Category: News

Hybrid work, security and sustainability share centre stage at Cisco Live EMEA 2023

Last week, communications technology company Cisco announced a plethora of new tools and capabilities in the areas of hybrid work, cloud, IoT, security, networking, sustainability and more. 

The technology innovations were announced at Cisco Live EMEA, the company’s annual training and education event for IT professionals in the EMEA (Europe, Middle East, Africa) region.

“Our customers rely on us to keep them connected and secure, with uninterrupted access to the apps they need to run their businesses efficiently, and to continue to adapt and grow,” said Wendy Mars, president of Cisco’s EMEA region. “That trust is something we’ve forged over many years, and the close collaboration between our teams and our customers and partners fuels the innovation we have on display here in Amsterdam.”

Here are some of the innovations announced at the event, held in Amsterdam:

Cloud security

Cisco customers can now access new risk-based capabilities to better protect hybrid work enabled through multi-cloud environments. That includes risk-based authentication that provides users with access, secured by real-time contextual signals.  

Additionally, Cisco unveiled Business Risk Observability, an enhancement to Cisco’s Full-Stack Observability application security solution, available through Cisco Secure Application. It allows teams to generate an application-based business risk score to help mitigate vulnerabilities on applications or services.

These capabilities seek to demonstrate Cisco’s vision to protect the integrity of an organization’s entire IT ecosystem.

Networking

Cisco announced IoT Operations Dashboard to help customers increase industrial asset visibility, securely manage assets from anywhere and converge IT and OT operations.

Cisco ThousandEyes introduced support for OpenTelemetry to provide expanded visibility, correlated insights, and optimized digital experiences.

Cisco+ Secure Connect, the company’s unified SASE ( secure access service edge) solution, now supports integration into Cisco SD-WAN fabrics (software-based, virtual IP fabric) to provide any Cisco SD-WAN customer with access to fast, secure, private application and internet access.

These announcements mainly serve organizations that need to connect core enterprise operations to industrial spaces, spanning utility grids, manufacturing facilities, and transportation networks.

Sustainability

Cisco announced the addition of Carbon Emissions Insights to its Webex Control Hub; this delivers actionable insights on energy consumption and usage of Cisco Webex devices, helping companies track their sustainability goals.

Cisco also enumerated its sustainability programs:

Takeback and Reuse Program – 99.9 per cent of Cisco’s end user hardware that is returned is reused and recycled
Cisco Room Bar, designed with 100 per cent recyclable packaging material
Cisco IP Phone 8800 series will have models made with 100 per cent Post-Consumer Recycled (PCR) resin
Cisco Green pay – circular payment solution that offers 5 per cent incentive on Cisco hardware, predictable payments for five years, and free product returns.
 Cisco Refresh – buy remanufactured, fully certified Cisco network routers, switches, phones, and collaboration products.

Training programs

Cisco announced its goal to train 10 million people across EMEA in digital and cybersecurity over the next 10 years through its Networking Academy program. This is part of Cisco’s 10-year plan to empower 25 million people globally with the digital skills they need to manage and safeguard the essential digital systems we rely on today.

The post Hybrid work, security and sustainability share centre stage at Cisco Live EMEA 2023 first appeared on IT World Canada.

Management, lack of money blamed for poor cybersecurity at Canadian hospitals

The biggest impediment to improving the cybersecurity of Canadian hospitals is “lack of focus” of management and lack of money, says the head of the country’s .ca registry.

Bryon Holland, chief executive officer (CEO) of the Canadian Internet Registration Authority (CIRA) told a Tuesday Globe and Mail webinar on cybersecurity in the healthcare sector that just short of 30 per cent of all organizations in this country have suffered a data breach.

“If a third of homes were broken into, or a third of business and hospitals were being [physically] criminalized, there would be an incredible uproar,” he argued.

But in the digital world, people don’t see the impact, so there is little support for more resources. CIOs and IT pros in healthcare tell CIRA the number one reason hospitals find it hard to fight cyber attacks is “lack of focus and money” to put in systems and technologies to keep up with the volume of attacks, Holland said.

Hospital management needs “a mindset upgrade,” he maintained. Cybersecurity “is an executive problem. This is a CEO, senior executive board problem, because there is liability and fiduciary risk at the top of the organization.”

They need to understand the solution is taking holistic security seriously — everything from installing multilayered defence in depth, DNS hardened firewalls, multifactor authentication and access control. These, he said are “table stakes.”

But he also said that cybersecurity “is not just the IT folks’ problem.”

In fact he claimed that “most compromises happening now are because people are compromised, not a firewall or a piece of tech.” That’s why cybersecurity awareness training is also important, he said.

Panel members included Jeff Curtis, chief privacy officer at Toronto’s Sunnybrook Health Sciences Centre; Steven Tam, chief data governance and privacy officer at Vancouver Coastal Health, which oversees all hospitals in the Vancouver area; and Hudda Idrees, CEO of Dot Health, a provider of mobile healthcare solutions for individuals and healthcare providers.

Hospitals and clinics have long been targets of hackers who believe the institutions are more willing than others to pay for the return of stolen data. For-profit hospitals and clinics are seen as a source of credit and debit card information in addition to sensitive medical data on patients. Non-profit hospitals often don’t have the money to make cybersecurity a priority.

Hospitals in Canada recently hit include Toronto’s Hospital for Sick Children and Lindsay, Ont.’s Ross Memorial Hospital. In the U.S., where for-profit hospital chains serve millions of people, California-based Regal Medical Group is now sending data breach notices to more than three million patients after suffering a ransomware attack late last year.

One of the worst attacks in Canada took place in Newfoundland and Labrador in 2021, when attackers copied years of patient and employee data from the provincial system.

Hospitals aren’t the only healthcare institutions hit. In 2019, hackers accessed medical lab results of 15 million Canadians when LifeLabs, the country’s biggest medical lab serving doctors, was hacked. The privacy commissioners of Ontario and British Columbia said the company failed to follow provincial data health protection laws.

Despite billions of dollars in annual healthcare spending in Canada, “funding for cybersecurity is getting short shrift,” Holland told the panel.

He got support for that from Indrees, who noted Ontario alone spends $70 billion a year on healthcare. “I don’t think it’s lack of funding. It’s just that people don’t think it [cybersecurity] is important enough.” While the province has set up a Digital Health Information Exchange, she said spending on “practical, tangible pieces of software or training … is seriously lacking.”

Hospitals spending more on IT in general will only exacerbate the problem, said Curtis. Money has to be targeted for cybersecurity.

However, he also said for better security, more institutions should be adopting shared systems. For example, there are shared diagnostic imaging services in Ontario used by many hospitals and medical practitioners.

He and others also pointed to a serious problem in Canadian hospitals: Legacy software and hardware that impedes the adoption of more secure technologies.

Tam said hospital CEOs and CIOs have to see cybersecurity as separate from IT in their budgets.

Proper governance is also important, he said. “We need to come together to collectively tackle these issues, to identify what the risks are and identify the solutions., If we’re working together, we can also improve our [cybersecurity] practices across the board. We have a diverse, broad healthcare system. We need to think how we govern our data and systems across the healthcare sector” rather than one hospital at a time.

The post Management, lack of money blamed for poor cybersecurity at Canadian hospitals first appeared on IT World Canada.

Cyber Security Today, Feb. 15, 2023 – Patches released for Microsoft Exchange, SAP, Apple and Adobe products

Patches released for Microsoft Exchange, SAP, Apple and Adobe products, and more.

Welcome to Cyber Security Today. It’s Wednesday, February 15th, 2023. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Microsoft issued a number of important security updates on Patch Tuesday. One affects all Exchange servers dating back to Exchange 2013. It closes a critical privilege escalation vulnerability, which is actively being exploited. It’s one of nine critical holes in Microsoft products that need patching. Another is in Microsoft Word, SharePoint, 365 Apps and Office for Mac. There are also three critical remote code execution vulnerabilities that can hinder Windows’ capability to establish secure connections with wireless clients.

By the way, Exchange Server 2013 reaches end of support on April 11th. You have until then to upgrade to a new on-premise version or switch to the cloud version of Exchange.

Also yesterday, SAP released 26 new and updated security patches. According to researchers at Onapsis, the most critical is a vulnerability in SAP Host Agent, which allows an authenticated ordinary user with local access to a server port to cause mischief.

Adobe released critical security patches for Illustrator and AfterEffects, as well as an important fix to plug a hole in Photoshop.

And Apple released security updates for iPhones, iPads and MacBooks.

On Monday’s podcast I told you about the compromise of Fortra’s GoAnywhere MFT managed file transfer service. Now there’s word of one victim: Community Health Systems, which runs a number of hospitals in many U.S. states. In a regulatory filing spotted by the news site Databreaches.net the company said personal information on nearly 1 million American patients was copied in hack. Bleeping Computer says the Clop ransomware gang claims it stole data from 130 organizations in the compromise.

Attention website administrators: Hackers continue to take advantage of poorly-secured websites that use the WordPress content manager. The latest evidence comes from researchers at Sucuri, who say over 2,600 new websites have been infected so far this year in a campaign that started last year. The goal is to covertly install code that redirects your website’s viewers to sites that talk about cryptocurrency and blockchains. Apparently this is an advertising fraud scam. The more an ad is seen the more revenue the crooks get. The researchers haven’t found a particular WordPress exploit the hackers are using for this. So their advice to administrators is be vigilant, patch all software, watch your WordPress code for compromises and secure WordPress administration consoles with multifactor authentication.

Attention application developers. Hackers continue finding ways to plant infected packages on the open-source Python Package Index (PyPI). Researchers at Phylum say an attacker last week uploaded over 451 downloadable malware packages. They attempt to hide by mimicking the names of popular packages. The crook hopes unwitting victims will mistake the fake packages for ones they are looking for. The malware finds and replaces cryptocurrency wallet addresses copied to a computer’s clipboard with the attacker’s wallet address. As always developers have to be careful what they download from any open source library of code. Recently Check Point Software found 16 malicious packages on the NPM repository for JavaScript code. They have been removed, but the malware enabled cryptojacking of computers. Operators of code repositories have to take more steps to detect and block bad code.

North Korea’s Lazarus hacking group is believed to have found a new way to launder millions of dollars worth of stolen cryptocurrency. Researchers at Elliptic Enterprises believe Lazarus is now using a mixer service called Sinbad. It replaces an online service called Blender, which disappeared last year after being sanctioned by the U.S. The suspicion is Sinbad is being run by the same operator as Blender. North Korean hackers are also using a mixer called Tornado Cash.

Finally, if you want a laugh as well as education on how online romance scams work, Sophos senior threat researcher Sean Gallagher has published a blog on how a crook posing as a woman tried to seduce him into investing in a phony gold-trading market. This person was not deterred by the fact that Gallagher told them what he does for a living.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Feb. 15, 2023 – Patches released for Microsoft Exchange, SAP, Apple and Adobe products first appeared on IT World Canada.

Hashtag Trending Feb.15th-U.S., U.K sanction ransomware gangs, new open-source “super cloud” and Salesforce adds gender options

Have ransomware gangs finally crossed “a bridge too far?”, a new “super cloud” says it’s not only open source, but it’s a magnitude cheaper than other cloud providers and Salesforce recognizes new gender options.



 

It’s Wednesday, February 15th. These stories and more on Hashtag Trending–today’s top technology news stories. I’m your host, Jim Love.

Could economic sanctions be the tool that finally takes down ransomware gangs? Some recent studies seem to suggest this new approach might be working..

Recently, the U.S. and the U.K collaboratively applied financial sanctions to seven individuals who are part of Russia-based cybercrime gang, TrickBot.

Trickbot has been one of the most prolific cyber crime outfits. It first appeared in 2016 and many feel it has survived due to its connections to and protection by Russian intelligence and the Russian government in return for its attacks against US and Western targets.

The group got its start during the height of the COVID-19 pandemic in 2020, first attacking non-Russian financial systems.  Later, Trickbot targeted hospitals and healthcare centers, affecting computer networks, telephones and in process disrupting already over-stretched ambulance services and hospitals across the U.S.

US and other authorities have targeted the gang and in 2020 their botnets were disrupted and two of the key gang members were arrested.  Despite that, the gang has survived and is reported to have continued supporting or working with Russian Intelligence Services to attack targets in the US and the UK, particularly major health care facilities.

Now, western governments are fighting back in a new way. They are levying sanctions on the gangs and applying fines that make it much more expensive for companies to pay the ransom, according to an article in CPO magazine. Victims often feel that they would rather rely on backup and remediation than paying to get their files back from the attackers.

In addition to acting to cutting off the flow of money, governments are taking a host of other actions, including starting to identify and even arrest group members.  Roger Grimes, an evangelist at cybersecurity firm KnowBe4 said that the sanctions, “represent a tipping point in the battle” noting that the full force of every possible government agency has been brought to bear – the Cyber Security and Infrastructure Agency CISA, the FBI, Department of Justice, the National Security agency, business councils, foreign agencies and more. Said Grimes, “even the President of the United States got involved. Ransomware finally crossed a ‘bridge too far’”

However, sanctions have limitations. While sanctions can limit the international movement of subjects, they cannot facilitate arrests if they stay in a country that encourages their activities such as Russia. Plus, hackers do not really go out of business, they usually just go underground for a bit and then emerge with a new criminal brand.

TrickBot, in particular, has proven more resilient than other ransomware gangs as they diversified their attacks, and do not always solicit payments from victims. So it is unlikely that the sanctions will cease all of their activities.

However, research from Intel 471 Threat Research Team said that “We’ve not seen any TrickBot activity since the Feb 2022 blog post. It is highly likely that TrickBot won’t be seen again. One possible scenario is that the source code may be sold or leaked, and other threat actors could re-use it or fork the source into a new project … “

Source: CPO magazine

Demand for public cloud is increasing but so is competition within the public cloud marketplace. And there may be a new competitor.

One company, Akash Network is taking a new approach to compete with  hyperscalers like Amazon, Google and Microsoft by operating an open-sourced, decentralized “super” cloud.

Their model allows any data centre or anyone with a computer, to share unused processing cycles creating a new, open source, collaborative cloud provider.

Trying to leverage unused computing cycles is an idea that’s been tried before. Decades ago, researchers tried to create a pool of unused cycles on personal computers as part of a search for intelligent life (SETI) project.

But now, the convergence of the cloud and open source technologies may have created a commercially viable option.

Akash Network CEO Greg Osuri said in an interview to Data Center Knowledge that they have created a marketplace that gives data center operators control over the pricing and amenities through reverse auctioning. This means that users, or tenants as Akash calls them, state their application needs and maximum budget. Providers bid on the order with the lowest bid winning.

“It’s 75 to 85 percent cheaper than the Amazons of the world,” said Osuri.

According to a report by Gartner, use of the marketplace is also perfect data center right sizing strategy and part of a wider trend to integrate “on-premises, co-location, cloud, and the edge.

The new offering promises to allow cloud-native and containerized applications to run faster on decentralized cloud. The open-source software is also beneficial to developers and users. It’s easier for developers to launch new applications and users can enjoy greater flexibility in how they use applications.

Source: Data Center Knowledge

Microsoft’s St. Valentine’s Day massacre

Yesterday, the giant permanently ditched Internet Explorer in certain versions of Windows 10. The company first stated that IE will be killed via a Windows Update, but later communicated that it would happen through an Edge update.

The update has been rolled out to all devices–both consumer and commercial, at the same time and with no possibility to roll back this change.

The banner with the headline “The future of Internet Explorer is in Microsoft Edge” is now visible and users will be redirected to Edge any time they try to launch an IE-based use-case. Their browsing data will be seamlessly migrated too.

Source: Neowin

Microsoft also killed enterprise social network Yammer yesterday, which it bought a decade ago for $1.2 billion.

The Redmond giant tried integrating Yammer in its office suite in 2019. But following the launch of Viva, the employee experience platform, the relevance of Yammer waned drastically. Yammer’s fate was sealed when Microsoft went all in on Viva with the launch of Viva Engage in 2022, which it branded at the time as an evolution of the Yammer Communities app.

But now the Yammer brand will be killed off and survived by Viva Engage.  This will include changing the existing Yammer mobile apps to Viva Engage in March 2023, which will be followed by a transition for the Yammer web app starting this summer.

Let’s have a moment of silence for Yammer.

Source: TechCrunch

Mozilla’s Thunderbird email client is experiencing a potential rebirth.

Mozilla Foundation decided to overhaul Thunderbird after it was practically abandoned in 2012 and moved to a community-driven development model with several developers volunteering to work on the project.

“Many volunteer contributors with varying tastes … resulted in an inconsistent user interface without a coherent user experience.” said the company’s Product design manager Alessandro Castellani.

The revamp dubbed Supernova aims to eliminate all the existing technical and interface debt accumulated over the past ten years on the platform.

Thunderbird 115 ‘Supernova is set to release in July 2023.

Source: The Register

Walmart is putting a stop to remote work, closing some offices and forcing employees to relocate or leave.

The company is closing offices in Carlsbad, California, Portland, Oregon, and Austin, Texas although it hasn’t said when these hubs will close.

With the office closures, hundreds of workers will either have to relocate to one of Walmart’s tech hubs or leave the retailer. The company said it will pay the transfer costs for those who decide to move.

The retailer is also cutting back on remote work for tech staff, the company’s spokesperson, Rob Munroe told Insider. Everyone who works on the Global Tech team under Suresh Kumar, Walmart’s global chief technology and development officer, will be expected to work from a tech office at least two days a week.

“Our decision to be together more frequently anchors to Walmart’s fundamental belief that our people make the difference, our culture matters and we build stronger partnerships when we are physically together,” Munroe said.

Source: Business Insider

Salesforce has added two new fields to its software wherever people are referenced, one to include pronouns and the other for gender identity.

With this move, the business software giant seeks to allow customers to better represent transgender and nonbinary people but also help make gender-related data more accurate.

Administrators no longer need to add custom fields to expand the potential for more standard data reporting across a wider range of gender identities, Axios wrote.

To expedite this move, Salesforce worked with its own employees from the LGBTQ+ community as well as non-profit Out and Equal, working to advance LGBTQ+ inclusion.

Salesforce has however made it clear that it is not requiring customers to collect data on gender identities, which in some cases can be unnecessary and inappropriate.

Salesforce chief ethical and humane use officer Paula Goldman said that at the end of the day, this move is about more inclusive language. “It’s about giving businesses the tools to better understand and serve their diverse customer base.”

Source: Axios

That’s the top tech news stories for today.

Links to these stories can be found in the article posted on itworldcanada.com/podcasts. You can also find more great stories and more in-depth coverage on itworldcanada.com or in the US on technewsday.com

If you’re trying to keep up on cybersecurity, you might want to follow our sister podcast, CyberSecurityToday.

Hashtag Trending goes to air five days a week with a daily newscast and we have a special weekend edition with an interview featuring an expert in some aspect of technology that is making the news.

Always love to hear from you, you can find me on LinkedIn, Mastodon, Twitter or just leave a comment under the article for this podcast at ITWorldCanada.com

I’m Jim Love, have a great Wednesday.

The post Hashtag Trending Feb.15th-U.S., U.K sanction ransomware gangs, new open-source “super cloud” and Salesforce adds gender options first appeared on IT World Canada.

Ten key attributes of leadership success Leadership in the Digital Enterprise: Gary Davenport

With technology evolving at a rapid pace, leadership in IT becomes less a matter of telling people what to do as turning data into intelligent action. According to Gary Davenport of the CIO Association of Canada, smart leaders cut through the noise.

“Leaders today have the standard business challenges plus digital layered on top of that, which makes for an exceptionally high level of complexity. Today’s effective leader has learned not to sweat every little thing. They prioritize and keep their composure.”

In a recent talk with ITWC, the former retail and telecom industries CIO and current consultant to Board of Directors on digital transformation talked about digital-era leadership, and how his values have been his guiding light through the years.

“I’m all about all values-based leadership, and [that there is] a higher purpose to why we’re all here and what we’re going about,” he said. “As leaders, our values help us be the best we can be as individuals, as team members, and in leading others. I see the latter especially as a great privilege, a responsibility and a means of accountability.”

Davenport allowed that today’s rapid pace of change may serve to magnify certain challenges leaders are facing, but that “the basics” of treating people with respect, of strategy and vision, of operating always according to one’s core values, remains.

“Some things have changed, some have stayed the same,” he said. “However, the fundamentals of what leaders need to focus on – and what I would advise aspiring leaders to focus on as they pursue leadership positions – remains roughly the same.”


Leadership Learning

Davenport, who currently serves on the Board of Directors for the Information and Communications Technology Council of Canada (ICTC), is strong when it comes to the power of mentorship, and he has not only mentored but been mentored. And he has absorbed the leadership teachings of many through the years.

“I have had the pleasure of working with some incredible leaders in my career, and I have learned from them not only what to do in certain key situations but, perhaps more importantly, what not to do,” he said. “I’ve studied the work of Jim Collins [and Jerry Porras’] Built to Last and Good to Great, and used it extensively in my career.

“I have also studied Jack Welch of GE fame. While his approach is very different from my own, he had such a great record of success that I wanted to know what he was doing and how I could possibly leverage what he’s doing in my career.”

Mentors and Mentees

Most often talked about the mentor-mentee relationship is what the latter receives from the former. But Davenport, who over the years has mentored many, said mentors receive arguably as much or more than they give.

“Mentors can learn a lot from mentees. As much as I was giving them, they were giving me. There is a great value in being able to see things from your mentees’ perspective about technology and how it is evolving. It can only make you a better leader.”

Key Attributes

Further to the idea of becoming a better leader, Davenport came up with 10 key leadership attributes – some of which have particular meaning in the digital age and others that have always been true and relevant:

Business-focused – They understand the fundamentals of business and what must be accomplished in order to achieve success
Values-based – They can be relied on; they have undeniable integrity
Digital Technologist – They understand technology, particularly what’s coming and how to best leverage it
Strategist – They can think long-term and know how to get where they want to be
Team Builder – They know how to pull together a strong team with interlocking, complementary skills
Relationship Builder – They see other C-suite members as key partners, and put energy into building strong relationships and partnerships with them
Communicator – They know how to get messages out and market them properly
Innovator – They look at things with fresh eyes, and are willing (if needs be) to blow up the status quo and start again
Action-Oriented – They work to achieve real, measurable results
Resilient – They see opportunities even in failures; when knocked down. Said Davenport: “I’ve had projects go off the rails that forced to step back and take stock before moving on. Every leader faces this scenario, but what’s important is how you come out of it, what next steps you take. A great leader is someone who, in the face of failure, learns lessons so the same mistake is not repeated.”

Davenport allowed that no leader is perfect. “Nobody’s going to be a perfect 10 out of 10 on all these attributes. But the closer you are on each, the closer you will be to achieving success over the long haul.”

Reflecting in Words

Davenport has also published a “Leadership Blog” series aimed at CIOs and other digital leaders for the CIO Association of Canada. It is a well written summary of his experience and learning over his career. Davenport, with classic modesty describes in these terms:

“This was me stepping back and reflecting on what I have learned over the course of my career. I would recommend this to other leaders – that they sit down and reflect on what they have learned, how they have developed, and how they can help others develop.”

The post Ten key attributes of leadership success Leadership in the Digital Enterprise: Gary Davenport first appeared on IT World Canada.

‘AI revolution’ firmly entrenched in Check Point’s orbit, CPX360 reveals

Itai Greenberg, chief strategy officer with Check Point Software Technologies Ltd., has what some might consider the unenviable task of annually having to present a three-year product development plan to the firm’s board of directors and executive team.

As the company’s mandate is to prevent cybersecurity incidents from occurring, there is no opportunity to get it wrong. Fortunately, Greenberg, who, aside from strategy, also oversees business development and mergers and acquisitions (M&A) for Check Point, is not the type to avoid such challenges, but to embrace them.

“During the year I am presenting updates for the strategy,” said Greenberg late last week, in an interview with IT World Canada, adding that adjustments are made over time based on developments occurring in the cybersecurity market.

He needs to be on the mark, as witnessed by the company’s 2023 security report, released last week, that revealed cyber attacks hitting an all time high, the result of what the company said was “response to the Russo-Ukrainian war. Education and research remains the most targeted sector, but attacks on the healthcare sector registered a 74 per cent increase year-on-year.”

Authors of the report note that cyberattacks rose by 38 per cent in 2022 compared to the previous year, with an average of 1,168 weekly attacks per organization being recorded.

Reducing those numbers and others was a central theme behind the company’s most recent product rollout, which took place on Thursday at CPX 360 Americas, the company’s annual user and partner event, which was simulcast in Toronto, New York, and several other locations across North America.

Speaking in New York, company founder and chief executive officer, Gil Shwed, predicted the world is on the verge of what he described as a “very interesting revolution – the AI revolution. We have been investing in building AI technologies – more than half of our threat engines at Check Point contain AI – but I think 2023 might be the tipping point where (it) becomes an important part of our life and our world.”

Speaking in Toronto, Greenberg said that today using AI technology is “the only way that you can deal with a cyber attack. The proliferation of attacks, the variety of the attacks, and how fast they’re changing, it’s very hard for a deterministic approach to actually block the attack.

“You need to go with something that is powered by machine, powered by AI, to understand what are the patterns of the communication, the data, the source, the destination. Now, in order for you to come up with a good technology that actually is accurate, you need to rely on long lists of indicators.”

Those theories, those sentiments, are what are behind details about two product announcements he delivered at CPX 360: Check Point Horizon XDR/XPR and Quantum SD-WAN, both of which are generally available now.

The latter is a new software blade in the Check Point Quantum Gateway, a unified management platform that contains an assortment of threat management capabilities that the company says provides prevention against zero-day, phishing, and ransomware attacks.

“Most existing SD-WAN technologies in the market are not built with security in mind,” the company said in a release. “Connecting branch office SD-WANs directly to the internet bypasses traditional data centre-based security, exposing branch offices to cyberattacks.”

According to Check Point, Quantum SD-WANs block upwards of 99.7 per cent of new malware, which means branches no longer need to choose between rapid connectivity and security.

Meanwhile, Horizon XDR/XPR – XDR is short form for extended detection and response and XPR stands for extended prevention and response — Check Point said, “elevates cyber security with a focus on proactive prevention using intelligent correlation of data, stopping cyber attacks from spreading across all vectors and minimizing the impact of threats.

It contains the following capabilities:

The ability to take immediate prevention actions such as blocking, isolating assets, quarantining, and integrating with both Check Point and third-party security products.
Streamlined cybersecurity management, which provides organizations visibility into attack behavior, context and damage, and detailed analytics on indicators of compromise.
The ability to enable organizations to “consolidate and optimize their security operations, improving collaboration between security and IT teams to strengthen threat prevention across multiple vectors.”

Dave Gruber, principal analyst at research firm ESG, said “the extended detection and response movement was fundamentally driven by the growth of a more advanced, multi-vector threat landscape. Yet prevention solutions remained siloed, often falling short in their ability to ward off advanced threats.

“The introduction of Check Point’s extended prevention and response introduces a more integrated approach to threat prevention, following principles already proven by XDR (offerings). This advancement in collaborative prevention technology looks promising and could potentially drive change across the broader security industry.”

Paul Comessotti, sales and operations executive with Check Point, who is based out of Calgary, said that attacks are happening so quickly now that the response part of the equation can no longer be handled by human beings.

“Horizon takes that out of the people’s hands and puts it in the experts’ hands using AI. For example, if something happens in Singapore, two seconds later, personnel in the Toronto office, although they are not being attacked, will not only know about it, but know they are protected. Rather than wondering what is going to happen, the prevention measures are shared via ThreatCloud AI. The technologies and the intelligence are applied and it’s all automated for them.”

The post ‘AI revolution’ firmly entrenched in Check Point’s orbit, CPX360 reveals first appeared on IT World Canada.

Coffee Briefing Feb.14 – TELUS donated $125 million in 2022; Government of Canada invests to prevent attacks from quantum computers; Romance scams to surge on Valentine’s Day; and more

Coffee Briefings are timely deliveries of the latest ITWC headlines, interviews, and podcasts. Today’s Coffee Briefing is delivered by IT World Canada’s editorial team!

Missed last week’s Coffee Briefing? We’ve got you covered.

What’s new this week

TELUS donated C$125 million in 2022

TELUS has announced that it donated C$125 million, or 5 per cent of its pre-tax profit, to charity in 2022, the highest it has ever given in one year. Contributions went towards supporting Canadian youth and marginalized communities as well as to foreign humanitarian relief.

Since 2000, TELUS has donated C$1.5 billion in cash, in-kind contributions, and other programs, and allocated two million days for global volunteerism.

“Increasingly, citizens are choosing to do business with organizations that share their values, exemplifying the symbiotic relationship between doing good in our communities and doing well in business,” said TELUS chief executive officer, Darren Entwistle. “Now, more than ever, communities need the support of organizations to enable their critical philanthropic efforts.”

Over the past three years, TELUS said it has supported 

More than 1 million youth in 2022, through 548 charitable organizations
Contributed to humanitarian and emergency relief around the world, including in Ukraine, after hurricanes Fiona and Ian, unrest in Iran, and flooding in Pakistan
Delivered on a C$10 million commitment to support Indigenous groups across Canada.
Expanded low cost internet, mobility, health, and technology programs to support 342,000 marginalized individuals to date, including low-income seniors in BC, Alberta, and Quebec, government-assisted refugees, and Indigenous women.

Government of Canada tests security solutions to prevent attacks from quantum computers

Toronto-based quantum technologies provider Quantum Bridge Technologies (QBT) has obtained a C$1 million contract under the Innovative Solutions Canada program (ISC), a government of Canada R&D innovation funding program.

As part of this contract, the ISC will trial QBT’s Key Management Entity (KME) and Black Phone products, designed to protect networks and devices with a layer of security that is impenetrable, even with advanced quantum computers. 

QBT describes KME as an easy to use, cost-efficient solution that delivers keys to network hardware in any layer of the communications stack such as network encryptors and switches, and connects easily through standard API calls.

Black Phone employs pre-shared cryptographic keys on mobile devices to protect the device’s messaging, voice, video calls as well as file transfer all with end-to-end encryption and authentication.

The keys in both solutions are delivered through the Distributed Symmetric Key Exchange (DSKE), a widely-used RSA protocol that protects existing security frameworks in multiple sectors, including government, banking, telecommunications, aerospace and many others, from malicious attacks using a quantum computer.

“We are both encouraged that the Government of Canada is testing innovations for quantum safe communications, and pleased to obtain this contract to participate in this important testing phase in real-world environments,” said Mattia Montagna, chief executive officer (CEO) of Quantum Bridge Technologies. “Computationally unbreakable encryption which can be mathematically proven is the pinnacle of communications security. We at QBT are very proud to be on the pathway to commercializing this technology with the support of ISC.”

Canadian mom entrepreneurs can now apply for C$50,000 in grants and services

Total Mom Inc., an Ontario-based organization that provides business support to mom entrepreneurs across Canada, is accepting applications for its fifth annual Canada’s Total Mom pitch initiative

Having supported over 6,000 applicants since its start in 2020, the program gives Canadian mom entrepreneurs a chance at winning C$50,000 in funding and support.

Under the program, 100 applicants will be chosen via a voting process to go through a business accelerator program to gain media recognition and visibility. Ultimately, five finalists will be selected and invited to pitch their business ideas live at the Canadian Women Entrepreneur Industry Gala (CWEgala) on May 30, in front of leading companies, executive judges, media, and influencers.

“Total Mom Inc. exists because it’s simply unrealistic to expect women to have to choose between their career and raising a family,” said Anna Sinclair, chief executive officer of Total Mom Inc. “We are dedicated to building an organization that supports working women, and we plan to grow our programs and events, and Total Mom Pitch is an exciting program that fuels our dedication to women.”

Applications for the program close on Mar. 20. 

Total Mom receives support from organizations including The Scotiabank Women Initiative, Visa, American Express, UPS, VistaPrint, GoDaddy, Export Development Canada (EDC), and the Business Development Bank of Canada (BDC).

Total Mom has also announced a two-year partnership with Bell this year, to elevate and share the voices and stories of entrepreneurial mothers across the country.

Shopify highlights 100+ platform updates in Winter 2023 Edition

Shopify highlighted its platform’s most important updates from the last six months in its semi-annual Winter ‘23 Edition showcase.

Some of the new and enhanced products included:

Updates to Shop app

Shop Minis to enable developers to build features for mobile, designed to create innovative in-app shopping experiences
-New customization functions to give merchants greater control over the look of their Shop Store (a merchant’s storefront on the Shop app)
Shop Cash campaigns is a pay-per-sale customer acquisition channel that Shopify Plus merchants can use to target high-impact audiences with special deals and offers.
-Sign in Shop to help merchants identify valuable customers early in their purchase journey.

2. Checkout on Shop is now one page, and offers code-free customizations. Shopify also added more levels of extensibility on the checkout page to help merchants optimize for conversion.

3.  Supercharging Shop Promise with SFN– Any merchant outsourcing their logistics with Shopify’s fulfillment service SFN (Shopify Fulfillment Network) will have Shop Promise automatically enabled on their storefronts. Shop Promise is a badge that means a merchant has been verified by Shopify to offer reliable delivery.

Beware of romance scams this Valentine’s Day

According to a study by the Canadian Anti-Fraud Centre (CAFC), a record C$64.6 million was lost to romance scams in Canada in 2021, more than double the C$28 million in 2020.

Scammers have inundated dating apps and social media sites, especially around Valentine’s Day, to prey on single people searching for love and a connection, and susceptible to being victimized. 

The CAFC’s study showed that seniors (those aged 60 years and older) are more likely to be targeted with fraud in general. Additionally, Ontario had the highest number of victims, with a total of 9,713.

Socialcatfish.com, a platform that verifies online identities with reverse image search, has outlined the top three signs that a would-be date is actually scammer and how to avoid it:

They seem too good to be true – scammers steal the photos of attractive and rich-looking people to lure susceptible singles. Approach such advances with a healthy level of skepticism and reverse search their images to see if the photos are being used elsewhere under different names.
They fall in love despite having never met you, which is highly unlikely regardless of how strong one’s flirt game is. Ask to video chat or meet in person. Scammers always come up with reasons why they cannot do either. Stop communicating if they will not video chat or meet up.
They ask for money, crypto or gift cards. The biggest red flag is when a person you have never met starts asking for money, often for reasons including issues with bank account, medical emergencies, or because they need money to come visit. Scammers like to be paid with gift cards or bitcoin as this is harder for authorities to trace. Never give money to anyone you meet online.

More to explore

U.S., South Korea issue alert on North Korean-based ransomware groups

North Korean state-sponsored ransomware groups are targeting hospitals and other critical infrastructure organizations, U.S. and South Korean law enforcement and intelligence agencies are warning.

Indigo suffers ‘cyber incident,’ knocking it offline

Canada’s biggest book chain has suffered what it calls a cyber incident that knocked it offline on Wednesday.

Give tax break so small Canadian firms can invest in cybersecurity, Parliament told

Ottawa should deploy a wide range of strategies, including tax breaks, to encourage small businesses to take cybersecurity more seriously, a member of a think tank told a parliamentary committee this week.

Government of Canada announces final policy direction to the CRTC to improve competition in the telecom sector

Innovation, Science and Economic Development Canada (ISED) has finalized the policy direction to the Canadian Radio-television and Telecommunications Commission (CRTC), proposed last summer to enhance competition in the telecom sector.

Hiring to increase in Canada, despite market volatility: Robert Half study

The job market has been facing the changing demands of a new workforce and a new economic environment, but it remains robust. More than half of Canadian companies are planning to hire early this year, a new study by recruitment agency Robert Half found.

Toronto university to help train Ukrainians in cybersecurity

A Canadian university is partnering with Ukraine for a pilot program to train up to 100 Ukrainians to become cybersecurity professionals.

Google unveils new AI search capabilities as rivalry with Microsoft intensifies and Bard spews its first nonsense

Today, Google unveiled several new search capabilities and a demo of its AI chatbot, known as Bard, a day after Microsoft announced plans to inject AI into its Bing search engine and Edge web browser.

Microsoft Edge switching to Adobe PDF rendering engine

Microsoft has long used its own rendering engine for displaying PDFs in its Edge browser, but that will change next month.

Channel Bytes Feb. 10, 2023 – CDN Top 100 submissions & Channel Innovation Awards nominations open; iWeb becomes Leaseweb Canada; Oracle Java licensing changes explained; and more

Staying informed is a constant challenge. There’s so much to do, and so little time. But we have you covered. Grab a coffee and take five while you nibble on these tidbits.

Listen to the latest episode of Hashtag Trending

Hashtag Trending Feb.14- Layoffs hamper innovation, AI cloning technology shows President Biden read transphobic text and data brokers selling mental health records

Listen to the latest episode of Cybersecurity Today

Cyber Security Today, Feb. 13, 2023 – Hole in GoAnywhere file transfer utility exploited, ransomware attacks in the U.S. and Israel, and more

Listen to the latest episode of Hashtag Tendances

If you live in Québec, or prefer to consume the latest technology news in French, our sister publication Direction Informatique has you covered. Follow them on Twitter as well.

The post Coffee Briefing Feb.14 – TELUS donated $125 million in 2022; Government of Canada invests to prevent attacks from quantum computers; Romance scams to surge on Valentine’s Day; and more first appeared on IT World Canada.

Few companies have visibility into their ICS/OT networks: Report

The U.S. came dangerously close to suffering a major cyber attack on its energy infrastructure last year, says the head of a cybersecurity company that focuses on risks to operational technology (OT) systems such as industrial control systems (ICS).

The discovery of malware dubbed Pipedream by Dragos Inc. and U.S. cyber agencies was “the closest we’ve ever been to having U.S. infrastructure go off-line,” said company CEO Robert Lee.

“I don’t think people realized how close it was to happening.”

He made the comment to reporters in a briefing before Dragos released its annual year-in-review report on Tuesday.

The report highlighted problems in network visibility in ICS/OT networks, an increase in ransomware attacks on industrial firms, and problems with identifying the seriousness of  vulnerabilities in ICS/OT devices.

Pipedream was created by a new nation-state group dubbed Chernovite. Its existence was publicized last April, but Lee said its significance was missed by news media, who focused on the malware’s ability to target programmable logic controllers [PLC’s] from Schneider Electric and Omron, and that it appeared to initially target electricity and liquid natural gas plants in the U.S..

“That was just their initial set of targets,” Lee said. “This thing can work anywhere. This is a state-level, war-time capability” to bring down infrastructure.

“One of the things that makes Pipedream truly unique is that this is the first time ever that we’ve had a set of malware that can be disruptive or destructive in industrial control environments across [any] industry.” Until now, he said, ICS/OT malware was created for particular environments — what worked against a power distributor wouldn’t work in a factory, for example.

“You could put it in a data centre, you could put it in a wind farm, you could put it in an oil and gas refinery, you could have it targeting drones … ”

While Pipedream had been installed in an unnamed system, Lee said, for some reason “they [Chernovite] weren’t ready to pull the trigger. They were getting very close.”

Related content: Canada should follow US scrutiny of electric utilities

The revelation of Pipedream gave industrial/critical infrastructure firms time to comb their systems for evidence of the malware. “There’s no fixing this,” Lee said. “No vulnerabilities that, if you patch them, you’ll be fine.”

Chernovite is still working on Pipedream, he warned, predicting the malware will eventually be deployed on some victim’s network.

Industrial firms “better have a detection and response program,” he added. “You have a zero per cent chance of being successful against this adversary and this capability if you’re just relying on prevention. You must be doing detection and response.”

The discovery of Pipedream and what the company called its “breakthrough escalation in capabilities” was one of the important events in the ICS/OT community last year, the Dragos report says.

The report also highlighted a theme throughout the report: While the industrial sector is getting better at being prepared for a cyber attack, it has a long way to go.

One of the biggest problems: Few companies have visibility into their ICS/OT networks.

Eighty per cent of Dragos’ customers have only limited network visibility, Lee said, which is “why we’re still finding some scary things.” And, he added, his company’s clients are usually firms that have a mature cybersecurity strategy.

“If you have limited or no visibility, you can’t detect anything in your OT environment,” he said.

Other problems are poor security perimeters, remote and exposed connections to the OT environment, and shared IT and OT credentials in Active Directory. “We see a ton of that” in ransomware attacks Dragos investigates, Lee said, where a hacker targets the IT network, populates ransomware out through an Active Directory domain controller, which then spreads through the OT network.

Among the report’s highlights:

— ransomware attacks on industrial infrastructure organizations nearly doubled in 2022 compared to the previous year. Of those, over 70 per cent of ransomware attacks focus on manufacturers;

— ICS/OT vulnerabilities increased 27 per cent compared to 2021. However, Lee complained that few vulnerabilities reported by vendors offer mitigation as well as a patch. Sometimes a mitigation — like disconnecting a device from the internet — is faster than installing a patch, he said.

The report also complains that 33 per cent ICS-related vulnerability advisories last year had errors that could mislead IT practitioners who use CVSS scores to triage mitigations or patching.

For that reason, Lee also maintained that only half of ICS/OT vulnerabilities are serious — ones that would result in loss of control of a system or loss of network visibility. And of those, only two per cent — ones whose devices are perimeter-facing and easily exploitable, whose vulnerabilities are actively being exploited, or add net new functionality in the industrial environment (ie you couldn’t modify the logic on a safety system) — need to be patched immediately. IT/OT should focus on these, leaving them free to do other things than vulnerability management, Lee argued.

Of the rest of the vulnerabilities, 68 per cent can be mitigated by updating firewall rules and waiting until the next scheduled maintenance period to install patches. The remaining 30 per cent may never need to be patched, depending on a risk assessment.

Dragos tracks 20 threat groups that go after industrial control systems. Of those, only eight were active during 2022. The company ranks these groups in terms of their activity: Stage One groups can infiltrate IT networks and are trying to get into OT networks, while Stage Two groups can get into OT networks and are stealing information that could be useful in disruptive or destructive attacks.

Chernovite was one of two groups Dragos discovered last year. It calls the other Bentonite. It targets the oil and natural gas sector, taking advantage of opportunities, such as poorly protected internet-facing remote connectivity, to slip into networks.

So far Bentonite hasn’t gotten into OT networks. But, Dragos warns, when it gets into IT networks it establishes long-term persistence. Its malware has data-wiping capability. “They’re smart, they’re stealing the right info,” said Lee.

The post Few companies have visibility into their ICS/OT networks: Report first appeared on IT World Canada.

Hashtag Trending Feb.14- Layoffs hamper innovation, AI cloning technology shows President Biden read transphobic text and data brokers selling mental health records

Layoffs killing innovation, AI-cloning technology that shows President Biden reading transphobic text and data brokers selling your mental health data – cheap.



 

It’s Tuesday, February 14th. These stories and more on Hashtag Trending–today’s top technology news stories. I’m your host, Jim Love.

Layoffs have shattered dreams and sidelined the intriguing and potentially valuable projects.

As they struggle to reign in costs and shore up share values, Big Tech has been reconsidering their approach towards funding moonshot projects with uncertain returns.

Will there be Microsoft’s a third iteration of Microsoft’s HoloLens headset after the company cut 10,000 workers? And what about Amazon’s robotics and drone delivery, or Meta’s vision for the metaverse after their drastic reductions in headcount?

It’s no surprise that risk takers and innovators will bear the brunt of economic challenges. But in fact, slashing the workforce and doubling down on profitable departments does make investors very happy.

There is still a great deal of innovation funding aimed at Artificial Intelligence. In fact, investors have been flocking to AI stocks. But we can easily forget that at one point, AI was a moonshot that required years of investment that might or might not pay off. 

That being said, it’s important to note that the biggest tech companies launched by people who were part of previous downsizing, such as the famous tech bubble that burst in the early 2000’s.

Could the silver lining be that layoffs translate into a new group of innovators and entrepreneurs? 

These are key questions, especially since spate of layoffs is far from over. 

Cloud communications company Twilio Inc (TWLO.N) said on Monday that it was eliminating about 17 per cent of its staff and closing some offices as part of a restructuring effort to focus on profitability.

Streaming service Disney has yet to announce the details of its 7,000 job cuts. But the company’s chief technology officer, Jeremy Doig packed his bags before the cuts could be made official.  Hopefully, when others pack their bags they don’t take future innovation with them. 

Source: Axios & Bloomberg News & Reuters

Voice cloning tools could be an alarming misuse of AI technology.

We watched in amazement as President Joe Biden’s Jan.25 news report on tanks has been doctored to make it appear he gave a speech that attacks transgender people. The doctored video garnered thousands of views on social media.

Digital forensics experts say that the video was created using a new generation of AI tools which allow anyone to quickly generate audio, simulating a person’s voice, with a small sample and a few mouse clicks. 

The video failed to fool most users, but raised the alarm on how easy it is to create deep fake videos filled with misinformation and hateful content.

Hafiz Malik, a professor of electrical and computer engineering at the University of Michigan who focuses on multimedia forensics said that “Tools like this are going to basically add more fuel to the fire. He added “The monster is already on the loose.”

Accordingly, following the Biden’s video, other such videos surfaced including Hillary Clinton reading the same transphobic text, Bill Clinton saying the Covid-19 vaccine causes AIDS and actress Emma Watson reading Hitler’s manifesto “Mein Kampf”

At least one company, ElevenLabs’ whose voice synthesis platform allows users to reproduce such kind of content said that it is exploring safeguards to clamp down on the misuse, following the surge of deep fake videos

However, the startup maintained that the technology was developed to dub audio in different languages for movies, audiobooks and gaming to preserve the speaker’s voice and emotions, not to be used to fuel hate speech and disinformation. 

Source: AP News

The fourth quarter of 2022 saw the biggest fall in PC processor shipments in three decades, according to Mercury Research. The company says that CPU sales are suffering their biggest year-on-year slump since they started recording that data in 1994. The company notes that this is part of a trend, where every quarter the decline breaks the previous record.

Excluding ARM processers, which seem to be defying the trend, around 374 million CPUs were shipped in 2022 which is 21 percent less than in 2021. 2022 CPU revenues saw a 19 per cent drop to $65 billion.

One reason for the slump is inventory adjustments which might mean that although shipments dramatically plummeted, it might not indicate a drastic decline in sales to end users.

As noted, the decline is not across the board. While x86 processors have slumped ARM processors are gaining market share in the laptop market, and have not suffered the same decline x86 units suffered last year.

Analysts at Mercury predict that the decline in CPU shipments could continue through the first half of 2023 will persist before turning around in the second half of the year. 

Source: TechSpot

New data from Counterpoint Research, reported that it takes $464 US to manufacture the iPhone 14 Pro Max with 128 GB according to a story in industry blog 9to5Mac.

The article notes that while Apple doesn’t disclose its profit margins or production costs on a per device basis, it does report its overall profit margin – which Apple claims is about 37 per cent which the authors note is historically very stable for apple. 

So how is it that the iPhone 14 Pro Max costs the same as the previous iPhone 13 Pro Max?

The cost to make iPhone 14 Pro Max is roughly 3.4 per cent more expensive than the iPhone 13 Pro Max. The main reason for this difference is the new 48MP rear camera as well as the new “always-on” display.

The new A16 Bionic chip costs Apple around $11 more per unit than the older A15 Bionic chip. But external costs are apparently not the only factor. Some other components, such as those in the 5G cellular technology have fallen in cost as 5G cellular becomes more popular.

Apple’s self-designed components account for 22 per cent of the overall bill of materials cost of the iPhone 14 Pro Max and Apple works very closely with its suppliers to finalize costs well in advance of production. So even with these cost increases, and inflationary pressures on production, assembly, packaging and distribution – Apple has kept the line on prices avoiding a repeat of prior relatively high increases in costs between the iPhone 11 and iPhone 12. 

Now if only someone could do that to the price of eggs.

Source: 9TO5Mac

You can buy mental health records of 10,000 people for as little as $0.20. And you get a discount if you buy in bulk. 

Lots of companies will line up to sell these to you. They will even include the names, emails, home addresses, income and ethnicity of people with depression, anxiety, bipolar disorder, PTSD, or OCD.

At least that’s what a study published by Duke University’s Sanford School of Public Policy has reported. The researchers found at least a dozen data brokers were offering to sell mental health data at cheap prices, often with no resistance from the person trying to buy the data and little to no restrictions on how the information is used.

The data brokers scavenge the information coming from from personal devices and health tracking. But they also scavenge web traffic data, some of which is sold to advertisers. Even a search on WebMD compromises your medical data.

Incredibly, this of not covered by The Health Insurance Portability and Accountability Act (HIPAA).

HIPAA’s health data rules are limited to “covered entities” including doctors and health care providers, insurance companies, and businesses who work with them directly.

Regulators are only just starting to investigate, but it isn’t certain whether US law gives them the authority to interfere.

Thank heaven that Congress always moves quickly to deal with technology challenges.

Source: Gizmodo

That’s the top tech news stories for today.

Links to these stories can be found in the article posted on itworldcanada.com/podcasts. You can also find more great stories and more in-depth coverage on itworldcanada.com or in the US on technewsday.com

If you’re trying to keep up on cybersecurity, you might want to follow our sister podcast, CyberSecurityToday.

Hashtag Trending goes to air five days a week with a daily newscast and we have a special weekend edition with an interview featuring an expert in some aspect of technology that is making the news.

Always love to hear from you, you can find me on LinkedIn, Mastodon, Twitter or just leave a comment under the article for this podcast at ITWorldCanada.com

I’m Jim Love – and with this last name, I’m the perfect person to say – happy Valentines Day.  Talk to you tomorrow.

The post Hashtag Trending Feb.14- Layoffs hamper innovation, AI cloning technology shows President Biden read transphobic text and data brokers selling mental health records first appeared on IT World Canada.

Government of Canada announces final policy direction to the CRTC to improve competition in the telecom sector

Innovation, Science and Economic Development Canada (ISED) has finalized the policy direction to the Canadian Radio-television and Telecommunications Commission (CRTC), proposed last summer to enhance competition in the telecom sector.

Today’s announcement legally binds the CRTC, under the Telecommunications Act, to translate the final policy direction into detailed regulations. 

The new policy direction also rescinds the 2006 policy direction which included language that the CRTC should rely on market forces when implementing the Telecommunications Act. Instead it builds on the 2019 direction on competition, affordability, consumer rights, and innovation.

“Access to affordable and reliable Internet and wireless services is critical in today’s society and economy. This is why our government is using every tool at our disposal to ensure that telecom services are competitive, reliable and, above all, affordable,” said Industry Minister the Honourable François-Philippe Champagne.

“In general, smaller telecom service providers supported the proposed direction, but wanted the government to make it more prescriptive. Some improvements were made to make it more clear,” said Andre Arbour, director general of telecommunications and internet policy at ISED. “Several of the large telecom service providers opposed much of the direction. The government disagrees with those views, and it’s moving forward with measures to advance competition and consumer interests.”

The new policy direction to the CRTC aims to:

Enhance wholesale Internet access and competition for more affordable Internet by;

– requiring large companies to give access to competitors at regulated rates so they can offer lower prices and more choices to Canadians. The CRTC should take action to improve availability of more timely and improved wholesale rates

– The existing model of service, called the aggregated model of service, that the smaller companies relied on had been slated to be phased out by the CRTC. The direction states that this model must remain in place. 

– Require large companies to make the speeds that Canadians are demanding available to competitors.

– CRTC should ensure that wholesale Internet access is available evenly across the market, including on fibre-to-the-home networks.

2. Increase mobile wireless competition for more affordable cell phone plans by

– directing the CRTC to improve its hybrid mobile virtual network operator (MVNO) model (in which a wireless communications services provider does not own the wireless network infrastructure over which it provides services to its customers). The government will also move to a full MVNO model if necessary to support competition in the telecom sector.

3. Improve consumer rights by;

– require new measures to address unacceptable sales practices and improve transparency in terms of service and pricing, and make it easier and more affordable for consumers to change or cancel services

– require service providers to implement mandatory broadband testing to ensure Canadians know they are getting the service that they are paying for. The CRTC currently only has a voluntary broadband testing program with SamKnows, which involves the installation of specialized equipment in a representative sample of homes to monitor and test the speed and the performance of the connection in a particular location. The purpose of today’s provision is to beef up that process so that it will be mandatory, and that key providers especially in rural areas participate, Arbour said. “But ultimately, it will be up to them [CRTC] to lay out the specific rules for who it applies to and how the testing is undertaken.”

– improve accessibility of telecommunication services to Canadians with disabilities

– improve consumer protection in the event of a service outage

– strengthen the Commission for Complaints for Telecom-television Services (CCTS), including by giving consumers and non-industry representatives a more prominent voice

– raise public awareness on CCTS and its capabilities to resolve disputes for consumers

4. Speed up service deployment and universal access

– Improve access to telephone poles and similar infrastructure so service providers can deploy new services more rapidly

– Adjust its Broadband Fund to meet connectivity needs across Canada. Champagne said that the government continues to roll out its C$3.225 billion in Universal Broadband Fund to support connectivity in underserved rural and remote communities.

5. Build better regulations

– directing the CRTC to use resources available to make sound decisions while being more proactive in strategic planning and market monitoring

– CRTC’s regulations should be efficient and proportionate to their purpose, balancing economic needs with competition and investment considerations

– improve decision timeliness

“Under the Telecommunications Act, the CRTC is responsible for implementing the policy direction and is required to take certain steps and approach all of its future decisions in a way that is aligned with it,” said Champagne. “I trust that the CRTC will act on this important work, and I look forward to seeing the direction being put into action soon.” 

The post Government of Canada announces final policy direction to the CRTC to improve competition in the telecom sector first appeared on IT World Canada.