Showing posts with label data storage. Show all posts
Showing posts with label data storage. Show all posts

Tuesday, 12 June 2018

Security Add Ons Are Crap & Don't Protect Data


In the last couple of weeks, we have participated in several industry events, including the recent SAPPHIRENOW event hosted by SAP. I am a big supporter of these types of events as it is invaluable to be able to learn, share information, monitor market trends, and perhaps most importantly, speak with customers and have one-on-one conversations on what problems they need addressed and what they are currently lacking.

It is evident that organizations are looking to increase their value and maximize their technology investments by moving many business-critical applications to the Cloud. There are obvious benefits to this – cost savings, more efficiency in operations and enhanced ability to leverage analytics for more focused business decisions are just a few to name. However, to move all of this forward, customers are looking for new and innovative ways of protecting their critical business and data assets in our very volatile and breach-prevalent market. Security is challenging enterprise progression, and after attending several events recently, it is clear there is a discrepancy between the perception and reality by vendors on what customers actually want to fix this.

Companies and vendors continue putting out “new” solutions that are simply add ons to existing security investments, but it seems that customers are fed up with the security industry “add-ons” for promised enhanced security, as time and time again, the same old vendors are promising new and exciting solutions to protect companies and their data, yet major breaches keep happening.

I will be blunt – security add ons are crap. They are just a patch to stop bleeding so to speak, but they are not permanent solutions and they certainly are not innovative and new. Now, I am not saying that all current security solutions are crap, but we have had the current security practices for over a decade now, and while they have definitely worked in some cases, there are other well documented ones where they have blatantly not. This alone tells me that we need to re-evaluate how we are protecting our systems and data.

I am not saying that companies should stop purchasing specific security applications, CASB's, Firewalls, VPN's etc., but instead of bolstering the current systems with new patches and add ons, it is time that we ask ourselves if we are doing it right and providing enough trust and security to enable organizations to allow their customers to use that data correctly. Where we need to focus our security efforts is on the data itself, both at rest and in transport. The core focus must be on protecting the data at the foundation level.

Given that a business will easily spend millions to protect access to data, it would only make sense to secure the data itself as it comes through and sits in your database. But wait, you say we do that, right? Well yes, this happens with encryption, but there is a flaw - current database systems can encrypt stored data, but it is carried out in a way that anyone (human or machine) that has access to the system at any administration level generally also has access to the plain unencrypted data. This leaves a big come get me sign. That’s why at BOHH Labs we believe in offering database or specific field level security. All data that needs to be secured is removed from the source, encrypting it and storing it separately without changing the structure, enabling prioritization and control over every data point. We do this because it stops the inside hacking job. If the database does not contain the data, then a malicious actor who has gained root or admin privileges cannot run a simple query on the data, extract it, and have it available to them to sell to whoever they like, unlike traditional TDE Data Encryption or homomorphic encryption technologies!

By putting our security focus on the data itself, not just where it is coming from, where it is stored or being transacted to, it enables better protection for both external and internal threats that customers desperately need.

Thursday, 31 May 2018

Data Storage: From Then to Now & What’s Still Needed Ahead


- Becca Bauer

Data storage has in fact been around for hundreds of years and has gone through a number of changes before arriving at the cloud storage era we have currently arrived at. Starting in the 1720’s, punch cards were introduced and eventually became the first tool for data storage and recording. Since then data storage has gone through a radical evolution including the introduction of magnetic tape and then the first hard drive invented by IBM in 1956. This was followed some 20-30 years later by the introduction of floppy disks, CD-ROM and DVDs. Next, the USB flash drive arrived on the scene in 2000 and dominated storage from several years until cloud storage entered the market and was debuted by Amazon Web Services in the early 2000s and took a major hold in 2006. Since then, the use of the Cloud has become increasingly popular for data storage and brings us to the present-day climate.

While there are many clear benefits to moving the Cloud, there are also several flaws revealing themselves that indicate the storage market is in need of a continued evolution. For example, recent studies are indicating that moving storage from in-house to the Cloud won’t achieve cost savings unless the storage needs are fully assessed, and anticipated savings are planned out. In fact, over-estimating storage capacity is one area that can make a dent in the savings. While estimating a higher capacity can secure better cloud storage rates from vendors, if you don’t have enough data to meet this higher capacity, you are essentially paying for unnecessary and wasted space.

Another major challenge to the current cloud data storage model is data security. Most organizations turning to cloud storage solutions hold a mix of data that often includes sensitive and protected personal information in their databases that they have a responsibility to keep protected, such as PHI (Protected Health Information), PII (Personally Identifiable Information) and GDPR (Global Data Protection Regulation). Unfortunately, current database systems can encrypt stored data, but this encryption is carried out in a way that anyone (human or machine) that has access to the system at any administration level generally also has access to the plain unencrypted data. This design flaw leaves a “come get me” sign that has led to many diverse organizations becoming victims to data theft and losing millions of dollars.

So now that we have highlighted what is missing from the current cloud storage systems, what is the solution?

Enter BOHH Labs introducing the next phase of data storage, Secure Data as a Service (SDaaS) that puts a focus on both the actual security of the data and removes wasted spend with a storage consumption model. SDaaS acts as a layer between the user/application and the back-end data store and enables total security on all your stored data, without changing the data structure, while making certain data points visible only to those with the correct permissions. Whether this is in a database or a document, the BOHH SDaaS enables full use of data without the security concerns. This solution uniquely offers database or specific field level security that businesses desperately need. All data that needs to be secured is removed from the source, encrypting it and storing it separately without changing the structure, enabling prioritization and control over sensitive data such as PHI, PII or GDPR. We do this because it stops the inside hacking job and it also enables companies can choose which data to store with full knowledge of data confidentiality/ sensitivity. This kills the flaws within the current storage market and enables stored data to be securely opened to the Cloud, without putting it at risk of breach.

All of this is done without impacting user accessibility and it is introducing secure storage as a consumption-based model, rather than the current

Thursday, 24 May 2018

What’s the Point of Analytics if You Can’t Access Them?


- Becca Bauer, Director of Marketing & PR

In the workplace, data has become the golden ticket for companies to drive sales and stay competitive. However, much of the focus has been on the development of analytics and using data insights gathered on your marketing, sales, customers, products, new leads and so on to grow market share. All of this sounds good – hey it’s basically free marketing advice generated from your own information - but while this focus serves marketing and finance purposes, this emphasis fails to address the fundamental need of how we actually access those insights.

Big amounts of data is nothing new. It has always existed. Granted, not in such quantities as we have today with all of our applications and collaborative sharing tools, but document management has been holding a large amount of data since the 80s and email storage has been “big” ever since the late 90s. The onset of nonstop data being produced from everything from web history, emails and documents to contracts and CRM systems continues to grow daily, even hourly, enabling organizations to access corporate knowledge that is more relevant and targeted than ever. And as we move forward, there is no foreseeable end because we as a digital society produce a massive amount of data constantly that needs to be housed somewhere.

One major issue many companies are having is that they are looking to Cloud vendors and deployments to store historic or archived data in their infrastructure, as opposed to in the company’s own data center, and this often means recent data or even just 12-months old data get archived. The problem with this is, once the data is stored, how are companies easily able to access this data to extract business value or analytical insight to help businesses remain competitive? This is a big need! After all, how are companies supposed to take a targeted approach to their data and see if patterns emerge that can better be applied to high-value business decision to increase their bottom line if it is all archived and not easily accessible?

Access to data is the critical function here. Add to the fact that securely accessing stored data is an increasing challenge for companies, as often the data they want to examine contains confidential data such as PII (Personal Identifiable Information) and PHI (Personal Health Information), and it’s difficult for companies to guarantee the security of this sensitive data accessed by users.

So, what is the solution to putting your analytics and insights to use?

This is where BOHH Labs can step in and help. Our Secure Storage as A Service (SSaaS) acts as a layer between the user/application and the back-end data store and enables total security on all your stored data. This is done without changing the data structure, while making certain data points visible only to those with the correct permissions. Whether this is in a database or a document, the BOHH SSaaS solution enables full use of data without the security or accessibility concerns.

Our solution uniquely offers database or specific field level security. All data that needs to be secured is removed from the source, encrypting it and storing it separately without changing the structure, enabling prioritization and control over sensitive data such as PHI, PII or GDPR. If you know which data fields or rows contain sensitive data, companies can better protect these fields to ensure business compliance and enable data to be utilized by a wider audience to extract greater business value or insight, while still securing it and only providing access to those who have the correct privileges to see it.

As the enterprise market continues to become more digital and the amount of data we produce rapidly grows, it will be even more important that secure access to this data is simple. The ability to to manage your continually growing data and extracting more accurate results to deliver valuable analytics will be critical for businesses to stay competitive.

Tuesday, 22 May 2018

Why a Cloud Consumption Model Should Replace Pay as You Go for Data Storage



- Alan Jamieson, VP of Business Development


In a previous blog, we highlighted why planning your Cloud storage requirements is the only way to ensure your company achieves operational savings moving to the cloud.  Today, we are going to look at the various consumption options:

Pay as you Go

Subscription (fixed term, monthly fee per user or unit) based commercial models have been around for several years driven by Customer Relationship Management vendors such as Salesforce, Infrastructure as a Service (IaaS) vendors such as VMware, and Information Technology Service Management (ITSM) vendors such as ServiceNow, who all enable us to pay for services we use, typically based on user number pricing bands. This pay as you go approach has also been widely adopted by the leading Cloud vendors who companies are turning to streamline operations and offerings.  However, this approach is more limited when you look at Cloud data storage. Typically Cloud vendors look to companies to their Cloud infrastructure by charging them lower rates for storing historic or archived data in their infrastructure as opposed to in the company’s own data center. This often means recent data or even just 12-months old data get archived. The problem with this is, once the data is stored, how are companies easily able to access this data to extract business value or analytical insight to help businesses remain competitive? This is a big need!

Research also shows that companies are paying money for storage that they currently don’t need, as they either have too much in-house storage capacity or they have estimated and invested more than their businesses need today for Cloud storage. Regulation is often the main driver for companies to retain transaction data and customer data for a defined number of years, but unless there is a data retention policy, storage investments in this area can be an unnecessary expense. Companies should only retain data for specific periods of time, exceeding these period is an overhead to the business.
It’s clear there is a struggle to find the right balance of leveraging the Cloud to streamline the collection and storage of a company’s increasingly growing data without wasting money. As detailed above, the current standard method of pay as you go is not setup to help companies cost-efficiently move their storage to the Cloud. 

So, what is the solution?

BOHH Labs believes introducing a consumption-based model to the storage market can help companies maximize the benefits of moving storage to the Cloud without paying for resources they don’t actually need. Subscription (consumption-based) fixed term agreements are paid monthly or quarterly and can help businesses to start achieving operational savings with small initial investments that grow through greater use of the service and increased user adoption over time. This approach allows companies to pay for the resources they need without overestimating on resources that roll in to wasted costs, yet still allows them to expand as they grow. This model will be beneficial for all companies – those with a small number of employees to global enterprises with hundreds of thousands to benefit from the same services. 

Within the consumption model, we believe it needs to be split into two areas:

  1. Data storage:
    As discussed above, companies should choose the right data storage period and commercial model to support their individual businesses, and thus pay for storage based on volume or data retention period.
  2. Data acces
    This is an area that is included in user subscription agreements such as CRM, but if not, it is an area that all companies need to explore to understand how they can gain business value from data they store. Stored data serves companies no purpose if it cannot be accessed easily to leverage insight and analytics from it t apply to their business decision-making. 

What Does this Look Like? 

When companies run a marketing campaign, they typically include all their active target customers to help ensure that they gain the maximum return from the planned campaign.  However, when a global financial services or health provider needs to make longer term investment decisions based on historic data over several years, securely accessing this stored data, which often contains confidential data such as PHI (Personal Health Information), PII (Personal Identifiable Information) is not available, as they cannot guarantee the security of sensitive data accessed by business users.

BOHH Labs has identified this business challenge and has a created a Secure Storage as a Service solution that ensures that all stored sensitive data remains secure and confidential.  If you know which data fields or rows contain sensitive data, BOHH Labs protects these fields to ensure business compliance. As such, the BOHH service leverages a consumption model to provide a secure way to enable your noncompliant data to be utilized and have the cost of storage recovered from it as its value is extracted. By protecting the compliant data, securing it and only providing access to those who have the correct privileges to see it, allows longer period (often years) non-compliant and non-corporate sensitive data to be utilized by a wider audience to extract greater business value or insight.


Thursday, 17 May 2018

Post Industry Event POV: It’s Clear Customers Are Fed Up with New Security “Add-Ons”


BOHH Labs VP of Business shares his thoughts on BOHH's attendance at the GDS Security Summit.

Last week BOHH Labs attended GDS’s Security Summit in Atlanta, GA.  The summit was well attended with CISO’s and VP’s of Security from global enterprise accounts in the finance, healthcare, manufacturing sectors etc.

It was evident that global enterprise accounts across all market sectors are looking for innovative ways of protecting their critical business and data assets.  The desire to move from data center to cloud is prevalent and often cost driven but mitigating the risk of data breaches is the main obstacle to be overcome by organizations. Additionally, as part of the discussion on security challenges, there is an increasing need to avoid further data breaches and meet new compliance regulations as Friday May 25, 2018 is fast approaching when the new General Data Protection Regulation (GDPR) becomes effective and impacts all global customers with European Union (EU) member customers.

One thing was made very clear: Companies and customers have been searching for new solutions and are keen to avoid buying another security solution that is layered on existing security investments. They are fed up with the security industry “add-ons” for promised enhanced security. The same old vendors are promising new and exciting solutions to protect companies and their data, yet time after time major breaches keep happening.

BOHH Labs was honored to take part in this industry discussion and present its new solution to help address the security challenges plaguing customers and organizations alike. We were delighted with the reaction to our new Secure Storage as a Service (SSaaS), which enables companies to protect compliant and confidential data fields while importantly enabling analytical insights to be gained without the risk of a data breach.

We demonstrated our service on a cloud platform to highlight how our solution is platform agnostic and show how compliant plus non-compliant data residing in a Hadoop data platform could be searched for analytical insights and the compliant data (i.e. PII, PHI) fields only being accessed by authorized users.

Seldom has the BOHH Labs team comprising of Simon Bain – CEO, Ken Hawkins – CTO and Alan Jamieson – VP Business Development seen such a positive and enthusiastic reaction to new technology.  Perhaps it was showing the Secure Storage as a Service working on a cloud platform and accessing data in a Hadoop data platform that validated how powerful and importantly how relevant our service is?  We left the summit upbeat with our message and solution resonating with most of the
conference attendees.

All in all it was a great industry event and if you want proof and to learn more, contact us and we will be happy to place a POC on your storage system, to show how we secure, scale and enable easy access to your valuable information stores.

Thursday, 26 April 2018

Stop Throwing Away Money on Data Storage (Even When Moving it to the Cloud)


- Alan Jamieson, BOHH Labs VP of Business Development

Does moving your data center storage to the Cloud (Private/Hybrid) help with saving operational costs on increasingly challenged IT budgets?  For most people, this is an automatic answer, yes; however, recent studies are indicating that moving storage from in-house to the Cloud won’t achieve cost savings unless the storage needs are fully assessed, and anticipated savings are planned out. This is alarming, and you may ask why?

Firstly, capacity planning is an issue: how much do we need today and in 12 months’ time?  Over-estimating storage capacity is one area that can make a dent in the savings. While estimating a higher capacity can secure better cloud storage rates from vendors, if you don’t have enough data to meet this higher capacity, you are essentially paying for unnecessary and wasted space.

Secondly, while over 80% of data centers have the storage capacity in-house, it is difficult to do routine checks, so when looking to switch and invest in Cloud storage, companies often don’t have the whole picture and can be making a choice that is often not financially beneficial. The fixed costs (electricity, cooling, licenses and maintenance) of running a data center and any spare storage or processing capacity is often overlooked when formulating your cloud migration/deployment strategy.

The volume and variety (structured and unstructured, regulated data etc.) we are collecting is increasingly on an annual basis.  Data is now seen as a business asset with new Chief Data Officer roles in enterprise accounts being created, but are we realizing the value of the data assets we have?

From research done by Jonathan Koomey in late 2017, only 25% of companies would save money if they transferred their server data directly onto the Cloud, whereas 75% would see an increase in annual costs. However, all the sample group would save if the companies migrated after quantifying out how much server space they need. This unnecessary Cloud storage spends costs companies around the world an estimated $62 billion annually.

If we step back from the cost of storage, the other important and increasing challenge for global companies is extracting the value from data that is stored in the Cloud and often is not accessible.  With the massive amount of data being produced daily, operational cost challenges are pushing companies to store data over 12 months or even more recent too soon. The world has become analytically focused; however, insight is only gained when data over a significant number of years is analyzed to extract the insight to achieve greater operational efficiencies, greater insight in how to retain your customers and how to improve the quality of manufactured parts.

Another research report puts the cost of Cloud waste at about 35%. So, for every dollar spent on Cloud resources, you only get $0.65 investment value. Now that we have addressed how companies are losing money, below are six ways your company/department can alleviate some of the wasted

Cloud spend:

  1. Identify and retire abandoned applications – why store what is no longer needed?
  2. Choose the right storage model – What is needed today and plan.
  3.  Right-size instances – Invest in only what is needed.
  4. Perform licensing audits – Do your software vendors enable your licenses to be used in the Cloud at no extra cost?
  5. Automate server usage for peak/off peak hours – only pay the Cloud provider for services that are needed.
  6. Pay upfront – Looking at license options could save more than purely monthly subscription fees.

While the global market is focused on enhancing how data is stored and embracing the benefits of making a transition to the Cloud, having a clear idea of want storage is needed and how often you need to access your data will ensure that you select the most cost-effective model for your business.

Tuesday, 10 April 2018

How to Flip Data Security into a Driver for Cloud Adoption, Not an Inhibitor


It’s no secret the Cloud brings enormous advantages to companies and the way they interact with data. Cloud environments offer companies the ability to share, store and access data from anywhere on any device at any time. As such, more companies are embracing digital transformation and integrating cloud services to their architecture strategies to enhance business agility, efficiency a new revenue stream, and let’s not forget the cost savings in terms of operations, personnel and technology updates.

To meet these demands, big data centers want to be able to open data access to the Cloud, yet organizations hold sensitive and protected personal information in their databases that they have a responsibility to keep protected, such as PHI (Protected Health Information), PII (Personally Identifiable Information) and GDPR (Global Data Protection Regulation) data that is held within them. Unfortunately, current database systems can encrypt stored data, but this encryption is carried out in a way that anyone (human or machine) that has access to the system at any administration level generally also has access to the plain unencrypted data. This design flaw leaves a “come get me” sign that has led to many diverse organizations becoming victims to data theft and losing millions of dollars.

This puts current data centers at a conundrum – Cloud-based data storage will help facilitate better use and collaboration of data housed, but the sensitive nature of the data and risk of breaching these compliance regulations is challenging adoption.

Security is still the most important concern for customers wanting to give Cloud access to their data stores. Now that we’ve seen how important data security is, what if you flip the switch and provide complete protection of Cloud data storage?

Strong risk management and data integrity systems can help companies avoid breaches and better manage disruption to operations, turning strong data security into a driver not an inhibitor for embracing Cloud environments.

But how does this work?

Enter Secure Storage as a Service. While the market has various related offerings: public Cloud, IaaS, PaaS, etc., secure data storage is not available. BOHH Labs is introducing a Bring your own storage (BYOS) capability which offers databases or specific file security that businesses desperately need. This enables on premise deployments to actively prioritize applications, databases or infrastructure to a lower cost, and secure cloud deployment without impacting user access.  Companies can choose which data to store with full knowledge of data confidentiality/ sensitivity.

Our solution removes the sensitive data from the source, storing it separately, enabling prioritization and control over sensitive data storage. This kills the flaws within the current storage market and enables stored data to be securely opened to the Cloud, without putting it at risk of breach, flipping the switch on data security making it a driver, not an inhibitor.