|By Xenia von Wedel||
|February 26, 2014 12:35 PM EST||
Thanks for taking the time to answer my questions. Please tell us, what is Agiliance all about and what do you do?
Torsten George: Cyber-attacks, insider threats, monetary fraud, and data breaches - affecting some of the world's most renowned organizations - make headlines every day. At the same time, the worst economic downturn since the 1930s has focused intense attention on inadequate risk management and the effectiveness of governance practices. The key to addressing these complex, interlocking problems is implementing a context-aware, scalable risk management infrastructure that makes risk visible, measurable, and actionable across financial, operational, and security domains.
That's where Agiliance® comes into play. We're known as the Big Data Risk CompanyTM and leading independent provider of integrated solutions for operational and security risk programs. Our mission is to help organizations to unlock and use their knowledge of risk to optimize business investments and performance.
As the pioneer of the Big Data Risk Management category, we're disrupting the established practice of performing risk management as continuous consulting, replacing it with continuous, automated software-based monitoring.
What are you launching at RSA?
George: Agiliance is launching RiskVisionTM 7, which redefines the management of enterprise and supplier risk, regulatory compliance, security, and incidents using a big data-driven model. RiskVision 7 performs near real time analysis of petabytes of governance and security risk data to accelerate incident response actions, identify cross-domain threats, automate process change, speed user productivity, scale operational efficiency, and ultimately assess risk based on business impact.
Organizations are operating in a dynamically changing risk ecosystem, which is characterized by mushrooming government regulations (e.g., UK FSA, Singapore MAS) that scrutinize inadequate, assessment-based risk management and governance practices, as well as new cyber-attack vectors such as bring-your-own-devices (BYOD) and an organization's supply chain. As a result, it has become imperative to strategically align datacenter operations, cloud operations, and supplier services with accurate risk prioritization, remediation, and audit reporting.
RiskVision 7 addresses these market requirements by enabling continuous diagnostics and remediation on more than one million assets and correlating threats, vulnerabilities, controls testing, and policies for near real-time risk management. It is also the only commercial integrated risk management system in production for enterprise and supplier incident response with a ten-thousand practitioner deployment.
Who is your target audience and how do you intend to reach them?
George: Agiliance's priority target segments are Global 2,000 companies and government agencies in North America, Europe, Singapore, and Australia. These organizations face complex threats and compliance requirements, have mature security defenses, and typically have implemented failed silo-based departmental approaches to risk management. Target buyers for Agiliance solutions are the Chief Information Security Officer, or their superior, normally the Chief Information Officer or Chief Risk Officer.
I'd be curious to hear any general thoughts you have on market trends...
George: For 2014 we predict five major trends: #1 Organizations will finally transition away from a compliance, check-box mentality and adapt a risk-based, pro-active approach. This trend is primarily driven by the realization that you can schedule an audit, but you cannot schedule a cyber security attack. Furthermore, we are foreseeing as the #2 trend that legislation and industry standards will shift their focus from providing mandates for preventive measures to risk awareness and remediation response. Early examples in this context are MAS, OCC Guidance, and PCI DSS 3.0. For instance, introducing set response times in Singapore MAS is challenging organizations to change their culture. #3 We foresee that threats will finally be recognized as one of the main factors that determine risk. In support of the adoption of threat modeling and intelligence feeds, standards such as VERIS and STIX will emerge. Confirmation for this trend can be seen by the growing number of threat intelligence feed vendors; notably four out of the ten RSA Sandbox Innovation Awards finalists are tied to threat intelligence. #4 Based on the uptick in cyber-attacks targeting the supply chain, we predict that vendor risk management will completely change. The days where end user organizations relied on vendor risk assessments via questionnaires are coming to an end. Instead end user organizations will turn the table on their suppliers and in case of software vendors require an independent accreditation certification before allowing the technology to be deployed in the enterprise. And last, but not least we anticipate 2014 to be the break-through year for Managed Security Services. This is simply based on the fact that the data volume, velocity, variety, and complexity is overwhelming many organizations. Thus, outsourcing of threat diagnostics and remediation responses will be highly accepted service.
What is the viral aspect of your product?
George: It's only February and we've already experienced several massive data breaches at Target and Neiman Marcus. Any time that there is a data breach intense attention is being put on inadequate risk management and the effectiveness of governance practices, offering Agiliance ways to provide public commentary and then take these media clips viral.
What's the business model? How will you make money?
George: Agiliance's business model is best described as Managing Risk-as-a-ServiceTM (M-RaaS). The RiskVision solution is delivered by a broad range of organizations, both on-demand and on-premise, across a mix of physical and virtual environments. This flexibility allows customers to purchase according to their organizational maturity and scale; allowing them to extend usage as their maturity increases.
RiskVision pricing is based on number of applications, connectors, and managed assets. The platform and the majority of content are covered by annual subscriptions. Pricing starts at $25,000 per application per year with cumulative volume discounts for all applications, connectors, and managed assets purchased.
In the midst of the widespread popularity and adoption of cloud computing, it seems like everything is being offered “as a Service” these days: Infrastructure? Check. Platform? You bet. Software? Absolutely. Toaster? It’s only a matter of time. With service providers positioning vastly differing offerings under a generic “cloud” umbrella, it’s all too easy to get confused about what’s actually being offered. In his session at 16th Cloud Expo, Kevin Hazard, Director of Digital Content for SoftL...
Jun. 30, 2015 05:00 PM EDT Reads: 2,029
Agile, which started in the development organization, has gradually expanded into other areas downstream - namely IT and Operations. Teams – then teams of teams – have streamlined processes, improved feedback loops and driven a much faster pace into IT departments which have had profound effects on the entire organization. In his session at DevOps Summit, Anders Wallgren, Chief Technology Officer of Electric Cloud, will discuss how DevOps and Continuous Delivery have emerged to help connect dev...
Jun. 30, 2015 04:39 PM EDT Reads: 310
Today air travel is a minefield of delays, hassles and customer disappointment. Airlines struggle to revitalize the experience. GE and M2Mi will demonstrate practical examples of how IoT solutions are helping airlines bring back personalization, reduce trip time and improve reliability. In their session at @ThingsExpo, Shyam Varan Nath, Principal Architect with GE, and Dr. Sarah Cooper, M2Mi’s VP Business Development and Engineering, will explore the IoT cloud-based platform technologies drivi...
Jun. 30, 2015 04:21 PM EDT Reads: 314
Containers are changing the security landscape for software development and deployment. As with any security solutions, security approaches that work for developers, operations personnel and security professionals is a requirement. In his session at DevOps Summit, Kevin Gilpin, CTO and Co-Founder of Conjur, will discuss various security considerations for container-based infrastructure and related DevOps workflows.
Jun. 30, 2015 03:59 PM EDT Reads: 323
It is one thing to build single industrial IoT applications, but what will it take to build the Smart Cities and truly society-changing applications of the future? The technology won’t be the problem, it will be the number of parties that need to work together and be aligned in their motivation to succeed. In his session at @ThingsExpo, Jason Mondanaro, Director, Product Management at Metanga, discussed how you can plan to cooperate, partner, and form lasting all-star teams to change the world...
Jun. 30, 2015 02:15 PM EDT Reads: 2,097
Overgrown applications have given way to modular applications, driven by the need to break larger problems into smaller problems. Similarly large monolithic development processes have been forced to be broken into smaller agile development cycles. Looking at trends in software development, microservices architectures meet the same demands. Additional benefits of microservices architectures are compartmentalization and a limited impact of service failure versus a complete software malfunction. ...
Jun. 30, 2015 01:56 PM EDT Reads: 517
Internet of Things is moving from being a hype to a reality. Experts estimate that internet connected cars will grow to 152 million, while over 100 million internet connected wireless light bulbs and lamps will be operational by 2020. These and many other intriguing statistics highlight the importance of Internet powered devices and how market penetration is going to multiply many times over in the next few years.
Jun. 30, 2015 01:45 PM EDT Reads: 1,936
Internet of Things (IoT) will be a hybrid ecosystem of diverse devices and sensors collaborating with operational and enterprise systems to create the next big application. In their session at @ThingsExpo, Bramh Gupta, founder and CEO of robomq.io, and Fred Yatzeck, principal architect leading product development at robomq.io, discussed how choosing the right middleware and integration strategy from the get-go will enable IoT solution developers to adapt and grow with the industry, while at th...
Jun. 30, 2015 01:45 PM EDT Reads: 1,811
Containers have changed the mind of IT in DevOps. They enable developers to work with dev, test, stage and production environments identically. Containers provide the right abstraction for microservices and many cloud platforms have integrated them into deployment pipelines. DevOps and Containers together help companies to achieve their business goals faster and more effectively. In his session at DevOps Summit, Ruslan Synytsky, CEO and Co-founder of Jelastic, reviewed the current landscape of...
Jun. 30, 2015 01:30 PM EDT Reads: 2,062
Malicious agents are moving faster than the speed of business. Even more worrisome, most companies are relying on legacy approaches to security that are no longer capable of meeting current threats. In the modern cloud, threat diversity is rapidly expanding, necessitating more sophisticated security protocols than those used in the past or in desktop environments. Yet companies are falling for cloud security myths that were truths at one time but have evolved out of existence.
Jun. 30, 2015 01:15 PM EDT Reads: 2,012
The cloud has transformed how we think about software quality. Instead of preventing failures, we must focus on automatic recovery from failure. In other words, resilience trumps traditional quality measures. Continuous delivery models further squeeze traditional notions of quality. Remember the venerable project management Iron Triangle? Among time, scope, and cost, you can only fix two or quality will suffer. Only in today's DevOps world, continuous testing, integration, and deployment upend...
Jun. 30, 2015 12:30 PM EDT Reads: 1,809
The time is ripe for high speed resilient software defined storage solutions with unlimited scalability. ISS has been working with the leading open source projects and developed a commercial high performance solution that is able to grow forever without performance limitations. In his session at Cloud Expo, Alex Gorbachev, President of Intelligent Systems Services Inc., shared foundation principles of Ceph architecture, as well as the design to deliver this storage to traditional SAN storage co...
Jun. 30, 2015 10:30 AM EDT Reads: 1,860
To many people, IoT is a buzzword whose value is not understood. Many people think IoT is all about wearables and home automation. In his session at @ThingsExpo, Mike Kavis, Vice President & Principal Cloud Architect at Cloud Technology Partners, discussed some incredible game-changing use cases and how they are transforming industries like agriculture, manufacturing, health care, and smart cities. He will discuss cool technologies like smart dust, robotics, smart labels, and much more. Prepare...
Jun. 30, 2015 10:20 AM EDT Reads: 489
"We provide a web application framework for building really sophisticated web applications that run on a browser without any installation need so we get used for biotech, defense, and banking applications," noted Charles Kendrick, CTO and Chief Architect at Isomorphic Software, in this SYS-CON.tv interview at @DevOpsSummit (http://DevOpsSummit.SYS-CON.com), held June 9-11, 2015, at the Javits Center in New York
Jun. 30, 2015 10:15 AM EDT Reads: 803
The Internet of Things is not only adding billions of sensors and billions of terabytes to the Internet. It is also forcing a fundamental change in the way we envision Information Technology. For the first time, more data is being created by devices at the edge of the Internet rather than from centralized systems. What does this mean for today's IT professional? In this Power Panel at @ThingsExpo, moderated by Conference Chair Roger Strukhoff, panelists addressed this very serious issue of pro...
Jun. 30, 2015 09:45 AM EDT Reads: 836