Imperva’s VP Tim Matthews and Datapipe’s Director David Lucky Weighs in on DDoS Attacks and the New Datapipe Partnership

Datapipe’s David Lucky recently sat down with Tim Matthews, VP of Marketing for Imperva Incapsula regarding last week’s partnership news and why their Incapsula service is so important in light of evolving DDoS attacks. Read on to hear his take on how Incapsula works with AWS offerings to better safeguard data for enterprises and what this means for Datapipe’s own customers.

David: If our clients are reading about this partnership for the first time, can you tell our readers a bit about the Incapsula service?

Tim: Incapsula is a cloud service that makes websites and web applications both faster and safer. In particular, we are a reverse proxy between our end users and customer sites. We inspect the traffic as it comes through. Since we are seeing all the traffic, we can look at signatures of the traffic, including the location of traffic, helping us identify incoming requests that are not legitimate. What this enables us to do is look for signs of DDoS attacks before they hit the customer site and wreak havoc.

David: And what sizes and types of businesses should consider using your service?

Tim: We really have two main categories of businesses that should consider using our service. The first group is companies who can’t afford any downtime. These are mostly ecommerce, gaming, and travel companies who just can’t afford a minute of downtime otherwise the impact to their business would be detrimental. The second group consists of very large global brands that are concerned about hacktivism – groups of activist hackers bringing down a brand’s site to draw attention to their cause. Essentially Incapsula users, regardless of size, rely on us and Datapipe to keep them safe and running smoothly. They look to us to avoid downtime and keep their brand reputations intact.

David: One of the reasons we decided to integrate with Incapsula is because you integrate with AWS, which fits extremely well with how Datapipe works with this service. Can you tell our readers more about how you integrate with AWS?

Tim: When someone builds an app on AWS, they don’t own the data center or machines. They are hosting their app on AWS infrastructure. So when a Datapipe user implements Incapsula, we sit in front of AWS as another cloud, and that organization’s data is routed through us. We provide an application layer security capability and very easy access to caching on our network. We have a collection of 25 data centers around the world, which enables us to optimize routes and push out content to people a lot faster.

David: And what does Incapsula do that AWS doesn’t?

Tim: We are finding that there truly are more attacks happening at the application layer. Attackers are flooding organizations with requests, going after weak spots, utilizing giant files that take up massive amounts of bandwidth. AWS actually doesn’t offer that level of application layer protection and as a result, more sophisticated attackers are targeting those application flaws. Also, as a result of the increase in DDoS attacks, organizations sometimes have to spin up multiple servers to handle the increase in traffic, which can result in very large AWS bills. By utilizing Incapsula, all traffic is routed, reviewed and filtered so the DDoS attacks never actually reach AWS’ systems, saving organizations money. In addition, organizations can also scale up their protection, just like you can with insurance, which isn’t something you can currently do utilizing the AWS service on their own. In short, we act as an additional barrier, an additional layer of security, providing customers peace of mind.

David: How do you actually identify unwanted traffic?

Tim: There are three things we use to figure out if the traffic is malicious.

  • Country of origin – we monitor typical traffic patterns and when we see traffic from an unusual place, such as a country the customer has never received incoming traffic from, that’s a definite tip-off.
  • IP addresses – if we notice that customer A is attacked by a certain IP address, when traffic from that IP address attacks customer B, we can automatically block it. Once we identify that traffic is bad, we’ll put it in our database. We have thousands of illegitimate IP addresses in our database.
  • Cookie/Javascript/CAPTCHA challenge – we also test connections to see if it’s a human or a bot. Not all bots can handle a cookie, however people using browsers can. If it passes that test, we’ll see if they can handle Javascript. If it passes both those tests and we are still suspicious we’ll put up a CAPTCHA for the user to solve.

David: Are you seeing a growing trend of these more sophisticated DDoS attacks?

Tim: Absolutely. We do an annual report capturing how attacks are changing over time and most recently there are two trends we are seeing. One is that the size of attacks are getting even bigger. As organizations are taking advantage of the economies of the cloud, so are the bad guys. Secondly, we are seeing an increase in the types of the attacks that are application layer attacks, plus people are now posing as Google bots or browsers. No web teams want to block Google bots because they naturally want to be found. However, attackers are now pretending to be bots so they can get right through the system and crawl all the pages for the data they need. They are getting more sophisticated and learning new techniques – it’s up to us to continue to block them at every turn.

Overcome information silos with seamless database integration

Database_Integration

2014 Blog Posting – From content management systems to big data analytics, there’s a lot of discussion about eliminating data silos and integrating resources. Processes such as reporting and document retrieval benefit from being able to pull from multiple sources of information – a step that is hindered when disparate systems prevent the fluid flow of data.

For customers with hybrid IT infrastructures, avoiding these data silos and integrating databases is critical to facilitating streamlined, robust operations and fueling the most effective application performance. In addition to selecting the most appropriate type of environment for each type of resource or program, you also need to implement an efficient way for these components of the system to work together.

What is database integration?

Today, perhaps more than ever before, there’s an incredible amount of digital data available to organizations in just about any industry. Whether they collect and store their own information or draw from external sources, enterprises can run advanced analytics, retain information about their customers, develop compelling new services and catalyze their research endeavors with ready access to a wealth of knowledge.

However, storing all of this information requires data centers and other solutions – often with different specifications based on the type of files involved and facing limitations as to how many resources can be kept on the same machines. Within a hybrid cloud deployment, for example, organizations may store sensitive data within private environments and utilize public configurations to run analytical applications. Often, these pieces need to share information with each other in order for the system to run effectively as a whole and offer users comprehensive results.

Making the most of database benefits

In fact, properly linking different databases and other components of the enterprise system is also critical for realizing the value that the benefits of each element offer. For example, you might host Oracle Real Application Cluster servers to enjoy the advantages of a high availability stack with scalability and agility to support just about any application. However, if your applications can’t efficiently transmit information to and from your resources on Amazon Web Services clouds, your high availability benefit will break down.

Similarly, SQL server enterprise clusters form excellent counterparts to virtual private cloudor public cloud solutions. These clusters store and retrieve data requested by applications hosted in other environments, but they require the right connections to transmit information quickly and reliably. Some corporations utilize VPN hardware for this sort of task, but such solutions have significant limitations, falling short when it comes to supporting more than 4 Gbps. If you have the network and cloud computing power to exceed this rate, why slow it down when linking between databases?

Meeting needs with unique hybrid cloud connectivity

As WiseGeek summarized nicely, integrating databases can be a complicated task requiring connections that use advanced programming logic and can be tested from multiple angles. However, successful integration fuels activities such as displaying search results that pull from a number of sources, ultimately saving end users a great amount of time. With the right connections, these processes happen seamlessly and rapidly from the perspective of the person using the programs.

With Datapipe’s unique hybrid cloud connectivity offering, you can enjoy the benefits of an expertly integrated system without the headache of trying to customize each piece of the puzzle. AWS Direct Connect Enabled Services are tailor-made to connect your Oracle and SQL server enterprise clusters hosted on Datapipe servers with your virtual private cloud or public cloud resources with AWS. Forming a low-latency layer 3 connection between these elements gives you dependable data movement that won’t slow down your applications or processes.

You invest significantly in robust databases and cloud computing services. To eliminate data isolation and segmentation, you need direct connections you can count on.

Fast food industry’s focus on customer engagement demands back-office support

fast-food-industrys-focus-on-customer-engagement-demands-backoffice-supp_1565_40006159_0_14107982_500

2014 Blog

The fast food industry is currently in the midst of some major changes. Some of these developments are relatively familiar, but on a larger scale – for example, the increasing focus on breakfast offerings. Even more overarching is the public’s growing appetite for healthy foods and subsequent weaning off of fast food. This long-gestating shift is so significant that many brands now see the introduction of higher-quality menu items as key to their survival.

It’s not all about the food, though. One of the single biggest changes currently occurring in the fast food industry concerns technology. Specifically, franchises are rapidly developing plans to improve their customer engagement by introducing mobile ordering, pre-ordering and other convenient offerings. Many analysts believe that such efforts will prove vital to fast food vendors’ competitiveness in the years to come. However, to make these plans a reality, these companies need to shift their IT teams’ focus from the back office to the front office.

This means that back-office managed services are rapidly becoming an essential resource throughout the fast food industry.

Front-office measures
The industry’s emphasis on front-office efforts is clear to every industry observer. Writing for CNBC, Brian Sozzi, CEO and chief equities strategist at Belus Capital Advisors, offered an assessment of the biggest fast food trends likely to emerge in 2015. These included the addition of new fountain drinks, the introduction of loyalty programs and, critically,  the introduction of voice-activated ordering apps for mobile devices. Specifically, these apps will be designed to integrate with the Apple Watch.

According to Sozzi, voice-activated ordering apps are a winner for the fast food industry, one that will almost certainly pay off.

“Companies, from restaurants to retailers, continue to try and remove barriers to buying their goods and services,” he wrote. “Who wants to tap five times on an app to order a pizza, right?”

Already, fast food chains are taking steps to introduce voice-activated ordering apps, as well as other mobile apps specifically designed to make ordering faster and easier. For example, Domino’s Pizza has begun to market a virtual-voice ordering assistant on its app known as “Dom.” Additionally, Taco Bell recently unveiled a new app that, in addition to pre-ordering, allows customers to save meals and reorder them simply by rotating their mobile devices quickly.

It’s a game-changer,” Taco Bell President Brian Niccol said, the Orange County Register reported. “We believe mobile ordering and payment is the biggest innovation since the drive-through. This is the future if you want to stay relevant.”

Back-office efforts
Developing, maintaining and upgrading these mobile apps is not an easy task. These resources need to be easy-to-use, aesthetically pleasing, completely reliable and totally secure. Anything less will not only undermine the value of these efforts, but could potentially damage the company’s reputation and brand loyalty.

And it’s not just a question of difficulty – it’s also a matter of time. Moving away from traditional Point of Sale systems and toward mobile payments and preordering is a time-consuming process.  Fast food companies now need their IT teams to devote their time to overseeing this shift from systems of record to systems of engagement.

But there are still plenty of back-office issues that need attention under this new arrangement. After all, apps and mobile payment tools cannot function without a robust and well-maintained infrastructure. Yet the shift to systems of engagement will inevitably eat up the vast majority of IT personnel’s time.

That’s where a managed services provider can provide immense value. With an MSP, fast food companies can outsource back-office responsibilities to a third party, freeing up their in-house staff to focus on front-end matters. This allows the franchise to remain competitive, improving its outreach and customer service, without sacrificing functionality or reliability, and without vastly expanding their IT department.

By working with an MSP, businesses can set themselves to thrive in the still-evolving fast food industry.

About David Lucky

David Lucky
As Datapipe’s Director of Product Management, David has unique insight into the latest product developments for private, public, and hybrid cloud platforms and a keen understanding of industry trends and their impact on business development. David writes about a wide variety of topics including security and compliance, AWS, Microsoft, and business strategy.
 

Product Launch Example 2014 – Datapipe Access Control Model for AWS (DACMA): Bringing deeper, more secure AWS adoption to the enterprise

As a business, your IT infrastructure is your foundation. It runs your systems. It connects your employees with your customers. The success of your business is tied to having both an agile and flexible IT foundation as well as one that is highly efficient and cost effective.

Running key parts of your enterprise IT on the AWS public cloud provides a cost-effective solution that allows for great flexibility, scalability, and power. But it also brings added complexity to your business – complexity that staff members often don’t have the skills or capacity to effectively manage. Datapipe helps companies globally to overcome these challenges and effectively modernize their infrastructures using AWS. We future-proof your IT and help you manage your AWS environment so your IT operations teams and developers can focus on strategic initiatives and applications. And starting today, with the launch of our new Datapipe Access Control Model for AWS, we instill an even deeper level of trust and security specifically focused on protecting and safeguarding your virtual infrastructure.

As we move from companies managing and protecting physical infrastructures to virtual infrastructures, new challenges emerge for the protection of these new IT assets.  There is a lot of discussion around cloud infrastructure being compromised from the outside, with hackers and cybercriminals looking to infiltrate your system and steal data. But one of the biggest threats to a company’s cloud infrastructure comes from the inside – from employees and partners unintentionally exposing an organization through a lack of security best practices – risk that opens up the enterprise to outside threats. When looking for ways to reduce risk, you should start by shoring up the internal security operations. DACMA helps with this. DACMA implements AWS environment security best practices seamlessly, effectively and without additional action or inconveniences needed on your part. With DACMA, you can enjoy all the benefits inherent with Datapipe managed services without worrying that you might not have complete control over your virtual infrastructure and associated data.

Here is how DACMA works:

  • You Keep the Keys: Think of the key to your house. Once you share it, you have to start worrying about who is using the key and what they are doing when inside. Even if you trust this person completely, you have to worry that they may leave your key in a place that would be easy for others to find. If your key is shared with the wrong person, or stolen, then you have to change all your locks or risk that your stuff will betaken. Traditionally, when working with a managed services provider, a business has to hand over their administrator level credentials or root level credentials and API keys to enable that managing hosting provider to run and manage the network. You basically have to hand over the keys to your virtual IT systems and data. DACMA removes this requirement. Through AWS Trust Relationships and Security Token Service(STS) software, Datapipe is able to effectively manage your system without you having to hand over the keys to the system. This method keeps you in complete control of your virtual infrastructure and your data.
  • Role-Based Access: DACMA also enables role-based access within a system. This gives you the ability to control who has access to certain data with ease. An engineer could have full access to the infrastructure while a service delivery manager may have read-only privileges. Role-based access is an essential component for compliance, and DACMA helps businesses achieve it easily and with a high degree of customization.
  • Accountability: With DACMA, all system access and activities are tied back to unique user names without the hassle of managing a long list of AWS users. This identity information is tagged to all actions taken by users and visible to both you and Datapipe via CloudTrail. Accountability within the system ensures you are meeting compliance requirements and also enables detection and response ensuring nefarious actions won’t go undetected.
  • Two-Factor Authentication: DACMA requires two-factor authentication for Datapipe employees to login to the Datapipe SSO. An additional layer of security is enforced by also requiring two-factor authentication for Datapipe employees trying to access your AWS account.
  • Credential Security:  DACMA was built with key protection as a fundamental tenant. Datapipe support personnel never see or directly access their own AWS login credentials. Logins are automated and personnel keys are never exposed. They are stored encrypted in a password vault protected by a high security Hardware Security Module and extensive auditing, access control, and reporting. These security features ensure that for every step of the login process, account keys are secured and protected.

All of DACMA’s security measures for platform security are used by default for all of Datapipe’s Managed AWS clients. Datapipe also offers additional instance-based security protection measures including intrusion detection and threat management, data encryption for all sensitive data and web application firewall to protect against internet-based threats.

DACMA is seamless. It requires no extra steps or oversight once it is set up. Once implemented, DACMA dramatically reduces the risk of a disruption of service or data breach due to unauthorized access of an AWS environment by Datapipe.

We are excited about the launch of the DACMA. DACMA is the result of Datapipe’s deep understanding and experience in effectively planning, building and running highly secure and available AWS environments for clients across the globe. Enterprises often struggle with understanding and implementing the complete set of security capabilities that are available in the AWS platform as well as the security policies and process transformation required for their teams. DACMA bridges that gap. DACMA is security best practices fully realized.

You shouldn’t have to hand over the keys to the virtual infrastructure that runs your business in order to use a managed service provider. Datapipe has always prided itself on partnering with our clients to future-proof their IT, delivering modern, agile infrastructures with the choice and control they expect. The legacy continues with these new capabilities.  If you are interested in learning more about how the DACMA works, we’d love to hear from you.

David Lucky
As Datapipe’s Director of Product Management, David has unique insight into the latest product developments for private, public, and hybrid cloud platforms and a keen understanding of industry trends and their impact on business development. David writes about a wide variety of topics including security and compliance, AWS, Microsoft, and business strategy.

Multi-cloud orchestration offers major backup benefits

2014 Blog Posting of mine:

Cloud computing is here to stay. The technology has easily passed the point where it can be considered a questionable or risky resource – instead, cloud services are now widely and correctly seen as basic essentials for businesses in every sector. Company leaders who previously fretted about whether or not to deploy cloud solutions now focus on the question of how to best leverage these resources.

Increasingly, the answer that business decision-makers are reaching is via the hybrid cloudand multi-cloud orchestration. Multi-cloud deployments offer significant advantages over singular alternatives. And of these, one of the most notable and powerful is improved backup, as InformationWeek contributor John Keagy recently highlighted.

Varied options

Keagy noted that  businesses are increasingly turning to multi-cloud deployments for a number of key reasons. Among the most obvious and important of these is improved backup capabilities. The writer explained that by utilizing multiple cloud environments from a diverse range of providers for data backup, firm leaders can rest assured that their digital assets will remain accessible even in the event of a catastrophe striking one of the vendors. In essence, this is the same benefit that cloud-based backup offers over on-premise and legacy backup strategies: Diversifying the location and method of storage decreases the risk of loss.

“Adopting a multi-cloud approach to application architecture is critical for business continuity,” Keagy wrote. “And in an emergency, depending on the level of resilience you need and the speed at which you want to recover, taking even minimal steps toward multi-cloud will ensure your business can recover.”

Beyond this, Keagy emphasized that there is major value to be gained by deploying cloud workloads to multiple locations. For example, this may represent a key way of optimizing performance, as firms can distribute their cloud-based operations to different geographic regions in order to maximize efficiency and minimize load times for site visitors. Going even further, the writer noted that companies can deliver customized content to site visitors depending on where those individuals originate from.

Moving ahead with multi-cloud orchestration

With all this in mind, it’s clear that more companies will decide to pursue multi-cloud orchestration in the near future. Before too long, this will quite possibly be the standard option for organizations in virtually every industry.

This raises the question of how companies should go about leveraging these solutions. This can be a somewhat complicated issue. After all, hybrid and multi-cloud deployments are typically more complex than singular cloud services, be they public or private. Determining which vendors to partner with for which services and then how to best implement those various components can present an intimidating challenge.

It is not an insurmountable challenge, though, especially when companies work with industry-leading multi-cloud orchestration service providers, such as Datapipe. Datapipe’s staff of multi-cloud experts has the means and knowledge needed to guide clients through every stage of the deployment process. This includes:

  • Assessment: Before developing a multi-cloud orchestration plan, a Datapipe team will evaluate the client’s existing infrastructure and determine the most important, over-arching business objectives.
  • Roadmap: The roadmap will lay out both the immediate strategy for deploying the multi-cloud solution as well as a long-term plan for success, thereby future-proofing the company’s IT.
  • Implementation: Once all of this preparation has been completed, Datapipe will manage the complete implementation process, ensuring the multi-cloud solution is up and running successfully.

All of this makes multi-cloud orchestration not only feasible for a diverse range of companies, but also the clear choice in many cases. Business leaders are understandably eager to take advantage of these deployments, and Datapipe is positioned to transform these decision-makers’ goals into reality.

2015 posting on New Global Center of Excellence will help Enterprises Migrate to the AWS Cloud

One of our main goals at Datapipe is to future proof IT for our customers. This means many things, but key among them is that:

  1. We listen to our customers and develop solutions based off their feedback, and
  2. We find and work with great partners to ensure our customers have access to the best the industry has to offer.

Delivering on both of these things at the same time? That’s a win-win in our book and why we are particularly excited to announce today that we are collaborating with AWS to create a new global Center of Excellence. Datapipe’s hybrid IT and cloud experts will run and direct the Center – and we’ll be backed by AWS services and support.

The focus of this new Center of Excellence will be on Hybrid IT. We’ll further develop the tools and resources our customers need around the globe take full advantage of all AWS has to offer, in sync with Datapipe’s Hybrid IT Services. This new development will help move our global customers out of individual data centers and into true Hybrid IT environments.

As a premier AWS partner, Datapipe will continue to implement purpose built hybrid IT environments that offer the flexibility and scalability of AWS, while fulfilling security needs through our own private data centers. The new CoE will combine Datapipe’s deep understanding of AWS and hybrid IT implementations in the planning, building and management of enterprise applications to AWS and broader Hybrid IT Solutions – all the while backed by AWS services and support.

The joint Global Cloud Center of Excellence will focus on the following:

  • Developing a framework that will help enterprises simplify their migration on to AWS while leveraging Datapipe’s managed services and Hybrid IT Solutions
  • Refining and advancing services, architecture, networks, storage, security, application migration, application modernization, deployment and on-going managed services

We are excited to be able to add yet another huge benefit to our AWS managed service offering. Datapipe’s continued global strategic partnership with AWS highlights our deepening commitment to bringing best-of-class hybrid IT solutions to the enterprise. We’ll be writing more about this new Center of Excellence as its benefits and innovations are fully realized. Keep an eye on the Datapipe blog for the latest.

About David Lucky

David Lucky
As Datapipe’s Director of Product Management, David has unique insight into the latest product developments for private, public, and hybrid cloud platforms and a keen understanding of industry trends and their impact on business development. David writes about a wide variety of topics including security and compliance, AWS, Microsoft, and business strategy.

 

Product Launch Sample 2015 – Now Offering Enhanced Cloud Security Service for Enterprise Web Applications

With the continuing growth of cloud-based services, we are also seeing an increased concern surrounding the security of the data stored within those cloud-based infrastructures. If the same standard of security found in physical IT environments cannot be easily integrated to the cloud, enterprises will experience gaps in their security that could increase risk and expose sensitive data.

Knowing how important security is for our customers, we are excited to announce the integration of the Imperva Incapsula web application security and network protection service into our leading managed Hybrid IT Solutions offering.

With this partnership, we will be able to add cloud-based web DDoS and web application firewall (WAF) protection to the existing DDoS mitigation and hardware WAFs offered within our data centers; an ideal combination for protecting cloud assets. The new offering is an easily integrated, global solution that intelligently profiles incoming traffic in real-time to block even the latest web threats, from scrapers and spammers to sophisticated Injection and XSS attacks, as well as mitigating network and application DDoS attacks. In addition, outgoing traffic is accelerated and optimized through caching and optimization techniques.

Datapipe’s security and control for cloud-based applications now has the ability of the Incapsula service to mitigate DDoS and web application attacks in the cloud, where deployment of hardware based appliances are not possible. To learn more about key elements of the partnership, including how Incapsula will integrate with Datapipe, please see the press release here.

With this integration comes additional flexibility in how Datapipe can deploy and manage customized solutions, which means we can offer an even more consultative approach to an individual enterprise’s compliance or security needs. The service is fast and easy to plug in to an existing infrastructure and is cloud agnostic, allowing customers running on Amazon, Datapipe Hosted Private Cloud, or other public cloud platforms to take advantage of the added DDoS protection.

This new service is built to handle the largest volume-based attacks, such as SYN flood and DNS amplifications, and also mitigates sophisticated application layer attacks by implementing advanced and progressive challenge mechanisms. The service automatically and transparently mitigates DDoS attacks with minimum false positives, so that site visitors won’t know that the site is under attack. We are also offering real-time dashboards as part of this service to monitor & analyze attacks as they happen and features a dedicated 24/7 NOC, manned by experienced security experts, in order to ensure enterprise-grade uptime SLA when under attack.

Key offerings of the new service include:

  • Automatic always-on detection & triggering of “under attack” mode
  • Zero business disruption based on transparent mitigation with minimum false positives
  • End-to-end protection against the largest and smartest DDoS attacks
  • Provisioned without the need for hardware or software installation, integration or changes to the website

Datapipe has always delivered best-in-industry security standards to its customers and we’re proud to be one of the only providers in the market that can offer 100 percent overlap protection between your physical and cloud based infrastructure. We’re excited to enhance the solutions we’re already offering through our relationship with Imperva, a company that has industry recognition as a top WAF vendor, and that has also built a world-class network for DDoS mitigation. Many of our clients require their applications to be secure against a multitude of attacks – we are leveraging Incapsula to further strengthen our service.

This integration, coupled with the recent announcement of the Datapipe Access Control Model for AWS (DACMA), demonstrates Datapipe’s deep understanding and experience in effectively planning, building and running highly secure and available AWS environments for clients across the globe.

Be sure to check back next week for a guest blog post from Imperva’s own VP, Tim Matthews, who will be talking about the partnership from their perspective.

About David Lucky

David Lucky
As Datapipe’s Director of Product Management, David has unique insight into the latest product developments for private, public, and hybrid cloud platforms and a keen understanding of industry trends and their impact on business development. David writes about a wide variety of topics including security and compliance, AWS, Microsoft, and business strategy.

Product Launch Sample – Introducing 2Factor Secure Cloud Access for AWS Environments

40Cloud_animation1

2015 Blog posting – In case you missed our announcement at AWS Summit New York last week, we introduced a new security collaboration with FortyCloud, to help enterprises further secure Amazon Web Services (AWS) environments. This Datapipe/FortyCloud solution is called 2Factor Secure Cloud Access. It integrates Datapipe’s two-factor authentication service, Datapipe Auth, with FortyCloud’s software-as-a-service (SaaS) security model to deliver enhanced security, access, and control to clients operating AWS environments, which allows for easier, more secure remote access of public cloud operations.

Check out what FortyCloud’s CEO, Amit Cohen, had to say about the news:

“Across industries, the benefits of operating a public cloud are well known; however, the risk of unleashing control of an organization’s data is still a great concern. With the added Datapipe Auth capability and the FortyCloud native capabilities, we will offer customers a complete enterprise-grade managed security solution for AWS to help remove the barriers associated with enterprise adoption of the public cloud.”

Our CSO, Joel Friedman also weighed in on the day’s news, saying:

“Two-factor authenticated VPN is a security standard for enterprises, but is rarely used natively in public clouds. With today’s announcement, we are making it feasible for businesses to confidently deploy the same stringent security standards found in traditional IT environments to the public cloud. Given the amount of security breaches resulting from password compromises, strong authentication is a huge benefit for today’s public clouds. In addition, the benefit of restricting users to cloud assets by role delivers far more manageability and granular network access control than commonly used jump host configurations.”

Here is a brief overview on how the new Datapipe – FortyCloud solution works:

40Cloud_animation

For more information on 2Factor Secure Cloud Access, please see here.

Visibility, agility key for successful cloud security

2015 Blog Post – As cloud services become increasingly widespread and popular, many of the myths surrounding cloud security are inevitably fading away. In the technology’s early  P, many people viewed the cloud with extreme suspicion, assuming that entrusting their data and operations to third-party cloud vendors was inherently less secure than keeping these resources on-premise. Such a view was based more on fear than reality, and is quickly fading away. For example, a recent Black Hat and Bromium survey of 100 IT professionals found that only 9 percent considered the cloud the greatest security threat facing their organizations, tied with networks. By comparison, 55 percent pointed to endpoints and 27 percent cited insider threats, Cloud Tweaks reported.

Still, despite all of this, the fact remains that cloud security is indeed an issue that companies’ IT leaders need to take seriously. To this end, it’s critical for organizations to embrace cloud deployment strategies that emphasize both visibility and agility.

Visibility needed

FCW contributor Pete Nicoletti recently highlighted the importance of visibility in cloud security efforts. Nicoletti focused his attention on cloud computing among federal agencies, but this point holds true for any cloud deployment in either the public or private sector. Specifically, the writer emphasized that IT decision-makers must make visibility a priority when considering embracing any third-party cloud services. This is important not just for ensuring the integrity of cloud-based resources, but also in terms of the closely related issue of compliance.

“IT leaders need insight into the entire data-hosting network system – locally, regionally and globally – to ensure that compliance standards are met and that the provider is operating transparently,” Nicoletti wrote.

To confidently embrace a cloud solution, IT decision-makers must be aware of all of the components involved in the implementation, and have the ability to check in on these areas easily whenever needed. There’s simply no real way to protect a cloud-based network and its data if administrators and decision-makers are unaware of exactly what they are defending. This holds true whether the responsibility for cloud security services is kept in-house or outsourced to a third-party managed services provider. In the latter case, that third party should be willing to work closely with the company’s in-house team to develop a transparent, trusting relationship.

Agility advantages

In addition to visibility, cloud security demands agility. The cloud – and the threats it faces – is constantly evolving, and so cybersecurity efforts in this area need to develop apace to hold these dangers at bay. This is particularly true when it comes to hybrid clouddeployments, as Forbes contributor Jack Sepple recently highlighted. He pointed out that, in order to remain one step ahead of sophisticated and tenacious hackers, companies need to embrace policies and attitudes that go beyond traditional data security strategies.

“Companies that are doing this well are expanding their security measures beyond the traditional, internal perimeter – downgrading the intranet to an equal trust level as the public Internet,” Sepple wrote. “This disruptive perspective allows for streamlined, consistent security processes to be created, operated and maintained across any environment, public or private.”

To this end, the writer emphasized the importance of integrating “automation, orchestration, workflow and accessibility” into their overall cloud security plans.

Developing, implementing and maintaining such a sophisticated, multi-component cloud security strategy is not an easy task, especially for IT teams with limited resources. That is why it is often far better for businesses looking to shore up their cloud security capabilities to partner with a managed cloud security services provider such as Datapipe. Datapipe’s experts have unbeatable levels of experience and knowledge in this area, allowing them to work closely with clients to develop transparent, agile, reliable strategies and solutions.

2015 Post – Federal cloud use accelerating, but obstacles remain

In 2011, the White House announced its Cloud First initiative, mandating that federal IT decision-makers initially consider cloud-based services when seeking to add a new IT system or solution. Since then, the federal government has made significant strides toward broad cloud adoption. In many ways, agencies have even managed to surpass the private sector when it comes to cloud deployments.

The success of FedRAMP is perhaps the single biggest signal of this trend. As the General Service Administration recently reported, more than four-fifths of all federal cloud implementations went through FedRAMP during the six-month period observed. This is an encouraging figure, but it’s also true that there are still obstacles standing in the way of an optimized, government-wide embrace of cloud computing.

FedRAMP and the cloud

The purpose of the FedRAMP program is to vet cloud services for security concerns, ensuring that they meet the base-level requirements for most federal agencies. This is an essential process for overall government cloud adoption, as security remains the leading concern for most decision-makers when it comes to cloud implementations. This is particularly pronounced in the public sector, where the potential consequences of a data breach can be exceedingly damaging. Many, perhaps most, federal agencies do not have the talent and resources in-house to thoroughly vet potential cloud services to ensure they comply with federal guidelines, but FedRAMP largely reduces this requirement.

The GSA’s latest report makes it clear that FedRAMP is fulfilling this purpose. According to the study, 82 percent of the more than 1,400 federal cloud deployments examined received security clearance from FedRAMP. This figure is due to a number of factors, including the increase in the number of FedRAMP-certified cloud service providers by 41 percent to 38 total over the six-month period analyzed, Fierce Government IT reported.

Not only has FedRAMP increased federal agencies’ ability to embrace cloud solutions confidently, according to the GSA, but it has also saved $70 million per year by eliminating independent security assessment which would prove redundant, the source noted.

Room for improvement

Yet as positive as these results are, it is important to note that the federal government still has a ways to go in the realm of cloud adoption. Writing for The Washington Post, Aaron Levie recently emphasized that numerous government systems remain quite out of date. In many cases, agencies have favored short-term fixes over large-scale upgrades – such as moving data and operations into cloud environments. This has left agencies vulnerable to cyberattacks. The writer pointed to the recent breach of approximately 18 million federal records at the Office of Personnel Management as a leading example.

According to Levie, the older a piece of legacy IT is, the better the chances that cyberattackers will know or discover a way of exploiting its vulnerabilities. Embracing cloud services can therefore not only improve efficiency and productivity, but also shore up agencies’ cybersecurity capabilities. However, to enjoy these benefits, federal decision-makers will need to look for managed services providers that can offer the experience and expertise needed to ensure a smooth, save transition to cloud-based IT.