Friday, December 18, 2020

Lessons from the Solarwinds Orion Cyber Attack

 On December 13, 2020, SolarWinds CEO Kevin B. Thompson notified customers of a highly sophisticated supply-chain attack affecting Orion Platform software builds from versions 2019.4 through 2020.2.1.



The details were still emerging, but the attack appeared to involve malicious code inserted into software updates distributed to SolarWinds customers. Approximately 18,000 organizations may have installed the affected versions. The incident came to light shortly after cybersecurity firm FireEye disclosed that it had experienced a breach involving the theft of internal security tools.

This was a sobering moment for the cybersecurity community. The scope of the compromise extended beyond private companies, potentially affecting Fortune 500 organizations and government agencies, including entities responsible for national cybersecurity.

Why this attack matters

Most security conversations focus on attacks that come from outside an organization - such as denial-of-service attacks or penetration attempts - or attacks that exploit people and systems from within, such as phishing, ransomware, or malware.

The SolarWinds incident exposed a different and especially concerning risk: the compromise of a trusted software-development and delivery process. By inserting malicious code into legitimate software updates, attackers were able to take advantage of the trust customers placed in a widely used vendor.

The incident underscores an important reality: every organization may have vulnerabilities within its software development lifecycle. Even well-established processes can be compromised if appropriate safeguards, reviews, and monitoring are not in place.

For years, organizations have invested heavily in perimeter protection, intrusion detection and prevention, endpoint security, and network monitoring. Those controls remain essential. But this attack demonstrated that the software development process itself must also be treated as a critical security boundary.

The long-term impact will likely include stronger tools, more rigorous standards, and updated regulations designed to improve software supply-chain security.

What can be done?

Improve communication and information sharing

Effective response depends on timely, useful communication among companies, government agencies, and security professionals. Privacy and data-protection laws remain important, but organizations also need practical ways to share threat intelligence quickly and responsibly.

In a cybersecurity incident, early access to relevant information can help organizations contain an attack before it spreads. Coordination across agencies and industries is especially important when responding to threats with broad public and economic consequences.

Strengthen quality control and code review

Although the full technical details were still under investigation, the incident made clear that malicious code had entered the SolarWinds software delivery process. That should prompt every organization to review how code is developed, approved, tested, built, and released.



Agile development and automation can improve speed and consistency, but they do not eliminate the need for strong controls. Organizations should consider:

  • Independent code reviews and approval processes
  • Automated integrity checks between releases
  • Monitoring for unexpected code changes or behaviors
  • Secure, isolated test environments
  • Comprehensive audit logs for development and release activities
  • Regular reviews of third-party and open-source dependencies

Automation can help identify meaningful differences between code versions and flag suspicious changes for human review. It should support - not replace - clear accountability and sound engineering judgment.

Act now

Organizations should assess their current exposure and avoid assuming that any process is inherently secure. Review systems across the business, from software development and vendor management to finance and operational workflows.

A mature cybersecurity program may identify risks before they become incidents, but no single team or tool can protect everything. Security must be a shared responsibility across IT, engineering, leadership, legal, operations, and other business functions.

Breaking down departmental silos and examining the software development lifecycle honestly - even its weaknesses - is essential. Technology and standards will continue to improve, but organizations also need disciplined processes, open communication, and collective accountability to reduce the likelihood and impact of future attacks.

Sunday, September 27, 2020

COVID and the Great Re-Negotiation Strategy

 

The Great Three Four?

There are moments in life that change us. They give us a new perspective and divide life into a clear before and after. I have lived through several of those moments, and I think of them as “The Great Three.”

The first was getting married. My spouse and I went on our first date in 1991, and my life has never been the same. She is my best friend, my biggest supporter, and a constant source of joy. Sharing life with her has been good for my soul.

The second was becoming a parent. I used to think of it as the birth of my first child, but each of my three children has changed my life in a different and important way. The line between life before children and life after children is unmistakable. I understood that parents love their children, but I did not fully understand the depth of that bond until my son was born.

The third was losing a parent. I lost my father 16 years ago this December. Not a day goes by that I do not think about him in some way. Losing a parent is painful, but it is also one of those moments that changes how you see life. I am grateful that I still have my mother and my in laws.

What about COVID-19?

So what does this have to do with COVID-19?

Until 2020, I had never seriously considered how much a global pandemic could change everyday life. I now think “The Great Three” has become “The Great Four.” COVID-19 changed all of us, and many things will never return to the way they were.

As an IT executive, I have planned for disasters of all kinds: fires, floods, storms, hurricanes, tornadoes, and earthquakes. A pandemic was always possible in theory, but it felt distant and hard to picture. We had historical examples, including the 1918 flu pandemic, and more recent events such as H1N1. But none of those prepared most of us for the scale of disruption COVID-19 brought.

Businesses had to adapt quickly. Employees began working from home. Schools moved online. Healthcare changed. Companies had to find new ways to serve customers and keep operating. At the same time, many families faced illness, loss, and uncertainty.

The human cost has been heartbreaking.

The need for more empathy in business

The pandemic also made me look differently at the contracts we have with vendors and suppliers.

For much of 2020, I was responsible for corporate facilities in addition to my regular IT leadership role. Before work from home and shelter in place orders, our company operated five main locations along with several smaller offices around the world.

Once offices closed, we were still paying for buildings we could not use. Like many companies, we asked landlords for some relief. They had their own bills and mortgage obligations, of course, but many were unwilling to discuss meaningful options. The response often came down to contract language, late fees, collections, or delayed payments that would eventually still be due.

That experience made one thing clear to me: business contracts often leave little room for empathy when circumstances change dramatically.

The pandemic clause

Over the years, I have reviewed many contracts. Most include language for disasters or acts of God, but few clearly address what happens during a pandemic that prevents a business from using the space, equipment, or services it is paying for.

That needs to change.

Future contracts, especially longer-term leases and equipment agreements, should include clear provisions for a pandemic or government mandated closure. These clauses could define what happens if a business is required to close or cannot use what it is paying for.

For example, a lease could provide temporary rent relief if a shelter in place order prevents employees from occupying the space. An equipment contract could reduce payments if copiers, printers, or other office equipment cannot be used because no one is allowed in the office.

This is not about avoiding obligations because a company chooses to work from home. It is about fairness when a business is required to close through no fault of its own.

A landlord should not be expected to carry the entire burden, and neither should a tenant. The point is to agree in advance on a reasonable way to share the impact of an extraordinary event.

Hindsight is always clear. Still, COVID-19 has taught us to plan for risks that once felt unlikely. Hopefully, we will not see another pandemic of this scale for many years. But if we do, better contracts and more thoughtful business relationships can help everyone weather it with a little more fairness and empathy.

Friday, June 19, 2020

The Human Side of Technology - People Come First

 

People Come Before the Job

We are living through strange and difficult times. Our county has been under a shelter in place order for months. Some restrictions are beginning to ease, and we have been fortunate that our local healthcare system has been able to manage the case numbers so far.

Still, there is another cost that is becoming harder to ignore. It is not just about the health of our networks, systems, or businesses. It is about the health of the people doing the work, including their mental health and overall well-being.

A lesson I learned early

From 1999 to 2002, I worked for a technology startup called eHealthInsurance. At the time, it was everything I wanted in a job: a fresh approach to health insurance, an energetic leadership team, and a company that seemed excited to have me. I was young, motivated, and eager to contribute.

In 2001, my wife and I were expecting a baby. I spoke with my manager about transferring from the Bay Area to the Sacramento area, where we planned to raise our family. The move was approved.

We sold our home in San Jose, moved in with my in laws temporarily, and bought a home in Roseville. The plan was for me to stay in San Jose until our daughter was born in 2002.

Then life changed quickly.

The September 11 attacks happened. As a former firefighter and EMT, I felt the loss deeply. Soon after, the dot com bubble burst and the economy entered a downturn.

Early in 2002, the vice president of engineering learned about my move and revoked the approval for my transfer. This happened only two months before my daughter was due. We had already sold our house, were living with my in-laws, and were preparing to move into our new home.

It was a shock. We had made major decisions based on an agreement that was suddenly gone.

The meeting that changed my view of leadership

I spent the next several weeks trying to keep the conversation open and find a solution. The company already had a telecommuting policy for employees who lived more than 50 miles from the office. I hoped that some flexibility would be possible.

At our final meeting, I was told that my position would not transfer to Folsom. I would be required to work in Sunnyvale five days a week. Even if I moved to the Roseville area, roughly 120 miles away, I would not be allowed to work from home or from the Folsom office.

I was disappointed, but I also knew the decision had been made. After months of trying to do the right thing and communicate openly, I resigned.

That experience stayed with me.

My point is not to dwell on an old job. It is to highlight a lesson about management. As leaders, we have a responsibility to care about our employees as people, not simply as resources.

That leader saw the situation only as a business problem. There was no room for my family, the difficult economy, the baby we were expecting, or the fact that my manager had approved the move months earlier.

Understanding what people need now

Today, I am a vice president of IT. I manage people, carry responsibilities, and report to leaders above me. But none of that removes my responsibility to lead with compassion and empathy.

Recently, an employee came to me to talk about how the pandemic had affected their mental well-being. They were feeling isolated and struggling with the uncertainty of life during COVID-19.

I listened. I told them they were not alone.

Many of us have felt the strain. The boundaries between work and home have blurred. Workdays stretch into long hours while families share the same space all day. It can feel like we are caught somewhere between a permanent vacation and a constant workday.

Some days, it is hard to find motivation. Some days, it is hard to focus. That does not mean people are failing. It means they are human.

The specifics of what the employee needed were less important than making space for the conversation. They needed to be heard, and I needed to respond with understanding and flexibility.

Their health and well-being mattered more than the immediate task in front of them.

The kind of leader I want to be

After that conversation, I realized something important. I had become the leader I needed when I was in that difficult situation in 2002.

Over my career in IT, I have tried to learn from the best managers I have worked for. I have also learned from the ones who showed me what not to do. My goal has always been to combine those lessons with my passion for technology and become the best leader I can be.

This experience reminded me that leadership is not just about projects, budgets, systems, or results. It is about people.

COVID-19, shelter in place orders, social unrest, and economic uncertainty have taken a real toll on many people. Work life and personal life have blended together in ways few of us expected. Focus can become difficult. Isolation can become overwhelming.

As managers and supervisors, we need to make room for compassion. We need to listen. We need to remember that every employee has a life outside of work, with challenges we may not always see.

Business matters. Results matter. But the people doing the work matter more.

That is how I want to lead, every day.

Monday, April 20, 2020

Supply Chain and Infrastructure Limits

 

It often starts with congestion: a cough, a blockage, or a restriction in a pathway we depend on to function. I am not talking about COVID-19 in the human body. I am talking about the effect the pandemic had on the systems that keep our communities and businesses running.

In many ways, the same idea applied. As demand increased and normal patterns changed, supply chains and network infrastructure became congested. Things we had always assumed would be available suddenly were not.

The early warning signs

In January 2020, the CDC issued a travel alert related to Wuhan, China. At that point, the United States had only a small number of known cases. By the end of January, the U.S. government had begun issuing travel restrictions related to China.

In February, I moved my home internet service from Comcast Business to Xfinity Residential. At the time, it seemed like a practical decision. The service offered more bandwidth at a lower cost, and it worked well for my family. 

Then, in early March, as head of IT and the Facilities, I needed to purchase hand sanitizer and disinfecting wipes for the office - to replenish our stock. I searched through Amazon and other suppliers, only to find that delivery dates were more than 30 days away. Soon, sanitizer, wipes, and toilet paper became difficult to find almost everywhere.

These were ordinary items we had always taken for granted. We still had some supplies, but not in the quantities we wanted. For me, that was the first real warning sign that the supply chain was under strain. It was the first time in many years that a common item had simply disappeared from online retailers and local stores.

A sudden shift to working from home

By mid March, an incident at our San Jose office required us to begin working from home before the Bay Area issued its shelter in place order. Soon after, California followed with statewide restrictions.

My children were also sent home from school. Two attended Leland High School, and one attended De Anza College. Beginning March 16, 2020, they joined millions of other students across the Bay Area in trying to learn and connect from home.

At the same time, Silicon Valley and much of the region moved to remote work. We did not immediately realize how much pressure this would place on our network infrastructure.

Millions of people were suddenly working from home, attending online classes, streaming video, and trying to stay connected. Children who could no longer see friends in person turned to Netflix, YouTube, Hulu, gaming, and social media. Adults relied on Zoom, GoToMeeting, Webex, and other platforms to keep their jobs moving.

All of it created a massive and unplanned stress test for the internet.

When home internet became a business problem

My move to residential internet had seemed like a good decision in February. But once nearly every household in the area was relying on home connections throughout the day, the service became slow and unreliable.

I had to rethink the setup quickly.

I brought Xfinity Business back into the house because I could no longer depend on a connection that slowed down during the middle of the workday. The contract was not perfect, but it gave me a dedicated 100 Mbps connection, an LTE backup modem, and battery backup for about $120 per month during the first year. The installation and configuration took about two weeks.

In the meantime, my wife and I relied on mobile hotspots to keep working. Sometimes they worked well. Other times, they did not.

The experience made it clear how dependent we had become on systems that were never designed for everyone to rely on them at once.

The growth and growing pains of video meetings

As people adjusted to working and learning from home, platforms such as Zoom became essential. They gave families, schools, and businesses a way to stay connected when in person meetings were not possible.

But the rapid growth also exposed weaknesses. Zoom had been designed for ease of use, and some meetings lacked basic security settings. This made it easier for disruptive people to enter public meetings, sometimes sharing offensive sounds or graphic images.

The platform improved over time, adding stronger security options and better guidance for meeting hosts. Still, the early days were a reminder that rapid growth can reveal gaps in security, capacity, and planning.

Planning for the next disruption

Things are more stable now. Zoom is more secure, and my home internet is generally reliable, even though outages still happen from time to time.

The larger lesson is that we need to look more closely at the capacity of the systems we depend on. Businesses, service providers, schools, and governments all have a responsibility to consider what happens when demand reaches unexpected levels.

Few people imagined that tens of millions of students would need to learn online at the same time, often through video calls. Few expected entire workforces to depend on home internet connections overnight. Yet that is exactly what happened.

One positive outcome of 2020 was that it forced us to rethink what is acceptable and what we need to build for the future. We may not know exactly when a crisis will end, but we can prepare better for what comes next.

That means protecting our supply chains, strengthening our infrastructure, and planning for capacity before we need it.

Wednesday, April 8, 2020

Cloud Strategies and Authentication Methodologies

 

Making the Cloud Work for IT

Like most forward thinking IT teams, we are always looking for better ways to connect people with the data, tools, and services they need.

“Do more with less” is a phrase no IT leader loves to hear, but it is a reality in many organizations. After more than 25 years working in startups, I have learned that efficiency is not simply about reducing headcount or spending less. It is about using automation to handle repetitive work while protecting the reliability, security, and integrity of the systems the business depends on.

Moving toward the cloud

Many organizations have adopted cloud services for systems that once had to be managed on site. Ten years ago, I was hesitant about that idea.

Why hand over control of a system to someone else? Hosting a service internally meant control over the hardware, software, configuration, management, and customization. Giving that up felt risky.

My first real experience with cloud services was hosted Exchange, before Office 365 became widely available. As a systems administrator, the idea of no longer managing an email platform myself was uncomfortable at first. I worried that my skills would become less relevant.

Instead, it gave me room to focus on more important work.

Exchange is a complex system to operate well. By using a hosted service, I no longer had to spend as much time on day to day maintenance, disaster recovery planning, and troubleshooting every technical issue. When a problem occurred, the provider became the first level of support.

That freed me and my team to focus more on the company’s needs, rather than spending all of our time maintaining the underlying tools.

The value of cloud services

Today, cloud strategy is common across many organizations. Cloud services can take critical systems that might otherwise require several administrators and make them easier to manage at scale.

For example, our Exchange environment supports roughly 375 active email accounts and uses more than 3.3 TB of storage. It serves a global community of sales, services, and support employees, with availability close to 99.99 percent.

Running that same environment on site would require substantial hardware, dedicated storage, replication to a secondary location, backup and recovery systems, and likely one or more full time administrators.

Cloud services do not eliminate responsibility, but they can reduce the operational burden and allow IT teams to focus their time where it matters most.

Too many passwords

The move to cloud services also creates a challenge. Each platform often comes with its own login, password, and user management process.

As companies adopt more applications, this quickly becomes difficult for employees and IT teams alike. People have more passwords to remember. New hires need accounts in multiple systems. When someone leaves, IT needs to make sure access is removed everywhere.

Single sign on platforms such as Okta and OneLogin help solve this problem. They allow companies to use one identity system across multiple services, including Atlassian, Microsoft 365, Salesforce, NetSuite, Dynamics 365, and many others.

At Virtana, we use Okta to support authentication, multi factor authentication, and automated user provisioning and deprovisioning. This reduces the likelihood of manual errors and makes it easier to manage access consistently.

We have deployed this approach across more than 20 services used by the company. When we evaluate a new platform, such as SurveyMonkey or Monday.com, one of our first questions is whether it supports SAML and can integrate with our single sign on environment.

The goal is simple: make access easier for employees while keeping company systems secure.

Monitoring the cloud

As cloud environments grow, visibility becomes just as important as access management.

Virtana’s acquisition of Metricly added cloud monitoring capabilities for services such as AWS. The platform became part of our broader CloudWisdom offering and helps organizations understand how their cloud infrastructure is performing.

One of the most valuable capabilities is cost optimization. It is one thing to know that AWS cost $50,000 in a given month. It is much more useful to understand what drove that cost and where changes could reduce spending without affecting performance.

Those savings can be reinvested in innovation, infrastructure, or people.

Cloud services are not a replacement for thoughtful IT leadership. They are a way to spend less time maintaining routine systems and more time helping the business move forward.

Today, the world feels a little quieter, a little dimmer.

We knew this day would come, but we held onto the hope that there would be more time. John Michael "Ozzy" Osbourne—our beloved Pri...