Certified problem solver. Wannabe food fanatic. Passionate web ninja. Explorer. Lifelong reader.. In a fast paced social and mobile environment it's great to know you can come to a place where you will find relevant news and fresh ideas.
Friday, May 16, 2014
Welcome To The Grind (Motivation)
Friday, April 25, 2014
Verizon 2014 Data Breach Investigations Report
The 2014 DBIR is the most actionable yet and it will help companies to focus their strategy and approach more effectively. Download the report today to understand the key patterns and recommendations by industry.
Quick Facts:
- Seventh consecutive year of publication with more than 10 years of data
- Data from 50 organizations around the world
- 1,367 confirmed data breaches
- 63,000+ reported security incidents from 95 countries
- 92% of all incidents from the last 10 years fall into nine patterns
Wednesday, March 19, 2014
How the Internet of Things will put pressure on data centers.
Data Center
by Amy-jo Crowley| 18 March 2014
Objects will generate big data that needs to be processed and analyzed in real time.
Smart devices will put pressure on data centers as they generate big data that needs to be processed and analysed in real time, according to the latest research.
Gartner predicts that there will be 26 billion Internet of Things (IoT) units installed by 2020 as IoT suppliers generate $300bn in revenue.
IoT refers to appliances enabled with sensors and assigned their own IP address that connect to the internet - thus creating a world where devices and machines can communicate with each other, interpret information and make intelligent decisions in real time as more and more devices connect to the internet.
Fabrizio Biscotti, a research director at Gartner, said: "Processing large quantities of IoT data in real time will increase as a proportion of workloads of data centers, leaving providers facing new security, capacity and analytic challenges."
Gartner outlined the following challenges for data center technology providers.
1. Security - The increasing digitization and automation of the multitudes of devices deployed across different areas of modern urban environments are set to create new security challenges to many industries.
2. Enterprise - Significant security challenges will remain as the big data created as a result of the deployment of myriad devices will drastically increase security complexity. This, in turn, will have an impact on availability requirements, which are also expected to increase, putting real-time business processes and, potentially, personal safety at risk.
3. Consumer Privacy - As is already the case with smart metering equipment and increasingly digitized automobiles, there will be a vast amount of data providing information on users' personal use of devices that, if not secured, can give rise to breaches of privacy. This is particularly challenging as the information generated by IoT is a key to bringing better services and the management of such devices.
4. Data - The impact of the IoT on storage is two-pronged in types of data to be stored: personal data (consumer-driven) and big data (enterprise-driven). As consumers utilize apps and devices continue to learn about the user, significant data will be generated.
5. Storage Management - The impact of the IoT on storage infrastructure is another factor contributing to the increasing demand for more storage capacity, and one that will have to be addressed as this data becomes more prevalent. The focus today must be on storage capacity, as well as whether or not the business can harvest and use IoT data in a cost-effective manner.
6. Server Technologies - The impact of IoT on the server market will be largely focused on increased investment in key vertical industries and organizations related to those industries where IoT can be profitable or add significant value.
7. Data Center Network - Existing data center WAN links are sized for the moderate-bandwidth requirements generated by human interactions with applications. IoT promises to dramatically change these patterns by transferring massive amounts of small message sensor data to the data center for processing, dramatically increasing inbound data center bandwidth requirements.
Monday, March 3, 2014
Netflix IT is no house of cards
BY IJCOX
When looking for a case study of digital disruption there is probably no better example than Netflix, the US company that has revolutionized how we consume films and TV shows at home and on the move. Netflix started life in 1997 as a direct rival to Blockbuster in the DVD rental market. Instead of building a chain of thousands of stores to compete with its larger and more established rival, the Netflix model relied on using the postal system as a low cost distribution network.
The emergence of a low cost rival was challenging enough for Blockbuster but when Netflix introduced its video steaming service in 2007, the real disruption of its core market began. And this disruption would eventually play a major part in the demise of the Blockbuster business, which finally stopped trading towards the end of 2013. Today, Netflix has over 44 million members in more than 40 countries who view more than one billion hours of TV shows and movies per month. The company, which refers to itself as the “world’s leading internet television network”, has redefined the market for viewing films and TV.
And, if you are looking for an example of reinventing enterprise IT, then the way in which Netflix VP of IT Operations, Mike D Kail, runs the organization’s technology function is a good starting point. In a recent interview with CXOTalk, Kail summarised his philosophy for IT at Netflix with the comment “don’t build data centers if it’s not your core business.” In other words, as Kail explained further, he wants his IT team to focus on being an entertainment company, not on “hardware, network infrastructure and storage systems” which are readily available from service providers. To demonstrate his commitment to this approach he has migrated the company’s finance systems to the cloud, implemented Google apps and even the in-house developed customer applications, which are part of the core business, are deployed in the cloud thereby eliminating the need to acquire, maintain and support the infrastructure that would be needed to host these solutions internally. His objective is to have 100% of corporate IT in the cloud by the end of the current year.
In the digital age technology is being used to enable new capabilities, enhance the customer experience, create value and generate revenue; technology is now a source of differentiation and competitive advantage in all industries. To stay relevant and to play a key role in the digital age, CIOs and their departments also need to shift their focus to creating value and driving revenue. They cannot do this if the majority of the IT resources and hence management attention are allocated to maintaining and supporting the organisation’s existing infrastructure and systems. By focusing his team on the core business of Netflix Kail is ensuring that they are adding real value to the organization.
There has never been a better time for IT to fix its reputation in the industry. CIOs have to start fixing the reputation of their functions now. To succeed in the digital age, organizations need the right type of IT function, one that is focused on the areas where technology will have the greatest impact, is proactive and works with the rest of the business to find ways to use technology to create value. Businesses that do not have this type of IT function will find it increasingly hard to compete in the digital age. And CIOs that do not take this path are likely to find themselves bypassed by the rest of the organization and ultimately out of a job.
Tuesday, February 11, 2014
Verizon Study Finds Few Organizations
in Compliance with Payment Card
Security Standards
According to the Verizon 2014 PCI Compliance Report, which was released today, more than 82 percent of organizations were compliant with at least 80 percent of the PCI standard at the time of their annual baseline assessments in 2013, compared to just 32 percent in 2012.
The study, which aggregates data from actual PCI assessments done by Verizon during the course of the year, offers a look at the actual experiences of businesses that must comply with PCI DSS, which is the mandated set of guidelines for any organization that handles credit card transactions.
While assessment-time compliance is up, many organizations tend to fall out of compliance between audits, the study says.
"We continue to see many organizations viewing PCI compliance as a single annual event, unaware that compliance needs to have a 365-day-a-year focus," stated Rodolphe Simonetti, managing director for the PCI practice at Verizon Enterprise Solutions.
Areas where businesses struggle the most in achieving initial compliance include security testing (23.8 percent); security monitoring and the ability to effectively detect and respond to data compromised (17 percent); and protecting stored sensitive data (55.6 percent), the report says.
The compliance problem is not an issue of technology or flaws in the standards, but in the ongoing implementation, Verizon states.
"Anything less than 100 percent compliance is an issue for businesses today," Simonetti said . "We have seen time and time again that noncompliance leaves an organization open to credit card theft, which can potentially cost hundreds of millions of dollars when you factor in all the damages -- not to mention lost consumer trust and the impact on brand reputation. Organizations need to rethink how they factor in maintaining a PCI-compliant environment, whether it's devoting more resources or working with a managed security services provider."
Wednesday, February 5, 2014
Creating Enterprise Data and Mobility Security
February 5th, 2014By: Bill Kleyman
As more enterprise users are taking advantage of mobile devices, there’s a growing and important need for mobility security.
More end-users are bringing in their own devices into the corporate setting to get their jobs done. In fact, some users are now utilizing three or more devices, all of which may have access to corporate data.
Furthermore, the numbers around just how much data is being passed through these devices really paints the picture. According to the latest Cisco Visual Networking Index, “The increasing number of wireless devices that are accessing mobile networks worldwide is one of the primary contributors to traffic growth. Each year, several new devices in different form factors, and increased capabilities and intelligence, are being introduced in the market. By 2017, there will be 8.6 billion hand-held or personal mobile-ready devices and 1.7 billion machine-to-machine connections.”
A growing number of wireless devices, including smartphones, tablets and laptops, are accessing mobile networks worldwide.
There are some inherent benefits to creating corporate mobility – productivity, worker happiness, less end-point management – but there are also many concerns. IT administrators are already responsible for many devices on their network. Now, there’s the potential that they have to monitor and manage even more.
The most efficient way to approach mobility is to have a well-planned out deployment with good policies in place. Without a doubt, one of the first planning points will revolve around security and how to best manage it with so many devices being brought in.
Here’s the first mind-shift that has to happen. Instead of trying to control the device – you should care more about the applications, workloads, data and experience being delivered to the device. This way you create an optimal delivery methodology which is truly agnostic to the device itself. Still, security must be wrapped into these policies and around the workloads that are being delivered. To that extent – here are some great ways to create mobility and data security.
- Use Enterprise/Mobility Management Platforms. The rise of the mobility revolution meant that there had to be a technology that would help administrators manage both devices and the data flowing through them more efficiently. Working with these management platforms can have a lot of benefits for organizations allowing personal devices to connect to internal network components. Scanning for things like rooter or hacked devices and stopping access from malicious software are all MDM/EDM features. Furthermore, administrators can leverage granular control mechanisms to have better visibility and manageability of end-point devices. If a device is lost or stolen, administrators have the option to wipe only corporate data or the entire device remotely. Finally, these platforms can directly optimize how applications and other content is delivered to the user – by creating adaptive orchestration policies.
- Lock down applications and workloads. A large part of the mobility and data control environment resides with various virtualization technologies. In creating a good mobility security policy, administrators have to find ways to lock down their applications, various data points and even desktops. By usingnext-generation technologies, administrators can limit access to all or even part of an application or workload. Above and beyond just controlling how the end-point accesses the environment, user and data controls should be deployed to better manage mobility-enabled devices.
- Deploy next-generation security. Enterprise security has come a long way. Physical firewalls are no longer the end-all security solutions. Now, administrators can deploy specific security processes on dedicated virtual or physical devices. In working with next-generation security products, administrators are able to really lock down the access into their network.
For an enterprise mobility initiative, next-gen security can help with some of the following tasks:
- End-point device interrogation.
- Access based on the device, location, and user.
- Using application firewalls.
- Deploying virtual appliances as secondary checkpoints or isolated controllers for end-user personal devices.
- Deploying adaptive two-factor authentication methods driven by secure certificates.
- Data access monitoring.
- Data Leakage Prevention (DLP), Intrusion Prevention/Detection Services (IPS/IDS)
The term “next-generation” security really focuses on the new types of IT initiatives currently being deploying by many organizations. A part of that includes mobility, device, and data management. Terminology aside, if you’ve purchased a network access controller, security appliance, or some type of gateway technology – chances are that your device has some next-generation security features already built-in. Use your appliances – both virtual and physical – to their fullest capabilities to deliver a truly powerful computing experience.
Create Mobility and Data Usage Policies
An organization may have the best infrastructure in place for mobility; however, an uninformed user can still be a very dangerous asset to have to manage. User empowerment and education has come a long way in the IT field and many are much savvier than they are given credit for. In light of this, their usage of corporate data on personal devices may actually make them (accidentally, in most cases) more dangerous. First of all, there needs to be a corporate mobility policy in place. In many instances, this is an extension of the existing computer usage policy. Users must know that although the devices they are using are be personal, the data they are viewing is still corporate-owned. Because of this, their data usage or even working session may be monitored and controlled. Although visibility into the personal device will be limited by privacy regulations – all data accessed from the central data center may be monitored and user activity logged.
Creating a happier worker can have many different benefits. However, security and integrity of corporate data must be one of the top priorities. The beauty of today’s security technologies is that administrators are able to still deliver a powerful computing experience while locking down their infrastructure. When working with modern mobility trends, the main rule is simple: never allow a free-for-all to occur.
Although many devices may be allowed – IT administrators should still limit the types of devices they allow on their network. In many cases, to access corporate data, the end-user may need to install some client software. To ease management, IT should supply a hardware list which is capable of supporting the client on various end-point platforms. In doing so, the user can still bring in their own devices, access the data, and IT will be able to secure and control the experience.
Monday, February 3, 2014
How 3D Printing Will Change Everything!
What if I were to tell you that one day printers will be able to build homes, manufacture guns and cook food? That would be pretty remarkable progress, and to my surprise, it's quite possible.
The potential of 3-D printers reaches beyond revolutionizing the printing market and into transforming entire industries.
To be honest, the term "3-D printing" doesn't do justice to the true capabilities of this technology. Lucas Mearian, a senior writer at Computerworld wrote about this topic. In December, he wrote about the first 3-D printed organ (a liver), which is expected later this year. The month before, he explored the dangers of 3-D printed guns exploding.
Both of those examples highlight how 3-D printers can produce very complex products, one through advancing medical science, the other with thermoplastic materials.
If you take it one step further, you can see that once these printers can scale in size, much larger items can be built with little human labor. Construction of homes from 3-D printing becomes a real possibility. (There's already a video on YouTube from a TEDx talk last year about "contour crafting" and the automated construction of a house.) But if you really want to dream big, imagine sending these printers to the moon, where they could build facilities that are managed from Earth.
Not crazy enough for you? Think about the ability to actually have food available wherever there is electricity. The food would be freeze-dried, crushed and placed into "ink cartridges." With the push of a 3-D printer button, the heat it produces could cook your food.
Imagine having a 3-D printer available to print replacement parts at your business or home. When something breaks, you simply download the specs and print it out wherever you are. No customer service calls, no shipping and handling costs, no waiting.
When I think of the ramifications all this will have on intellectual property protection in just about every industry, it's more than a little mind-boggling. No wonder the Harvard Business Review wrote about this last spring under the headline, "3-D Printing Will Change the World."
I'd love to hear what you are thinking about the potential of this technology. Write to me below.
Friday, December 6, 2013
Cloud and outsourcing set to rule IT
A global survey of 550 senior IT executives has uncovered signs of a massive shift from in-house IT to outsourced and cloud services.
The survey was commissioned by IT services company Savvis and conducted by technology marketing consultancy Vanson Bourne. 550 CIOs, IT directors, VPs of IT and senior IT managers of organisations in the USA, Canada, UK, Germany, Japan, Hong Kong and Singapore were interviewed.
The report concluded: “We’re on the cusp of a major shift in IT infrastructure models. This shift ultimately leads to the outsourced cloud as the dominant model. However the journey will take almost five years.” It was clear from responses that the move to cloud is accelerating: 68 percent of the respondents using cloud had implemented their cloud service only in the last 12 months.
Commenting on the findings Savvis CMO, Becky Carr, said: “For years now mainstream adoption of the outsourced cloud has moved closer to reality. ... However the real news from this year’s survey of IT leadership is that enterprises are more immediately concerned with strategically shifting IT infrastructures from an in-house to an outsourced model. Within just five years, 70 percent of all IT infrastructures will be outsourced. This is a dramatic shift, and it’s huge.”
She continued: “IT leaders are balancing issues like security, uptime, loss of control, and company culture with their desire to outsource increasingly large portions of their infrastructures. Significant numbers of respondents said that, although functions such as disaster recovery, facilities and business applications were currently managed in-house, they belonged in an outsourced model.”
Cost reduction or containment was the main reason cited for outsourcing, by 42 percent of respondents. However the report said: “CIOs are no longer under duress to slash costs as a business survival tactic. Rather, IT leaders are looking for better cost structures to provide their businesses with competitive advantage. In fact, 36 percent of organisations see improved quality of service from outsourcing versus in-house solutions.”
The survey found that there is still reluctance to outsource business critical applications. “When asked about their strategic IT goals ... senior IT decision makers still put controlling costs on top of the list — but only barely. Almost as many IT leaders said focusing resources on business-critical applications was a priority.”
Outsourcing of business-critical applications is likely to become much more popular. There is a growing school of thought in IT that says business-critical applications should be outsourced or moved to the cloud where security and reliability can be guaranteed because although applications like email, IP telephony, etc are business-critical they are not significant differentiators and moving these to the cloud or to outsourcers freeing IT resources to work closely with the business and to concentrate on IT applications that differentiate the business and give it a competitive advantage.
Friday, November 8, 2013
The Cloud-Enabled Transformation of Enterprise IT
Thanks to exponential advances in processing power, bandwidth, and storage (what I call the three change accelerators), the business environment is undergoing a major transformation. I have been tracking the trajectory of these three change accelerators for the past five years and they have now entered a predictable new phase--one that will transform every business process. In fact, based on the technology-enabled hard trends that are already in place, including advances in cloud computing and virtualization, over the next five years we will transform how we sell, market, communicate, collaborate, innovate, train, and educate.
Friday, October 11, 2013
Another major cloud service is angling today to join the pantheon of public cloud providers such as Amazon Web Services, Google Cloud, Rackspace and Windows Azure. Verizon Terremark, a unit formed by Verizon's $1.4 billion purchase of the Miami-based cloud vendor Terremark in 2011, is launching two new public infrastructure services today: Verizon Cloud Compute and Verizon Cloud Storage.
But what will this new public cloud offering give the world that it already doesn't have?
Verizon Terremark's infrastructure-as-a-service Cloud Compute and object storage Cloud Storage offerings are most analogous to Amazon Web Service's EC2 and S3 services, respectively. But VT claims it offers some key technological and business advantages. Let's have a look.
The Technology Argument
For starters, VT claims its networking architecture will allow for multi-tier networking, with multiple network interfaces available to any virtual machine. Applications running on the VT cloud service can have any number of tiers available, from the client-server two-tier architecture, to the more stable three-tier presentation-business-data architecture that is common for many web apps and beyond.Using multi-tier networking can introduce a lot of stability and fault-tolerance into an application; the more parts of an application's process that are handled by different machines on the network, the less chance there is for the application to fail. And, if you want to swap out a software component of the application, it can be done without rewriting the whole app.
But, there's a catch. Any time an application process or data has to jump from one machine to another, it slows the process down. The more tiers introduced, the slower the process gets, as information has to potentially hop multiple times from one server to the next.
To adjust for this problematic latency, Verizon Terremark CTO John Considine told me that the topography of the network will also be laid out as an "ultra-flat network," which means that inside each of the new public cloud's seven regions, virtual-machine-to-virtual-machine communication will be done in one network hop, even if there are hundreds of thousands of virtual machines within a region's virtual network.
This is a sharp departure from what Considine called the typical leaf-and-spine topography seen in many places today. That topography, he claims, leaves many network links oversubscribed and can introduce latency into the system—especially with multi-tier network architecture. "We've removed the restrictions on where in a region we put a customer's servers," he said. "We can do this by rewriting network packets on the network layer as the packets move through the network."
This kind of network flexibility is pretty much what you would expect a network provider would feature: after managing a network of its own for so long, one would expect VT to have some decent tricks up its sleeve. Such network flexibility should translate into faster multi-tier applications, if developers want to build them.
The Business Argument
From a business perspective, Verizon claims its Cloud Compute customers will have far more control over the resources they use on the cloud.For example, in AWS's EC2 service, the m1.small server instance offers 1.7GB of RAM. So, Considine said, a customer with a 2GB app can either try to squeeze the app into the smaller 1.7GB space, or upgrade to Amazon's next instance, the 3.75GB m1.medium, and pay more.
By contrast, Verizon prices its services are priced by the gigabyte and the gigahertz. Servers, then, can be better sized to a customer's actual need, Considine said.
Verizon has also simplified pricing by eliminating, for instance, charges per input/output of memory transferred.
Simplified pricing would be a cool part of this new cloud service; given that some customers actually attend seminars to learn just how to read a bill from AWS, simplicity would be a welcome breath of fresh air.
The Bottom Line
U.S. customers will get the most access right now, with four available cloud regions. The EMEA will have two available cloud regions, and another cloud region in Brazil. The APEC region will see availability of Verizon Terremark cloud services in 2014, Considine said.If these cloud services deliver what they promise, Verizon Terremark could shake up the public cloud market. The company is targeting enterprise customers (naturally), but it is also driving towards medium-sized and government clients as well—the latter being a direct square-off with AWS's recent claim staking of the government sector this summer.
Lots of companies have tried to knock AWS off the top of the public-cloud heap, but Verizon Terremark might have a better chance than most. Unlike AWS and all of the other cloud competitors, VT controls a network, which may give it an advantage until the other services can catch up.
Image courtesy of Wikimapia
Subscribe to:
Posts (Atom)
About Me
- Bobby
- Certified problem solver. Wannabe food fanatic. Passionate web ninja. Explorer. Lifelong reader.

