Friday, 11 November 2016

The IoT Deluge


It was amusing to hear at a conference earlier this year, how one speaker had hacked into an acquaintances home network of smart devices and used this to scare the living daylights out of him one night, just to demonstrate the point that you need to firewall your home networks adequately. However, despite stories about peoples kettles and fridges being harnessed for use in Distributed Denial of Service (DDoS) attacks, the means for implementing Internet of Things (IoT) security frameworks already exist. If you go to any IoT event, someone will be promoting their IoT security platform. It's just that there is some catching up to do with the installed base of old unprotected SCADA systems and first generation "smart devices" to ensure that they are properly protected. As most of them were deployed with scant consideration of security.

Recently, it has become increasingly obvious that reality is beginning to set in about IoT exploitation. Businesses which want to exploit IoT in any meaningful way need to set about heavy duty industrialisation of key capabilities. Depending upon the business scenario in which you wish to exploit IoT, you may or may not have control of the end devices. In most cases you won't. So your solution may need to take into account different APIs for integration and different levels of security. It also needs to take into account that at any point in time, a significant part of the overall population of devices that you are communicating with may not be working for any number of reasons.

You also need to take into account the shear volume of data. IoT exploitation inevitably means large, fast growing volumes of data which has to be captured, sanitized, stored, analysed or exploited and managed according to relevant policies. However, many applications may need to take into account issues to do with geography; network bandwidth is not uniform within a county, let alone between countries. At sea it may be  extremely low compared with land. Legal jurisdictions can impact what is permissable from a privacy or even data export perspective.

However, key to scalability is the means to manage an IoT network. Each IoT device used by your solution will generate large volumes of data itself. Whilst attention to date has been focused on the application data, the volumes of event data for the devices, networks, associated installations and security devices could potentially drown the volumes of application data involved. Managing this data so that you can control the overall performance of the solution and optimise business outcomes, is a problem vastly larger than that which most IT organisations struggle with today. Automation is the only answer. Automation which brings all the data together, intelligently analyses it and visualises it for analysis is needed. IoT adoption, usually means changing your business model to do things differently and more intelligently. This cannot happen if you are not capturing and fixing problems as they happen as well as anticipating problems based on trend analysis. So Automation of monitoring and analysis is key. So automated monitoring is not just a nice thing to have because the DevOps boys told you it is trendy. Automation is key to survival. It has to deal with both operational and security incidents, and it has to be integrated across your whole environment. Point solutions are not good enough.

Fortunately, there is a new generation of tools which do this. They do it across hybrid cloud environments and deal with multiple protocols. Analysis of experience to date indicate that not only do they lead to dramatically shorter resolution times to problems (e.g. quarter to a third of previous times using traditional approaches), but to reductions in incidents (by similar margins) and therefore significantly reduced loss of value when problems occur. 




Wednesday, 9 November 2016

DIGITAL DECEPTIONS & ACCELERATION

It has been a great week for special events. Trump did the unspeakable and pulled off the Presidential contest in the US. Who would have forecast it?

Away from politics, there has been great excitement with the announcement that Dubai could host the debut of HyperLoop One's radical transit technology, linking to Abu Dhabi in 12 minutes and implementing Elon Musk's vision of near supersonic pod transport.

Sitting over a glass of Moldovan Wine (yes Moldovan) at the World Travel Market, in London's Excel, I casually bumped into one of London'd start up kings, Razvan Patrascioiu, see http://bit.ly/2fydFf4 , who is working on his new venture to ensure that London's visitors get to really enjoy the great restaurants that have become part of the capital's landscape. Later over Slovakian and Israeli wine on other stands I mused on the power of wine to connect people, especially in the digital world. So anyone who is remotely keen on this idea should check out the Chief Wine Officer on LinkedIn and Twitter. This is still my favourite digitaly enabled marketing vehicle and remains extremely effective at connecting CIO level people with technology providers.

Anyway, anyone who actually read my post about digital vikings, will know that digital entrepreneurs face defensive business fortifications which can derail their asymetrical attacks on new markets. This week Facebook halted the deployment of a Fintech Insurance app aimed at correlating facebook behaviour with driving behaviour. Facebook will not release the data to be used in the app. It's against their policy. Additionally, Uber was told that under UK law, their drivers are effectively employees and entitled to minimum wages and holiday pay. This just goes to show, that you need to able to respond quickly to set backs and if you cannot anticipate problems, at least plan to implement in ways that adapt to changes in circumstance and don't burn all your funds at once.

Finally in a great demonstration at the ACM Conference on Computer and Communications Security Hofburg Palace, Vienna, Austria, researchers from Carnegie Melon demonstrated how special glasses could be used to fool commercial facial recognition systems. For example a male test subject wearing the special glasses was recognised as actress Milla Jovovich..


Thursday, 3 November 2016

Blockchain Frenzy

You cannot pick up a business publication these days without seeing something written about Blockchain or Bitcoin. Blockchain has pushed Big Data, IoT and Digital Business Models onto the sidelines. This has been accompanied by a huge rush to invest in the technology and thousands of start ups being established, hoping to exploit the technology.

Yet if you read the articles written about Blockchain, it is difficult to get your head around the subject. Recently, I read a comment by a Consultant who specialises in Blockchain noting his complaints about the complete gibberish being published about it. So I decided to educate myself on the subject and was relieved to find an introductory talk on the subject being run by the Business Information Systems Group of the BCS. 

What I learnt was:

- Blockchain is a protocol for a Distributed Ledger;
- It creates read only transaction records which are cryptographically protected by Hashing;
- Transactions are contained within time-stamped blocks; each block is hashed; the blocks are chained together in such a way that their hashes are based on their position within the chain;
- The main parties participating in the transactions get complete copies of the chains;
- Parties can only view the records which relate to them;
- The ledger can deal with anything of value and does not have to be limited to money;
- It is possible to apply some conditional business rules via "smart contracts".

The speaker has a great web site www.distlytics.com on which he has provided some good resources for learning more. It's worth a visit.

Put together, this makes for a highly resilient (to fraud or denial of service attack) means of exchanging value or valuable assets without the involvement of trusted 3rd parties. It also provides confidentiality, traceability or provenance by default. So there are many innovative initiatives and opportunities around it. Removal of the need for a trusted 3rd party would remove the need for brokers in certain types of transaction, whether it is financial, commodity or asset based. The provenance trail could be useful in art dealing or international antiquity import and export; conveyancing of property deals could become a thing of the past and so on.

There are some issues. Some are regulatory. For example tax and treasury authorities typically do not like the unmonitored and invisible to them. There also is potential for the use of the technology for criminal purposes on the so called dark web.

However the key issue at present appears to be scalability. The scale of duplication in very large markets is likely to be unsustainable, unless new concepts are added. It appears that existing implementations are only able to sustain modest transaction rates for comparatively small sizes of market. The duplication involves significant overheads on transactional complexity, network traffic and storage.

So if Blockchain is going to involve, there is a need for a standards body or user body to evolve the protocol for performance, APIs etc. At present this is interesting as the original protocol was floated by someone or collection of people using a pseudonym. So at present there appears to be no authoritative owner to legitimise such a body.

It will be interesting to see what happens next and how market forces will shape the evolution of Blockchain.

Saturday, 29 October 2016

Platform Schizophrenia

This year I became aware that there are two definitions to Digital Platforms. Whilst I had been meandering around in IT Space thinking that digital platform meant services like AWS and Azure, our friends in Marketing Space had decided that digital market places were Digital Platforms. So to them ComparetheMarket.com, Deliveroo.com and Uber.com are platforms. 

Anyway moving on from this diversion, it has for some time been a surprise to me that amazon has dominated IT thoughtspace and the market for PaaS based Digital Platforms, whilst belatedly Microsoft pushed into the market with Azure. 

In recent projects I have been involved with both AWS and Azure as well as all sort of fun with the OSS tools which are available on them. To traditionalists coming across the database as a service offerings available is quite amazing. I was also blown away when a Solution Architect who had no experience of Neural Networks was able within 2 weeks to knock up a fully working and trained prototype of a Machine Learning application on Azure.

So it has become increasingly interesting to see that Google, one of the most born in the cloud companies going, has recently started promoting its services. One has to ask why did they wait so long, especially as they have always made much of the fact that their products are all architected around a SOA concept and the ability to expose themselves as services, both internally and externally.

Oracle and IBM have also appeared actively in the market place this year promoting their own special blends. 

The thing about this is that they all have really good stories to tell. You will note that I am not stating any preferences, as to be honest, anything I say about them today will already be wrong tomorrow as this is an ever faster moving situation. Today's facts will be obsolete tomorrow.

So what does it all mean to the average business trying to go Digital?

Firstly, the means are there. You have to be comfortable with the fact that terms and conditions are what they are. You need to examine the pricing and understand how this would play out in some key real world applications. However there is plenty available to "Free Your business from the Tyranny of Infrastructure" and Focus on Value. If you choose reasonable sensibly, you will be able to scale costs with business activity and exploit platforms which support Agile and DevOps so you can move quickly and lightly in the pursuit of opportunities. All the major vendors are investing significantly in security and if you dig deeper, most offer localisation options if data cannot move outside certain jurisdictions. Additionally there are industry certification schemes which many providers are signed up to. So a lot of inhibitors have been addressed.

The key issue is going to be how much do you insulate yourself from the risk that you may need to change platform provider. Business Performance, Legislation, Pricing etc. will change with time. So you may need an exit plan. Therefore, some thought needs to be given to insulating yourself from future supply threats. Where your application is going in for short term gains, e.g. a new financial instrument which will only be around for a a few months or perhaps a couple of years, this is not a problem. But if you are locking yourself into a platforms specific machine learning solution for years, you may need to think how you would deal with problems if the platform vendor ceases training.

In the end, however, we have always faced these problems. Finding a totally vendor agnostic solution has always been too complicated and too costly. So its time to get comfortable with not being in total control. The System of Systems concept of de-optimising components to integrate and optimise the overall performance of the Big System applies. You just need to understand your risk appetitie, your risks, how you want treat them, what you will accept, what you need to insure against and get on with it. The risks of not doing so are far greater.








Friday, 7 October 2016

Cyber, Robots, Digital, Oktoberfest, Gosling and Demming - all in one week

This week was eventful. It started with the announcement that the UK's National Cyber Security Centre had at last opened its doors, see: http://bit.ly/2dpPZJH. This was long announced and is an essential plank in safeguarding the UK's Digital Infrastructure and Capability. My concern is the glacial pace at which progress has been made here and the comparatively small amounts of funding that the Government has assigned to fund it.

Then someone posed a picture of a man shaking hands with a robot at AT Kearney's Digital Business Forum with the caption "Next gen employee greets legacy employee". This displayed typical 1930s thinking about the value of people drawing from the legacy of the original R.U.R. play Rossumovi UniverzálnĂ­ Roboti (Rossum’s Universal Robots) written by the Czech writer Karel Capek in 1920. In the play, a factory owner attempts to replace his high versatile human workers with mechanical machines, totally undervaluing the creativity and inspiration that people bring to the workplace. Digital models are largely about delivering this value not implementing mindless mechanisation. So perhaps the caption should have been about valuable human talent supplanting inappropriate technology.

Anyway, the highlight of this week was the IPexpo event in London. This had a wide array of suppliers and speakers. Notable about the event was the desire to celebrate Oktoberfest complete with free beer and people dressed in Bavarian costumes at 4:00 pm on the first day. Many of the suppliers were also offering beer at other parts of the day. It was a strange example of how modern "fun oriented" culture of digital start up companies is affecting the mainstream and making us weirdly 1960s and modern all at the same time.

James Gosling presented a captivating key note talk on liquid robots covering his current involvement with Marine UAVs used for data collation in remote seascapes and the IoT practices needed to make this work. The UAVs themselves are very cool, capturing wave energy and converting it into propulsion.  The techniques for transferring data from the middle of oceans, where there is very poor bandwidth available even from satellites, were also very interesting with the same data being transfered by differnt networks and routes to increase the reliability and speed of data transport from the UAVs to the place where it is analysed. The interesting point that he made was that Scalability is a relatively trivial issue for IoT. Security and reliable Availability are much more important.

Two other talks were really good. Mathew Skelton (skelton Thatcher Consulting) gave an illuminating talk on anti-patterns for continuous delivery (aka DevOps). He confirmed my viewpoint that typically you need roughly 1 operations person working continuously with each Product Team, to avoid the bottleneck that some traditional ITIL shops have introduced with undersized change management functions.

Derek Weeks also gave a well researched presentation on the use of Opensource software and how modern software product development practices have now become highly analagous with manufacturing and supply chain practices. He presented interesting statistics on how much open source code contains security and legacy debt bugs. His premise being that Deming's (the father of Quality Management) recommendations to reduce the number of suppliers and quality assure bought in products can raise productivity in the adoption and exploitation of Open Software.

Tuesday, 27 September 2016

GDPR Bricks and Mortar Defence or Digital Viking's Inspiration

GDPR - the General Data Protection Regulation - is the next wave of personal data privacy regulation from the EU and is expected to go live mid 2018, i.e. pre-Brexit. This generally tightens up privacy requirements in a number of areas and has been a theme of discussion at a number of Cyber Security events this year, including today's InfoSecurity Magazine event.

Anyone interested in "Things Digital" should ask themselves, will this act as a regulatory defensive wall for old fashioned Bricks and Mortar / Industrial Age companies to shelter behind, or is it a new discipline or challenge for digital Vikings to embrace?

A couple of today's speakers made some interesting observations and comments: 
  • GDPR means that you need to know the What, Where and Why of Personal Data, especially customer data;
  • Regulation should not drive data security, Security Should Drive Regulatory Compliance;
  • There is a strong case for Digital Companies to adopt Social Digital Responsibility as Part of their Brand.
In a way, it should be easier for purely Digital companies to do this, as they are mostly starting from scratch with few of the problems of IT Estate Sprawl that many established companies have, with legacy systems, infrastructure and the typical complications inherited from previous defunct strategies as well as mergers and acquisitions. 

Also, in a previous blog, I mentioned that many digital companies actually regard this data as part of their IPR. So addressing GDPR (& other jurisdictional requirements) should be core to their business activity. Although future approaches toward collection and explicit consent may have to be sharpened up to meet the new requirements.

The implication is that Digital company that plans and builds Privacy Protection in from Day 1, will actually be building its own competitive advantage over traditional companies who mainly will be playing catch up.

Friday, 23 September 2016

It's strategy Jim, but not as we know it ...

A friend of mine who was a leading light in the development of Information Strategy and Architecture practices in the 80s and 90s, retired a few years ago. The key driver being his disillusionment with organisations who said that there was no time for developing strategy.

In the time since then, Enterprise Architecture has enjoyed a considerable re-birth and growth, everything has gone digital and organisations have started to publish strategies which read more like marketing guff expounding bland benefits, than anything which informs the reader or directs action.

A couple of things have brought this to mind recently. the first was that I picked up a copy of Richard Rumelt's "Good Strategy Bad Strategy", in which he emphasises the need for a situation diagnosis of what is needed to succeed, proposing an integrated and coherent policy which addresses this, and a small set of supporting actions. This is a great read and worth while for anyone interested in Business Strategy.

Yesterday, I went to very stimulating talk about post merger integration by Henry McNeill at the British Computer Society. Afterwards as we huddled around the wine and sandwiches, several key themes came out:

  • Many companies are still not aligning acquisition activity with business strategy;
  • There was violent agreement that clarity of the aims, target state and value proposition of an acquisition is imperative for successful integration;
  • Participation of IT from due diligence onwards, provides an ideal opportunity for IT to show how it can help the business articulate and deliver against a strategy for the exploitation of the newly acquired business. Sadly, many organisations are still bringing IT in on Day 1 after deal completion and missing opportunities to mitigate risks and address early integration opportunities quickly. Some still take years to work out what to do with them.
This brings me to the point of today's commentary. My experience has been that almost all business strategies are usually incomplete and fail to unify the senior management of the business. IT needs a coherent exposition of Strategy which identifies the "game changing" opportunities or risks in the business market place to be able to prioritise its investments, define what common capabilities are needed and to support effective innovation. Working with business leaders at C suite and direct report level to "elicit the real business strategy that they work to" and agree the opportunities is valuable to the business as a whole. It's often a great way to get everyone to understand each others problems and can help unify purpose.  However, its got to be continuous to support the ever shifting business environment as businesses go Digital and Agile. Strategy has to take a Fail Early, Refactor and Learn approach to continuously calibrate its diagnosis, unifying policy and action plan. There's a role for the CIO in this.