The Wayback Machine - https://web.archive.org/web/20161012152710/http://security.sys-con.com/node/3921843

Welcome!

Cloud Security Authors: Kevin Jackson, Elizabeth White, Liz McMillan, Maria C. Horton, Ed Featherston

Related Topics: OpenStack Journal, @CloudExpo, Cloud Security, Government Cloud

OpenStack Journal: Blog Feed Post

Military Tips on Business Resiliency | @CloudExpo #API #Cloud #BusinessIntelligence

Business resiliency enables organizations that have suffered a damaging incident to bounce back to their former form

A steel bar is resistant to stress and is capable of maintaining its form while bearing large loads. While steel is also known as one of the world's strongest metal's (Titanium, Tungsten and Iconel round out the top four), it is also susceptible to shearing and completely breaking. A rubber brick, on the other hand, will bend easily under even small loads, but it's extremely difficult to snap or break. Moreover, once the load is removed from the rubber, its flexibility returns it to its original form. This is how the rubber brick displays resiliency.

Photo credit: Shutterstock

Business resiliency enables organizations that have suffered a damaging incident to bounce back to their former form. This is especially important for small and medium sized businesses because according to Tim Francis, enterprise leader for cyber insurance for Travelers, 60% of all cyberattacks in 2014 struck small to medium-sized businesses.  If you think company strength will protect you from this type of adverse incident, you are mistaken. Since salary and benefits for the workforce represents one of the largest expenses for a company, the "Revenue per employee" ratio is often used by investor as a measure of company strength. This ratio is most useful when comparing companies within the same industry. Using this ratio, the following companies were fairly strong before they were attacked but they didn't have the resiliency to bounce back afterwards:

  • Code Spaces (Annual Revenue $2.4M, Employees: 12, Revenue/Employees: $200,000)  was cited by SC Magazine as one of nearly 60% of small businesses that fail within six months of being hacked. The company was accessed through via its Amazon Elastic Compute Cloud control panel. The attackers attempted to extort the business by claiming a "large fee" would resolve data loss issues. Code Spaces was unable to continue operations as it acknowledged that the company had suffered debilitating damages to both its finances and reputation.
  • In 2011 Distributed.it (Annual Revenue: $691,092, Employees: 2, Revenue/Employees $230,364)  had secured 10% of the market for Australian domain names, held multiple international domain accreditations and had 30,000 hosting clients through 3,000 active resellers. Later that year the business suffered a severe cyberattack when attackers targeted and destroyed servers inside Distribute.IT's network, including back-ups, then locked the IT team out, meaning the only way to get control was to ‘pull the plug' at the datacenter

By way of comparison, in 2015 the revenue per employee ratios for IBM and Panasonic were $244,447 and $275,839 respectively.  So how should a company build up resilience against a cyberattack?

Years of conflict have taught the military how to build resiliency and researchers with the National Center for Post Traumatic Stress Disorder (PTSD) have actually developed a scale to rate psychological traits that promote resilience. Called the Response to Stressful Experiences Scale (RSES), the measurement has been tested in more than 1,000 active-duty military personnel and identifies six factors that are key to psychological resilience:

  • Positive outlook
  • Active coping
  • Self-confidence
  • Learning and making meaning
  • Acceptance of limits
  • Spirituality

With this as guidance, business leaders can take the following steps towards building cyber resiliency within your organization:

  • Build a positive outlook by educating senior management on the cyber threat and the practical steps that can be taken to prevent economic and reputational losses;
  • Actively cope with the threat through an active cybersecurity defense team with the responsibility to protect corporate assets;
  • Build self-confidence by periodically testing your cyber defense and business continuity processes;
  • Establish a continuous learning environment through regular and relevant training events for the entire staff;
  • Understand your limits and manage cyber risks that can't be eliminated; and
  • Believe in your team

In addition to these worthwhile leadership activities, more pragmatic steps should include:

With any luck, these steps will not only make your company more resilient, but it may also help you prevent the debilitating effect of a cyberattack.

This post was brought to you by IBM Global Technology Services. For more content like this, visit Point B and Beyond.

Cloud Musings

( Thank you. If you enjoyed this article, get free updates by email or RSS - © Copyright Kevin L. Jackson 2016)

Follow me at http://Twitter.com/Kevin_Jackson

Read the original blog entry...

More Stories By Kevin Jackson

Kevin Jackson, founder of the GovCloud Network, is an independent technology and business consultant specializing in mission critical solutions. He has served in various senior management positions including VP & GM Cloud Services NJVC, Worldwide Sales Executive for IBM and VP Program Management Office at JP Morgan Chase. His formal education includes MSEE (Computer Engineering), MA National Security & Strategic Studies and a BS Aerospace Engineering. Jackson graduated from the United States Naval Academy in 1979 and retired from the US Navy earning specialties in Space Systems Engineering, Airborne Logistics and Airborne Command and Control. He also served with the National Reconnaissance Office, Operational Support Office, providing tactical support to Navy and Marine Corps forces worldwide. Kevin is the founder and author of “Cloud Musings”, a widely followed blog that focuses on the use of cloud computing by the Federal government. He is also the editor and founder of “Government Cloud Computing” electronic magazine, published at Ulitzer.com. To set up an appointment CLICK HERE

@ThingsExpo Stories
With an estimated 50 billion devices connected to the Internet by 2020, several industries will begin to expand their capabilities for retaining end point data at the edge to better utilize the range of data types and sheer volume of M2M data generated by the Internet of Things. In his session at @ThingsExpo, Don DeLoach, CEO and President of Infobright, discussed the infrastructures businesses will need to implement to handle this explosion of data by providing specific use cases for filterin...
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at Cloud Expo, Ed Featherston, a director and senior enterprise architect at Collaborative Consulting, will discuss the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
As ridesharing competitors and enhanced services increase, notable changes are occurring in the transportation model. Despite the cost-effective means and flexibility of ridesharing, both drivers and users will need to be aware of the connected environment and how it will impact the ridesharing experience. In his session at @ThingsExpo, Timothy Evavold, Executive Director Automotive at Covisint, will discuss key challenges and solutions to powering a ride sharing and/or multimodal model in the a...
The WebRTC Summit 2016 Silicon Valley, to be held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA, announces that its Call for Papers is now open for June 7-9, 2017 event which will take place at the Javits Center in New York City. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 20th International Cloud Expo, @ThingsExpo, Big Data Expo, and DevOps...
In his general session at 18th Cloud Expo, Lee Atchison, Principal Cloud Architect and Advocate at New Relic, discussed cloud as a ‘better data center’ and how it adds new capacity (faster) and improves application availability (redundancy). The cloud is a ‘Dynamic Tool for Dynamic Apps’ and resource allocation is an integral part of your application architecture, so use only the resources you need and allocate /de-allocate resources on the fly.
The IoT has the potential to create a renaissance of manufacturing in the US and elsewhere. In his session at 18th Cloud Expo, Florent Solt, CTO and chief architect of Netvibes, discussed how the expected exponential increase in the amount of data that will be processed, transported, stored, and accessed means there will be a huge demand for smart technologies to deliver it. Florent Solt is the CTO and chief architect of Netvibes. Prior to joining Netvibes in 2007, he co-founded Rift Technologi...
Explosive growth in connected devices. Enormous amounts of data for collection and analysis. Critical use of data for split-second decision making and actionable information. All three are factors in making the Internet of Things a reality. Yet, any one factor would have an IT organization pondering its infrastructure strategy. How should your organization enhance its IT framework to enable an Internet of Things implementation? In his session at @ThingsExpo, James Kirkland, Red Hat's Chief Arch...
“Media Sponsor” of SYS-CON's 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. CloudBerry Backup is a leading cross-platform cloud backup and disaster recovery solution integrated with major public cloud services, such as Amazon Web Services, Microsoft Azure and Google Cloud Platform.
Machine Learning helps make complex systems more efficient. By applying advanced Machine Learning techniques such as Cognitive Fingerprinting, wind project operators can utilize these tools to learn from collected data, detect regular patterns, and optimize their own operations. In his session at 18th Cloud Expo, Stuart Gillen, Director of Business Development at SparkCognition, discussed how research has demonstrated the value of Machine Learning in delivering next generation analytics to impr...
An IoT product’s log files speak volumes about what’s happening with your products in the field, pinpointing current and potential issues, and enabling you to predict failures and save millions of dollars in inventory. But until recently, no one knew how to listen. In his session at @ThingsExpo, Dan Gettens, Chief Research Officer at OnProcess, will discuss recent research by Massachusetts Institute of Technology and OnProcess Technology, where MIT created a new, breakthrough analytics model f...
Video experiences should be unique and exciting! But that doesn’t mean you need to patch all the pieces yourself. Users demand rich and engaging experiences and new ways to connect with you. But creating robust video applications at scale can be complicated, time-consuming and expensive. In his session at @ThingsExpo, Zohar Babin, Vice President of Platform, Ecosystem and Community at Kaltura, will discuss how VPaaS enables you to move fast, creating scalable video experiences that reach your ...
In the next five to ten years, millions, if not billions of things will become smarter. This smartness goes beyond connected things in our homes like the fridge, thermostat and fancy lighting, and into heavily regulated industries including aerospace, pharmaceutical/medical devices and energy. “Smartness” will embed itself within individual products that are part of our daily lives. We will engage with smart products - learning from them, informing them, and communicating with them. Smart produc...
In his keynote at 19th Cloud Expo, Sheng Liang, co-founder and CEO of Rancher Labs, will discuss the technological advances and new business opportunities created by the rapid adoption of containers. With the success of Amazon Web Services (AWS) and various open source technologies used to build private clouds, cloud computing has become an essential component of IT strategy. However, users continue to face challenges in implementing clouds, as older technologies evolve and newer ones like Docke...
SYS-CON Events announced today that Coalfire will exhibit at the 19th International Cloud Expo, which will take place on November 1–3, 2016, at the Santa Clara Convention Center in Santa Clara, CA. Coalfire is the trusted leader in cybersecurity risk management and compliance services. Coalfire integrates advisory and technical assessments and recommendations to the corporate directors, executives, boards, and IT organizations for global brands and organizations in the technology, cloud, health...
The IETF draft standard for M2M certificates is a security solution specifically designed for the demanding needs of IoT/M2M applications. In his session at @ThingsExpo, Brian Romansky, VP of Strategic Technology at TrustPoint Innovation, explained how M2M certificates can efficiently enable confidentiality, integrity, and authenticity on highly constrained devices.
Businesses are struggling to manage the information flow and interactions between all of these new devices and things jumping on their network, and the apps and IT systems they control. The data businesses gather is only helpful if they can do something with it. In his session at @ThingsExpo, Chris Witeck, Principal Technology Strategist at Citrix, will discuss how different the impact of IoT will be for large businesses, expanding how IoT will allow large organizations to make their legacy ap...
One of biggest questions about Big Data is “How do we harness all that information for business use quickly and effectively?” Geographic Information Systems (GIS) or spatial technology is about more than making maps, but adding critical context and meaning to data of all types, coming from all different channels – even sensors. In his session at @ThingsExpo, William (Bill) Meehan, director of utility solutions for Esri, will take a closer look at the current state of spatial technology and ar...
Amazon has gradually rolled out parts of its IoT offerings, but these are just the tip of the iceberg. In addition to optimizing their backend AWS offerings, Amazon is laying the ground work to be a major force in IoT - especially in the connected home and office. In his session at @ThingsExpo, Chris Kocher, founder and managing director of Grey Heron, explained how Amazon is extending its reach to become a major force in IoT by building on its dominant cloud IoT platform, its Dash Button strat...
According to Forrester Research, every business will become either a digital predator or digital prey by 2020. To avoid demise, organizations must rapidly create new sources of value in their end-to-end customer experiences. True digital predators also must break down information and process silos and extend digital transformation initiatives to empower employees with the digital resources needed to win, serve, and retain customers.
Big Data, cloud, analytics, contextual information, wearable tech, sensors, mobility, and WebRTC: together, these advances have created a perfect storm of technologies that are disrupting and transforming classic communications models and ecosystems. In his session at @ThingsExpo, Erik Perotti, Senior Manager of New Ventures on Plantronics’ Innovation team, provided an overview of this technological shift, including associated business and consumer communications impacts, and opportunities it ...