Wednesday, May 20, 2015

Four Reasons the CTG and HP Partnership Matters

When a business comes to CTG and trusts us to provide an information technology platform to rely on every day, they are choosing our company for two critical components: our people and our partners.

We have built our company by finding young talent that believes in our customer-first approach and who are steady resources that grow with our client. But this is only part of the equation.

Equally important is that our team has developed critical partnerships to implement the best, most reliable and flexible technology in the industry today. That’s why we decided many years ago – after observing and testing products from the majority of the top IT manufacturers – to develop a strategic partnership with HP, whom is currently rebranding this part of it's business as Hewlett Packard Enterprises. Our strategic recommendations are built first on HP platforms and software, and we tap into other partnerships to meet specialty niches.

While you’re right to think that we’re a little biased about the high quality of HP at this point, we aren't the only ones. Just last week, the 2015 Gartner Magic Quadrant for Modular Servers – always a highly anticipated market analysis – endorsed the Palo Alto, Calif.-based manufacturer as a “Leader.” At CTG, we firmly believe in HP’s self-assessment that it “offers a strong product portfolio and delivers the right compute for the right workload at the right economics.”

By building a relationship with HP beginning nearly a decade ago, we, in turn, can offer key benefits to our customers:

1.      Simplicity. Whether you have an in-house IT team or rely on CTG for daily support, building a platform that connects different elements from storage and servers to desktops and networking from the same manufacturer streamlines your everyday management and workload. HP allows us to develop a strategic architecture and implement a single console for your IT needs, whether you are a mom-and-pop operation or a Fortune 500 company. Not many manufacturers can offer that full portfolio, and our CTG team provides a single point of contact.

2.      Expertise. As an HP Gold Partner, CTG has access to the best computing minds at Hewlett Packard. We receive unique training and education on the HP product suite. If you have a question, we can easily find the right answer. This single-vendor strategy allows us to deepen our knowledge as we consult with our clients to find the products that match their needs. That starts with HP hardware and extends to HP software as well. And when you have a specialty IT need that is outside the HP family, we can bring in the right resource and use our expertise to easily integrate it with your HP platform.

3.      Reliability and Innovation. Each is as important as the other. HP delivers products that are durable and carefully designed to meet evolving business needs. Of course, you want to know that you can trust your IT systems, but you also want to be ready to take the next step forward. We have seen firsthand that once HP releases a new product, it is already is back in the research and development lab, looking for enhancements to make that product even more efficient and effective – and to launch innovative new products. Our CTG team serves as a bridge to keep you running smoothly today and scaling up with new technology as your business grows.

4.      Value. Leveraging our knowledge of the HP product line, we can quickly assess your needs and recommend the best technology that delivers the best bang for your buck. In an ever more digitized economy, our clients are looking for the smartest solutions that allow them to best serve their customers. But IT budgets aren't limitless, and our HP relationship delivers a valuable win-win in the best firepower at the best price.

This is an exciting time to be working with the emergence of the Hewlett Packard Enterprise division. You will see the company putting a more complete focus on the data center. That means even greater R&D investments, better customer support, more product customization and a greater understanding of how technology intersects, drives and supports business strategies.

But don’t just take our word for it in this post. Give us a call – and we’ll show you the best that CTG and HP can offer.

John Monahan is a co-founder of Convergent Technologies Group.

Wednesday, May 13, 2015

Picking the Right Cloud

Last week, we discussed some common ground around what the Cloud should offer. Now let’s go with an analogy that I may just pile drive in to the ground by the end of this, but that I think is appropriate as we talk about types of clouds. And that is utilities. More specifically, let's talk power/electricity.

1. Public Cloud
Unless you live in the remote Western outback, odds are that you get electricity from your local power company.  You don't need to know how the utility company generated power or even how they delivered it to your home. You just know when it's there and when it's not. As a customer of cloud services, this works in a similar fashion.

You don't need to know, or totally care, about how your cloud provider's servers are configured, what the brand is, where they're physically located, or the name of the system administrators that keep it running. You will generally just care that it's there. Whether it's gmail/Google Apps, Office 365, or even if you are savvy enough to spin up your own servers on Amazon Web Services, you just don't need to know what is making all of that cloudy goodness happen. This is the public cloud.

However, if you’re a large enough company and are making a big move from housing your servers locally and onto the cloud, you'll be asking about all of the stuff most people don't care about when they use a hosted service.  For most businesses, though, it's more about brand recognition (Google, Microsoft, Amazon) than grilling potential providers about their infrastructure.

2. Private Cloud
A private cloud – which is generally used by large organizations with a well-qualified IT staff – is the equivalent (to return to our utilities metaphor) of running your own power generation operation.  

Using the same or similar technologies as the HPs, Googles, Microsofts and Amazons of the world, these businesses build out the network, servers, software and processes to deliver a similar set of services and characteristics internally. This is not for the light-hearted (or light-walleted) and very much like building your own power plant. The advantage is you get all of the benefits of cloudiness with all of the control that many organizations require or desire.

Just to add to the confusion, there is such a thing as a hosted private cloud, which may sound like it should be called a hybrid cloud, but it's not. You basically still run on a large cloud platform, but many more mechanisms keep your services separated from public services. You might need a VPN connection to get into your hosted private cloud.

3. Hybrid Cloud
No. This isn’t a Prius with a WiFi connection. That said, you have probably estimated that this combines public and private  cloud services. (In this case, private cloud is used as you've built your own in-house cloud).  This kind of setup offers the best of both worlds in that you can move services that may not be as critical  (or super secret) out to a Public Cloud provider and back as your own workloads require.  

Another common use of a hybrid cloud is for backup and recovery, as well as archiving.  Many companies today rent rack space in a data center, invest in another pile of hardware and set things up so that if their main office (or primary data center) were to have an issue they can continue to operate from that backup data center.  By deploying a private cloud and enabling it to talk and move services seamlessly to a public cloud provider,  they get a previously unheard of level of resiliency at a relatively low cost.

I almost forgot to whip out the power analogy (you know you would miss that). This is similar to having some solar panels that you use to cut down on your power bill a bit, but you still need the extra boost on a cloudy (pun intended) day and occasionally might even generate enough to sell back.  

4. Cumulonimbus Cloud
Ok, this isn't really a thing unless you're into the weather.   

I'm going to sign off for now, but I hope I've set us up with a common understanding of the cloud. Future posts will discuss different cases for the small, medium and large businesses, as well as myths and myth-busting.

In the next few weeks, our CTG team will be building our own private cloud, using HP Helion OpenStack on our Lab BladeSystems and 3PAR Storage. It's going to be a fun ride! Keep following us on social media to follow our journey.

Jeff Garell is a co-founder of Convergent Technologies Group.

Friday, May 8, 2015

Computing in the Cloud

Let’s start with the basics: What is the cloud? 

That's a really good question – but it doesn't come with an easy answer. The cloud means many things to many people, and you’ll often find the term used and abused by our industry’s marketing and advertising folks. 

To ground our discussion, let’s consider a common set of definitions, since this will be the first of many blog posts where we’ll be exploring the cloud, cloud services and where they might or might not fit in your environment.

So let's kick it off with a definition, ripped from Wikipedia.

Cloud computing is a computing term or metaphor that evolved in the late 1990s, based on utility and consumption of computer resources. Cloud computing involves application systems which are executed within the cloud and operated through Internet enabled devices. Purely cloud computing does not rely on the use of cloud storage as it will be removed upon users download action. Clouds can be classified as public, private and hybrid.

That clears it all up - thank you Virginia, good night!

Or perhaps not. Let's try to simplify this a little, but there’s no guarantee we won't get muddled up a little.

We should start with characteristics common to cloud technologies that carry across public, private and hybrid clouds.

Agility and Responsiveness are two words that you'll often hear cloudy sales people say. And while they sound kind of cheesy, when done correctly, they’re both absolutely  true. The ability to set up and tear down requested services – often via a self service portal – in a  matter of minutes (or an hour) is a big change to the monolithic change control process that many organizations have when requesting new services. 

CAPEX vs. OPEX is another driver for companies to move to a hosted (public) cloud solution regardless of their size. To dig a little deeper, CAPEX, or capital expense, is the use of your cash to buy physical things, such as servers and software.  As a business expense, you get to depreciate that spend over time.  OPEX, or operational expense, is what you pay to cover what it costs to operate. For example, a new copier is CAPEX, while paper and toner are OPEX. You can immediately write down OPEX instead of getting the credit over a multi-year period. Given that cash flow is king, many organizations prefer a monthly OPEX payment rather than a major CAPEX spend.

Scalability is another key characteristic of a good cloud solution. The ability to keep adding storage or compute power quickly and easily without having to re-engineer the whole thing is key to cloud provider growth.

Cost reductions are often touted as another reason to make the move, but this can be touchy. You need to conduct a Total Cost of Ownership (TCO) analysis to determine whether that will be true for your business. Cost should really be pretty far down on the list of reasons to go to the cloud unless you're hankering for some disappointment. When cost drives the cloud project, the results are often an under-provisioning of services (to meet a budget number) and unhappy end users.

Reliability and accessibility are another pair of words that those sales reps will toss out there without explanation. And once again, they're both enabled by the underlying architecture of cloud systems. Reliability comes in the form of hundreds or thousands (or, in the case of Microsoft and Google, 1,000,000 each of servers and the ability for various services to move seamlessly to a different physical server if one has a problem. Accessibility is delivered by having these services available on the Internet, which means if your office loses power, everyone can still work from home because the data is "in the cloud.”

Up next
Now that you have a framework for what a cloud and cloud computing can do for you, we’ll explore different types of clouds and how they could work in your business in our next post.

Jeff Garell is a co-founder of CTG.

Tuesday, April 28, 2015

Test and Learn

Do you remember how some of the best days in high school science class were when you got to go in the lab? When you had a problem to solve and you got to roll up your sleeves and experiment until you got the answer?

We got to do the professional version of just that last week, when we brought a handful of customers and special guests to the HP Customer Experience Center in New York. This is a living production laboratory for testing and learning, featuring the latest-and-greatest technology from HP today.

What made the trip invaluable:

We learned from the best in the business. At the Experience Center, HP offers its top subject matter experts to share new and emerging technology and answer questions on the spot. Technology represents one of the biggest line items for any company, and business leaders need to be confident that their suppliers and partners understand their needs and environment to offer the right resources at the right cost at the right time.

We saw the latest technology in action. Nothing is more important than seeing first-hand how different products and software can perform. The demonstrations not only presented good introductions to different resources, but they illustrated how to make the most of your technology. (Dare I admit that being in a nearly 10,000-square-foot facility with all that cutting-edge IT brought out the best geeks in us?)

We solved some vexing problems. A couple of clients came looking for answers to specific challenges with storage. In that real IT setting, HP experts were able to configure and demonstrate a storage array that would specifically eliminate those problems. Those clients now have a strategy to discuss with their business leaders and to use in determining how to prioritize the HP recommendations.

We got a sneak peak at what’s coming next. Our visit last week allowed us a glimpse into HP’s next generation of products, and how they will integrate with existing platforms.

Unique opportunity for customers
This hands-on experience is a rare perk of collaborating with CTG, which is an HP Gold Partner. During our nearly 10-year history, we have worked with a host of technology manufacturers, but we have chosen this specific partnership for HP’s comprehensive and integrated product portfolio. We know that all technology has a lifecycle, and our clients trust us to recommend hardware and configurations that meet today’s needs and are scalable for future business growth.

What our customers and guests told us was that this hands-on day gave them better insights into how HP’s architecture and products can deliver on all IT needs, from security to software, hardware to mobility. Because HP is one of the biggest in the industry, we know it can be daunting for our clients to navigate through all those products. This visit allowed our customers to learn more about why we trust HP, which delivers products that are equally innovative and reliable.

What happens next?
Our CTG team will be meeting with local HP account teams to host a technical discussion, where we will dive deeper into the day’s learnings.

And in keeping with our commitment to be on the leading edge, we already are planning our next visit to the HP Customer Experience Center. If you've got an IT challenge that is continuing to haunt you, let our CTG team know – and join us on our next trip to this IT laboratory.

John Monahan is co-founder of CTG.

Thursday, April 23, 2015

Kidnapping Your Data

Ransomware attacks at several of our customers over the past several weeks – including two in the past five days alone - speaks to the urgency with which you should understand and take action.

Ransomware, sometimes known by the names CryptoLocker or CryptoWall, are exploits that encrypt your data and then demand money to free it. So far, we've had some luck in mitigating the data loss for some customers that have been hit. Good backup practices in those cases saved the day.

First response is essential

I can't stress this enough: Call us immediately – but don’t wait for us to arrive before starting the first steps outlined below. 

The key first step is to right click the ransom note (usually a text file in the same directories as the encrypted files), select properties, and whomever owns that text file, well, that is the one that's infected.

Next, get any machine(s) off whatever network that file owner might have been using around the date/time that the file was created. Turn it off. Don't turn it back on until the operating system has been reloaded.

We'll want to look at every ransom note text file on the drive to make sure you don't have more than one infected machine. Do not delete those ransom note files: They're not infected, and they'll tell us how far the malware got before it stopped. They also hold important information should your worst case recovery option – paying the hackers - becomes the only option

Now that you’ve (hopefully) mitigated the problem’s spread, start lining up your recovery options.

1. Do you have a good recent backup? A good backup solution can reduce the amount of data lost to hours, or, at worst, days. Days might not be a big deal depending on the volume of changes to a file. The proposal you wrote a year ago? Not a biggie. Your accounting database? Probably a biggie.

2. Pay the ransom. Unfortunately, you might have to balance the ransom cost with the value of that hijacked data. At least you won't have ABC News doing a story on you, like a certain sheriff's department in that link above. The good news is that these efforts are specifically intended to generate revenue. In an odd bout of honor among thieves, they’ll want to unlock your files after payment because, if they don’t, then no one will pay.

Why? Why? Why?!! (or should that be How?? How?? How??!!)

The first thing we hear is "How did this happen? I have anti-virus running!" That doesn't really matter. In fact, we've seen in one case that anti-virus programs were blocking less than 20 percent of malware.

The latest efforts have gotten even more sophisticated. Where once you had to actually do something – such as click on a link or ad, go somewhere potentially suspect, or download software – now you just need to visit your favorite well-known website (think big trusted organizations with ads on their sites). This has gotten pervasive enough to get its own name: malvertising. Yes, those flashy (pun intended) ads that pop up and try to get your attention are the vector for this exploit. I'll skip repeating what other news stories or blogs say, and we can go on to some good suggestions to avoid this issue.

How to avoid ransomware

While you might be tempted to move to a remote cabin in Montana or disconnect the Internet entirely, you do have other viable options. But they come with some trade-offs, such as Web pages not rendering how they're intended or having to occasionally let scripts run on a site that requires it. Get hit once and lose critical data, and those trade-offs become more tolerable.

1. Choose your browser wisely. I rarely use Internet Explorer unless a vendor’s site is still locked in to some proprietary Microsoft Web things. Consider switching to FireFox or Chrome. Most of the security analysts I know and listen to use FireFox as their primary browser.

2. Add some extensions (add-ons) to your browser. Add and enable Flash and script blockers, which will stop ads and scripts from automatically running and potentially delivering the malware to your machine. For FireFox, I have FlashBlock and NoScript running. Each gives me the option to enable the Flash or scripts on a case-by-case basis, but nothing runs automatically, For Chrome I use FlashControl and ScriptSafe.

3. Stop clicking on shortened URLs. Those things can take you anywhere, and you won't know until it's too late. I know that kitten pic that someone tweeted about is incredibly tempting. Don't do it. At least not on a company PC.

4. Keep your applications and operating systems up-to-date. When you receive security patches and updates, be sure you are routinely running them.

5. User Awareness is paramount. You can’t take adequate precautions without being aware of the dangers. Given the ever-changing threat landscape of the Internet, make awareness a recurring theme. Over the next few months, we'll be putting together a regular published newsletter that you can forward to your employees.

6. Good backups are the answer. That statement probably stands on its own. Whether it's some outsider encrypting your data or a disk drive failing, you want to be able to get that data back.

The bad guys are getting more creative, and your traditional firewalls and anti-virus are no longer enough to hold off the horde. CTG is ready to come in and consult on ways to better protect your data from thieves, vandals and kidnappers.

 Jeff Garell is co-founder of CTG.

Wednesday, April 15, 2015

4 Reasons You Need CTG as Your IT Partner Right Now

It’s easy to call Convergent Technologies Group an IT company. But that’s like saying Nike is an athletics company or Kraft is a food company. Each of us provides a range of products or services under that category umbrella, but each of us has strategically honed in on core offerings that reflect what we can deliver best for our customers.

Being nimble and staying on the leading edge of the ever-changing IT market has been an integral part of CTG’s evolution over the past decade. We now offer a core platform of services that allow us to meet many common IT needs for our customers, no matter where they are in their lifecycle or within their industry.

Some customers come to CTG looking for a specific service, then deepen their relationship with us as they learn more about our extended capabilities. Other clients – including startups and smaller mom-and-pop operations – recognize us from the beginning as a daily partner to whom they can entrust their complete IT needs.

So, why should you consider CTG right now as your IT partner?

1.      We build the data center that meets your needs. From the initial steps of planning the architecture that aligns with your business operations to implementing storage and backup services to handle everyday tasks, we start by sitting down with our customers to understand both current and targeted goals, working to develop an IT framework that can scale with the business. Within that, we incorporate disaster planning and recovery, as well as integrating the best applications to support your varied business tasks. With our strong relationships to the nation’s top IT manufacturers, including as an HP Gold Partner, we can deliver the highest-quality platforms at the smartest cost for your business, including next-generation resources such as virtualization.

2.      We keep your IT secure. Every day, you hear news of attempted – or worse, successful – hacks on corporate technology networks. Because this is one of the biggest worries for business owners, we have developed critical processes using the most-effective tools to put up the best defense. The first step, with the customer’s blessing, is to do our own penetration testing to identify a network’s vulnerabilities, coupled with security audits and assessments. We then offer best-in-class resources, which are continually updated, to protect you and your business.

3.      We offer managed services that keep your doors open for business.Our remote support and help desk actively track and monitor your network operations, because we know that even the best systems can have their bad days. We often find and solve those hiccups before you – or your customer – even notice. We also offer cloud solutions and other resources that allow you to focus your energy on where it matters most: your business and customers.

4.      We support you wherever you are. Work doesn't happen in the office from 9-to-5 anymore. You and your workers are handling more and more remotely, whether delivering a presentation at a client’s office or catching up on a project at home after leaving early to watch a child’s performance. We can implement the best mobility resources and wireless solutions to ensure you can work productively, while maintaining the highest network security.

Information technology long ago stopped being a one-size-fits-all business commodity. We know that, which is why every solution we craft is based on the specific needs of our customers. We listen to what you need, then apply our expertise to develop the IT services that let you run your daily business effectively and efficiently.

John Monahan is co-founder of CTG.

Tuesday, April 7, 2015

Why You Need to Audit and Test Your Network

Security is a moving target. What’s acceptably secure today might not be tomorrow.

On the product side, even firewalls may have an undiscovered vulnerability lurking in the code. Recently announced vulnerabilities – such as HeartBleed, ShellShock and recent Windows fixes – were for things that had been sitting in the code for a decade or more and just hadn’t been found yet.

As discussed in last week’s post, threats on networks are intensifying, and your efforts to protect your business need to step up to that challenge.

Penetration Testing

To see how secure your network is, consider one of today’s security tests:

  • External: Attack from the outside and attempt to breach the network perimeter.
  • Internal: Attack from within to see what is possible if an intruder (or insider) got inside.
  • Social Engineering: Focus on whether your employees say or do something that could open a door to a breach.
  • Physical: Attempt to enter the premises under false pretenses and gain enough access to implant a remote access device, install software/malware or grab data without being detected.

Our CTG team regularly conducts either individual or a combination of security tests, working with our clients on the best approach to identify any vulnerabilities.

Monitoring, Detection and Incident Response

No matter how well you patch, secure and maintain your systems, ever-changing threats can thwart the best-laid plans and efforts. Putting your detection systems to work is just the first step.

Good detection without a solid incident response capability is nearly worthless. Just ask Target and Home Depot: These companies’ systems both detected breaches, buth their response protocols were not followed or were not fully tested.

An incident response plan mirrors many of the characteristics in disaster recovery planning:

  • Foresight to consider what can go wrong,
  • Written processes and procedures to avoid the “seat of pants” activities when it does,
  • Chain of command and reporting processes so management at all levels can remain informed and make appropriate business decisions. 
  • And practice, practice, practice.

Vulnerability Scanning

Vulnerability scanning is not a penetration test, however a penetration test includes vulnerability scanning. A vulnerability scan is an automated testing tool for basic probes and simulated attacks. With penetration testing, our highly skilled team uses our knowledge to attempt to bypass your security controls and gain access. An automated scanner can’t make tactical decisions based on responses.

That said, vulnerability scans are useful for helping to determine a device’s susceptibility to recently discovered exploits. For example, ShellShock and Heartbleed were long unknown vulnerabilities discovered in 2014. Vulnerability scanners were some of the first to release signatures and automated tests to help discover whether your systems included those risks.

Policy Audits

A policy audit often completes an Internal Penetration test. We’ll look at your written security policies (you do have written security policies, right?) and validate that they meet your targeted security posture and are implemented consistently.

Reporting and Remediation

Clients come to CTG to identify issues, and we complete each penetration testing and related analysis with comprehensive executive and technical briefings. We’ll tell you exactly what we uncovered, and, more importantly, we’ll offer specific recommendations on how to enhance your network security.

Jeff Garell is co-founder of Convergent Technologies Group.