Tuesday, July 20, 2010

Redundancy is Welcome, Indeed

As a writer, my wife grits her teeth when she sees or hears redundancies. Example: 8:00 p.m. in the evening. But in IT, redundancy is welcome, indeed. Redundancy is instant backup. Without it, a trading company can lose millions of dollars in just seconds or viewers will miss that exciting maneuver in a football game on TV.

I designed, installed and implemented Avon's website (not the graphics) for e-commerce. Later, at Gartner, I designed the redundancy network infrastructure for e-commerce websites so that the sites can function in the event that one site is down. Almost everyone who does online banking has experienced the frustration of trying to check balances, pay bills or schedule transfers at 8:30 p.m., only to get a message that the site is down. At 3:00 a.m., it's understandable, even though many on the West Coast may still be up. Chances are, that bank has a redundancy program that is simply inadequate. The customer won't lose money because the site is down, but the bank may lose customers if it develops a reputation for failure when the end-user needs it at a reasonable time.

Here's the bottom line: get your redundancy infrastructure so that's it's available when customers need it, whether it's 9:00 a.m. in the morning or 9:00 p.m. in the evening.

Tuesday, July 6, 2010

iFixes

It always amuses me to see people rush into the newest technology when it's common knowledge that there are bugs in first models. So what's with the bars on the iPhone 4? Users have been complaining of low signal strength and busy towers since the first iPhone came on the market. Last week, Apple shouted Eureka! They found the problem. It was a formula error. The company posted a statement on its website that explained "our formula, in many instances, mistakenly displays 2 more bars than it should for a given signal strength." They added, "Their big drop in bars is because their high bars were never real in the first place." Huh?

Apple will send a fix, but as far as I'm concerned, the company's explanation is a non-answer. I can just imagine if I gave such an answer as to why a security patch didn't work. "I called the company and was told that the indicators weren't real to begin with." Or "They said that there's an error in the coding." And my supervisor would take that at face value? I don't think so. I think I'd be shown the exit sign.

In Apple's case, it hasn't been officially determined whether the fix has to do with the software or the hardware. Critics claim that the problem is because of the new iPhone's external antenna. When a person's skin comes into contact with it, you know what happens. Other smartphones, including previous iPhones, have internal antennas, which have a natural buffer between the antenna and the hand that holds the phone. A possible solution is a rubberized case, but that means that show offs can't flaunt their trophy phones as easily.

I am in no rush for an iPhone, even when other carriers will be able to sell it. My wife and I have BlackBerry phones and we're pretty happy with them. The browser is hard to read, though, but for the most part, it serves our purposes.
My wife has worked on Apple computers at her newspaper and reports that while their physical structure is "seductive," they are underwhelming in their claims of what they can do, even for graphics. My advice: hold onto your current phone until the bugs are out -- and you have a choice of carriers.

Friday, April 30, 2010

What Does a Security Breach Cost?

Someone finally assigned a dollar value for security breach that we can relate to. Not in millions or billions or gazillions, but in three figures - $204 per lost record. This is according to a recent report by the Poneman Institute. At 66%, loss of business is the biggest cost. Customers lose trust. Then there's the cost of spin to control bad publicity.

What can companies do to minimize costs? It helps to put a chief information security officer at the helm. It also helps to keep up to date on the most advanced firewalls and penetration software. There will always be someone who thinks he's a better hacker. Oh, and for those who like figures in the millions, the average cost to an organization is $3.43 million. The figure of $204 per record is for the U.S. because of notification laws, but the sum varies among nations. Read the Ponemon Institute's "2009 Annual Study: Cost of a Data Breach"
http://www.encryptionreports.com/.

Monday, April 26, 2010

Visa's M-Bet

Visa, meet CyberSource. More than 40% of online payments are done through Visa, and e-commerce is getting old. Cell phone companies are pushing smart phones because they can increase their revenues as we become increasingly tethered not only to our cells phones, but to our computers.

CyberSource, Visa needs you. At $2 billion, this is the largest amount of money Visa ever paid for anything. But, hey, Visa needs to compete with PayPal. As much as people complain about the fees, they know they're stuck with it if they want to buy something on eBay. M-commerce is not going away and CyberSource may even be able to serve those who refuse to embrace BlackBerry devices and iPhones.

Now it comes down to data protection. There will be be a new level of penetration tests those of us in IT security need to learn. I hope Visa doesn't skimp on this. Otherwise, they will be in the same embarrassing -- and costlier -- position as other financial institutions that decided to gamble on security. They ended up paying for "free" credit monitoring. It wasn't free for them.

Read more at:
http://www.nytimes.com/2010/04/22/business/22visa.html

Tuesday, April 13, 2010

Toast

Yesterday's article in The New York Times about concern over nuclear arms in Asia is long overdue. This is something that I have been concerned about for years. Any American company that has a data center in India could be toast. This risk is bigger than the ones many financial institutions have taken by not allocating money for better security domestically. How many times have you heard that a particular company will offer its customers free credit monitoring for a year because their data has been compromised. That's nothing compared to the potential physical meltdown of a company's data center. As an investor, I worry about that.

There are backups, but that may be too little too late in this scenario. It wasn't just jobs that have been outsourced to India; it's security. It's a company's lifeline. Whatever money the company has saved by not upgrading firewalls and penetration software and by hiring cheaper labor overseas and temporary workers domestically can be gone in one explosion. Not a pretty picture and that's without even thinking about the consequences to the land and to people's health.

Thursday, April 8, 2010

iAm Not Surprised

The initial excitement over the iPad is beginning to settle down. Apple is, without a doubt, the most innovative company when it comes to visual design, applications and marketing. A few people will admit to buying Macs because of their seductive designs, but the majority justify buying the overpriced hardware because they think that Macs are flawless, never crash and never get viruses. Those are myths, something my wife, who has worked on one for years at a newspaper, can attest to that. My main complaints against Apples are the pricing, which I think is exorbitant in comparison to PCs which are equally good for graphics and the fact that PC desktops are expandable.

But I digress. The point of this blog is to address the first issue that has come up with the much-hyped iPad. There's a problem with the WiFi connection. You would think that the company did better testing, but at least it can be fixed. That said, I'd be livid if I spent all that money and it didn't work. One of my pet peeves is when sales people don't know enough about a product, you buy it and then have to return it because no one mentioned that the product doesn't work with your standard software.

I am a very cautious consumer. I've always embraced new technology, but at arms length at least until the second generation came out to remove the bugs from the first one.

Friday, March 12, 2010

Can Software Avoid Fraud?

With the recent 2200 page report about the accounting gimmicks at Lehman Brothers, it's worth looking at the merger of EMC and Archer Technologies. I'm not suggesting accounting fraud. On the contrary, the merger should take Archer's SmartSuite financial data security and EMC's own services from RSA Security Practice and boost standards and compliance to the next level. The Virtualization and Private Cloud Security services are supposed to assess secure virtual desktops and private clouds. A Fraud Assessment and Strategy offers recommendations to mitigate risk. A Risk Operations Service helps companies build security centers.

It isn't easy to create a corporate entity that's in the league of companies such as Lehman Brothers, Enron, MCI WorldCom or others that fell after accounting scandals, but it is possible to nip problems in the bud. You need ethical management and auditors. But it also helps tremendously to plug security breaches. All you need is vulnerability and one sticky fingered employee or financial whiz who thinks he can razzle-dazzle upper management by falsifying data, and you've got a potential disaster.

A new survey by the Ponemon Institute and Guardian Analytics found that 55% of businesses admitted that they have experienced fraud in the past year, with 58% enabled by online banking. A full 80% of banks failed to catch the fraudulent transactions before the funds were transferred out. Slightly more than one quarter of these companies were not compensated for their losses. The bottom line is that cybercrooks are targeting online bank accounts of small and medium-sized businesses and financial institutions are not protecting their customers' assets.
While new technologies such as virtualized data centers and cloud computing are exciting and are supposed to be cost-effective, they carry additional security and risk management issues. Companies cannot wait for auditors to identify weaknesses. There must be constant automated analysis and encryption of information from multiple sources. Who can benefit from such a product? A credit card processing company such as First Data, which is testing TransArmor. It will be able to take card numbers out of merchants' point-of-sale systems just as a transaction occurs. The software encrypts the data credit card companies and card-issuing banks for approval. Stores won't have to worry about protecting their customers' credit card information.

As an investor, I look forward to the potential of other software development that makes me feel confident that when the auditors sign their standard statement in a company's annual report, the figures are indeed accurate and that my investment won't go the way of Enron.