In the not-too-distant past the boardroom was a place where executives met to plan the future of the company, analyze the competition, discuss satisfaction and retention, and generally come together to brainstorm how to accelerate success. On occasion guests were invited to the boardroom – for example, top customers who required an executive briefing or an employee celebrating 25 years at a company.
Executives would spend hours, if not days, traveling to the boardroom to meet his or her peers face-to-face. The boardroom would be filled with executives sitting down to hammer out the company’s top initiatives.
Today’s boardroom is empty.
Or at least not quite as full as it was a few years ago.
Could it be that executive teams are hosting less face-to-face meetings? Is the desire for personal interactions decreasing? Do people value meetings less now than 5, 10, 15 years ago?
If anything the opposite is true: people want to meet more often but are more geographically dispersed. Executives want the boardroom experience without physically being in the boardroom. Work / life balance (which I personally refer to simply as “harmony”) has made all of us – executives included – demand more time at home which means less time in the boardroom.
Companies like Advocate Health Care and AXA Group have figured out how to bring the boardroom experience anywhere, at anytime.
Boardroom redesign leads to innovation at Advocate Health Care
Advocate Health Care has a very unique boardroom which sits at the heart of its headquarters in Oak Brook, IL. The multi-purpose boardroom is a meeting spot for board members, a place of celebration for associates commemorating a 25-year (or more) anniversary (and there are MANY of them which demonstrates what a great place Advocate is to work but that’s a topic for another blog), and even to film this video testimonial about innovation in the Advocate boardroom and beyond:
The Advocate team describes how adding Cisco TelePresence to the boardroom helped:
- Executives and associates collaborate more effectively and get face-to-face more quickly
- Reduce travel time and improve productivity to better serve patients. For instance, executives that previously spent a week traveling to individual sites can now meet with each site from the boardroom, saving days of travel.
- Include more key people in critical meetings as evidence by Dr. Rishi Sikka, Vice President of Clinical Transformation, “At the end of a long day, no physician wants to drive an hour each way for an in-person meeting. But if they can walk into a TelePresence room in their own hospital right after surgery…they appreciate that. We see more physicians in virtual meetings than we ever saw in our in-person meetings.”
- Save money. “if you get a group of highly-paid physicians into a central location without requiring them to travel, that translates into a considerable cost savings for the organization,” says Dr. Lee Sacks, Executive Vice President and Chief Medical Officer at Advocate
Dr. Sacks, also commented that prior to the TelePresence deployment, a meeting with 20 surgeons would have been difficult, if not impossible. But with Cisco Telepresence, not only is it possible, it is extremely effective and also provides considerable cost savings to the organization.
The results are eloquently summed up in this statement from Dr. Sacks, “We held a single TelePresence meeting for 20 spine surgeons to discuss implantable devices. I’m certain that we paid for our entire TelePresence investment with that one meeting.”
And while there are less people using the Advocate boardroom, productivity has increased, executive and employee satisfaction is higher, and everyone is spending more time focused on their priorities.
AXA Eliminates 20,000 Executive Business Trips
When AXA Group looked for a dynamic solution to leverage the collective knowledge of 214,000 employees worldwide to improve business, they understood the solution would need to be simple and scalable; like Advocate, they chose Cisco TelePresence.
At the beginning of the project, the AXA Tech department identified a few key meetings on which to test the new Cisco TelePresence system, including the annual board meeting.. Board members travel from all around the world to Paris for a 2-hour meeting costing the company a lot of time and money.
The pilot board meeting was a huge success (to the relief of AXA Tech!)! Greg Medwin, Manager Global Network Design Authority at AXA Tech told us, “Some of the initial responses to our AXA presence [Cisco TelePresence] systems was initially ‘wow, how can we adapt this into our business? The pure immersive and interactive response, as well as the ability to reach out and communicate with teams globally or on the other side of town is [powerful]’ It was seen as a great benefit by the executives, something immediately accessible and not expensive”
The success with Cisco TelePresence extends beyond the boardroom:
- Cut travel costs by €100 million over three-year period by hosting 43,000 meetings
- Reduced CO2 emissions by 240,000 metric tons over same timeframe
- Simultaneously allowed executives to make better use of their time by reducing the number of trips for executives by 20,000
- Eliminated 15,000 employee business trips
What is your company doing to bring the boardroom experience outside the boardroom? Share your story!
By Jill Shaul
Wednesday, July 4, 2012
Tuesday, July 3, 2012
Combating Malware and Advanced Persistent Threats
In the past decade, the security industry has seen a constant rise in the volume of malware and attacks associated with them. Malware are constantly evolving to become more complex and sophisticated. For example,
Changes to the Threat Landscape
In the last decade we have seen exponential growth in the number of Internet users worldwide. This expanding base provides a lucrative opportunity to criminal organizations to carry out illicit activities. Compared with earlier malware that primarily created nuisance attacks, today’s malware are much more focused on both their victims and goals. Today’s attacks are a major concern for enterprises and organizations. Not only do they risk the loss of intellectual property or data, but any disruption to business continuity can also severely hamper an organization’s productivity and reputation. Protecting networks with a wide variety of Internet-connected devices—desktops, laptops, smart phones, etc.—has become even more of a challenge.
Botnets are the most common form of malware used by cybercriminals to attack enterprises and government organizations worldwide. Botnets, networks of compromised “robot” machines (also known as zombies) under the control of a single botmaster, carry out malicious activities such as distributed denial of service (DDoS) attacks on servers, steal confidential information, install malicious code, and send spam emails. Recent examples are Operation Aurora, ShadyRAT, and DDoS attacks on payment websites in support of WikiLeaks.
Advanced persistent threats, on the other hand, focus on specific targets, such as government organizations, with motives ranging from espionage to disrupting a nation’s core networks, including nuclear, power, and financial infrastructure. Due to the discrete nature of the attacks, these can remain undetected for a long time. Such attacks are also much more complex and sophisticated compared with other malware. For example, Stuxnet targeted Iranian nuclear facilities and Flame targeted cyberespionage in Middle Eastern countries.
Challenges
Looking at the significance of intellectual property and national secrets as well as the vast potential of monetary rewards gained through these advanced attacks and threats, more and more cybercriminals—often well funded by criminal organizations—are attracted to develop malware. Their authors implement various techniques to make the malware and associated communication channels stealthier to avoid detection by security products on host systems and on the network. For example, encrypting communications between host and control server, using decentralized network architecture to stay undetected and resilient, using domain and IP flux techniques to hide control servers, and obfuscating malicious payloads are some of the techniques widely used by malware these days.
Traditional Detection and Its Limits
A signature-based detection mechanism that looks for unique network patterns has been the traditional method employed by security vendors to provide protection against attacks.
This method, though effective for defending against known threats, has limits.
McAfee Labs
To win the battle and keep customers protected against emerging threats in the future, security vendors must continue to innovate.
Based on the current challenges to and limitations of signature-based detection, McAfee Labs envisions a dynamic solution that can provide proactive protection against future threats.
Such a solution must:
In subsequent blogs, we will talk more about the solution that McAfee Labs believes will be capable of combating malware and advanced persistent threats on our networks.
I would like to thank my colleagues Chong Xu and Ravi Balupari for their contributions to this blog.
By Swapnil Pathak
- Unique malware samples broke the 75 million mark in 2011 – Network World
- 500 malware networks available to launch attacks – InformationWeek
- Malware authors expand use of domain generation algorithms – Computerworld
- Zeus/Spyeye variant uses peer to peer network model - Infosecurity.com
- Anonymous promises regularly scheduled Friday attacks – Wired
Changes to the Threat Landscape
In the last decade we have seen exponential growth in the number of Internet users worldwide. This expanding base provides a lucrative opportunity to criminal organizations to carry out illicit activities. Compared with earlier malware that primarily created nuisance attacks, today’s malware are much more focused on both their victims and goals. Today’s attacks are a major concern for enterprises and organizations. Not only do they risk the loss of intellectual property or data, but any disruption to business continuity can also severely hamper an organization’s productivity and reputation. Protecting networks with a wide variety of Internet-connected devices—desktops, laptops, smart phones, etc.—has become even more of a challenge.
Botnets are the most common form of malware used by cybercriminals to attack enterprises and government organizations worldwide. Botnets, networks of compromised “robot” machines (also known as zombies) under the control of a single botmaster, carry out malicious activities such as distributed denial of service (DDoS) attacks on servers, steal confidential information, install malicious code, and send spam emails. Recent examples are Operation Aurora, ShadyRAT, and DDoS attacks on payment websites in support of WikiLeaks.
Advanced persistent threats, on the other hand, focus on specific targets, such as government organizations, with motives ranging from espionage to disrupting a nation’s core networks, including nuclear, power, and financial infrastructure. Due to the discrete nature of the attacks, these can remain undetected for a long time. Such attacks are also much more complex and sophisticated compared with other malware. For example, Stuxnet targeted Iranian nuclear facilities and Flame targeted cyberespionage in Middle Eastern countries.
Challenges
Looking at the significance of intellectual property and national secrets as well as the vast potential of monetary rewards gained through these advanced attacks and threats, more and more cybercriminals—often well funded by criminal organizations—are attracted to develop malware. Their authors implement various techniques to make the malware and associated communication channels stealthier to avoid detection by security products on host systems and on the network. For example, encrypting communications between host and control server, using decentralized network architecture to stay undetected and resilient, using domain and IP flux techniques to hide control servers, and obfuscating malicious payloads are some of the techniques widely used by malware these days.
Traditional Detection and Its Limits
A signature-based detection mechanism that looks for unique network patterns has been the traditional method employed by security vendors to provide protection against attacks.
This method, though effective for defending against known threats, has limits.
- It is reactive: To provide coverage, researchers need to monitor and analyze network traffic, and reverse-engineer the attack to provide accurate detection coverage
- It is static: Malicious network patterns observed in previous attacks can change frequently, thus making the existing signatures ineffective to detect new variants of old threats
- It cannot react to unknown (such as zero-day) attacks
- The scope of detection is limited to a single network session and cannot correlate events across multiple network sessions
McAfee Labs
To win the battle and keep customers protected against emerging threats in the future, security vendors must continue to innovate.
Based on the current challenges to and limitations of signature-based detection, McAfee Labs envisions a dynamic solution that can provide proactive protection against future threats.
Such a solution must:
- Provide a behavioral-based detection framework in addition to the traditional approach
- Be capable of integrating various behaviors of the malware/threat lifecycle
- Have the ability to correlate attacks across multiple network sessions to precisely detect a specific type of threat
- Have the ability to do event-based correlation across multiple network sessions to detect unknown malware/threats
In subsequent blogs, we will talk more about the solution that McAfee Labs believes will be capable of combating malware and advanced persistent threats on our networks.
I would like to thank my colleagues Chong Xu and Ravi Balupari for their contributions to this blog.
By Swapnil Pathak
Subscribe to:
Posts (Atom)