Sunday, 11 July 2021

Security and the pandemic

Having spent a number of hours each week talking and writing about security, I kind of assume that it’s a topic that everyone is interested in and that everyone is pretty much clued up about these days. Every company of any size uses external penetration testing (pentesting) experts to check that their systems are secure (even mainframes), and most companies nowadays seem to run dummy phishing attacks just to see which of their employees are still clicking on dodgy links and downloading questionable attachments. So, it was interesting to see the results of the IBM Consumer Survey: Security Side Effects of the Pandemic. The survey was carried out in March by Morning Consult, which asked 22,000 people around the world about their online security habits.

The key findings of the survey were:

  • Global respondents shifted further into digital interactions during COVID-19 and are likely to continue digital-first interactions in life after the COVID-19 pandemic.
  • Across all categories, global consumers created about 15 new online accounts during the pandemic. Younger respondents created more new accounts during the pandemic across categories, and created more accounts across each category than any other age group or generation.
  • Over four in five (82%) global respondents are re-using the same credentials that they have used for other accounts at least some of the time. Younger respondents are more likely to say they always or mostly re-use the same credentials that they have used for other accounts.
  • Many would still rather place an order digitally – even if there were security/privacy concerns. Over four in ten (44%) global respondents, and 51% of millennials would rather place and pay for an order digitally than go to a physical location or call to place an order even if they had concerns about the website/app’s safety or privacy.
  • A majority of global respondents (63%) accessed COVID-related services via digital channels – including mobile apps, websites, email, and text messages.
  • Nearly half (44%) of respondents do not plan to delete or deactivate any of the new accounts they created during the pandemic after society returns to pre-pandemic norms.

The report says that “consumers not only increased their reliance on digital channels during the pandemic, but also that this ‘digital dependence’ is expected to linger even after society returns to pre-pandemic norms. Consumers reported they will continue to rely on digital services at higher rates than before the pandemic, and many say they will not delete any of the new accounts they created during that time.”

The survey found that respondents under 50 are most likely to predict they will interact through digital formats in life after the COVID-19 pandemic. Although the average number of new accounts was 15, millennials created over 18 new online accounts during the pandemic, more than any other generation. The only slightly good news was that the survey found that 56% respondents would remove permission for an application to track behaviour if the app requested permission to do so.

The survey concludes that “consumers’ increased reliance on digital channels during the pandemic may have caused more lax attitudes towards security – with the convenience of digital ordering often outweighing security and privacy concerns. Many consumers (particularly younger generations) say they would rather place an order digitally, even if there were security or privacy concerns with the application. Additionally, consumers rarely decline to use a new digital platform due to security or privacy concerns. This surge in new accounts may also be creating password fatigue, with consumers reporting high levels of password reuse across their accounts. This means many of the new accounts created during the pandemic likely relied on reused credentials, which may have been compromised in previous data breaches.

The survey also found that 35% of respondents have accepted terms they were uncomfortable with so they could use a service. 41% would avoid using an online platform to shop or place an order over concerns over app/website security, and 38% would avoid using online platforms if they had concerns around privacy.

For vendors, a bad online user experience can lead to people giving up on an online purchase, application, or transaction based on negative experiences. 42% said they’d done that when logging in, 41% when signing up, and 41%, again, when completing payment. Younger respondents are more likely to give up than older people. The survey also found that, on average, respondents across all age groups would attempt about 3-4 logins before they decided to reset their login credentials.

While 59% of respondents expect to spend between 1-5 minutes setting up a new digital account, 57% would reconsider setting up a non-essential digital account after spending 1-5 minutes. 44% of respondents keep online account information in their memory, and 32% have it written on paper. And while passwords are the preferred method to log in, respondents under 35 are more likely than older generations to prefer single sign-on or biometrics. It’s good to see that around two thirds of respondents have used two-factor or multi-factor authentication to access an online account. 65% of respondents are very or somewhat familiar with the concept of digital credentials, and 76% of respondents would be very or somewhat likely to use digital credentials.

63% of respondents have accessed COVID-related services via digital channels, and younger respondents were more likely to have accessed COVID related services digitally.

Overall, it’s an interesting, but worrying survey. IBM Security did offer companies the following guidance:

“Zero Trust Approach: given increasing risks, companies should consider evolving to a ‘zero trust’ security approach, which operates under the assumption that an authenticated identity, or the network itself, may already be compromised – therefore, it continuously validates the conditions for connection between users, data, and resources to determine authorization and need. This approach requires companies to unify their security data and approach, with the goal of wrapping security context around every user, every device, and every interaction.

“Modernizing Consumer IAM: investing in a modernized Consumer Identity and Access Management (CIAM) strategy can help companies increase digital engagement – providing a frictionless user experience across digital platforms and using behavioural analytics to decrease the risk of fraudulent account use.

“Data Protection & Privacy: having more digital users means that companies will also have more sensitive consumer data to protect. Organizations must ensure that strong data security controls are in place to prevent unauthorized access – from monitoring data to detect suspicious activity, to encrypting sensitive data wherever it travels. Companies should also implement the right privacy policies on premise, and in the cloud, in order to maintain consumer trust.

“Put Security to the Test: with usage and reliance on digital platforms changing rapidly, companies should consider dedicated testing to ensure the security strategies and technologies they’ve relied on previously still hold up in this new landscape. Re-evaluating the effectiveness of incident response plans, and testing applications for security vulnerabilities, are both important components of this process.”

Good advice.

 

Sunday, 4 July 2021

Mainframes not going away any time soon

The latest research about mainframe market size, market share, application analysis, regional outlook, growth trends, key players, competitive strategies, and forecasts for 2021 to 2029 have been published by Research and Markets.

They say that the global mainframe market is projected to witness a substantial growth, growing at a compound annual growth rate (CAGR) of 3.2 percent during the forecast period from 2021 to 2029, according to a new report added to ResearchAndMarkets.com website.

Not surprisingly, they say that, based on geography, North America led the overall mainframe market accounting for the largest market share in 2020. The region is likely to remain market leader throughout the forecast period from 2021 to 2029. 

The presence of some major players, such as IBM, BMC Software, Dell, and Hitachi Vantara, also supports the growth of the market and is expected to provide lucrative opportunities in the years to come, according to the report. In North America, the USA dominated the regional mainframe market in 2020, and is projected to reign throughout the forecast period from 2021 to 2029, the report claimed.

The report informs us that mainframe manufacturers are adopting strategies like new product development and partnerships to cater for the needs of their customers and gain competitive advantage over other players. The major players in the mainframe market include Atos SE, BMC Software, CA Technologies, Cognizant, Dell, DXC Technology Company, FUJITSU, HCL Technologies Limited, Hitachi Vantara Corporation, Infosys Limited, IBM, LzLabs GmbH, Redcentric, Unisys, ViON, and Wipro, among others.

The full report looks at segmentation by product type, including Z Systems, GS 21 Series, and others. There’s end-use vertical segment, including BFSI, Healthcare, Defense & Government, Retail, Public Utilities, and others (Academics and Research, etc). And there is geography, looking at North America (USA and Rest of North America), Europe (UK, Germany, France, Rest of Europe), Asia Pacific (Japan, China, India, Rest of APAC), and the rest of the world (Middle East & Africa, Latin America).

The list of key questions answered in the report are:

  • What was the market size of mainframe market in 2020 and forecast up to 2029?
  • What are the key factors driving the global mainframe market?
  • What are the key market trends and high-growth opportunities observed in the mainframe market?
  • What are the drivers of the mainframe market?
  • Which is the largest regional market for mainframe market?
  • Which segment will grow at a faster pace? Why?
  • Which region will drive the market growth? Why?
  • Which players are leading the mainframe market?
  • What are the sustainability strategies adopted by the key players operating in the market?

The trouble with any report like this, certainly looking towards the end of the decade is that, obviously, it cannot predict unexpected events. Its biggest assumption is that life will pretty much carry on as normal – and not allow for pandemics and other crises occurring. However, as that’s the way all of us plan for the future, that’s not too much of a criticism.

The good news for those of us who work in the mainframe world is that the predictions are that the mainframe market will continue to grow over the next eight years, which indicates that we will still be in paid employment for the foreseeable future. Although, perhaps our employment prospects might become in doubt as AI and machine learning make experienced mainframers less needed to run these new machines of the future.

And, there’s always the possibility that mainframes will be replaced by fully functional quantum computers in a few years’ time. And that will have a devasting effect on predictions for the mainframe marketplace by the end of the decade.

Perhaps many mainframers are simply hoping that the industry will still be around until it’s time for them to retire!

 

Sunday, 27 June 2021

Computing tomorrow


Following the announcement of a £210 million partnership between the UK government and IBM to support businesses in the adoption of new digital technologies, we wondered what the future of computing might look like.

Amanda Solloway, the science minister, explained that the investment will be put towards the new Hartree National Centre for Digital Innovation (HNCDI). Based in Daresbury, Cheshire, HNCDI will enable businesses to acquire the skills, knowledge and technical capability required to adopt digital technologies like supercomputing, data analytics, artificial intelligence (AI), and quantum computing – according to their website.

The website goes on to say that HNCDI will help organizations and individuals with an appetite for change, who are ready to innovate and create useful solutions, enhance and adapt products and processes, adopt new digital technologies, and expand into new markets. They say they will work with start-ups and SMEs to large corporates, and public sector organizations such as NHS Trusts and local government. And, they offer training on an individual and group basis.

The UK government is investing £172 million over five years through UK Research and Innovation (UKRI), and IBM is contributing £38 million. In addition, 60 more scientists, interns, and students will join IBM Research and the Hartree Centre in the joint Science and Technology Facilities Council (STFC) – IBM Programme.

While we were working from home over a Teams meeting, we started kicking around some ideas of what the future of computing, that they might be researching, would look like. Here are some of the things that were said.

Quantum computing is an obvious goal. The benefits of getting workable quantum computing are enormous, and companies like IBM and Google are regularly making small changes to how the define and measure quantum computing and then making announcements. Quantum computing will be a complete breakthrough in computing when it comes because so much more computing power will become available. One of the consequences of that is that many levels of encryption will be broken by a quantum computer in a relative short period of time (it would currently take hundreds of years using the available technology to break the encryption in use). So, that has worrying implications.

Artificial Intelligence is another obvious goal. AI and Machine Learning mean that computers can not only do straightforward repetitive tasks, but can also learn, make decisions, and perform more complex tasks. This, in turn, allows things to happen more quickly (computers work faster than people, and for longer hours). It should make our lives easier. Cars really could drive themselves, planes could fly themselves, etc. The downside is, of course, that fewer people would be needed because the ‘machines’ would be doing the work. And this has a huge impact on the economy. And, according to the movies, could lead to the formation of Skynet and the arrival of the Terminators!

Data analytics is something that many organizations are enjoying the benefits from using. The traditional model of selling is that person A makes a product and takes it to person B. Person B sells the product in their shop to Person C, who then takes it away and uses it. Data Analytics allows Person B to see what types of product Person C has been buying and is able to suggest to them other products that they might like. And they can do this with vouchers, on social media, via an app on their phone, etc. It’s a way of understanding customers and encouraging them to buy more from you rather than your competitors. Using the information available from data analytics helps a company be more competitive and therefore successful than its rivals.

Supercomputing is all about getting as much computing power as possible so it can be used to answer difficult questions like, “what will the weather be like tomorrow?” IBM has its Blue Gene/P supercomputer and Summit. Other names you’ll hear are Cray and Fugaku Systems. It’s thought that quantum computers could replace the need for supercomputers.

In the near future, mainframes are likely to continue running the amount of work they do. It’s also likely that mainframes and distributed systems will continue offloading parts of their work to the cloud. Replicating data to the cloud makes restoring data quicker and easier and is vital in a business continuity situation.

Security seems to be the biggest challenge. Any computer that people can use (and that’s all of them) is likely to be hacked. Employees, in an unguarded moment, are likely to click on a link or click on an attachment and download a piece of malware that could start the attack. It’s not just the software on a laptop that can be attacked, but the firmware can be as well – meaning that extra levels of security are required. And trusted members of staff can be cynically manipulated by bad actors to steal data or give them access. New security terms are being coined all the time to describe where the focus for security should be placed. Things like ZTA (Zero-Trust Architecture), SASE (Secure Access Service Edge), APM (Application Performance Monitoring), XDR (Extended Detection and Response), and CASB (Cloud Access Security Broker), to name but a few.

Computers getting smarter clearly has a positive impact on businesses and, indirectly, everyone. It makes life easier for them. The downside, unless steps are taken, is that smarter computers make life easier for hackers. As mentioned earlier, quantum computers could break through quite sophisticated levels of encryption. Criminals could use data analytics techniques to identify people who they could most easily manipulate to perform criminal acts. And AI could lead to various doomsday scenarios.

This has been the case with every development ever. It can be used for good or bad. Let’s hope that the developments coming from HNCDI are used for our good.