Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

12/9/2019
10:00 AM
Shane Buckley
Shane Buckley
Commentary
Connect Directly
Twitter
LinkedIn
RSS
E-Mail vvv
100%
0%

4 Tips to Run Fast in the Face of Digital Transformation

This gridiron-inspired advice will guarantee your digital transformation success and keep your data safe.

Unlike the 16-game NFL season, for the eight in 10 companies in the US undergoing digital transformation (DX), there's no off-season. The journey is an ongoing one that, for IT leaders, can feel like an endurance challenge, not to mention a massive expense, with DX spending predicted to reach nearly $2 trillion in 2022, according to IDC.

Application-centric visibility is key to accelerating DX. By better visualizing, isolating, and understanding application interaction and usage patterns, organizations can accelerate secure deployment of their digital applications and prompt touchdown dances for DX victories both small and large along the way. I mean, who doesn't want to see a SecOps team do the Ickey Shuffle?

But getting there requires adapting to the speed of the game, or transforming rapidly, which isn't an easy feat when DX involves complexities like public, private, and hybrid cloud infrastructure and a new breed of multitier applications need to be managed and secured. Much like a wide receiver making plays in double coverage, networking pros have to be able to run fast networks during DX while navigating everything from changing IT environments to regulatory challenges like the General Data Protection Regulation and security demands in the context of escalating cybercrime.

Here are four gridiron-inspired tips that can help see your way to DX success with data, guaranteeing a SecOps Gronk spike:

1. Create a championship culture from top to bottom.
Organizations can take a cue from great sports franchises that develop and maintain a winning culture. Digital transformation is a business imperative and, much like winning, is built on strong technology underpinnings, ultimately focused on driving the culture of the organization. It starts at the board and C-level team with a vision of what you want the company to be in five years and then determining whether or not you have the culture, people, and resources to get there. You have to deliberately become a data-driven culture in every aspect from top to bottom, and treat cybersecurity as a strategic business enabler rather than an obstacle, in order to win at DX.

2. See everything, all the time. 
Whether we're talking turf or network, clear visibility of the traffic is just as important as any other technical skills. Like a pass rusher on the quarterback's blind side, malware moves and data exfiltration happens across the network in stealth mode — not to mention the complexity of applications operating on-premises, in the cloud, or both. Having a clear line of sight into the organization's network and application layers lets you visualize your infrastructure, what's running on it, and how applications are performing and interacting with each other — and from there, extract kernels of insight to guide your DX efforts.

3. Handle complex schemes at top speeds.
Getting 53 professional athletes to master an NFL playbook comes with its challenges, not unlike wrangling the new breed of digital applications. Both require turning complexity into cohesion — and doing so fast. I'm referring to applications with multiple tiers (where each tier is scaled out and there's a set of microservices), some of which are built in-house, others are built externally, and some come from open source. When the components are sandwiched together, complexity escalates rapidly, which ultimately manifests itself as challenges around securing the applications, as well as ensuring consistent performance and experience. The key to keeping things under control is having the right kind of data to help you understand the interaction, performance, and security characteristics of these applications.

4. Be a good halftime coach.
Good coaches make quick adjustments to position the team for second-half success. NetOps and SecOps teams can relate when it comes to troubleshooting, managing, and securing applications. Whatever the application architecture, once in deployment something at some point is bound to go awry. You need to figure out what's happening and quickly course correct, but when you're scaling microservices, it's hard to troubleshoot just through application instrumentation. By analyzing the network traffic pertaining to these applications, you get immediate actionable data points that can be used to address trouble spots and understand security implications as well. The ability to isolate specific applications or microservices communication streams for deeper inspection would allow the security operations to easily understand access patterns and put in place effective micro segmentation strategies.

The NFL game is faster than ever, and the same can be said for the pace of digital business and the proliferation of cyber threats. The ability to the handle day-to-day challenges while positioning the organization for future success is only possible with the appropriate infrastructure in place. NetOps and SecOps teams are tasked with the development, implementation, maintenance, and security of very complex enterprise infrastructures that prepare their organization for tomorrow, much like NFL teams must draft and develop players for future success. Both must do so while reducing risks, costs, and security threats along the way. With the above-mentioned tips as the foundation of your journey, you can position your organization for success for seasons to come.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "10 Security 'Chestnuts' We Should Roast Over the Open Fire."

Shane Buckley is President and Chief Operating Officer of Gigamon with responsibility for expanding the company's business and markets worldwide. He brings more than 20 years of executive management experience to the team and joins Gigamon from Xirrus where he was CEO prior ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Wings2i
50%
50%
Wings2i,
User Rank: Apprentice
12/27/2019 | 12:14:51 PM
Digital Transformation
Informative read on the importance of Digital Transformation, and how to keep in pace with Digital Transformation...
joshuaprice153
50%
50%
joshuaprice153,
User Rank: Apprentice
12/10/2019 | 11:03:05 PM
4 Tips to Run Fast
Consider yourself fortunate to have acquired such  a collection of confidential info from them. But this article is lacking more in depth analysis which would have made more sense. Ran'D Shine - Magician in Philadelphia
Malicious USB Drive Hides Behind Gift Card Lure
Dark Reading Staff 3/27/2020
How Attackers Could Use Azure Apps to Sneak into Microsoft 365
Kelly Sheridan, Staff Editor, Dark Reading,  3/24/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-10560
PUBLISHED: 2020-03-30
An issue was discovered in Open Source Social Network (OSSN) through 5.3. A user-controlled file path with a weak cryptographic rand() can be used to read any file with the permissions of the webserver. This can lead to further compromise. The attacker must conduct a brute-force attack against the S...
CVE-2020-5527
PUBLISHED: 2020-03-30
When MELSOFT transmission port (UDP/IP) of Mitsubishi Electric MELSEC iQ-R series (all versions), MELSEC iQ-F series (all versions), MELSEC Q series (all versions), MELSEC L series (all versions), and MELSEC F series (all versions) receives massive amount of data via unspecified vectors, resource co...
CVE-2020-5551
PUBLISHED: 2020-03-30
Toyota 2017 Model Year DCU (Display Control Unit) allows an unauthenticated attacker within Bluetooth range to cause a denial of service attack and/or execute an arbitrary command. The affected DCUs are installed in Lexus (LC, LS, NX, RC, RC F), TOYOTA CAMRY, and TOYOTA SIENNA manufactured in the re...
CVE-2020-10940
PUBLISHED: 2020-03-27
Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.
CVE-2020-10939
PUBLISHED: 2020-03-27
Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.