Red Hat continues to make inroads into the enterprise storage software market, improving two of its core storage technologies and striking partnerships with key IT system resellers.

The company has updated both its Ceph and Gluster storage system software, in time for the Red Hat Summit, the company's annual user conference, held this week in Boston
[ Survive the data explosion -- InfoWorld tells you how to meet the challenge of the onslaught of petabytes before it overwhelms your company. | Stay up on best practices and news with InfoWorld's Storage newsletter. ]
Although Red Hat was initially known for its corporate-ready version of Linux, Red Hat Enterprise Linux, it has been expanding its open source-based stack to accommodate additional needs of large organizations, including software to manage large amounts of storage.

Red Hat took over the stewardship of the open source Ceph file system last year when it purchased Inktank Storage. It brought the Gluster file system, also open source, into the fold in a 2011 acquisition.

Gluster can be used for setting up storage clusters to hold large amounts of data, such as log files for big data analysis. Casio and Intuit both use Gluster.

Ceph, on the other hand, is ideal for cloud workloads, particularly those that need object-based storage. It is frequently paired with OpenStack cloud deployments. Yahoo uses Ceph to store for its Flickr photo sharing system. Because Ceph is open source, Yahoo was able to tweak the software to work more efficiently for its own case load.

With Ceph Storage 1.3, Red Hat used contributions from Intel and SanDisk to equip the software to work with solid state flash devices. Flash is quickly becoming the predominant medium in today's servers, said Ranga Rangachari, Red Hat vice president and general manager for storage and big data.

Ceph has also been improved for virtual environments. The software can boot up more quickly in virtual machines, thanks to the use of read-ahead caching. Work has also been done to limit disk fragmentation, when blocks of data are distributed about a disk in such a way that it is difficult to quickly read them all.

Ceph 1.3 is also smart enough to not let bureaucratic meddling slow performance at crucial times. It can block routine automatic administrative checks from taking place during periods of peak usage, when they could slow responsiveness. Developers also refined the software so that routine functions will run faster, such as resizing, deleting or exporting blocks of data.

Gluster got some new capabilities with its update as well.

This is the first version of the software that does not require RAID (redundant array of inexpensive disks) technologies to ensure data integrity, meaning organizations could save on storage hardware by as much as 75 percent, given they would not have to buy the additional storage to make duplicate copies of the data.


Gluster can now also guard against bit rot, or the gradual decay of files on disk that can, over time, render them impossible to read.

Gluster can now also take the place of hierarchical management systems, which offload old or less consulted data to less costly, slower storage systems. Gluster now offers operators fine-grain control of where to store data.

Red Hat struck a few deals with other IT service providers to expand the potential customer base for its storage software. About 60 percent of commercial Ceph or Gluster sales are done by Red Hat itself, but the rest are executed by partners, Rangachari said.

Systems provider Supermicro, which has offered Gluster systems, is now offering Ceph-based storage systems to its customers as well. Multimedia optimization software provider Vantrix has packaged Red Hat Gluster Storage into its Vantrix Media Platform to provide organizations with a way to store, archive and serve large amounts of content.

At the Summit, Red Hat also demonstrated some storage technologies it is currently developing. It showed off software that allows administrators to manage a diverse array of different types of storage systems from a single console. This software should be released later in the year, Rangachari said.
Read More

The enterprise is facing a dangerous combination of mounting cybersecurity threats of increasing subtlety and a widening gap in the skills required to identify and combat them. Knowing how to lead the charge in identifying and analyzing threats, creating strategic security plans, and ensuring compliance, requires the right level of expertise. Many businesses, especially small and medium businesses, simply don’t have it.

Last October the Information Systems Security Association spoke of a “missing generation” in information security, pointing to an estimated 300,000 to one million vacant cybersecurity jobs. 

Clearly it’s going to take time to fill that gap, but if the talent isn't available right now, what are companies supposed to do?

The Right Person for the Job

According to Cisco’s 2015 Annual Security Report, 91% of companies have an executive with direct responsibility for security, but only 29% of them have a chief information security officer. Businesses with a CISO in place recorded the highest levels of confidence in their security stance, both in terms of optimization and clarity.

Many organizations are asking other executives to step into the gap and they often lack the expertise required to outline a solid information security policy and drive it forward. There may be areas of your business where you can afford to have employees feeling their way and learning through trial and error, but security is not one of them.

“For small to mid-sized businesses it may be difficult to justify the expense of a full-time CISO,” says Candy Alexander, CISSP, CISM and Boston GRC consultant. “Recruitment can also be a real challenge. How do you find the right fit for your business within your budget when you lack the internal experience to properly evaluate a candidate?”

Enter the Virtual CISO

Perhaps it’s time to consider a less traditional approach. There are lots of reasons to consider a virtual CISO. If you’re suffering from attrition and need someone to step in on an interim basis, if you want some supervision and advice for a relatively green infosec manager, or if you want to ensure that you only pay for what you actually need, then a vCISO could be the answer.

For smaller businesses it simply doesn’t make sense to invest in a full-time CISO when you can hire a virtual one and get the specialty skills you need to draw up a strategic overview and deliver the big picture. No need to worry about benefits or monthly overhead.

"A vCISO can be invaluable as a firefighter, but don’t wait until the worst happens: prevention is always better than cure"
It’s a flexible solution. You can set up a retainer for a certain number of hours, you can hire someone on a project basis, and/or you can even buy a chunk of support hours and use them when you need them. It’s a way of getting the cream of security talent for a fraction of the cost. And it's totally scalable. If you decide you need a full-time CISO then you can even have the vCISO help you create a tailored job spec and then screen and interview candidates.

Contracting a virtual CISO can be far most cost effective than hiring a full timer. They can fill in where you need it the most, helping your CIO pull together your security policies, guidelines, and standards. That could entail anything from getting to grips with HIPAA or PCI compliance, to staying on top of vendor risk assessments.

A qualified vCISO is going to be fully up to speed on the latest best practices. They have experience dealing with a wide variety of scenarios, and they are well-placed to train your internal security staff.

Planning for a Brighter Future

Many companies are being forced to spend an ever-increasing proportion of their budget on cleaning up after incidents. A vCISO can be invaluable as a firefighter, but don't wait until the worst happens: prevention is always better than cure.

A deeper dive into potential vulnerabilities, and support with a remediation plan now, could save your organization a great deal of time and money in the long run.

Whether you’re looking to fill a temporary gap, get a snapshot of your security health, or you need some leadership to roll out a comprehensive security policy, the vCISO is a compelling value proposition. Until the new generation of security graduates matures, the vCISO may be your best shot at reducing security risks.


Read More

More than 87.3% of enterprises have adopted Microsoft cloud-based services including Word, Excel, PowerPoint, Exchange Online, OneDrive and Sharepoint Online.

According to research from Skyhigh Networks, released on the eve of the Windows 10 launch, a full 1.37 terabytes of data are uploaded to Office 365 each month by the average organization, equivalent to approximately 1 billion Word documents.

Out of that, about 17.4 percent of documents in Office 365 contain sensitive data. At 9.2 percent, corporate data such as financial statements, business plans and source code makes up the largest percentage of sensitive data stored in Office 365.

And, 4.2 percent of the sensitive data stored in Office 365 was classified as personally identifiable information (PII) such as social security numbers, phone numbers and home addresses. About 2.2 percent of the sensitive data was protected health information, and another 1.8 percent was payment data including credit card and bank account numbers.

Perhaps the most shocking of the report’s findings was that enterprises have an average of 143 files in Office 365 with “password” in the filename.

All of this means that security should be ever more tantamount to companies using Office 365. And notably, there are about to be a lot more of them, considering that the new Office for Windows 10 universal apps require an Office 365 subscription. This should drive adoption of OneDrive and SharePoint Online.

Already, Office 365 has already established a foothold in a majority of enterprises and provides a benchmark for future growth. The majority (87.3 percent) of organizations have at least 100 employees using Office 365, however 93.2 percent of employees are still using Microsoft on-premise solutions. This finding suggests that while Office 365 has tremendous traction in enterprises, it is in the early innings and there is a massive opportunity ahead to transition all employees to Office 365.

Further, the report found that the average large organization collaborates with 72 business partners on Office 365. Top industries collaborating with partners via Office 365 are high-tech, manufacturing, energy, financial services and business services, respectively. This makes Office 365 one of the top “collaboration” services connecting businesses to each other.

While Microsoft offers security for its cloud-based services, many enterprises require an additional layer of protection for corporate data in Office 365.

“It’s important to strike a balance between what tools and services you provide your employees and what security controls to have around those services to track data and manage confidential information,” said Tim Topkins, senior director of security innovation at Aetna. “Companies should look for solutions that make the secure path the easy path. A frictionless approach to visibility, compliance, data security and threat detection on top of a service in demand like Office 365 creates a secure and productive workforce.”


Read More

Tech giant Google is to embark on a UK-wide security roadshow after revealing that over a quarter of people in the country have been either a victim or a target of hacking in the last two years.

Beginning on 7 August, the roadshow will cover five UK cities and over 30 schools and will see Google security experts hosting free workshops and consultations as to how to beat hackers.

Such advice is well merited: a recent survey by Google revealed that 27% of 2000 respondents had their online services, such as an email account or online bank account, hacked or targeted by hackers in the last two years. Just over a third were afraid that their personal information – such as password(s), bank details, or emails – could be taken by hackers and used without their permission.

Alarmingly, a quarter of those surveyed admitted they do not have any kind of security, such as a 4-digit code, pattern lock, or fingerprint scan, to secure their smartphone, despite an increasing amount of important personal information being stored on mobile devices. A tenth reported that personal information had been used online without their permission.

“With a marked increase in phishing, identity theft and consumer data breaches, it is now more important than ever for people to understand how to best protect themselves and their sensitive data,” said Raj Samani, CTO EMEA at Intel Security, a partner for the program.

“Just this year Intel Security discovered that 57% of UK consumers do not believe it is their responsibility to protect their own devices, showing that work needs to be done to educate. Simple measures such as understanding what makes a secure password and how to recognize phishing emails can empower consumers of all ages to use technology safely. With accurate education, preparation and implementation of security measures, we will hopefully see a drop in successful attacks in the future.”

Read More