to our website and application went through the roof. We were issuing one card every six seconds – totally, utterly insane,” he tells Cloud Pro.

Sudden influxes of traffic, often prompted by media coverage, are not a daily occurrence for many companies. However, when they do happen, many websites cannot handle the demand and buckle up under pressure. This means that the company can miss out on new orders and – most importantly – profits. 

For Currensea, however, this moment was made possible by the elasticity and scalability of the cloud on which its website is built.

“The platform just handled that surge in volume,” says Goulding. He describes the appearance on the show, as well as the subsequent frenzy, as “an amazing experience” that was fully enabled by technology, allowing Currensea to sit back and reap the rewards. 

“One of the great things about the cloud is that you don’t have to worry about servers,” he tells Cloud Pro. “So you can concentrate on building and running applications and business logic, rather than having to worry about having to manage the infrastructure. Amazon Web Services just takes care of all that for you.”

Goulding adds that this was especially important for the small team of engineers that makes up Currensea, allowing them to focus on “building products and building differentiation, rather than having to worry about the kind of nuts and bolts of the service and goodness knows what”. The experience with The Gadget Show helped Goulding realise the importance of the ability to scale up and scale down on demand, especially when these kinds of peaks in traffic are rare. It also helps the company save money.

“If you’re not using it in the cloud then you’re not paying for it, so it’s a very flexible and adaptable model as well,” he says.

The cloud offers more than just peace of mind, though.

“Another huge benefit is just the number of tools they have in their environments, which you just point and click and configure, then you magically get them, which is incredible. Again, if you’re having to kind of build that up yourself, it would be a hugely conservative resource, so it’s just a massive accelerator for us,” he says. 

“Then you’ve got the resiliency as well. You’re spread across multiple data centers and everything kind of fares over if there’s any issues in one data center. So, you run a 24/7 operation with no downtime.”

Saving the oceans, one card at a time

The cloud has been hailed as a life-saver for many industries, especially during the COVID-19 pandemic. For Currensea, however, it’s allowing the challenger bank to channel all its attention into its environmental efforts.

While many banks are undergoing a digital transformation, offering a brighter and more convenient future, what actually lies ahead might be rather more bleak. Extreme weather, food shortages, and pollution are only the tip of the environmental iceberg, with the gradual melting of ice caps and rising sea levels threatening to submerge coastal cities such as Miami as early as 2050. All of these issues could impact everyone’s long-term plans – but could something as small as a bank card help reverse them?

Whether debit or credit, banking cards are most often made out of polyvinyl chloride, more commonly known by the initials PVC, which is notoriously difficult to recycle, usually ending up sitting in landfills for centuries to come. This has prompted Currensea to opt for biodegradable cards that, when disposed of, will take about a decade to decompose. However, the challenger bank’s environmental drive isn’t limited to cards only: Earlier in 2021, the company launched a new feature that enables customers to contribute to cleansing the oceans of plastic waste every time they spend money abroad, with a pledge to remove 2.5 times the amount of plastic they produce every year.

“For each card that we’re producing, we’re also extracting plastic from the oceans – more plastic than we’re actually introducing to the world,” explains Goulding.

When asked about the problem of greenwashing – companies branding themselves as sustainable for marketing purposes, with limited positive impact for the environment – Goulding says he is “very conscious of that”.

“You either do it properly, or you don’t do it at all,” he says.

TechUK subsidiary extends digital training initiative to tackle skills shortage


Bobby Hellard

7 Sep, 2021

Employer-led training firm, TechSkills, has announced an extension of its Tech Industry Gold accreditation to help tackle the tech industry’s digital skills shortage. 

The training body is a subsidiary of lobby group techUK and its Gold certificates acknowledge intensive digital training programmes that offer «high-quality» pathways into the digital industry. 

The credentials make it easy for employers to understand the skillsets of individuals and match them to job vacancies, according to TechSkills.

Learners themselves can choose Tech Industry Gold accredited programmes and be confident in the relevance of their training for their next career move. It includes an award (Tech Industry Gold Digital Credentials) which proves job-ready skills in a form that is easy to understand and portable across companies, sectors and geographies.

«As the chair of the Tech Industry Gold Steering Group, and on behalf of the TechSkills Employer Board, I am delighted with the extension of Tech Industry Gold accreditation into intensive training programmes,» said Colin Bannister, VP of solution engineering at VMware EMEA.  

«This will make it easier for individuals to choose high-quality pathways into tech, and Tech Industry Gold Credentials will make it easier to secure employment and progress careers. I believe this will make a real contribution to strengthening the talent pipeline and helping individuals realise their potential in our fast-growing digital economy.»

Professional services organisation FDM Group is the first company to achieve ‘Training Programme accreditation’. The company’s Business Analysis training programme has been recognised for its quality and relevance in preparing learners for employment in entry level Business Analysis roles.

«We are very proud to join the Tech Industry Gold community as the first company to achieve industry accreditation for training programmes,» said Rod Flavell, CEO, FDM Group.

«Our people come from all walks of life and all backgrounds, and we want to give each person the best possible start to their career. Ensuring our programmes are independently reviewed and approved helps us to continually deliver the very highest standards of training, focused on job readiness for our employees and value for our clients. 

«These are exciting times for FDM Group. We have big ambitions to increase our new hires this year and help build the tech careers for a whole new generation of candidates.»

US officials warn of “mass exploitation” of Atlassian Confluence flaw


Keumars Afifi-Sabet

7 Sep, 2021

Hackers are exploiting a vulnerability in the on-premise Atlassian Confluence workplace collaboration platform on a massive scale, with businesses urged to patch their systems without delay.

US Cyber Command issued a public notice just before the weekend warning that mass exploitation of the remote code execution flaw tracked as CVE-2021-26084 is “ongoing and expected to accelerate”. 

“Please patch immediately if you haven’t already,” the notice added. “This cannot wait until after the weekend.”

Confluence is a workplace collaboration platform that allows teams to work together remotely on projects or ideas. 

The vulnerability, which is embedded in the Atlassian Confluence Server and Confluence Data Center products, can allow an unauthorised attacker to execute arbitrary code on either of the affected platforms. 

Confluence Cloud, which is hosted on public cloud environments, isn’t affected by the flaw. Rather, the on-premises versions of the product are those susceptible to exploitation.

It’s rated 9.8 on the CVSS threat severity scale out of ten, suggesting it’s highly exploitable. The firm had never publicly revealed the precise exploit mechanisms, though, beyond describing the flaw as a Confluence Server Webwork OGNL injection. This was presumably to avoid fuelling any future attacks before businesses had a chance to apply the fix. 

Atlassian disclosed this vulnerability a couple of weeks ago and urged businesses to patch their systems at the time. However, cyber criminals from around the world have since been detected as scanning for vulnerable systems and launching attacks.

The threat intelligence firm Bad Packets, for example, detected mass scanning and exploit activity from hosts in a number of regions including China and Brazil earlier last week.  

Atlassian previously addressed a serious vulnerability in its system that could allow hackers to compromise user accounts, and control several apps that users can access seamlessly through a single sign-on (SSO) feature.

This latest vulnerability in Confluence is just one of many serious vulnerabilities that have been exploited during 2021, with the rate of successfully abused zero-days surging over the last few months. 

The benefits of Bare-Metal-as-a-Service for fintech


Sponsored content

3 Sep, 2021

It is expected that, by the end of 2025, the global fintech market will grow to $125 billion. But the development and maintenance of a good app comes with challenges. What technologies should you choose? How much will it cost to maintain? And crucially, what hardware should a fintech project choose?

For the growing needs of high-capacity financial calculations, there’s almost no alternative to dedicated servers. Add to that the speed, flexibility and affordability of the as-a-Service format, and you’ll get a high-quality solution for all the infrastructural needs of your business: a public cloud with bare metal servers.

What is a bare metal server?

A bare metal server is a physical server rented by the client. The hardware is available as is – the user gets a clean system, with no pre-installed OS, and is in full control.

If you’re the sole lessee of a server, you have full control over all its resources. You can install anything on it and set it up any way you want, like your own desktop. You want to deploy your own virtual machines? Feel free to do that. You want to use the entire node for a single project? No problem.

Why is bare metal a good fit for fintech?

Dedicated servers are a better fit for resource-heavy apps. In the world of financial services, there’s a lot of transactions going on. Virtual machines are not the best choice for such an environment, since the “virtualisation tax” prevents you from using 100% of their capacity. Another issue is the distribution of the platform’s resources between users – when one of them uses too much of the server’s capacity, their neighbours pay for it.

Unlike virtual machines, dedicated nodes are better at coping with resource-heavy tasks. According to research, when performing tasks that require high processing speed, virtual machines lose up to 17% of capacity compared to bare metal servers. This is because bare metal users have full access to the server and can single-handedly use all its computational resources. This approach allows the organisation of a more productive platform to receive, process and store financial app data.

Why the Bare-Metal-as-a-Service model?

Bare metal solutions are often harder to order than a virtual machine, and you must wait longer for the server to be prepared for operation. Another issue is the management of the disparate infrastructure of dedicated servers, virtual machines and clouds when purchased from different providers.

G-Core Labs’ new offering, Bare-Metal-as-a-Service, solves these problems. With this service, a user can get a ready-for-use dedicated server as easily as a virtual one. Just select the right features, connect a private or public network, or several networks at once, and in a few minutes, the physical server will be ready for use.

Extra security is expected from fintech

To provide financial services on the EU and US markets, you need to be 100% confident that your app works securely and your infrastructure is reliable. If the PCI DSS standard is not met, a company may have to pay hefty fines.

That can be avoided by choosing a reliable provider. For example, with G-Core Labs, you can be confident about the high level of protection of the cardholder’s personal information in the cloud, which is particularly important for the financial sector and for any companies that work with acquiring. The G-Core Labs cloud has been certified under the PCI DSS 3.2.1 standard for storage, processing and transfer of payment card data. The certification has been confirmed after the yearly QSA audit run by the company Compliance Control Ltd.

To ensure even better data security, G-Core Labs dedicated server users can use the encryption technology Intel SGX, a set of processor instructions that an app can use to allocate private parts of code or data, ensuring extra protection from disclosure or modification.

Fintech app developers need full access to hardware

When working with high loads, you need maximum capacity, so it is crucial to be able to choose and set up all hardware components on your own.

For example, digital insurance creates a significant increase in policy administration speed and processing of hundreds of kinds of claims. Such apps help reduce the likelihood of insurance fraud. They can be anything from a simple website offering an insurance policy for a car rental to a complex CRM system, for which even the most powerful stock servers might not be enough.

In the G-Core Labs Bare-Metal-as-a-Service public cloud, all these tasks – configuration management, orchestration and the addition of new dedicated servers – can be automated through API to quickly scale the platform in accordance with the client’s resource needs. The data can be also stored on NVMe drives. Servers located in G-Core Labs data processing centres offer capacity and control so full as though they were located right in your office.

Latency should be minimal

Modern fintech apps need the servers to be as failure-proof and high-capacity as possible. Imagine you’re launching an instant loan service for small businesses. The first thing you need to ensure is efficient processing of credit requests and interaction between borrowers and loaners. The essence of this concept is very quick data processing, instant decision making and split-second responses.

Such solutions require high-bandwidth infrastructure. G-Core Labs has dedicated servers that provide this, located in reliable data Tier III and IV data servers in over 15 cities of the world.

Fintech apps need quick database access

Fintech apps, especially those with real-time bidding (RTB), often need quick access to user profiles and information about their access. Disintermediation is fintech’s most powerful weapon, but it has a lot of requirements.

For example, digital investment platforms allow beginner and pro investors to explore and use different financial assets. These solutions allow the users to get analytics data, which, in turn, allows them to increase the efficiency of their investments. The servers of such apps manage millions of operations simultaneously.

In the G-Core Labs cloud, you can use high-capacity NVM disks, and the processing power is ensured by Intel. In April 2021, the provider was one of the first in the world to start integrating 3rd gen Intel Xeon Scalable (Ice Lake) processors in the server infrastructure of its cloud services. This equipment allows fintech apps to quickly manage any tasks.

Cloud services pretty much emulate a local data-processing centre, with its high and predictable capacity. They are the perfect fit for the resource-heaviest tasks. Therefore, bare metal is the most useful for tasks like real-time transaction processing or analytics systems, without which a fintech app cannot be imagined. Bare-Metal-as-a-Service is the most realistic alternative to a private server for a fintech startup.

Discover more about Bare-Metal-as-a-Service with G-Core Labs