Page 27 of 55

Leaders looking for a unified, built-in governance of data and AI: MIT report

Sixty per cent of organizations say a single approach to governance of data and AI assets is “very important”, a new report by MIT Technology Review Insights revealed. This indicates struggles with a siloed data architecture as well as increasing and thornier security and compliance needs.

The report gathered insights from a survey of 600 technology leaders as well as in-depth interviews from industry heavyweights at AT&T, Databricks, Dell Technologies, Walmart and others.

Arsalan Tavakoli, co-founder and senior vice president of field engineering, Databricks, said, “CIOs are realizing that there’s a real cost to maintaining the different monolithic stacks they previously acquired in the cloud. It’s not just the systems but the glue between them and getting them all to work together, which is painful and duplicative. There’s now a strong push to simplify.”

This unified approach is especially critical as organizations kickstart their AI journey to transform their operations, explained John Roese, global chief technology officer at Dell Technologies.

“A modernized data infrastructure is essential to scale AI across the enterprise. AI is not just a new consumer of our existing data systems. It will need a set of technologies that are optimized to feed data into its models, exchange that data with other models, and curate what the models produce. All of those are new workloads.”

The report notes that many technology leaders who were interviewed see a unified approach as a long-term aim, and that, in the meantime, they are employing federative approaches to ensure maximum commonality of language and rules across different models. However, the need for consistent, secure, and scalable governance remains a unifying strategic thread.

The report also speaks to the importance of creating industry data ecosystems to bolster AI-led growth. 

Sixty-four per cent of survey respondents say the ability to share live data across platforms is “very important,” while an additional 31 per cent say it is “somewhat important.”

Technology teams at insurers and retailers, for example, aim to ingest partner data to support real-time pricing and product offer decisions in online marketplaces, while manufacturers see data sharing as an important capability for continuous supply chain optimization.

“The growing realization of the power of data and the increasing vertical and horizontal integration of the value chain elevate data sharing to a much more strategic level,” said Tavakoli. “After all, sharing is the cornerstone of synergy creation.” CIOs, he added, are asking how they can share data without imposing restrictions on what technology they are going to use.

For example, 63 per cent of respondents across verticals believe that the ability to leverage multiple cloud providers is at least somewhat important. Seventy per cent feel the same about open source standards and technology.

Tavakoli advised, “You don’t know what technologies are going to be created. Don’t put your data in walled gardens; use open formats, open standards, and open specifications to preserve strategic flexibility.” The growing availability and popularity of open-source LLMs, for instance, presents new opportunities.

The report concluded that generative AI adoption, which is booming across enterprises of all sizes and industries, will not be a one-size-fits-all approach, but in every case, “value creation will depend on access to data and AI permeating the enterprise’s ecosystem and AI being embedded into its products and services.” 

The key to AI growth will also be to get data into the hands of every employee, affirmed Tavakoli.

“Every C-level executive we talk to in every industry understands that data and AI must underpin everything the organization does, and reach every individual in the organization. That means getting data into the hands of all employees—from the most technical to the least— so all of them can play an active role in driving insights to improve operations, developing new products, and serving audiences better.” 

The post Leaders looking for a unified, built-in governance of data and AI: MIT report first appeared on IT World Canada.

Warning: A fake ‘security researcher’ is trying to trick ransomware victims

Beware of so-called security researchers emailing firms that have been victimized by ransomware and claiming to be able to recover their stolen data.

That’s the warning from researchers at Arctic Wolf, who have found at least two examples of what are being described as follow-on extortion attacks.

The fake researcher offers to hack into the server infrastructure of the original ransomware group to either recover or delete exfiltrated data. This is a scam whose goal is to get the victim organization to pay bitcoin for supposed assistance.

The report details two cases researchers investigated:

— in early October 2023, an entity describing themselves as “Ethical Side Group (ESG)” contacted a Royal ransomware victim by email and claimed to have obtained access to victim data originally exfiltrated by the crooks. Royal had told the victim firm it had deleted the stolen data.

“ESG” offered to hack into the ransomware gang’s server infrastructure and permanently delete the organization’s stolen data for a fee.

— in early November 2023, an entity describing themselves as “xanonymoux” contacted an Akira ransomware encryption victim and claimed to have obtained access to a server hosting victim data exfiltrated by the crooks. This despite the fact that Akira claimed it didn’t exfiltrate any data and had only encrypted the victim’s IT systems.

“Xanonymoux” claimed to have compromised Akira’s server infrastructure and offered to help either in deleting the victim’s allegedly stolen data or providing the victim firm with access to Akira’s server.

“Based on the common elements identified between the cases documented here, we conclude with moderate confidence that a common threat actor has attempted to extort organizations who were previously victims of Royal and Akira ransomware attacks with follow-on efforts,” say the researchers. “However, it is still unclear whether the follow-on extortion cases were sanctioned by the initial ransomware groups, or whether the threat actor acted alone to garner additional funds from the victim organizations.

“This research highlights the risks of relying on criminal extortion enterprises to delete exfiltrated data, even after payment.”

The post Warning: A fake ‘security researcher’ is trying to trick ransomware victims first appeared on IT World Canada.

Cyber Security Today, Jan. 10, 2024 – Vulnerabilities found in internet-connected factory torque wrenches

Vulnerabilities found in internet-connected factory torque wrenches.

Welcome to Cyber Security Today. It’s Wednesday January 10th, 2024. I’m Howard Solomon, contributing reporter on cybersecurity for ITWorldCanada.com and TechNewsday.com in the U.S.



Anything that connects to an IT network can have software vulnerabilities. The latest example: WiFi connected pneumatic torque wrenches used by car manufacturers. According to researchers at Nozomi Networks, the vulnerabilities they found in a Bosch Rexroth wrench could let a hacker plant ransomware that would spread across a network. Or the holes could let an attacker alter a wrench’s tightening controls and affect the safety of products. A manufacturer using compromised devices could be extorted by a hacker, and sued by customers. The vulnerabilities are in the device’s Linux-based operating system. The wrench connects to a wireless network so it can be remotely programmed. The lesson: Makers of any internet-connected device have to continuously scrutinize their code for vulnerabilities.

Microsoft SQL database servers in the U.S., Europe and Latin America are being targeted by a threat actor. According to researchers at Securonix, the gang either sells access to compromised servers or plugs them with a strain of ransomware called Mimic. This particular gang has been ramming their way into servers through brute force attacks, which are preventable. Then they leverage a command to create a Windows shell, a command that is supposed to be disabled by default. Among the lessons from this attack: Don’t expose critical servers to the internet — and if you have to, protect them with security like a virtual private network. And IT should always be watching for the creation of new local users on servers and other endpoints.

An American judge has sentenced a Nigerian man to 10 years and one month in prison and ordered him to pay almost US$1.5 million in restitution for conspiring to launder money pulled from internet fraud schemes. The 33-year-old man worked directly with the Nigeria-based leader of an international criminal organization to defraud individuals and businesses across the U.S. He was convicted last August by a federal jury. Three co-accused pleaded guilty to conspiracy to commit money laundering.

A threat actor is using hacked YouTube accounts to plant videos of cracked software like games. According to Fortinet, victims who fall for the scam are tricked into downloading malware. The tactic isn’t new. The lessons: Listeners should know by now to secure their social media accounts with multifactor authentication. And employees should be warned that promises of free versions of commercial software by unknown providers only leads to misery.

Finally, yesterday was Microsoft’s monthly Patch Tuesday, when the company issued security updates for its products. January’s patches include fixes for Windows Kerberos and the Hyper-V hypervisor, as well as holes in Microsoft Office, SQL Server and SharePoint Server.

Follow Cyber Security Today on Apple Podcasts, Google Podcasts or add us to your Flash Briefing on your smart speaker.

The post Cyber Security Today, Jan. 10, 2024 – Vulnerabilities found in internet-connected factory torque wrenches first appeared on IT World Canada.

Hashtag Trending Jan.10- Only 700 IT jobs added in the U.S. in 2023; 23 vulnerabilities in network-connected wrench used globally in factories; Microsoft discovery that could reduce lithium use in batteries by 70 percent

Only 700 net new jobs were added in the U.S. in 2023, an “intelligent wrench” has vulnerabilities that would permit hackers to breach a network, AI solves an innovation dilemma, more from the X files and – they might call it the “smellphone” 



 

These and more top tech stories on Hashtag Trending

I’m your host Jim Love, CIO of IT World Canada and Tech News Day in the US.

In a startling revelation for the tech industry, a mere 700 IT jobs were added in the U.S. in 2023, a dramatic downturn from the 267,000 jobs in the previous year. This information, based on an analysis of U.S. Bureau of Labor Statistics data by Janco Associates, highlights a significant shift in the IT job market. The report indicates that while over 21,000 IT jobs were created in the last quarter of 2023, the overall growth remained stagnant due to mass layoffs. Interestingly, despite these layoffs, there remains a surplus of vacant IT roles, with about 88,000 positions unfilled. This paradox is attributed to a skills mismatch in the industry, with a high demand for professionals skilled in AI, security, development, and blockchain, while entry-level positions are increasingly automated. Salaries in AI-related roles are on the rise, suggesting a pivot towards more specialized skills in the IT sector. 

So where are all the new jobs coming from if not from tech?  It turns out the construction industry is booming in Canada and the U.S.  Apparently nobody’s laughing at “bricks and mortar” now. 

Sources include: The Register

Security researchers from Nozomi have discovered 23 vulnerabilities in the Bosch Rexroth Handheld Nutrunner NXA015S-36V-B, a network-connected wrench used globally in factories for assembling sensitive instruments and devices. These vulnerabilities could allow hackers to sabotage or disable these tools, posing significant risks to manufacturing processes. The Nutrunner, critical for ensuring precise torque levels for safety and reliability, can be compromised to either tighten fastenings too loosely or too tightly, while falsely indicating correct settings.

Bosch Rexroth has acknowledged the issue and is working on a patch, expected to be released by the end of January 2024. The vulnerabilities allow for remote execution of arbitrary code with root privileges, enabling various attack scenarios. In a lab environment, Nozomi researchers demonstrated two potential attacks: installing ransomware to make the device inoperable and demanding a ransom, and stealthily altering the tightening programs while displaying normal values to the operator. These findings highlight the growing cybersecurity challenges in the increasingly networked manufacturing sector.

Sources include: Ars Technica

If you remember your high school science history you may know that Edison didn’t invent the light bulb. What he did was have 1,000 unsuccessful attempts before he figured out what filament in what bulb construction would work to design a light bulb that could be commercially produced and used in homes and businesses.  

That method of discovery hasn’t changed much in the decades since Edison until recently. 

Microsoft and the Pacific Northwest National Laboratory have discovered a new material using AI and supercomputing that could reduce lithium use in batteries by up to 70 per cent. This breakthrough was achieved by using advanced AI and high-performance computing to narrow down 32 million potential materials to 18 candidates in less than a week, a process that would traditionally take decades. 

The new material, a solid-state electrolyte, has been used to power a lightbulb and shows promise as a sustainable energy storage solution.  

It’s one of many proposed solutions to a key dilemma. Lithium is not only rare, but also dangerous.    

But this invention is the one that has also leveraged AI to accelerate innovation and invention.  

Sources include: BBC News

I almost didn’t cover this story, but in the end I had to run it, because IF it’s true, and that’s an IF, it explains a lot.

Elon Musk, the CEO of Tesla and SpaceX, is facing allegations of possible illegal drug use, according to a report in the Wall Street Journal. These allegations have raised concerns among executives within his companies. 

The report details an incident at a recent SpaceX meeting where Musk’s behavior was described as “nonsensical,” “unhinged,” and “cringeworthy.” He reportedly arrived nearly an hour late and was rambling and slurring his words. Linda Johnson Rice, a former Tesla board member, reportedly decided against re-election due to concerns about Musk’s drug use and unpredictable behavior.

According to recent reports, Musk has previously admitted to using ketamine to treat depression and smoked marijuana during a “Joe Rogan Experience” podcast in 2018, which led to complications with NASA.

Musk has denied these claims, stating that no drugs or alcohol have been found in his body during random tests conducted over the past three years.

Musk’s lawyer, Alex Spiro, confirmed that Musk had never failed a drug test and criticized the report for citing “false facts” without specifying them.

Source: Euronews 

And I’m getting tired of the continued bad news in tech jobs, but here’s another story I thought I had to cover.  

Unity, the company behind the popular game engine, is facing a significant workforce reduction, with plans to lay off about 25 percent of its staff, amounting to around 1,800 employees. This decision, as stated in a filing with the Securities and Exchange Commission, is part of Unity’s restructuring and refocusing efforts on its core business to achieve long-term and profitable growth.

This latest round of layoffs follows several others within the past year, including a notable reduction of 265 workers last November. The specifics of whether the 1,800 job cuts are in addition to last year’s layoffs remain unclear. Unity’s recent layoffs occurred shortly after the company altered its pricing model, which initially frustrated developers. These changes were partially reversed, and former CEO John Riccitiello resigned in the aftermath.

Kelly Ekins, Unity’s director of PR, expressed that the decision to reduce the workforce was challenging and extended gratitude to those affected for their dedication and contributions. Unity’s game engine is used in popular games like Fall Guys and Pokémon Go. The gaming industry has seen a wave of layoffs over the past year, with major companies like Epic Games, EA, and Naughty Dog also announcing job cuts, affecting over 9,000 people in the industry in 2023.

Source: The Verge

And to get a whiff of something different to close off the show…

An Israeli firm Mobile Physics, backed by Oracle founder Larry Ellison, has developed this technology to transform any cellphone into a personal “envirometer” and weather station. It utilizes a phone’s existing sensors to measure air quality, smoke levels, temperature, and UV exposure. In real-time, the technology can alert users to hazardous conditions, advising actions like opening or closing a window, turning on an air purifier, or wearing a mask.

This innovation is particularly timely as air pollution and increasingly severe wildfires pose growing health risks. The technology has been embedded within Qualcomm’s new Snapdragon 8 Gen 3 mobile processor, using STMicroelectronics’s direct time-of-flight (dToF) sensors, capable of detecting small particulate matter. Phone manufacturers like Samsung, Google, and Xiaomi have shown interest in this technology.

The data collected by these “envirometer” phones could be invaluable not only to individual users but also to governments, health authorities, and insurance companies, offering a detailed portrait of local environmental conditions. Mobile Physics also plans to introduce a subscription version with additional information, which could be especially beneficial for people with respiratory diseases.

Source: Axios

Hashtag Trending goes to air 5 days a week with a special weekend interview show we call “the Weekend Edition.”

You can get us anywhere you get audio podcasts and there is a copy of the show notes at itworldcanada.com/podcasts 

I’m your host, Jim Love. Have a Wonderful Wednesday!

The post Hashtag Trending Jan.10- Only 700 IT jobs added in the U.S. in 2023; 23 vulnerabilities in network-connected wrench used globally in factories; Microsoft discovery that could reduce lithium use in batteries by 70 percent first appeared on IT World Canada.

Female cyber pros group targeted in phishing scam

A threat actor is trying to con female cybersecurity pros into downloading malware.

The warning comes from the Canadian-based Women CyberSecurity Society (WCS2), which says someone is targeting members of the leadership team, members, and volunteers, trying to trick them into clicking on malicious links in text-based phishing messages, which is also called smishing.

“A volunteer recently reported receiving a text message claiming to be from founder Lisa Kearney citing an urgent need for help,” the warning says.

“We believe others will be targeted in such a manner and we urge you to exercise caution when interacting with emails, messages and online links from someone who you don’t know.”

The text message asked the volunteer to buy some Google certificate back codes.

One key this is a scam: The sender said they were in a meeting, could only text and asked the volunteer “to run a task urgently.”

Experts say a message asking a person to do something quickly — such as spend money, send money, or send a copy of sensitive information — should be seen as suspicious.

WCS2 believes the threat actor used LinkedIn and open-source intelligence to gather information about the organization, members, and volunteers to target them.

The group asks members to

– Verify caller identity: If you receive a call claiming to be from the Women CyberSecurity Society, ask for the caller’s name and contact information. Hang up, independently verify the information through official channels, and call back using a published contact number;

– Do not click on suspicious links: Avoid clicking on any links received through phone calls, voicemails, or text messages, especially if the communication seems unexpected or unusual;

– Report suspicious activity: If you receive any communication that seems suspicious or if you believe you have been targeted, please report it immediately to WCS2’s security team;

– Use security software: Install and regularly update security software on your mobile device, desktop, laptops and tablets to help detect and prevent smishing attacks.

– Educate yourself: Stay informed about common phishing tactics and be cautious when receiving unexpected messages, even if they appear to be from familiar sources.

WCS2’s next event is Jan. 30, when it will host a two-hour webinar on how to start a new career in cybersecurity.

The post Female cyber pros group targeted in phishing scam first appeared on IT World Canada.

Info-Tech analyst, VMware partner denounce Broadcom’s new channel strategy

Broadcom gave the market, and specifically the channel, an unwelcome New Year’s surprise when it announced plans to end the VMware partner program effective Feb. 5, precisely the sort of action that was predicted by analysts and feared by customers and (now) former resellers, says John Annand, executive councilor practice lead at Info-Tech Research Group.

Annand,  who in a former career once sold, installed, and configured VMware, said the VMWare partner program has been around since the company’s inception in 1998 and has long been a darling of the reseller, VAR, and channel communities.

“Almost a rite of passage certification for so many IT professionals, especially early in their career, it was so popular that a scant 12 years later, the unofficial meetups, chatrooms and email lists of practitioners banded together to form VMware User Group (VMUG),” he said.

“An organization independent of VMware that quickly turned into a global organization with a mission to help members connect, collaborate and network with fellow VMware users, VMUG has chapters in most major cities, put on its own conferences, and developed its own training materials, webcasts, and even awards.”

Among those partners severely impacted by Broadcom’s move is Whipcord Edge Data Centers, an infrastructure service provider with data centre facilities in Toronto and Lethbridge that has offered private cloud services for more than 10 years and leverages VMWare’s Cloud Service Provider program.

In addition to receiving the VMware Partner Programs Termination Notice on Dec. 22, said Dan Hamilton, Whipcord Edge’s chief operating officer (COO), the company also received a CSP-specific termination notice.

“The second paragraph starts with ‘effective April 30, 2024, the ability to transact as a VMware Cloud Services Provider, under the VMware Partner Connect Program, will come to an end.’

“This sentence in particular came as a tremendous shock to us. There was no forewarning; no indication at all that this was coming. We knew about the changes to the bundles and pricing on the reseller side, but nothing at all about changes to the CSP program. They mention the Broadcom Expert Advantage Partner Program, but to date we have not received any invitation.”

Hamilton added that the “other piece to this that is shocking is the silence from the aggregators. Under the CSP program, we rely on the aggregators to provide our link with VMware in terms of information and concerns regarding the program. Our aggregator (Ingram Micro) has been completely silent. No communication whatsoever. We have reached out multiple times and received no reply. When reaching out to VMware directly, they point back to the aggregator.”

This is, he said, a “a major component” of Whipcord’s business that is now in limbo:  “We have no idea if we will be invited to the Broadcom program, or how that program will be structured. Given the other changes we have seen, I am very concerned that the structure could change from the current consumption-based vRAM model to a core-based model. Or the program could end entirely; we do not know since VMware and Broadcom have not provided any details at all. Either way, this could kill VMware-based private cloud solutions like ours.”

Annand said that VMware was a company that embraced partners both on the sales enablement (resellers, MSPs and consultants) as well as on the technology side (Veeam, Microsoft, etc). It was a company that had collaboration as part of its DNA.

“The result was a product that was comparatively easy for the enterprise to buy and was a sufficiently complete as a solution. And where perhaps there were deficiencies, other OEMs and independent software vendors were encouraged and incentivized to help fill in those gaps. The result was stability and innovation which let whole generations of Infrastructure professional rest easy at night.”

Broadcom, at its heart, he said, “appears to me to be more like a private equity company. Concerned about operational efficiencies over technological upheaval and revolution. They have announced an end to perpetual licensing (which, to be fair, VMware was moving towards already) and promised a simplification of the license model.

“This means bundling fewer subscription-only SKUs at average higher price points. No longer will you just be able to buy the bare necessities of what you need. Fewer partners will mean less competition on price and greater onus for the enterprise to solution design for themselves.”

The acquisition, said Annand, has been a “great move for Broadcom and its shareholders. Broadcom’s ongoing public communications continue to prove that there is little to no – to perhaps negative – upside for former VMware customers.”

Channel Daily News did reach out to VMware Canada for comment, but at press time, had yet to receive a reply.

When contacted about Hamilton’s concerns, a spokesperson for Ingram Micro Canada said, “I have forwarded this to the team, to work with the customer. And at this time, we are unable to provide any comments.”

The post Info-Tech analyst, VMware partner denounce Broadcom’s new channel strategy first appeared on IT World Canada.

American regulator slams data broker for selling mobile location data without consent

In a warning that American data brokers need to be careful about selling precise geolocation information of mobile phone users, the U.S. Federal Trade Commission has proposed banning a major company from taking advantage of all the data it can collect.

Assuming the settlement is confirmed, the FTC will forbid Outlogic LLC from sharing or selling any sensitive location data. This would settle allegations that the company sold precise location data of mobile users, without their consent, that could be used to track people’s visits to sensitive locations such as medical and reproductive health clinics, places of religious worship, and domestic abuse shelters.

FTC also charged that Virginia-based Outlogic (the firm that acquired the operations of X-Mode Social in 2021, which is where the FTC investigation began) failed to put in place reasonable and appropriate safeguards on the use of such information by third parties.

“Geolocation data can reveal not just where a person lives and whom they spend time with but also, for example, which medical treatments they seek and where they worship. The FTC’s action against X-Mode makes clear that businesses do not have free license to market and sell Americans’ sensitive location data,” said FTC Chair Lina Khan. “By securing a first-ever ban on the use and sale of sensitive location data, the FTC is continuing its critical work to protect Americans from intrusive data brokers and unchecked corporate surveillance.”

X-Mode collected precise consumer geolocation data from a wide variety of sources, the FTC explained. That included third-party apps with X-Mode’s software development kit (SDK) built in, its own mobile apps, and information it bought from other data brokers and aggregators. The company then compiled consumers’ location data and sold it to hundreds of clients for advertising, brand analytics, and other marketing purposes. According to the  FTC complaint, the company also sold the raw data to private government contractors.

The FTC says this was done without consumers’ informed consent and without disclosing all of the purposes for which consumers’ data would be used, practices of unfair or deceptive conduct in violation of the FTC Act.

To settle the case, the company has agreed to make major changes to how it does business going forward, the FTC said. That includes putting substantial limits on sharing certain sensitive location data. The settlement requires the company to develop a comprehensive sensitive location data program to prevent the use and sale of consumers’ sensitive location data. Outlogic also must take steps to prevent clients from associating consumers with locations that provide services to LGBTQ+ individuals or with locations of public gatherings like marches or protests.

In addition, the company must take effective steps to see to it that clients don’t use their location data to determine the identity or location of a specific individual’s home. And even for location data that may not reveal visits to sensitive locations, Outlogic must ensure consumers provide informed consent before it uses that data. Finally, X-Mode/Outlogic must delete or render non-sensitive the historical data it collected from its own apps or SDK and must tell its customers about the FTC’s requirement that such data should be deleted or rendered non-sensitive.

Outlogic must also give consumers an easy way to withdraw their consent for the collection and use of their location data, to require the deletion of any location data that was previously collected, and to request the identity of any individual and business to whom their personal data has been sold or shared.

Once the proposed settlement is published in the Federal Register, the FTC will accept public comments for 30 days, after which the commission will decide whether to make the proposed consent order final.

In response to the settlement, Outlogic told TechCrunch that it disagrees with the implications of an FTC press release. “After a lengthy investigation, the FTC found no instance of misuse of any data and made no such allegation. Since its inception, X-Mode has imposed strict contractual terms on all data customers prohibiting them from associating its data with sensitive locations such as healthcare facilities. Adherence to the FTC’s newly introduced policy will be ensured by implementing additional technical processes and will not require any significant changes to business or products.”

Meanwhile, the FTC continues with its investigation against data broker Kochava Inc. for allegedly acquiring and selling consumers’ sensitive, identifying, and mobile geolocation information without their consent.

The collection and sale of information by data brokers has worried consumers and regulators for years. In Canada, the federal Office of the Privacy Commissioner began an investigation into the practices of six data brokers in 2018.

Last November, the Irish Council for Civil Liberties warned extraordinarily sensitive information about key European and U.S. figures and military personnel is being sold to foreign states and non-state actors through online advertising’s Real-Time Bidding (RTB) system.

Also in November, Duke University reported that sensitive personal information about active-duty American armed forces members, their families, and veterans is being sold by data brokers for 12 cents a person.

The post American regulator slams data broker for selling mobile location data without consent first appeared on IT World Canada.

Canadian companies struggling to put ESG mandates into action as reporting pressures ramp up

Over 1000 Canadian companies are facing environmental, social and governance (ESG) reporting requirements under the new Corporate Sustainability Reporting Directive (CSRD), research published in the Wall Street Journal revealed.

CSRD mandates companies both inside and outside the European Union (EU) to report on ESG. Canadian companies will need to publish their first report in 2025 and obtain an independent review of what they report. So time is of the essence.

However, a new report by Enterprise Ireland that surveyed 332 senior Canadian decision makers in Medium to Enterprise businesses found that 74 per cent are still struggling to put ESG mandates into action. In fact, only 39 per cent report having taken “substantial steps” toward implementing ESG initiatives.

Over half of the surveyed organizations had a moderate-to-low understanding of ESG commitments and implications, while 42 per cent saw pitfalls in resource constraints – which includes the adoption of technology to capture data, and report on progress. Additionally, only one-third have a dedicated ESG role or department, and another 18 per cent do not know how it is managed.

With these challenges, companies are employing a mix of internal initiatives like employee surveys and external initiatives such as sustainability reports and third-party audits to capture data. 

Over 70 per cent say they are likely to adopt new technologies in order to deliver on ESG initiatives in the future. Meanwhile, 38 per cent have developed such technology in the past 12 months, the report noted.

Forrester, in fact, predicts that the sustainability management software market will double next year due to compliance needs.

Nonetheless, only 26 per cent feel that they are capturing “very accurate” ESG data, while 34 per cent say it is not accurate, or they simply do not know.

Businesses that can’t answer questions from customers and investors about how they manage their material ESG risks and opportunities in a satisfactory manner—and are unable to produce trusted data to support their narrative—may lose market share and access to financing, PwC asserted in a recent report.

Canadian companies, accordingly, recognize the importance of ESG initiatives to corporate policy, with 67 per cent predicting that ESG would escalate as a company priority. 

“We know that today’s consumers are more purpose-oriented than ever before, and that
individuals are more likely to support a brand that aligns with their values, whether that’s
in support of climate change, human rights efforts, or ethical business practices,” said David McCaffrey, country manager and senior vice president at Enterprise Ireland Canada. “Based on this, organizations understand that ESG initiatives are more than a government
requirement, but a business imperative to effectively compete in today’s landscape.”

Between 42 and 66 per cent of the surveyed companies are targeting environmental initiatives, including waste management (66 per cent) and carbon footprint reduction (63 per cent). And 55 per cent plan to reduce scope 1, scope 2, or scope 3 emissions.

However, companies are targeting social initiatives more, with employee well-being and labour practices (both 89 per cent) marked as top priorities.

A possible reason for this is that “social initiatives have often more immediate and visible impacts on local communities and employees, making the targets and results more tangible for companies,” explained McCaffrey. “We have also seen that addressing social
issues may more closely align with a company’s values and mission, making it a priority.”

Finally, between 57 per cent and 76 per cent are targeting ESG governance and reporting, including ethical business practices, and anti-corruption measures as well as stakeholder engagement.

“The bottom line: these problems are not independent of one another, and that opens the
door for Canadian companies that might be feeling the pressure under this year’s
mandates to target ESG initiatives that can solve for more than one issue,” said McCaffrey.

The post Canadian companies struggling to put ESG mandates into action as reporting pressures ramp up first appeared on IT World Canada.

Many IT departments still don’t know how many APIs they have: Report

IT departments still don’t have an accurate count of the number of application programming interfaces (APIs) their app developers are putting into production, says a new report.

That’s one of several conclusions researchers at Cloudflare came to in a report on API security and management released today.

APIs, which allow applications to communicate with each other, outpace other internet traffic, the report found. They comprised more than half (57 per cent) of the dynamic internet traffic processed by Cloudflare last year.

However, many organizations don’t know how many APIs they are supposed to oversee. Cloudflare found some organizations have 30 per cent more API endpoints than they think they have.

“You can’t protect what you don’t know exists,” John Cosgrove, product manager for Cloudflare’s API gateway, commented in an interview about the report.

Not only that, the report says, IT may unintentionally block legitimate traffic because they don’t know how many APIs to protect.

So called ‘zombie’ or ‘shadow’ APIs may have been undocumented by developers who created them, but who have left the organization, Cosgrove said, or they may be hanging around from abandoned projects.

If exploited, these APIs can lead to data exposure, unpatched vulnerabilities, data compliance violations, lateral movement and other problems.

The 2019 data breach of a medical diagnostics company exposed the data of nearly 12 million patients when an unauthorized user gained access to an API that was sending information to billing vendors, the report notes.

“API threats are out there,” Cosgrove said. “They can be as old as SQL injection or as new as a broken authentication attack. You need to have a tool that compiles an API inventory and then you need protection from all these attacks.”

Some CISOs may be worried about advanced attacks, he said, but “if your web application firewall isn’t even protecting your APIs, the ‘old’ threats will still come and get you.” One problem, he said, is that a lot of APIs weren’t written to withstand large volumetric distributed denial of service attacks.

The report is based on traffic data collected by Cloudflare’s global network between Oct. 1, 2022 and Aug. 31, 2023.

Another possible problem the report discovered is the misinterpretation of API errors. For example, the most frequent HTTP status code error IT departments see is 429, which means the API server has automatically throttled traffic because of a certain action, such as an IP address exceeding a set number of requests per minute per endpoint. However, the report says, a wrongly-set request rate limit may be triggering that error.

As consumers and end users continue to expect faster, more dynamic web and mobile experiences, the report warns, development and API teams will come under more pressure to deploy and maintain many more APIs.

“These well-meaning app developers will continue to deploy APIs fast — sometimes without consulting other IT and security stakeholders,” the report says. This lack of a cohesive approach will force enterprises into difficult corners as they face several challenges, including an increase in business logic-based fraud attacks.

CISOs at the very least have to pay attention to API discovery, Cosgrove said. Those with more mature security programs should look at their rate-limiting strategies. Those who have no API security posture should at least have the bare basics, he added, including DDoS protection.

The report can be downloaded here. Registration is required.

The post Many IT departments still don’t know how many APIs they have: Report first appeared on IT World Canada.

CES 2024: Intel drops full 14th Gen mobile and desktop processor lineup

Last night at CES 2024, Intel unveiled its full Intel Core 14th Gen mobile and desktop processor lineup as well as its new Intel Core mobile processor Series 1 family for mainstream thin and light mobile systems.

Core 14th Gen mobile processors

Led by the flagship Intel Core i9-14900HX, the latest generation mobile processor family includes 5 new processors, and is built mainly for creators and gamers who use laptops yet requiring higher compute performance.

It features up to 5.8 GHz turbo frequency and includes 24 cores (eight performance / 16 efficiency) plus 32 threads in its i9-14900HX processors. These chips also support up to 192 gigabytes (GB) of total DDR5-5600 megatransfers/second (MT/S) memory, integrated Intel Wi-Fi 6E and 7, the latest in Bluetooth connectivity, ThunderBolt 5 and more.

Intel did not offer any comparison to last year’s 13th Gen chips, but there have been minor upgrades in turbo frequency, and memory, as well as Wi-Fi 7 connectivity.

See also:

CES 2023: Intel unveils new mobile processors

Intel did however, compare its flagship with AMD’s Ryzen 9 7945HX and Ryzen 9 7945HX3D, touting higher gaming performance in several popular games at 1080p.

Source: Intel

More than 60 partner systems, including HP, Alienware, Acer, Lenovo, and more will use Intel’s mobile chips and launch new products in 2024, Intel said.

Core 14th gen desktop processors

Intel dropped 18 new desktop processors in addition to the six launched last October.

Overall, the desktop processors will include up to 5.8 GHz turbo frequency, support for up to 192 GB of total DDR5-5600/DDR4-3200 MT/S memory, support for in-box thermal solutions, Intel Wi-Fi 6E and 7 connectivity, ThunderBolt 4, integrated USB 3.2 connectivity support and more.

The flagship – Core i9-14900 processor with 24 cores (eight P-cores / 16 E-cores) and 32 threads – will cost US$549.

Intel again touted higher mainstream performance in everyday productivity and content creation, compared to AMD’s RyzenTM 9 7900.

New Intel Core mobile processor Series 1

The newly introduced Series 1 family will have three processors designed to provide balanced and efficient performance in thin and light devices, the company said.

The chips include up to 5.4 GHz turbo frequency along with up to 10 cores (two P-cores, eight E-cores) and 12 threads in its flagship Intel Core 7 processor 150U.

Additionally, the processors support up to 96 GB of total DDR5-5200/DDR4-3200 MT/S memory, include the latest Bluetooth and Thunderbolt 4 universal connectivity, support for both Intel Killer Wi-Fi 7 and 6E, and more.

Mobile systems powered by the Intel Core U Processor Series 1 will come to market in the first quarter of 2024, the company said.

The post CES 2024: Intel drops full 14th Gen mobile and desktop processor lineup first appeared on IT World Canada.