The Secure UX Enterprise - Part 2
December 07, 2016

Gabriel Lowy
TechTonics

Share this

Start with The Secure UX Enterprise - Part 1

A Unified Approach Begets Convergence and Collaboration

Unfortunately, most enterprise IT teams still monitor and manage user experience from traditional technology domain silos, such as server, network, application, device, operating system and security. As workloads continue to shift to new architecture, this approach only perpetuates an ineffective, costly and politically-charged environment. 

A unified approach allows IT teams to help their companies leverage technology investments to discover, interpret and respond to the myriad events that impact their operations, competitiveness, security and compliance.

IT Ops teams must understand their users and prioritize the performance of their apps and websites accordingly. They can make sure the apps that drive the business have the highest availability and reliability. In concert with the security team, they can take a balanced approach to prioritizing risks across the enterprise.

As opposed to conventional security layering by infrastructure, application, device and user, a prioritized risk approach allows the security team to dedicate more resources and attention to the assets that are most important to the organization. This strategy is more proactive and intelligence-based, enabling the security team to better defend the organization's most valuable data assets, respond to and remediate incidents in a timely fashion and meet GRC requirements.

Automated continuous monitoring, advanced behavioral analytics, incident response automation and software-defined perimeter provide transaction-level insights into the IT environment that UX and security teams need to better ensure performance, while protecting against risks and improving incident response. Correlations, machine learning engines, and advanced behavioral analytics and data visualization create context based on granularity about users, applications, and endpoints.

The intelligence they provide establishes benchmarks against key performance indicators (KPIs) for what is normal activity and identify anomalous behavior in real time. UX teams can triage the root cause of poor performance to speed MTTR.

Monitoring that is more pervasive, automated and intelligent allows security teams to better understand risks and prioritize threats. Policies and enforcement can be applied automatically to specific applications, user groups or roles so that security teams can use this intelligence to isolate and contain an attack before intruders can cause substantial damage.

A unified approach facilitates mapping resource and application dependencies through a single view of all components that support a service to ensure transaction completion. For security teams, it provides visibility and intelligence into the validity of the transaction and the users involved. They can see the data going into these environments, whether users are authorized to work with this data and when data is attempting to leave.

Automation provides speed and scale to keep up with new architectures and traffic growth. It improves agility and governance, reduces costs, and helps UX and security teams mitigate human error and remediate more effectively.

Next-generation solutions are all capable of collecting vast amounts of transaction data. They can then run advanced analytics against this data for a variety of secure UX use cases. To enable this type of collaboration, data also has to be assimilated from network service providers and cloud service providers in addition to data from within the enterprise.

Data Integration is Key

The better integrated these technologies are, the more intelligence UX and security teams derive from them and the more efficiently they can prioritize risks and remediation. Greater efficiency with IT Ops and security data can drive sustained competitive advantage and reduce risk at lower total cost of ownership (TCO).

Data integration is labor intensive and time consuming. IT teams get bogged down trying to integrate data from different tools. The proliferation of tools for both performance and security monitoring has resulted in a patchwork quilt of incompatible consoles and data. Teams end up spending more time writing scripts preparing data for analysis than gaining real-time insights into secure UX. And they often ignore the barrage of false positives these different tools generate.

Modern integration tools automate much of the cleansing, matching, error handling and performance monitoring that IT Ops and security teams often struggle with manually. Application governance allows teams to take a standardized approach to integrating diverse data sets, including those from SaaS applications and IaaS or PaaS clouds. Unifying disparate data points provides both IT Ops and security teams with more actionable intelligence to speed MTTR and incident response.

Conclusion

Secure UX has a domino effect across all functional areas of the organization. Users from sales, marketing and product development through manufacturing and supply chain management have more confidence in the data they are working with. The result is improved modeling and decision outcomes. At the same time, companies strengthen financial management, reduce risk and ensure adherence with governance, regulatory and compliance requirements.

IT teams must evolve toward a unified approach that promotes collaboration and efficiency to better align with corporate ROI and risk management objectives. Nearly three years ago, we introduced the PADS (Performance Analytics and Decision Support) Framework as a more strategic approach to integrating next-generation performance management and security with big data analytics technologies. It established best practices for assuring user experience, reducing risk and improving decision making enabling IT Ops and security teams to rapidly respond to the myriad events that impact their operations, security, compliance and competitiveness.

Leading and next-generation vendors in adjoining spaces such as application delivery controllers (ADCs), network and application performance monitoring and management (NAPM) and security information and event management (SIEM) have been coalescing around a unified approach to secure UX.

Expect these platforms to evolve further toward operational intelligence by expanding the types of data sources they collect and correlate. They will also drive deeper into analytics, including predictive capabilities, to allow IT – and eventually, line of business users – to monitor secure UX with greater granularly.

Gabriel Lowy is the founder of TechTonics Advisors, a research-first investor relations consultancy that helps technology companies maximize value for all stakeholders by bridging vision, strategy, product portfolio and markets with analysts and investors
Share this

The Latest

March 31, 2020

Organizations face major infrastructure and security challenges in supporting multi-cloud and edge deployments, according to new global survey conducted by Propeller Insights for Volterra ...

March 30, 2020

Developers spend roughly 17.3 hours each week debugging, refactoring and modifying bad code — valuable time that could be spent writing more code, shipping better products and innovating. The bottom line? Nearly $300B (US) in lost developer productivity every year ...

March 26, 2020

While remote work policies have been gaining steam for the better part of the past decade across the enterprise space — driven in large part by more agile and scalable, cloud-delivered business solutions — recent events have pushed adoption into overdrive ...

March 25, 2020

Time-critical, unplanned work caused by IT disruptions continues to plague enterprises around the world, leading to lost revenue, significant employee morale problems and missed opportunities to innovate, according to the State of Unplanned Work Report 2020, conducted by Dimensional Research for PagerDuty ...

March 24, 2020

In today's iterative world, development teams care a lot more about how apps are running. There's a demand for fixing actionable items. Developers want to know exactly what's broken, what to fix right now, and what can wait. They want to know, "Do we build or fix?" This trade-off between building new features versus fixing bugs is one of the key factors behind the adoption of Application Stability management tools ...

March 23, 2020

With the rise of mobile apps and iterative development releases, Application Stability has answered the widespread need to monitor applications in a new way, shifting the focus from servers and networks to the customer experience. The emergence of Application Stability has caused some consternation for diehard APM fans. However, these two solutions embody very distinct monitoring focuses, which leads me to believe there's room for both tools, as well as different teams for both ...

March 19, 2020

The 2019 State of E-Commerce Infrastructure Report, from Webscale, analyzes findings from a comprehensive survey of more than 450 ecommerce professionals regarding how their online stores performed during the 2019 holiday season. Some key insights from the report include ...

March 18, 2020

Robinhood is a unicorn startup that has been disrupting the way by which many millennials have been investing and managing their money for the past few years. For Robinhood, the burden of proof was to show that they can provide an infrastructure that is as scalable, reliable and secure as that of major banks who have been developing their trading infrastructure for the last quarter-century. That promise fell flat last week, when the market volatility brought about a set of edge cases that brought Robinhood's trading app to its knees ...

March 17, 2020

Application backend monitoring is the key to acquiring visibility across the enterprise's application stack, from the application layer and underlying infrastructure to third-party API services, web servers and databases, be they on-premises, in a public or private cloud, or in a hybrid model. By tracking and reporting performance in real time, IT teams can ensure applications perform at peak efficiency — and guarantee a seamless customer experience. How can IT operations teams improve application backend monitoring? By embracing artificial intelligence for operations — AIOps ...

March 16, 2020

In 2020, DevOps teams will face heightened expectations for higher speed and frequency of code delivery, which means their IT environments will become even more modular, ephemeral and dynamic — and significantly more complicated to monitor. As a result, AIOps will further cement its position as the most effective technology that DevOps teams can use to see and control what's going on with their applications and their underlying infrastructure, so that they can prevent outages. Here I outline five key trends to watch related to how AIOps will impact DevOps in 2020 and beyond ...