Consumer gratification is present day company battleground. The winners are the companies that provide the most effective, maximum-operating software program and purposes in the shortest total of time.
ChatGPT is the latest case in point of a successful app. In just a several months, the software has achieved 100 million buyers, generating it the quickest-expanding consumer application ever. Its good results has also established off an artificial intelligence (AI) apps arms race, with competitors, which includes Google, rising to get industry share as speedy as feasible. This race illustrates the ongoing struggle businesses confront to immediately develop higher-undertaking computer software and purposes that are also remarkably secure. This is a sensitive balance in present day ecosystem, exactly where buying and selling protection for speed could lead to disastrous repercussions.
Stability-Speed Equilibrium
One particular strategy that corporations are embracing to strike this balance is implementing the “change left.” The change still left in this context refers to shifting procedures associated to tests software package as early in the improvement method as doable. By embracing the shift still left, technological innovation teams — especially DevOps teams — can discover bugs, errors, and vulnerabilities early on and take care of them, ensuing in superior-doing, very protected application, and apps.
Below are 4 techniques DevOps teams can take to embrace the shift still left, enhance application general performance, lower vulnerabilities, and gain the stability battle.
Stage 1: Outline the Security Strategy
No army value its salt heads into the subject with no a comprehensive map of the terrain, facts on adversaries, and a hierarchy in location with duties for just about every rank. The same should be legitimate of any DevOps unit shifting left.
Organizations should really just take the time to establish who will be in charge of what responsibilities, ascertain metrics for achievement, and formalize methods. DevOps leaders ought to establish appropriately staffed groups, put into action processes that maximize stability, and establish what type of checks they will operate and how often they will operate them. Enterprises ought to also identify and put together for unique recognized vulnerabilities that could direct to problems.
Shifting remaining includes developing a new established of concepts for program supply and stability thus, planning and defining the strategy is quite significant.
Action 2: Have an understanding of the Progress Pipeline and Deployment System
As firms change left, it can be significant to have a comprehensive being familiar with of the software package improvement pipeline and the deployment system.
This pipeline is the established of equipment and procedures in location to create and release software and programs. When this assessment and understanding is comprehensive, DevOps groups can begin carrying out assessments in the create pipelines, examining code validity inside improvement environments, and considerably far more.
A single solution that is assisting DevOps groups map and comprehend their pipelines and embrace the shift remaining is observability. With observability, groups can assist groups get a one-pane-of-glass check out throughout purposes, databases, and infrastructures that can be vital to being familiar with software performance, person practical experience, and the all round environment necessary for fashionable application architecture. Some observability solutions even offer you live code profiling that automatically sees probable person problems or effectiveness bottlenecks prior to code is shipped.
Phase 3: Incorporate Safety Automation
In organization technological know-how, software package groups have turned to automation to streamline tests for a number of explanations. First, manually tests program can introduce human mistake. Next, the change still left necessitates companies to exam software program as early and often as probable. And whilst these rules are meant to develop much more protected, far better-doing goods, this higher quantity of tests can also end result in overloaded teams, demanding DevOps to manually appraise every new attribute the progress crew introduces.
To prevent this circumstance, DevOps teams should use applications that automate operating exams. Doing so will aid reduce the worry placed on DevOps groups though also delivering faster feed-back similar to any vulnerabilities that may perhaps be located in software code. Frequently, automating checks in the development cycle makes it possible for organizations to improve the velocity with which a item is concluded whilst guaranteeing that fewer bugs or vulnerabilities are located afterwards.
Action 4: Create a Tradition of Transparency
While automation and contemporary engineering can contribute substantially to an organization’s accomplishment, a more human approach and trait performs an equally vital position — communication and transparency.
A single of the important rules powering DevOps is narrowing the divide concerning advancement and production. Growing conversation and transparency across the product and software program growth existence cycle can enable narrow this divide. As it relates to the change left, involving the suitable group members as early as probable and through each step in the procedure is important to escalating transparency.
By prioritizing communication and incorporating transparency to the approach wherever feasible, group members will far better recognize how to test, what vulnerabilities to glance for, and how to make software package and programs additional safe, much better undertaking, and far more resilient.
Alarmed by a September ransomware attack that crippled Suffolk County government, several Long Island towns and villagessaidthey are re-evaluating their cybersecurity programs and taking steps to close vulnerabilities that could be exploited by hackers.
Municipalities contacted by Newsday said they had not experienced any recent attacks on their systems. But the breach on Suffolk Countycomputer networks that may have exposed the Social Security numbers of some 26,000 county employees and the personal information of up to 470,000 people was a wake-up call,they said.
For instance, in East Hampton Town and Patchogue Village, officials are beefing up their cybersecurity systems.
The Sept. 8 ransomware attack on Suffolk County exposed weaknesses in hardware that stores sensitive personal information on employees and people who pay fees and fines to county agencies, officials said, and it forced the county to resort to paper records and in-person payments, applications and evaluations across a range of departments.
“It really made you aware of the gravity of it,” Patchogue Mayor Paul Pontieri told Newsday. “If you can paralyze a county … and paralyze Suffolk County, can you imagine what it would do to a village our size? It would shut us down.”
Town, city and village agencies, from clerk’s and tax receiver offices to courts to building and police departments, typically store information from residents and employees such as home addresses and driver’s license numbers that could be of interest to hackers.
Long Island municipalities, speaking generally about cybersecurity in the wake of the county attack, said they believe their computer systems are protected against hacking attempts, and some said they have moved in recent months to improve data backups, upgrade monitoring programs and educate staff about cybersecurity.
Officials in Brookhaven, Riverhead and Southampton towns declined to disclose how much they spend on cybersecurity and refused to discuss details of their programs — citing fears that even the slightest public dissemination of those measures might help hackers break into their systems. But they said their systems were secure and tested frequently.
Riverhead Supervisor Yvette Aguiar, a retired NYPD sergeant, said the town has increased monitoring since the county attack and worked to ensure it has data backups both locally and off-site. “Currently, we have not experienced any unusual activity or losses in our town,” she said in a voicemail message to Newsday.
Brookhaven Town “had a number of things in place prior to what happened to the county that protected our system, and we continuously monitor, update and upgrade,” said Kevin Molloy, chief of staff to Supervisor Edward P. Romaine.
East Hampton Town on Dec. 20 authorized $865,000 for a cybersecurity service to monitor possible cyberthreats and implement a cloud-based backup system, and Pontieri said Patchogue officials are following recommendations from the village’s East Northport-based consultant to move more sensitive information to the cloud.
Smithtown officials met last fall with IT staff to discuss upgrading security, conducting “penetration testing” to see whether data is secure and possibly hiring an outside consultant to monitor the town’s systems, spokeswoman Nicole Garguilo told Newsday.
“There’s no harm in … hardening your defenses and review what you’re doing,” she said. “You could have a secure [system] this month, and next month someone hacks into your system.”
The Islip Town Board voted 5-0 on Jan. 24 to pay a Pennsylvania firm, Custom Computer Systems, $136,000 for “investigation, repair and remediation” following the discovery in November of what town officials called “unusual activity” in cyber systems.
The Town of Southold has added to cybersecurity since the county attack, implemented multifactor authentication and is in the process of getting cyber insurance, said Lloyd Reisenberg, network and systems administrator.
Officials in Long Beach, Hempstead, North Hempstead and Oyster Bay were tight-lipped about protocols but said they take protecting municipal IT systems seriously and regularly test safeguards in place.
Officials in the towns of Huntington and Babylon declined to comment or did not return phone, email and text messages.
Glen Cove Mayor Pam Panzenbeck told Newsday the city has budgeted $100,532.49 this year for cybersecurity, about 52{b7c9e2c88beb1a84f22d94ab877a147f4adc4b3519717f3f957a0f34e16918d1} of its information technology budget.
Cybersecurity consultants contacted by Newsday warned against complacency, saying no system is perfect and breaches are inevitable.
“The biggest mistake we see with state and local governments is not taking cybercrime seriously enough,” said Steve Morgan, founder of Cybersecurity Ventures, a Northport-based cybersecurity research firm. “The prevailing attitude having to do with a major cyberattack is that, ‘It won’t happen to us,’ which leads to, ‘We’ll deal with it when it happens.’ ”
Budget-conscious municipalities often don’t spend enough on security — a shortsighted view that could lead to much greater costs later on, said Vahid Behzadan, assistant professor of cybersecurity and networks at the University of New Haven in West Haven, Connecticut. Paying ransom and restoring compromised systems could run to millions or tens of millions of dollars, he told Newsday.
Behzadan and others strongly recommend moving backup data to off-premises sites such as cloud systems and storing some information in separate on-site computer systems. They also advise simpler steps such as frequently changing passwords, adopting multifactor authentication — using separate devices to log in to computers and email — and training staff to recognize potentially malicious messages.
“Many of the larger organizations drill on a regular basis, but smaller organizations either can’t see the benefit” or think it’s not cost-effective, Behzadan told Newsday. “In many cases, it’s worth the time and the effort because it prevents larger problems that may occur.
“No one on the internet is safe. … Everyone on theinternet can become a target or a victim of a ransomware campaign,” he added.
Estimates of Suffolk’s costs related to the September breach have ranged from $5.4 million for investigation and restoration to as much as $17 million for new software, hardware and licenses.
County Executive Steve Bellone said in December officials refused to pay a $2.5 million ransom to hackers.
Gov. Kathy Hochul on Wednesday proposed the state provide $44 million to strengthen local governments’ cyber defense and response to attacks. The funding would cover hardware and software security tools and the cost of some trained workers. The idea is to reduce vulnerabilities in government computer networks in state and local governments, she said.
Suffolk officials added $8 million to the county budget this year for cybersecurity. The funds are earmarked for 10 cybersecurity analysts, a chief information security officer and to “upgrade and harden existing systems to better protect the county from the possibility of future intrusions,” Suffolk spokeswoman Marykate Guilfoyle told Newsday in an email Friday.
The Nassau Legislature in December approved a contract with a cybersecurity vendor but did not disclose the vendor or how much the firm would be paid, citing concerns that such information could compromise county systems.
Attacks on town and village systems appear to be rare.
But Islip Town reported suspicious activity during the Thanksgiving weekend that prompted the town to “limit access as we thoroughly review any potential unauthorized use of the system,” officials said at the time.
Town officials declined to specify the nature of the suspicious activity or how it was addressed. Newsday on Thursday submitted a state Freedom of Information Law request for that information.
Officials of other towns said they regularly test their systems for flaws, even conducting surprise tests of staff.
Paula Pobat, information technology director for Southampton Town, said the town has both in-house staff and an outside consultant working on cybersecurity. She declined to discuss specific security measures.
“We continue to look at our cybersecurity posture as part of our daily operations. Can I say that something has changed specifically [since September]? Probably not,” she said. “The town, and probably all towns at this point, need a cybersecurity coordinator. I think that really is a necessity, which probably wouldn’t be the case five years ago.”
Shelter Island IT chief Kevin Lechmanski said the town regularly conducts hacking simulations, or “test phishing,” by sending fake emails to staff. Employees are trained to look for anomalies such as nonstandard email addresses that indicate a seemingly innocuous message could be an attempted hack, he said.
“People are pretty aware … about what not to open,” he told Newsday. “If you know what you’re looking for, you can tell that they’re kinda fake.”
Some phony emails, such as the infamous Nigerian prince scam, are relatively easy to spot, Lechmanski said. But others might be disguised as the kind of casual messages office workers see every day, he said.
“Someone sent out an email saying, ‘We’re organizing a birthday party,’ ” Lechmanski said, recalling one recent spam message. “Uh, no, we’re not.”
Patchogue officials agreed to upgrade their cybersecurity following a Dec. 12 presentation by Sourcepass Inc., the village’s IT consultant.
Sourcepass security architect Dan Levy told officials and residents at a village board meeting that the Suffolk attack left the county scrambling to restore systems that had not been properly “segmented,” or separated from main data storage centers.
“When systems went down, their ability to restore and get things up in a timely matter was very difficult,” Levy said.
“There’s never perfect,” he said. “We always have to continually improve.”
With Brinley Hineman, Brianne Ledda and Michael Gormley
Alarmed by a September ransomware attack that crippled Suffolk County government, several Long Island towns and villagessaidthey are re-evaluating their cybersecurity programs and taking steps to close vulnerabilities that could be exploited by hackers.
Municipalities contacted by Newsday said they had not experienced any recent attacks on their systems. But the breach on Suffolk Countycomputer networks that may have exposed the Social Security numbers of some 26,000 county employees and the personal information of up to 470,000 people was a wake-up call,they said.
For instance, in East Hampton Town and Patchogue Village, officials are beefing up their cybersecurity systems.
The Sept. 8 ransomware attack on Suffolk County exposed weaknesses in hardware that stores sensitive personal information on employees and people who pay fees and fines to county agencies, officials said, and it forced the county to resort to paper records and in-person payments, applications and evaluations across a range of departments.
WHAT TO KNOW
Several Long Island towns and villages are re-evaluating their cybersecurity programs in the wake of a September ransomware attack that crippled Suffolk County.
Municipalities contacted by Newsday said they had not experienced any recent attacks on their systems but said the attack on Suffolk was a wake-up call.
Experts said governments must guard against complacency, saying no system is perfect and breaches are inevitable.
Patchogue Mayor Paul Pontieri at a village board meeting on Dec. 12. The village is following recommendations from an East Northport consultant to move more sensitive information to the cloud.
Credit: Dawn McCormick
“It really made you aware of the gravity of it,” Patchogue Mayor Paul Pontieri told Newsday. “If you can paralyze a county … and paralyze Suffolk County, can you imagine what it would do to a village our size? It would shut us down.”
Town, city and village agencies, from clerk’s and tax receiver offices to courts to building and police departments, typically store information from residents and employees such as home addresses and driver’s license numbers that could be of interest to hackers.
Steps to ensure cyber safety
Long Island municipalities, speaking generally about cybersecurity in the wake of the county attack, said they believe their computer systems are protected against hacking attempts, and some said they have moved in recent months to improve data backups, upgrade monitoring programs and educate staff about cybersecurity.
Officials in Brookhaven, Riverhead and Southampton towns declined to disclose how much they spend on cybersecurity and refused to discuss details of their programs — citing fears that even the slightest public dissemination of those measures might help hackers break into their systems. But they said their systems were secure and tested frequently.
Riverhead Supervisor Yvette Aguiar, a retired NYPD sergeant, said the town has increased monitoring since the county attack and worked to ensure it has data backups both locally and off-site. “Currently, we have not experienced any unusual activity or losses in our town,” she said in a voicemail message to Newsday.
Brookhaven Town “had a number of things in place prior to what happened to the county that protected our system, and we continuously monitor, update and upgrade,” said Kevin Molloy, chief of staff to Supervisor Edward P. Romaine.
Lisa Guerin of Sourcepass Inc. discusses cybersecurity at the Dec. 12 Patchogue Village board meeting.
Credit: Dawn McCormick
East Hampton Town on Dec. 20 authorized $865,000 for a cybersecurity service to monitor possible cyberthreats and implement a cloud-based backup system, and Pontieri said Patchogue officials are following recommendations from the village’s East Northport-based consultant to move more sensitive information to the cloud.
Smithtown officials met last fall with IT staff to discuss upgrading security, conducting “penetration testing” to see whether data is secure and possibly hiring an outside consultant to monitor the town’s systems, spokeswoman Nicole Garguilo told Newsday.
“There’s no harm in … hardening your defenses and review what you’re doing,” she said. “You could have a secure [system] this month, and next month someone hacks into your system.”
The Islip Town Board voted 5-0 on Jan. 24 to pay a Pennsylvania firm, Custom Computer Systems, $136,000 for “investigation, repair and remediation” following the discovery in November of what town officials called “unusual activity” in cyber systems.
The Town of Southold has added to cybersecurity since the county attack, implemented multifactor authentication and is in the process of getting cyber insurance, said Lloyd Reisenberg, network and systems administrator.
Officials in Long Beach, Hempstead, North Hempstead and Oyster Bay were tight-lipped about protocols but said they take protecting municipal IT systems seriously and regularly test safeguards in place.
Officials in the towns of Huntington and Babylon declined to comment or did not return phone, email and text messages.
Glen Cove City budgeted $100,532 this year for cybersecurity
Glen Cove Mayor Pam Panzenbeck told Newsday the city has budgeted $100,532.49 this year for cybersecurity, about 52{b7c9e2c88beb1a84f22d94ab877a147f4adc4b3519717f3f957a0f34e16918d1} of its information technology budget.
Cybersecurity consultants contacted by Newsday warned against complacency, saying no system is perfect and breaches are inevitable.
“The biggest mistake we see with state and local governments is not taking cybercrime seriously enough,” said Steve Morgan, founder of Cybersecurity Ventures, a Northport-based cybersecurity research firm. “The prevailing attitude having to do with a major cyberattack is that, ‘It won’t happen to us,’ which leads to, ‘We’ll deal with it when it happens.’ ”
East Hampton Town authorized $865,000 for a cybersecurity service
‘No one on the internet is safe’
Budget-conscious municipalities often don’t spend enough on security — a shortsighted view that could lead to much greater costs later on, said Vahid Behzadan, assistant professor of cybersecurity and networks at the University of New Haven in West Haven, Connecticut. Paying ransom and restoring compromised systems could run to millions or tens of millions of dollars, he told Newsday.
Behzadan and others strongly recommend moving backup data to off-premises sites such as cloud systems and storing some information in separate on-site computer systems. They also advise simpler steps such as frequently changing passwords, adopting multifactor authentication — using separate devices to log in to computers and email — and training staff to recognize potentially malicious messages.
“Many of the larger organizations drill on a regular basis, but smaller organizations either can’t see the benefit” or think it’s not cost-effective, Behzadan told Newsday. “In many cases, it’s worth the time and the effort because it prevents larger problems that may occur.
“No one on the internet is safe. … Everyone on theinternet can become a target or a victim of a ransomware campaign,” he added.
Estimates of Suffolk’s costs related to the September breach have ranged from $5.4 million for investigation and restoration to as much as $17 million for new software, hardware and licenses.
County Executive Steve Bellone said in December officials refused to pay a $2.5 million ransom to hackers.
Gov. Kathy Hochul on Wednesday proposed the state provide $44 million to strengthen local governments’ cyber defense and response to attacks. The funding would cover hardware and software security tools and the cost of some trained workers. The idea is to reduce vulnerabilities in government computer networks in state and local governments, she said.
Suffolk officials added $8 million to the county budget this year for cybersecurity. The funds are earmarked for 10 cybersecurity analysts, a chief information security officer and to “upgrade and harden existing systems to better protect the county from the possibility of future intrusions,” Suffolk spokeswoman Marykate Guilfoyle told Newsday in an email Friday.
The Nassau Legislature in December approved a contract with a cybersecurity vendor but did not disclose the vendor or how much the firm would be paid, citing concerns that such information could compromise county systems.
Hacking tests to security upgrades
Attacks on town and village systems appear to be rare.
But Islip Town reported suspicious activity during the Thanksgiving weekend that prompted the town to “limit access as we thoroughly review any potential unauthorized use of the system,” officials said at the time.
Town officials declined to specify the nature of the suspicious activity or how it was addressed. Newsday on Thursday submitted a state Freedom of Information Law request for that information.
Islip Town is paying $136,000 for ‘investigation, repair and remediation’ following ‘unusual activity’ in their cyber systems
Officials of other towns said they regularly test their systems for flaws, even conducting surprise tests of staff.
Paula Pobat, information technology director for Southampton Town, said the town has both in-house staff and an outside consultant working on cybersecurity. She declined to discuss specific security measures.
“We continue to look at our cybersecurity posture as part of our daily operations. Can I say that something has changed specifically [since September]? Probably not,” she said. “The town, and probably all towns at this point, need a cybersecurity coordinator. I think that really is a necessity, which probably wouldn’t be the case five years ago.”
Would you fall for this spam email?
Here is an example of a suspicious email used by Shelter Island Town IT staff to train employees about potentially malicious messages. The town conducts “test-phishing” exercises in which fake emails like this are circulated to see if employees respond to spam. Those who click on links contained in the emails are reported, and those employees receive additional training, Shelter Island IT director Kevin Lechmanski told Newsday.
Shelter Island IT chief Kevin Lechmanski said the town regularly conducts hacking simulations, or “test phishing,” by sending fake emails to staff. Employees are trained to look for anomalies such as nonstandard email addresses that indicate a seemingly innocuous message could be an attempted hack, he said.
“People are pretty aware … about what not to open,” he told Newsday. “If you know what you’re looking for, you can tell that they’re kinda fake.”
Some phony emails, such as the infamous Nigerian prince scam, are relatively easy to spot, Lechmanski said. But others might be disguised as the kind of casual messages office workers see every day, he said.
“Someone sent out an email saying, ‘We’re organizing a birthday party,’ ” Lechmanski said, recalling one recent spam message. “Uh, no, we’re not.”
Patchogue officials agreed to upgrade their cybersecurity following a Dec. 12 presentation by Sourcepass Inc., the village’s IT consultant.
Patchogue officials agreed to upgrade their cybersecurity following a Dec. 12 presentation by Dan Levy of Sourcepass Inc., the village’s East Northport-based IT consultant.
Credit: Dawn McCormick
Sourcepass security architect Dan Levy told officials and residents at a village board meeting that the Suffolk attack left the county scrambling to restore systems that had not been properly “segmented,” or separated from main data storage centers.
“When systems went down, their ability to restore and get things up in a timely matter was very difficult,” Levy said.
“There’s never perfect,” he said. “We always have to continually improve.”
With Brinley Hineman, Brianne Ledda and Michael Gormley
Cybersecurity tips
Experts offer this checklist of steps municipalities should take to improve their cybersecurity:
Back up sensitive data such as emails and payment information to separate computer systems that are not linked to the main data storage area;
Move existing backups to cloud-based storage;
Install website filtering and anti-virus software;
Conduct penetration testing and phishing simulations;
Instruct staff to change passwords frequently;
Adopt multifactor authentication;
Train staff to recognize potentially malicious email and text messages;
Test systems several times annually.
Carl MacGowan is a Long Island native who covers Brookhaven Town after having previously covered Smithtown, Suffolk County courts and numerous spot news and feature stories over his 20-plus year career at Newsday.