Month: January 2020

Ransomware Risk Mitigation: The Desktop-as-a-Service Solution

Ransomware is a dangerous and growing threat. Find out how security-minded executives establish best-in-class protection.

2019 has proven to be an alarming year for cybersecurity professionals and cyber-attacks show no signs of slowing down in 2020.

One cybersecurity firm characterized the rapidly growing pace of cyberthreats across all industries as an “unprecedented and unrelenting barrage”. Within 24 hours of its report, the City of New Orleans and several other municipal organizations fell victim to ransomware attacks.

But it’s not just large-scale enterprises and public institutions that are under attack. Small and mid-sized businesses offer low-hanging fruit for opportunistic cyber criminals, who often use automation to widen their area of attack.

Small businesses, large enterprises, and public institutions alike have all struggled to respond decisively to the ransomware threat. Until recently, executives had few options – and fewer defenses – in their fight against cybercrime. Now, Desktop as a Service (DaaS) solutions offer comprehensive, scalable ransomware protection services to organizations of all sizes.

 

What Exactly is Ransomware and How Does It Work?

 

There are a number of ways for a cyber intruder to take over your computer system without your knowledge. You won’t know about it until it’s too late.

The typical ransomware attack begins with the stealthy takeover of the victim’s computer. This may be accomplished through phishing, social engineering, or a sophisticated zero-day exploit – the goal is to have access to the network while remaining undetected.

Upon compromising the network, the cybercriminal can begin slowly encrypting important files. Most ransomware applications do this automatically, using a variety of different methods to evade detection. The process may take days, weeks, or months to complete.

Once the ransomware encryption algorithm reaches critical mass, it then locks users out of the network, displaying a ransom note demanding payment for a decryption key. Sometimes the demand is small – on the order of $500 to $1000 – and sometimes the demand reaches into six-figure sums.

Ransom demands are usually for bitcoins. “If one organization is willing to pay $500,000, the next may be willing to pay $600,000.”

Small sums make paying the ransom a tempting option, but a dangerous one. There is no guarantee that the cyber attacker will relinquish control of the network. Instead, executives who pay up reinforce the cybercriminal profit cycle. It is only a matter of time before the ransomware attacker strikes again.

Famous examples of ransomware variants include WannaCry, which spread to over 230,000 computers across 150 countries in 2017, and Petya. The WannaCry crisis targeted healthcare clinics and hospitals, causing untold damage and highlighted the risk that outdated IT systems represent in these industries.

Petya was unique because it did not encrypt specific files. Instead, it encrypted the local hard drive’s Master File Table, rendering the entire device unusable. There are dozens of other variants out there, and each one uses a unique strategy to take advantage of victims. NotPetya developed on Petya’s attack method, using the same vulnerability previously exploited by WannaCry.

Who Is At Risk of Ransomware Attacks?

 

Emsisoft reports that during the first half of 2019, 491 healthcare providers were hit with ransomware. The attacks are increasing and the demands are for larger ransoms.

Everyone. Although high-profile targets like hospitals and municipal institutions make headlines, thousands of business owners are defrauded every day. On average, one business falls victim to ransomware every 14 seconds.

Small and mid-sized businesses are especially vulnerable because they typically do not have access to the kind of comprehensive security resources that large enterprises can afford. Small businesses that do not rely on reputable third-party managed service providers make especially easy targets.

Cybercriminals have shown that they are willing to target hospitals and public institutions without shame. The greater the need for functioning IT systems is, the more likely the cybercriminals are to get paid. This is how the cybercrime profit cycle perpetuates itself.

What Can Small and Mid-sized Businesses Do About Ransomware?

 

Organizations caught unprepared have few options. Although cybersecurity experts correctly warn against paying the ransom, desperate business owners often pay anyways. But the relief is only temporary. 60% of small and mid-sized businesses victimized by cybercriminals do not recover and shut down within six months.

Preparation is key to successfully resisting a ransomware attack. Organizations that cannot afford to develop, implement, and deploy state-of-the-art security resources need to contract a reputable third-party vendor for the purpose.

Even enterprise-level organizations with tens of thousands of employees often find themselves opting for a managed solution instead of an in-house one. The cybersecurity industry is experiencing a widening talent shortage, making it difficult even for deep-pocketed businesses to hold on to their best security officers.

Introducing IronOrbit: Comprehensive Ransomware Protection

IronOrbit achieves best-in-class ransomware protection through a unique approach to cloud desktop hosting. There are three key processes that must work together flawlessly to guarantee ransomware resilience:

1.   Prevention

The best way to prevent a ransomware attack from taking place is preventing the initial malware deployment. Firewalls, email filters, content filters, and constant patch management all play a critical role in keeping malicious code out of DaaS systems.

Maintaining up-to-date software is more important than most executives and employees realize. Since NotPetya used the same attack vector as WannaCry, its victims entirely consisted of individuals and businesses who neglected to install security patches after the WannaCry crisis.

2.   Recovery

There is no way to guarantee 100% prevention. However, business owners and their IT teams can circumvent the damage ransomware causes with consistent backup and restoration tools. IronOrbit’s disaster recovery features can wind back the clock, reloading your entire suite of business systems to the state they were in just before the attack occurred.

3.   Remediation

Ransomware recovery cannot guarantee business continuity on its own without best-in-class remediation tools. Without the ability to trace the attack to its source in a fully logged environment, there is no way to tell whether the attack has been truly averted or not. IronOrbit uses state-of-the-art digital investigation tools to track ransomware attacks to their source and mitigate them.

Schedule a Consultation with an IronOrbit Security Expert

IronOrbit has helped numerous businesses capitalize on the efficiency and peace of mind that secure DaaS solutions offer. Protect your business from the threat of ransomware with the help of our expertise and knowledge.

 

The Top Cloud Solutions Every AEC Firm Should Be Using in 2020

The quantity and quality of cloud offerings have grown significantly in the last few years. There are a number of new solutions available to AEC firms that are especially worth taking a look at. We’ll look at a few of the top cloud solutions in this article.

The AEC industry faces incredible growth and changes in urbanization and globalization. As traditional data centers become insufficient to meet these demands, so does the demand for security and efficiency. Trends such as hyper-automation, the distributed cloud, and practical blockchain are just some of the trends that will continue to proliferate into 2020. Each one of them has the ability to transform and optimize initiatives.  The AEC sector has done a good job of keeping up to date. More than 2/3 of AEC firms store data in the cloud. The reason: cloud solutions are an important ingredient to maximizing workflow, costs, and sustainability.

Cloud storage, for instance, can be a more cost-effective alternative to spending thousands on upgrading your local IT. Cloud computing has become increasingly popular for a number of reasons: it’s more affordable, able to perform computationally intensive work, workspace flexibility, and more secure.

Also, there is the added advantage that, with cloud-based computing, it’s possible to view and work with complex renderings on an underpowered device.

Scalability is also easier in the cloud. Most providers allow for scalable, on-demand resource usage. This enables your company to have more computing power when it’s needed.

Cloud storage providers enable benefits that are impossible to duplicate. A Cisco report suggested, “By 2021, 94 percent of workloads and compute instances will be processed by cloud data centers.”

Firms that have moved to the cloud have an edge over the competition. With that in mind, let’s take look at what kind of cloud services are available. Let’s also consider how each one benefits an AEC firm.

 

1 – Cloud Storage

It’s less expensive than storing large CAD files on premises to house large data with a cloud storage provider

 

Cloud storage is a great solution because it is simple and offers several important benefits.

First, cloud storage providers backup your data. Cloud storage companies will often have servers in two different parts of the world. One server might be on the West Coast of the United States. The other server might be on the East Coast so that even the largest disaster won’t wipe out your files.

Files stored on the cloud can be accessed from anywhere. Whether your crew is working 10 or 1,000 miles away they’ll have easy access to everything stored online. It’s also simple to set permission levels on various files. For example, an administrator can dictate that renderings can be viewed at the job site but only edited in the office.

 

Everyday examples of cloud storage providers include DropBox, Google Drive, Sharepoint and One Drive.

2- Cloud Storage Gateways

Cloud storage gateways can help to reduce costs in a number of ways. Data compression reduces bandwidth which enables increased storage. These cloud storage gateways can make smart decisions about where to save files. Files that accessed frequently) are called “hot files.” Hot files can be more expensive to store online. A gateway may keep them in local storage while storing more infrequently used files in the cloud.

Panzura

Panzura has a cloud-based version designed to create a shared environment for everyone to work in. With Panzura users can store CAD and BIM files online and open them in a matter of seconds, not minutes. All files can be accessed from any location making collaboration easier. Panzura claims to “reduce infrastructure costs up to 70%,” over traditional data centers.

Like all cloud storage service providers, Panzura makes it easy to share files and collaborate across a variety of devices.

Another of Panzura’s interesting features is the work-sharing monitor. Work-sharing allows for remote viewing of another Panzura user’s workstation. As with other cloud-based solutions, Panzura can scale as your firm grows.

3 – Cloud-Based Accounting and Management Applications

Running your firm’s accounting and management applications in the cloud simplifies workflow. Collaboration is fluid when everyone at the company has access to the files. Accessibility to files while at the office, at home, or at a hotel room on the other side of the country.

Decreased IT and Hardware Costs: You’ll be able to significantly reduce IT and hardware costs when you host your Sage or QuickBooks software off-premise with a cloud hosting provider.

The cloud enables collaborators to work in real-time. Different permission models can be set for different users. It is also easier to collaborate with suppliers, distributors, and contractors. Since the files and data are already online it’s simple to give outside parties access. That’s opposed to localized data which is more difficult to share.

Deltek is a cloud-based solution to track projects. Project steps can be broad or detailed. Deltek tracks billable hours, resource usage, and expenses. If your firm uses different programs for different purposes, it may be time to consolidate.

While localized programs have offered project tracking for years. Deltek makes collaboration easier for the whole team. Everyone from accounting to the drafting team has access to the same program. The functionality is the same whether they’re on a $5,000 workstation or a $200 smartphone.

 

4 – Internet of Things (IoT)

The number of Internet-connected devices is growing at an exponential rate. As microchips and transmitters are becoming more affordable, more applications and innovations are being introduced onto the market. This means more tools for the AEC industry to track and improve efficiency.

The whole Internet of Things (IoT)

Internet-connected GPS devices, for instance, are great at tracking fleet mileage. They can also make recommendations about necessary vehicle maintenance. There is a Bluetooth tag that attaches to a piece of equipment making it easy to locate on a crowded job site. The tag also helps recover lost tools.

 

5 – Hosted Desktops

Hosted desktops transform computers into more powerful workstations without having to purchase expensive PC hardware.

A hosted desktop is ideal for AEC firms running multiple AutoCAD workstations. Scaling is also a breeze as hosted desktops can increase their resources to handle any task.

A hosted desktop transforms cheap laptop or tablet devices into a powerful workstation. The kind of devices that can launch power-hungry programs and model complex drawings. That makes it great for the crew out in the field who don’t normally have access to powerful computers.

 

IronOrbit INFINITY: The All-in-One Solution
The all-in-one solution offered by IronOrbit provides peace of mind, increased agility, and true synergy with key organizational objectives.

While cloud solutions (here are 7 good reasons why AEC firms need the cloud) offer a number of advantages to AEC firms, not all products are created equal. Products like INFINITY offers tremendous functionality and flexibility.

INFINITY is a convenient cloud-based workstation. It combines the best features of cloud-based solutions into one place. This includes:

  • Hosted desktops
  • Cloud storage (including Panzura integration)
  • Application hosting (any application, including accounting and ERP software)
  • Unlimited computing, upgrades, and bandwidth
  • Managed backups and disaster recovery
  • Managed security and compliance
  • 24/7 US-based IT support

INFINITY is a workspace that allows access to CPU and graphics-intensive applications from anywhere.

With unlimited CPU and RAM upgrades you never have to be concerned that you’ll run out of processing power and collaboration is easy when your whole team is working in a centralized environment.

Centralization allows the team to work with the same version software. The whole team uses the same application and work from the same set of files. There’s no longer the concern that employees are accessing different versions.

Inconsistent files can cause delays, accidents, compliance violations and more. Having the team working from the same set of files is a considerable benefit.

Then there’s the convenience of dealing with one vendor. Forget about tracking costs from multiple service providers. There’s no dealing with half a dozen account managers and support teams. IronOrbit gives you everything in one package so that you’ll only ever need to work with a single company.

An Easy-To-Manage and Future-Proof Solution, Too

Speaking of the all-in-one package, IronOrbit wants to make cloud management as simple as possible. They take care of setup, backups, application security as well as user support.

Other cloud solutions require the client to do a number of things. They have to set up the service. Integrate the service with existing infrastructure, and manage it on an ongoing basis. With IronOrbit these time-consuming processes are gone.

When considering a cloud service provider, it’s important to think about the future. IronOrbit is backed by today’s cutting-edge technology. It’s flexible enough to support any future technology growth.

IronOrbit is constantly upgrading its infrastructure. Their clients can take advantage of unlimited GPU and RAM; unlimited bandwidth, and unlimited upgrades to the latest versions of Windows and Microsoft Office.

Whatever devices and operating systems the future holds, IronOrbit INFINITY will be ready to support them and give you the same level of service that you’d expect from a professional cloud-solution package. With INFINITY’s centralized, all-inclusive and convenient software you’re always in good hands.

In Thomas Friedman’s book THANK YOU FOR BEING LATE, he refers to the exponential acceleration in technology based on Moore’s Law: the speed and power of microchips double every 24 months.

In this age of acceleration, companies have 3 major objectives. They want to do more. They want to move faster. They want to do it at less cost.

To achieve all 3 objectives, a company has to ensure one thing. That there is alignment between their business objectives and their IT capabilities. Harmonizing clear objectives with IT capabilities, companies will realize their full potential. Not all companies are able to follow that path on their own. They may know they need to change, but don’t know how to get there.

If they do know how to get there, they don’t know who will manage the new environments. It’s more common now that company leadership won’t have a clue of what their future state should look like. Our primary job is to listen to the customer. We need to understand our client’s objectives and future-state desires. Then we analyze the requirements against IT capabilities. It has to be a solid yet flexible enough infrastructure that will support the future business goals. To the degree this harmony between goals and technology is in place, the intended transformations will happen.

It’s Time for an Upgrade

In the last couple of years, there have been a lot of exciting developments in the AEC-cloud-industry. From time and maintenance tracking to hosted desktops allowing users to render complex projects on their iPhones, the cloud has much to offer.

Not to mention savings, when you factor in the thousands or tens of thousands of dollars you can save by not having to continuously upgrade your workstations.

If you haven’t looked into getting on the cloud yet there has never been a better time. Cloud computing and project management are the directions the AEC industry is heading toward. No firm is going to want to play catch up to its competitors.

What is the True Cost & Benefit of Moving to the Cloud

Moving to the cloud should be more of a business decision than an IT decision. Cloud servers are a keystone of modern business technology. Once you consider moving to the cloud as an initiative to make full use of new technology, you begin to envision the kind of agility, stability, and responsiveness the cloud enables down the road. It’s also a solid first step in future-proofing your business. This perspective demands a view on ROI that moves beyond calculating dollars and cents.

 

Calculating ROI
Calculating the ROI of your technology investment doesn’t have to be rocket science, but remember what Einstein once said, “Not everything that counts can be counted.”

Looking beyond spreadsheets and calculations means considering how your technology helps you meet your strategic objectives.  Long-term success depends on a proactive agenda of workforce transformation, strategic flexibility, security, and manageability.  Are your technology investments driving productivity for your business? Are they solving challenges or creating more problems? Answers to questions like these are the main reasons why many companies are moving to the cloud.

 

Forrester released a report in early 2019 that stressed the importance of corporate leaders to gain more fluency in the technology choices made. They need to understand the different performance yields of different innovation efforts. It’s important to be visionary about where the company is headed during the years to come. Know what is at stake should you keep your IT infrastructure on-prem or move it to the cloud. Become focused on how to make business technology a basis of a durable strategic advantage.

Board Meeting
While corporate leaders need not be able to use devices, programs, and apps, they should know enough about them to discuss them intelligently with the team.

In a more recent podcast, Forrester gives its top predictions in IoT, AI, and cloud computing.

About half the big enterprise outfits that try to transform their systems fail or stall under the sheer size, and complexity of the process. Certainly, a large part of the problem has its origins in the failure to design a strategic plan that works. Don’t put the cart before the horse. Remember the carpenter’s rule, “measure twice, cut once.” You’ll avoid costly mistakes, both in terms of time and money, if you do research and get as much information as possible before you start spending resources on cloud migration.

ADVICE FROM EXPERTS 

Every organization has its own unique strategic needs. Not all businesses have the same priorities. There is no one-size-fits-all approach to developing a strategy or plan to move to the cloud. Any significant technological transformation requires analyses and consultation with experts in the field. It also helps if these experts know as much as possible about your business goals.

The first step is to become clear-eyed on the business strategy.  Evaluate business objectives and assess how your existing technologies align with meeting those plans. Inevitably gaps will become apparent.

Utilize the insights from the best technology consultants you can find. They’ll be able to recommend available options and optimal routes. In some cases, there may not be an immediately available option that best suits your objective. In those situations, something more innovative and customized to specific needs may be needed. This is exactly why a good advisor is critical to successful cloud migration. A good advisor will be a true IT professional, one who stays abreast of the latest technologies, but also one who has a comprehensive understanding of business operations. Having this kind of resource on hand can mean all the difference between a successful transformation or one that goes off the rails. Failed attempts are costly with absolutely no ROI.

While it’s true that every company is unique and each one has its own set of priorities for future growth and productivity, there are a few technology industry trends that can serve as a guiding light.

THE INCREDIBLE EVER-CHANGING WORKFORCE

This isn’t your grandfather’s workplace environment anymore. It’s not even your father’s workplace environment.  For people to become fully engaged and productive, they need flexibility over the tools they use. The choice of places to work would be nice too. Employees need reliable and secure access to the resources they use and depend on.  Consistency of experience shouldn’t be over-rated either.

Wakefield Research conducted a survey showing the scope of this on-going technological evolution. Not too surprising, the report found that 69% of the employees regularly work remotely. Some 21% of them blend environments by working both in an office and somewhere else, such as at home or a communal workspace (Starbucks anyone?). The survey went on to show that a whopping 80% of the office professionals agree that, within 5 years, businesses will not be competitive without using cloud-based apps. Future-proofing means leveraging cloud servers and taking advantage of new technologies as they become available.

MEETING RISING EXPECTATIONS, PRESSURES, AND DEMANDS FOR INCREASED SECURITY

New business models, competitors, and customer preferences emerge seemingly from nowhere. Turn around for a moment, and there are new things to look at. During this age of acceleration, all of us have to stay on our toes. We have to practically reinvent ourselves from Monday through Friday. Companies of all sizes have to move quickly to capture new opportunities. And if you think it’s intense now, just wait until next year and the year after that. Modern technology and its impact on business is moving at an exponential rate.  I’m getting dizzy just thinking about it.

Even as things are moving at breakneck speed, security demands have never been greater. Security is also more challenging than ever.  Check out our previous blog on cyber attacks and ransomware for some not so gentle reminders of how costly cyber attacks can be. IT transformation has increased the opportunities available to would be hackers. And these hackers have their choice of mobile devices, web apps to IoT. New mandates, like the General Data Protection Regulation (GDPB) have raised the stakes for everyone.

As companies increasingly leverage the cloud to store customer data, SOC 2 compliance is becoming a necessity.
START AT THE BEGINNING

So, let’s start at the beginning of any company’s transformational journey. Ask the question, “Can your current technologies help you meet all the requirements in ways that enable you to move quickly and stay on top of your priorities?”

 

Wakefield Research shows that 69% of the employees regularly work remotely and 21% of them combine home and office environments.

MOBILE FORCES

MORE PRODUCTIVITY, WITH LESS STRESS AND IN LESS TIME

It’s becoming more common to see employees working from home or both at home and in the office.  Where ever they choose to plow through their day, they need tools that are smart, fast, seamless. They need to work collaboratively. They need to be open robust programs like Revit, or SoftImage, or After Effects, and use them quickly, seamlessly, and without interruption.  Having apps on cloud servers enable distributed teams to collaborate easily across great distances.  Whatever the scenario, the new IT setup needs to empower your people to get more things done, more easily.

 

KEEP IT SIMPLE

Before making an investment in technology, consider if it adds to the complexity of your workplace or helps reduce it.  Does it help to streamline operations? In other words, does it impose a burden of daily management that diverts attention and resources? Or does it free-up people’s time so that they can focus more on their own work.

 

SECURITY IS A CHALLENGE

The threat of cyber attacks is greater than ever. A breach of security can be devastating. Finding skilled security professionals has never been more difficult. The more complex the IT environment, the greater the security risk. There are more openings for attacks. Consider public networks, mobile devices, and web apps. There are insider threats, phishing, and so on.

Sometimes it may be worth taking on the additional security risk in exchange for exceptional business value. It’s a trade-off that should be factored into the evaluation of your transformation strategy. Keep in mind, if a technology can make security simpler, more transparent, and more effective, that’s an advantage.

Cryptojacking is the unauthorized use of one’s computing devices. It is accomplished by injecting the system with hidden code that immediately starts benefiting third parties. About two-thirds of companies targeted by ransomware attacks have been infected.
LEVERAGE THE FLEXIBILITY TO IMPROVE STRATEGY

It’s a great period of time to be an IT professional or developer. The hybrid, multi-cloud era has brought tremendous freedom and flexibility to what used to be just a metal box and a lot of colorful cables.  Now, cloud technology enables us to provision resources and demand, scale easily, and support users anywhere. Cloud servers also allow for beefed up security and greater performance. The cloud is where data rules supreme.  It’s not under the rug, in the closet, or filed away on hard drives stored in a drawer. We now have a place, seemingly with no limits, to put all the data we’re accumulating (organizations stockpile data but seldom dispose of it).

On the user side of things, cloud computing has given employees the freedom to choose any device, time, or place to work. These various cloud options mean a consistency of quality user-experience.

The prediction is that 41% of enterprise workload will be run on public cloud platforms by 2020. Another 20% will be private-cloud-based, while 22% will rely on hybrid cloud adoption.
NO TECHNOLOGY EXISTS IN A VACUUM

If one of your investments limits the utility of another, it degrades the value of both. A Good strategic transformational designer will always look at the big picture and assess how everything is connected.

When it comes to remaining profitable while future-proofing a company, not everything is about dollars and cents. Considering the ever-evolving workplace, with all its need for mobile applications, collaboration tools, data crunching, and massive amounts of storage. Keeping our eyes on the big picture is necessary if we’re to evaluate ROI accurately.

The true ROI has to do with information technology that advances key priorities such as productivity, reducing complexity, strengthening security, and ensuring choices are available whenever needed.