Showing posts with label compliance. Show all posts
Showing posts with label compliance. Show all posts

Tuesday, December 24, 2019

Deloitte and Google Cloud unveil plans to collaborate on next-generation security offerings

Building on their existing global alliance, Deloitte and Google Cloud announces that they will jointly leverage the strength of their portfolios in cyber and cloud solutions to provide customers with end-to-end secure cloud transformation services and solutions in support of their digital transformation journeys and to better combat cyber threats.

As organizations move more of their businesses to the cloud, better control over data and activities in the cloud, as well as preventing privilege misuse, becomes critically important. Migrating a single application to cloud can seem straightforward, but more often, that application's function is tied to multiple business processes. Deloitte employs complex logic, data-driven analysis, and automated tools to rapidly map your applications and infrastructure to Google Cloud Platform (GCP), helping to increase speed, quality and savings.


Deloitte has received Google Cloud’s Cloud Migration and Infrastructure specializations, demonstrating success in architecting and building GCP infrastructure and workflows, and migrating customer workloads to GCP.

Google Cloud’s infrastructure is designed, built and operated with rigorous attention to security. Deloitte has spent decades helping clients protect their businesses from security threats, and can help move securely to the cloud.

As clients increasingly leverage cloud native services to modernize their existing application portfolios and build new and innovative products and services for their customers, they turn to us to help drive increased value through Google Cloud. Its functional knowledge of client businesses and products, combined with the capability of Google Cloud services, helps clients reduce technology operating costs, accelerate innovation, and increase business agility and security.

Through its alliance with SAP, Deloitte and Google have the people, knowledge and experience to help capture the transformative potential of SAP running on Google’s fast, reliable, and global platform. Its integrated SAP offering can help leverage the power of SAP S/4 HANA and Deloitte’s preconfigured solutions to devise a comprehensive cloud strategy.

As a recognized global leader in business analytics and business strategy, Deloitte and Google are able to help harness the power of Google Cloud’s array of big data processing and analytics tools to enable data-driven insights at speeds and volumes that were previously unimaginable. Combined with its cognitive computing practices, Deloitte uses Google Cloud’s machine learning engine to provide next-generation machine learning offerings that help solve tough business challenges.

Deloitte provides dedicated, active, scalable cloud management as a service to help you set the pace of change in your industry. We leverage our secure platform and worldwide network of specialists to understand every dimension of your challenges and how they impact your requirements. Deloitte’s business insight, coupled with turnkey, on-demand cloud management offerings on Google Cloud, make it possible to accelerate the path to cloud.


"The increasing integration, interconnectedness, and data exchange of our businesses and lives create shared vulnerabilities where a problem in one area can quickly cascade into another. By building security into these environments, organizations can better protect their data, privacy, and operations," said Deborah Golden, U.S. cyber leader, Deloitte Risk & Financial Advisory, and principal in Deloitte & Touche LLP. "Together with Google, we are supporting secure transformative change for our clients, something that all organizations should prioritize, and can enable them to be better secured in their critical cyber and cloud needs."

"For enterprise customers moving to the cloud, security isn't an afterthought, it's at the top of every CIO's list, and in general is a board level topic," said Sunil Potti, vice president engineering at Google Cloud Security. "Building in the right security processes and controls from the beginning of the cloud journey can significantly reduce risks and costs for customers, and so we are delighted to be collaborating with Deloitte to help deliver end-to-end security services and solutions to our joint-customers."

As a Google Cloud Security Premier Partner, Deloitte offers cloud security services to its clients globally and helps assist Google Cloud Platform customers address security, privacy and compliance related risks as they migrate and transform their business in the cloud. 

As part of growing the alliance, Deloitte will offer Google Cloud customers cloud security solutions in the areas of security monitoring and threat response, zero trust, identity and access management (IAM) and data security. 

The alliance will also provide next-generation capabilities that can help organizations proactively detect, continuously monitor and respond to unauthorized activity before it can adversely affect networks, and establish and operationalize a zero trust architecture and program to continuously monitor and authenticate users — constantly determining their level of risk based on who they are, what they access, and when and where they do it from. 

The companies will also enhance a digital transformation strategy and lay the foundation to leverage new data-driven identity models as they evolve, and provide a suite of services designed to help organizations address data risk management challenges and help them understand the value of their data and privacy considerations, as well as to operationalize their data risk governance program. 

CloudJumper launches distribution agreement with Crayon to improve access to cloud workspace for Azure

CloudJumper announces alliance with Crayon that combines the power of CloudJumper’s Cloud Workspace Management Suite (CWMS) for VDI and RDS workloads with the expertise of Crayon’s managed services and independent 'cloud economics' consulting practice.

CloudJumper and Crayon’s partnership bring new possibilities for customers and MSPs who want the flexibility of choice for management, security options and the ability to build their own value-add services suite leveraging WVD. 


Microsoft’s Windows Virtual Desktop (WVD) brings new choices for customers who want more control of the managed services running on top of desktop and application virtualization solutions. Legacy VDI providers have historically served as a gatekeepers controlling the workstation management plane. CloudJumper brings to Azure WVD what the legacy vendors will not – the flexibility of controlling managed services on top of managed desktops.

The utility of Windows Virtual Desktop (WVD) is further enhanced through CloudJumper's Cloud Workspace Management Suite (CWMS). CWMS is an automation, orchestration workflow and policy solution to deploy, configure and manage WVD in real-time and at cloud scale. CWMS will instantly, and continually, optimize the customer’s Azure investment.


WVD is a complex collection of Azure services. CloudJumper simply funnels the hundreds of WVD setup options into a few key questions and then orchestrates and deploys a customized environment. With CloudJumper, the customer is just minutes away from deploying thousands of new WVD VMs– something that is not available in a native Azure user interface (UI).

To provide additional support for this distribution partnership, CloudJumper's product development team has been working closely with Microsoft's WVD product team for over two years. As a result, CloudJumper is proud to be recognized as a Microsoft Preferred Solution Provider for WVD.

Microsoft Azure WVD provides customers with unique licensing options and operating system flexibility for Windows 10 and Windows 7 desktop virtualization. Windows 7 desktops can now be migrated to Azure WVD and receive up to three years extended security updates at no additional costs. 

New Windows 10 multi-session OS options are only offered in Azure. These OS choices along with the many complementary Azure PaaS management and security offerings can be securely delivered directly into the Azure tenant. Native Azure Management, supported by CWMS, means no redirection and no third party vendor lock-in. This allows customers to leverage current Microsoft licensing instead of buying overlapping third party tools.

The partnership with Crayon combines the strengths and expertise of CloudJumper and Crayon to deliver the next generation of cloud DaaS and WaaS VDI and RDS desktop and application virtualization solutions.


Headquartered in Oslo, Norway, Crayon is in over 35 countries, providing more than 8,000 customers with strategic advice, consulting and managed services, and support with complex IT estates. Crayon has been the preeminent IT infrastructure consulting business in the Nordic region for more than 12 years, and has expanded its footprint in the US in the last two years.

“Crayon’s deep experience in all aspects of the digitalization journey helps ensure the success of the new partnership. We are pleased to combine CloudJumper’s advanced platform with Crayon’s unique SAM to Cloud Consultancy Services as companies take the next step in digital transformation with their move to Windows Virtual Desktop,” said Alex Picchietti, global director of cloud services for Crayon. “The wealth of expertise from both companies will support organizations making this important move to improve productivity and operational efficiency.”

“The advent of WVD and the partnership with a respected industry leader like Crayon extends the reach of our combined solutions globally,” said JD Helms, president of CloudJumper. “Customers are demanding choice and flexibility in their managed workspace providers and CloudJumper is uniquely positioned to do just that.”

SolarWinds Backup for Office 365 delivers cloud-first data protection for Office 365 Exchange, OneDrive, SharePoint

SolarWinds, provider of IT management software, launches SolarWinds Backup for Office 365, designed to extend data protection services by helping ensure the retention and recoverability of Office 365 data.

Backup for Office 365 backs up and helps restore Exchange, OneDrive and SharePoint data, managed from the same web-based dashboard used to protect servers, workstations, and critical business documents. The need for effective and affordable tools to help MSPs reduce the potential impact of malicious external attacks or internal user error is growing. 


Related data retention, recoverability, and the ability to demonstrate regulatory compliance is becoming even more critical, as more businesses continue to adopt SaaS applications and shift resources to the cloud.

With Backup for Office 365, users are able to save administrative time by managing Office 365 backups alongside server and workstation backups, keep recoverable copies of Exchange data for seven years, and archive OneDrive and SharePoint data for one year. Backup storage in SolarWinds’ private cloud is included, with more than 30 data centers worldwide to help meet data locality requirements.


Users can often unwittingly (or purposely) delete important emails, or OneDrive or SharePoint files. If this happens, SolarWinds Backup offers the ability to search for, and recover what is needed. If employees leave and the company does not want to continue paying a subscription fee to store their email and shared documents, then the SolarWinds Backup for Office 365 offers an additional way to retain and access this data. If the enterprise must comply under regulations with data-retention requirements, SolarWinds Backup is designed to help retain and archive critical data.

With SolarWinds Backup for Office 365, users can manage Office 365 Exchange, OneDrive, and SharePoint backups from a single web-based dashboard. They can also view and manage backup status across customers, and several devices and data types. SolarWinds Backup also helps strike the right balance between automation and control. Users can manually select which accounts and mailboxes they want to protect, or automatically add newly created Office 365 accounts to the backup schedule.


“Backup for Office 365 has assisted us in making our clients feel more secure and comfortable with cloud solutions because they’ve regained control over their data backups,” said Kelvin Tegelaar​, CTO, Lime Networks. “This solution is easy to manage, is super-efficient, and gives our customers an extra layer of protection and continuity.”

“If you’re relying on storage to do the job of backup, you’re putting your data at risk. Anything from an overzealous email cleanup to a deliberate ransomware attack can leave you scrambling if your data isn’t safely backed up. Microsoft is focused on the availability of active email and data, but potential gaps exist around the recoverability of accidentally deleted or overwritten data that are only solved by an effective backup product,” said Mav Turner, group vice president of products, SolarWinds MSP. “Backup for Office 365 is designed for peace of mind; you retain control over the retention and recoverability of your customers’ data in Office 365 and can be ready to help them in their time of need. Your backups will run seamlessly in the background, and the only difference you’ll notice will be increased trust that your data is safe, no matter what.”

Friday, December 20, 2019

Anomali, Trend Micro identify credential harvesting campaign targeting government procurement sites

Multiple government procurement services were targeted by a credential harvesting campaign that uses bogus pages to steal login credentials. Cybersecurity company Anomali uncovered a campaign that used 62 domains and around 122 phishing sites in its operations and targeted 12 countries, including the United States, Canada, Japan, and Poland.

The Anomali Threat Research Team identified a credential harvesting campaign designed to steal login details from multiple government procurement services. The procurement services are used by many public and private sector organisations to match buyers and suppliers. 


In this campaign, attackers spoofed sites for multiple international government departments, email services and two courier services. Lure documents sent via phishing emails were found to contain links to spoof phishing sites masquerading as legitimate login pages relevant to the spoofed government agencies. Victims duped into following the phishing email link would then be invited to login. Anyone who fell victim to the adversaries would have provided them with their credentials.

This credential harvesting campaign has been primarily targeting government bidding and procurement services. The focus on these services suggests the threat actor(s) are interested in potential contractor(s) and/or supplier(s) for those governments targeted. The purpose of this insight could be a financial incentive to out compete a rival bidder, or more long term insight regarding the trust relationship between the potential supplier and the government in question. 


Campaigns like these are difficult to protect against because unless the domains hosting the phishing pages are known as malicious, an organisations firewall will not know to block it. Legitimate sites were also hosting the phishing pages, and were likely compromised as part of the campaign. At the time of writing none of the sites in this campaign were active, Anomali researchers consider it likely that the actors will continue to target these services in the future.

The use of bogus login pages continues to be a popular method for credential harvesting campaigns. The Trend Micro Cloud App Security solution blocked 2.4 million attacks of this type in the first half of this year — a 59 percent increase from 1.5 million in the second half of last year.

Organizations should look into adopting advanced technologies such as the Trend Micro Cloud App Security solution. It combines artificial intelligence (AI) and computer vision in order to help detect and block attempts at credential harvesting in real time. 

After suspected phishing emails go through sender, content, and URL reputation analyses, computer vision technology and AI will examine the remaining URLs to check if a legitimate login page’s branded elements, login form, and other website components are being spoofed.

For this campaign, threat actors used phishing emails carrying documents written in the language of the country being targeted. The phishing emails were also found with URLs to fake but legitimate-looking login pages. If the recipient of the phishing email clicks on the malicious URL, they will be redirected to a login page that is an imitation of a legitimate website the campaign is spoofing. A login attempt will then lead to the theft of the user’s credentials.


Aside from the websites of international government departments, those belonging to email services and two courier services were also spoofed by the threat actors. The U.S. Department of Energy, Canada’s Government eProcurement service, China’s SF-Express courier service, and Australia’s Government eProcurement Portal were some of the target organizations.

Email users should always be aware of the latest phishing tactics in order to avoid falling victim to credential harvesting attacks. After all, such attacks are becoming highly deceptive; in fact, it has become relatively easy for cybercriminals to obtain a .gov domain that they can use to further disguise their schemes.

To minimize the chance of becoming a victim, users can be cautious of emails from individuals or organizations that ask for personal information. Most companies will not ask for sensitive data from its customers, especially with stricter data privacy laws; look out for grammatical errors and spelling mistakes in suspicious emails. Emails from legitimate companies are often proofread to ensure that the materials they send out are error-free. 

Emails that call on a sense of urgency or have an alarmist tone should not be hastily acted on. If in doubt, recipients should verify the status of their accounts with their company’s system administrator or service provider.

Wednesday, December 18, 2019

Kaspersky’s IT Security Calculator reveals budgets lower than average in 45% of SMBs and 50% of enterprises

Data released by the Kaspersky IT Security Calculator shows that budgets at 45 percent of SMBs and 50 percent of enterprises are below the average spend at US$205,000 for small to medium, and $8 million for enterprise businesses. This is despite a Gartner report announcing cybersecurity spending is growing year-on-year with almost 9 percent growth this year.


The Kaspersky IT Security Calculator is a free web tool that allows IT security managers to view the average budget for cybersecurity in their region and industry, as well as to compare budgets within their organization. The tool is becoming increasingly important as it allows companies to understand their position in the market and also gives them the ability to compare their budget with competitors and improve planning.

Globally, IT security budgets are demonstrating positive dynamics with a number of analyst reports showing that budgets continue to grow year over year. 


Kaspersky’s own survey of almost five thousand organizations across the world confirms this trend with 70 percent of respondents showing they expect their IT security budget to increase in the next three years. However, statistics from usage of the Kaspersky IT Security Calculator in October 2018- 2019 revealed that some businesses are not keeping up with this trend, as their IT security spending is lower than average.

Overall, budgets for SMBs were reviewed more actively (46 percent) than for enterprises (38 percent) and very small companies (16 percent). For small and medium businesses, the budget issue proves to be complicated as it’s not only about finances but also the alignment of the budget planning process. Another challenge to consider is the demands on human resources to hire experts in relevant cybersecurity risks and the protection methods needed for different business services.


“Budget planning is a very important process for companies to carefully consider as the proper investments ensure a company is ready to meet current cybersecurity challenges and threats,” said Sergey Martsynkyan, head of B2B product marketing at Kaspersky. “Though it may be a complex task which demands a deep understanding of business needs towards cybersecurity, it is important to understand how to address them and how much it can cost. At Kaspersky, we do our best to give organizations insights to help them with this process. Along with the report on IT security economics we prepare annually, the IT Security Calculator gives a glance on average cybersecurity spending as well as specific threats and advice on protection measures.”

The Kaspersky IT Security Calculator website with threat statistics and recommended protection is available, and free to use.

Tuesday, December 17, 2019

Oracle makes it to DISA Impact Level 5 provisional authorization for Oracle Cloud Infrastructure

Following closely on the heels of Oracle achieving FedRAMP authorization, Oracle announces Tuesday three new government regions: Ashburn, Virginia; Phoenix, Arizona; and Chicago, Illinois. These regions have achieved DISA Impact Level 5 provisional authorization (IL5 PATO), providing a cloud environment where U.S. Department of Defense (DoD) and other federal customers can harness the power of Oracle Cloud to unlock innovation, improve mission performance, and enhance service delivery.  

This is an important milestone in Oracle’s journey to deliver innovative cloud services with consistent high performance and exceptional security to the entire U.S. government. In 2020, Oracle plans to bring additional full-scale Gen 2 Cloud Regions online to support the classified missions of the US Government.



“U.S. DoD and other Federal customers are continually looking for new, secure ways to improve citizen services and keep our nation safe,” said Don Johnson, executive vice president, Oracle Cloud Infrastructure. “Oracle’s Generation 2 Cloud was engineered to deliver highly secure, high-performance, cost effective infrastructure that helps government organizations address the needs of the nation today and tomorrow.” 

Oracle has been a key technology partner of the U.S. government. Currently, more than 500 government organizations take advantage of Oracle’s technologies and superior performance. State, local and federal government customers using Oracle to modernize their technology include Defense Manpower Data Center (DMDC) and the U.S. Air Force.

The Department of Defense recently awarded a contract to Oracle for its Oracle Cloud Infrastructure to support a large portion of the enterprise human resource portfolio. The award modernizes existing infrastructure and will assist the Defense Manpower Data Center in providing necessary human resource services and capabilities to its military members, veterans and their families.

With Oracle Cloud Infrastructure, customers benefit from best-in-class security, consistent high performance, simple predictable pricing, and the tools and expertise needed to bring enterprise workloads to cloud quickly and efficiently. In addition, Oracle now provides organizations with a complete set of solutions for any high performance computing (HPC) workload, enabling businesses to capitalize on the benefits of modern cloud computing while enjoying performance comparable to on-premises at a lower cost.

Oracle Cloud Infrastructure has achieved certifications and attestations for key security standards and compliance mandates. These independent third-party assurance programs demonstrate Oracle’s commitment to security and to meeting the needs of the public sector. These IL5 PATO government regions will launch with initial Oracle services including VM and bare metal compute (CPU and GPU), storage (including archive, block, and object storage), database, identity and access management, key management service, load balancer, and Exadata cloud service.


“Oracle Cloud Infrastructure brings incredible performance, flexibility, security, and cost-savings benefits to our federal civilian, commercial and higher education customers,” said Paul Seifert, federal sector president, Mythics. “Mythics’ DoD customers will now be able to leverage Oracle Cloud to better serve the unique requirements of the DoD at home and abroad.”

“We’re excited to see the Oracle Cloud Infrastructure achieve DISA Impact Level 5 provisional authorization, as it provides additional options that our federal government clients—especially those seeking to migrate large and complex Oracle-based solutions to the cloud—can leverage,” said Anthony Flake, managing director of Accenture Federal Services’ Oracle practice.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...