March 31, 2015

Creating a Creative and Innovative Culture at Scale
The development managers are responsible for holding regular one-on-one coaching talks. Each has a team that is spread over different game teams in different studios (see figure 1). The development managers remain developers and typically their team members share a similar skill set so that the development manager understands the domain in which their team works. Although spread out in the organization, development managers work as a community. All of them come together weekly to discuss what’s happening in different parts of the company, which allows them to identify issues and address them quickly.


Repository pattern, done right
The repository pattern has been discussed a lot lately. Especially about its usefulness since the introduction of OR/M libraries. This post (which is the third in a series about the data layer) aims to explain why it’s still a great choice. ... The repository pattern is an abstraction. It’s purpose is to reduce complexity and make the rest of the code persistent ignorant. As a bonus it allows you to write unit tests instead of integration tests. The problem is that many developers fail to understand the patterns purpose and create repositories which leak persistence specific information up to the caller.


Data Transparency Transformation
Data standardization is essential but not sufficient to improve the quality of financial data, to reduce or eliminate duplication, and carry out our work. We also need to improve ways to securely share sensitive data, both among authorities within the same jurisdiction and across borders. Data sharing is essential because none of us no one regulator or company alone  possesses or has access to all of the data needed to paint a complete picture of threats to financial stability. The financial system is complex and ever-changing, so even if we put all of our data together in one place, significant gaps would remain and new ones would emerge. It is a puzzle with many interlocking types and pieces of data


If Everybody is Responsible, Nobody is Responsible.
The tough part of compliance is the coordination of multiple compliance efforts and filling the gaps. When compliance fails, it often fails because a piece of compliance was not handled properly. It might have been a simple piece, but nonetheless a critical one. Everyone wants responsibility for compliance, because they have a piece of compliance and they believe theirs is most important. If you have ever watched the congressional hearings of Enron, WorldCom, or Tyco, you will have seen a parade of people from Audit, Legal and the Board saying, “I had my piece covered. What failed was not my responsibility and I was as surprised as you that it failed.”


The Privacy Challenges of Cloud Computing
Where an organization engages a cloud services provider it is important to identify whether the cloud provider is a controller or a processor. In most instances, it is likely that the cloud provider will be a processor. The Information Commissioner has issued guidance on this issue which may be helpful in making more detailed analysis. The geographical location of the servers used to store personal data is often contentious. Where the servers are based outside of the European Economic Area (EEA), a customer will need to address the eighth data protection principle which, in broad terms, requires adequate safeguards to be in place when personal data is transferred outside the EEA.


Distributed Cloud?
Migrating applications to the cloud is more than just moving virtual machines into the cloud; many tools, such as HotLink,CloudVelox, Veeam, and Zerto do this well enough. Migration is more about how those applications work within the cloud. It is about the connections between tools running within the VMs. Ultimately, it’s about applications and their attendant data. The intersection of data and application needs to be considered when moving to the cloud. To provide resiliency for an application using a cloud service, you may use multiple data centers within a cloud, or even multiple clouds. When you use multiple clouds, you end up with a hybrid cloud approach to your application.


BI and Big Data: Same or Different?
Contrary to some of the market hype, data democratization and big data do not eliminate the need for the "BI 101" basics, such as data governance, data quality, master data management, data modeling, well thought out data architecture, and many others. If anything, big data makes these tasks and processes more challenging because more data is available to more people, which in turn may cause new mistakes and drive wrong conclusions. All of the typical end-to-end steps necessary to transform raw data into insights still have to happen; now they just happen in different places and at different times in the process. To address this challenge in a "let's have the cake and eat it too" approach, Forrester suggests integrating the worlds of BI and big data in a flexible hub-and-spoke data platform.


Taking IT reorgs to the extreme
What's different today is the degree of uncertainty about what the IT group is if virtually all companies are now built, top to bottom, on technology. CIOs themselves are divided about their own futures. In our 2015 State of the CIO survey, 49 percent of 558 IT leaders said they're destined to become managers of contractors and cloud vendors--hardly strategic. Indeed, sometimes old ideas and established leaders don't cut it. RSA Insurance Group in London cleaned house last year, replacing several senior executives, including all IT leaders and the CIO. RSA also created the position of chief digital officer as it tries to move to "more disciplined and effective use of technology."


Hologram - Finally, AWS Key Distribution that Makes Sense
Hologram is written in Go, Google’s “systems programming language” written by some of the original designers of C and Plan 9 from Bell Labs. It is a language explicitly designed for aggressive simplicity, both of programming itself and of deployment / operational concerns. The ability to create a static binary with assets compiled in allowed us to do a sophisticated multi-stage rollout of Hologram to developers, which we credit with how quickly developers adopted it. Go allowed us to produce a version of the binary that had some placeholder credentials compiled in, that was first deployed to developers. This version would simply use the compiled-in credentials to generate temporary ones, and expose the same metadata interface that applications expected.


Taiwan seeks stronger cyber security ties with U.S. to counter China threat
Taiwan was the most-targeted country in the Asia-Pacific region during the first half of 2014 for hacking attempts aimed at penetrating computer systems to steal data, according to U.S. data security firm FireEye Inc. Chang said the percentage of cyber attacks on government systems originating from mainland China was "very high", and warned that there was potential for hackers to use Taiwan as a back door into the U.S. systems. "The possibility is there," Chang said, while emphasizing that the main purpose of Chinese hacking attempts into Taiwan is not to steal U.S. data and that he has "no way of knowing" if an incursion into Taiwan has led to any U.S. intelligence leaks.



Quote for the day:

"Example is not the main thing in influencing others. It is the only thing." -- Albert Schweitzer

March 30, 2015

Probing the Whole Internet for Weak Spots
The scan showed that more than five million sites were affected, including those operated by the FBI, Apple, and Google. Facebook’s like button, a fixture on many popular sites, was also vulnerable. The results prompted an urgent, careful effort to inform key companies and organizations before the problem was announced publicly. The FREAK flaw allows an attacker to break a secure connection between a Web browser and a vulnerable site, gaining access to encrypted data sent between the two. The attack works by forcing a site to fall back to a weak form of encryption mandated by the U.S. government in the 1990s.


Big data collection makes it hard for you to remain anonymous
The fault for the spread of this ”myth,” they say, is not with findings presented by researchers in primary literature, but “a tendency on the part of commentators on that literature to overstate the findings.” They contend that de-identification, done correctly, is close to bulletproof, reducing the chance of a person being identified to less than 1% – far less than the risk of simply taking out trash containing documents that might have PII in them. They also argue that unwarranted fear of a loss of anonymity may undermine, “advancements in data analytics (that) are unlocking opportunities to use de-identified datasets in ways never before possible … “creating anonymized datasets requires statistical rigor, and should not be done in a perfunctory manner.”


New threat intelligence report skewers industry confusion, charlatans
Today, there are large numbers of TI vendors and advisory papers (often issued through vendors' marketing departments) that describe extremely different products and services, all under the banner of threat intelligence. The research explains, "For example, at a high level, some products come in the form of prose that explains developments in a particular area, while at a lower level, others might be a stream of XML-formatted indicators of compromise, such as IP addresses or binary hashes." What's worse, "Even within similarly placed sources, such as feeds of indicators of compromise, there is very little overlap between competing products. Recent research suggests that in three popular feeds of flagged IP addresses, containing more than 20,000 IP addresses in total, there was as little as a 1% overlap."


Oracle HCM Cloud Adds Social, Mobile Learning Option
Using smartphones or tablets, salespeople are sharing video product demos, retailers are creating how-to-merchandize videos, and field-service staff are capturing maintenance-and-repair videos, for example. Oracle Learning Cloud is designed to enable employees at any level to create such videos, and HR or business leaders can then curate these and other assets, such as images, infographics, documents, or even massively open online courses (MOOCs) into learning tracks geared to specific departments and roles. "A manager can point to these tracks and say, 'I would like people in my organization to learn the following, so please follow this track,'" said Alarcon.


Eliminating Passwords in the Enterprise
While issuing an enterprise credential with a strong password is fairly easy to accomplish, managing that password over the credential's lifetime is more difficult. User password resets, compromised passwords and a lack of synchronized passwords across enterprise systems all cause problems for users, IT departments and security professionals. And users truly hate passwords. There are too many to remember, each system has different rules, and there is a lack of standards for reset processes. A positive associated with passwords is that they are well understood by both providers and end-users. ... But, usability and security of password-backed credentials are in decline and a passwordless future is something that keeps coming up in the IAM conversation. So what will it take?


Leverage Big Data Cross-Industry Panel: Video Now Available
Big data represents a challenge to Kerry Hughes, the advanced computing leader at Dow Chemical, who was also on the panel. For Hughes, connecting big data and high performance computing (HPC) technology with the person with the requisite domain expertise is the tough part to crack. Helping clients to act on fast-moving data is important for panelist Asif Alam, the head of enterprise capabilities at Thomson Reuters. The advent of machine readable financial data generated by more than 400 different exchanges, in combination with outside data such as weather and news, allows Thomson Reuters to help its clients make decisions quickly in our fast-changing world.


What happens with data from mobile health apps?
Mobile health applications as a class are becoming more sophisticated, and vacuuming up information like glucose levels, heart rate and fertility, all while operating unchecked by the statutory restrictions that apply to information collected in a medical setting. Pooled together, those data points could provide potential indicators for conditions such as obesity or Alzheimer's. But the market for that data is fairly opaque, and Bedoya fears that health information in the hands of data brokers could be sold to businesses for dubious purposes, such as insurance companies that might deny applicants coverage or charge steeper premiums based on information collected through health apps.


GitHub recovering from massive DDoS attacks
Anthr@X wrote that it appeared advertising and tracking code used by many Chinese websites appeared to have been modified in order to attack the GitHub pages of the two software projects. The tracking code was written by Baidu, but it did not appear the search engine—the largest in China—had anything to do with it. Instead, Anthr@X wrote that some device on the border of China’s inner network was hijacking HTTP connections to websites within the country. The Baidu tracking code had been replaced with malicious JavaScript that would load the two GitHub pages every two seconds. In essence, it means the attackers had roped in regular Internet users into their attacks without them knowing.


Cyber what? (part 2 of 2)
All the different “cyber” terms sure are confusing and it’s no help that many of the terms used to describe the threat actor behind a cyber attack are often used interchangeably. In part I, we established what constitutes a “cyber attack” within “cyberspace”. Now the real fun begins – we’ll dissect the four most commonly confused terms: “cyber war,” cyber terrorism,” “cyber vandalism” and “cyber espionage” and provide a common lexicon. The objective is to dispel myths and, by establishing common understanding, provide a way for managers to cut to the chase and understand risk without all the FUD. The graph below shows the four terms and attributes at a glance.


Crossing the Cybersecurity Trust Chasm
It is a rare case, where the perpetrators of cyber-theft crossed the line in to threatening violence in real life. Cyber attacks are now a top national issue. People are outraged that cyber terrorism could lead to physical terrorism. They want to know how the government and private sector can safeguard them against such scenarios. Everyone’s interests are seemingly aligned. Let us all seize the moment before it is lost and build trust. A critical piece for rebuilding trust is having the right talent focused on it. Box recognized thattrust is a competitive advantage and appointed a Chief Trust Officer few years ago to build trust with their customer base on their security practices.



Quote for the day:

"Always and never are two words you should always remember never to use." -- Wendell Johnson

March 29, 2015

Compliance biggest cloud security challenge
Of those concerned most about compliance, 58 percent said that cloud services violated data protection laws in their country, 31 percent said they violated internal security policies, and 11 percent said they violated laws against moving sensitive data out of a country. As a result of the data residency laws in particular, there were significant geographical differences in whether companies opted for encryption or tokenization. CipherCloud's technology allows companies to use platforms such as Salesforce, Office 365 and Gmail while encrypting sensitive data and allowing the companies to control the encryption keys. And the encryption mechanism used still allows for some functionality to be preserved, including searching and sorting while the data is still in encrypted form.


Implement Performance Measurement in Project Ripples
One of the easy-to-correct reasons that most organisations do get paralysed with performance measurement is that they stack too much at the start: learning the methodology; proving the methodology; engaging the entire organistion in applying the methodology; tailoring and tweaking the methodology; perfecting each step of the methodology and striving to hit high-performance targets. ... It might sound counterintuitive, but starting smaller actually means you achieve much more, and much faster. That’s what a system of project ripples achieves. We implement performance measurement systematically, in ever-growing ripples of projects.


The Role of Domain Experts in Data Science
Domain expertise is most relevant, perhaps, in the interpretation of insights, particularly those insights gained using unsupervised learning about the workings of complex physical processes. An example of just such a situation was the use of Aster discovery platform to perform root cause analysis of failures in a multiple aircraft fleet from aircraft sensor and maintenance data. While the analysis started with no a priori model, a post prioriinterpretation of the results from the path analysis and the subsequent follow-up to improve aircraft safety certainly required domain expertise.


5 Ways For IT Organizations To Enable Business Success
When it comes to all the challenges facing IT organizations these days, there is no shortage of issues to focus on–everything from retiring legacy systems to figuring how to do more with less. Given the competing priorities, it’s critically important for IT organization to focus their efforts on the initiatives that will have the most strategic impact on the business. With that said–and to that end–there are things every IT organization should do to enable their business partners to succeed:


Control vs Chaos: Taming the Project Requirements Beast
One of the intrinsic challenges in software development occurs in the initial elicitation phase, when stakeholders get together and figure out what they want to achieve. The analysis, specification, and validation stages are all important moments in the project requirements definition and management, but elicitation remains a crucial first step, one that will determine the fate of the whole project. When the requirements are clear and realistic from the outset, the rest of the project unfolds naturally, even gracefully, but when the requirements are vague and impractical, they create problems that invariably snowball.


Right Now, The IoT is Like the Internet of the 1990s
Tibbets compares it to the early days of the web, which saw "a decade or more of unrestrained value" before patterns and standards around security started to emerge. "So one of the things we need to learn from is, once we learn from that value piece—which is really crucial, otherwise you're going to have a really secure thing that no one uses—that very next step has to be the follow-up, how to understand that value, and how to secure it," he says. ... "Every bike should be connected, so you can figure out where it is when it gets stolen. Bikes get stolen all the time," he says. "Once you're into less expensive products like that, it's going to become more ubiquitous."


Humanizing Big Data: The Smart Guide to Tracking Customers
“Humanizing Big Data” contends that every business recognizes the power of collecting and learning from data. But Strong insists the problem has to do with where some businesses focus when getting this information. More and more, businesses may be exclusively focusing on technology to bring in customers only to forget the customer in the process. But placing too much emphasis on technology without considering its impact on human behavior can have implications that affect the bottom line of a business now and in the future, Strong says. In other words, humans are more than a collection of clicks, Likes, mentions and Pins.


Beware of these IoT designs with security flaws
Preventing someone from attacking a device via Baby Duck Authentication is almost impossible for the average consumer-grade electronic device. The money, time, and effort put into Blu-Ray DVD security or satellite television set-top box protection is the level of effort to make something robust in the consumer market. That level of effort is rarely economical for consumer-grade hardware. ... Secret Handshakes are a very insecure design pattern because they are trivial and obvious to spoof. If a Secret Handshake can be captured, then it can be replayed. Anti-replay design patterns exist, but they often add complexity to a process or workflow that does not tolerate a lot of complexity, like the reset procedure, reconfiguration procedure, or initialisation process.


Half of enterprises have no budget at all for mobile security, survey finds
These are large companies we're talking about. Put that in the context that today's enterprises spend millions of dollars on security, locking down everything from databases to desktops. However, scant attention is being paid to today's client of choice: mobile apps. These findings come from new research released by IBM and the Ponemon Institute, which looked at the two sides of mobile security -- the apps that enterprise teams produce for customers, employees and clients. Looking at internal app development, the study concludes that mobile security is virtually non-existent, even in the largest corporations.


Beena Ammanath, GE on the Industrial Internet for Data-driven Innovation
The Industrial Internet connects brilliant machines with people at work and data analytics to find new ways to address major global challenges and improve healthcare, increase transportation and energy efficiency, and eliminate waste across every major industry. The Industrial Internet will unleash a productivity revolution to build, power, move and cure the world. ... The global economic impact of building cleaner, safer, more productive railroads, airlines, hospitals and power plants will transform industry and help our customers be more efficient and productive. By eliminating downtime, waste and guesswork, the Industrial Internet will save hundreds of billions of dollars, unleashing a productivity revolution.



Quote for the day:

"The leader who exercises power with honor will work from the inside out, starting with himself." -- Blaine Lee

March 28, 2015

Work in the 21st Century: Between the Industrial and the ICT Revolution
In the age of social media and the end of fixed workstations, large corporations have no choice but to adapt themselves. In order to survive, companies must promote change from within. The new BBVA headquarters in Madrid, designed by Herzog & de Meuron, is an example of how corporate architecture can adapt to a new working environment, where a culture of collaborative, flexible and open work is nurtured, supported by technology. The “New Approaches to Work” project linked to the newly built BBVA headquarters focuses on the functional and personal needs of employees, as the BBVA New Headquarters Team explains in OpenMind.


The economic laws of positive technology disruption
Increasingly this decision comes down to the IT leader, but this person is perhaps not always the CIO or the CTO. The emergence of the Chief Digital Officer (CDO) might require an additional key to the C-suite washroom, but it is a role worth creating. With a CDO firms are creating a special new role in terms of someone who understands business outcomes as much as he or she understands software application development (or at least what the code is supposed to achieve) today. The Chief Digital Officer’s role today revolves around IT value. But specifically, what does this really mean? The CDO has to be able to read the disruption barometer, decide how to ride the storm and be able to assess outcomes and future direction for the firm as a result of actions taken.


Microsoft EA 101
So how can an EA help you take advantage of this exciting, new cloud-first, mobile-first world? Microsoft has released some pretty interesting products in the last six months to help guide you through that. As part of the Enterprise enrollment, you get a cloud-optimized option with Office 365. You get the server cloud enrollment that’ll give you Azure and other products that are all catered towards the cloud. In the newest offering, the Enterprise Cloud Suite even offers Windows on a user base license as needed. There’s a tremendous amount of flexibility there. Oh, and don’t get the wrong idea—those “big savings” I mentioned earlier are still there. If you’re comparing EA to current select licenses, you could have anywhere between 15–45% savings. There’s still no better way to save on Microsoft.


A Look at How Keyless SSL Works
In keyless SSL used by CloudFlare, the “handshake” operations are typically broken down into two segments. One, the public key operation, and Two, the private key operation. In order to prevent the private key from being handed over to a third party, all aspects of the private key handshaking process happens within the origin website's infrastructure. To do this, CloudFlare simply sets up a remote key server at the customer's end. This way, the private part of the handshaking process is complete within the origin web server and thus stays exclusive. So what happens now is that when a visitor approaches a secure website, the web server first sends out the public key certificate along with the random symmetric encryption key to the browser.


Delving deeply into the narrative hierarchies of computer vision analytics
The more disruptive real-world applications of deep learning will be those that generate deeper situational insights through correlation with additional contextual variables. This added context can help deep learning algorithms to unambiguously identify that a particular person is in a particular circumstance at a particular time and place. ... This is a daunting technical challenge, and deep learning researchers aren’t promising that they’ll crack it any time soon. But this challenge has a clear path to a solution, through ongoing efforts in the deep learning community to leverage the extrinsic context that comes from other machine learning algorithms, such as those used for natural language processing, sentiment analysis and behavioral analytics.


Facebook Lets Developers Build on Its Chat App
Messenger Platform became available Wednesday, and Marcus said that more than 40 apps are participating. Facebook also unveiled a plan to let businesses chat with customers in a new way. The hope is that when you’re buying something online, a retailer will let you choose to be contacted via Messenger about your order, and if you assent, you can see an order confirmation, shipping details, and other information in the app. You’ll even be able to do things like change your order or, as a demo with online clothing retailer Everlane indicated, buy additional items via chat.


The Indian Banking Community Cloud
Community clouds offer services to support organizations with shared objectives and common security and privacy requirements. By providing cloud-based services exclusively to Indian banks, the Indian Banking Community Cloud (IBCC) aims to address the financial sector’s growing demand for secure cloud-based services. ... The IBBC team developed a cloud security framework based on the available guidelines from the US National Institute of Standards and Technology, PCI-DSS, the European Network and Information Security Agency, and the Cloud Security Alliance, and recommendations from chief in- formation security officers in the Indian bank- ing sector. This framework is used to implement IBCC security.


Microsoft's Nano Server: What to expect from this leaner, meaner Windows Server
As traffic increases, administrators will want to launch additional VMs with shorter boot times, but Windows Server isn’t the best operating system (OS) for elastic workloads. It also undergoes frequent reboots, usually in response to a new software patch or security update, which has a knock-on effect on the uptime of applications. With the addition of components and services that are not core to the applications, Windows’ footprint has increased over time, bringing with it a larger attack surface for malware and viruses. Furthermore, the large VM image size hogs network bandwidth during provisioning, which should go some way to further explaining why Microsoft is looking to introduce a pared-back version of Windows server.


A Budget is Not an IT Strategy
The generally accepted rule of thumb is that, for most companies, IT-spend usually runs somewhere between 1 to 5 percent of overall revenues. Many CEOs assume that so long as their IT leaders keep it within an acceptable range, they don’t need to focus too much on how it’s being spent. But a revenue-based metric is meaningless unless you think about factors such as the organization’s business model, maturity, industry, capital structure, and most importantly, their overall objectives. Investing in IT Does Not Imply Investing Wisely


How virtual reality will impact the enterprise
This is most useful for remote observers in order to feel like they are actually there and in conjunction with telepresence robots could allow remote employees, students, security guards, managers, or executives to instantly feel they are actually in a remote location and gain similar freedom of movement and engagement to folks that are actually there.  This is much better than teleconference because it forces the remote person to concentrate on the image they are seeing and it makes them less likely to be looking at something else on their PC screen or their local room when an important point is being made or a critical observation needs to be captured.



Quote for the day:

"If you spend your life trying to be good at everything, you will never be great at anything." -- Tom Rath

March 27, 2015

Ayasdi Raises $55M to Blend AI and Machine Learning
“Traditional analytics have hit the wall,” said Ayasdi Chief Marketing Officer Patrick Rogers. “It starts with an analyst asking questions, and then applying them against data that may or may not find insight. You must then go back and reformulate until you find something impactful. There are a lot of tools, but it’s still fundamentally a human-driven process. That model is not going to scale—the number of possible questions grows exponentially with data sets.” Rather than the hypothesis/test approach, Ayasdi takes a very machine-driven one to address complex data. At the heart of Ayasdi’s machine intelligence is topological math, which is building a more automated discovery process and eliminating manual processes.


The dark side of commercial open source
This brings us to one critical problem with commercial open-source companies: they can be bought. And sold. And when they are, the community can be shafted. Completely. Not that this must necessarily happen. Most companies that have acquired open-source companies have done so to benefit from and grow their associated communities. Not surprisingly, open-source leader Red Hat has acquired a range of companies, from JBoss to InkTank (Ceph), and has worked hard to grow their communities. But even proprietary software companies -- like VMware, which acquired SpringSource, and Oracle, which acquired MySQL -- have gone to great lengths to continue development of the open-source code they've acquired.


Agility Is Within Reach
The sweet spot lies somewhere in between. The appropriate level of agility won’t be the same for everyone, but for all companies in all industries, we’ve found that being agile depends on developing two key attributes: strategic responsiveness and organizational flexibility. These two qualities are mutually reinforcing but are developed in different ways, and it is easy for a company to possess one without the other. But until you explicitly develop proficiency in both, you won’t have the agility you need. It’s an absence that will become all the more glaring. In PwC’s latest CEO study, more than half of CEOs surveyed said they believe they will be competing in new sectors in the next three years, and 60 percent said they see more business opportunities now than they did three years ago.


Cloud Native Application Maturity Model
Cloud native applications are built to run optimally on cloud infrastructure. Cloud native application architectures are very different than traditional tiered applications which are designed for a data center. In this post I will discuss maturity model, from the Open Data Center Alliance (ODCA), for assessing the cloud nativeness of an application. ... The Cloud Application Maturity Model from the Open Data Center Alliance provides a way to assess the cloud nativeness of an application, understand best practices, and plan improvements. Although, I would have used slightly different level names and terms, the differences are minor. Keep in mind that this model only assess the maturity of an application. To be successful, you will also need to build a DevOps culture. Perhaps we need a DevOps maturity model as well?


An SDN vulnerability forced OpenDaylight to focus on security
Security will be an integral component of SDN, since a flaw could have devastating consequences. By compromising an SDN controller -- a critical component that tells switches how data packets should be forwarded -- an attacker would have control over the entire network, Jorm said. "It's a really high value target to go after," Jorm said. The Netdump flaw kicked OpenDaylight into action, and now there is a security team in place from a range of vendors who represent different projects within OpenDaylight, Jorm said. OpenDaylight's technical steering committee also recently approved a detailed security response process modeled on one used by the OpenStack Foundation, Jorm said.


7 exceptional Windows hybrids ready for Windows 10
Hybrids, or 2-in-1s, offer decent mobility as laptops and tablets, and are reasonable candidates to take advantage of the features in Windows 10. They are good options for those wanting very portable notebook computers that can operate as tablets when that best fits the situation. Some hybrids use a display that rotates under the keyboard to form the tablet, while others have a detachable screen that operates independently from the laptop dock. The eight hybrids in this collection come in various shapes and sizes. There are devices at the top of the price range, and others more budget-friendly. Most in the hunt for a good hybrid that should run Windows 10 well should find one that fits their needs.


Rethink How Your Business Consumes Technology
Using a consumption-based IT management approach, you collect all pertinent data across the hybrid IT environment -- both internal operations and external sources, including public cloud, private cloud, virtual resources, traditional resources, network and applications. This usage data is enriched with business intelligence, allowing views of usage by department, geography, technology, and application. When the data is married with unit costs, a financial control plane is created, allowing IT to understand the cost of all IT resources in aggregate. By having the most up-to-date view of usage by user and costs, your reports and analytics show both the historical perspective across a variety of views that enhances forecasting.


New cybersecurity models driven by tsunami of data, devices
"If something happens that looks odd, it's not an immediate stop, it's just more that the security officer or someone will have a conversation and say, ‘I see you are trying to access this application that you don't normally access, is there a reason? Can you tell me why? Or are we seeing abnormal patterns?'" he said. "I think that is what we need to get into, which is almost like the machine is helping to tip and cue what looks odd. There may be a valid reason, or it may be a hardware or software issue, but there's just so much going on in an organization that if we are reliant solely on human eyes paying attention to it, we will miss things. We need the machines that can actually say, ‘I'm not exactly sure what's going here, but someone needs to take a look at it.'"


Making Agile Deliver Good Software
The key thing is to do it, to have the information exchange. The reason this is often a meeting of some form is because people don't do it unless they're made to. People go to meetings when they're told to. Well, mostly. But if you cajole people to do the information share it can work in other ways. Note that it's not just writing the information share that's important. You also have to READ it. Just as when you have a meeting it's not just giving your status update that's important but listening to everyone else's. That's why the meeting (when you have one) needs to be short. Remember that a standup is not just the tech team. It's the product owner from the business. The test people. Any support people. Anyone involved in what you're doing. You've got to find a way to keep all those people involved in what you're doing, preferably everyday.


IT Security Lessons from the World’s Biggest Data Breaches
Hackers see small business as easy targets. Often with less IT security measures and lots of valuable data to be had – small businesses across the country are at risk for data breaches. Don’t believe me? According to a survey by the National Small Business Association, 44% of small businesses have been hacked, with associated costs averaging $8,700. According to a study by the Ponemon Institute, that number is even bigger with 55% of respondents reporting a data breach. With risks and vulnerabilities only increasing as hackers continue to target small business, it’s important to explore takeaways from some of the world’s biggest data breaches and apply them to your organization’s IT security.



Quote for the day:

"The very essence of leadership is that you have to have vision. You can't blow an uncertain trumpet." -- Theodore M. Hesburgh