Wednesday, May 20, 2015

Ongoing BARC BI Survey 2015 Preliminary Results

Preliminary data from the 2015 BARC BI Survey indicate that use of BI is increasing and becoming more pervasive in departments besides Finance and upper management:

Following rather stagnant numbers in 2014, this year reveals an upward trend across all business departments. The biggest increase can be found in production departments (from 21 percent to 53 percent). The operationalization of BI has progressed rapidly in recent years. This is particularly evident in big data analytics scenarios where ever-increasing volumes of machine and sensor data are being used in the production process – for example for optimizing production processes or predictive maintenance of machines.

The Business Application Research Center (BARC) is an enterprise software industry analyst doing research in data management, business intelligence, customer relationship management, and enterprise content management.

Participation has its benefits. If you take the survey, you will:
  • Receive a summary of the results from the full survey
  • Be entered into a draw to win one of ten $50 Amazon vouchers
  • Ensure that your experiences are included in the final analyses

Sounds like it might be worth the 20 minutes or so it will take you complete the survey.


Monday, May 4, 2015

Web Intelligence, Lumira and the Road Ahead

Our SAPinsider-hosted Q&A on April 22, 2015 was a resounding success. It featured a cast of SAP luminaries:
  • Ty Miller - Vice President, Lumira Product Management, SAP
  • Frank Prabel - Senior Director of Product Management, SAP
  • Gregory Botticchio - BI Product Manager, SAP
  • Sylvain Riboud - SAP BusinessObjects Web Intelligence and Semantic Layer Area Delivery Manager, SAP
  • Ian Booth - Director Product Management, SAP

Here's Frank Prabel on the road ahead for Web Intelligence:

SAP has a very large installed base of Web Intelligence customers and is committed to investing in the WebI future.

The investment will be partly incremental innovations such as those planned for BI 4.1 SP06 (global input controls, freehand SQL, etc.), but we are also working on key new innovations (commentary, parallel queries, or HANA direct access). Please refer to this Web Intelligence roadmap slide for additional details:





Thursday, April 16, 2015

Will Your Web Intelligence Journey Lead You into Lumira?

When: April 22, 2015 - 11:30 am EDT

APOS is pleased to present this online Q & A session in conjunction with SAP and SAPinsider. During this session, SAP Product experts will explore the latest capabilities, future roadmap, and product synergies of SAP Web Intelligence and SAP Lumira. The SAP expert panel will include:

  • Ty Miller - Vice President, Lumira Product Management, SAP
  • Frank Prabel - Senior Director of Product Management, SAP
  • Gregory Botticchio - BI Product Manager, SAP
  • Sylvain Riboud - SAP BusinessObjects Web Intelligence and Semantic Layer Area Delivery Manager, SAP
  • Ian Booth - Director Product Management, SAP

Understanding product roadmaps and capabilities is key to successful SAP BI tool selection and usage. What criteria will differentiate the application and uses of SAP BusinessObjects Web Intelligence and SAP Lumira, now and in the future?

This online interactive Q & A session will give you the opportunity to pose your questions directly to these SAP experts, learn about recent and upcoming Web Intelligence and Lumira enhancements, and explore opportunities to harmonize the use of these tools for better user engagement.

Register for this session.

Tuesday, March 24, 2015

Healthcare GRC and Social Engineering

There is some debate over whether or not the CHS, Anthem and Premera data breaches were the result of "sophisticated" attacks. The jury is still out, but cautious journalists are using quotation marks to indicate that this explanation is not universally accepted. Regardless of the sophistication of these attacks, attacks they certainly are, and healthcare organizations should be prepared for the onslaught to continue, because healthcare data breaches are so lucrative. They have to assume they are being targeted by criminal hackers for fun and profit.

Maybe former Intel CEO Andrew S. Grove's book title got it right: only the paranoid survive. Perhaps healthcare organizations could learn from their corporate antitheses, the tobacco companies, who have many enemies, but are protected by a culture of hardened security.

There is certainly room for technological solutions to help manage risk, but we must recognize that the most frequent cause of data breaches is human behavior. (According to a Verizon data breach report, about 76% of network intrusions involve weak credentials -- bad passwords.) The biggest risk to the security of your data is your people. No amount of monitoring using sophisticating technology can protect your data from bad decisions by people on your network.

Let's not forget the subtitle of Grove's book: How to Exploit the Crisis Points that Challenge Every Company and Career. The threat to data is also an opportunity to establish a culture of data governance. In such a culture, the value of data is recognized, and human behavior is shaped by this recognition.

Human behavior is a critical factor, because social engineering is how malware and other created vulnerabilities find their way into your network. It is essential that your systems have malware protection, but it is equally important that your people know what not to click.

A strong governance, risk management and compliance (GRC) culture fights social engineering with social engineering.

If healthcare organizations can learn to fend off the cyber attackers, they will be in a better position to fend off the lawyers bearing class action law suits.

Monday, March 16, 2015

Pentagon EHR System Upgrade Contract Said to Be Worth $11 Billion

The U.S. Department of Defense has narrowed the field to three contenders for the estimated $11 billion upgrade to the DoD EHR:
  • Computer Sciences Corp., HP, and Allscripts
  • Cerner, Leidos, and Accenture Federal
  • IBM, Epic, and Impact Advisors

The winning EHR company will certainly benefit greatly, both from the DoD, and in the healthcare sphere in general, but I'm sure the other two will also benefit from the vote of confidence on their ability to deliver EHR capable of achieving Meaningful Use.

Numerous challenges have been noted by the bidders:
  • Interoperability - Allscripts senior vice presi dent, sales, Dean Mericka says interoperability will lead to personalized precision medicine and improved telemedicine.
  • DoD mission and culture - Cerner Federal VP and general manager Travis Dalton notes that the task goes far beyond bringing a set of tools. The winning vendor will have to adapt to the DoD's culture, philosophy and mission.
  • Scalability - Epic U.S. federal and global services executive Leslie Karls indicates the scalability of the solution is key.

Those are just the EHR perspectives. The IT and infrastructure challenges present a whole other level of difficulties.

Read more at FierceEMR.

Thursday, March 12, 2015

New Case Study - Redevco B.V.

Established in 1999 to manage the real estate investment activities of the venerable Dutch C&A fashion retail chain, Redevco B.V.'s portfolio includes 450 properties at top locations in major cities across Europe, with tenants including many major national and multinational retail companies.
Redevco implemented the APOS Publisher solution to handle invoice publishing after they started creating the invoices in Web Intelligence instead of Desktop Intelligence.

Check out the new APOS case study on Redevco to find out how they re-engineered their invoicing workflow with APOS Publisher.


Monday, February 23, 2015

Was the Anthem Data Breach "Sophisticated"?

Anthem CEO Joseph R. Swedish apologized to Anthem members immediately after the December 2014 data breach was made public, saying "Anthem was the target of a very sophisticated external cyber attack." Swedish continued, in what may become a model for such apologies:
Anthem’s own associates’ personal information – including my own – was accessed during this security breach. We join you in your concern and frustration, and I assure you that we are working around the clock to do everything we can to further secure your data.

It's a nice trick to have the CEO of a major healthcare payer -- a man whose total compensation package for fiscal 2013 was $16,979,927 -- come across as one of us, just another victim of cybercrime.

But was the Anthem hack really a sophisticated attack?

Dan Munro
at Forbes quotes security analyst Ken Westin:

Because it was clearly pre-meditated and because the attackers spent time identifying the vulnerabilities, it definitely qualifies as well executed, but once the initial intrusion was successful, they didn’t have too far to look. By gaining admin credentials to the database there was nothing ‒ including encryption ‒ to stop the attack. The only thing that did stop it was a lucky administrator who happened to be paying attention at the right time.

There is some speculation that the initial breach at Anthem occurred much earlier than the December 2014 public announcement, perhaps as early as April 2014, and that it was a result of the Heartbleed Bug.

Munro also discusses the earlier CHS and Sony hacks, noting that they too were described as sophisticated or "unprecedented" attacks, and that numerous security analysts had thrown cold water on those descriptions. Let's face it: no board of directors is going to say that they were victims of an attack that a five-year-old could have perpetrated. The PR front likely bears little resemblance to what is going on behind closed doors, where damage is being assessed, and governance, risk management and compliance are being reassessed.

There are always the nagging questions: What should you have known? When should you have known it? Did you exercise due diligence?


I once heard an auditor defined as the person who walks onto a battlefield after the battle is over and bayonets the wounded. I'm not sure that's an apt description of an auditor, but it's a pretty good description of the audited.