“By 2025, 80% of organizations seeking to scale digital business will fail because they do not take a modern approach to data and analytics governance.”
News report: “Universal Health Services, one of the largest healthcare providers in the U.S., has been hit by a ransomware attack.” In a ransomware attack, the bad guys probe for vulnerabilities in the target’s computer system. Once in, they enter code that encrypts files, rendering them inaccessible. The hackers will send a decryption key only after the victim pays the demanded ransom.
Plan to be a SOAR winner against ransomware
Ransomware attacks (malware) are happening more frequently than ever before. Every company needs to have a security framework that includes a Security Orchestration, Automation and Response (SOAR) plan to address ransomware attacks. SOAR solutions streamline security operations in three main areas:
1) Threat and Vulnerability (Orchestration)
You need to detect and prevent the security vectors (the pathways into your system used by hackers) that allow ransomware to be installed and run in your company’s network. Threat detection/analysis solutions are constantly updated with the latest security vectors from around the world. These solutions analyze and detect security threats and prevent your environment from being compromised. Detecting, analyzing and removing the latest ransomware/malware versions is a critical first line of threat and vulnerability defense.
2) Incident Response
Okay, you tried your best to detect and prevent all the security vectors from entering your computing environment, but there was that one person who received an email and clicked an attachment or hyperlink. That one click started the download and installation of the ransomware on a computer and its replication to other servers and applications.
Having an Incident Response (IR) plan to address this type of event is critical to stopping and recovering from a malware incident. The Incident Response needs to have easy to follow steps on how to stop and uninstall ransomware from running and propagating within your network.
If Personal Identifiable Information (PII) was compromised, then the General Data Protection Regulation (GDPR) and/or California Consumer Privacy Act (CCPA) may require you to notify the impacted end users within a set timeframe. The Incident Response playbook should detail how to notify those end users whose personal data may have been compromised.
3) Operations automation
Streamlining or automating security practices frees up engineering time that would otherwise be used scanning, patching and resolving security incidences. Automation:
Removes potential human errors (such as typos, wrong admin commands or admin rights to a wrong account) made during regular operational tasks.
Increases operational security by consistently performing manual tasks, removing potential human errors from happening.
Provides standard procedures for Incident Response activities and tasks.
Deploys Identity and Access Management (IdM) solutions to secure and manage user Identity life cycle (identity and access recertification, password management), and access management (SSO, 2FA, PAM) across the enterprise.
Make SOAR part of your security framework and help ensure that your company will stay out of the latest news reports on hackers and ransomware.
Talk with us
You have a vision for your organization – don’t let your technology slow you down. Prolifics Security helps you architect and implement SOAR solutions by discussing and prioritizing security requirements, as part of an overall security framework. Talk with us – let’s discuss your challenges, review and reevaluate your plans and get you started where it makes the most sense. Vision to Value. Faster. It’s not just our tagline, it’s what drives us. It’s how we deliver solutions and services. It’s our commitment to you – and it’s needed today more than ever. Visit www.prolifics.com or emailsolutions@prolifics.com.
About the author
Rob Adachi is Head of Security – Identity and Access for Prolifics and also leads a team of engineers implementing Tivoli security solutions for Fortune 500 companies. He has more than 20 years in the Identity Management field, starting with the early software development of the product that is now known as Tivoli Identity Manager (ITIM). Learn more about Rob here and reach him at Robert.Adachi@prolifics.com.
Prolifics and IBM data science experts discuss getting your tech environment ready for modern data science projects and the use of artificial intelligence (AI). Our team covers key re-platforming considerations, diverse talent and diverse tools, and how to get started with Watson Studio Premium for IBM Cloud Pak for Data.
Out-of-the-box thinking – it’s thinking in a new, imaginative and innovative way that delivers creative solutions with quality results. During IBM’s Think, the Cube’s Victor Dabrinze interviewed our own Kirsten Craft, Head of Business Development and Marketing here at Prolifics, to learn more about this approach and how it helps Prolifics’ clients gain advantage in their space!
Our client is a large, diverse North American company (DNAC) with operations ranging from construction, equipment and shipbuilding to hydro-energy, forestry and logistics.
About our Client
Challenge
An older tech needs an upgrade – fast
DNAC had been running Cognos – IBM’s premier business analytics solution – throughout its entire enterprise. It was an integral and ingrained part of its business, generating thousands of analytic reports that kept the huge business on course and running smoothly.
DNAC’s version of Cognos, however, was older. The company was facing support issues and, looking ahead, the current platform was not going to help them with their ongoing analytic requirements. It just wasn’t sufficient enough for the business needs going forward. For DNAC, the decision to upgrade to the newest solution, IBM Cognos Analytics, was an easy one. Cognos Analytics was released as a robust upgrade, with the features, functions and capabilities that DNAC wanted to take advantage of and build on.
Because Cognos was so essential and ran across the entire DNAC footprint, the challenge was finding a technology partner who could manage a complete upgrade at once – not a piecemeal approach, meet DNAC’s timing requirements, and understood and shared the company’s sense of urgency.
Action
Automated testing seals the deal
Prolifics has worked with DNAC over the years on Cognos planning and analytics pieces, but DNAC had an incumbent company for things like upgrades. However, it became clear to DNAC that the current tech partner would not be able to meet the company’s deadline. DNAC asked us to present our thoughts on an upgrade solution – and the company liked what they heard.
“What they really liked about what we had, which they didn’t see from other organizations, was the whole testing component. Prolifics automated testing is a core expertise of ours that can be an integral part of any project, from its very beginning. So, what impressed them was our capability to expertly upgrade them to the new version and set-up their new environment, combined with the automating testing that everything, like thousands of reports, was working correctly.”
Steve Livingstone is Prolifics’ Regional Sales Director, Canada, and works with DNAC.
Many companies can do Cognos upgrades, while other companies have testing abilities, or the client-company might do their own testing. What DNAC saw was the timing efficiency of both our automated testing and not having to split the project (upgrade and testing) to two organizations.
Result
It’s about the best opportunity
Prolifics is currently in the process of doing the upgrade. Our expertise in upgrading and our automated testing will have the project done – enterprise wide – in the timing DNAC was looking for. DNAC said it was clear Prolifics would have it all tested, working and operating by their deadline.
Steve Livingstone points out that while this client wanted the entire enterprise upgraded at once, it can be done differently depending on client circumstances. “A company that wants to do it in chunks can still take advantage of our process. There’s no need to do things in small increments because of our ability to actually provide a working production environment in a very expedient time, using our know-how and automation. So, while there should be no risk around in going to the new platform in one enterprise move, it doesn’t really matter. If somebody really likes the Cognos Analytics platform, Prolifics gives you the best opportunity to get there in the most expedient amount of time, with the least amount of risk and the most amount of opportunity for success in production.”
Technology
Test automation is an integral part of any project
IBM Cognos Analytics is IBM’s premier and robust business analytics solution for sharing actionable insights and augmented intelligence to drive analysis across your organization. IBM Cognos Analytics helps you clean, combine and find new insights from your data. Create striking, dynamic visualizations and share across stakeholders with ease.
At Prolifics, test automation is an integral part of any project, from its very beginning. We’re always developing new testing accelerators and digital products, while applying AI/ML in innovative ways for optimal performance. A test automation strategy will:
Map business goals to testing requirements – business and technology goals
Identify and design types and levels of test automation to ensure an optimal strategy
Leverage tools and accelerators to increase speed and reduce cost of execution
Implement intelligence when, where and how you need it
Test systems to scale; make them responsive, secure and resilient for optimal performance
Analyze result patterns to better predict potential future outcomes
About Prolifics
Prolifics is a global digital transformation leader with expertise in Data & AI, Integration & Applications, Business Automation, DevXOps, Test Automation, and Cybersecurity across multiple industries. We provide consulting, engineering and managed services for all our practice areas at any point our clients need them. Vision to Value. Faster. It’s not just the Prolifics’ tagline, it’s what drives us. Email solutions@prolifics.com or visit us at prolifics.com.
Statistical Analytics System (SAS) is software used for data analysis. It’s the most widely used data science platform across the globe, so if your organization uses it, you’re in good company. However, SAS is a legacy environment that many organizations find problematic. As with any mature legacy system with tentacles wending their way through an organization’s operating systems, a SAS environment requires a great deal of upkeep — to operate properly, it must be updated and upgraded frequently, which requires purchasing a lot of licenses, and that results in a high cost of ownership.
How Do You Reduce Your Reliance on SAS?
What executives often don’t realize is that there are not only many cloud platform options, but plenty of migration paths, all of which have their own benefits and levels of cost savings.
Why Do Organizations Migrate to the Cloud?
Most organizations cite seven main reasons behind their choice to migrate to the cloud. Read about those reasons here.
Different Migration Paths
Replatform: This migration path requires very few changes to an organization’s existing legacy code. Instead, systems are simply redeployed to a new platform. Some businesses might choose this method as a proof of concept before undertaking a more complex migration method. It also could serve as a migration’s first phase, before shifting to a second.
Refactor: In this migration path, a system’s general functionality is not altered, but legacy code is translated to the Python programming language, and technical debt, which is created when development decisions prioritize speed over design, is reduced. An organization may choose to stop at this point, or refactoring can be a step on the path toward total replacement.
Replace: For a migration that implements a total platform replacement, legacy code is fundamentally rewritten in order to optimize and modernize an organization’s systems and allow them greater ability to innovate. This option requires decision-makers to take part in a Design Workshop, which helps them imagine the possibilities a modern platform would allow and choose the landscape that would best serve them.
What is PAM?
Prolifics literally wrote the book on migrating from a legacy system to a modern cloud architecture environment. Our experts created a business-sensitive Prolifics Agile Migration (PAM) process manual. This manual provides definition, formality and rigor around the process, and provides a jumping off point to create a unique solution for your organization.
Regardless of the path you choose, however, two things are evident: thorough testing is imperative, and Python must be the programming language used to build the new platform.
Why Does the World Love Python?
Python is an agile, sophisticated and robust open-source programming language widely used for data science, and it is the most downloaded one in the world. Dr. G opines that it is above and beyond SAS in data science, and he believes that any organization considering a move to modern cloud architecture has to make Python part of the equation. “The reality is that Python is eroding legacy scripting languages, like SAS,” he said. “These legacy scripting languages evaporate because they’re islands — they are not a part of an integrated system.”
Because it doesn’t require licenses and allows users to pick and choose only the pieces of code they need, Python offers the flexibility and cost savings that legacy scripting languages can’t.
FUN FACT: Legend says that when Guido van Rossum began to implement Python, he was reading scripts of the 1970s BBC television show “Monty Python’s Flying Circus,” which served as naming inspiration. Presumably, he thought “Python” was a better name than “Silly Walk.”
Let Prolifics Take Charge of Your Migration
Prolifics takes cloud migration, which seems to many organizations an insurmountable task, and breaks it down into a series of simple steps that will help your organization reach its modernization goals.
Download the Prolifics Agile Migration (PAM) process manual, Prolifics’ business-sensitive approach to cloud migration
Schedule one of our customized workshops — we offer a range of workshops that can do everything from help you dream of the possibilities that modernization offers to educate your team on how to effectively use the new operating system
Michael L. Gonzales, Ph.D., (Dr. G) is Prolifics’ chief data scientist and an active practitioner in the IT space with more than 30 years of industry experience. He specializes in the formulation of business analytics that give competitive advantages to global organizations. Dr. Gonzales is a successful author, industry speaker, published researcher and lifetime Mensa member.
Our client, an international bank hold company (IB) headquartered in Japan, has an extensive global network of finance and business centers. This story focuses on Prolifics’ work with the North American branch of the organization.
About our client, an international bank
Aligning Culture, Business Outcomes and Technology
Our client’s challenge was one that many companies face. Their middleware, which typically acts like the connective tissue between applications, data and users, was reaching end-of-life. Complicating the issue was that the IB was experiencing this looming concern within the framework of a corporate culture — Ringi — that is not unlike the corporate culture in government organizations or security companies. These organizations often have strict and detailed processes in place that ensure smooth and accurate technology implementation, but these processes can be lengthy and circuitous. The IB required a partner in software architecture who could align with their business culture and support them through the duration of their project.
Managing Through Middleware Selection and Implementation
We entered this project as consultants, helping IB determine the cost of and time to implementation for the middleware software they were considering for purchase. We also helped them ascertain whether their chosen software would meet their needs.
As they drew closer to purchasing the software, Prolifics’ team of experienced software architects and developers began designing the new middleware system to prove that the project could be completed on time and on budget. Based on our guidance, the IB completed the software purchase, and we continued the build, rolling it out in phases.
Project Alignment with Ringi
Throughout the eighteen-month timeline of this project, in adherence to the Ringi process, we oversaw the implementation of new middleware software into IB’s workflow. The IB required us to provide approximately five times the documentation typically required for such an integration so they could have full oversight and ownership of the software and its capability. We were able to fulfill this need while remaining within their project budget.
What is Ringi?
The Ringi philosophy is a common approach to business in Japan. It recognizes that managers are not infallible, and seeks consensus from the majority. Lower-level employees will discuss an idea, reach consensus, then present it to their superiors who then go through the same process. The resulting decision is balanced, taking into account the concerns of many people at an organization. But it’s also time-consuming and can sometimes take years.
Result
Middleware Implementation
IB is now running nearly all of their enterprise traffic through the new middleware system that is state-of-the-art and future-ready.
Ringi Alignment
IB was delighted not only with our work, but with our partnership, and they have continued to engage with us as they move their modernization process forward. We’ve helped them identify and execute additional projects, such as digital transformation and cloud implementation, as they work toward becoming a faster and more nimble global entity.
Technology
To provide the best opportunity for the IB to reach its modernization goals and global standards, the following technology was emphasized:
IBM Integration Bus (IB) – connects applications together, regardless of the message formats or protocols they support. It allows for diverse applications to interact and exchange data and other applications in a flexible, dynamic, and extensible infrastructure.
IBM App Connect Enterprise Software – combines the existing, industry-trusted technologies of IBM Integration Bus with IBM App Connect Professional and cloud native technologies, to delver a platform that supports the full breadth of integration needs across a modern digital enterprise.
Urban Code Deploy (UCD) Tool – automates application deployments through your environments. It’s designed to facilitate rapid feedback and continuous delivery in agile development while providing audit trails, versioning and approvals needed in production.
As kids (okay, and as adults too), we’d gaze at the shapes of clouds in the sky and talk about what they looked like to us. Today, in a technology context, the shape of your cloud takes on a whole new, and much more important, meaning when you’re talking cloud migration.
Whether you’re leaving your on-prem systems behind, or looking to jump from your current cloud set-up, you need to take a hard look at your prospective new cloud homes. Make sure you compare the qualities and benefits in each cloud provider, so you get the combination that’s right for your business goals – not all clouds are created equal.
Here are seven things to think about when you’re gazing at the tech clouds and contemplating migration:
1) Cost. As compared to on-premise, cloud saves you big money on hardware, maintenance and related infrastructure (like climate-controlled rooms). It also frees up IT staff to do more important work. Yet, among the big cloud service providers, things like optimized computing pricing; per second pricing; and available commitment discounts vary, as do data storage and movement costs. While these charges may seem similar on paper, you could save tens, if not hundreds, of thousands of dollars based on choosing the right cloud platform for how your business runs.
2) Scalability. Clouds are certainly scalable. But make sure you only pay for what you need; and know whether you have to purchase access or pay a scheduled fee to scale up or down.
3) Availability and redundancy. What’s the cloud vendor’s uptime guarantee? A 99.95 percent guarantee still means about ½ a workday down in total over a year. But – do uptime guarantees come with any additional costs associated with redundancy? Does it cost you more to get to 99.99 percent?
4) Security and Access. What’s the provider’s approach to security? Have there been any breaches? What enhanced measures are in place? On the flip side, can you access your data at any place (e.g., remotely), method (e.g., mobile) and time?
5) Compliance. Similar to security, does your provider meet all needed provisions for government regulations, like privacy regulations or PII protections? Especially consider the compliance regulations or certifications most important to your industry and company.
6) Compatibility. Again, not all clouds are created equal. There could be compatibility issues with operating systems, apps, image formats – issues you need to know about before you choose your provider, not in the middle of a migration.
7) Lock-in. You may have felt locked-in with your aging on-prem systems or the cloud set-up you’re looking to leave. Don’t let it happen again. Does the provider have high fees for data transition or transfer? Is there a claw back of those original commitment discounts? Know your exit strategy so the next move isn’t a surprise mix of costs and difficulties.
So, keep your eyes skyward and if you need help finding your right cloud shape, feel free to connect with us at solutions@prolifics.com.