SPECIAL HOW IS COVID-19 IMPACTING THE ICT INDUSTRY
PA G E S 6 4 VOLUME O7 | ISSUE 09 APRIL 2020 WWW.EC-MEA.COM
CYBERSECURITY
WILL NEXT GENERATION SOLUTIONS BE
SMARTER AND FASTER
Why travel business Seera moved to AWS cloud Abdulrahman Mutrib, Seera Group
Are your ideas hampering digital growth Dave Aron, Gartner
Do you have the soft skills to manage DevOps
Rodrigo Albuquerque, F5 Networks
Managing challenges of complexity Daniel Fried, Veeam
AD-ECMEA-102020
15+ top executives give their take on how AI and ML is being embedded in next generation cybersecurity solutions.
Why Should You Partner with NetApp to Help Customers Achieve a True Hybrid Multicloud Experience?
350+ customers
The only one
NetApp multicloud products are proven, with more than 350 customers and more than 200PB deployed to date.
NetApp offers the only hybrid cloud infrastructure in the market today.
Why HCI?
0 3x
lock-in: NetApp products are open and flexible storage performance more than others
22% 59%
more efficient use of compute performance lower TCO: much less to implement/manage
What customers say? 87% of customers report that hyperconverged has made their organization somewhat or significantly more agile.
Contact Ingram Micro today to know more about NetApp solutions Tel.: +971 4 369 7111 | Web: ae.ingrammicro.com
A BRAND NEW WORLD OF COLLABORATION AND NETWORKING AWAITS YOU
AVAILABLE ON THE
App Store
W E A R E M U LT I LINGUAL English • Türkçe • Italiano • • fganh • Français • Afrikaans • Español
ANDROID APP ON
Google Play D OWNLOAD NOW
www.globalcioform.com
INTEGRATE INFLUENCE IMPACT
EDITORIAL
Stress testing innovation
ARUN SHANKAR EDITOR A R U N @ G E C M E D I A G R O U P. C O M
As an aftermath of the financial institution’s meltdown of 2008, triggered by the collapse of Lehman Brothers, and the bailouts of JPMorgan Chase, AIG, Morgan Stanley, Goldman Sachs and others, US banks were asked to stress test their financial liquidity levels. Could they withstand the fallouts of another meltdown as had happened in 2008? Today with COVID19, almost every type of institution, whether healthcare, banking, financial, technological, operational, logistical, civil or social, is being tested and may continue to be stress tested for some time ahead. In a recent discussion with a leading global cybersecurity researcher, he mentioned that with the work from home approach adopted by nations all over the world, corporate networks are being inundated by a plethora of end point devices. Never before have corporate networks been so inundated with so many types of end points, clamoring for real time visibility, with such huge varying levels of security compliance and non-compliance. Across the world, in so many developed and developing nations we have the engineering and innovation capability to find the solution to the disruption being caused by the pandemic. By what is challenging everyone, including the CISOs, cybersecurity vendors, and consultants, is that there is too much of everything at the same time, a real classic case of, stress testing to the limits. Continuing in the discussion with the global researcher, he was at lengths to point out that the innovation required to solve the work at home challenge for CISOs is well within the capability of the present-day cyber security industry. The challenge for CISOs and other cross industry executives, caught up in the global pandemic survival saga - is a never before encountered situation. CISOs and other global heads just need to come to terms with how to manage the situation, very quickly. Watch this space for more survival feedback! In this month’s edition, we look at the various points of inflexion across cyber security technologies. Says ManageEngine’s Rajesh Ganesan: A major pain point with the current generation of tools is the lack of ability to support changes in technology and user behaviour. An unfortunate scenario like the current global pandemic has turned things upside down with organisations scurrying to enable employees to work remotely. For CISOs, this has been a huge source of stress. Despite figuring out the logistics, if the current security tools are inadequate, it is a career-defining call for most CISOs to allow remote work. In other words, CISOs are playing with a rolling dice as work at home gets underway. Turn the pages to read what 15+ other top industry executives have to say about the impact of AI, ML, quantum computing, IoT, social engineering, algorithms and analytics, on the current portfolio of cyber security solutions. From GEC Media Group Do take care of your health Steady and safe remote working ë
PRINTED BY
MEA MANAGING DIRECTOR Tushar Sahoo tushar@gecmediagroup.com EDITOR Arun Shankar arun@gecmediagroup.com CEO Ronak Samantaray ronak@gecmediagroup.com
EVENTS EXECUTIVE Lhodith Ann ann@gecmediagroup.com
DESIGNER: AJAY ARYA ASSISTANT DESIGNER: RAHUL ARYA
SUBSCRIPTIONS INFO@GECMEDIAGROUP.COM SOCIAL MARKETING & DIGITAL COMMUNICATION yasobant@gecmediagroup.com
A P R I L 2020
MEA
PUBLISHED BY ACCENT INFOMEDIA MEA FZ-LLC PO BOX : 500653, DUBAI, UAE 223, BUILDING 9, DUBAI MEDIA CITY, DUBAI, UAE PHONE : +971 (0) 4368 8523 31 FOXTAIL LAN, MONMOUTH JUNCTION, NJ - 08852 UNITED STATES OF AMERICA PHONE NO: + 1 732 794 5918
YASOBANT MISHRA
04
DUBAI, UAE
PRODUCTION, CIRCULATION, SUBSCRIPTIONS info@gecmediagroup.com
DESIGNED BY
EVENTS EXECUTIVE Shriya Nair shriya@gecmdiagroup.com
MASAFI COMPOUND, SATWA, P.O.BOX: 5613,
SALES AND ADVERTISING Ronak Samantaray ronak@gecmediagroup.com Ph: + 971 555 120 490
GLOBAL HEAD, CONTENT AND STRATEGIC ALLIANCES Anushree Dixit anushree@gecmediagroup.com GROUP SALES HEAD Richa S richa@gecmediagroup.com
AL GHURAIR PRINTING & PUBLISHING LLC.
A PUBLICATION LICENSED BY INTERNATIONAL MEDIA PRODUCTION ZONE, DUBAI, UAE @COPYRIGHT 2013 ACCENT INFOMEDIA. ALL RIGHTS RESERVED. WHILE THE PUBLISHERS HAVE MADE EVERY EFFORT TO ENSURE THE ACCURACY OF ALL INFORMATION IN THIS MAGAZINE, THEY WILL NOT BE HELD RESPONSIBLE FOR ANY ERRORS THEREIN.
CONTENTS APRIL 2020 | VOLUME 07 | ISSUE 09
06
ARE YOUR OUTDATED IDEAS HAMPERING DIGITAL GROWTH DAVE ARON, GARTNER.
08
DO YOU HAVE THE SOFT SKILLS TO MANAGE DEVOPS RODRIGO ALBUQUERQUE, F5 NETWORKS.
14-17
SPECIAL COVID NEWS
23-25 CLOUD NEWS
54
INNOVATION RUNNING AI APPLICATIONS ON ORACLE’S EXADATA PLATFORM
10
12
MANAGING THE INCREASING COSTS OF WORK AT HOME TALA SEIF, SCHNEIDER ELECTRIC GULF.
MANAGING CHALLENGES OF DATA AND CLOUD COMPLEXITYE DANIEL FRIED, VEEAM.
26-30
32-34
SECURITY NEWS
CHANNEL STREET
59
REAL LIFE WHY TRAVEL BUSINESS SEERA MOVED TO AWS PUBLIC CLOUD
COVER FEATURE 38
36
37
39
40
41
42
43
44
45
46
47
48
49
50
52
53
THREAT INTELLIGENCE, NEXT FRONTIER FOR TRANSFORMATION ASHRAF SHEET, INFOBLOX
MOVING AWAY FROM BEST OF BREED TO BEST OF SUITE FADY YOUNES, CISCO
LEVERAGING CLOUD, MICROSERVICES FOR SMART INTEGRATION JEFF OGDEN, MIMECAST
DISCOVERY AND AUTOMATION CRITICAL FOR DIGITAL BIZ KARL LANKFORD, BEYONDTRUST
IMAGINE YOUR DATA HAS BEEN HACKED BUT NOT REMOVED NEIL MCELHINNEY, THALES
MANAGING YOUR SECURITY BUDGETS WITH AI AND ML AMIR KANAN, KASPERSKY
CAN WE DELEGATE SECURITY TO MACHINES FAST ENOUGH? DR MIKE LLOYD, REDSEAL
LEVERAGING CLOUD AND AI TO BOOST THREAT INTELLIGENCE HARISH CHIB, SOPHOS
SECURING CLOUD APPS, MOBILE USERS IS FUNDAMENTAL JOHN PESCATORE, SANS INSTITUTE
INTEGRATING AND SECURING IT AND OT ENVIRONMENTS MAHER JADALLAH, TENABLE
AI, QUANTUM COMPUTING WILL TRANSFORM CYBERSECURITY PAUL VAN DE HAAR, KPMG
NAME OF THE GAME WILL BE AGILE BEHAVIOURAL TOOLS AMMAR ENAYA, VECTRA
CISOS MUST PLAN FOR HUMAN ELEMENT IN THEIR DEFENSE EMILE ABOU SALEH, PROOFPOINT
PREDICTING A POSSIBLE BREACH BEFORE IT CAN OCCUR HESHAM ELSHERIF, A10 NETWORKS
CISOS CHALLENGED BY TEAMS, PROCESSES, TECHNOLOGIES JONATHAN COUCH, THREATQUOTIENT
COMING UP: AUTOMATION, CORRELATION, VISUALIZATION MARCO ROTTIGNI, QUALYS
AI, ML SYSTEMS MAY BE HACKED BY PRIVILEGED USERS RAJESH GANESAN, MANAGEENGINE
AP R I L 2020
MEA
05
VIEWPOINT
ARE YOUR OUTDATED IDEAS HAMPERING DIGITAL GROWTH
DAVE ARON AT GARTNER LISTS SIX STEREOTYPED MINDSETS AND RECOMMENDATIONS THAT CAN SET BACK AN ORGANISATION’S DIGITAL INVESTMENTS.
82%
While 82% of CEOs have plans to transform, only 22% understand the need to make changes to their business model.
DAVE ARON, DISTINGUISHED VP ANALYST, GARTNER.
Examples of bottom-line benefits usually share a common thread, a maturing approach to digital business. Instead of simply translating a traditional process into a digital equivalent, organisations changed their process by optimising it or doing something that was not possible before. There are six outdated ideas listed that are hampering digital growth. OUTDATED IDEA #1 IT ALONE IS RESPONSIBLE FOR DIGITAL C-suite leaders tend to look to their CIOs for guidance on how to integrate digital approaches throughout the organisation. While the CIO has a critical role to play, IT cannot drive digital transformation alone any more than marketing can be solely responsible for the customer. Recommendation: Promote holistic ideas of what digital means for the organisation and encourage business leaders to consider digital as part of every decision or initiative.
06
A P R I L 2020
MEA
OUTDATED IDEA #2 GLOBAL ROLES ARE FIXED Successful digital businesses will think creatively about location. They will reach across geographic boundaries and transcend geographic stereotypes to access the talent, resources and partnerships that drive success. Recommendation: Adopt a mindset for a multipolar world. Promote broad diversity in teams and invest in multicultural awareness for all employees. OUTDATED IDEA #3 GROWTH EVOLVES FROM CORE POSITIONS Strategists used to pursue organic growth through product or brand extensions that leveraged existing core competencies. Digital capabilities and data expand the possibilities. Just as Amazon Web Services grew out of the company’s in-house data center, so too can legacy firms build capabilities that evolve into new business lines. Recommendation: Look for new markets where in-house digital capabilities and data resources unlock opportunities. Explore partnerships with organisations that have complementary skills for these new markets.
60%
of enterprises are digitally vulnerable.
OUTDATED IDEA #4 CX HAPPENS INSIDE AN ORGANISATION’S BOUNDARIES Customer experience, CX has long focused on customer interactions with a product or service. The borders that mark where one product experience ends and another begins are becoming porous, however, as people interact with both physical and digital platforms as part of a holistic customer experience. Recommendation: Think of CX as an integrated cross-market effort. Explore opportunities through the lens of customer behavior. Sector overlap is a natural consequence of how customers operate in the real world. Look for opportunities to exploit it. OUTDATED IDEA #5 ENTERPRISE SUCCESS IS ONLY ABOUT PROCESSES A digital mindset requires openness to spontaneous and sometimes one-off opportunities to solve customer problems. Process thinking is not totally irrelevant in a digital context, but it has to serve products capable of flexibly serving customer needs and behaviors. Recommendation: Communicate how placing too much emphasis on process can lead to rigid approaches incapable of capturing new opportunities. Integrate process and product teams to design digital products and services that take both sides into account. OUTDATED IDEA #6 AGILE PRACTICES MAKE FOR AGILE ORGANISATIONS Agile development enables tech teams to deliver new functionality and still pivot quickly when new needs arise. The proven benefits have encouraged agile’s spread to non-IT departments like marketing and operations. It is still not enough. Recommendation: Cultivate an adaptable culture, enabled by a leadership growth mindset. For concrete priorities, embrace a product management approach that encourages fast, incremental deliverables and the ability to shift and adapt as necessary. ë
End-To-End Business Networking Solutions by
WIRELESS
NUCLIAS
IP SURVEILLANCE
by
SWITCHING
SECURITY
CABLING
Next-Business-Day Replacement Register at www.dlinkmea.com/nbd and avail:
3 Years Free Next-Business-Day Replacement* 5 Years Warranty Services**
PROTECT
https://me.dlink.com
*
Register the product within 60 days of product purchase NBD registration applicable to end customer/actual product user only ** Only applicable on D-Link Managed and Smart Managed Switches
VIEWPOINT
DO YOU HAVE THE SOFT SKILLS TO MANAGE DEVOPS
IF YOU ARE NOT SHARING IDEAS WITH DEVOPS COMMUNITY, THEN YOUR PROJECT IS LIKELY TO FAIL, ELABORATES RODRIGO ALBUQUERQUE AT F5 NETWORKS.
Much has been written about technical aspects of DevOps but, less attention has been spent on fundamental soft skills.
RODRIGO ALBUQUERQUE, DEVOPS SOLUTION DEVELOPER, F5 NETWORKS.
Before jumping full-blooded into the DevOps realm, it is always prudent to test processes.
Innovation and progress have the best chance to succeed when inter-team alignment is constant, and everyone is relentlessly, continually engaged in collaborative dialogue. This is exactly why DevOps methodologies are having such an influential impact on software development right now, bringing development and operations teams together to produce the best possible outcomes. Much has been written about the technical aspects of DevOps but, regrettably, less attention has been spent on championing the fundamental soft skills that make it so powerful. The key soft skills and behaviours essential for DevOps actualisation are not technical, though they are closely related to technology. First, let us look at community. DevOps tools are open source and maintained by a vibrant group of people, so it is important to be in touch with peers. If you are not sharing ideas and contributing to the community, you are probably doing it wrong. DevOps is an inherently social process where you must engage to stay relevant and up to date. Then there is collaboration. You cannot succeed in the DevOps world without it. A non-stop development pipeline without barriers will not happen if any contributor is left behind. Details matter. Fortunately, DevOps automation tools are starting to diminish siloed thinking and departments operating as opaque fiefdoms. To make everything work, a level of collaboration between the traditional development and
operation teams needs to have real depth and should become culturally ingrained. These same principles apply whether you are a Silicon Valley tech behemoth or a smallto-medium size independent developer that is taking a more gradual approach to DevOps. In fact, the cultural challenges can often be greater for larger organisations, many of which are hamstrung by both legacy systems and business-as-usual mindsets. In this scenario, implementing DevOps means changing the way individuals and teams work on a day-to-day basis. Abandoning bad habits is never easy but it is a necessary transition. If you are at the start of your DevOps journey, it is vital to get relevant staff on board with the new methodology from the outset. Undertake extensive education initiatives and get all stakeholders to agree on a viable approach. Identify bottlenecks upfront and, crucially, repeat the discussion over time. Before jumping full-blooded into the DevOps realm, it is always prudent to test processes. Pick a few projects that are not mission-critical before scaling the initiative far and wide. Ultimately, any worthwhile DevOps strategy needs to be owned from the top down with credibility and purpose. Otherwise it will not work. A process of constant self-evaluation is non-negotiable. Each project should have its own designated DevOps coach or champion to help drive the process of constant self-evaluation and improvement. Whether your organisation is tentatively stepping into the DevOps space, or is already at an advanced stage firing on all cylinders, it will all end in tears with the wrong culture in place. No amount of technical skill will save a DevOps project if participatory behaviours are inappropriate or misaligned. ĂŤ
A non-stop development pipeline without barriers will not happen if any contributor is left behind.
08
A P R I L 2020
MEA
VIEWPOINT
MANAGING THE INCREASING COSTS OF WORK AT HOME
WORK AT HOME IS NOT WITHOUT A COST AND THE LONGER YOU WORK AT HOME THE MORE ELECTRICITY YOU CONSUME, POINTS OUT TALA SEIF AT SCHNEIDER ELECTRIC GULF.
Smart home technologies provide an integrated energy management system for the home through a smartphone app.
TALA SEIF, CHANNEL ENGINEER INTERIOR DESIGN TEAM, SCHNEIDER ELECTRIC GULF.
When you shut off a device from its charger, the power strip senses it and will shut off all power to the device.
As many of us settle into a routine of working from home, companies have never been better prepared to take advantage of the technology now available to meet these new demands. However, this greater flexibility in how we are working comes with some drawbacks. To stay connected with our colleagues, remote working requires greater usage of electricity and energy, between plugging in our machines, using appliances more often, and the temptation for regular trips to the coffee machine or boiling water for a cup of tea. This means we are using far more energy without realising it, and in turn seeing our electricity bills rise. But there are some simple tips and tricks you can implement into your daily work at home routine that will help you use energy more efficiently and save money on your electricity bills in the process. USE SMART POWER STRIPS These allow you to plug in different devices into outlets to allow for greater energy efficiency. Some outlets are for devices that need to stay on all the time, while others work for items that go into standby mode or use energy, but do not need to be on. When you shut off a device or disconnect your device from its charger, the power strip senses it and will shut off all power to the device. A 2015 study by UL Environment determined that a smart power strip could curb wasted power by 26% in just one night of use.
Set up your temporary office in the room with the most amount of light.
10
A P R I L 2020
MEA
UNPLUG UNNECESSARY DEVICES One of the pitfalls of working from home is all the potential distractions around your home that are tempting you to stray from your work duties. The solution? Simply unplug it so it no longer becomes a distraction. Not only will this ensure you stay focused on the task at hand but devices such as televisions, game consoles or extra monitors will no longer waste energy. ELECTRONICS DURING PEAK LOAD According to the Dubai Electricity and Water Authority, peak electricity usage in Dubai is 12 to 6pm in summer. By limiting the use of nonessential appliances during these peak-load times electricity can be provided more efficiently. This can be done by adjusting the air conditioning to 24C and avoiding the use of power-hungry appliances such as irons, washing machines, dryers and dishwashers during peak hours. CONNECTED HOME TECHNOLOGIES Smart home technologies provide an integrated energy management system for the home through a smartphone app. These solutions allow you to control lighting, shutters and heating as well as manage energy levels to identify where electricity is being wasted and adjust power use for greater efficiency. USE NATURAL LIGHT We are blessed with an abundance of sunlight in the UAE, so why not make the most of it to conserve energy and reduce our energy bills. Set up your temporary office in the room with the most amount of light and throw open the curtains to let in as much as possible. This will mean energy is not wasted to power desk lamps or overhead lights. By making a few simple changes to our behavior and improving our awareness about energy consumption we will not only use electricity more efficiently but also save money on our bills. ĂŤ
VIEWPOINT
MANAGING CHALLENGES OF DATA AND CLOUD COMPLEXITY
ENHANCING AND MANAGING THE AVAILABILITY OF DATA ACROSS MULTI-CLOUD AND HYBRID CLOUD IS THE NEXT FRONTIER, EXPLAINS VEEAM’S DANIEL FRIED.
According to a survey of IT decision makers, three-quarters aim to have adopted cloud data management by the first few months of 2020.
DANIEL FRIED,
GENERAL MANAGER AND SENIOR VICE PRESIDENT, EMEA, VEEAM.
The cloud, as a data management platform, has grown in importance and is growing in complexity.
The trend of businesses turning to hybrid and multi-cloud strategies is accelerating. According to Gartner, hybrid cloud became the standard IT strategy for enterprises in 2019. Furthermore, 81% of respondents to a survey conducted by its analysts said they are already working with two or more providers. The cloud, as a data management platform, has grown in importance and is growing in complexity. Business leaders, however, are looking for simplicity. As the value of data increases, organisations must finely balance the data availability needs of the business against the demands of data protection regulations like GDPR. Doing so requires a digital infrastructure that is both flexible and reliable – as well as easy to manage. Cloud data management refers to the management of data across an organisation’s entire cloud and data management provision. It is about ensuring that data is always available – regardless of whether an organisation is using private, public, hybrid or multi-cloud infrastructure. According to a survey of IT decision makers conducted by Veeam, three-quarters of organisations aim to have adopted cloud data management by the first few months of 2020. This is partly due to a recognition that cloud data management is a key component of delivering a higher level of business intelligence. This is also
Cloud data management refers to the management of data across an organisation’s entire cloud and data management provision.
12
A P R I L 2020
MEA
a fundamental part of an organisation’s derisk strategy. On the other hand, any change which requires people to take on new skills, adapt culturally and view their role differently, brings risk of its own. Changing the way technology infrastructure is managed may take some technical personnel out of their comfort zone. Therefore, cloud data management must be viewed as a strategy rather than a one-sizefits-all approach. Organisations must choose the right partner to help them deliver on this vision in a way which brings maximum value at minimal risk. The value of data has been compared to everything from oil to gold. Whichever of these descriptions you prefer, it cannot be disputed that when harnessed properly data can deliver value to an organisation that only a few years ago would have been unimaginable. Furthermore, many businesses are sitting on a potential goldmine of data, of which the value is 99.9% untapped. However, the idea that businesses who own and control data have all the power is a misconception. Owning the data means nothing if you do not know how to use it. You need to be able to read, analyse and gain insight from data for it to make your business faster and more effective. To do this, data has to be available to the right people at the right times. While the rising value of data puts the onus on businesses to ensure they use it to gain better insights and drive operational efficiencies, it also makes protecting data even more vital. Whether due to lost or stolen data, a ransomware attack or a systems outage resulting in unplanned downtime, businesses cannot afford to take any chances. While becoming more data-driven as an organisation is a priority for business leaders, this is another area in which they must derisk. When it comes to certain types of data, especially personal data or customer records, businesses are merely custodians rather than owners. ë
THE VALUE OF
Partnering with NetApp NetApp is committed to being the data authority in the evolving landscape with our partners. DID YOU KNOW?
42% By the end of 2019, digital transformation spending will reach $1.7 trillion worldwide, a 42% increase from 2017.
Empower Customers - Flash - NetApp HCI - Cloud
NetApp Delivers a Data Fabric Built for the Data-Driven World NetApp Data Fabric simplifies the integration and orchestration of data for applications and analytics in clouds, across clouds, and on-premises to accelerate digital transformation. Cloud connectivity is one of the core tenets of our portfolio, whether it’s cloud connected, or cloud-connected flash, or NetApp® HCI. And the underlying technology for that connectivity is the NetApp Data Fabric. The Data Fabric is what glues together your customers’ on-premises world with hyper-converged partners, whether it’s Amazon Web Services (AWS), Microsoft Azure, or Google Cloud Platform (GCP). We enable customers to choose their hyperscaler and connect to it with Data Fabric.
Accelerate Profitability
Succeed Together
- Customer Touchpoints - Business Opportunities - Optimize Operations
- Distinguish Yourselves - Differentiated Vision - Drive Product/Services
Contact Ingram Micro today to know more about NetApp solutions Tel.: +971 4 369 7111 | Web: ae.ingrammicro.com
SPECIAL NEWS
SentinelOne offers free access to mitigate COVID-19 risks
TOMER WEINGARTEN, CEO AND CO-FOUNDER, SENTINELONE.
SentinelOne, an autonomous cybersecurity platform company, has announced that it is making SentinelOne Core available free of charge, enabling enterprises to secure remote work as the world combats COVID-19. SentinelOne will be available for free beginning March 16 through May 16, 2020, protecting enterprises of all sizes with AI-powered cloud native technology that autonomously identifies and defeats cyberattacks – deployable in seconds. SentinelOne’s cloud-based platform seamlessly scales, making it well suited to protect both businesses and employees rapidly transitioning to a work-from-home environment, whether they are using corporate or personal devices. As part of this free offering, SentinelOne will provide: * SentinelOne Core: AI-powered prevention, detection, and automated response in a single, autonomous lightweight agent; legacy antivirus replacement across Windows, Mac, and Linux operating systems with no connectivity or
network dependency * Deployment services: Remote deployment assistance to ensure rapid installation and customised configuration SentinelOne is offering businesses as many licenses as they need, without limits. This timely offering immediately puts invaluable resources at security professionals’ disposal during a period of significant disruption. Many cybercrime groups are capitalising on COVID-19 concerns to deliver new malware payloads and test new techniques. SentinelOne’s patented ActiveEDR allows security teams to quickly understand the context and root cause behind any potential intrusion and autonomously respond, providing a critical service to cybersecurity professionals trying to navigate a difficult period full of workplace upheaval that can easily result in new vulnerabilities. With the vast majority of the workforce changing its habits, securing the world’s commerce, communications, and creativity has never been more critical.
ESET’s Tony Anscombe on scams exploiting coronavirus fears From malware-laden emails to fake donations, these are some of the most common cons you should watch out for amid the public health crisis, according to Tony Anscombe, Global Security Evangelist and Industry Ambassador at ESET. Scammers, too, have taken notice. Emergencies offer golden opportunities for con artists to launch fraudulent campaigns that feed off, and cash in on, the climate of concern. Against the backdrop of a disease that continues to spread, scammers have wasted no time in playing on people’s fears or evoking feelings of compassion. The scams can take various forms, and the ESET research team has shared a few examples of the despicable tactics seen in use recently. As a major source of information on the outbreak, the World Health Organisation is among the most-impersonated authorities in the ongoing scam campaigns. In the example below, fraudsters pretend to offer important information about the virus in an attempt to get potential victims to click on malicious links. Typically, such links can install malware, steal personal information, or attempt to capture login and password credentials. The WHO is aware that its brand is being used by scammers, so it provides advice on its website on how it communicates, and provides details of
14
A P R I L 2020
MEA
TONY ANSCOMBE, GLOBAL SECURITY EVANGELIST AND INDUSTRY AMBASSADOR AT ESET.
what it will or will not do in official emails. One of the most important points to note reads: Make sure the sender has an email address such as person@who.int. If there is anything other than who.int after the @ symbol, this sender is not from WHO. WHO does not send email from addresses ending in @who.com, @ who.org or @who-safety.org, for example. The organisation also advises to check the URL for any links in emails and that all web content will start with https://www.who.int/ and that no other domain is used. If there’s any doubt, then directly type the address into your browser. Importantly, the WHO has not randomly started to email people who are not subscribed to a service. Consider navigating to the dedicated
WHO site or to the sites of your respective national health care institutions, such as the Center for Disease Control and Prevention in the United States or the National Health Service in the United Kingdom. The real news can also be found on the trusted sources you normally visit to get your daily intake. Links in unsolicited emails do not have unique or breaking news stories. In another example, the phishing website below is attempting to impersonate the Wall Street Journal and is supposedly reporting the latest COVID-19 news. Nevertheless, some visual consistency with WSJ branding is there in a clear attempt to subtly trick the visitor into thinking that this is the Wall Street Journal. The delivery of advertising on the site is generating revenue for the bad actors, even if no personal details are gleaned from the user. In another type of fraud, scammers send spam emails in a bid to dupe the victims into thinking they can order face masks that will keep them safe from the novel coronavirus. What happens instead is that the victims will unwittingly reveal their sensitive personal and financial information to the fraudsters. As you would expect, Google Trends shows that search volumes for terms such as hand sanitizer and face masks and are reaching unprecedented levels. With demand for these products outstripping supply, con artists have been increasingly targeting people who are looking to take protective measures.
SPECIAL NEWS
ServiceNow releases four apps to navigate COVID-19 crisis
Gartner lists actions for CIOs bracing for COVID-19 disruptions
SANDY SHEN, SENIOR RESEARCH DIRECTOR AT GARTNER.
ServiceNow has announced a customer care plan to support its public and private sector customers in managing the COVID 19 pandemic. As part of this effort, the company has announced four new community apps to help its customers, including government agencies and enterprises, manage complex emergency response workflows. These apps are now available for customers to access free of charge through September 30, 2020. Emergency Response Operations app for government agencies Washington State’s Department of Health, a ServiceNow customer, initially created the Emergency Response Operations app on the Now Platform to manage their own response to COVID 19. Working with ServiceNow, the Department of Health is making the app available to all government entities at no charge. ServiceNow has launched a customer care plan to support its customers as they focus on maintaining business operations during the COVID 19 pandemic. This includes a commitment to maintaining virtually 100% uptime for ServiceNow instances; and launching a Now Community forum where customers and partners can interact with other customers, as well as an Apps Suggestions portal, where customers and partners can provide their ideas for COVID 19 related apps or features. In addition to the State of Washington’s Emergency Response Operations app, ServiceNow has developed and introduced three, free of charge community apps to benefit all customers. The additional apps include: Emergency Outreach: during a crisis, this workflow leverages the Now Platform to help companies connect with employees to assess the impact. Employers can reach out by email to provide information and safety measures and request a response to confirm if employees are safe and where they are located. Employers can also leverage the ServiceNow Now Mobile App to send push notifications to employees via mobile to get response. Emergency Self Report: this workflow helps an employee notify their employer that they are self quarantined and when the employee will return to work, and provides workflow support for the employer. Emergency Exposure Management: when a company becomes aware that its employee is diagnosed with an illness, this workflow helps the employer identify other people who might have been exposed based on the employee’s meetings history and job location.
With the spread of the coronavirus, COVID-19, CIOs should focus on three short-term actions to increase their organisations’ resilience against disruptions and prepare for rebound and growth, according to Gartner. Sandy Shen, Senior Research Director at Gartner, observes that with such a dynamic situation like COVID-19, it has the potential to be as disruptive, or more, to an organisation’s continuity of operations as a cyber intrusion or natural disaster. When traditional channels and operations are impacted by the outbreak, the value of digital channels, products and operations becomes immediately obvious. This is a wake-up call to organisations that focus on daily operational needs at the expense of investing in digital business and long-term resilience. #1 SOURCE DIGITAL COLLABORATION TOOLS WITH SECURITY CONTROLS AND NETWORK SUPPORT
In organisations where remote working capabilities have not yet been established, CIOs need to work out interim solutions, including identifying use case requirements such as instant messaging for general communication, file sharing meeting solutions, and access to enterprise applications such as enterprise resource planning and customer relationship management, while reviewing all security arrangements. #2 ENGAGE CUSTOMERS AND PARTNERS THROUGH DIGITAL CHANNELS, AND MAINTAIN SALES ACTIVITIES
Offline face-to-face engagement still plays a big role. Workplace collaboration, video conferencing and livestreaming solutions can serve various customer engagement and selling scenarios. Organisations should also enable customers to use self-service via online, mobile, social, kiosk and interactive voice response channels. #3 ESTABLISH A SINGLE SOURCE OF TRUTH FOR EMPLOYEES
Confusing data from unverified sources, or the sheer lack of data, can lead to ill-informed decisions being made, escalating employee anxiety and making organisations underprepared for returning to normal operations. Such anxiety can be somewhat relieved if organisations can leverage data to support better decision making and communicate progress more efficiently to employees.
AP R I L 2020
MEA
15
SPECIAL NEWS
GCC mobile market’s future uncertain due to COVID-1
BREAKDOWN OF TOP 4 GCC SMARTPHONE BRANDS, Q4 2018–Q4 2019.
Smartphone shipments to the countries of the Gulf Cooperation Council, GCC, increased 6.3% quarter on quarter in Q4 2019 to total 5.15 million units, according to the latest insights from global technology research and consulting firm International Data Corporation, IDC. However, this was not enough to prevent a
small 0.2% QoQ decline in the region’s overall mobile phone market. Smartphones accounted for 78.0% of overall mobile phone shipments in Q4 2019, up from 73.2% in the previous quarter. The extreme decline in feature phone shipments stemmed from the fact that telcos and channel players across the region, particularly in Saudi Arabia and Bahrain, have actively started to move away from offering devices that support the 2G spectrum. In terms of value, smartphone shipments increased 11.2% QoQ to $1.2 billion, while the value of feature phone shipments slumped 20.8% to $28.9 million. The UAE and Saudi Arabia saw smartphone shipments increase 9.9% and 6.7% QoQ, respectively, in Q4 2019. Together, these two countries account for more than 75% of the GCC smartphone market. QoQ, smartphone shipments also grew in Bahrain, 9.6%, Kuwait, 2.1%, and Qatar, 3.0%. Oman was the only GCC market to suffer a decline, with smartphone shipments falling 2.2% over the quarter. Samsung continued to dominate the GCC smartphone market in Q4 2019 with 40.6%-unit share, although this was down 5.1 percentage points on the previous quarter. The contraction in Samsung’s unit share largely stemmed from supply chain shortages. Looking ahead, vendors and channel partners are expected to release new form factors and increasingly push 5G devices to consumers over the coming year. However, the COVID-19 outbreak is likely to dampen mobile phone shipments over the course of the year, with IDC’s initial forecast of growth for the GCC market in 2020 being downgraded to a year-on-year decline of 1.4%.
Kaspersky find coronavirus scams targeted at businesses Kaspersky researchers have found multiple COVID-19-related malicious e-mail campaigns and hundreds of downloadable files that attempt to infect users’ devices with the threats. While news on coronavirus spread continue to appear and dominate the headlines, attackers are also looking for opportunities to use this topic in malicious purposes. This is a very dangerous practice, as it exploits people’s concerns for their health and safety of their beloved ones in attempt to pressure them into falling for a trick. The researchers have detected malicious files that were masked under the guise of pdf, mp4 and docx files about the coronavirus. The names of files imply that they contain video instructions on how to protect yourself from the virus, updates on the threat and even virus detection procedures, which is not actually the case. In fact, these files contained threats to users’ devices. Some malicious files are spread via email. For example, an Excel file distributed via email under the guise of a list of coronavirus victims allegedly sent from the World Health Organisation was in fact a Trojan-Downloader, which secretly downloads and installs another malicious file. This second file was a Trojan-Spy designed to
16
A P R I L 2020
MEA
TATYANA SCHERBAKOVA, SECURITY RESEARCHER AT KASPERSKY.
gather various data, including passwords, from the infected device and send it to the attacker. In the meantime, governments and businesses across the world are increasingly encouraging home working in a bid to slow the spread of COVID-19 coronavirus. It is likely that, where feasible, companies will allow more people than ever before to work remotely, so now is a good time for organisations to re-examine security around remote access to corporate systems. Once devices are taken outside of a company’s network infrastructure and are connected to new networks and WIFI, the risks to corporate
information increase. There are a number of simple steps that can be taken to reduce the cyber-risks associated with coronavirus. If you are an individual, Kaspersky advises the following: l In order to stay safe, we advise users to carefully study the content of the emails they receive and only trust reliable sources. l Use reliable security solution for comprehensive protection from a wide range of threats. l Provide a VPN for staff to connect securely to the corporate network l All corporate devices, including mobiles and laptops, should be protected with appropriate security software. l Allowing data to be wiped from devices that are reported lost or stolen, segregating personal and work data, along with restricting which apps can be installed l Always implement the latest updates to operating systems and apps l Restrict the access rights of people connecting to the corporate network l Ensure that staff are aware of the dangers of responding to unsolicited messages
SPECIAL NEWS
Sophos warns of coronavirus email spam targeting Italians
CHESTER WISNIEWSKI, PRINCIPAL RESEARCH SCIENTIST, SOPHOS.
SophosLabs has uncovered a new email spam attack targeting Italians with a document containing a macro loaded with Trickbot malware. The email takes advantage of COVID-19 fears by offering up a clickable document that allegedly includes a list of precautions to take to prevent infection. Unfortunately, the document is weaponised. According to SophosLabs, the COVID-19 twist to the spam message may be new, but the mechanisms used to deliver it, including the spam bots that send the message, the enclosed scripted Word document and the JavaScript dropper, are similar or identical to those used in Trickbot campaigns that have been active for at least six months. In order to stay cybersafe: l Never let yourself feel pressured into clicking a link in an email. l If you are genuinely seeking advice about the coronavirus, do your own research and make your own choice about where to look l Do not be taken in by the sender’s name. This scam says it’s from World Health Organisation. l Look out for spelling and grammatical errors. Not all crooks make mistakes, but many do. l Check the URL before you type it in or click a link. If the website you are being sent to does not look right, stay clear. l Do your own research and make your own choice about where to look l Never enter data that a website should not be asking for. l There is no reason for a health awareness web page to ask for your email address. l If you realise you just revealed your password to imposters, change it as soon as you can. l Never use the same password on more than one site. Once crooks have a password, they will usually try it on every website where you might have an account. l Turn on two-factor authentication if you can. l Six-digit codes that you receive on your phone are a minor inconvenience to you, but are usually a huge barrier for crooks.
Citrix offers workspace solutions for business continuity Natural disasters and public health emergencies can strike anywhere at any time. And when they do, organisations need to be prepared to protect their people and minimise disruptions to their business and the larger economy. Armed with digital workspace solutions from Citrix Systems, many are creating flexible work environments that provide access to the tools and information employees need to work safely and securely in the face of unforeseen circumstances. Coronavirus is clearly taking a toll on the global economy. Productivity is lagging as companies restrict travel and workers in affected areas remain quarantined. Supply chains are being disrupted as manufacturing in key markets has ground to a halt. And corporate forecasts are being revised downward as a result. But this is not the only crisis businesses today face. The talent crunch continues to wreak havoc as well. Korn Ferry recently forecast that by 2030, there will be a shortage of 85.2 million workers globally, and that it will result in lost revenue opportunities of $8.452 trillion. That’s a serious problem. But with digital workspaces, companies can overcome it too. They can, for instance, dip into untapped pools of talent such as the home force and bring back parents who’ve put their careers on hold to care for children, or people who left jobs to tend to ageing relatives. They can set up Baby Boomers who retired, but still want to work a few hours a week. And they might even entice part-time, contract and gig workers to take on more hours and fill the roles they need to advance their objectives. Citrix provides a complete range of digital workspace solutions that unify everything an employee needs to be productive into a seamless, intuitive experience. With Citrix, companies can empower people to work in a flexible, secure and intelligent way that unlocks their creativity and innovation and enables them to deliver better business results.
DAVID HENSHALL, PRESIDENT AND CEO, CITRIX.
AP R I L 2020
MEA
17
CHANNEL NEWS
R&M TEAM AT THE NEW DUBAI HQ.
R&M opens new regional HQ and production facility in Dubai Following strong regional performance in 2019 and in anticipation of continued business momentum in the Middle East, fuelled by growing connectivity requirements, mega projects and
events, R&M has announced the inauguration of a new regional head-quarters in Dubai. The company also announced its expansion into a new supply chain facility, a move which
Infoblox announces new integration, partnership with Nutanix Infoblox and Nutanix announced that Infoblox Core DDI and Cloud Platform appliance products, which are part of the Nutanix Elevate Programme, have been certified as Nutanix Ready. Infoblox will support its customers with the integration of Nutanix and Infoblox NIOS DNS, DHCP, IPAM DDI solutions, including NIOS virtual appliances running on Nutanix AHV and Nutanix Calm support for orchestrated DNS IPAM workflow. NIOS is now the only DAVE SIGNORI, DDI solution that runs on and supports SENIOR DIRECTOR, PRODUCT MANAGEMENT AT INFOBLOX. automated workload orchestration on Nutanix Enterprise Cloud. The NIOS integration with Nutanix will automate the steps of IP address allocation and DNS updates during spin up and spin down of virtual machines, addressing problems caused by lengthy, manual workload provisioning and will further simplify infrastructure management by running completely in the Nutanix environment. According to IDC, DDI platforms are essential components to building a modern datacentre that relies heavily on automation and programmability. Cloud computing platforms have created a new paradigm for hosting and accessing applications, and they have also driven IT organisations to modernise their internal datacentre operations to provide a cloudlike agility on their own premises. Infoblox sees continued, steady growth in the DDI market as enterprises continue to automate DDI and the number of IP addresses in enterprise networks continues to rise. With this partnership, Infoblox can continue to deliver a safe and secure next-level networking experience to these enterprises.
strategically consolidates its production and warehousing hubs and positions them closer to key facilities including Al Maktoum International Airport, Jebel Ali Port and the site of Expo 2020. R&M has increased its employee strength by over 200% since it first entered the region in 1998. The company has also doubled the production hours at its existing solution assembly facility in the Dubai Airport Free Zone, which was established in 2012. With closer proximity to Dubai’s key air and sea ports, the overall efficiency of R&M’s supply chain is set to be greatly improved by shortened customs clearance times, and a reduction in materials handling processes. The new production facility will make it possible for R&M to rapid deliver highly customised cabling solutions for regional markets.
Mindware to market Microsoft’s OEM products across the GCC
DAVE SIGNORI, SENIOR DIRECTOR, PRODUCT MANAGEMENT AT INFOBLOX.
Mindware, a Value-Added Distributor, in the Middle East and Africa, has announced that it has signed a new agreement with Microsoft. Under the partnership, Mindware will market Microsoft’s Original Equipment Manufacturer products, which includes Microsoft Windows 10, Windows Server 2019 and Microsoft Office 2019, across the GCC. Mindware currently manages volume and value licensing for the Microsoft suite of cloud solutions. The new agreement extends upon this existing partnership. For the new OEM products, Mindware will look to target small and medium businesses as well as individual consumers through its reseller network. Microsoft and Mindware will work jointly in promoting these OEM products. These will include roadshows, digital campaigns, traditional advertising and other business-relevant marketing activities. Mindware will provide support to its channel partners by way of credit facilities and ongoing technical support.
AP R I L 2020
MEA
19
CHANNEL NEWS
SecureLink to distribute Cloud Range cybersecurity products
REGHU MOHANDAS, DIRECTOR, RISK ADVISORY AND ANALYTICS, SECURELINK.
SecureLink, a risk advisory firm based in Dubai, has announced a distribution agreement with Cloud Range, a global provider of cyber ranges and simulation-based virtual cyber defence training. Cloud Range provides Security Operations Centre analysts and incident response teams the opportunity to regularly practice detection, response and remediation of cyber-attacks. Regular simulated trainings give SOC’s the ability and confidence to detect and defend against the most advanced malicious cyber-attacks before they occur. Cloud Range simulates cyber-attacks in a hyper-realistic environment where teams use industry-leading security tools combined with live simulated cyberattacks to ensure they are prepared for potential threats. Utilising Cloud
Huawei BG announces new partner development strategy Ramping up its global technology ecosystem, Huawei’s Enterprise Business Group, BG, recently announced a new partner development strategy named Profitability, Simplicity, Enablement, and Ecosystem under which it will cooperate with global partners in supporting digital transformation programmes. By the end of 2019, Huawei
20
A P R I L 2020
MEA
had more than 22,000 Sales Partners, 1200 Solution Partners, 4200 Service Partners, 1000 Talent Alliance Partners, and 80 Investment and Operation and Financing partners. In terms of partner profitability, in 2020 Huawei Enterprise BG will maintain the channel partner incentive framework’s stability,
Range’s next generation cyber range, companies can now provide SOC operations and incident response teams with customised, hands-on simulation training in a controlled and secure environment. Simulation training allows security professionals to hone technical skills, problem solving, and critical thinking capabilities. These skills are crucial in various scenarios that are custom-built to reflect attacks that teams have faced or will potentially face in the future. Attack scenarios are regularly updated and added to reflect the latest threat landscape. The distribution agreement now allows SecureLink partners the ability to provide next generation cyber security innovative services directly to their customers.
and expand the scope of partner incentivised products to include standalone software as well. Diversified special incentives, such as capability rebates and Business Incentive Programme will be introduced to motivate partners to pursue more ambitious goals. Driving greater simplicity, Huawei Enterprise BG will release a list of products that partners can get rebated to improve policy transparency, and make incentive eligibility clearer. It will allow partners to independently apply for and accept Marketing Development Fund to accelerate the execution of marketing activities, and make Huawei Enterprise BG’s entire business process visible to partners. For enablement, Huawei will launch Huawei Certified Pre-sales Professional certification for IP and storage products to help partners gain in-depth knowledge about relevant products and acquire practical skills. Huawei Enterprise BG has also extended the availability of Marketing Development Fund and Joint Marketing Fund to support global partners, solution partners, and carrier partners in their business development. Hank Stokbroekx, Vice President of Enterprise Service at Huawei Enterprise BG, also announced the Huawei ICT Academy Programme 2.0 to develop two million ICT professionals and popularise digital skills over the next five years by collaborating with universities. This is part of Huawei’s digital inclusion initiative, TECH4ALL. Huawei will set up the Huawei ICT Academy Development Incentive Fund, with a total investment of at least $50 million over the next five years.
CHANNEL NEWS
MANSOUR ALTHANI, CEO AND CO-FOUNDER OF ITCAN.
ITCAN says it is close to earning AED 100 million this year
Startup company ITCAN, a full-service technology and digital marketing company that brings insights, information, and expertise to
create exponential growth, has announced that it is close to earning AED 100 million this year since its launch in Dubai. The milestone is about to be reached against the backdrop of growing e-commerce activities in the UAE and Saudi Arabia as noted by a recent report by the World Economic Forum. According to the firm, its expansion is expected this 2020 in terms of earning potential, market reach, and new offerings amid the continuously rising popularity of e-commerce and increasing support for start-ups from both the government and private sectors across the region. ITCAN, which was founded by young Saudi entrepreneurs, is behind the growth of many e-commerce companies in the MENA region through its portfolio of services. The company has expanded since its launch in 2015 to enter new markets outside the UAE, with
special focus on the Saudi market, while at the same time broadening its offered digital services to its client base along the way. Its Saudi Arabia and Egypt offices formally opened their doors in 2016, followed by its branch in India in 2019. Initially, the start-up firm offered performance and digital marketing services before launching its technology development service in 2016. Through its expertise, two e-commerce giants in 2017 made great headway in their digital initiatives. In 2018, ITCAN’s teams across its offices grew significantly with 60 marketers and developers joining its organisation. By then, the company had established its leadership in scaling and growing businesses in the local market. ITCAN also made history in 2015 as the first company to utilise influencers within the affiliate marketing landscape.
Insight Partners completes Veeam acquisition at $5B valuation
Huawei and Saudi Arabia’s STC offer enterprise solutions
Veeam Software has announced that Insight Partners has completed its acquisition of the company, which was announced on January 9, 2020, at a valuation of approximately $5 billion. Following an investment from Insight Partners at the beginning of 2019, the acquisition of Veeam, the clear market leader with over $1 billion in annual sales and more than 365,000 customers worldwide, will drive accelerated growth in the US market. WILLIAM H LARGENT, In addition to enabling Veeam to CEO AT VEEAM accelerate its Act II, the company will move the company’s headquarters to the US from Switzerland and add strength and experience to its executive team. As part of the acquisition, the following appointments have been made: l William H. Largent has been promoted to Chief Executive Officer. He previously held the role of Executive Vice President, Operations. l Danny Allan has been promoted to Chief Technology Officer. l Gil Vega, previously Managing Director and CISO at CME Group, and the Associate Chief Information Officer and CISO for the US Department of Energy and US Immigration and Customs Enforcement in Washington, DC, has been appointed Chief Information Security Officer. l Nick Ayers, of Ayers Neugebauer and Company, a member of the World Economic Forum’s Young Global Leaders and former Chief of Staff to the Vice President of the United States, joins Insight Partners Managing Directors Mike Triplett, Ryan Hinkle, and Ross Devor on the Veeam Board of Directors.
STC has announced that Solutions by STC has developed a new partnership with Huawei to enrich its ICT products and solutions offered to enterprise customers within Saudi Arabia. The MoU was signed between by Omar Alnomany, CEO of Solutions and Dennis Zhang, CEO of Huawei Tech Investment Saudi Arabia in Riyadh. This agreement sets a milestone for deeper collaboration between Huawei and Solutions by STC. Both parties will leverage their expertise to jointly build the latest innovated solution delivery across Saudi Arabia. Both parties are confident this will create win-win business models, unlock opportunities, and achieve higher profit on the three strategic industries Oil and gas, Healthcare and SME.
AP R I L 2020
MEA
21
CHANNEL NEWS
SEIDOR AND BASF EXECUTIVES AT PARTNERSHIP LUNCHEON.
BASF partners with Seidor on business transformation project Seidor has announced that it has joined forces with BASF to support the global chemicals producer in a sweeping corporate-restructuring project in their construction chemicals business unit. Having decided to operate the division as a standalone entity, BASF needed to separate the unit’s technology systems to prepare it to run independently. For the past 12 years, BASF has been running SAP R3 COBALT but since SAP announced that support for R3 will not extend
beyond 2025, BASF decided that its restructuring project should also involve migration to a futureproof system. The project will extend to 22 countries, across Asia Pacific, the Middle East and South America, and affect some 280 users. Given the tight timeline to complete the implementation, and the need for optimal efficiency, BASF’s stakeholders identified Seidor, and specifically Dubai based entity, Seidor MENA, as the partner. Seidor MENA began by helping BASF to clas-
Rackspace expands to the Middle East, launches hub in Dubai
Rackspace is investing heavily across Europe, Middle East and Africa in 2020 as part of its overall strategy to be the best technology services company in the world. As part of this ambition, it has announced its expansion into the Middle East to enhance the support of local customers. The expansion is endorsed by a RACKSPACE EMEA LEADERSHIP multi-million-dollar investment and TEAM. includes the launch of a hub based in Dubai, UAE, which will employ a robust salesforce, professional services consultants and marketing support. The focus on recruitment will support the cloud skills gap locally, further enhancing the customer experience delivered in the region. The move responds to both Rackspace’s established success in the Middle East as it currently has over 500 customers in the region, as well as the market growth and maturity of cloud technology. The strategy will be led by George Pawlyszyn who has been appointed as General Manager, Middle East and Africa at Rackspace. He will be focussed on providing trusted and unbiased expertise to migrate customers to the cloud securely and enhance existing customers’ environment whilst working closely with partners, including Amazon Web Services, Google Cloud Platform and Microsoft Azure. George has over 30 years’ experience in management and business development and joins from IBM where he was Business Development Executive, MEA Leader, responsible for driving large scale and long-term strategic services.
22
A P R I L 2020
MEA
sify countries by the size of operations. As an SAP partner, Seidor MENA was then able to advise BASF’s IT team on the best business application fit for the company’s transformation needs, as well as the best implementation approach to ensure a smooth transition from the legacy R3 system. BASF opted to deploy a mixture of SAP S4 HANA and SAP Business One ERP running on Amazon Web Services. Seidor MENA will manage the entire implementation, from its Dubai offices. The implementation started last month and will take place in phased rollouts throughout the year. BASF’s project team will work from a Seidor MENA-crafted global template for the consolidation of business processes. As lessons are learned from initial rollouts, Seidor MENA will continue updating this template over a three-year period, based on business needs. Seidor MENA will also engage heavily with end users in the pilot countries to ensure successful implementations and boost users’ confidence in the new solution. Over the next three years, BASF will continue relying on Seidor MENA to enhance and support the ERP deployment.
Mindware to distribute ESET biz products in Saudi Arabia
FADI MATTA, GENERAL MANAGER AT MINDWARE SAUDI ARABIA.
Mindware, a Value-Added Distributor, in Middle East and Africa, has announced that it has signed a distribution agreement with ESET, an information security software provider. As per the agreement, Mindware will offer the entire suite of ESET business products, including twofactor authentication, endpoint protection, endpoint encryption, endpoint detection and response among others. The distributor will target enterprise customers, small and medium businesses and government organisations in Saudi Arabia through its expansive channel network. As part of the ramping up process, ESET will conduct sales and presales workshops and provide training and certification to Mindware’s designated engineers. Mindware on the other hand will focus on driving ESET’s business by reaching out to existing partners as well as onboarding new partners. The distributor will provide knowledge transfer to partners through regular technical enablement sessions. It will also assist partners with potential business leads by helping them conduct proof-of-concepts. Mindware and ESET will jointly conduct marketing activities that include events, promotions, traditional and digital advertising campaigns and much more.
CLOUD NEWS
Avaya Spaces cloud app granted TRA approval in the UAE
Avaya has commended the approach to publicprivate partnerships being taken by the UAE’s Telecommunications Regulatory Authority, following the confirmation that the cloudbased Avaya Spaces collaboration app has been
approved for use in the country. Avaya Spaces provides a cloud meeting and team collaboration solution that enables people and organisations to connect and collaborate remotely, and goes beyond integrating chat, voice,
video, online meetings and content sharing. It gives users an extensive set of meeting and team collaboration features, including voice and video conferencing for up to 200 participants. Avaya Spaces was approved by the Telecommunications Regulatory Authority, which will not direct local operators to block the app during a time of increased demand for applications that enable telemedicine, working from home, and distance learning. Earlier this month, Avaya announced that it will provide its Avaya Spaces collaboration software for free to education institutions, including colleges and universities, along with qualified non-profit organisations worldwide. Avaya Spaces is recognised for its ease of implementation and the significant impact it can have on organisational resilience and continuity. Since January, Avaya has seen a 200% increase in video collaboration traffic on this platform.
DEWA migrates on-premise SAP landscape to Moro Hub
HE SAEED MOHAMMED AL TAYER, MD AND CEO OF DEWA.
Dubai Electricity and Water Authority, DEWA, has migrated its on-premise SAP landscape to Data Hub Integrated Solutions, Moro, to realise innovation, cost efficiency, scalability, speed, and resiliency. This is one of the world’s largest migrations for SAP HEC in the utilities sector. It is also one of the largest data migrations across all industries at the EMEA level. The project consists of two parts: the migration of on-premise landscape to SAP HEC and the managed services by Moro Hub. DEWA collaborated with Moro Hub and several international IT vendors including SAP, EY and Virtustream to complete the project. DEWA’s SAP landscape consists of 24 SAP modules including business-critical systems like Business Suite on Hana, CRM, SRM, PO, Business Intelligence, Fiori and complex integration along with external entities and thirdparty systems. The move is one of the largest of its kind globally. Nearly 250,000 man-hours were spent, with more than 150 specialists from DEWA, Moro Hub, EY, SAP and Virtustream working on the project. The project transferred over 100 terabytes of data from 101 systems and tested more than 28,370 business transactions. This migration aims to offer better business support to all DEWA stakeholders; as Moro Hub manages all its information technology operations, IT support, data management, monitoring operational efficiency, maintaining the highest security standards and state-of-the-art technologies in data centres as well as providing support around the clock. Moro Hub is the leader in offering data centre and cloud services along with digital services for the public and private sectors in the UAE and the region. It also provides integrated data centre solutions to utilise the latest disruptive technologies and keep pace with the Fourth Industrial Revolution, to deliver secure, reliable cloud solutions to support innovation in AI, IoT, blockchain, and machine learning.
AP R I L 2020
MEA
23
CLOUD NEWS
Extreme Networks showcases cloud networking technologies
Pure Storage expands cloud-native collaboration with Anthos Ready
MAAN AL-SHAKARCHI, REGIONAL DIRECTOR FOR MIDDLE EAST, TURKEY, AND AFRICA, EXTREME NETWORKS.
Extreme Networks has kicked-off its inaugural Extreme Cloud NOW roadshow in the Middle East, with the first event held in Dubai. The debut event focused on helping end-customers and channel partners unlock the potential of cloud technologies by giving attendees direct access to Extreme’s new product innovations, solution demos, top EMEA and META executives, and its sales strategy. As one of the key areas of digital transformation investment in the Middle East, the roadshow event was firmly focused on discussing the potential of cloud technologies. IDC predicts that regional businesses will spend upwards of $2.7 billion on the cloud this year. However, for these cloud investments to drive positive business outcomes, organisations need to ensure their networks are ready for such a fundamental technological shift. Through a series of presentations by Extreme’s top systems engineers, attendees were given insights into how the vendor’s solutions, such as ExtremeCloud IQ, leverage machine learning and artificial intelligence to provide enterprises with insights, as well as complete visibility, control, and automation of their entire network. Having recently launched its new Extreme Retail Select platform, the company also showcased this powerful solution, demonstrating its ability to remove the cost and complexity associated with selecting, buying, building, deploying, and managing network services at retail locations. The live demos highlighted how the solution enables customers to automate new store setups, maximise operational efficiencies, and deliver consistent services and experiences at scale. With a large number of channel partners in attendance, Extreme used the inaugural ExtremeCloud NOW event as an opportunity to highlight its commitment to its partners and outline its channel strategy for the year ahead. This includes a move away from a centralised global channel approach, towards a more local, personal, and direct approach via the regional channel managers. Furthermore, Extreme’s META channel strategy is built around incentivising partners to integrate cloud-based solutions into their portfolio. The company emphasised its belief that managed services offer channel partners the greatest potential for growth and expressed its intention to launch its Managed Services Program in the region later this year. The next leg of the ExtremeCloud NOW roadshow will take place in Saudi Arabia with the company set to soon announce details of the event in Riyadh.
24
A P R I L 2020
MEA
ROB WALTERS, GENERAL MANAGER OF STORAGE-AS-A-SERVICE, PURE STORAGE.
Pure Storage has joined Google Cloud’s Anthos Ready Storage Initiative, having demonstrated that its solutions for data storage and data can be confidently deployed on the Anthos platform across hybrid environments. This news expands on Pure’s partnership with Google Cloud to help customers modernise existing applications and build new ones on a simple, scalable and reliable platform. With seamless integrations between Google Cloud’s open platform and Pure’s all-flash storage, organisations can now invest confidently in custom-engineered solutions built specifically to drive multi-cloud strategy and enable a modern data experience. Anthos is an open hybrid and multi-cloud application platform that provides consistent development and operations experience across cloud and on-premises environments. As a qualified Anthos partner, Pure’s Container Storage Interface driver-based solution will allow customers to seamlessly deliver storage as-a-service to their containerised applications on the Google Anthos on-premises platform. With Pure Service Orchestrator from Pure Storage, mutual customers can now extend the simplicity, scalability and reliability of the Google Anthos platform all the way down to the storage layer. Anthos Ready Storage designates partner solutions qualified by Google Cloud to meet the requirements defined for applicable solution categories. The Anthos Ready Storage Initiative is reserved for companies optimised to work with Google Cloud’s Anthos by fulfilling the requirements for the applicable solution category, and are invited by Google Cloud to participate in the Anthos Ready Partner Initiative. The primary computing environment for Anthos relies on Google Kubernetes Engine, which allows customers to take advantage of Kubernetes and cloud technology both in their data centres and in the cloud. Pure Service Orchestrator integrates with container orchestration frameworks like Kubernetes, so customers can deliver persistent storage support for containerised applications, on-demand. Pure Service Orchestrator pools multiple FlashArray and FlashBlade systems supporting block-based and file-based storage arrays under one CSI driver deployment, to allow intelligent volume placement across that pool.
CLOUD NEWS
VMware expands telco cloud portfolio with new offerings VMware has showcased how communications service providers across the world, including Millicom, Singtel, Telecom Italia, Telia Company and TIM Brazil, are adopting VMware’s Telco Cloud platform to accelerate time to revenue, automate service lifecycle, and simplify operations management. The company also unveiled new capabilities across its Telco and Edge Cloud product portfolio, including innovations to its telco cloud core, edge and RAN offerings. VMware’s Network Functions Virtualisation platform is relied upon by more than 100 operators to deliver their telecom services to 800 million subscribers globally. Today, several customers highlighted why they chose VMware’s Telco Cloud platform as the foundation for their digital transformation. VMware Telco Cloud Automation, previously announced at VMworld 2019 Europe as Project Maestro, is a software solution for telco cloud orchestration and automation.
SHEKAR AYYAR, EXECUTIVE VICE PRESIDENT AND GENERAL MANAGER, TELCO AND EDGE CLOUD, VMWARE.ST.
Nutanix finds upswing in financial organizations adopting hybrid cloud Nutanix has announced the financial services industry findings of its second Enterprise Cloud Index Report, measuring financial firms’ plans for adopting private, public and hybrid clouds. The report found the financial sector outpaces all other industries in hybrid cloud deployments, hosting workloads in both private and public cloud, but trail others in their use of multiple public cloud services. Most financial services companies must adhere to strict regulatory requirements and government mandates. Not surprisingly, 60% of respondents called out security as the single biggest influence on future cloud strategies. Additionally, because so many organisations struggle to migrate workloads between environments, financial services companies have the highest percentage of traditional data centres, 59%, delivering key applications. Yet, in the face of digital transformation, the sector faces mounting pressure to modernise IT and to make services more convenient for end-users. Together, this explains why nearly 18% of financial companies have deployed hybrid cloud today, while 51% plan to shift investment to hybrid cloud in just three to five years. Additional findings of this year’s report include: FLEXIBILITY TO MOVE APPLICATIONS AS NEEDED IS CRITICAL
Nearly three-quarters of financial companies
surveyed, 71%, shared their plans to move one or more applications running in a public cloud back on-premises. In the financial services industry, regulatory requirements are constantly evolving, meaning companies must keep pace with changing regulations that govern where these companies can store and manage their data. Respondents also ranked hybrid cloud as the most secure IT operating model, 27% of the time, signalling the importance of flexibility, alongside security, in this ever-changing environment. FUTURE OF WORK AND DIGITAL TRANSFORMATION PLAYS A ROLE IN FINANCIAL SECTORS’ DECISIONS
Financial services selected support for remote, branch office users, as a motivator for cloud decisions nearly 30% of the time, a significantly higher percentage than cross-industry averages, pointing to the increasingly remote workplace landscape and the role of digital transformation in customer experience. In the short term, respondents listed lack of adoption stemming from concerns around nascent tools for managing hybrid environments, 66%, a lack of hybrid cloud skills, 30%, and a lack of cloud-native development skills, 23%. SECURITY IS PARAMOUNT FOR COMPLIANCE AND REGULATION
Data showed that financial companies are running the highest percentage of data centres
GREG SMITH, VP OF PRODUCT MARKETING, NUTANIX.
today, with just over 59% of financial companies. Accounting in part for this trend is dissatisfaction with public cloud, with only 39% of financial services companies reporting public cloud services were completely meeting their expectations.
AP R I L 2020
MEA
25
SECURITY NEWS
Secureworks finds ransomware more than doubled in 2019
GOPAN SIVASANKARAN, SENIOR MANAGER, SOLUTIONING, MIDDLE EAST, TURKEY AND AFRICA, SECUREWORKS.
Post-intrusion ransomware continues to be a major threat and spiked in September and October 2019, continuing a trend that had been observed throughout the year, according to a report from Secureworks Counter Threat Unit research team.
Secureworks incident response engagements involving post-intrusion ransomware more than doubled between 2018 and 2019, according to the company’s recent Threat Intelligence Executive Report 2019. There has also been an increase in the number of groups operating these schemes, and many have mature playbooks that have proven successful. CTU researchers expect the post-intrusion ransomware threat to increase due to its profitability. Organisations can greatly reduce the risk by preventing the initial intrusion. If organisations identify an intrusion, it is important to thoroughly remove all malware and possible access vectors during remediation. Threat groups primarily use two techniques to establish a foothold. The first method is to leverage existing commodity malware infections. For example, the Ryuk ransomware uses TrickBot infections, and BitPaymer uses Dridex infections. The initial malware is usually delivered by large-scale spam campaigns. The infection can exist for an extended time before the ransomware
is deployed. The second method for initial infection involves scanning for and compromising vulnerable Internet-facing servers. Threat groups typically use the Remote Desktop Protocol to access the Internet-facing portion of the victim’s network. They then compromise a system by exploiting a known vulnerability. The compromised system can be used as a foothold to access the rest of the network. As the number of sophisticated attacks increases and threat actors demonstrate greater adaptability, it is important to remember that most cybersecurity incidents leverage wellknown malware and tools CTU researchers recommend that organisations continuously review their defensive posture against these known threats to implement basic security controls on all systems. For example, using multi-factor authentication on Internet-facing systems could mitigate many attacks. Organisations should also maintain awareness of geopolitical events that could increase risk from advanced threat groups.
Esharah to power secure communications for Expo 2020 UAE firm Esharah Etisalat Security Solutions will help ensure the safety of millions of Expo 2020 visitors and participants as provider of secure communications for volunteers, security staff and first responders. The systems integrator and state-of-theart smart solutions firm has been named Official Secure Systems Provider for Expo 2020 Dubai, and will provide a secure, encrypted mobile telecommunications network for all handheld communications devices used at The World’s Greatest Show. The group, a subsidiary of UAE-based Professional Communication Corporation, Nedaa, is the security network provider for the Government of Dubai, offering its services across a wide range of industry verticals that includes public transport, law enforcement, customs, ports and security, and aviation. With more than 200 participants and millions of visitors, Expo 2020 Dubai will serve as a platform for international collaboration, innovation and meaningful partnerships that help create a better future for all. It will run for six months from 20 October 2020.
26
A P R I L 2020
MEA
SECURITY NEWS
F5 Labs finds rise in DDoS attacks against service providers
Distributed denial-of-service, DDoS, attacks on service providers are significantly on the rise, according to new research from F5 Labs. An analysis of global customer security incident data from the past three years, both mobile and landline, also found that brute force attacks, though still prevalent, are on the wane. Other prominent observed threats include compromised devices and web injection attacks. DDoS attacks were by far the biggest threat to service providers between 2017 and 2019, accounting for 49% of all reported incidents during this period. There was a big jump in 2019, with attacks rising to 77% of all incidents, up from just 25% in 2017. Denial of service attacks in the service provider space tend to be customer-facing or focused on applications that allow users to, for example, view bills or monitor usage. Most attacks were sourced from within the service provider’s subscription base. Many of these, particularly in the case of DNS-related incidents, will leverage service provider resources to attack others. F5 Labs found that most reported incidents focused on DNS DDoS such as reflection and water torture attacks. Reflection attacks use service provider-hosted resources such as DNS and NTP to reflect spoofed traffic so that responses from the leveraged service end up going to the target, not to the initiator. DNS Water Torture is a form of reflection attack that uses intentionally incorrect queries to generate increased load on the target’s DNS servers. However, requests still go through the service provider’s local DNS servers, generating increased load strains, and occasionally rise to the level of Denial of Service. The first indication of attack is usually an increase in network traffic discovered by a service provider’s operations team. Other red flags include customer complaints, such as slow network service or non-responsive DNS servers. Brute force attacks, which involve trying massive numbers of usernames and passwords against an authentication endpoint were the second most reported incident. Attackers often use credentials obtained from other breaches, which are then used to target services via a tactic known as credential stuffing. Other forms of brute force attacks simply use common lists of default credential pairs commonly used passwords, or randomly generated password strings.
GCC suffered more than 5.5 million malware attacks in 2019
DR MOATAZ BIN ALI, VICE PRESIDENT, TREND MICRO, MIDDLE EAST AND NORTH AFRICA.
Trend Micro has released its 2019 security roundup report. Ransomware continued to be a mainstay cyber threat last year. Overall, Trend Micro discovered a 10% increase in ransomware detections, despite a 57% decrease in the number of new ransomware families. The healthcare sector remained the most targeted industry, with more than 700 providers affected in 2019. In the GCC, malware attacks were one of the biggest cyber threats. Trend Micro detected a total of 5,544,299 malware attacks in GCC, making the region the fifth most-hit by malware in Asia, and 14th in the world. Top GCC countries that endured the most attacks were Saudi Arabia, 2,352,570, and the UAE, 1,980,718. GCC was also home to 9,047 banking malware attacks in 2019, coming in eighth in Asia and ninth in the world for such attacks. In 2019, Trend Micro’s Zero Day Initiative disclosed 171% more high severity vulnerabilities than in 2018. The criticality score reflects the likelihood of these flaws being leveraged by attackers, so high severity bugs are more likely to be weaponised and the patches should be prioritised. To protect against today’s threat landscape, Trend Micro recommends a connected threat defence across gateways, networks, servers, and endpoints.
AP R I L 2020
MEA
27
SECURITY NEWS
CyberKnight focuses on zero trust security at e-crime meet
During the 12th annual e-Crime and Cybersecurity Congress in Dubai, CyberKnight showcased its ZTX Framework, originally developed by Forrester, while participating along with six strategic cybersecurity vendors. CyberKnight’s focus on Zero Trust Security supports enterprise and government organisations in the Middle East attain a state of security resilience by simplifying incident response while achieving compliance. According to a recent forecast by Gartner Middle East and North Africa enterprise information security and risk management spending will total $1.7 billion in 2020, an increase of 10.7% from 2019. An ever-evolving threat landscape and the advent of digital transformation is forcing security and risk leaders in the region to re-evaluate their spending priorities. THE TECHNOLOGIES THAT WERE REPRESENTED BY CYBERKNIGHT AT THE EVENT INCLUDED:
Deep and Dark Web Threat Intelligence, Flashpoint Remote Browser Threat Isolation, Cyberinc l Data Access Governance and Active Directory Security, Stealthbits l Security Training, Awareness and Anti-Phishing Platform, PhishRod l Mobile Threat Defence and Mobile App Security, Zimperium l Data Centric Security, Digital Rights Management and Data Classification, Seclore l l
CYBERKNIGHT AT THE 12TH ANNUAL E-CRIME AND CYBERSECURITY CONGRESS IN DUBAI.S.
Kaspersky find coronavirus scams targeted at businesses A new Kaspersky report, titled, With superpower comes super responsibility: benefits and challenges of IoT in business, has revealed that the use of Internet of Things business platforms is growing year-on-year in almost all industries. In 2019, nearly two-thirds, 75%, of companies in the UAE implemented IoT applications. The technology is benefiting UAE businesses with savings, new income streams and increased production efficiency, but the fact that 48% of all organisations experience cybersecurity incidents targeting connected devices also reveals the need to carefully protect IoT. Kaspersky’s report shows that the use of IoT platforms has increased in almost all industries globally, with the most significant growth in hospitality, from 53% in 2018 to 63% in 2019, healthcare from 56% to 66%, and finance from 60% to 68%. As of 2019, the IT and telecom, 71%, and finance, 68%, industries have embraced IoT more than all other verticals. IoT platforms are used in many different use cases including smart cities, grids, metering, transportation and logistics, as well as automated manufacturing and connected heating, venting and air conditioning. The growth of IoT use has not been discour-
28
A P R I L 2020
MEA
aged despite potential cybersecurity risks and incidents. As Kaspersky’s survey shows, 48% of companies in the UAE stated that they experienced incidents involving non-computing connected devices last year. These incidents can be critical as sensors and smart devices collect
terabytes of data, including sensitive information such as business data or customers’ personal information. Also, IoT platforms can be connected with critical systems, like traffic, power or transportation processes, so it is vital to ensure their continuity and integrity.
SECURITY NEWS
Centrify poll says employees are the largest threat to security
Fortinet announces findings of the latest Global Threat Report
DEREK MANKY, CHIEF, SECURITY INSIGHTS AND GLOBAL THREAT ALLIANCES, FORTIGUARD LABS.
TORSTEN GEORGE, CYBERSECURITY EVANGELIST AT CENTRIFY.
Centrify has revealed the results of an onsite poll conducted at RSA Conference 2020, held last week in San Francisco. The survey asked conference attendees about their cyber hygiene habits at work to determine how much of a threat they posed to their organisation’s overall cybersecurity, ultimately revealing that employees themselves pose the largest threat. Nearly 60% of respondents correctly identified employees as the largest threat to their organisation’s security, followed by hackers, 23%, and third-party vendors and partners, 18%. Additional poll findings further validated why employees pose a cybersecurity threat in the first place: l 40% of respondents have tried to bypass a corporate security policy at work l Nearly 1 in 4 respondents, 23%, use the same passwords for work and personal accounts, defying industry best practices l More than 1 in 5 respondents, 21%, still store passwords on their phone, computer, or in printed document, violating industry best practices On a positive note, the poll also revealed that less than 15% of respondents reported having previously shared their work login credentials or used someone else’s login credentials at work. The poll results illustrate that every employee has an important role to play when it comes to protecting their organisations from cybersecurity threats.
Fortinet has announced the findings of the latest FortiGuard Labs Global Threat Landscape Report. The research from Q4 2019 not only shows that cybercriminals continue to attempt to exploit any possible opportunity throughout the digital infrastructure, but that they are maximising global economic and political realities to further enable their goals. Research shows significant levels of activity across regions associated with Charming Kitten, an Iran-linked advanced persistent threat group in Q4. Active since around 2014, the threat actor has been associated with numerous cyberespionage campaigns. Recent activity suggests that the threat actor has expanded into the election disruption business, having been linked to a series of attacks on targeted email accounts associated with a presidential election campaign. In addition, Charming Kitten was observed employing four new tactics against intended victims that were all designed to trick victims into parting with sensitive information. IoT devices continue to be challenged with exploitable software and these threats can affect unexpected devices such as wireless IP cameras. This situation is magnified when components and software are embedded into different commercial devices sold under a variety of brand names, sometimes by different vendors. Many of these components and services are often programmed using bits and pieces of pre-written code from a variety of common sources. Spam continues to be one of the top issues for organisations and individuals to deal with. This quarter’s report combines the volume of spam flow between nations with data showing the ratios of spam sent vs. spam received, visually revealing a new perspective on an old problem. The majority of spam volume seems to follow economic and political trends. For example, the heaviest spam trade partners of the United States include Poland, Russia, Germany, Japan, and Brazil. In addition, in terms of exported spam volumes from geographic regions, Eastern Europe is the largest net producer of spam in the world. Most of the outbound-heavy spammers beyond that hail from Asian sub-regions. The remaining European subregions lead those with net negative spam ratios, receiving more than they send, followed by the Americas and Africa.
AP R I L 2020
MEA
29
SECURITY NEWS
Organisations lack skills to fully utilise Cyber Threat Intelligence In the past few years, CTI has evolved from small, ad hoc tasks performed disparately across an organisation to, in many cases, robust programmes with their own staff, tools and processes that support the entire organisation. This is according to the SANS 2020 CTI Survey, the latest report by the global leader in cyber security training and certifications, SANS Institute. In fact, survey results indicate that just under 50% of respondents’ organisations have a team dedicated to CTI, up from 41% in 2019. In total, more than 84% of organisations reported having some kind of resource focusing on CTI. While the number of organisations with dedicated threat intelligence teams is growing, results also demonstrate a move toward collaboration, with 61% reporting that CTI tasks are handled by a combination of in-house and service provider
teams. Another sign of maturity is the definition and documentation of intelligence requirements. The number of organisations reporting a formal process for gathering requirements increased 13% from last year, to almost 44% in 2020. This makes the intelligence process more efficient, effective and measurable, keys to long-term success. When asked which inhibitors were holding their organisation back from implementing CTI effectively, the highest response, by 57% of respondents, was a lack of trained staff or lack of skills needed to fully utilise CTI, while 52% named a lack of time to implement new processes, and 48% said the issue was a lack of funding. The report also looked at where CTI team members are drawn from within the organisation, the types of information used for intelligence
SANS INSTRUCTOR, ROBERT M LEE.
gathering and the sources used for gathering that intelligence. The 2020 SANS Cyber Threat Intelligence Survey received 1006 responses from a wide-ranging group of security professionals from various organisations. There was good representation from small, medium and large organisations and from across the globe, with 327 respondents coming from organisations headquartered in EMEA.
ManageEngine fortifies endpoint security with new software
Sophos offers firewall with performance transport layer security
ManageEngine, the IT management division of Zoho Corporation, has announced the launch of Application Control Plus, advanced enterprise security software that brings together endpoint privilege management and application control capabilities. The move gives organisations greater authority over their critical applications by enabling control processes based on Zero Trust and MATHIVANAN threat prevention. VENKATACHALAM, Many security problems arise VICE PRESIDENT, MANAGEENGINE. due to the countless unsupervised applications running in enterprise networks. According to the National Vulnerability Database, the number of application-related security issues has increased 273% during the last decade, emphasizing the importance of adopting a Zero Trust approach to application control. Despite enterprise implementations of a Zero Trust model by filtering and controlling applications, attacks leveraging applications’ privileged access persist. A combination of whitelisting, blacklisting and administering application-specific privileges is required to tackle the applicationrelated threats. Application Control Plus helps enterprises gain a holistic view of their network by aiding in the instant discovery and categorisation of authorised and unauthorised applications. With applicationlevel privileged management and dynamic, rule-based whitelisting and blacklisting, Application Control Plus ensures only authorised access occurs, minimising an enterprise’s attack surface.
Sophos has introduced a new Xstream architecture for Sophos XG Firewall with high performance Transport Layer Security, TLS, traffic decryption capabilities that eliminate significant security risk associated with encrypted network traffic, which is often overlooked by security teams due to performance and complexity concerns. XG Firewall now also features AI-enhanced threat analysis from SophosLabs and accelerated application performance. Sophos has also published the SophosLabs Uncut article, nearly a Quarter of Malware now Communicates Using TLS, which explains how 23% of malware families use encrypted communication for Command and Control or installation. The article details, for example, three common and ever-present Trojans, Trickbot, IcedID and Dridex, that leverage TLS during the course of their attacks. Cybercriminals also use TLS to hide their exploits, payloads and stolen content and to avoid detection. In fact, 44% of prevalent information stealers use encryption to sneak hijacked data, including bank and financial account passwords and other sensitive credentials, out from under organisations. Latency too often deters IT admins from using decryption, as seen in an independent Sophos survey of 3,100 IT managers in 12 countries. The survey white paper, The Achilles Heel of Next-Gen Firewalls, reports that while 82% of respondents agreed TLS inspection is necessary, only 3.5% of organisations are decrypting their traffic to properly inspect it.
30
A P R I L 2020
MEA
DAN SCHIAPPA, CHIEF PRODUCT OFFICER AT SOPHOS.
SECURITY NEWS
ORACLE
CENTRAL ADMINISTRATION OF DISPARATE TOOLS
THE NEXT WAVE OF DEVELOPMENT WILL NOT BE A POINT PRODUCT BUT RATHER A BRINGING TOGETHER OF DISPARATE SECURITY TOOLS INTO AN INTEGRATED WORKFLOW.
O
JOHNNIE KONSTANTAS,
SENIOR DIRECTOR SECURITY, ORACLE
Organisations have to look across tens of security tools to understand how to holistically protect a footprint.
racle is a company with a 40+ year history of helping enterprises and governments protect and unlock value from their mission critical data. Oracle’s security spans the enterprise applications that are the backbone of the world’s business as well as the infrastructure and database services that underpin those applications. Innovations like Autonomous Database and Autonomous Linux give customers highly automated ways to manage, patch and secure their databases and operating systems in the cloud. Built-in capabilities like DataSafe offer a centralised view of data security and access patterns augmented by Machine Learning to analyse behavior and access to data and flag that which is anomalous and poses security risk. Oracle IaaS, PaaS and SaaS clouds offer many built-in security capabilities as well as tools that customers can use, in many cases at no cost, in order to maintain a cloud security posture that is inline with organisational and compliance targets. Those tools span monitoring, alerting, automated remediation and even include integrations with tools from 3rd parties and other clouds. The expansion of a digital footprint to leverage public cloud or more accurately multiple public clouds make it inherently difficult for any-one organisation to keep up with all the security configurations and gaps. The limitation is not with cybersecurity products but rather the fact that there are simply too many of them to stitch together to cover security needs from the network to the application layer and everything in between. What is missing is a singular cloud security management platform which automates the low hanging fruit or obvious security best practices and makes it easy for a cloud customer to manage their posture. Organisations are in a position where they
CISOs are seeing their roles change to be in coordination with lines of business.
have to look across tens of built-in security tools to understand how to holistically and consistently protect an expanding footprint. These same organisations must compete for cyber skills with cloud service providers, governments and systems integrators. It is an intractable problem that can only be solved with automation and simplification of the security management process. The next wave of development will not be a point product but rather a bringing together of disparate security tools into integrated workflows that make common security tasks including risk remediation, automated and centrally administered. Cloud Security Providers are in the best position to lead this evolution. Public clouds like Oracle Cloud Infrastructure have embedded cloud security posture management and workload protection as native built-in services with templates and options to take action on behalf of security administrators and those who administer access to cloud resources. This development will help cloud customers meet increasing complexity and threat vectors without requiring deep in-house expertise and surge in personnel staffing. Making security best practices accessible and enforceable by all cloud users including security teams, development teams and apps users will be at the center of the next generation of information and data protection. CISOs are seeing their roles change to more closely be in coordination with lines of business and aligned to cloud-first and cloud migration initiatives. Security training in best practices, helping accelerate cloud-driven initiatives and enabling all personnel to be participants on security is all part of how security teams are morphing into experts guides rather than strict overseers of gates and boundaries. Technology is only part of the answer to challenges that involve people and processes but CISOs can expect to evolve the job descriptions and collaboration protocols by virtue of security tools that are pervasive, easy to use and allow broader organisational participation in maintaining a strong cloud security posture.
AP R I L 2020
MEA
31
CHANNEL STREET
NETAPP AND INGRAM MICRO BOOST DIGITAL TRANSFORMATION SOLUTIONS
BY ASSESSING USER REQUIREMENTS AND BOOSTING SKILLS OF PARTNERS, NETAPP AND INGRAM MICRO ARE WELL POSITIONED TO SELL OUT CLOUD TRANSFORMATION SOLUTIONS IN THE REGION.
I
n every industry, digital transformation has become a corporate imperative. From manufacturing to biotechnology, leading companies are harnessing data to stay competitive. As enterprises adopt digital transformation solutions across the region, NetApp and distribution partner Ingram Micro, are gearing up and adapting to these changes in the market. NetApp is making continuous changes to its channel strategy across the Middle East to maximise opportunities and its return from digital transformation. According to Maya Zakhour, Channel Sales Director Middle East and Africa at NetApp, digital transformation includes the building of a digital ecosystem in which there is seamless integration between customers, partners, employees, suppliers, and external entities. Most importantly, it is dependent on managing exponential growth, intrinsic value, and the movement of data. As a vendor, NetApp has digitally transformed its solutions a few years ago to ensure value differentiation and launched its Data Fabric. Data Fabric is a set of data services that integrates data management across cloud and on-premise to accelerate digital transformation. It delivers consistent and integrated hybrid cloud data services for data visibility and insights, data access and control, and data protection and security.
MAYA ZAKHOUR, CHANNEL SALES DIRECTOR MIDDLE EAST AND AFRICA AT NETAPP.
32
A P R I L 2020
MEA
CHANNEL STREET
As part of its go to market for digital transformation solutions, NetApp is now positioning itself as a vendor of hybrid cloud data services and data management, and no longer as just a storage vendor. However, some of NetApp’s legacy customers may not be ready for the cloud or they may not have their own data centres.
Any NetApp solution can be connected to the cloud in future
FUTURE PROOFING “We are helping our customers modernise their infrastructure so they can scale on demand and respond quickly to business needs. We want them to get the results they need, boost performance for existing applications and analytics workloads, and improve data centre economics, so they can fund their transformation by reducing infrastructure and operations cost,” says Maya. NetApp supports customers in deciding how to manage their data best – whether on-premises or connected to one of the hyperscalers like AWS, Microsoft and Google. “Customers now have the choice to select which hyperscaler they would like to partner with. They can even manage their data between several clouds and on premise,” explains Maya. Any NetApp solution can be connected to the cloud in future. This is giving customers confidence in their investment. They can engage with NetApp on how to build their Data Fabric and how to connect to the cloud when they are ready. On the flip side, if customers feel their data needs to be resident on-premises and cannot be moved to the cloud, they have the choice of investing in converged and hybrid cloud infrastructure solutions from NetApp. They can build private clouds and host their data on-site in a cloud-like environment.
Customers now have the choice to select which hyperscaler they would like to partner with
“With NetApp’s hybrid cloud infrastructure, we integrate data management across cloud and on premise to accelerate digital transformation no matter what the customer’s cloud strategy demands,” elaborates Maya. NetApp’s cloud data services are realigning the company and reshaping its future. The company has created strong alliances with global hyperscalers to offer cloud data services, whether from the edge or the core. This gives customers the flexibility and freedom to drive their data between clouds as required. Customers can move their data across these platforms from their legacy on-premise installed base to the cloud or between clouds. “Our solution works with any of the hyperscalers and is opening the door for bigger opportunities,” says Maya.
GO TO MARKET In a dynamic and competitive market like the Middle East, channel partners are required to adapt the way they interact and sell to customers. This essentially means that partners not only need to reassess existing capabilities and gaps, but also modify their go-to-market strategy to stay on top of changes that emerging technologies are making to customer demands. They need to evolve with the market by investing in resources around digital transformation, service delivery, advisory capabilities and portfolio offerings. “To take Data Fabric to the market, we decided to transform the way we reach our distributors, partners and customers. Our distributors play a key role in NetApp’s two-tier channel structure,” says Maya Zakhour. The value-added distributor Ingram Micro supports NetApp in its go-tomarket strategy to target commercial and run rate business. The relationship between NetApp and Ingram Micro spans several years. Ingram Micro’s value distribution model is purely partner-first by collaborating with them from the inception of the end user requirement. One of the distributor’s key focus areas is cloud, and this works well with NetApp. Maya points out that Ingram Micro has relationships with significant channel partners in the Middle East. To leverage its go-to-market, Ingram Micro collaborates with NetApp to ensure a closer working relationship to transform not only its structure and strategy but also its product portfolio. Together, they provide technical, financial, and added value to the partners.
AP R I L 2020
MEA
33
CHANNEL STREET
Partners whose solutions are aligned with hyperscalers and are helping end users along their transformation journey are essential
Channel partners who understand the infrastructure and applications of a customer are an ideal fit
ROLE OF INGRAM MICRO “Collaboration with NetApp is helping us address storage opportunities effectively. We see requirements from customers using mission critical applications, which demand higher IOPS and performance. We can address these with NetApp and provide them with the best in class solution,” says Bahaa Salah, Managing Director, Ingram Micro, Gulf and Near East. A key requirement for both NetApp and Ingram Micro is the skill set of channel partners. Salah points out that channel partners who understand the infrastructure and applications of a customer are an ideal fit. On top of that, partners whose solutions are aligned with hyperscalers and are helping end users along their digital transformation journey are essential “We enable our channel partners in various ways by constantly updating them with tech refresh sessions on digital transformation and cloud solutions. One of the main events we host every month is the NetApp Café, where we focus on technologies. We give a classroom-style training to partners’ sales and presales champions to help them become successful,” points out Salah. In addition, Ingram Micro created the Experience Zone in its office to demonstrate solutions around digital transformation. Also, channel partners are encouraged and motivated in their go to market activities through various joint rebate programmes. By closely aligning with both end customer and channel partner requirements, NetApp and Ingram Micro expect to see continuous increasing demand for their high value digital transformation solutions. ë
34
A P R I L 2020
MEA
BAHAA SALAH,
MANAGING DIRECTOR, INGRAM MICRO, GULF AND NEAR EAST.
COVER FEATURE
CYBERSECURITY
WILL NEXT GENERATION SOLUTIONS BE
SMARTER AND FASTER 15+ top executives give their take on how AI and ML is being embedded in next generation cybersecurity solutions. By: Arun Shankar
(Left to right, top to bottom) l Amir Kanan, Managing Director, Middle East, Turkey, Africa, Kaspersky l Ammar Enaya, Regional Director Middle East, Turkey and North Africa, Vectra l Ashraf Sheet, Regional Director MEA, Infoblox l Dr Mike Lloyd, CTO, RedSeal l Emile Abou Saleh, Regional Director, Middle East and Africa, Proofpoint l Fady Younes, Cybersecurity Director, Middle East & Africa, Cisco l Harish Chib, Vice President, Middle East and Africa, Sophos l Hesham Elsherif, Principal System Engineer, A10 Networks l Jeff Ogden, General Manager Middle East and India, Mimecast l John Pescatore, Director Emerging Security Trends, SANS Institute l Jonathan Couch, SVP Strategy, ThreatQuotient l Karl Lankford, Director Solutions Engineering, BeyondTrust l Maher Jadallah, Regional Director Middle East, Tenable l Marco Rottigni, Chief Technical Security Officer EMEA, Qualys l Neil McElhinney, Head of Critical Information Systems and Cyber Security, Thales Middle East l Paul van de Haar, Associate Director, Digital and Innovation, KPMG Lower Gulf l Rajesh Ganesan, Vice President, ManageEngine. AP R I L 2020
MEA
35
COVER FEATURE
KASPERSKY
MANAGING YOUR SECURITY BUDGETS WITH AI AND ML BY IMPLEMENTING NEXT GENERATION SOLUTIONS WITH THE LATEST AI, CISOS DO NOT HAVE TO WORRY ABOUT HAVING TO JUSTIFYING BUDGETS IN THE BOARDROOM.
A
AMIR KANAN, MANAGING DIRECTOR, MIDDLE EAST, TURKEY AND AFRICA, KASPERSKY.
CISO is tasked with choosing a defense plan that is in line with the business vision
36
A P R I L 2020
MEA
rtificial intelligence and machine learning are two major buzzwords that are used in the cybersecurity space. Artificial intelligence is the latest innovation that is used by cybersecurity experts to help identify and prevent cybersecurity attacks. We are seeing cybercriminals find ways to always stay one step ahead but with the use of the latest technologies, cybersecurity providers can aim to predict cybercriminals next moves. Machine learning and artificial intelligence can help anticipate a cybercriminal’s next step in time to stop the attack. By implementing the next generation of cybersecurity products and solutions with the latest technologies like artificial intelligence for example, CISOs do not have to worry about having to justify their cybersecurity budget in the boardroom. This is because artificial intelligence helps to reduce the funds needed to manually detect and prevent attacks. By automating this entire process, artificial intelligence also ensures that accurate decisions are made quickly and efficiently. The main pain points of CISOs are ensuring that they have selected the best practices of protection for their business. The CISO is tasked with choosing a defense plan that is in line with the business vision. Therefore, CISOs cannot dismiss a technology that their business would like to implement. Instead they are required to evaluate the risks involved and suggest an ideal security solution that will not hinder how the business functions. They are not only in charge of making sure the security solutions run smoothly but also offer advice to other employees on cyber awareness. The skill sets required by IT and cybersecurity professionals to manage the next generation of cybersecurity products and solutions are not only restricted to technical skills but should also include soft skills. Most professionals are well aware of how to implement and manage the
latest cybersecurity solutions but, what they lack are essential soft skills that is much needed in a business environment. FUTURE SKILL SETS Business acumen Cybersecurity professionals should be able to organise their department’s work to meet business demands. Communication and presentation skills They should be able to speak the language that other parts of the business use and also be able to describe the technical aspects of their jobs in a simplified manner. Crisis management skills In case of a breach, it is essential that the IT professionals are aware of what steps to take next and do so swiftly and efficiently. PRODUCT SUITE Kaspersky Threat Management and Defense is Kaspersky’s flagship product which focuses on risk mitigation delivering a unique combination of leading technologies and services to support the implementation of an Adaptive Security Strategy – aiding the organisations’ security personnel to prevent the majority of attacks, detect unique new threats rapidly, respond to live incidents and predict future threats. KasperskyOS is a specialised operating system designed for embedded systems with strict cybersecurity requirements. We are looking forward to meeting and collaborating with hardware manufacturers who might be open to developing the KasperskyOS for their own products. Kaspersky Enterprise Blockchain Security consists of a range of services such as Smart Contract, Chain Code Audit and Application Security Assessment. The service ensures correct business logic configurations of smart contract and secures operations of Blockchain applications. ë
COVER FEATURE
VECTRA
NAME OF THE GAME WILL BE AGILE BEHAVIOURAL TOOLS NEW BEHAVIOURAL ANALYTIC TECHNIQUES WILL REDUCE THE TOTAL NUMBER OF SECURITY TOOLS IN USE WITHIN SECURITY OPERATIONS, LESS IS GOING TO BE MORE.
A
AMMAR ENAYA, REGIONAL DIRECTOR, MIDDLE EAST, TURKEY AND NORTH AFRICA, VECTRA.
We have an opportunity to address security challenges for customers through automation of threat detection and response
s nations and organisations in our region increasingly become digital enterprises, the protection of data, services, and infrastructure has become a high priority. Provision of local cloud services will be a core contributor to may digital transformations too. These factors are drivers that will see around $1.9B spent on Enterprise Information Security in the Middle East and North Africa region this year. Cloud architectures are plagued by security vulnerabilities and The SANS Institute says that one out of five businesses were hit by unauthorised access to their cloud environments in the past year. As more enterprises turn to the cloud for greater operational scale and cost efficiencies, it is critical to address these security vulnerabilities, so businesses can innovate, free from external threats. Couple this with a significant cybersecurity human resource and skills gap, and we have a market opportunity to address strategic security challenges for our customers through automation of threat detection and response. Security operations is going to take a major shift to behaviour-based methodology for threat detection and response. Companies are already performing a stack ranking on the tools they have and the ones that do not make the cut are going to be out. There are too many tools in the toolset and companies do not want to pay for these anymore. New behavioural analytic techniques will reduce the total number of security tools in use within security operations today. Less is going to be more. AI powered, behaviour solutions allow the post-perimeter monitoring of international networks, datacentres and cloud instances — areas which are common blind spots for many organisations. Operating at machine speed, these solutions empower security teams to work
at previously unattainable levels of efficiency to identify, understand and respond to active attackers before a full-blown breach can occur. Continued advances in AI are also making it easier to automate many laborious security tasks, reducing the barriers to entry into our profession. This is creating more opportunities for new entrants and means that entry level roles will no longer need as much hands-on experience — these are people who traditionally would be unable to take on these positions without significant further education, professional development, and substantial experience. This enables them to quickly ramp up to being productive members of the cybersecurity team by using AI to empower them. This is good news for the profession, given the massive human resource talent gap we are currently facing. PRODUCT SUITE Powered by AI, Vectra and its flagship Cognito threat detection and response platform enable organisations to automatically detect and respond quickly to hidden cyberattacks in cloud, data centre and enterprise environments. The Cognito platform consists of Cognito Stream and its equally powerful AI counterparts, Cognito Detect and Cognito Recall. Cognito Stream delivers enterprise-scale network metadata enriched with security insights in Zeek formally Bro format to data lakes and security information and event management SIEM applications without the complexity, constant tuning and scale limitation of opensource Zeek. Cognito Recall is an investigative workbench that enables AI-assisted threat hunting and conclusive incident investigations while Cognito Detect automates the real-time detection of hidden attackers from cloud SaaS, cloud IaaS, and data centre workloads to user and internet-of-things IoT devices. ë
AP R I L 2020
MEA
37
COVER FEATURE
INFOBLOX
THREAT INTELLIGENCE, NEXT FRONTIER FOR TRANSFORMATION OVERBURDENED SECURITY PERSONNEL CONTEND WITH MULTITUDE OF SILOED TOOLS AND DELUGE OF ALERTS, LEADING TO POOR INCIDENT RESPONSE AND SLOW REMEDIATION.
S ASHRAF SHEET, REGIONAL DIRECTOR MEA, INFOBLOX.
The speed at which COVID-19 has spread has proven a challenge for IT professionals
38
A P R I L 2020
MEA
ecurity organisations are under tremendous pressure to protect their infrastructure and data from existing and emerging cyberthreats and hazards. Through threat intelligence, security teams can make informed decisions on how best to respond to these threats. Threat intelligence is evidence-based knowledge that includes context, mechanisms, indicators, implications and actionable advice, about an existing or emerging threat or hazard. Threats can have internal as well as external sources and can come in the form of malicious IP addresses, hostnames, domain names and URLs. According to the Ponemon Institute’s 2018 report on Exchanging Cyber Threat Intelligence: l More than 60% of survey respondents were not satisfied with the quality of threat intelligence l Nearly 25% of survey respondents were unable to prioritise the threats by category l Nearly 40% of respondents lacked context to make threat intelligence actionable Although threat information in the form of raw data is freely available, it can be enormously difficult and time-consuming to make sense of it in a timely fashion. Many organisations lack the visibility and contextual insight required to prioritise threats, much less to respond to them proactively. Additionally, overburdened security personnel must contend with a multitude of siloed tools and hundreds to thousands of alerts every day. A lack of effective threat intelligence leads to poor incident response and slows remediation. Digital transformation is changing the way that enterprises operate. Businesses seeking to provide better customer service, empower their employees, and respond more quickly to markets will invest in tools to digitise their operations, move them to the cloud, and develop architec-
tures that take advantage of mobile computing and the IoT revolution. These innovations mean that users, devices, applications and data are increasingly located or run from the network edge, and challenging the data-center centric architecture of traditional network models. To address these challenges, experts are predicting the rise of the Secure Access Service Edge, or SASE. As the world is focusing on the ongoing pandemic and so many people are working from home, safe and secure networks are a critical component to keeping companies running. Infoblox recommends that businesses implement the guidelines and best practices to ensure the security of their networks and corporate data while employees are working from home. The speed at which Coronavirus has spread has proven a challenge for everyone, IT professionals included. This situation has highlighted the importance for organisations to invest in networking and security services, especially at the network edge, not just for crisis situations, but for the changing nature of work. As networks continue to be more decentralised and more employees take advantage of the benefits of working from home, securing networks from malware and other cyber threats will remain a challenge. Emphasizing and implementing cybersecurity training and decreasing the amount of vulnerable IoT devices when working from home will help IT managers ensure that corporate networks remain cyber-safe. Companies most likely already have a robust security infrastructure in place to protect their corporate network. Now that the corporate perimeter has vanished, IT managers need to ensure that technologies are ready for employees to use when working from home. ĂŤ
COVER FEATURE
REDSEAL
CAN WE DELEGATE SECURITY TO MACHINES FAST ENOUGH?
MACHINES CAN EXTEND THE SPEED OF SECURITY PROFESSIONALS, BUT YOU CANNOT TAKE THE HUMAN OUT OF THE LOOP, LEADING TO EMERGENCE OF AUGMENTED INTELLIGENCE.
T DR MIKE LLOYD, CTO, REDSEAL.
Humans are better at understanding whether access controls are appropriate for current threats an organization faces
he main challenge with existing cybersecurity products is that there are too many of them. Organizations world-wide are finding they cannot staff enough experts, trained in enough different products, to use their existing cyber investments effectively. Buying 20 products is not helpful if you only have enough people to run just five of them. Tool sprawl and short staffing are the two biggest pain points around cybersecurity technology. The industry has focused too long on point products to attack single issues, leading to a countermeasure of the month mentality. Another challenge has been over-hyped artificial intelligence, where an algorithm alone will spot the bad guys or quarantine the threats. Technology is evolving towards inter-product linkage and partial automation of workflows. Machines can greatly extend the speed and power of security professionals, but you cannot take the human completely out of the loop, because security is a cat-and-mouse game with constantly shifting tactics, techniques, and procedures. The alternative to AI is Augmented Intelligence, the idea of using computer reasoning to assist human operators, so that each can do what they are best at. Augmented Intelligence deals directly with the shortage of skilled resources, without assuming that computers really understand our business and political environment. It allows fewer people to take on more adversaries by using machine reasoning to extend their ability to find things in much the same way that we use search engines to find what we’re looking for on the Internet. It is essential for cybersecurity professionals to learn which work is best for humans, and which for computers. Computers are inexhaustible, and can check hard questions across complex
interactions, like has every cloud database been secured behind access controls? Humans, on the other hand, are better at understanding the wider context — asking, for example, whether those access controls are appropriate to the current threats an organization faces. Humans are better at strategic insight, while computers excel at tactical rigor. PRODUCT SUITE RedSeal shows customers what is on their networks, how it is connected and the associated risk. It creates a dynamic network model using advanced algorithms to find defensive gaps that humans cannot spot. Defensive teams can be confident have applied security fundamentals uniformly across their hybrid, dynamic infrastructure. Risk and compliance managers can see if their network was set up as intended and get alerts if anything changes. They can see if networking devices are securely configured and know exactly what line in the configuration to fix to make them more secure. RedSeal shows them their entire network and network security infrastructure, so they aren’t surprised by risks from datacenters they thought were decommissioned or unauthorized AWS instances. And, they will get a single metric — RedSeal’s Digital Resilience Score — to communicate with their executives. This metric can also demonstrate the network’s security posture to cyber insurance providers. Incident responders can speed their investigation and containment with the network situational awareness RedSeal supplies. RedSeal connects with SIEMs, quickly locating compromised devices and determining which assets bad actors could reach from there. ë
AP R I L 2020
MEA
39
COVER FEATURE
PROOFPOINT
CISOS MUST PLAN FOR HUMAN ELEMENT IN THEIR DEFENSE SINCE 99% OF CYBERATTACKS NEED HUMANS TO CLICK, CYBERCRIMINALS
TARGET PEOPLE, RATHER THAN SYSTEMS AND INFRASTRUCTURE, TO INSTALL MALWARE, STEAL DATA.
A
EMILE ABOU SALEH, REGIONAL DIRECTOR, MIDDLE EAST AND AFRICA FOR PROOFPOINT.
Many organisations in UAE have not yet deployed the DMARC protocol authentication, leaving them exposed to email fraud
40
A P R I L 2020
MEA
s technology evolves, cyberattacks become more sophisticated and organisations must recognise the human factor threat to apply a robust security strategy. One of the limitations across organisations globally is the lack of awareness about common risks and their role in defending against them. Additionally, while business email compromise scams will continue to be a global issue, many organisations in the UAE have not yet deployed the DMARC protocol authentication, leaving them exposed to email fraud as a result. Cyber-attacks involving malware, phishing, machine learning and artificial intelligence have placed the data and assets of corporations, governments and individuals at constant risk. Proofpoint’s latest State of the Phish report highlighted that nearly 90% of global organisations surveyed were targeted with business email compromise BEC and spear phishing attacks, reflecting cybercriminals’ continued focus on compromising individual end users. As more than 99% of cyberattacks rely on human interaction to work, CISOs must prioritise a people-centric approach to security that protects all employees. At the same time, they should put in place a holistic people-centric cybersecurity approach that includes effective security awareness training and layered defenses that provide visibility into their most attacked users. Over the past few months, we have seen the growth of many technologies supported by the increased adoption of 5G networks. For instance, artificial intelligence, AI is one of the main drivers as it will process massive amounts of data, most of which will be in public clouds. Additionally, AI will help in tackling and defending against potential threats and will improve modes of detecting and responding to incidents. Furthermore, we will start to see more AI-based tools that provide threathunting, attack analysis and incident response
to proactively search for potential issues. However, as with all innovative technologies, organisations must consider the potential security implications when deploying. Proofpoint solutions are built on the cloud and through the world’s most advanced intelligence platform stop 99% of attachment-based attacks. As 99% of cyberattacks need humans to click, cybercriminals target people, rather than systems and infrastructure, to install malware, initiate fraudulent transactions, steal data. Therefore, we have evolved as a next-generation cybersecurity company to help CISOs to stop targeted threats, safeguard their data, and make their users more resilient against cyber-attacks. The current cybersecurity landscape requires IT professionals that are always on top of the current trends across the entire cybersecurity spectrum. CISOs need to be familiar with the disruptions and risks driven by technology, while constantly find new ways of leveraging technology for business transformation and growth. Additionally, it is vital that CISOs realise the importance of implementing ongoing and effective security awareness trainings when building a strong security culture. By educating employees, CISOs are able to empower users to truly understand the best ways to protect theirs and their organisation’s data, making them a less vulnerable target for attackers. PRODUCT SUITE Proofpoint delivers the most effective cybersecurity tools available to protect people against the threats that target them, as well as the information they create and access. As cybercriminals are increasingly targeting people, instead of infrastructure, our comprehensive suite of advanced solutions spans email, social media, web, network and cloud— including Microsoft Office 365. Proofpoint Security Awareness Training, helps CISOs to change employee behaviour and manage end-user risk to create a culture of security through simulated attacks and knowledge assessments with interactive training and reinforcement activities. ë
COVER FEATURE
CISCO
MOVING AWAY FROM BEST OF BREED TO BEST OF SUITE
COMPLEXITY INSIDE THE SECURITY ORGANISATION IS REACHING BREAKING POINT AND CISOS ARE NO LONGER LOOKING AT INCREASING SOLUTIONS AND VENDORS.
F FADY YOUNES,
CYBERSECURITY DIRECTOR, MIDDLE EAST AND AFRICA, CISCO.
CISOs cannot afford to spend more money for more tools that require more effort to get a team running. CISOs cannot afford to spend more money for more tools that require more effort to get a team running.
or CISOs the top challenges include private cloud infrastructure, network infrastructure, and mobile devices. Malware and malicious spam come in as #1 and #2 causes of downtime. In third place with phishing and spyware, ransomware tends to reap more than 24 hours of downtime. The trend to reduce complexity through vendor consolidation continues in 2020 with 86% of organisations using between 1 and 20 vendors, and 13% using over 20 vendors. Defined as virtually giving up on proactively defending against malicious actors, 42% of respondents are suffering from cybersecurity fatigue. Notably, the overwhelming number of alerts is having an impact on cybersecurity fatigue. Of those who say they are suffering from cyber fatigue, 93% of them receive over 5,000 alerts every single day. At Cisco, the priority is to ensure businesses are combating complexity and deploying the right technologies that will speed up their response and remediation times, improve visibility, foster collaboration and protect their overall business from threats. The threat landscape requires an integrated, not isolated approach. Cisco has always built on this foundation and hence, recently launched platform SecureX is following this methodology. An integrated platform needs to deliver increased visibility, improve automation, automate data enrichment to reduce manual efforts and simplify deployment and management. Security is complex, and CISOs today do not want a complex solution to an already complex problem. In response, we are beginning to see a majority of customers shift from a best-of-breed to best-of-suite approach for security solutions. We are seeing a push for fewer strategic partners and more out-of-the-box value from products designed to work together. Many CISOs cannot afford to spend more money for more tools that require more effort to get a team up and running on each tool. This loss of time keeps
security teams from high-value work, like applying security insights to keep the enterprise secure. Cisco’s annual CISO survey revealed a trend toward vendor consolidation, which tells us CISOs are looking for ways to make network security easier to manage. This trend toward simple solutions will only continue in 2020. The security workforce shortage is impacting two-thirds of organisations, while the gap, currently at 4 million, continues to grow. Security teams are short-staffed, to the point where 25% say the inability to keep with the workload is a root cause of security incidents. Every new technology added to a security infrastructure not only adds complexity but is resource intensive, not to mention the decreased efficacy in detecting and preventing threats. PRODUCT SUITE Cisco’s cybersecurity offering spans across the cloud, networking, collaboration tools and endpoints; the solutions are designed to meet the challenges faced by small and large enterprises operating across different industries. Cisco’s products include: Advanced Malware Protection, Cloud Security, Email Security, Threat Response, NextGeneration Firewalls and Multi-Factor Authentication to name a few. Cisco is re-defining what is possible for businesses through Cisco SecureX - a cybersecurity platform that addresses tomorrow’s evolving threats as businesses accelerate innovation and agility. SecureX provides greater visibility across the entire security portfolio, delivering security analytics, and automating workflows to speed threat detection and response. ë
AP R I L 2020
MEA
41
COVER FEATURE
SOPHOS
LEVERAGING CLOUD AND AI TO BOOST THREAT INTELLIGENCE NEXT GENERATION SOLUTIONS AUTOMATE INCIDENT RESPONSE AND
ELIMINATE MANUAL WORK OF TRYING TO FIGURE OUT WHO, WHAT AND WHEN A COMPROMISE HAPPENED.
T HARISH CHIB, VICE PRESIDENT, MIDDLE EAST AND AFRICA, SOPHOS.
Security products are invasive, they look in every file and inspect packets for information, with little impact to network performance.
he growth in complex and coordinated attacks is outpacing many organisations’ ability to protect themselves. Overstretched IT departments struggle to respond fast enough to threats entering their ever-expanding IT infrastructure. Continuing to manage disparate products is leading to increasing risk to business. Unless there is a distinct change in approach to IT security this will only get worse. In the race to catch every attack, many products produce false positives that is sending an alert when there is no real incident. However, IT administrators do not know that until they investigate it and this can increase the time taken to respond to actual events. Security products are invasive, they look in every file and inspect packets for information, they have to do this in real-time with little impact to network performance. All these products are complex and require management and updates, particularly during persistent attacks. The average midmarket company has between 1-3 IT professionals – and none are dedicated to security. Competition for IT resource to keep the
These products are complex and require management and updates, particularly during persistent attacks.
42
A P R I L 2020
MEA
company productive and secure is high. Cybersecurity solutions incorporate nextgeneration machine learning and artificial intelligence technologies, to combat constantly evolving cyber threats. Endpoint Detection and Response has swiftly become must-have technology and which makes sense, as it helps to reduce the time spent investigating security incidents and increases visibility into the threat chain. Interestingly, EDR has become a tool for all, and we see almost equal demand from both smaller and larger organisations. Next generation cybersecurity solutions that act as a system automate incident response via constant and direct sharing of threat, security, and health information between endpoint and network. These solutions eliminate the manual work of trying to figure out who, what and when a compromise happened. When an endpoint is attacked, the firewall can immediately isolate it from the network and send an alert to the IT admin with the user name – not just an IP address – making the response for the IT admin faster and more efficient. PRODUCT SUITE As a worldwide leader in next-generation cybersecurity, Sophos protects more than 400,000 organisations of all sizes in more than 150 countries from today’s most advanced cyberthreats. Powered by SophosLabs, a global threat intelligence and data science team - Sophos’ cloud-native and AI-enhanced solutions secure endpoints laptops, servers and mobile devices and networks against evolving cybercriminal tactics and techniques, including automated and active-adversary breaches, ransomware, malware, exploits, data exfiltration, phishing, and more. Sophos Central cloud-based platform integrates Sophos’ entire portfolio of best-of-breed products, from the Intercept X endpoint solution to the XG Firewall, into a single system called Synchronised Security. ë
COVER FEATURE
A10 NETWORKS
PREDICTING A POSSIBLE BREACH BEFORE IT CAN OCCUR AI SOLUTIONS CUT DOWN RESPONSE TIMES BUT NEW CHALLENGES ARISE
AROUND DATA VOLUME, PROCESSING POWER, USING SPECIFIC ALGORITHMS FOR THE PROBLEM SET.
T HESHAM ELSHERIF, PRINCIPAL SYSTEM ENGINEER, A10 NETWORKS.
Some attacks might be detected by one technology, which may be blocked by another technology
he same way organisations strive to enhance their defenses, attackers are constantly improving their tools, tactics, and procedures in order to break through defenses. The problem is that the cybersecurity industry and technology are largely reactive, and the cyber attacker is always one step ahead. In order to keep up with modern attackers, security technologies need to evolve alongside them — without relying on human intervention. Artificial intelligence and machine-learning innovations are critical in defending the most vulnerable security gap. Visibility is one of the major pain points for CISOs, as data encryption will affect the ability of security devices located within the security zone; hence malicious activities and cyber-attacks can leverage this. Another area of difficulty for CISOs is the correlation between different security devices logs, alarms and mitigations. Some attacks might be detected by one technology, which should be blocked by another technology. Similarly, some attacks may be detected and classified as a minor threat while other technologies may see it as a major threat. Lastly, a major concern is automation detection and protection. There are many cases where an attack takes place, the installed security system raises an alarm, but no action is taken. Therefore, it is important to minimise the need for human intervention and increase visibility and correlation between different security elements. We believe predictive analytics, which discovers a data breach before it happens, are the future. Artificial intelligence and machine learning are paving the way for a new generation of threat intelligence and security solutions. This innovation, however, comes with cautions, and some reality checks. While AI-based solutions can cut down response times and help us learn from attack data, new challenges arise around data volume, raw processing power and threat actor parties, as
well as the challenge of actually using the correct algorithm for the specific problem set. The integration and correlation between collected data and an automated response will be critical for CISOs. FUTURE SKILL SETS A key skill for a security CIO is project management for setting set procedures to audit security rules from a very early stage, building web service and data structure and authentication, authorisation hierarchy. It is important for these sets of procedures to be updated before and after publishing the service. A skilled security engineer also needs to master different useful tools to run deep analysis, and build automation and correlation among security devices. Scripting skills are also useful to be able to build a customised tool using APIs not only to correlate between collected data but also to fetch data. PRODUCT SUITE A10 Networks Thunder Convergent Firewall CFW, a security solution that incorporates multiple security functions for enterprise and service provider deployments Thunder SSLi, SSL Insight is a comprehensive SSL, TLS decryption solution that enables your security devices to efficiently analyse all enterprise traffic Thunder Threat Protection System TPS, detects attacks across the network and mitigates DDoS attacks at the network edge Thunder Application Delivery Controller ADC, Combined with A10 Harmony Controller enables customer applications to be highly available, accelerated and secure with centralised management and analytics. ĂŤ
AP R I L 2020
MEA
43
COVER FEATURE
MIMECAST
LEVERAGING CLOUD, MICROSERVICES FOR SMART INTEGRATION CUSTOMERS AND PARTNERS ARE USING MIMECAST PLATFORM FOR SMART INTEGRATION OF THREAT SHARING, ORCHESTRATION, REMEDIATION AND PROVISIONING.
D JEFF OGDEN, GENERAL MANAGER, MIDDLE EAST AND INDIA, MIMECAST.
CISOs are constantly feeling pressure to perform, innovate and stay ahead of risk as the business grows and changes
igital transformation initiatives are accelerating the adoption of cloudbased productivity services like Office 365 or G Suite, but concerns remain around the security and availability of email and web services. Traditionally, organisations would build their own resilience with on-premise layers of security, sizable investments in archive hardware and teams of people to manage everything. But today’s organizations are concerned about cyber risk and struggling to attract and retain sufficient cyber security expertise and budget. CISOs are challenged by the cost and complexity of implementing and managing a growing body of technology solutions while constantly feeling the pressure to perform, innovate and stay ahead of risk as the business grows and changes. They often rely on a handful of strategic vendors, among the many, to help them stitch together an actionable view of threat intelligence across and outside their organisation. Avoiding the hype out there on AI and machine learning, we have found the most effec-
Avoiding the hype out there on AI and machine learning, we have found the most effective innovations around integration
44
A P R I L 2020
MEA
tive innovations have been around integration. Everyone has too much data and not enough actionable insights. This is why Mimecast was designed with cloud-native platform, known as Mime|OS using a microservices architecture. Alongside internal R&D advantages, this is now allowing our customer and alliance partners to quickly build smart integrations such as for threat sharing, orchestration and remediation and provisioning. This API-led approach allows organizations to build a sustainable cyber resilience strategy and fully leverage the collective power of the best technologies in the industry. CISOs can then demonstrate the reduced complexity, lower risk, and optimized investments that management demands. IT and cybersecurity professionals need to feel confident about their complex mix of on-premise and cloud infrastructure, demonstrating credibility and control to management and users. Teams large or small, need to mix people skills with a broad range of technical ability and know how to lean on their technology partners and vendors for area of expertise. PRODUCT SUITE Mimecast is an email security and cyber resilience company that helps organisations protect their brand, employees and supply chain from malicious attack, technical failure and human error. Traditionally the core business has been emailing security, stopping phishing, impersonation and ransomware emails, and backup by archiving a secure email copies in the cloud. Mimecast has also added web security, employee awareness training, DMARC analysis and brand protection services that detect and takedown spoofed websites. ĂŤ
COVER FEATURE
SANS INSTITUTE
SECURING CLOUD APPS, MOBILE USERS IS FUNDAMENTAL THE SKILLS GAP IN THE MARKET IS JUST THAT, SHORTAGE OF SKILLS
RATHER THAN OF HEADCOUNT AND UPSKILLING EXISTING EMPLOYEES IS COST-EFFECTIVE.
S JOHN PESCATORE, DIRECTOR EMERGING SECURITY TRENDS, SANS INSTITUTE.O.
Cybersecurity training courses that address the issues unique to cloud-based applications and mobile users are key.
ANS is the largest global cybersecurity training and certification provider. The Institute offers intensive in person and online cybersecurity training courses that include hands-on labs to keep cyber security professionals up to date with the latest threats and cyber security techniques and to enable graduates to immediately fill the many cybersecurity openings at companies and government agencies worldwide. SANS also develops and maintains, the largest free collection of research documents about various aspects of information security, and it operates the Internet’s early warning system - the Internet Storm Center. There are two broad classes of cybersecurity products: HOST BASED SOFTWARE These products are too easily bypassed by users or system administrators, leaving PCs and servers open to attack. NETWORK-BASED APPLIANCES The movement to the use of cloud-based systems and mobile applications means that traditional network security appliances, which are very effective against advanced threats, are often not in the path between the attackers and the target
users and servers SANS carries out several surveys each year and the top 3 pain points CISOs consistently list are: l Lack of cybersecurity skills l Movement to the cloud l Inability to get other parts of the organisation, particularly IT operations, to change and reduce vulnerabilities Cybersecurity training courses that address the issues unique to protecting cloud-based applications and mobile users are key. The skills gap in the market is just that – more a shortage of skills than of headcount – and upskilling existing employees is usually much more cost-effective than hiring new people from the outside. Next generation cybersecurity products are integrating into virtualisation and cloud features to improve overall security performance. The security operations teams need increased skills in developing cybersecurity architectures and playbooks that integrate across on-premises data centres and cloud-based data centres, and mobile applications. Security staff needs hands on experience with cybersecurity tools and products that implement those processes. CISOs need better communication and influencing skills in order to get IT operations and application development to make changes and incorporate security from the start of each project. ë
CISOs need better communication in order to get IT operations to make changes and incorporate security.
AP R I L 2020
MEA
45
COVER FEATURE
THREATQUOTIENT
CISOS CHALLENGED BY TEAMS, PROCESSES, TECHNOLOGIES CISOS STRUGGLING TO MANAGE NON-COHESIVE TEAMS WITH DIFFERENT
TECHNOLOGIES, IMPLEMENTING DIFFERENT PROCESSES WITH VARYING LEVELS OF SECURITY.
T JONATHAN COUCH, SVP STRATEGY AT THREATQUOTIENT.
CISOs have an internal marketing responsibility to show the value of cybersecurity.
hreatQuotient strives to address gaps in operational capabilities that SIEM and other security technologies have created. ThreatQuotient provides a security operations platform that creates a threat-focused environment for security teams to collaborate, leveraging and enhancing current security tools. Many security products just do not talk the same language in order to share information. Security solutions need to do a better job at forced collaboration for security teams. Each team and analyst are learning something about the environment or threat as they are doing their job and that information needs to be communicated to others. It seems a simple concept, and there are standards out there for sharing, but they do not apply across products in operational environments. We need to do a better job at enabling people, process, and technology: not just technology niche capabilities that address a specific issue. For years, the center of gravity for SOC operations has been the SIEM. It is a 20-year-old, multi-billion-dollar part of the industry that has
Automation and integration seem to be the biggest projects we see in the market.
46
A P R I L 2020
MEA
candidly failed on the promise of delivering real operational capabilities for SOC teams. CISOs face non-cohesive teams that all leverage different technologies, each requiring or implementing different processes that require varying levels of security and technical proficiency. CISOs struggle to pull this all together to communicate the security story to executives and the business. Automation and integration seem to be the biggest projects we see in the market. Security teams are trying to do the traditional more with less, and that means automating repetitive processes and having your security environment do a better job of communicating between devices. The name of the game in current security teams is efficiency and effectiveness and that tends to lead down the path of automation, prioritisation, and collaboration. In addition to actual security work, CISOs have an internal marketing responsibility to show the value of cybersecurity. They need to anticipate the regular questions from business leaders on important external threats, whether or not they will affect the business, and what security is doing to minimise the impact. Security products and solutions need to help CISOs bridge the gap between the technical work of securing the enterprise with the marketing work of communicating the value of that security to the business. Many of the skillsets will likely remain the same in the future. You will always need entrylevel analysts that go through alerts and malware analysts or threat hunters that really understand code or threats and security technology. It is hoped that cybersecurity professionals could evolve to become more process-oriented. Technologies need to allow analysts to understand the processes that adversaries use to breach networks and then leverage their own processes to anticipate and counter those activities. Focusing on processes removes the technical hurdles and provides more agility to our teams. ĂŤ
COVER FEATURE
BEYONDTRUST
DISCOVERY AND AUTOMATION CRITICAL FOR DIGITAL BIZ FOR CYBERSECURITY TO WORK AT THE SPEED OF DIGITAL BUSINESS IT IS CRITICAL TO AUTOMATE AND SELF-DISCOVER VULNERABILITIES ACROSS THE EXPANDING ATTACK SURFACE.
B KARL LANKFORD, DIRECTOR SOLUTIONS ENGINEERING, BEYONDTRUST.
eyondTrust is a global vendor in Privileged Access Management, empowering organisations to secure and manage their entire universe of privileges. The vendors integrated products and platform offer the industry advanced PAM solution, enabling organisations to quickly shrink their attack surface across traditional, cloud and hybrid environments. The BeyondTrust Universal Privilege Management approach secures and protects privileges across passwords, endpoints, and access, giving organisations the visibility and control they need to reduce risk, achieve compliance, and boost operational performance. For all of information technology’s benefits, most organisations are well acquainted with the by-product of rapid IT advances and expansion — increased cybersecurity risk. Indeed, growing cybersecurity concerns correlate directly with your organisation’s expanding digital universe and the number of people given some level of authority to operate within it. A swiftly expanding digital perimeter — both physical and logical — inevitably makes organisations more vulnerable to the so-called cyberattack chain, regardless of how far the perimeter has extended. The attack process starts with a successful perimeter breach or insider malfeasance, followed by the theft of privileged user credentials, through either poor privilege security management or exploitation of a vulnerability. With privileged user IDs and passwords in hand, an attacker can then move laterally throughout an organisation, seeking its most valuable digital resources. The favorite question to ask a CISO is - are we compliant? At BeyondTrust we recognise that there is no turning back the clock when it comes to our expanding and increasingly complex digital footprint. It is time for organisations to get serious about placing their privileged accounts under tight control, regardless of their digital presence.
Highly regulated industries, such as banking and healthcare, are required to maintain a comprehensive audit trail of privileged user activity. Organisations must establish individual accountability for all privileged users and have the capability of reviewing privileged sessions according to its potential risk. Many are even required to review a specific percentage of all privileged workloads, but manually identifying high-risk activity can feel like searching for a needle in a haystack. Strong privileged access controls enable security teams to predefine commands, actions and activities, create risk scores and easily pinpoint threats in a manner that dramatically simplifies audit and compliance requirements and saves time. The adoption and understanding of cloud native technologies is vital to any organisation’s success. Lines of business are quickly adopting cloud and SaaS technologies, as well as making use of DevOps and IoT devices to drive business value. Without understanding this new environment that you need to defend, it can leave the door open for attackers. As businesses continue their journey of transformation to operate in a digital capacity, the number of attack surfaces continues to exponentially grow. Without some level of discovery and automation, any cybersecurity product will struggle to deliver the protection necessary for the enterprise. It is vital that the tools empower the security team, and work at the velocity of the business. Having a strong understanding of where privilege exists and how to manage secrets will be the key to success. It is also recommended to learn some basic programming skills – python, golang, and shell scripting. More and more services are becoming API driven and automated, so it will become a requirement for cybersecurity professionals. ë
AP R I L 2020
MEA
47
COVER FEATURE
TENABLE
INTEGRATING AND SECURING IT AND OT ENVIRONMENTS IT IS ESSENTIAL IT AND OT PROFESSIONALS UNDERSTAND THE INCREASING ATTACK SURFACE THEIR ORGANISATION HAS TO MANAGE, MEASURE, AND REDUCE FOR RISK.
T MAHER JADALLAH, REGIONAL DIRECTOR MIDDLE EAST, TENABLE.
Where are we exposed? Where should we prioritise? Reducing exposure over time? How do we compare to our peers?
48
A P R I L 2020
MEA
he Tenable Cyber Exposure platform is the industry’s first solution to holistically assess, manage and measure cyber risk across the modern attack surface. It uniquely provides visibility into cyber risk across IT, Cloud, IoT and OT environments, and the depth of analytics to measure and communicate cyber risk in business terms to make better strategic decisions. The goal is to arm every organisation with the visibility and insight to answer four critical questions: Where are we exposed? Where should we prioritise based on risk? Are we reducing our exposure over time? How do we compare to our peers? The tools and approaches organisations are using to understand cyber risk do not even work in the old world of client server, on-premises data centers and a linear software development lifecycle where there is less complexity and more control over security. An asset is no longer just a laptop or server. It is now a complex mix of digital computing platforms and assets which represent your modern attack surface, where the assets themselves and their associated vulnerabilities are constantly expanding, contracting and evolving - like a living organism. The old way of simply scanning on-premises IT devices for vulnerabilities is no longer enough. Today’s IT environment is ever-changing. Different types of assets constantly enter and exit the enterprise, and some are ephemeral – lasting mere seconds or minutes. Another element adding to what is already a complex situation is security teams being tasked to secure operational technology utilised within critical infrastructure. In tandem, the number of vulnerabilities present in hardware and software is also rising, with the severity of each increasing. The result is
security teams with hundreds of vulnerabilities and, even if prioritising by criticality, still have far more than they can possibly handle. Tenable is focused on providing solutions that allow our customers to holistically assess their environment - both IT and OT. Risk-based vulnerability management cuts through the immense volume of data, giving precise focus needed to act swiftly and effectively to focus efforts on the real risks within organisations’ environments. Using machine learning, each vulnerability is analysed and correlated against severity, threat actor activity and asset criticality. This comprehensive visibility is communicated using metrics that align with the business’ risks, so are understood by the board, with the ability to compare their security posture against internal departments and peers. Increasingly we are seeing those whose remit was solely IT cybersecurity being given responsibility for the organisation’s OT environment too. This move makes sense, given the convergence of IT and OT, and how one can be compromised and used to navigate across into the other environment. However, OT environments are very different from traditional networks. Security professionals need to understand what the infrastructure looks like, its inter-reliance and identify vulnerabilities. Finding a solution to any problem begins with acceptance. Effective risk management is built on a unified understanding of the entire IT OT attack surface, which includes ICS devices, IT-based workstations on OT networks and IT networks. It is essential that IT and OT professionals understand the increased attack surface if their organisation is to manage, measure and reduce their business risk. ë
COVER FEATURE
QUALYS
COMING UP: AUTOMATION, CORRELATION, VISUALISATION
AI CAN PLAY A HUGE ROLE IN ATTACK SIMULATION AND USER BEHAVIOURAL ANALYTICS, EXPOSING ANOMALOUS SITUATIONS AT SCALE FOR MORE REFINED ANALYSIS.
I MARCO ROTTIGNI, CHIEF TECHNICAL SECURITY OFFICER, EMEA AT QUALYS.
The most important innovation has been integration amongst platforms, API-based to reduce friction, while augmenting velocity
f we look at the security landscape today, there are hundreds, if not thousands, of vendors in the market. What is more concerning is that – on average – a small organisation uses 15 to 20 security tools, a medium-sized one uses around 70 and a large enterprise could be using up to as many as 130 different cybersecurity solutions. Many of these solutions are specialised, offering very niche functionality but all of them are producing an overwhelming number of events, logs, data. To make matters worse, today’s IT estate is perimeter-less and more ephemeral and geo-fragmented than ever. To combat these challenges, organisations should focus on going back to basics and to develop fundamental capabilities. This means gaining visibility and awareness of what exists across the digital landscape, understanding vulnerabilities and possible breach-points across their environment and prioritising remediation and response. CISOs today essentially want to achieve three goals — risk mitigation, operational efficiency, and sustainable compliance. At an operational level, this requires having complete visibility across the very diversified IT estate; accuracy in detection to minimise false positives and negatives; enriched context about data such as exploitation, exposure, non-discoverable metadata and cyber threat intelligence; an integrated or API-based communication within the same platform, or across solutions, in order to guarantee velocity; and controlled automation in response. Arguably the most important innovation has been better integration among platforms, leveraging API-based integration to reduce the friction, while augmenting the velocity of secure information flows. To a certain extent, artificial intelligence could play a remarkable role in the field of attack simulation and user behavioural analytics, exposing anomalous situations at scale for more refined analysis. Controlled automation will need to
show that a previously existing process or procedure can effectively be executed in less time; a vulnerability lifecycle management solution must prove that the context provided enables proper prioritisation of threats, resulting in a shorter time to remediate. FUTURE SKILLS The focus will shift from hard skills towards more soft skills. Example of these are the ability to quickly correlate contexts, to connect the dots and understand a set of events from a higher holistic standpoint; clarity of communication and the ability to express complex concepts while adapting them to different audience types; and the ability to interpret cyber threat intelligence and map it to events detected by the technology stack. Cybersecurity professionals will need to become a live part of an orchestrated workflow in which they will interact closely with the technology stack — humans will take on the more noble role of making crucial decisions, while repetitive operations and the analysis of large amount of data will be left to an integrated and interoperable technology stack. PRODUCT SUITE Qualys is a provider of information security and compliance cloud solutions. Leveraging a cloud platform architecture, built over the last two decades, integrated combination of 20+ cloud apps enable our 15700+ customers in more than 130 countries to harmonise IT, security, and compliance processes, with the lowest impact on resources, while maximising operational effectiveness and efficiency. Qualys recently announced Vulnerability Management, Detection and Response - a solution that unifies workflows for discovery of what exists in a digital IT estate, detection of the vulnerabilities, enrichment of the context with cyber threat intelligence, understanding exploitability and security posture according to CIS compliance benchmarks, prioritisation of response and remediation with patch management. ë
AP R I L 2020
MEA
49
COVER FEATURE
THALES
IMAGINE YOUR DATA HAS BEEN HACKED BUT NOT REMOVED ONE OF THE GREATEST UPCOMING RISKS INTO 2025 WILL BE ATTACKERS
ALTERING DATA RATHER THAN COMPROMISING IT, CREATING HAVOC IN DATA SENSITIVE MARKETS.
NEIL MCELHINNEY, HEAD OF CRITICAL INFORMATION SYSTEMS AND CYBER SECURITY, THALES MIDDLE EAST.
Behaviour systems can anticipate data breach and loss incidents before they occur with machine learning
50
A P R I L 2020
MEA
A
ccording to the 2020 Thales Data Threat Report, 50% of all corporate data is stored in the cloud, and nearly half 48% of that data is considered sensitive. With multi-cloud usage becoming the new norm for companies, all respondents said at least some of the sensitive data stored in the cloud is not encrypted, and 49% globally indicated that they had experienced a breach. Having the right cloud security in place has never been more critical. As 5G networks are rolled out, IoT continues to expand, and quantum computing creeps closer to becoming a reality, organisations must adopt a more modern data protection and cybersecurity mindset. Unfortunately, many organisations are playing catch up when it comes to cybersecurity as the digital transformation of organisations, along with the acceleration brought about by the Internet of Things, have increased the threats to our digital infrastructure. Until recently cybersecurity was not part of the scope when designing systems, or at best, was added as an afterthought. Given the increasing risk and the stakes involved, security features must be designed and integrated into new solutions during the early stages of their development. Doing so will avoid retrospective stickyplaster solutions that will ultimately leave gaps in defences. Relying on a product to secure a system is not enough; we must adopt a cybersecurity by design approach that embeds cybersecurity across the entire ecosystem. Changes and advances in technology, emerging essential skills, evolving and increasing number of threats are all top issues CISOs face. Though the set of projects, risks and cybersecurity faced by each organisation are unique, there are a set of common concerns faced by all enterprise security executives.
Cloud-related cybersecurity challenges are a significant challenge for CISOs at a time where organisations continue their process of moving more and more of their systems and data out of their legacy data centres to the cloud. CISOs are considering the benefits of adopting zero-trust policies that are used to authenticate and authorise users and devices accessing applications and networks. More mature organisations are looking at cyber resilience and asking what happens to our sensitive data should zero-trust fail? Another challenge CISOs face is successfully adopting an appropriate encryption strategy. Organisations mainly rely on encryption to protect data against specific, identified threats to vital business and customer data. Compliance with regulations also plays a significant role in driving organisations to adopt encryption solutions. However, the leading challenge organisations face is the inability to discover where their sensitive data resides, which creates a barrier to building a successful encryption strategy. Cybersecurity has traditionally been reactive and threat centric. This approach worked when organisations were able to secure their critical data in data centres, they owned and managed. But digital transformation, globalisation, cloud, and workforce mobility have spread data and users far beyond the perimeter of easily walled-off office networks and data centres. The next five years of cybersecurity is going to focus more on behaviour-based systems that can anticipate data breach and loss incidents before it occurs faster and more effectively with the help of machine learning and artificial intelligence. Instead of mitigating the damages after breaches, these solutions will help in preventing data losses from happening before they even
COVER FEATURE
occur. Improving automation is also becoming a critical factor amongst CISOs, as it presents a substantial advantage in cybersecurity in terms of efficiency and resources. Encryption will also become more prevalent. Techniques like homomorphic encryption are already becoming more widespread, enabling data that is encrypted but is still searchable and we are moving towards a point where all communications will encrypt as standard, albeit slowly. Cloud security is another area where we are making advances. Having the right cloud security in place has never been more critical. As 5G networks are rolled out, IoT continues to expand, and quantum computing creeps closer to becoming a reality, organisations must adopt a more modern data protection mindset. While many governance issues will remain, we should see some advances in the standardisation of cloud regulations to address the critical security issues. This will provide transparency around cloud providers’ security practices that relate to their clients, removing the dilemma for a CISO of transitioning to the cloud. When we think of the vectors of attack that we
might see evolve through to 2025, it is likely we will start to see a shift from the theft of sensitive data to more integrity attacks, attacks where data is still present, but it has been altered or changed. This can have significant impacts on financial markets and transactions that are based on data. It is here we will see de-centralised technologies like Blockchain having the potential to play a significant role over the next few years in mitigating such attacks. Indeed, artificial intelligence could also provide a vital line of defence in combination with Blockchain. FUTURE SKILLS We continuously hear about the global lack of cybersecurity skills. Though the gap is slowly closing in some disciplines, especially those related to governance, risk and compliance, we still are lacking the in-depth technical knowledge and skills to understand and defend against sophisticated attacks. The areas of expertise organisations should be recruiting or developing to address this gap are coding, machine learning, reverse engineering, forensics, threat analysis and incident response
Solutions will help in preventing data losses from happening before they even occur
because there is a small subset of the cybersecurity community that can adequately complete these tasks. PRODUCT SUITE Thales has established a cybersecurity competence centre in Dubai that supports a diverse range of Thales cybersecurity products, platforms and services. The regional competence centre allows us to tailor our solutions to local needs by using local expertise, with the ultimate aim of enabling local businesses to adopt a more agile and proactive response to customer needs. The centre extends Thales reach as a global cybersecurity provider, delivering cyber transformation programmes across critical national infrastructure, defence and aerospace. Thales supports over 140 of the world’s largest and most complex organisations, mastering their cyber challenges and delivering tailored solutions to address their specific cybersecurity needs. The Thales Cybels portfolio provides market-specific cyber solutions allowing customers to embrace their digital future. Thales’ end to end portfolio extends across the critical areas of cybersecurity: GOVERNANCE Understanding cyber risk exposure, through the analysis of the latest cyber threats, for specific market verticals and the implementation of strategic roadmaps to mitigate risk and deliver an effective response in the event of a breach. VIGILANCE Real-time monitoring of systems, networks and devices, ensuring an alert security policy and capability to detect, analyse and respond to attacks. DESIGN Ensuring that software, products and systems have security built into the design at all stages of the development lifecycle, through constantly checking for vulnerabilities and testing against all potential exposure scenarios.
The challenge organisations face is the inability to discover where their sensitive data resides
ASSURANCE Delivering regular assessment of cyber maturity, including people, processes and products. INSIGHT Strategic threat intelligence offering market-specific analysis of the latest threats, helping organisations understand their exposure to the latest, most common and severe external threats. ë
AP R I L 2020
MEA
51
COVER FEATURE
AI, QUANTUM COMPUTING WILL TRANSFORM CYBERSECURITY IN THE SHORT-TERM AI AND IN THE LONGER-TERM QUANTUM COMPUTING ARE
EXPECTED TO DRAMATICALLY TRANSFORM CYBER SECURITY SOLUTIONS AS WE KNOW THEM TODAY.
T PAUL VAN DE HAAR, ASSOCIATE DIRECTOR, DIGITAL AND INNOVATION, KPMG LOWER GULF.
The AI engine can learn over time and is capable of understanding a network’s traffic and behavior and spot deviations from the norm.
here are a vast number of cybersecurity products and solutions in the market that perform specific functions and can protect against certain threats. A majority of these products may introduce complexities in terms of integration - as an ideal cybersecurity solution would cover the end-toend stack of cybersecurity requirements. Aiming to fully integrate these solutions across the organisation would enable a holistic view and help protect against more complex cyber threats. Some cybersecurity vendors have identified these limitations and are building out their cybersecurity solutions across the organisation and technology stack. Over the past years, there has been a rapid evolution in technology. Its usage within businesses to build new channels of digital transactions has potentially increased the exposure to cyber attackers as well as malicious insiders. CISOs are struggling to find resources to handle the daily and constant barrage of cyber events. In the current to near future, artificial intelligence innovation will likely be, a big driver for the cybersecurity industry. AI makes use of advanced algorithms to help identify malicious attacks based on the behaviors of applications and the behavior of the network. In the distant future, quantum computing may play a big role in the cybersecurity industry, as it can easily break current security protocols,
In the distant future, quantum computing may play a big role, as it can easily break current security protocols
52
A P R I L 2020
MEA
meaning there may be a need for newer and more advanced security technologies. AI-driven cybersecurity solutions may allow for analysis of much larger volumes of information across organisations’ networks, emails, files, and websites in a smaller fraction of the time required by humans. The AI engine can also learn over time, which means it is capable of understanding a network’s regular traffic and behaviors and spot deviations from the norm. Where these activities were previously performed by the security team, instead of focusing on finding threats, the security team can focus on responding to incidents. FUTURE SKILL SETS In order to keep up with the rapid digitisation of businesses and the constant evolving cyber threats, the next generation of cybersecurity professionals may require a combination of both technical skills and soft skills. Technical skills would cover a broad range of specialisations across IT infrastructure, software development, architecture, and databases. Soft skills are also important as they define the personal attributes of an individual, such as business understanding, leadership, communication, analytical thinking, collaborative, and writing skills. PRODUCT SUITE For KPMG, the solutions are agnostic. KPMG advises clients on the products and solutions that best suit their requirements. KPMG Cyber Security has four service lines to help organisations build their desired cyber capabilities l Strategy and governance to predict cyber risks. l Transformation to implement adequate cyber security controls and prevent cyber incidents. l Cyber defense to detect cyber security incidents in a timely manner. l Cyber response to contain and eradicate cyber security incidents. ë
COVER FEATURE
MANAGEENGINE
AI, ML SYSTEMS MAY BE HACKED BY PRIVILEGED USERS IN FUTURE, TRACKING PRIVILEGED USERS WILL BE IMPERATIVE SINCE AL, ML, SELF-LEARNING SYSTEMS, ARE VULNERABLE TO THEIR ACTIONS.
P RAJESH GANESAN, VICE PRESIDENT, MANAGEENGINE.
The goal of identity mapping is to hold users accountable for their actions amidst automation and self-learning systems.
rominent limitations of cybersecurity solutions include the lack of largescale threat analytics that leverage ML for both structured and unstructured data, the inability to empower end-user devices to detect threats and initiate the first-level response, general lack of context about the overall IT environment, and poor integration capabilities with other IT components. It is worth mentioning that to effectively leverage the benefits of cybersecurity solutions, organisations need to be self-aware and undergo a cultural change. A major pain point with the current generation of tools is the lack of ability to support the recent changes in technology and user behaviour. An unfortunate scenario like the current global pandemic has turned things upside down with organisations scurrying to enable employees to work remotely, and for CISOs, this has been a huge source of stress. Despite figuring out the logistics, if the current security tools are inadequate, it is a careerdefining call for most CISOs to allow remote work. Making the call to allow remote work can be risky, especially if, for example, the organisation’s endpoint security solution lacks the ability to automatically enforce restrictions based on the geolocation of the user or the device they are using to access enterprise information. Other pain points include bring your own device environments, the growing number of IoT devices in the infrastructure, SecOps becoming more agile with DevSecOps, enabling just-in-
Organisations need the ability to trace actions back to a human user.
time privileges for users, and integrating security tools for the quickest possible incident resolution process. These everyday pain points can be effectively addressed with a suite of solutions that take a central approach to information security. Another innovation is strong identity mapping across the entire infrastructure to combat privileged internal users who can create duplicate identities to carry out motivated internal attacks. The goal of identity mapping is to hold users accountable for their actions amidst all the automations and self-learning systems. Malicious insiders can intentionally train AI models wrongly to carry out certain actions. This is why organisations need the ability to trace actions back to a human user. Given the significance of the security orchestration, automation, and response approach and its growing adoption, ManageEngine is in a position to put together operations and security products from its suite that increases the value of customers’ investments. This suite of solutions can be integrated to deliver security orchestration, automation, threat analytics, and rapid security incident response from one central location. Like in the other areas of technology, the next generation of security products are adopting specific operating principles that help CISOs stay at the top of their game. The next generation of products will be self-aware, be able to self-learn, and guarantee optimal security levels without requiring constant human intervention. The processing and decision-making model will move to the edge—meaning processes, decisions, and implementation will move closer to the user— to enable rapid response from each user and each device who is under attack while a central engine detects and orchestrates a response. Solutions will also move to Zero Trust models for all information access and operations and enforce just-in-time privilege elevation for all users, regardless of their position in the organisation. This shifts the operating model from understanding where the data is and where all it flows to building layers of security to protect it. ë
AP R I L 2020
MEA
53
INNOVATION
RUNNING AI APPLICATIONS ON ORACLE’S EXADATA PLATFORM
INSIDE ORACLE’S EXADATA DATABASE PLATFORM, DATA DOES NOT TRAVEL AND IS IMMERSED IN ALGORITHMS, AND LATEST COMPUTING, NETWORKING, STORAGE.
being mined for intelligence and insights is only 2% to 5% of the total volume, points out Chung Heng. While there is a huge amount of data that can be used for modelling, people also need to spend a huge amount of time preparing the data for modelling. This leads to the low rate of conversion for modelling of data into insights. “What is important in artificial intelligence is that you need to analyse high volumes of data. When you have high volumes of data, you need to be able to bring everything together. With Oracle’s Exadata and Engineered Systems you can actually reduce the bottleneck from reading the data source,” points out Chung Heng.
HAN CHUNG HENG, SENIOR VICE PRESIDENT, SYSTEMS EMEA JAPAC, ORACLE.
n B Y: A R U N S H A N K A R
W
hile artificial intelligence has been around for the last 50 years, its use cases have only recently been looked at seriously. The reason for this is artificial intelligence requires large volumes of data that have only recently become available as unstructured data, crossing the volumes of data available in relational databases. “90% of the world’s data has been created in the last two-three years and 90% of the data are not in relational databases. They are all in big data, social media feeds. Every day tons of data are coming in through IoT and 5G will bring in even more data,” says Han Chung Heng, Senior Vice President, Systems EMEA JAPAC, Oracle. While social media, social collaboration, smartphones, are adding to the volumes of unstructured data, the actual amount of data
54
A P R I L 2020
MEA
EXADATA DESIGN Oracle’s Exadata has the unique strength of combining machine learning and artificial intelligence solutions within the same environment of computing, networking, and storage. “Our design point for Exadata is very simple. We bring storage and compute to the database so that data does not have to travel. This makes it very fast and this is our design point for Exadata. We also bring algorithms to the database,” explains Chung Heng. The traditional way of generating insights and intelligence from data has been to make data travel to where applications and algorithms are hosted. It was all about how people are going to bring data to the algorithms and do modeling. And that means the data has to do a lot of traveling. This puts pressure on building performance capabilities to make data travel. Exadata has been designed to bring algorithms to the database, and build compute, storage and networking around the database. “The combination of our database and our Exadata allows us to do analytics very fast, says Chung Heng. AUTO INDEXING By bringing computing, storage, networking, closer to the database, Oracle is helping to boost the efficiency of applications that are built on algorithms of machine learning and artificial intelligence.
Generating insights from a database also implies that the data is well indexed. The larger and more complex the data, the longer it takes to index the database. However, once indexing has been completed, data retrieval is much faster. “Indexing is required to help you get the information you want fast. Now for many years when you do indexing it takes a long time. It took us about 15 years of experience to index about close to 9,000 indexes. With the new database and new Exadata we are able to reduce the 15 years to around 10 hours. Obviously, they were 6,000 indexes,” adds Chung Heng. Auto indexing is now an in-built feature in the Exadata platform and works in conjunction with the algorithms of machine learning, and artificial intelligence. UNIFYING DATA While large amounts of unstructured data are being generated, they also need to be consolidated into data lakes and then integrated with relational databases before algorithms can be applied to complete the contextual analysis. As an example, closed circuit TVs capture millions of images across the globe at any particular time. How do you link face recognition with biometric thumb print and identity card information? “People are trying to pull big data into data lakes but they have not unified them. We are unifying big data and structured data into one pool. And we are using machine learning to make sense and combine it together to analyse both big data and relational data to make sense of what you have,” explains Chung Heng. Engineered Systems from Oracle help to unify the data from structured and unstructured sources. Engineered Systems have Oracle’s Data Fusion platform that is using NoSQL and data integration tools. A NoSQL database provides a mechanism for storage and retrieval of data that is modeled in means other than the tabular relations used in relational databases. NoSQL databases are increasingly used in big data and real-time web applications.
INNOVATION
Unifying both structured and unstructured data.
Exadata inbuilt features.
AP R I L 2020
MEA
55
INNOVATION
Energy saving by using the Exadata platform and training data in the cloud
TRAINING THE DATA Once the multiple databases have been unified, the data needs to be trained or modelled. Training the data is a compute intensive operation and demands large amount of energy. Training of data is meant to recognise certain trends, would be very specific to an industry, and would require algorithms. Chung Heng advocates training and modelling of the data in the cloud and not on-premises. Training or modelling of the data needs to be done only once, and therefore is better suited in the cloud. Once the data has been modelled, testing of the data and production can be done on-premises. By moving the training of data into the cloud, end users can use the complete computing, networking, and storage power of the Exadata platform to run the use cases of artificial intelligence. The overall process to develop an artificial intelligence use case, is to build the training and modelling of data in the cloud, then move the testing of data on premises, and as the model develops, move it into production, again on-site. For all these stages algorithms need to be embedded in the processes. If training of the data is moved to the cloud, the full power of Exadata’s computing, networking and storage can be used for test and development and production. Reinforces Chung Heng, “This is very good since it provides for green technology innovation. Sustainability is a very important part of the process. ĂŤ
EXADATA
The Oracle Exadata Database Machine is engineered to deliver better performance, cost effectiveness, and availability for Oracle databases. Exadata features a modern cloud-enabled architecture with scale-out high-performance database servers, scale-out intelligent storage servers with state-of-the-art PCI Flash, and an ultra-fast InfiniBand internal fabric that connects all servers and storage. Algorithms and protocols in Exadata implement database intelligence in storage, compute, and InfiniBand networking to deliver higher performance and capacity at lower costs than other platforms. Exadata runs all types of database workloads including Online Transaction Processing, Data Warehousing, In-Memory Analytics as well as consolidation of mixed workloads. Simple and fast to implement, the Exadata Database Machine powers and protects your most important databases. Exadata can be purchased and deployed on premises as the ideal foundation for a private database cloud, or it can be acquired using a subscription model and deployed in the Oracle Public Cloud or Cloud at Customer with all infrastructure management performed by Oracle.
BIG DATA AND NOSQL
A NoSQL database provides a mechanism for storage and retrieval of data that is modeled in means other than the tabular relations used in relational databases. NoSQL databases are increasingly used in big data and real-time web applications. NoSQL systems are also sometimes called Not only SQL to emphasise that they may support SQL-like query languages, or sit alongside SQL databases. Motivations for this approach include: simplicity of design, simpler horizontal scaling to clusters of machines which is a problem for relational databases, finer control over availability and limiting the object-relational impedance mismatch. The data structures used by NoSQL databases that is key-value, wide column, graph, or document are different from those used by default in relational databases, making some operations faster in NoSQL. The particular suitability of a given NoSQL database depends on the problem it must solve. Sometimes the data structures used by NoSQL databases are also viewed as more flexible than relational database tables.
56
A P R I L 2020
MEA
INNOVATION
ACCELERATING DATA ANALYTICS TO DELIVER FASTER INSIGHTS NETAPP BIG DATA STORAGE SOLUTIONS WERE DEVELOPED TO MEET EXTREME ENTERPRISE REQUIREMENTS FOR SPLUNK, HADOOP, NOSQL MONGODB DATABASE WORKLOADS.
NetApp has developed validated reference architectures for main vendors in this space like Splunk, Hadoop, Cloudera, NoSQL MongoDB.
WALID ISSA, SENIOR MANAGER, PRESALES AND SYSTEMS ENGINEERS, MIDDLE EAST AND AFRICA, NETAPP.
hidden patterns and behavior. The mining of big data for meaningful insights has several use cases in different industries. E-commerce companies, for example, can use this information to tailor advertisements to a specific audience. Effective solutions for big data analytics should have the following characteristics: REDUCE COST Avoiding copying the same data multiple times. Maintaining data availability and performing at 33 to 66% less storage overhead.
D
ata is growing at a speed that no one could have predicted 10 years ago. The constant influx of data being produced needs to be stored somewhere – just think of the amounts of data created by technologies such as CCTV cameras, driverless cars, online banking, credit card transactions, online shopping, machine learning, or social networking. In the past, it was estimated that 90% of the world’s data have been generated during the past two years. With such large amounts of data, it is imperative for organisations to analyse it and to discover
FLEXIBILITY Achieving huge operational advantages by modifying the compute layer at will and non-disruptively scaling storage and compute independently. INTEGRATE INTO CLOUD Running analytics on-premises or in the cloud without worrying about where the data sits within the organisation. OPTIMISE COST AND PERFORMANCE Freely moving data across heterogenous storage tiers based on its age or usage allowing efficient utilisation of infrastructure.
IN-PLACE ANALYTICS Avoiding moving massive amounts of data and adding infrastructure – rather have it analysed in-place. Today, organisations are looking for ways to improve speed and responsiveness of applications that control their critical business operations. Because application performance is a key driver for time to market, revenue, and customer satisfaction, it is crucial that companies operate at the highest levels with maximum efficiency. NetApp has built its software technology to enable customers to accelerate data analytics by 50% or more to deliver faster business insights and results. In addition, NetApp customers can build their data lake on the most open, and scalable platform in the industry. NetApp big data storage solutions were developed to meet extreme enterprise requirements for customers’ Splunk, Hadoop, and NoSQL MongoDB database workloads. NetApp big data storage solutions are open, scalable, and backed by comprehensive support to deliver the consistent high performance and maximum uptime NetApp customers need to stay ahead. NetApp provides a wealth of resources that make it easy for NetApp customers and partners to be a successful IT professional. With a broad range of certifications and training to choose from, NetApp partners and customers can gain the specialised knowledge needed depending on the technology and level of expertise. These certifications vary from associate, professional, specialist to expert level. This will enable IT professionals to maximise their effectiveness and demonstrate their expertise when it comes to deploying big data analytics projects. Since NetApp solution is designed and built to take into consideration the main big data analytics players in the industry, the vendor has developed validated NetApp reference architectures for main vendors in this space like Splunk, Hadoop, Cloudera and NoSQL MongoDB workloads. Therefore, certification and experience with these technologies is always an added advantage. ë
AP R I L 2020
MEA
57
INNOVATION
HOW SAS IS DEMOCRATISING ANALYTICS ACROSS VERTICALS
THE SAS PLATFORM IS ABLE TO HANDLE THE COMPLETE DATA LIFECYCLE FROM SOURCE TO ANALYTICS TO FORM INDICATORS FOR INTELLIGENT DECISION-MAKING.
SAS provides an open platform that caters to the entire data application life cycle
S
ABED HAMANDI, REGIONAL DIRECTOR PROFESSIONAL SERVICES, MIDDLE EAST AND AFRICA, SAS.
AS main mission is democratising analytics for organisations by enabling all personnel to access and consume analytics as per their clearance, requirements and duties. It includes IT staff, decision makers, and citizen data scientists. SAS solutions are deployed across several industries; from banking, public sector, energy, utilities, retail, telco to healthcare SAS try to cater the needs of every business entity. In banking, the SAS platform employs applications such as fraud detection, money laundering and others which are applicable to scalable degrees across many financial institutions. In government entities, SAS software and platform offers applications for security intel-
SAS is cloud ready which means SAS can run products on the cloud remotely as well as in hybrid scenarios
58
A P R I L 2020
MEA
ligence, smart cities, and national security as well. In healthcare and life science, SAS offers consultant applications centering on diagnostics. In manufacturing and energy, SAS offer supply chain optimisation as well as energy forecasting. In communications and telecom sectors, SAS does customer intelligence and network analytics. SAS is always on the lookout for new ways to utilise data for the benefit of the business regardless of size. The SAS platform is flexible to address customer needs and as the company has been an expert in data analytics for more than 40 years, SAS has a lot of experience in addressing specific customer challenges with a data driven approach. SAS, is a data solutions provider and alsoan institute. SAS has an academic programme, where we teach a course on the SAS language and the platform is taught and adopted in several universities and educational institute. SAS also has an education programme where SAS provides certification for several technology trends and career paths such as data science certifications, big data, analytics certifications, and so on. In addition to the classroom training, SAS also provides online training as well free training sessions for anyone who wants to learn the SAS language or platform. SAS provides an open platform that caters to the entire data application life cycle. This platform is powered by artificial intelligence, which provides several capabilities centered on machine learning, natural language processing, computer vision, forecasting and optimisation. The SAS platform is able to handle the whole data lifecycle from source to analytics to finally form indicators for decision-making. As an open platform, SAS is cloud ready which means SAS can run products on the cloud remotely as well as in hybrid scenarios such as on premise and on cloud. SAS platform is compatible with any database or data source, as well as having streamlined infrastructure requirements such as servers, databases and storage. This means that the platform is scalable and can cater to any size business from SME’s to multinationals. Í
REAL LIFE
WHY TRAVEL BUSINESS SEERA MOVED TO AWS PUBLIC CLOUD
FACED WITH REBUILDING ITS DATA CENTRES OR MOVING TO PUBLIC CLOUD, TRAVEL FOCUSED SEERA GROUP, SELECTED AWS AS PART OF ITS CLOUD FIRST STRATEGY.
C
Andy Isherwood, Managing Director, Amazon Web Services EMEA: Seera has been at the forefront of understanding the power of cloud technology to bring transformation to the travel industry.
ompetitive pressures and disruptive forces have changed the rules of the game in many industries. Scalability and agility have become pivotal. The travel industry is no exception: the legacy travel model is being replaced by digital entities with disruptive business models and wider partnerships. There has been a seismic shift in the way people procure their travel toward digital channels, transparency in pricing, ease to benchmark, ease of use, breadth of offers, and partnerships. Seera established in 1979 is the leading provider of diverse travel services in the Middle East. The Tadawul-listed holding did not have an extensive online presence until 2015. Given the shift in buying patterns toward digital channels, the company decided to push aggressively toward an online model in order to stay relevant in the market. The decision to move toward a cloud model for its online entities Almosafer and tajawal was based on fundamental factors of cost, scalability, and security. In 2015, Seera’s management team decided to respond to the shift away from legacy travel models. The decision to be made was whether to use a cloud model or to leverage and build up Seera’s existing legacy infrastructure to support its online business. Based on its criteria, Seera’s board and new management decided to adopt a singlevendor cloud strategy to support the birth and expansion of its online brands. Seera conducted due diligence and found that the public cloud model would reduce costs, support rapid growth across the region, and support the company’s key big data initiatives. All this was achieved without undermining the critical security and privacy of data. The choice Seera faced with moving to a new digital business model was whether to draw on internal resources and build a state-of-the-art data center or go directly to the cloud. The overwhelming view from the board of directors
AP R I L 2020
MEA
59
REAL LIFE
and management was that cloud was the better option. A cloud service would deliver on the four main criteria that the company planned to benchmark: scalability, decentralisation, security, and cost-effectiveness. The scalability factor was critical given the seasonal nature of the travel business. A cloud strategy was the preferred option with the board and management, and there was no need to canvass buy-in from stakeholders. Seera’s board of directors was concerned about the issue of data residency and privacy. Incountry data residency is not yet mandated by law in Saudi Arabia. But Seera needed to consider the implications in case there is a future change in requirements, given it was leveraging AWS regions in Frankfurt and Dublin. AWS was the cloud service provider of choice for Seera. Ovum’s data ICT Enterprise Insights 2018-19 shows AWS as the number one public cloud provider in the Middle East, with nearly 40% of respondents stating they run more than 20% of their workload in AWS. The approach Seera adopted was straightforward. It wanted to partner with the leader and an established service provider in the Middle East. That made the decision to go with AWS obvious. Seera found that AWS was by far the leader in the region at the time and had the largest set of enterprise customers. At the time, Seera found that Microsoft Azure did not have enough presence in the Middle East, and Google targeted a different segment of the market and also did not have much of a presence. Seera was not able to make price comparisons, because AWS’s rivals did not offer the same level of services. The only alternative option it could compare for ROI was building its own data centers. The overall cost savings expected and achieved are in the range of 35% to 40%, which Ovum believes is on a par with or slightly ahead of the industry average.
CLOUD MIGRATION The rollout and implementation went quickly and smoothly. Seera hired a new team for this project, since its existing IT resource did not have enough cloud, AWS, or DevOps experience. In the early stages, it relied heavily on AWS online tools and resources. As the consumer travel division of Seera grew rapidly, with annual net book value reaching over SAR2bn, $530m by 2018, Seera’s activity and consumption caught the attention of AWS, which approached the company directly to offer guidance and support. Seera has leveraged AWS platform to build an enterprise-wide big data architecture, which
60
A P R I L 2020
MEA
it will use for predictive analytics and machine learning to curate future offerings that match the expectations and demands of its customers. These analytics plans are core to Seera’s founding principles of customer centricity. The company will strive to build products and services that directly meet the needs of its customers. The big data platform stores both structured and unstructured data, which includes all travel-related searches by its customers on travel on social media, all interactions, transactions, HR, procurement, and other sources. Seera chose AWS because of its high levels of security, its broad and deep portfolio of cloud services. In less than six months, Seera migrated
70+% of its mission critical applications to AWS and adopted a microservices architecture to increase agility. The group worked with AWS to re-architect its technology stack, which includes moving Seera’s legacy application development process to Amazon Elastic Kubernetes Service, Amazon EKS. This enabled Seera to develop new products and services quickly and at scale, allowing the group to be more agile and responsive to customer needs across all vertical businesses, including its consumer travel brands Almosafer and tajawal. Seera uses Amazon EKS to manage more than 1,000 containers in production. As a result, the business has seen a 65% improvement in applica-
Abdulrahman Mutrib, CTO and EVP of Technology, Seera Group: We have a cloud-first strategy, and have selected AWS as our preferred cloud provider.
REAL LIFE
tion performance, including faster response time for customer search results. Prior to this move, some customer holiday searches on Seera’s online booking platforms were taking approximately five to eight seconds to produce results, now customers get results in under two seconds.
BENEFITS AND GAINS
The decision to move toward a cloud model for online entities Almosafer and tajawal was based on cost, scalability, and security.
AWS SERVICES USED BY SEERA n
n n
n
n
n
n n
Amazon EC2. This is computing capacity in the cloud that Seera leverages to support both online portals. Amazon RDS. RDS is used to operate and scale databases for Seera. Amazon ECS. This is a container orchestration service that Seera leverages as it migrates most of its applications on Docker containers. Amazon Redshift. This is a data warehousing service that powers up and stores all the mission-critical workloads for the online portals. Amazon EMR. The open source framework is used by Seera to analyse the vast amount of data that it stores and collects daily to support decision-making. Amazon CloudWatch. This is used by its IT team to monitor applications and infrastructure to ensure all are running optimally. Amazon S3. Seera stores and protects its vast amount of data on S3. Amazon IAM. Security remains core to Seera, and Amazon Identity and Access Management is the foundation for its cloud security framework.
Seera also relies on AWS data analytics services to quickly and cost-effectively analyse data gathered from travel related searches, customer interactions, transactions that have been executed, and other sources. It took the group less than four months to build a sophisticated data analytics platform that connects over 20 data sources, using services such as Amazon Redshift. This platform has helped the company optimise marketing costs and as a result reduced the cost-to-revenue ratio to less than 10% this year. Seera believes this platform will help give the company an edge as it harvests the data to understand where customers are going or are interested in going. This allows the company to customise its products and services to meet constantly changing needs and demands. Seera has set up its own team of data scientists to design real-time analysis tools that ultimately personalise the experience for every single customer, whether through its app or online. Seera has also been able to carry out targeted marketing campaigns that led to improvements in sales and optimisation of marketing costs. It has been able to reduce its cost-convert-torevenue, ratio to less than 10% this year. This is an internal benchmark the company uses to gage the effectiveness of reaching out to new customers, to support and scale up quickly and meet all the demands, and to avoid losing potential revenue. Seera would like to further leverage AWS to bring all its entities onto AWS under a single unified cloud infrastructure. This will include its businesses serving the public sector, hospitals, and others. Seera plans to develop microservices across its operating entities once it consolidates on a single platform. Seera also plans to roll out blockchain. This is still at the experimental stage, but it will be largely used to improve working relationships and accountability with all its suppliers. The plan is for Seera to work with AWS on emerging and complex technologies. Finally, the company plans to improve its AI-chatbot capabilities for a better customer engagement experience. ĂŤ
AP R I L 2020
MEA
61
PEOPLE
Emitac appoints Mohammed Nimer as the new Head of Sales
SentinelOne appoints Roland Stritt as Senior Director Channel EMEA SentinelOne, the autonomous cybersecurity platform company, has announced the appointment of cyber industry veteran Roland Stritt as Senior Director of Channel for EMEA. Stritt will be responsible for driving channel engagement across the EMEA region to deliver hyper growth and value for SentinelOne’s growing community of committed partners. With two decades’ experience in senior sales and partner management roles at cyber and infrastructure vendors including Palo Alto Networks, Roland Stritt joins SentinelOne
Emitac has appointed seasoned specialist Mohammed Nimer as the new Head of Sales for the company. With over two decades of IT and managerial sales experience within UAE and Middle east, Nimer possesses impressive account planning and channel management expertise, and his appointment adds to the strength of Emitac’s senior management. Born in 1976, Mohammed Nimer is an alumnus of the University of Lincoln, where he pursued his MBA. Married and a father of 3 children, Nimer is supremely committed towards achieving his personal and professional goals. In his leisure time, he enjoys reading and playing football.
Aruba names Sherifa Hady as EMEA Channel Sales Director Aruba, a Hewlett Packard Enterprise company, has announced the appointment of Sherifa Hady as the Channel Sales Director for Europe, Middle East and Africa. In her role, Hady will oversee the channel team, working closely with them to build partnerships with resellers and distributors across the region, exploring new and existing opportunities for mutual business growth. Prior to her new role at Aruba, Sherifa spent 18 years with HPE, building experience of working closely with partners in the region. Her roles have included Distribution Director, Channel Manager, and managing the Retail and Consumer Business Unit in the Middle East and, most recently, as the Managing Director for HPE in South Africa.
from Rubrik where he was formerly Director of EMEA Channels.
Veeam appoints cybersecurity veteran Gil Vega as CISO
Nutanix appoints Sylvain Siou as Vice President Systems Engineering Nutanix has announced that it has appointed Sylvain Siou as Vice President, Systems Engineering, for the Europe, Middle East and Africa region. Having formerly been Senior Director, Systems Engineering, EMEA, in his new position, Siou will take a more strategic role in supporting Nutanix’s expansion in EMEA, whilst continuing to have overall responsibility for the company’s growing team of systems engineers in the region. With almost 30 years’ experience in the technology and media sectors, Siou joined Nutanix as Manager, Southern EMEA, Systems Engineering, in 2013, being promoted to Senior Director EMEA, Systems Engineering, three years later.
62
A P R I L 2020
MEA
Veeam announced that Gil Vega has been appointed Chief Information Security Officer. Vega, His previous experience includes serving as Managing Director and CISO at CME Group, and as the Associate Chief Information Officer and CISO for the US Department of Energy and US Immigration and Customs Enforcement in Washington, DC. Vega will be responsible for establishing and maintaining Veeam’s vision and strategy to ensure its information assets and solutions are adequately protected. He will be pivotal in driving strategies to help customers protect their critical data across multiple environments and ensure regulatory compliance.
Centrify appoints Chris Peterson as VP, Worldwide Channels Centrify has announced the appointment of Chris Peterson as Vice President of Worldwide Channels and Alliances. In this role, Peterson will accelerate Centrify’s rapidly-growing channel partner ecosystem and will be responsible for leading all aspects the company’s global channels and alliances. Peterson brings more than 30 years of enterprise channel, sales, and marketing experience to Centrify. He was most recently Vice President of Global Channels at Tenable, where he designed, built and executed a robust channel and managed security service provider programme featuring a roster of blue-chip customers.
A series of thought-provoking and leadership stirring conversations built around critical topics
WebSummit Schedule APRIL 12, 2020 Business Continuity in challenging times
APRIL 23, 2020 Is digitization the only vaccine for an affected economy?
MAY 07, 2020 Cloud migration Much needed than ever
APRIL 14, 2020 Intelligent Automation
APRIL 16, 2020 Empowering borderless enterprises
APRIL 30, 2020
MAY 01, 2020
Workplace collaboration and effectiveness
Workforce reskilling and transformation
MAY 14, 2020 Unifying global ICT committees
BROUGHT TO YOU BY
ORGANIZED BY
MAY 20, 2020 How technology enables economy amidst crisis