Monday, 8 April 2019

Cloud Computing Trends That Will Amaze You in 2019


Initially, cloud computing was just a tool to facilitate smooth computing experiences. With time, it has evolved to be a scalable service essential for a modern firm. It has turned out to be a buzz offering a lot of practical value. Cloud Computing has changed the way the business environment operates. The enterprises are striving hard to provide cheap, advanced and secure services to grow themselves in this competing world. Today, the cloud has come a long way and has been widely acknowledged by analysts and enterprises as the driving force to alter the IT landscape.








In the era of cloud computing buying servers, updating applications or operating systems or disposing of hardware becomes outdated. The world of internet is sure to suffer without a cloud. According to a report, industries run 79% of their workloads in the cloud. Companies leveraging the emerging trends in cloud computing are expected to grow at a faster rate.

Here are a few emerging cloud technology trends to watch in 2019.

1. Hybrid Cloud Solution

Hybrid cloud is likely to become the dominant business model in future since it enables a modernised infrastructure with two or more delivery models. Hybrid cloud environment connects a mix of public cloud, private cloud and on-premises infrastructure evolving to suit the unique needs of an organisation.




Cloud bursting is the primary reason for its rising demand. Hybrid cloud allows the enterprises to use unlimited resources to process the fluctuating workloads. To balance the organisations demand with supply, it offers close monitoring of the used resources.

The hybrid cloud solution is more popular among medical organisations to keep full control over sensitive data. It enables organisations to protect their most confidential data on their terms. In other words, Organizations themselves decide the data storage and conditions to secure the data.

2. Artificial Intelligence Platform

Artificial Intelligence is expected to aid the world mainly in providing intelligent business functionalities in future. The amalgamation of both artificial intelligence and cloud computing is “The Intelligent Cloud”. It is capable of processing big data with greater efficiency and speed.
The two critical pillars of AI are data and compute. Artificial intelligence has automated businesses with robotic process automation. It automates human tasks in organisations and used for hiring employees for a job. It is increasingly adopted in industries to reduce human workloads.



Hardware optimisation is the primary reason behind its rapid adoption. AI- optimised silicon chips can be inserted in any device to carry AI-oriented tasks.

3. Serverless Computing

Server less architecture is event-driven. In other words, for each request, a state is generated, and once the architecture serves the application, a state is destroyed. Server less computing referred to as Functions as a Service (FaaS). Since the Server less functions are accessed as private APIs, you need to set an API Gateway.



The industries are leveraging Server less computing to support a wide variety of dynamically changing needs including IoT, mobile applications and web-based applications.
This event-based programming spins up to complete user request and spins down once the task accomplished. It runs typically for a few seconds or milliseconds at a time thus, reducing the cost.

4. Edge Computing

Edge computing is shifting the computing functions close to the source - edge of the network. It dramatically reduces the complexity of interconnected systems making it much easier to gather and analyse data in real time. It has a distributed and open-ended architecture that decentralises the processing load.




Edge computing enables industrial equipment to make autonomous decisions without human intervention. It is the building block for smart factories equipped with temperature, motion and climate sensors capable of controlling light, cooling and other environmental factors. This will result in efficient use of power.

5. Backup and Disaster Recovery



The increasing usage of data is driving the adoption of backup and disaster recovery software among organisations. The thought that hardware failure can result in companies compromising its confidential data leads to the rise of disaster recovery software in the market. Data backup can’t be considered as a “set and forget” solution. It requires regular maintenance and testing to ensure an appropriate facility and easily accessible to the company.


The customers enjoy a better business continuity plan since a cloud disaster recovery plan is automated and recovers the files in seconds. The pay-per-consume feature makes it more popular among enterprises with less budget.

6. Cloud Security



Cloud computing
security is a set of policies, controls, technologies and procedures working together to protect cloud-based systems, data and infrastructure. The delivery of cloud security depends on individual cloud provider or cloud security options in place.

Cloud security is mainly responsible for securing the data and fighting against hackers. Cloud backup ensures your data is protected from external threats without a need to have an antivirus plan.

The security layer in cloud consists of network security, physical security, measuring endpoint security and communication encryption. The traffic moves to and from the cloud through public channels. The encryption like SSL is vital to maintaining the integrity of data. Carefully inspect the data movement and implement the possible checks.

Final Thoughts

Cloud computing growth continues to accelerate with the technological innovations and rising trends. It is capable of providing better security, storage and helps in better decision making. The trends in cloud computing are sure to automate the businesses thus reducing the machine complexity and labour. The companies are leveraging these cloud-computing trends to stay ahead of the competition.

Monday, 1 April 2019

Safeguarding your Organization from Internal Threats

Just a quick recap from my previous blog where we focused majorly on How crucial data is and what’s even more important is its security. We also saw some standard practices for ensuring Data Security.
1. Disk Encryption- Converting data into a form that cannot be easily interpreted without a key that makes it legible.

2. Backups- Creating multiple copies of data at regular interval so it can be recovered if the original copy is lost.

3. Data Masking- Masking certain areas of data so sensitive information can be protected from unauthorized access.

4. Data Erasure- Ensuring data no longer in use is completely removed and cannot be recovered by unauthorized people.

Threats are not always bound by external sources; we need to focus on Insider Threats as well which now a days are posing more serious risks to any organization. We do have lots of security measures inside our perimeter but is it not enough? Speaking of an organization like ESDS, need to protect its integrity from our staff, vendors, customers who have Co-located their servers, Contractors, etc. The in-depth knowledge of our Network Layout, Connectivity, Policies, Processes, Business practices completely lie in the hands of our staff members.

One interesting fact about security which I came across while browsing the security zone website is maximum data breaches occur due to Internal Attackers.
The study also revealed, Organization that incurred serious loss and negative financial impact was of major share of 68%.
Most of the Internal Threats can be prevented rather it is manageable to prevent by giving proper Trainings to the employees. What an organization needs are a clearly drafted and defined policy framework that is implemented across the complete organization and monitored regularly by the Security Teams. Following are some of the steps which will enable an organization in prevention against internal threats.
1) First Security Policy

Your ISMS 27001 should include the Information transfer process. How is the data flow for Internal Teams? Similarly, while sending data outside your organization, it should be sent through secure network.

Organization Chart is another important aspect. Hierarchy should be followed in-case of any incident. Specify in your Security policy who is allowed to access which data. Even with whom the employees are allowed to share the data. Inform the consequences if any data is mishandled.
2) Educate your employees

Every department of your organization has some localized data within the department. This data might be of high or low importance. It may relate to Marketing, Sales or Personal Information of any customer. To secure this data from your employees, they need to undergo security training sessions. The best way to reduce risk from Internal Threats is to provide High end security training; explaining the importance of data and what will be the consequences if they fail to follow the security standards. Make the training interactive with some security related games. We do not say that employees will do any malicious incident but at least if they see, they may recognize it and will raise a red flag to their seniors.
3) Classify your Data

Data is classified into 3 main categories: Restricted, Private and Public data. This classification is mandatory in every organization and for every process. It should be included in your Security Policy. This helps the security team to easily rectify the data and its severity. Access to the classified data will be based on the designation of employees.
4) Physical Security

Every valuable computer must be highly secure. Only the ones who are handling the data must have the access. Use of CCTV to monitor the sensitive areas. Dual Factor authentication using smart cards or pins must be implemented in Secure zones like Data Center, Stores, Legal etc. Even consider biometric authentication for all your employees. Use of USBs must be restricted for the employees unless it is necessary. It should get scanned from IT team before using.
5) New Hires Screening

One way where you can minimize the risk is during the employment process. The role of HR begins while hiring a new candidate. A thorough background check is necessary before the employee gets on-board. HR needs to perform checks not only at the professional level but also a complete family background check if necessary. For an organization security of data is the main concern. After onboarding the employee should undergo training on Security related to the organization. Not only this, when any employee leaves the organization, HR needs to revoke all its access and make sure before being relieved the employee has submitted all the data which he was holding in his possession.
6) Strong Authentication

A strong password policy should be followed. The password should change on biweekly basis to prevent any kind of loss. Every system, servers, and the storage must be in Dual Authentication mode.
7) Monitor for “Abnormal” Behavior

Try to install right software and devices with proper access control. You need to use granular access control to monitor all the activities of the systems. Unauthorized users must be blocked from logging into the sytem. Track the behavior and if you find any abnormal action track the behavior and raise the red flag for further investigation and any Legal implications.
For investing on security we always look for reliable service provider. If you want more details on External and Internal Threats and about securing your organization, you have come to the right blog!
Request you to visit https://www.esds.co.in/soc-as-a-service for our offerings and experience of (Security Operation Center) SOC as a Service.

Thursday, 21 February 2019

Hacks to Secure Your Data in Cloud


To the digital era, the cloud has proved to be a big blessing. It enables storing of a large amount of information- photos, videos, music, messages, etc. with a limited budget. With the dawn of internet, backing up data became much easier by storing it on the server rather than hard drive. Also, data can be accessed using internet enabled devices. It is fascinating to know that the birth of the internet has made it possible to squirrel away a huge amount of data without buying extra storage devices like memory sticks or hard drives. Recently, with technological advancements, we have seen Google Docs and Gmail taking place of Microsoft Word and Outlook Express. But, the raised concerned is data security in the cloud. Have you ever thought is your data secure on the internet? 



We have seen too many cases of data hacking in the past. In 2011, Sony’s PlayStation Network carried all the news channels by storm for its news of data hacking. A huge amount of user information was compromised. Also, recently in September 2018, we came across news of Facebook security breach exposing more than 50 million user accounts. This was the largest breach in the last 14 years of the company’s history affecting millions of lives by compromising their personal information. 

Though hacking is considered to be highly illegal there are different hacking groups targeting businesses, national security and also, private information. The user information like usernames, passwords, home address and also, credit card information encourages the hackers by enabling easy access to boatloads of personal information. Passwords are a way to safeguard your information from the prying eyes. But, let’s be honest that we prefer simple passwords which are easier to memorize. But, these passwords can be easily guessed by the hackers and your personal information can be at risk. We keep on blaming the security systems for poor security and the hackers for the malicious attacks. But, it is a fact that the users are also at fault in these attacks. 

Here are a few tips to help you secure your data on the cloud 

1. Don’t Reuse or Share Passwords

It is really bad to use simple passwords as the hackers can easily guess them and breach into your account. Once, the hacker gets access to your email account he can easily breach into your other web logins since the passwords are mailed to your email accounts. Your information networking sites like Facebook, Instagram, banking, etc. will be compromised. The hacker can also change the passwords restricting your access to the accounts. So, it is a piece of advice to use passwords that are hard to break and difficult to guess. You can use a combination of capital and small characters, numbers, symbols to secure your data. 

The second suggestion is never to use the same passwords for different sites. If you wish to reuse the password across multiple sites change up letters, capitalization and symbols. You need to be sure that you don’t repeat the password across different sites which carry your banking details like credit card information or social security number. Out of all, your email account password is the most important so don’t repeat it for any site. 

Lastly, never share your passwords with anyone may it be friends or family members. The number of people who know your passwords is directly proportional to the possibility of your passwords being compromised. Following these password rules will make your online life more secure. 

2. Data Backup 



It is beneficial to take backup of your data to be on a safer side. The unexpected accidents like system failure, robbery, power surge and faulty hard drive may take place when they are least expected. Years ago, data backup was an expensive task but, cloud storage brings a cost-effective and better solution. Cloud storage is available in all sizes and shapes. 

The smartest way to backup data is storing all the files on the cloud instead of depending on a single device. It is highly important to locally backup data on a secondary device or automated backup drive with hard to crack passwords. 

There are many organisations offering cloud storage services to set up some cloud accounts for storage purpose. 

3. Password Manager

Password manager allows you to lock all your unique passwords behind one master password. In other words, it allows you to create separate logins for different accounts like Facebook, Twitter and cloud storage but, you can access them memorizing the single password. Last Pass, KeePass, etc. are the online password management utilities available in the market. 

These online utilities are also capable of creating random passwords that are impossible. These utilities synchronize the information across multiple web browsers and devices thus, enabling to fill the forms with just a click. 

4. Data Encryption 



Data encryption is an excellent practice to encrypt data before uploading it to the cloud. This can be a better precaution against the malicious attacks from hackers. Using local encryption as an additional layer of security will help you protect your information from the service providers and administrators. While selecting a service provider make sure you choose the one that provides data encryption facility

5. Avoid Storing Sensitive Information

There is a huge number of enterprises that avoid storing confidential or sensitive information on their servers. This is because saving such confidential information can be a risk to the organizations. Hackers are always ready to target the firm’s sensitive information, securing which is of utmost importance to the enterprises. Compromising this information can cause gruesome troubles and losses to the firm. 

Also, uploading sensitive data on the cloud is risky for customers too. It is your responsibility to make sure to keep your personal information out of this virtual world to protect it from hackers. So, it is an appropriate solution to avoid storing such information on the cloud. 

6. Be Aware of Your Online Behavior 

Your online behavior is sometimes responsible for the security of your data on the cloud. It is good advice about not saving passwords while using public desktops. Also, make sure you logged out once you are done using the public computer. If these rules are not followed, your data may be compromised by the strangers accessing it. 

Hackers target you by sending spam emails that are worth not opening. Similarly, while making online payments and shopping make sure you research everything you need to know and it is not a fraudulent site. 

Also, connecting to open Wi-Fi hotspots in public places to access the data in the cloud may be a high risk. These public connections are unencrypted which means the hacker can intrude your data on the same network. He may get access to your confidential information like login credentials. Smart browsing can help you secure your data in the cloud. 

Conclusion

Despite, Cloud Computing having several benefits the major concern is data security in the cloud. The rise of the internet has given birth to hackers who are capable of breaking the security. You can prevent the hackers from entering your cloud security system by following the above techniques. Data encryption, avoid reusing passwords and all others mentioned in the blog are a few hacks that need to be implemented to safeguard your privacy from hackers.