Showing posts with label business architecture. Show all posts
Showing posts with label business architecture. Show all posts

Daily Tech Digest - December 20, 2022

Ransomware: It’s coming for your backup servers

Backup and recovery systems are at risk for two types of ransomware attacks: encryption and exfiltration – and most on-premises backup servers are wide open to both. This makes backup systems themselves the primary target of some ransomware groups, and warrants special attention. Hackers understand that backup servers are often under-protected and administered by junior personnel that are less well versed in information security. And it seems no one wants to do something about it lest they become the new backup expert responsible for the server. This is an age-old problem that can allow backup systems to pass under the radar of sound processes that protect most servers. It should be just the opposite. Backup server should be the most updated and secure systems in the data center. They should be the hardest to login to as Administrator or root. And they should require jumping through the most hoops to login remotely. An important role backup servers play is providing the means to recover from a ransomware attack without paying the ransom. 


How We Improved Application’s Resiliency by Uncovering Our Hidden Issues Using Chaos Testing

The goal of chaos engineering is to educate and inform the organization of unknown vulnerabilities and previously unanticipated outcomes of a computer system. A primary focus of these complex testing procedures is to identify hidden problems that can potentially arise during production environments prior to an outage failure outside of the organization’s control. Only then can the disaster recovery team address systematic weaknesses and enhance the system’s overall fault-tolerance and resiliency. Hence, Chaos testing is being carried out at various levels. ... Chaos testing is a new concept, but we always had the mindset to perform it, and we did perform it sometimes, without knowing that it was a chaos testing. It has its own principles, benefits and pitfalls. However, I would advise all teams to weigh the pros and cons of conducting these tests before formulating a plan. You should be very clear as to what you want to achieve from these disruptive tests. Take permissions from your bosses and convince them why it is important to carry out these tests. 


How Our Behavioral Bad Habits Are a Community Trait and Security Problem

Internal naming groups and conventions become exposed to the outside world in a variety of ways. They're buried in website code, detailed in technical documentation or as part of APIs, or just simply published in public system information. Admittedly, this is a very large haystack, but finding the needles is exactly what the patent I was involved in (US Patent 10,515,219) endeavors to do. Site-scanning tools collect a range of information, and unsurprisingly, an overload of information. My approach strips out all the technical programming information (such as markup, JavaScript, etc.), and leaves just words. It then compares results with lists of English words. The algorithm then identifies groupings of words or abbreviations not present in the selected language that, presumably, may signify an internal naming convention or credentials. As is common with brute-force campaigns, it may not, but as the axiom goes, the attacker only needs to be right once, so the ability to generate context-sensitive word lists may make or break your next campaign. This is when the picture may start to become clearer and the shape of things such as user groups, system names, etc., manifest.


The Agile Compromise Calls for Courage

We cannot eliminate the risk of building the wrong thing with better design and more focus groups. We can only do it by shorter and more frequent iterations of a working product that is incomplete and maybe not that great yet. That’s the Agile compromise. Shorter cycles decrease the risk of building the wrong thing but increase the risk of degrading the process. Accruing technical debt is one. Not a necessary consequence, just a standard price to pay for quicker deliveries. No pundit with stories about the constant commitment to quality will convince me otherwise. If you want greater speed, accept more risks. The Agile compromise towards risk-taking also recognizes that software, as a creative discipline, by nature exposes black swans: the risks we didn’t know we would ever run into. No engineering approach provides full reassurance against them, nor can testing and validation ever give you full peace of mind. It’s a little bit scary, but if you pride yourself on an Agile mindset, you must embrace it. Software is complex rather than complicated. Its many moving parts behave in unpredictable ways when unleashed on the world. Risks are a natural part of that property.


GPT: High-tech parlor trick or the first real AI for everyday use?

In many cases, such as ChatGPT, AI is still a parlor trick that will enthrall us until the next trick comes along. In some cases, it’s a useful technology that can augment both human and machine activities through incredibly fast analysis of huge volumes of data to propose a known reaction. You can see the promise of that in the GPT-fueled Copysmith.AI even as you experience the Potemkin village reality of today. At a basic level, AI is pattern matching and correlation done at incredible speeds that allow for fast reactions — faster than what people can do in some cases, like detecting cyberattacks and improving many enterprise activities. The underlying algorithms and the training models that form the engines of AI try to impose some sense onto the information and derived patterns, as well as the consequent reactions. AI is not simply about knowledge or information, though the more information it can successfully correlate and assess, the better AI can function. AI is also not intelligent like humans, cats, dogs, octopi, and so many other creatures in our world.


How you can stop corporate login credential theft

Organizations should take a layered approach to credential management. The goal is to reduce the number of sites users have to put passwords into. Organizations should endeavor to implement single sign-on (SSO) for all reputable necessary work applications and websites. All SaaS providers should support SSO. If there are logins that require different credentials, a password manager would be helpful in the interim. This also provides a way for employees to know if a login page can be trusted, as the password manager won’t offer credentials up for a site it does not recognize. Organizations should also enable multi-factor authentication (MFA) to secure logins. FIDO2 is also gaining adoption. It will provide a more robust solution than traditional authenticator apps, although those apps are still better than codes sent via text messages. Not all of this is foolproof, and risky login pages could slip through the net. A last resort is needed for flagging risky login pages to employees. This can be done by analyzing, in real time, threat intelligence metrics, webpage similarities, domain age and how users got to a login page. 


Security Risks, Serious Vulnerabilities Rampant Among XIoT Devices in the Workplace

The potential intent of assorted Chinese hardware manufacturers (such as Huawei and ZTE) led to a 2018 ban on use of their equipment by federal agencies. These devices remain widely in use in private organizations, however, and sometimes banned devices slip through dragnets via the process of “white labeling”. Organizations also often do not have visibility into the code that XIoT devices run on. When these devices draw on third-party firmware libraries, several possible security risks emerge. One is simply that the vendor will abandon support for the device, no longer issuing security patches to address emerging vulnerabilities. Another is that the code may be maintained by open source developers, who have the capability to insert malicious elements or even abandon or spike the project unexpectedly. A simple problem that has dogged XIoT devices from the very beginning also remains; the manufacturers are often not tech outfits and thus are not familiar with security by design elements, and/or do not have the budget in place to add them and still come in at their desired price points in competitive markets.


Understanding e-signatures: the key differences and requirements

A QES is considered to have more probative value than an AES, which means that courts will give more weight as evidence. The first key difference is that they offer a higher level of security than AES. This is because qualified signatures are created using a qualified signature creation device (QSCD), which stores the signing key. Examples of physical QSCDs include smart cards, SIM cards or USB tokens. It’s also possible for signatories to create a QES without having a physical device in their hands. In this instance, signatories remotely access a signing key, which is stored in a trusted service provider’s data centre. This is often the preferred choice for organisations since it streamlines device management. A QES must also be based on a ‘qualified certificate for electronic signatures’, which is another key difference between an AES and a QES. Only ‘Qualified trust service providers’ (QTSPs) listed on the European Union’s trusted provider database can issue this certificate. To become a QTSP, organisations must successfully complete a series of evaluations and audits that ensure compliance with eIDAS regulations.


Top cloud strategy mistakes CIOs can’t help making

“Not architecting for the cloud,” says IDC analyst Dave McCarthy, when asked where CIOs commonly go wrong when building their cloud strategy. “While it is possible to ‘lift and shift’ existing workloads, enterprises often experience less than desirable costs and performance with this approach. You need to adapt applications to cloud-native concepts to realize the full value.” CIOs also often make the mistake of “not implementing enough automation,” says McCarthy, who is research vice president of cloud and edge infrastructure services for IDC. “Best practices in cloud include automating everything from the deployment of infrastructure and applications to management and security. Most outages or security breaches are the result of manual misconfigurations. But perhaps the worst sin CIOs can make, analysts across the spectrum agree, is fail to plan for the shift in culture and skills required to devise and implement a successful cloud strategy. The cloud functions differently than traditional IT systems, and a cloud strategy must not only require new skills but a change in thinking about how to design and manage the environment, McCarthy says.


What is a business architect and how do you become one?

An enterprise architecture is comprised of different kinds of components (business strategy and outcome, technology platforms and infrastructure, and security), and a business architecture encompasses how all these things come together to best serve the business. It is a component of enterprise architecture. My responsibility as a business architect is to manage the business architecture practice and its governance. I primarily focus on establishing standards and best practices for our team's deliverables and developing relationships within our organization. I also collect information on our business and map domains (including capabilities, value streams, information, and organization) according to the business architecture framework to gain insights. I think business architecture is foundational to organizations today. A strategy is a plan of action to achieve a goal. My team receives business ideas and potential projects that align with our organization's strategies and influence our performance as a leader in our market. 



Quote for the day:

"The leader has to be practical and a realist, yet must talk the language of the visionary and the idealist." -- Eric Hoffer

Daily Tech Digest - November 06, 2022

Best Practices for Enterprise Application Architecture

The iterative approach is a more practical method of building enterprise application architectures, where you start small and build out your architecture in small, incremental steps. This approach is particularly useful for enterprises with limited resources and can’t afford to build a full-scale architecture from scratch. Instead of starting with a full-scale architecture, design and implement a series of smaller “proof-of-concept” applications that prove the feasibility of your ideas. Once these applications are ready, you can scale them into an enterprise-level solution. ... The Agile adoption process is a critical step for any enterprise application, and the implementation of agile methodology can be daunting for organizations that have not done it before. However, there are many benefits to adopting a more agile development approach, which includes delivering software faster and at less cost. ... EA governance is the process involved in managing and maintaining an EA. This includes identifying and defining an EA’s goals, objectives, and key performance indicators (KPIs). It also involves establishing a governance framework that supports the EA’s development, management, and maintenance.


Technology leader shall be open to accepting changes

As systems evolve over time, so does their complexity. Maintaining such systems or components will always be a challenge. While people will be on the move, there shall be an inventory of all the systems and components, along with actively maintained documentation, which many organisations don’t adhere to. Maintainability should be considered as a key consideration while designing and building systems. ... Technology leaders must demonstrate consistent delivery of high-quality services, which necessitates the implementation of appropriate systems and processes. Simultaneously, such systems and processes must not be a barrier to adapting to a changing business and technology ecosystem. ... Like GDPR, many countries are coming up with regulations for data privacy and cyber security requirements. Coping with such demands is necessary, but it is difficult because it is complex, dynamic, and ever-changing. To add to that, establishing a return on investment for security solutions is very challenging.


7 hard truths of business-IT alignment

Some CIOs treat IT-business alignment as their own responsibility. That’s a mistake, experts say. “The leadership team below the CIO also needs to be customer facing. It needs to be able to help solve problems. It shouldn’t just be going away and writing code,” Pettinato says. “To make it scalable, you need to take it beyond just one individual.” “I clearly can’t, myself, be involved in every organizational conversation,” Barchi says. “That is where trusting your team helps. There are many leaders on my team who are in these meetings day in and day out, solving problems in real time.” In fact, he says, creating a team that’s capable of doing this is the most important part of his job. “As I’ve grown as a leader, I’ve recognized that my contribution is not my own technical skill and my ability to make decisions. It’s my ability to create a team that can do all of that,” Barchi says. “I think CIOs do well when we know that our job is not to be involved in every technology decision — it’s to create the environment where that can happen and create a team that can do that.”


Teaching is complicated. But technology in the classroom doesn't have to be

When the pandemic forced schoolchildren to learn from home and adapt to digital learning, educators lost their students' attention, and learning suffered. But once schools opened up, digital learning didn't disappear; for many, it became the norm. Seage says technology should never be the driver of the classroom. "The technology has to complement what you do. It complements all different teaching styles," he says. As a former student, Seage recalls the difficulty teachers faced in finding novel ways to engage students and wanted to offer a solution. Interactive whiteboards offer a low learning curve for teachers and students while also promoting interaction and collaboration, he says. In the school's gymnasium, for instance, boards serve as an enhanced coaching tool, allowing coaches and players to re-watch game footage during practice, or strategize game plays for future matches. Micah Shippee, director of education technology consulting and solutions at Samsung, is a former educator who now works with schools to adopt Samsung technology.


How to Choose the Best Software Architecture for Your Enterprise App?

Patterns in architecture are ways to fix common design problems that can be used repeatedly. Their framework makes it easier to reuse code and keeps apps running smoothly for longer. In addition to being scalable, flexible, and easy to keep up with, the software must be able to handle a wide range of requests without any problems. But making software hard to use could go against these goals because it makes it less likely that people will use the software and use it well. Because of this, the software needs to be very flexible to be changed to meet the needs of each user. ... An event producer and a consumer are the two most important parts of an EDA system. A producer is someone who knows how to put on an event. Put another way, it is up to the person watching the possibility to pay attention to what is happening. Event-driven architecture (EDA) is a way of making software that relies on events to send messages between modules. It breaks applications into small pieces called modules that can run on their own and share data with a small number of other modules using standard protocols. 


Is there a cyber conflict happening behind the scenes?

There’s a global digital dependency happening right now, accelerated even further by the pandemic driving a need for remote services in nearly every industry. While this adaptation is an overall benefit to progressive societies, it opens new and innovative ways for cyber attackers to target organizations and consumers alike. Even those who aren’t connected are inadvertently impacted by the digital world and cyberattacks, which has people around the world asking: is there a cyber battle going on? ... At the beginning of the Russian-Ukrainian conflict earlier this year, Russians attacked a satellite provider in Ukraine, affecting countries including Germany and France and bricking edge devices across the continent. This affected both civilian and military communication, hindering war efforts on the Ukraine side and evacuation efforts for fleeing citizens. These attacks aren’t just being carried out by high-level nation-state actors, they’re also being carried out by hacktivists and volunteers. Even simple distributed denial-of-service (DDoS) attacks can generate damage with the right amount of devices. 


IT Ops 4.0: Operations Architecture For The Industry Automation Age

A structured communication effort is essential to gaining support and motivating employees. Every organization has its way of getting started and doing this, but most steps involve at least three elements. Engage people in alignment with the vision. It’s essential to be transparent about where we are (or where we started), where we’re heading, and how we’re getting there as a team. This is to demonstrate the value of transformation, both for the organization and its employees.It is essential to experience problems, challenges, or innovative approaches. Employees gain a better understanding by learning from the companies leading the way. Tours enable employees to think outside the box, hear stories of change, and discuss the challenges that come with it.When people know that change has been around for a long time and understand why it is happening, they tend to want to learn as much as possible about it. Employers need to gain momentum and make it as easy as possible to provide access to information and resources on new technologies and approaches.


Why Wasm is the future of cloud computing

Wasm is already very capable. And with the new technologies and standards that are on the way, Wasm will let you do even more. ... WASI will provide a standard set of APIs and services that can be used when Wasm modules are running on the server. Many standard proposals are still in progress, such as garbage collection, network I/O, and threading, so you can’t always map the things that you’re doing in other programming languages to Wasm. But eventually, WASI aims to provide a full standard that will help to achieve that. In many ways, the goals of WASI are similar to POSIX. Wasm as it now stands also doesn’t address the ability to link or communicate with other Wasm modules. But the Wasm community, with support from members of the computing industry, is working on the creation of something called the component model. This aims to create a dynamic linking infrastructure around Wasm modules, defining how components start up and communicate with each other (similar to a traditional OS’s process model).


Making the case for security operation automation

Security teams must be able to scale operations to deal with the increasing volume of everything coming at them. Faced with a global cybersecurity skills shortage, CISOs need alternatives to hiring their way out of this quagmire. ... When it comes to security operations process automation, one might equate this activity with security orchestration, automation, and response (SOAR) technology. In some cases, this is a correct assumption, as 37% of organizations use some type of commercial SOAR tools. Interestingly, more than half (53%) of organizations eschew SOAR, using security operations process automation functionality within other security technologies instead – security information and event management (SIEM), threat intelligence platforms (TIPs), IT operations tools, or extended detection and response (XDR), for example. Those organizations using SOAR admit that it is no day at the beach – 80% agree that using SOAR was more complex and time consuming than they anticipated. Technology aside, security professionals acknowledge that there are a few major impediments to security operations process automation. 


Gender has no bearing on your abilities in tech industry

According to statistical information, there is clearly not an equal representation of women in technology. ... The first is stereotyping, conscious & unconscious biases, which occur when people believe that being a woman, may have a negative impact on performance, level of intelligence or aptitude. I believe it began when women were not encouraged to pursue STEM courses – Science, Technology, Engineering and Math. Nowadays, there are concerted efforts and interventions to encourage women to pursue STEM degrees. Secondly, there aren’t enough role models, advocates, and people who are challenging the status quo. Although overall, things have improved significantly in recent years. I do not recall knowing any Nigerian woman in Data Analytics or Business Intelligence when I started my career. I never met them or heard about them. I seriously doubt they existed at the time, which says a lot. The lack of role models at the time was a major factor, but I am glad things are improving now.



Quote for the day:

"Setting an example is not the main means of influencing others, it is the only means." -- Albert Einstein

Daily Tech Digest - June 14, 2022

Business Architecture - A New Depiction

Crucial to this depiction are components which exist in both the vertical pillars and the horizontal Business Architecture layer as follows: Application Architecture: includes the Business Process component, to associate application components (logical & operational) with the business activity they support. Information Architecture: includes the Information Component from a business perspective separately from any logical or operational representation of that information by data (structured or unstructured). Infrastructure Architecture: contains the location component. This is to recognize that business infrastructure is linked to an organization / location either by physical installation or network access. Business Architecture consists of these business components – shared with the other domains – and, in addition, more complex views which link the architecture with the business plans. For example, an architecture view for a business capability (as defined through capability-based planning) would show how the components support that capability. The 3 vertical domains can be considered to constitute IT Architecture (for the enterprise). 


Meet Web Push

One goal of the WebKit open source project is to make it easy to deliver a modern browser engine that integrates well with any modern platform. Many web-facing features are implemented entirely within WebKit, and the maintainers of a given WebKit port do not have to do any additional work to add support on their platforms. Occasionally features require relatively deep integration with a platform. That means a WebKit port needs to write a lot of custom code inside WebKit or integrate with platform specific libraries. For example, to support the HTML <audio> and <video> elements, Apple’s port leverages Apple’s Core Media framework, whereas the GTK port uses the GStreamer project. A feature might also require deep enough customization on a per-Application basis that WebKit can’t do the work itself. For example web content might call window.alert(). In a general purpose web browser like Safari, the browser wants to control the presentation of the alert itself. But an e-book reader that displays web content might want to suppress alerts altogether. From WebKit’s perspective, supporting Web Push requires deep per-platform and per-application customization.


Introduction to Infrastructure as Code - Part 1: Introducing IaC

In recent years, development has shifted away from monolithic applications and towards microservices architectures and cloud-native applications. However, modernizing apps introduces complexity, as maintaining the cloud computing architecture requires infrastructure automation tools, efficient provisioning, and scaling of new resources. Too many developers still see infrastructure provisioning and management as an opaque process that Ops teams perform using GUI tools like the Azure Portal. Infrastructure as code (IaC) challenges that notion. The practice of IaC unifies development and operations, creating a close bond between code and infrastructure. Why should we use IaC? When you develop an application, you create code, build and version it, and deploy the artifact through the DevOps pipeline. IaC allows you to create your infrastructure in the cloud using code, enabling you to version and execute that code whenever necessary. This three-article series starts with an introduction to IaC. Then, the following two articles in this series show how to use the Bicep language and Terraform HCL syntax to create templates and automatically provision resources on Azure.


VPN providers flee Indian market ahead of new data rules

The new directive by India's top cybersecurity agency, the Indian Computer Emergency Response Team (Cert-In), requires VPN, Virtual Private Server (VPS) and cloud service providers to store customers' names, email addresses, IP addresses, know-your-customer records, and financial transactions for a period of five years. SurfShark announced on Wednesday in a post titled "Surfshark shuts down servers in India in response to data law," that it "proudly operates under a strict "no logs" policy, so such new requirements go against the core ethos of the company." SurfShark is not the first VPN provider to pull its servers from the country following the directive. ExpressVPN also decided to take the same step just last week, and NordVPN has also warned that it will be removing physical servers if the directives are not reversed. ... Like many businesses around the world, Indian companies have increased their reliance on VPNs since the COVID-19 pandemic forced many employees to work from home. VPN adoption grew to allow employees to access sensitive data remotely, even as companies started adopting other secure means to allow remote access such as Zero Trust Network Access and Smart DNS solutions.


5 top deception tools and how they ensnare attackers

To work, deception technologies essentially create decoys, traps that emulate natural systems. These systems work because of the way most attackers operate. For instance, when attackers penetrate the environment, they typically look for ways to build persistence. This typically means dropping a backdoor. In addition to the backdoor, attackers will attempt to move laterally within organizations, naturally trying to use stolen or guessed access credentials. As attackers find data and systems of value, they will deploy additional malware and exfiltrate data, typically using the backdoor(s) they dropped. With traditional anomaly detection and intrusion detection/prevention systems, enterprises try to spot these attacks in progress on their entire networks and systems. Still, the problem is these tools rely on signatures or susceptible machine learning algorithms and throw off a tremendous number of false positives. Deception technologies, however, have a higher threshold to trigger events, but these events tend to be real threat actors conducting real attacks.


MIT built a new reconfigurable AI chip that can reduce electronic waste

The team's optical communication system comprises paired photodetectors and LEDs patterned with tiny pixels. The photodetectors feature an image sensor for receiving data, and LEDs transmit that data to the next layer. Since the components must work like a LEGO-like reconfigurable AI chip, they must be compatible. "The sensory chip at the bottom receives signals from the outside environment and sends the information to the next chip above by light signals. The next chip, which is a processor layer, receives the light information and then processes the pre-programmed function. Such light-based data transfer continues to other chips above, thus performing multi-functional tasks as a whole," the team explained. ... The team fabricated a single chip with a computing core that measured about four square millimeters. The chip is stacked with three image recognition "blocks", each comprising an image sensor, optical communication layer, and artificial synapse array for classifying one of three letters, M, I, or T. They then shone a pixellated image of random letters onto the chip and measured the electrical current that each neural network array produced in response.


Augmented reality head-up displays: Navigating the next-gen driving experience

HUDs work by projecting a transparent 2D or 3D digital image of navigational and hazard warning information, for example, onto the windscreen of the vehicle. These projected images then merge with the driver's view of the road ahead. Windshield HUDs, for example, are set up so that the driver does not need to shift their gaze away from the road in order to view the relevant, timely information. This technology helps to keep the driver's attention on the road, as opposed to the driver having to look down at the dashboard or navigation system. Technological advances in this area have led to HUDs with holographic displays and AR in 3D. This added depth perception makes it possible to project computer-generated virtual objects in real time into the driver's field of view to warn, inform or entertain the user. The driver's alertness to road obstacles is increased by enabling shorter obstacle visualization times, and eye strain and driving stress levels are reduced. "Holographic HUDs are paramount if we are to explore the possibilities of augmented and mixed reality for road safety," said Jana


Nigerian Police Bust Gang Planning Cyberattacks on 10 Banks

The operation was a coordinated effort between the Economic and Financial Crimes Commission of Nigeria, Interpol, the National Central Bureaus and law enforcement agencies of 11 countries across Southeast Asia, according to Interpol. The operation was initiated after Interpol's private sector partner Trend Micro provided operational intelligence to the agency about the "emergence and usage of Agent Tesla malware" in this case. Agent Tesla was found on the mobile phones and laptops of the syndicate members that were seized by the EFCC during the bust. "Through its global police network and constant monitoring of cyberspace, Interpol had the globally sourced intelligence needed to alert Nigeria to a serious security threat where millions could have been lost without swift police action," Interpol Director of Cybercrime Craig Jones says in the statement. "Further arrests and prosecutions are foreseen across the world as intelligence continues to come in and investigations unfold." 


10 ways DevOps can help reduce technical debt

In most cases, technical debt occurs because development teams take shortcuts to meet tight deadlines and struggle with constant changes. But better collaboration between dev and ops can shorten SDLC, fasten deployments, and increase their frequency. Moreover, CI/CD and continuous testing make it easier for teams to deal with changes. Overall, the collaborative culture encourages code reviews, good coding practices, and robust testing with mutual help. ... Technical debt is best controlled when managed continuously, which becomes easier with DevOps. As it facilitates constant communication, teams can track debt, facilitate awareness and resolve it as soon as possible. Team leaders can also include technical debt review into backlog and schedule maintenance sprints to deal with it promptly. Moreover, DevOps reduces the chances of incomplete or deferred tasks in the backlog, helping prevent technical debt. ... A true DevOps culture can be the key to managing technical debt over long periods. DevOps culture encourages strong collaboration between cross-functional teams, provides autonomy and ownership, and practices continuous feedback and improvement.


Once is never enough: The need for continuous penetration testing

The traditional attitude to manual pen testing is kind of like the traditional approach to driving navigation: nothing can replace the sophistication and accrued knowledge of a human. A taxi driver will always beat Google Maps, and a trained pen testing professional will find vulnerabilities and attacks that automated tests may miss, or identify responses that appear legitimate to automated software but are actually a threat. The truth is, on a case-by-case basis, this could conceivably be true. But with off-the-shelf tools and services like RaaS (Ransomware as a Service) or MaaS (Malware as a Service) that use AI/ML capabilities to enhance attack efficiency – you’d need an army of pen testers to truly meet the challenges of today’s cyber threats. And once you’d found, trained and employed them – cyberattackers would simply increase their automation efforts and you’d need to draft another army. Not a sustainable cybersecurity model, clearly. Similarly, the widescale adoption of agile development methodologies has translated into increasingly frequent software releases.



Quote for the day:

"If you are truly a leader, you will help others to not just see themselves as they are, but also what they can become." -- David P. Schloss

Daily Tech Digest - August 06, 2021

The Role of Business Architecture in Defining Data Architecture

Data architects can systematically examine the information concepts in the information map and define corresponding data entities for each of those concepts. There is no assumption that the data model and the information map will be identical. Data architects will apply data modeling techniques to formalize data entities as appropriate. The information map’s role is rather to provide business ecosystem transparency, delivering a business-driven perspective to ensure that data models and related deployments enable and do not hinder the organization they are meant to benefit. As data entities are defined, data architects can leverage information concept relationships to establish corresponding relationships among data entities in the data models. All information maps have a set of relationships that data architects may interrogate to derive their entity relationships. The next step is to attribute the data entities. Figure 5 depicts data attribute derivation using child capabilities defined under Agreement Management.


HTTP/2 Implementation Errors Exposing Websites to Serious Risks

To show how such an attack would work, Kettle pointed to an exploit he executed against Netflix where front-end servers performed HTTP downgrading without verifying request lengths. The vulnerability allowed Kettle to develop an exploit that triggered Netflix's back-end to redirect requests from Netflix's front-end to his own server. That allowed Kettle to potentially execute malicious code to compromise Netflix accounts, steal user passwords, credit card information, and other data. Netflix patched the vulnerability and awarded Kettle its maximum bounty of $20,000 for reporting it to the company. In another instance, Kettle discovered that Amazon's Application Load Balancer had failed to implement an HTTP/2 specification regarding certain message-header information that HTTP/1.1 uses to derive request lengths. With this vulnerability, Kettle was able to show how an attacker could exploit it to redirect requests from front-end servers to an attacker-controlled server. 


How to prepare your Windows network for a ransomware attack

Too many of us are still reliant on older server platforms that make it harder to roll out security solutions through Active Directory. We may have Server 2016 and Server 2019 servers in our network, but we’re not taking advantage of the security features of that domain functional level. Too many of us are still on older forest and domain functional levels because we have older servers or applications and a lack of testing that keep us from rolling out these newer features. Or we have vendors that won’t certify newer platforms and Active Directory features. Raising your forest level to 2016 provides many features that better protect the network such as privileged access management and automatic rolling of NTLM secrets on a user account. If your functional level is still 2008 R2, you don’t have a UI for the Active Directory recycle bin, which makes it easier for recovery. It also doesn’t allow you to get rid of an old security hole of unchanging passwords on your service accounts if you are still running 2008 R2 functional level.


Can the public cloud become confidential?

The Confidential Cloud is a secure confidential computing environment formed over one or more public cloud providers. Applications, data, and workloads within a Confidential Cloud are protected by a combination of hardware-grade encryption, memory isolation, and other services in the underlying host. Like micro-segmentation and host virtualization, resources within a Confidential Cloud are isolated from all processes and users in a default zero-trust posture. But the Confidential Cloud does more than isolate network communications, it isolates the entire IT environment used by a workload—including compute, storage, and networking. That enables support for virtually any application. Because Confidential Cloud protection is inextricably part of data, the protection extends wherever the data goes. Legacy enterprise perimeters are defined by physical appliances, but a Confidential Cloud’s perimeter is established by an inextricable combination of hardware isolation, encryption, and explicit least-privileged access policy. 


Why the future of service is hybrid

For many businesses though, this has led to employment issues, especially as the workforce ages. Knowledge loss is an increasingly common problem. According to the Service Council, 70% of service organisations say they would be burdened by the knowledge loss of a retiring workforce in the next five to 10 years, while 50% claim they are currently facing a shortage of resources to adequately meet service demand. Automation is great, but it will only go so far to help. Interestingly, the TSIA recently found that half of all field services organisations don’t have a formal career path in place for their field service engineers. This, in my view, is a huge point of unnecessary commercial risk. These organisations are not doing enough to prepare younger service techs for a mixed reality future – one where they will have to work more closely with digital technology and machines than any previous generation. It won’t happen by accident. There is certainly a need for an integral ‘system of record’ that captures accurate data about equipment ‘as maintained’. 


How to Recognise and Reduce HumanDebt

HumanDebt™ is the equivalent to Technical Debt but for people. All of the initiatives, the projects, the intentions we (the organisation) had to do better by our employees, but we abandoned halfway. All of the missed opportunities to make their lives and their work easier and more joyful. All of the empty talk on equality, respect, lack of blame, courage and trust. All of the missing focus on empowered teams and servant leadership. All of the lack of preoccupation or resources for building better team dynamics. All of the toxic culture created by these. That’s Human Debt. ... It is tempting to believe that this type of debt is the organisation’s problem only. Even more tempting is to believe that it only happens at that macro, cultural level and that that is the only level where it can be fixed. Both are fallacies though. It’s important that the organisation has a degree of recognition, which enables them to offer "organisational permission" and help, as there really is only one solid thing to start with - empower teams to work on their own dynamics and improve their happiness by giving them the resources they need to do so.


How to deal with a toxic teammate

Toxic behavior may have occurred less frequently or been less noticeable during the pandemic. “There has been more stress but also a lot of grace-giving and cutting-of-slack to account for whatever people have going on in their personal and professional lives,” Cuthbert says. “The water cooler is gone and hasn’t been replaced and there is less of a forum for those who are negative or unhappy.” But it can take numerous forms. “Motivating through fear and unattainable goals and timelines, obfuscating expectations and scope of job descriptions or projects, not clearly identifying the North Star and who is doing what, being inconsistent in holding people accountable, dominating, yelling, talking over others, and interrupting are all signs of toxic behavior,” Mattheis says. “Working remotely has not changed that reality. What it has done is adjust how it looks and feels as well as made it more difficult to speak to it and hold people accountable.” Like dealing with a toxic boss, responding to a peer’s unhealthy dynamics can be tricky, but there are constructive approaches for using emotional intelligence to address the issues and mitigate their impact on your own productivity and well being.


Chip shortage has networking vendors scrambling

The semiconductor industry is predicting a possible recovery in 2023. But who knows what demand will be at that time, Sadana said. Part of the problem is that current semiconductor foundry capacity is not adequate to meet the recent surge in global demand, wrote Baron Fung, industry analyst at Dell'Oro Group, in a recent blog. “The cost of servers and other data center equipment is projected to rise sharply in the near term partly due to the global semiconductor shortages,” Fung stated. “An increase of server average selling prices could approach the double-digit level that was observed in 2018, which was another period of tight supply and high demand. However, in the longer term, we anticipate that supply and demand dynamics could reach equilibrium and that technology transitions could drive market growth.” ... “We continue to proactively manage the supply chain, and our strategic relationship with Broadcom is helping us in this regard. Importantly, we have secured vendor commitments that will allow us to accelerate product delivery and bring down backlog as of Q2 and beyond,” Thomas stated.


Why businesses should embrace cloud-native development

Containers provide the infrastructure to realise a microservices architecture in practice. It provides individual standalone components for an app that can be independently replaced, changed, or removed without jeopardising the rest of your infrastructure. This is essential to realise the cloud-native vision because the completeness of a container package and its agnosticism to its environment ensures the portability needed for cloud-native apps – containerised apps can be deployed in whatever cloud environment you operate in, whether it be public, private, or hybrid. The use of containers in the cloud-native model thereby brings speed and scalability that cannot be achieved through traditional systems architecture, and addresses a fundamental business need: for changes in software to be applied quickly and seamlessly so that tasks can be completed efficiently and inexpensively. For all these reasons, containers are one of the biggest trends in enterprise software development


CISA's Easterly Unveils Joint Cyber Defense Collaborative

"To some extent, some of these activities are already going on across the federal government, but they're running largely in stovepipes. So the idea is that we bring together our partners in the government and our private sector partners to really mature this planning capability," Easterly said. Besides CISA and its parent organization, the Department of Homeland Security, other federal government participants will include the U.S. National Security Agency, U.S. Cyber Command and the FBI. Easterly announced nine companies have signed up to participate,: CrowdStrike, Palo Alto Networks, FireEye, Amazon Web Services, Google, Microsoft, AT&T, Verizon and Lumen. The JCDC will build on the relationships CISA has with Information Sharing and Analysis Centers, or ISACs, which represent various industries. The concept for the new initiative came from the Cyberspace Solarium Commission, which published its report in 2020 (see: Senate Approves Chris Inglis as National Cyber Director).



Quote for the day:

"Added pressure and responsibility should not change one's leadership style, it should merely expose that which already exists." -- Mark W. Boyer

Daily Tech Digest - January 16, 2021

How next-gen cloud SIEM tools can offer critical visibility for effective threat hunting

Organizations must adopt a new cloud-centric mentality, supported by a combination of new security solutions ready to handle the high volume and velocity of data flowing across cloud environments. Organizations must focus on tools such as Next-Gen SIEM, cloud-focused tools such as cloud access security broker (CASB) and cloud security posture management (CSPM), and modern consolidated network and security services such as secure access service edge (SASE), which all enable modern security architecture approaches. These scalable tools include license models not based on the volume of data ingested but other variables, such as number of users monitored. CSPM and CASB can help users adopt new policy enforcement practices, helping organizations to navigate complex security settings and services from public cloud providers and cover any gaps in visibility from the multiple IaaS, PaaS and SaaS services adopted. Additionally, where users are operating off of personal devices and accessing cooperate resources, SASE offerings help transition controls such as secure web gateways to a cloud-based model from anywhere in the world. Companies no longer need to debate losing visibility for a better price or improved network resiliency.


Five emerging fraud threats facing businesses in 2021

Synthetic identity fraud – when a fraudster uses a combination of real and fake information to create an entirely new identity – is currently the fastest growing type of financial crime. The progressive uptick in synthetic identity fraud is likely due to multiple factors, including data breaches, dark web data access and the competitive lending landscape. As methods for fraud detection continue to mature, fraudsters are expected to use fake faces for biometric verification. These “Frankenstein faces” will use AI to combine facial characteristics from different people to form a new identity, creating a challenge for businesses relying on facial recognition technology as a significant part of their fraud prevention strategy. ... Once the stimulus fraud attacks run their course, it is predicted that hackers will increasingly turn to automated methods, including script creation (using fraudulent information to automate account creation) and credential stuffing (using stolen data from a breach to take over a user’s other accounts) to make cyberattacks and account takeovers easier and more scalable than ever before.


A guide to being an ethical online investigator

It’s not just legal issues that would-be amateur online investigators need to be aware of. Much of the online activity carried out in the wake of the Capitol riots raises ethical questions, too. Should a person who didn’t storm the Capitol but attended the rallies leading up to the riots be identified and risk punishment at work? Do those who were in and around the Capitol on January 6 automatically lose the right to privacy even if they weren’t involved in riots? It’s worth thinking through how you feel about some of these questions before you continue. Few are clear cut. So, where does the information come from? “Our bread and butter is open source,” Fiorella says. “Open-source media” refers to information that is publicly available for use. Data archivists, or those who collect and preserve information online for historical purposes, accessed such open-source data to save posts before they disappeared as social media companies pushed President Donald Trump and many of his supporters off their platforms. “If you were at the Capitol storming and recorded video and took selfies that anyone can access, and it’s openly available on the internet, it’s fair game,” says Fiorella.


Top Five Artificial Intelligence Predictions For 2021

Though regulation hasn’t reached a boiling point yet, AI governance will continue to be a hot topic in 2021. As AI becomes more pervasive, more and more stakeholders are waking up to the potential problems it introduces to the public. In response, organizations everywhere — from the most cutting-edge to the laggards — will be expected to deliver AI systems that are responsible, transparent, and unbiased. But whose responsibility is it to make sure this happens and regulates AI – the government, businesses, industry groups, or some combination? If businesses want to regulate themselves before the government does, they will have to take steps to ensure the data that feeds their AI is fair and unbiased, and that their models are empathetic, transparent, and robust. ... With several big consumer brands in the hot seat around questionable AI ethics, most people still don’t trust AI. For many, it’s because they don’t understand it or even realize they’re using it daily. Consumers are getting so many AI-powered services for free — Facebook, Google, TikTok, etc. — that they don’t understand what they’re personally giving up in return — namely their personal data. As long as the general public continues to be naïve, they won’t be able to anticipate the dangers AI can introduce or how to protect themselves — unless the market better educates customers or implements regulations to protect them.


Amid WhatsApp privacy concerns, the draft Data Protection Bill comes to mind

Is data property? No, because then it would fall under The Sale of Goods Act. Only if something can be physically sold, rented out or gifted, then it becomes a property. Data is an intimate connection bet­ween the human being and the thing in question. It has tremendous value, hence, there are always people waiting to take it. This was a concern in Puttaswamy vs Union of India where the Supreme Court said: “Aadhaar is a serious invasion into the right to privacy of persons and it has the tendency to lead to a surveillance state where each individual can be kept under surveillance by creating his/her life profile and movement as well on his/her use of Aadhaar.” ... Not everything is clear yet. The consent conundrum remains. With the age of majority being 18, all contracts under this age are said to have no value. Yet, when a child clicks “I agree”, it technically becomes a contract. Children often lie and say they are 18 and/or claim to have parental consent. Of course, it can have positive outcomes too. The Justice gave an anecdote of his grandson being aware of advanced mathematical concepts thanks to one Khan Academy. Consent should be given in a manner which is understood.


Can Cloud Revolutionize Business and Software Architecture?

The physics behind software development changed completely in the past two to five years, Ahlawat said, with the growth of hybrid, multicloud, and edge. “Eighty percent of enterprises today have workloads that span multiple clouds and two out of three of them are using multiple clouds for many strategic reasons,” he said. That means applications in today’s environment can span data centers and clouds as well as go to the edge. Tied to this trend is the evolution of connected devices and the Internet of Things, Ahlawat said. “Up until a few years ago, there was still a question whether IoT was hype,” he said. “Today we have 20 billion connected devices generating about 50 zettabytes of data a year.” Use cases on this front, Ahlawat said, include connected homes and smart cities, which still have room to grow to become mainstream. The further development of data and AI also affects software development, he said. “Of all the data generated ever, 90% of that was generated in the last two years,” Ahlawat said. “When we talk with large software companies and enterprises, data and AI are central to their strategies.” This is unlocking transformative use cases such as autonomous cars and medical imaging, he said.


'Scam-as-a-Service' Scheme Spreads

The fraudsters are posting fake online classified advertisements for products to dupe interested buyers into visiting phishing pages, where their personal and payment data is harvested, according to Group-IB. Although the operation started in Russia two years ago, by early 2020, it had expanded to include 40 subgroups that have focused on targets in the U.S. and Europe, the new research report says. Brands spoofed by the cybercriminal gang include French marketplace Leboncoin, the Polish online brand Allegro, the Czech website Sbazar and Romania's FAN Courier site. The report also notes the group has expanded its operations in the U.S. and Bulgaria by mimicking FedEx and DHL Express. ... The hackers have set up several Telegram chatbots for automated management and expansion of the scheme, the report notes. These bots are designed to provide scammers with ready-to-use pages mimicking popular classified advertising, marketplace and phishing URLs. "Classiscam chatbots, where fake pages are generated and profits are reported, are not completely autonomous. They require ongoing technical support and moderation," says Dmitriy Tiunkin, head of the digital risk protection department at Group-IB Europe.  


Successful Malware Incidents Rise as Attackers Shift Tactics

"That shift is really interesting because it starts to show the new reality of the work device truly morphing into a work-and-personal device," Covington says. "When you don't leave the house anymore, the phishing events and social engineering events — the ways that attackers get into organizations — are not just happening in the context of business email anymore." Others have noted the impact of the move to remote work on security. In September, a survey of CIOs found that 76% of the executives were worried that content sprawl put company data at risk. An earlier survey found that about six in 10 workers were using personal devices to work from home, and most of them considered the devices to be secure. Wandera found a similar set of impacts from the move to remote work, with many employees behaving differently. Because workers traveled less, they were about half as likely to use a risky Wi-Fi connection for work. And because personal time and work time blended together, a single device had a greater blend of business and personal applications, says Covington. "Honestly, they were looking to kill time," he says. "The types of apps that we installed on work devices this year, we would not have typically seen installed. A lot of games and a lot of productivity tools."


Drone Technology Extends Reach of Mobile IoT

Drones are typically equipped with two types of software. The software that’s closely coupled with the drone hardware manipulates the drone and the gear to keep it aloft while connecting it back to an operator who controls the drone’s flight path. The second type of software is the application—the programs that enables the drone to complete its specific task and to gather relevant information. Currently, there are no standards for the control or the application software, so a potential purchaser must be aware that the application software usually has to be customized to work with a specific manufacturer’s drone and its basic operating system. As a result, you have to ensure that the software you need can actually run on the drone hardware you intended to acquire. Skydio, for example, markets some applications software, such as Skydio 3D Scan and Skydio House Scan, with its drones, and also partners with third-party drone software makers for other applications. And, of course, a potential user has to confirm that the format of the data that the drone collects and disseminates is consistent with other formats currently used by the data analysis programs already in place. Some integration work may be required.


What analytics can unveil about bot mitigation tactics

Shortcomings have recently come to light about even the most common and accepted bot mitigation technologies. For example, solutions offering CAPTCHA challenges are not only ineffective at detecting and stopping automated attacks, but they often lead to a friction-filled experience, frustrating customers and leading to lower conversion rates. Many online retailers and e-commerce providers will actually forgo implementing security due to fear that this friction will have a negative impact on sales. Bot mitigation approaches that are based on observations from historical and contextual data (e.g., IP addresses and analysis of known behaviors) and then rely on taking steps to block similar behavior can often block IP addresses or stop specific user behavior that might not actually indicate an attack (e.g., late night banking or shopping). These methods trigger poor experiences and have been shown through analysis to not produce the desired mitigation or prevention results. More recently, use of a rules-based architecture to prevent attacks has grown in popularity. Unfortunately, a rules-based solution falls short when faced with advanced AI- and ML- equipped bots that can morph on the spot to evade an organization’s cyber defenses.



Quote for the day:

"When building a team, I always search first for people who love to win. If I can't find any of those, I look for people who hate to lose." -- H. Ross Perot

Daily Tech Digest - July 20, 2019

FinServ in the age of AI – Can the FCA keep the machines under check?

Zz0yZGVlNWFjNzUyNjgwYjFmMDc2NzMyNWM0MGQyZTYzMA==
There are banks who are also looking at reverse engineering the explainability when the AI algorithm is complex. The FCA and the Bank of England have tried this approach too. A complex model using several decision trees to identify high risk mortgages had to be explained. The solution was to create an explainability algorithm to present the decisions of the black box machine. The pace at which startups are creating new solutions makes it harder for service providers. In recent times I have come across two firms who help banks with credit decisions. The first firm collected 1000s of data points about the consumer requesting for a loan. One of the points was the fonts installed on the borrowers laptop. If the fonts were used in gambling websites, the credit worthiness of the borrower took a hit. As the font installed indicated gambling habits, the user demonstrated habits that could lead to poor money management. The second firm had a chatbot that had a conversation with the borrower and using psychometric analysis came up with a score. The score would indicate the “intention to repay” of the customer. This could be a big opportunity for banks to use in emerging markets.



Foundations Of Business Architecture


The work of creating and defining a business architecture is not meant as an academic exercise. A business architecture is based on the organization’s business strategy. The business architecture positions the organization to operate efficiently in pursuit of its goals. As defined, a business venture is about creating value. Value is demonstrated in the form of corporate profits or in returns to owners and shareholders. Corporate goals tend to be high-level and wide. Organizations use various processes and methods for capturing and documenting the corporate goals. The method used in capturing the corporate goals is less important than having the discipline, structure, and communication methods to support the creation and dissemination of the corporate goals across the entire organization. Used most effectively, corporate goals are developed within the context of a larger enterprise wide strategic planning function. Often, the process is used in creating the organization’s data strategy, which may occur during enterprise architecture planning.


The Pipeline Driven Organization - Enabling True Continuous Delivery


"Pipeline driven" means we want to rely more and more on pipelines to make technical decisions (judgements) related to the code and its associated artifacts, and then have the pipeline immediately act based on those decisions as autonomously as possible. ... Continuous Delivery is a software engineering approach in which teams produce software in short cycles, ensuring that the software can be reliably released at any time. I believe that the key to succeeding with continuous delivery is to remove human bottlenecks from the chain of tactical decision making, and enable pipelines to work almost autonomously in deciding and pushing code around, all the way to production, without human fear and doubt getting in the way of receiving fast feedback about the way our code behaves. In order to be able to trust a pipeline enough so that we can rely on its decisions, we need to start teaching our software pipelines to make those tactical judgements without needing humans in the process.


5 Tips for Agile Testing

Agile Planning
When both of the teams cooperate closely, they clearly understand the functional requirements of the software even if user stories are described superficially. The developers distribute the tasks to be performed and the order of passing the results to software testing engineers. At this time, the QA specialists start preparing test documentation and clarifying technical issues with the developers.Why is it important? By following the above-mentioned process, you can prevent errors earlier in the development, improve the code quality, and reduce the number of defects. ... According to the Scrum Guide, it should be an external specialist who will have control over the Scrum processes finding out the gaps and detecting all possible risks. Most often, a manager performs this function. Nevertheless, whomever is a Scrum Master on the project – a QA engineer or a developer – the person should be able to smoothly switch the role and carry out appropriate duties. With practice, even experienced software testing engineers with managerial skills successfully coped with this role.


How one bank is using AI, big data and chatbots to create new services


Simon McNamara, chief administrative officer at RBS Group, was brought into the bank in the wake of that episode in September 2013. He says the very reason he was brought into his job was that the executive team believed he was the person to "fix" the bank's IT systems and to create resilience. McNamara refers to "material progress" in regard to achieving that resiliency. It's provided a platform for him and his colleagues to face the challenge of digital disruption in the banking sector head on. In fact, pushing an innovation agenda has been one of his key aims since the day he started – yet it was something that some of his executive peers were reticent should be a focus when he first joined the bank in 2013. "I was actually told by some people that you're not going to be able to do that," says McNamara. "Some people said I was here to fix things and should forget about innovation. And that's literally where we started – and I'm somewhat proud of actually ignoring that advice and building an innovation agenda here, which is second to none in the UK in terms of any financial institution."



Why do 87% of data science projects never make it into production?

“It’s broken because nobody owned it, we didn’t have the data science team to be able to continually iterate on the models, think of it as an asset, and have data operations making sure it’s working well,” Chapo said. “We’re starting to bring those ways of working to life. But it’s hard, because can’t just do it all overnight.” “One of the biggest opportunities for all of us today is to figure out how we educate the business leaders across the organization,” Leff said. “Before, a leader didn’t need to necessarily know what the data scientist was doing. Now, the data scientist has stepped into the forefront, and it’s actually really important that business leaders understand these concepts.” AI is not going to replace managers, she adds, but managers who use AI are going to replace those who don’t. We’re starting to see that awakening of business leaders wanting to understand how machine learning works, and what AI really means for them, and how to leverage it successfully. And those leaders are going to be the most in demand, Leff said. Another essential key to success, Chapo added, is keeping it simple.


As FTC cracks down, data ethics is now a strategic business weapon

GettyImages 1058320822
To weave ethics into the very fabric of their business strategies and tech systems, startups should adopt “agile” data governance systems. Often combining law and technology, these systems will become a key weapon of data-centric Third Wave startups to beat incumbents in their field. Established, highly-regulated incumbents often use slow and unsystematic data compliance workflows, operated manually by armies of lawyers and technology personnel. Agile data governance systems, in contrast, simplify both these workflows and the use of cutting-edge privacy tools, allowing resource-poor startups both to protect their customers better and to improve their services. In fact, 47% of customers are willing to switch to startups that protect their sensitive data better. Yet 80% of customers highly value more convenience and better service. By using agile data governance, startups can balance protection and improvement. Ultimately, they gain a strategic advantage by obtaining more data, cultivating more loyalty, and being more resilient to inevitable data mishaps.


Will Cyberattacks Lead to Prolonged Conflicts?

"We need to separate what is happening with corporations, where the news is relatively good because the technologies are getting better and it is now possible if you spend enough to defend yourself," says Clarke, a former adviser on intelligence and counterterrorism in three presidential administrations. "We need to separate that good news from the bad news that governments are behaving badly - governments are engaging in increasing cyberattacks and boasting about it." In an interview with Information Security Media Group, Clarke says he's concerned that more cyberattacks of a sufficient gravity will lead to kinetic responses and prolonged conflicts. "We actually have had a government engage in a conventional or kinetic attack because of cyberattacks - the Israelis, frustrated by the cyberattacks on them by Hamas, flew F-16s and bombed the Hamas cyber facility," he points out. Clarke and Knake believe that the key to dealing with future cyberthreats can be distilled to a single word: resilience. 


Data Governance Program Team Structure


The need for business data stewards, both the lead business stewards and the line data stewards, is especially important in an incremental approach to data governance. Using this method, the organization usually establishes one or two data stewardship teams to address specific data-related challenges with the support of the small Data Governance Program team, after they are trained in data governance and data stewardship concepts. The data stewards may be asked to support the DG program team in writing policies that apply to their specific issue – and that will be expanded to include the organization in general – under the approval of the Data Governance Council. Additional data stewardship teams should be enacted according to a schedule developed by the DG Program team and the DG Council, for projects identified by the DG Council. This schedule should be assertive, to maintain program momentum and to retain interest across the organization in data governance and data stewardship, while demonstrating value. In the starting projects, and perhaps with smaller organizations, the data stewardship teams may consist of a lead business data steward and one to three line business data stewards, based on the organization’s subject areas.


Q&A on the Book Virtual Leadership

It’s for those who lead virtual teams and those who are part of virtual teams. Even if you don’t consider yourself a leader, you will be able to make a lasting difference in the quality of your virtual work through developing your own virtual leadership. Do you strive to work well with people spread around the globe, or even just around your locality? Do you wonder how to overcome the challenges and frustrations of virtual working? Do you want to see real and lasting benefits for your organization through your virtual work and that of your colleagues? If so, I wrote the book for you, whatever your role and whatever type of organization you work within. Of course, InfoQ caters to the software development community, and readers say that there is a lot in it that is really helpful there. While you are likely to be incredible with technology, it takes more than technology to make virtual teams work well! My background was as a software engineer initially, and many of the case studies are from situations involving IT.



Quote for the day:


"You may not control all the events that happen to you, but you can decide not to be reduced by them." -- Maya Angelou