Showing posts with label control. Show all posts
Showing posts with label control. Show all posts

Wednesday, July 10, 2013

BYOD 2.0 -- Moving Beyond MDM

#BYOD has quickly transformed IT, offering a revolutionary way to support the mobile workforce. The first wave of BYOD featured MDM solutions that controlled the entire device. In the next wave, BYOD 2.0, control applies only to those apps necessary for business, enforcing corporate policy while maintaining personal privacy. The #F5 Mobile App Manager is a complete mobile application management platform built for BYOD 2.0

 

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Monday, June 18, 2012

The Exec-Disconnect on IT Security

Different Chiefs give Different Security Stories.

A recent survey shows that there is a wide gap between CEOs and Chief Security Officers when it comes to the origin and seriousness of security threats.  They differ on how they view threats to IT Infrastructure  and remain far apart on how to best address an issue that according to analyst reports, costs organizations more than $30 billion annually.  The survey of 100 CEOs and 100 CISO (or other C-levels with security responsibility), shows that the discrepancy is often due to lack of communication.  36% of CEOs said that they never get a security report from their CISO and only 27% receive updates on a regular basis.  Is it the CISO that doesn’t report back or the CEO that is not interested?  Let’s look at some more data.

The CISO felt that the biggest threat was from internal (their employees) due to lack of education and attention while the CEO felt that the biggest threat was from the outside, such as phishing attacks.   Thus, 61% of CEOs said they did have enough time and resources to adequately train the staff on how to mitigate threats while Only 27% of CISOs felt the same.  It’s opposite day.  When asked if their IT systems were ‘definitely’ or ‘probably’ under attack without their knowledge, 58% of CISOs said yes while only 26% of CEOs agreeing.  The chasm grows.  What percentage of each, do you think, said they were very concerned about their IT systems getting hacked?  30 seconds on the clock, please.  Don’t peek.  Only 15% of CEOs and ‘only’ 62% of CISOs are anxious about breaches.  15%?  That’s it?  Maybe they have great confidence in their security team…or, they don’t have the information.  65% of CEOs admitted to not having the sufficient data needed to interpret how security threats translate to overall business risk.  Wow, the very day-to-day operations.  Granted, the CEO is further removed from the specific threats and how they are handled but there is clearly a distance between how each views threats and the company’s ability to successfully mitigate them.

Lack of interest or lack of understanding/information?  Probably both.  An old adage was that a great boss hired people who were good at the things he/she wasn’t so good at.  Surround yourself with those who know their areas better.  Or maybe there is a culture that you don’t alert the top unless it’s dire, critical or unstoppable.   Communication or interest, it is evident that the C-suite isn’t really talking about these critical business issues especially when 3 times as many CEOs worried about losing their jobs following an attack than did CISOs.

ps

References

Technorati Tags: F5, security research, botnet, threat landscape, Pete Silva, security, business, technology, cloud,compliance,regulations, web,internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, January 26, 2012

Evolving (or not) with Our Devices

IMG_0095When I talk on the phone, I’ve always used my left ear to listen.  Listening in the right ear just doesn’t sound right.  This might be due to being right handed, doing the shoulder hold to take notes when needed.  As corded turned to cordless and mobile along with the hands-free ear-plugs, that plug went into the left ear whenever I was on the phone.  Recently, I’ve been listening to some music while walking the dog and have run into an issue.  The stereo ear plugs do not fit, sit or stay in my right ear.  I have no problem with the nub in my left ear but need to keep re-inserting, adjusting and holding the plug in my right ear.  I’m sure I was born with the same size opening for both ears years ago and my only explanation is that my left ear has evolved over the years to accommodate an ear plug.  Even measuring each indicates that the left is opened more ever so slightly.  I seem to be fine, or at least better, with the isolation earphone style but it’s the ear-bud type that won’t fit in my right ear.  I realize there are tons of earplug types for various needs and I could just get one that works for me but it got me thinking.  If my ears or specifically my left ear has morphed due to technology, what other human physical characteristics might evolve over time.

As computers became commonplace and more people started using keyboards, we started to see a huge increase of carpal tunnel syndrome.  Sure, other repetitive tasks of the hand and wrist can cause carpal tunnel but typing on a computer keyboard is probably the most common cause.  Posture related injuries like back, neck, shoulder and arm pain along with headaches are common computer related injuries.  Focusing your eyes at the same distance over extended periods of time can cause fatigue and eye strain.  It might not do permanent damage to your eyesight but you could experience blurred vision, headaches and a temporary inability to focus on faraway objects.  Things like proper design of your workstation and taking breaks that encourage blood flow can help reduce computer related injuries.  Of course, every profession has their specific repetitive tasks which can lead to some sort of injury and, depending on your work, the body adjusts and has it’s own physical memory to accomplish the task.  Riding a bike.  Often smokers who are trying to quit can tolerate the nicotine deduction but it’s the repetitive physical act of bringing the dart up that causes grief.  That’s why many turn to straws or toothpicks or some other item to break the habit. 

We’ve gotten use to seeing people walking around with little blue-tooth ear apparatus attached to their heads and think nothing of it.  They’ll leave it in all day even if they are not talking on the phone.  Many probably feel ‘naked’ if they forgot it one day, almost like a watch or ring that we wear daily.  I mentioned a couple years ago in IPv6 and the End of the World that with IPv6, each one of us, worldwide, would be able to have our own personal IP address that would follow us anywhere.  Hold on, I’m getting a call through my earring but first must authenticate with the chip in my earlobe. That same chip, after checking my print and pulse, would open the garage, unlock the doors, disable the home alarm, turn on the heat and start the microwave for a nice hot meal as soon as I enter.  Who would have thought that Carol Burnett's ear tug would come back.

Now that many of us have mobile devices with touch-screens, we’re tapping away with index fingers and thumbs.  I know my thumb joints can get sore when tapping too much.  Will our thumbs grow larger or stronger over time to accommodate the new repetitive movement or go smaller and pointy to make sure we’re able to click the the correct virtual keypad on the device.  We got video eyewear so it’s only a matter of time that our email and mobile screens could simply appear while wearing shades or as heads up on the car windshield.  With special gloves or an implant under our hand, we can control the device through movement or tapping the steering wheel.

Ahhh, anyway, I’m sure things will change again in the next decade and we’ll have some other things happening within our evolutionary process but it’ll be interesting to see if we can maintain control over technology or will technology change us.  In the meantime, I’ll be ordering some new earphones.

ps

Technorati Tags: F5, humans, people, Pete Silva, security, behavior, education, technology, mobile, earphone, ipv6, computer injury, iPhone, web,

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, November 2, 2011

When Personal Security is Compromised

My Greatest Fears Realized

I debated about writing and/or blogging about this for a few days since it is very personal and didn’t want a pity-party coming my way.  But covering security, often from the human behavior standpoint, is what I do and what better way to share a security incident than when it happens directly to you.  Plus, being able to simply get it out is cathartic to some extent.  So here goes.

I attended the London IPExpo on Oct 19-20 at Earl's Court Two.  IPExpo is one of the largest IT infrastructure shows in Europe with many focus areas: Cloud, Storage, Security, Network, Virtualization and so forth - pretty much anything that touches IT.  I was invited by the F5 EMEA team to present at a number of speaking sessions F5 offered during the conference.  I also brought my family along since we hadn’t been to London in about 5 years and we really like the city. 

A couple weeks ago while I was at work at our EMEA headquarters there was an attempted abduction/kidnapping of my 5 year old daughter at one of the underground stations in London. My wife and daughter were on their way shopping when a man grabbed her.  He started with a little lure and when they got closer, he grabbed her arm and tried to yank her away from my wife.  Luckily my wife was able to keep hold of her and said to another woman, ‘Did you see what that guy just did to my daughter?’  She responded with, ‘yes and it looks like he’s doing it to another little girl!’  At that point, my wife asked for assistance from the Underground personnel.  The BTP (British Transportation Police) arrived and took him into custody while taking my wife and daughter to the station for statements.  My daughter asked if she could tell the officer about what happened and she told the PC, ‘that man grabbed my arm.’  That was pretty much all they needed, especially after viewing the CCTV footage and they didn't want to pressure a grueling interview of a child. 

I was finishing lunch with an F5 colleague when I got the call – ‘we are at the police station and you need to come now.’  At first I wasn’t sure if she was joking since she’s used that ‘I’m at the cop-shop’ routine before and I said, ‘What?!?, are you kidding?’  She then briefly told me about the incident, that he was in custody and at that point, it was no joke and my personal security had been threatened.  My co-worker immediately said, ‘I’ll take you wherever you need to go.’  This is one of the things that I love about my working family at F5, personal family is always first.  That was when the flood of emotions overcame me and the gravity of the situation hit.  As an aside, I don’t worry about my family going anywhere since my wife is a former Federal Law Enforcement Agent and certainly knows how to handle such situations.

I often look at human behavior and the ‘feeling of security’ or ‘peace of mind’ when discussing the topic.  I think that many of the fears about say, cloud security or any other topic that seems to take a few years to fully catch-on, has to do with the fact that we humans simply have a hard time with change.  Add loss of control to the picture makes it even more daunting.  Friends will say, ‘Let it go, it’s out of your control,’ and while you may understand, it doesn’t always make you feel any better.  That day, I did not have a feeling of security, peace of mind or any control over the situation.  I knew they were safe but I did not feel safe.  The mind kept telling the belly ‘it’s OK.’ but the gut wasn’t listening.  The stress increases, it’s harder to think, you’re sweating and it’s uncomfortable. 

Finally arriving at the station, the Sergeant tells me everyone is fine, the guy is arrested and we’ll let your family know you are here.  Some anxiety is finally released and soon, we get to hug.  More stress leaves the body and thinking becomes more focused but still has plenty of questions.  The BTP was great and gave us a ride in the blue and white back to our hotel. We were told on the way back that he is well known within the police department and a repeat offender.  Not sure if that was good or bad news.

The following day, the BTP called and said that the guy is being charged with assault (of a minor).  The CCTV caught everything.  Now, I’m not a big fan of the increased surveillance everywhere but in this situation it helped tremendously.  The next day it was determined that he needed a psychiatric evaluation and spent the next week in the mental facility.  My wife was also asked to appear for his trial, which was scheduled for the following week.  Wow, right quick as they fast tracked his trial.

My wife was at the Magistrates' Court most of the day.  After a week in the mental hospital, one doc called him crazy and another said he was fit.  That obviously determines which institution will be his new home. The judge had already watched the CCTV, received testimony from the responding officers, including the one who testified on my daughter's behalf and my wife's testimony only lasted about 10-15 minutes.  The Magistrate just wanted to hear if her story matched what was on the video and other witness statements. His lawyer tried to make it seem like he was just being 'friendly.'  She was let go after her testimony for the final determination.

Later that evening we got a call and was told he had been found Guilty of assaulting a minor.  We dropped a huge sigh of relief and the flow of comfort came back again.  I was starting to feel secure again, I started to feel somewhat in control again and I could think clearly once more.  I believe we all go through stages when trying to make a security decision or faced with a security situation.  It’s called Risk Analysis, Risk Management and Emergency Preparedness.  This was an extreme case, of course, but the threat came unannounced from the outside like many that occur within the corporate infrastructure.  My wife was prepared and I was uncomfortable yet, we still needed to handle the situation and mitigate the risk.  With your corporate infrastructure, be prepared, have a plan, mitigate risk and you will feel secure and know that you are.  And if an incident does arise, you’ll be ready.  Find that common ground between the head and the heart.  Often that’s hard when various groups have different fears and things that make them uncomfortable.  Acknowledge the human factor, ask questions and communicate. 

I truly appreciated the F5 support and warm wishes during this ordeal.  I’ve been with F5 since 2004 and while we recently announced that we’ve passed $1 Billion in revenue, which is an amazing financial accomplishment but I have to tell you that it is the feeling of family that keeps F5 rolling.

ps

Technorati Tags: F5, personal security, police, london, Pete Silva, security, BTP, vulnerabilities, crime, child, CCTV, the tube, abduction, identity theft

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, June 29, 2011

The Land of a Thousand Twist-Ties

imageHave you unpacked a children’s toy set, game, doll things or any kid’s play thing that has several pieces recently?  My 5 year old got a big box with a baby doll, her bassinette, bottle, baby food, rattles, and the other accessories any new born and mommy may need to care for the infant.  I’ve this noticed before but trying to take, rather unlatch all the stuff included is a major task.  Every little item was so secured to the inner packaging that it took me several minutes to untie, clip, cut and otherwise unshackle the items from the box.  Everything was locked down with either thick twist-ties or those plastic things with the ‘T’ on both ends – you know the ones where if it’s stuck to the item, you cut one end and shove the other end inside the item, never to seen again.  And just when you think you’ve got them all and ready to pull everything out, there’s always one more hidden one that snags the escape….and the adult’s patience.  This packaging, this method of securing toys sure makes getting to the toys a challenge.  There sometimes comes a point where you just want to rip it right out but you know it’ll damage the toy along with the kid’s excitement watching each accessory painstakingly extricated from the box.  And don’t get me started on those blister wrap packages – it’s like they soldered them closed and you need a chainsaw or a blowtorch just to open it.

Of course, this got me thinking.  These companies go to great lengths to secure the items within the packaging system.  Not only to keep them in place for a nice display but to also keep them from getting lifted in the store.  Each item is locked down from different angles at multiple points.  They are secured to the packaging and each other.  The twist-ties are wrapped in ways that I never thought they could.  The plastic ties are just strong enough to require a scissors or some hardened tool in some cases.  You can’t just snap it with your fingers and if you yank it, it might break, rip or otherwise damage the item it is holding.  It takes time to get to the good stuff.  It’s layered security.

Think about your own home.  People put locks, alarms and guard dogs to protect their house - they invest in layered security - and they feel safe, confident and don't worry about their valuable or sensitive possessions.  But when it comes to protecting data, systems and infrastructure, some might think that maybe one solution in one area will stop an intruder.   It is often difficult to quantify Information Security business value and ‘didn’t get attacked' doesn’t always equate to some monetary savings.  Often it is avoiding things like negative press, breaking customer loyalty/trust, damaging brand reputation, failing regulatory compliance, downtime and so forth.  Security is often thought of as insurance and the business value is not necessarily measured in dollars and cents....until you are exposed.  The real value is avoiding all of the above.  What would be the business value to any of the recent breached companies if they had not been hacked?  The value is keeping the people (users and employees) and business safe.  The value is comfort, confidence and compliance. It’s not that you need multiple twist-ties at every segment of your infrastructure but dated, static devices cannot protect against evolving, dynamic threats.  Protect your systems and your business with solutions that are adaptable, intelligent and provide the secure, strategic point of control for your application delivery infrastructure. 

Security is not only about risk mitigation/management but security is also Peace of Mind.  Knowing that stuff is protected and secure; knowing that the infrastructure will be available and scale; knowing that if something bad does happen, that the proper mechanisms are in place to mitigate the damage.  Plus, intruders will need more than scissors to play with their toys.

ps

Resources:

Technorati Tags: F5, data breach report, threats, Pete Silva, security, malware, technology, layered security, cyber-threat, attacks, risk, web, internet, cybercrime, identity theft, scam, data breach, toys

photo courtesy: http://commentarista.com/

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, March 24, 2011

Has The Sky Cleared on Cloud Security?

Last year I embarked on a blog series, lead by my trusty advisor CloudFucius, that evolved into an exploration of the numerous cloud computing surveys, reports, statistics and other feelings about the technology.  At the time, 4-5 surveys a week were being released covering some aspect of cloud computing and security was cited as the biggest hurdle in almost 90% of the surveys.  I also found that availability, control and a general lack of understanding were also drivers in challenges to cloud adoption.   Almost 6 months have passed since the last CloudFucius entry and I wanted to see if the same fears were still lingering or at least, were the current surveys reporting the same concerns from a year ago about Cloud Computing.

First up, is UK based technology publication, Computing.   Working with Symantec.cloud, they surveyed 150 IT decision makers and learned that as more companies embrace Cloud Computing, they are finding that the cloud solutions meet or beat, not only their expectations but also their own existing in-house solutions.  While on-premise security solutions might be adequate today, as the security threats evolve, the cloud providers may have the advantage over time due to the infrastructure investments in advanced filtering and detection along with 24/7 trained staff.  Last year, availability and uptime also emerged as concerns and today there is great interest in the contractual SLAs offered by cloud providers since it often surpasses what they are capable of in-house.  Resiliency and disaster recovery across multiple data centers can ensure that if there is an outage in one location, the customers can still access their data.  Management and control still create some anxiety but many IT teams are happy to abdicate routine maintenance, like OS patching and hardware upgrades, in exchange for management SLAs.  Now that the hype of cloud services has passed and many providers are proving themselves worthy, it is now becoming part of the overall IT strategy.  As the perceived threats to data security in the cloud dwindle, trust in the cloud will grow.

The Cloud Connect Conference in Santa Clara also released a survey during their gathering.  In that one, elasticity and speed of deployment were the top motivators to using cloud services.  Elasticity or the flexibility to quickly add or reduce capacity, can greatly influence the availability of data.  These folks however were less motivated by improved security or access to the provider’s IT staff.  Their top concerns were data privacy and infrastructure control.  I do find it interesting that last year the term ‘security,’ which can encompass many things, was the primary apprehension of going to the cloud while today, it has somewhat narrowed to specifically data privacy.  That too can mean several things but areas like outsider’s physical access to systems doesn’t seem to worry IT crews as much any more.

When it comes to our school/educational system, Panda Security released a study that focused on IT security in K-12 school districts.  Like many companies, they must deal with unauthorized user access, malware outbreaks and admit that IT security is time and resource intensive.  They do believe however that the cloud can offer security benefits and improve their overall infrastructure.  91% see value in cloud solutions and are planning to implement over the next couple years with 80% saying improved security was a main reason to deploy cloud-based security.

Finally on the consumer front, GfK Business & Technology surveyed 1000 adults about cloud services and storing content in the cloud.  With all of our connected devices – cell phone, computer, tablet, etc. – there will be a greater demand to move data to the cloud.  Not real surprising, less than 10% of the consumers surveyed fully understand what the cloud actually does.  The know of it, but not what it accomplishes.  With what you don’t understand comes fear.  61% said that they were concerned about storing their data in the cloud and almost half said they would never use the cloud unless it was easy to store and retrieve data.  As businesses begin to feel content with the cloud, they then need to both educate and communicate cloud benefits to their consumers.

So it does appear like comfort with the cloud is beginning to take hold and as cloud offerings mature, especially around security, err ah, I mean data privacy solutions, the fear, uncertainty and doubt from last year is starting to loosen and it sure seems like greater adoption is on the horizon.

And one from Confucius: They must often change who would be constant in happiness or wisdom.

ps

Resources:

Technorati Tags: F5, infrastructure 2.0, integration, cloud computing, Pete Silva, security, business, education, technology, application delivery, cloud, cloud survey, infrastructure 2.0, web, internet

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Thursday, February 3, 2011

Audio White Paper: Achieving Enterprise Agility in the Cloud

Cloud computing continues to be one of today’s most intriguing IT technologies, yet enterprises are still weighing whether it can help them achieve their business goals. Working together, VMware, F5 Networks, and BlueLock offer integrated solutions that help enterprises develop agility so they can easily and efficiently use cloud resources on demand to meet their changing needs.  Running Time: 24:21  Read full white paper here.  And click here for more F5 Audio.

ps

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_facebook[1] o_twitter[1] o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Technorati Tags: F5, integration, data center, Pete Silva, security, business, education, technology, application delivery, data replication, cloud, consolidation, WAN, web, internet, security, hardware, audio, whitepaper, big-ip

Posted via email from psilva's prophecies