Tuesday, February 10, 2015

Anthem Data Breach and Due Diligence

Anthem is the second-largest health insurance company in the US, and when they reported being hacked recently, it was estimated that the healthcare information (and identities) of 1 in 4 Americans was compromised -- that's more than 80 million. To put that in perspective, in the decade previous to this breach, the HHS "wall of shame" identifies approximately 40 million identities compromised in breaches. The Anthem breach compromises twice as many identities as all other breaches combined.

The breach was detected on Jan. 27 and announced on Feb. 4. By Feb. 6, there had already been four lawsuits launched against anthem, alleging they "did not take adequate and reasonable measures to ensure its data systems were protected."

I mentioned in an earlier post that healthcare data breaches are quite lucrative for the criminal elements perpetrating or benefitting from them. I should also mention that data breaches in general are quite expensive to the organizations breached as well.

One estimate has Anthem on the hook for $100 million to $200 million just to fix vulnerabilities and/or damage done. However, costs may be much higher depending on whether Anthem can demonstrate due diligence. Most security experts regard data breaches as inevitable, but the investigation of data breaches by regulatory authorities will judge whether Anthem did their best to prevent the breach, and to minimize its impact. If they didn't, HIPAA enforcement come into play. A finding against Anthem by the HHS Office for Civil Rights (OCR) could also open the door to more lawsuits.

In May, 2013, a study sponsored by Symantec and carried out by Ponemon Institute LLC estimated the cost of data breaches in the US to be approximately $188 per identity compromised. I'll let you do the math on that with regard to the Anthem data breach. Let's hope they can find economies of scale.

Of course, performing due diligence and demonstrating due diligence to an auditor are two different things. Whatever your regulatory requirements are, will you be ready for the auditor?

Wednesday, October 15, 2014

Migration Webinar Today - Web Intelligence Update

When: Wednesday, October 15, 2014, 10 am / 4 pm EDT
Guest Presenter: Gregory Botticchio, Solution Manager, SAP
Our migration webinar series continues as SAP's Gregory Botticchio joins us to to provide an update on the latest news for Web Intelligence in SAP BusinessObjects BI 4.1. Gregory will discuss new and incremental features, and provide glimpse into coming capabilities. Join us to learn about:
  • Performance improvements
  • New customization capabilities
  • Enhanced core capabilities

Wednesday, October 1, 2014

Webinar Today - Agile BI Platform Management at HP Enterprise Services

When: Oct. 1, 2014, 2 pm EDT - Today
Guest Presenter: Niladri Chowdhury, HP Enterprise Services
Register for the webinar. All registrants will receive a link to this and other recorded webinars.

Agility is now the defining quality for BI platform management, because the agile enterprise has become the norm, and an enterprise can only be as agile as its least agile component -- like the weakest link in a chain.

Niladri Chowdhury joins us today to discuss agile BI platform management at HP Services, an enterprise that specializes in helping other enterprises achieve agility. The "Always on" enterprise integrates mobility, connectivity and interactivity. "Always on" means 24/7, and if your business team is making decisions around the clock, your BI platform has to deliver on the same basis.

BI is central to enterprise decision making, but increasing volume and complexity make it increasingly difficult for BI platform managers and administrators to deliver on BI's promises. Everyone has heard the story of the frog in a pot of water that is slowly brought to a boil. The frog doesn't notice the increasing heat and is boiled alive. Being a BI platform manager can feel like that.

What's to be done? You can stand still and lower service levels; you can add resources; or you can look at strategies for achieving agile BI platform management. Join us today to see how HP Enterprise Services is employing the third option with the help of APOS well managed BI solutions.

Monday, September 22, 2014

APOS Announces Dashboard Auditor Product

APOS Systems Inc. today at the 2014 SAP Analytics & BusinessObjects Conference (SABOUC) announced the release of its new APOS Dashboard Auditor for SAP BusinessObjects.

Using the Dashboard Auditor, you can:
  • Audit Xcelsius and Design Studio dashboards, as well as Xcelsius components streamed into Design Studio using APOS Dashboard Migrator.
  • Implement usage auditing - know who is using your dashboards, and where and when.
  • Implement functional auditing - know how your dashboards are being used.
  • Verify that your investment in dashboards is paying off - that the dashboards are being used by your target audiences, and as you intended.
  • Analyze your current Dashboards environment in preparation for migration to Design Studio.

Dashboards are an increasingly important means of delivering business intelligence. Companies are investing substantial sums in dashboard development and want to know how effective they are in delivering that information, and how dashboards can be improved to meet user requirements and expectations.
Visit the APOS team at SABOUC, Booth #105, to learn firsthand how the APOS Dashboard Auditor can help you optimize the dashboard experience of your information consumers.

Read the press release.

Friday, September 19, 2014

See You at SABOC 2014, Booth #105

Will you be there in Dallas / Fort Worth? The APOS team will be at booth #105, ready and willing to talk to you about how we can help you become more agile in your SAP BusinessObjects BI platform management and administration.

We will also be hosting an education session on Agile BI Platform Management at HP Enterprise Services, featuring HP's Niladri Chowdhury. Niladri will be sharing his migration and platform management experiences.

The HP "Always On" initiative positions HP Enterprise Services as an agile enterprise enabling agility in other enterprises. Naturally, they need their SAP BusinessObjects BI 4 platform management to be agile as well. With customers such as the US Navy, the UK Ministry of Defense and NASA, HP ES must also be the agile enterprise which it sells. Using HP products such as HP Vertica and HP Autonomy with SAP BusinessObjects, their IT department is a model for the integration of complex information systems to produce real-time BI and effective data visualization.

If you are experiencing challenges with volume and complexity in your BI deployment, Niladri's experiences will be familiar to you. Find out how he brings agility to the HP Enterprise Services SAP BusinessObjects deployment.

Wednesday, September 17, 2014

Webinar Alert: Healthcare & BI Platform Management

When: Thursday, Sept. 18, 2014 - 10 am, 4 pm EDT

BI in the Healthcare sector is growing rapidly in response to US healthcare reform, and healthcare organizations are looking for proactive ways to manage and administer the BI platform in the face of increasing volume, complexity and compliance considerations.

Join us for a discussion of the major challenges facing SAP BusinessObjects BI platform managers and administrators in the healthcare industry. This webinar will examine ways to increase your BI platform management agility to help you:
  • Master complexity in data sources and information consumer requirements
  • Manage compliance through greater system visibility and high-volume administration
  • Maintain credibility through reliable, secure, accurate and timely delivery of information

Please join us as we explore techniques and best practices for SAP BusinessObjects platform management in healthcare.

Monday, August 11, 2014

Security Blogging - A Stitch in Time…

For information on using APOS solutions to help you bolster and manage security, visit our more recent series of security posts.

By Rick Epstein

Have you ever heard someone rationalize an important decision with a folksy saying? It may make one seem wise at the time, but you should be aware that, for every such "wise" saying, there is generally an equally wise and opposite saying. For example, "look before you leap," but "he who hesitates is lost."

If your rationale for not reconsidering your SAP BusinessObjects security model is "If it ain't broke, don't fix it," then my reply to you is that "A stitch in time saves nine." You won't know whether it's broken until you look.

There are, of course, other sorts of objections to taking action that I hear over and over again from normally risk-averse people who don't want to address necessary changes to their SAP BusinessObjects security model.

Here are the top five:

We don't have any data that needs to be secured.
Great. Just publish it all on the Internet. No? Every company has private data that they don't want to share with competitors and/or the public. The only difference is the degree to which a breach will hurt. What is your pain threshold?

We don't have time right now.
What will it take to get your attention? Delaying the discussion of your SAP BusinessObjects security model will almost inevitably lead to an unanticipated security breach. Implementing a well designed security model is an investment. Prioritize and make the time.

We don't have money in the budget.
Budgets are expressions of priorities. If you don't have money in the budget, then you need to re-examine your priorities. The potential cost to your company -- in terms of both money and reputation -- in the event private information is viewed by an unauthorized person or persons far exceeds what it would cost you to analyze and reengineer your SAP BusinessObjects security model.

Why should we change? Our security model works fine.
If it seems as though the pain of change is too much to bear, ask yourself how you will feel about the pain of regret. It is quite likely that there are unknown security holes in your security model. Designing and implementing a security model using a true top-down methodology is the only way to ensure that there are no such holes.

We don't have resources who know enough…
…about SAP BusinessObjects security to instantiate a true top-down security model. Then I guess today is your lucky day. Please reach out to me at repstein@resolvitinc.com. I would be glad to provide some tips and tricks and answer some questions in a 1-hour free consultation.