Saturday, May 26, 2018

Data Breach to GDPR


This the most basic breach that can be discussed and prevented up to great extent by simple measures like 80-20 rule so if you address 20% of prevention religiously you could stop 80% of these leaks.
Let’s define data breach, "A data breach is a security incident in which sensitive, protected or confidential data is copied, transmitted, viewed, stolen or used by an individual unauthorized to do so." Data breaches may involve financial information such as credit card or bank details, personal health information (PHI), Personally identifiable information (PII), trade secrets of corporations or intellectual property. Most data breaches involve overexposed and vulnerable unstructured data – files, documents, and sensitive information, it is the intentional or unintentional release of secure or private/confidential information to an untrusted environment. Other terms for this phenomenon include unintentional information disclosure, data leak and also data spill (source Wikipedia).
There are various Data Protection Regulation has been implanted worldwide but I personally believe the overall ignorance of users feeds the 99% of these Data Breach overall, so this is my humble effort to address such shortfalls.
Let’s consider simple data breach by an employee by wrong attachment, dissemination of wrong information by mistake can lead to major issue for the individual or cooperates. This can be prevented by checking the email before sending them. We could just queue the emails while composing and send them later to prevent any such nightmares.
Then there are
Then there are Malwares, a short for malicious software programs which is any software intentionally designed to cause damage to a computer, server or computer network. Malware does the damage after it is implanted or introduced in some way into a target's computer and can take the form of executable code, scripts, active content, and other software.
Now even, File-less malware is a huge security challenge for organizations today, and traditional email security controls aren't sufficient to meet the challenge.
Believe me, it’s really easy to do 100 variants of the same [malicious] document even if we are using the same code, the same document, but you're putting 100 different random characters that aren't even visible in the document. It's super easy to create these, and if you're relying on signatures, you're going to have to wait for every one of the 100 to catch a signature. the points to consider here are

  •     How malicious attachments are infecting organizations;
  •     Why traditional defenses fail to detect these payloads;
  •     How to respond when infections do penetrate defenses.

Information management is critically important to all of us as employees, business and consumers. For that reason, various institutions has been tracking security breaches, looking for patterns, new trends and any information that may better help us to educate consumers and businesses on the need for understanding the value of protecting personal identifying information and business critical data.
To understand various data loss methods consider following points

  1. Insider Theft
  2. Unauthorized Access
  3. Hacking / Computer Intrusion (includes Phishing, Ransomware/Malware and Skimming)
  4. Data on the Move 
  5. Physical Theft 
  6. Employee Error / Negligence / Improper Disposal / Lost 
  7. Accidental Web/Internet Exposure  
  8. Stalking on social network

Let’s take a breath and understand how we could reduce these seven risks factors.
Insider theft is the act of stealing information stored on computers, servers, or other devices from an unknowing victim with the intent to compromise privacy or obtain confidential information. Data theft is a growing problem for individual computer users as well as large corporations and organizations.

Prevention for data breach are

  1. Train yourself, employees, customers
  2. Segregate & Secure sensitive information.
  3. Build strong security policies
  4. Periodically & Properly dispose of sensitive data.
  5. Protect against malware
  6. Control physical access to your business computers
  7. Encrypt data communication
  8. Build & plan  incident response teams
  9. Review / update all account sittings once a week


1. Train your employees.
 According to the various reports, employees are the top cause of data breaches in small and mid-size businesses, accounting for 48 percent of all incidents. It’s usually due to an innocent mistake; employees often lack basic awareness of data security and how hackers work. Employee education is one of the most important things you can do to lower the potential of data theft.

Offer mandatory awareness training on the security risks employees face every day. Social engineering is a growing threat for small businesses whereby hackers pose as a trusted source in need of confidential data. Through phishing, employees are invited to click on a link that installs a virus on their computer without their knowledge. Ransomware will hold a computer hostage until the required ransom is paid.

To prevent employees from falling into these traps, advise them to:

  •     Confirm the legitimacy of the source before giving out confidential information
  •     Never open attachments from people they don’t know
  •     Avoid suspicious links in emails, websites and online ads


2. Secure sensitive information.
 Sensitive data is the valued commodity that criminals seek to exploit for profit. It includes personally identifiable information (PII) for employees, customers and patients as well as business trade secrets, financial data and other company-confidential information. In the wrong hands, this information can damage your business, customers and reputation.

Limit access to online files based on an employee’s need to know. Store paper files and removable storage devices containing sensitive information in a locked drawer, cabinet, safe or other secure container when not in use.

3. Properly dispose of sensitive data.
Be equally vigilant when disposing of sensitive data. Shred documents containing confidential information prior to recycling. Remove all data from electronic devices—whether computers, tablets, smartphones or storage hardware—before disposing of them.

4. Use strong password protection.
Passwords are under constant attack and hackers use a number of different means to crack their code. To deter their efforts, password-protect your business computers, laptops and smartphones as well as access to your network and accounts. Require employees to change default passwords and set a strong, complex password with a variety of characters that must be changed at least quarterly.

5. Protect against malware.
Malware refers to “malicious” software, such as viruses and spyware, that is installed on a computer with the intent to access sensitive information or cause damage. Malware can be installed when an unsuspecting employee uses a malware-laden USB device or clicks on an infected link in an email or on a website.

To prevent a malware attack, install and use antivirus and anti-spyware software on all company devices and be sure your employees are on the lookout for suspicious links.

6. Control physical access to your business computers. 
Create user accounts for each employee to prevent unauthorized users from gaining access to your business computers. Laptops can be stolen easily; make sure they’re locked in place when unattended. Also limit network access on computers located in or around public spaces, such as the reception area.

7. Encrypt data.
Encryption encodes information, whether it is stored on a device, in the cloud or being transmitted over the Internet, and only the person or computer with the proper key can decode it. Encryption is highly recommended for all devices containing sensitive information, including laptops, mobile devices, USB drives, backup drives and email.

Most operating systems and many software applications have a built-in encryption option which you simply need to activate (instructions vary). You may also purchase encryption programs tailored to the needs of your business—whether for an entire drive or one or more files or folders. Secure Sockets Layer (SSL) certificates are the standard way for businesses to encrypt sensitive information, such as those containing credit card details, before it is transmitted over the Internet.

8. Keep your software and operating systems up to date.
Malware continuously evolves and software vendors continuously update or “patch” their programs in order to address new security vulnerabilities. For this reason, it’s vital to install updates to security, web browser, operating system and antivirus software as soon as they are released. They’re your first line of defense against online threats.

9. Secure access to your network. 
To prevent outsiders from gaining access to private information on your network, enable your operating system’s firewall or purchase reputable firewall software. Configure a Virtual Private Network (VPN) to provide workers with a secure means of accessing your network while working remotely. If you have a Wi-Fi network for your workplace, make sure it is secure and encrypted, and that your SSID (service set identifier) is hidden so that it can’t be picked up by the public. Also require a password for access.

10. Verify the security controls of third parties. 
Most businesses rely on third-party vendors for some aspect of their operation, whether for payroll, credit card processing or to manage their security functions. But there are security risks in doing so. If a breach occurs on the vendor’s watch, your data may be compromised and you could still be held responsible for the loss.

Before engaging the services of a third-party vendor, evaluate their security standards and best practices to ensure they meet your minimum requirements. Look for vendors that:
  • Have strong security policies and procedures
  • Regularly backup their data on a hard drive as well as the cloud
  • Perform routine internal security audits
  • Run background checks on employees with access to your data
  • Require employees to complete data security training
  • Keep up-to-date with the latest security patches and security software

    Have a comprehensive incident response plan for responding to and managing the effects of a security attack

Once you’ve vetted and selected a third-party service provider, put a service level agreement (SLA) in place that details your security expectations and give you the right to audit the vendor to confirm compliance with your policies.

Let me also include my take on General Data Protection Regulation (GDPR) universal guidelines (these address almost 80-87% of breaches by guiding users on what is critical )
                                                                                                                                                                                
Individuals have the right to:
  • Access their personal data
  • Correct errors in their personal data
  • Erase their personal data
  • Object to processing of their personal data
  •  Export personal data
Online portals, companies will need to:
  • Protect personal data using appropriate security
  • Notify authorities of personal data breaches
  • Obtain appropriate consents for processing data
  • Keep records detailing data processing
  • Provide clear notice of data collection
  • Outline processing purposes and use cases
  • Define data retention and deletion policies
  • Train privacy personnel and employees
  • Audit and update data policies periodically
  • Employ a Data Protection Officer who can address grievances or queries
  • Create, publish and manage compliant & non-compliant vendor contracts
Me and my group (India Training Services, ITS) already adopted GDPR guidelines and a big supporter from long time, now its enforced by law I would also recommend India government to completely support this great move.
Enhance your capabilities to support the privacy rights of individuals with tools and documents that help you respond to data subject requests (DSRs) and personal data breaches, as well as the information you need to create your own data protection impact assessments (DPIAs) , We at ITS can help you in this as we are committed to protect all user & companies rights for privacy. Feel free to contact me at rrpande@indiatrainingservices.in

Saturday, February 24, 2018

Best Home Computer


Looking for a computer at home with least payout choose Raspberry PI3. A computer for kids, home & normal day to day  work including documentation. You can use this with your LCD/LED TV with best Full HD resolution True 4K with wireless connection  read this. Need help reach me at ravindrapande@gmail.com


Creating amazing projects is easy with a Raspberry Pi, but first you need to plug it in and set up Raspbian, the default operating system.

This guide will get you up and running in no time.

The Raspberry Pi is a wonderful microcomputer that brims with potential. With a Raspberry Pi you can build robots, learn to code, and create all kinds of weird and wonderful projects.

Hackers and enthusiasts have turned Raspberry Pi boards into fully automated weather stations, internet-connected beehives, motorised skateboards, and much more. The only limit is your imagination.

But first, you need to start at the beginning. Upon picking up your Raspberry Pi for the first time, you’re faced with a small green board of chips and sockets and may have no idea what to do with it. Before you can start building the project of your dreams, you’ll need to get the basics sorted: keyboard, mouse, display, and operating system.

Creating projects with a Raspberry Pi is fun once you’ve mastered the basics. So in this guide, we’re going to take you from newbie zero to Raspberry Pi hero. Grab your Raspberry Pi and let’s get started.

Get to know the Raspberry Pi 3
The Raspberry Pi 3 is the latest model, and the version with the most features. It’s the fastest board, and has the most connections (four USB sockets, Ethernet and wireless networking, and so on).

Featuring the latest 1.2GHz quad-core ARM CPU (central processing unit), the Raspberry Pi 3 is faster than many smartphones, and powerful enough to be used as a desktop computer.

What you need to set up a Raspberry Pi 3 or Pi Zero W
You don’t require much to get your Raspberry Pi started (no matter which model you have): a smartphone charger, a recycled HDMI cable, and a keyboard and mouse are all you need.

Most items can be sourced from computer hardware around the house, or begged and borrowed from friends and family. If you’re looking for the ultimate in low‑cost computing; the Raspberry Pi is it.

You should be able to source, salvage, and scavenge most equipment you need to get a Raspberry Pi up and running. To get the most out of your Raspberry Pi in the long term, though, you should use high-quality components.

Any equipment you can’t recycle can be picked up from the Raspberry Pi Shop or from distributors like Element14, Allied Electronics, and RS Components.

Power your Raspberry Pi
The Raspberry Pi is powered using a micro USB cable, the same type used by many smartphones. You can also buy an official power supply, which supplies a regular amount of power.

Not all USB power adapters are born equal. A reliable branded adapter will provide a steady stream of power, even when you attach multiple devices to the Pi.

A good 2 A or 2.5 A power supply provides you with enough power to run your Pi Zero. Many people use an Android or iPhone adaptor and micro USB cable. Or you can buy an official Universal Power Supply.

A micro SD Card and the Raspbian operating System
The operating system, ‘Raspbian’, is loaded onto a microSD card and plugged into the Raspberry Pi. The official SD Card is pre-loaded with software called NOOBS (New Out Of Box Software) which helps you install Raspbian. You can also download the NOOBS software and copy it to an old SD Card and use it to run your Raspberry Pi.

Use a HDMI monitor
An HDMI socket enables you to connect the Raspberry Pi to a monitor or a modern television set.

An HDMI cable is the easiest way to connect your Raspberry Pi to a computer monitor or television. You don’t need an expensive one, and most people recycle one from an old games console or DVD player.

To keep the size down, the Pi Zero features a smaller-than-normal mini HDMI socket. You’ll almost certainly need a mini HDMI-to-HDMI adapter or cable to connect the Raspberry Pi to a television or monitor. Most Pi Zero W devices are sold with the mini HDMI-to-HDMI adaptor.

Attach a keyboard and mouse

A keyboard and mouse are connected via standard USB sockets. An Ethernet cable can be plugged directly into a router to provide network access (or you can connect to a wireless network).

What keyboard to use
Any standard USB keyboard can be used to enter commands to your Raspberry Pi. You can use a Bluetooth keyboard with the Raspberry Pi 3, or any other Pi with a Bluetooth dongle attached. A wired keyboard is easier to use when setting up your Raspberry Pi.

I prefer wireless mouse & keyboard so that I can have 55" full HD ultra tru  colours screen operating from with 10 mtrs distance.

Attach a mouse to your Raspberry Pi
Any standard mouse will work with the Raspberry Pi, although ones with two buttons (non-Apple mice) work better. If your wired keyboard lacks a USB socket, then you’ll need a USB hub to connect a mouse and keyboard. A Bluetooth mouse will work once it’s paired.

Insert the micro SD card and power up
On the underside of the Raspberry Pi 3 board is the SD card slot. If you have an official micro SD card it will boot into NOOBS. Follow the on screen instructions to install Raspbian, the official operating system.

If you’re using your own micro SD card you need to download NOOBS from the Raspberry Pi website, format the SD card, and copy the files across. This preloads the operating system onto a micro SD card, and you then use it to boot up the Raspberry Pi.

Sounds complex? Don’t worry, this guide to installing NOOBS has everything you need to know.

The micro SD card in your kit acts as the hard drive for your Raspberry Pi. You install the Raspbian operating system onto the card, then all your documents, files, and projects are saved to it as you work.

If you want to use a larger card, and are wondering which brand and type to get, take a look at the results from benchmark tests done by Raspberry Pi fan Jeff Geerling. Some cards run up to four times as fast as others.

Connect to a wireless network
Raspbian boots into a familiar GUI-style display (like you’ll see on Windows and macOS).

The Pi 3 and Pi Zero W both feature built-in wireless LAN and Bluetooth. This enables you to connect to a wireless router and get online without using a WiFi dongle (which was required on older Raspberry Pi).

Click on the wireless networking icon in the top right of the screen and choose your wireless network. Enter the wireless password and you’ll now be online. You’re now ready to start using your Raspberry Pi to learn computing and create amazing projects

I hope this guide has helped you get started with the Raspberry Pi. Enjoy your new single board computer (SBC). Now get thinking about all the great projects you can make with it.

GET STARTED WITH YOUR NEW RASPBERRY PI
reating amazing projects is easy with a Raspberry Pi, but first you need to plug it in and set up Raspbian, the default operating system.

This guide will get you up and running in no time.

The Raspberry Pi is a wonderful microcomputer that brims with potential. With a Raspberry Pi you can build robots, learn to code, and create all kinds of weird and wonderful projects.

Hackers and enthusiasts have turned Raspberry Pi boards into fully automated weather stations, internet-connected beehives, motorised skateboards, and much more. The only limit is your imagination.

But first, you need to start at the beginning. Upon picking up your Raspberry Pi for the first time, you’re faced with a small green board of chips and sockets and may have no idea what to do with it. Before you can start building the project of your dreams, you’ll need to get the basics sorted: keyboard, mouse, display, and operating system.

Creating projects with a Raspberry Pi is fun once you’ve mastered the basics. So in this guide, we’re going to take you from newbie zero to Raspberry Pi hero. Grab your Raspberry Pi and let’s get started.

Saturday, February 3, 2018

IoT Updates22018

Internet of Things (IoT) is an ecosystem of connected physical objects that are accessible through the internet. The ‘thing’ in IoT could be a person with a heart monitor or an automobile with built-in-sensors, i.e. objects that have been assigned an IP address and have the ability to collect and transfer data over a network without manual assistance or intervention. The embedded technology in the objects helps them to interact with internal states or the external environment, which in turn affects the decisions taken.
Internet of Things can connect devices embedded in various systems to the internet. When devices/objects can represent themselves digitally, they can be controlled from anywhere. The connectivity then helps us capture more data from more places, ensuring more ways of increasing efficiency and improving safety and IoT security.
IoT is a transformational force that can help companies improve performance through IoT analytics and IoT Security to deliver better results. Businesses in the utilities, oil & gas, insurance, manufacturing, transportation, infrastructure and retail sectors can reap the benefits of IoT by making more informed decisions, aided by the torrent of interactional and transactional data at their disposal.
IoT improving at phenominal rate in industry as the IT leaders helping various big non-IT setups to improve the effciencies & tracking with IoT implimentations.
IBM will be working to turn the Port of Rotterdam—Europe's largest shipping port—into the model smart shipping port of the future, the port announced Wednesday.
In the long-term effort, the port will use Internet of Things (IoT) sensors, artificial intelligence (AI), and big data to become more efficient and cost-effective, the press release said. The project may show how emerging technologies can be used to alter workplaces and industries, and its success may drive other ports to do the same.
The IoT sensors are a key feature of the smart port, as they will measure weather, water, and communications data. The data will provide insights into the port's activities, and may be able to help employees reduce wait times and select the best entry and exit times for the cargo ships.
The data, along with real-time information from ship captains and other officials, will be available in a dashboard, granting all parties the necessary information to fully use the port, according to the release.
The efforts are part of preparing the port for connected and autonomous cargo transportation, the release said. Aside from prepping for the shipping of the future, the sensors and data may provide a better understanding of the port, leading to more cost-effective procedures and efficiency in shipping.
Shipping companies and the port could save up to $80,000 an hour with the fully implemented changes, the release said.
Additional tech will be used in the port's greater digital transformation strategy, including sensor-equipped buoys to determine the best time for ships to dock and 3D metal printing to create ship parts.
here are other ventures to digitize and connect the shipping industry. In March, IBM and Maersk announced a partnership to speed up the shipping industry through blockchain technology.
Other technologies have been used to push other segments of the shipping industry towards greater digital transformation. Tesla's autonomous semi-truck could aid the trucking sector, with Uber Freight on-demand trucking service offering similar impacts.
Let’s understand great dream projectcts like Self Driving cars, not every self-driving car has to be able to move passengers from point A to point B. Take, for example, Nuro: The startup just revealed their unique autonomous vehicle platform, which is more of a mobile small logistics platform than a self-driving car.
The company, which has been working away in stealth mode in Mountain View until now, has raised a $92 million Series A round led by Banyan Capital and Greylock Partners to help make its unique vision of autonomous transport take shape.
Nuro’s vehicle is a small, narrow box on wheels, which is about half the width of a regular car, and which is designed to be a lightweight way to get goods from a local business to a customer, or from one person to another within a neighborhood or city. The platform is just one example of what Nuro wants to do, however; the startup bills itself as a product company focused on bringing “the benefits of robotics” to everyday use and ordinary people.
Nuro’s AV also operates completely autonomously, and looks like something you’d see on a Moon base in a retro-futuristic sci-fi show. There’s a pin pad for user interaction, so that only the right customer can access the contents stored within, and a top-mounted sensor array that includes LiDAR, optical cameras and radar (other sensors are located around the vehicle to enable its autonomous driving).
The young startup’s goal is to partner with businesses to set up transportation services. You can easily imagine this slotting in nicely to something like Uber Eats, and bringing food from the local lunch spot to offices around where people are hungry but can’t make the trip out to their usual places in person. Or, these could support Amazon’s last mile needs for in-city delivery, for example. Nuro isn’t yet talking about specific partnerships, however.
This fit-for-purpose vehicle and dedicated focus could help Nuro accomplish some of the vision that Ford has for its AV program, for instance, with potentially fewer barriers to deployment in limited markets and specifically bounded environments. It’s still early days for the startup, however, and it’s also competing in some ways with more established young companies like Starship Robotics. Still, it’s a neat first product and an interesting vision.
With $18 million in funding from Defy Ventures, Khosla Ventures, Menlo Ventures, Sherpa Capital and others, Owl has launched its always-connected, LTE security camera for your car. Co-founded by Andy Hodge, a former product lead at Apple and executive at Dropcam, and Microsoft HoloLens development lead Nathan Ackerman, Owl is designed to give drivers peace of mind with an always-on dashboard camera for their cars.
There’s a bunch of people mucking around in the home already,” Hodge told TechCrunch. “It’s not the place to do something really dramatic and amazing because you’d mostly be doing what they’re doing but better. With the car, there’s nobody doing anything.”
The two-way camera plugs into your car’s on-board diagnostics port (Every car built after 1996 has one), and takes just a few minutes to set up. Once it’s hooked up, you can access your car’s camera anytime via the Owl mobile app.
Owl is always on, which means it’s able to capture car crashes, break-ins and people dinging your car in the parking lot. If Owl detects a car accident, it automatically saves the video to your phone, including the 10 seconds before and after the accident.
To conclude summerise this thoughts lets dwell on the IoT & applications / implimentations again, IoT platforms can help organizations reduce cost through improved process efficiency, asset utilization and productivity. With improved tracking of devices/objects using sensors and connectivity, they can benefit from real-time insights and analytics, which would help them make smarter decisions. The growth and convergence of data, processes and things on the internet would make such connections more relevant and important, creating more opportunities for people, businesses and industries. Feel free to contact me at ravindrapande@gmail.com for any further assistance or details required. We are developing many IoT based products like Smart Swithches for Indian markets to get the Indian end customer benifit for IoT locally than just keep dicussing on topics.

Thursday, January 11, 2018

IoT Market Maturity 2018



The IoT market matured considerably in 2017. In this thought, we take a look at how the industry will continue to grow up in 2018. And yes maturity is also a major aspect of growth here,, with cyber security concerns as well. This is my first blog in 2018. Love to know your thoughts / feedback at ravindrapande@gmail.com

2015 was a year of education & Medical instruments for IoT, where the enterprise sector learned what the technology could offer to their organization on a theoretical basis. In 2016, most companies began to get a sense of the tangible benefits the technology could provide them. This year was the year IoT scaled — often extending beyond the awareness of many workers. But what will 2018 hold for the technology? Next year, expect IoT technology to become both more common, but less obvious. The number of connected devices, as well as IoT-driven projects, will continue to expand, but the technology itself will begin to become something like electricity — technology professionals rely on for their own operations and service offerings, but don’t necessarily think about. Instead, expect buzzwords like “digital transformation” and “digitalization” that include IoT as a component to gain ground — driven by vendors and analysts, along with industry-specific terminology such as “smart manufacturing” and “precision agriculture.”

To get a sense of additional trends on the horizon, we reached out to several professionals and came up with a dozen points. The thought process has touched on a variety of trends, ranging from the likely consolidation of the IoT platform market to the rise of IoT-enabled services.
Reach increase:  IoT markets will consolidate and grow more integrated, in 2017, the number of IoT platforms surged to more than 450. According to MachNation, IoT platform revenue increased 116 percent in 2017. It is likely, however, in the coming year, some of the smaller IoT platforms will begin to fall away or merge with rival platforms. This trend will likely be similar to the search engine market in the 1990s. The market doesn’t need hundreds of specialized platforms that are nevertheless similar in function.
It is doubtful the IoT platform market will consolidate to anywhere close to the extent of the search engine market given the wide variation of IoT deployments across a diverse set of industries, ranging from aviation to healthcare. It is probable that, in 2018, the number of IoT platforms could begin a steady slide southward, perhaps shrinking from 450 down to around 100 or so, said Nitesh Arora, marketing leader at Cloudleaf.

Successful platforms will tend to be generic for IoT deployments from large tech vendors that support custom deployments. There also will be a vital role for specialized IoT platform vendors targeting niche industries. But many industrial companies are looking for a single IoT platform they can use for asset tracking and management. Fragmented IoT platforms will thus fall by the wayside.

Dave McCarthy, director of products at Bsquare, forecasts a move away from platforms to IoT driven applications. “Businesses will continue to create use-case based applications that solve specific business problems to maximize IoT outcomes,” McCarthy said. Consolidation and continued integration will also be prevalent in the consumer realm in 2018, as the public begins to deploy a growing number of connected devices, yet grows weary of having to install specific apps for each new device they purchase. There is already evidence of this trend as two companies — Amazon and Google — have emerged as leaders of the smart home market, prompting the majority of smart home companies to integrate with those companies’ respective voice assistant platforms.

Smart home companies unable to create recurring revenue models will fail, said Patrick Maloney, the CEO of Inspire. Despite substantial advances in the smart home space, the market will likely consolidate, given the crowded marketplace and lack of differentiation of smart home products. These factors make it difficult to maintain long-term growth, Maloney said. “The revenue models for most smart home products and devices are transactional, one-time purchases,” he said. “Unless you are Amazon or Google, creating predictable and capital-efficient revenue streams is not likely.”
[IoT World demonstrates how the next generation of IoT will converge to unlock the intelligence of things in the industrial, enterprise and consumer realms. Get your ticket now.]

The top four smart home companies — Amazon, Apple, Google and Samsung — have all built an ecosystem of smart products, but they have all created selectively open ecosystems. “The resulting walled gardens often leaving consumers frustrated when they need to use three different apps to get products to communicate, or stop communicating,” said Patrick Maloney, the CEO of Inspire. “Consumers want convenience, not walled-garden products.” In 2018, Maloney says he expects to see ecosystems built around best-in-class products. “The companies that make them work well together will be the ones to succeed,” he said. “This will come from seamless technology integration, interoperability between hardware devices and automation that adjusts energy consuming devices. Making energy the constant in the smart home ecosystem will add new value in a way that is tangible to consumers.”

Privacy Concerns on adaptions& Solutions : 2017 was a big year for the IoT sector with many consumers embracing technologies such as smart voice assistants. In 2018, expect the technology to continue to make inroads with consumers, which will also help pave the way for the technology’s deployment in the enterprise. This trend matters for industrial and enterprise companies because, as IoT deployments mature, the number of B2B2C IoT projects is increasing, as Ed Abrams, vice president, enterprise IoT at Samsung Electronics America stated.
 
Many consumers, as well as enterprise-level users of IoT technology, will remain wary of the data that connected devices collect, as well as their potential for security problems. Part of the reason for their concern is the overall uptick in cyber breaches in 2017, as well as a rise in reports of connected devices that surreptitiously spied on users. “There is still a lot of work to be done to confirm who legally owns what data and how it can be used,” said Dave McCarthy, director of products at Bsquare.
 
Consumer IoT paranoia, however, will not meaningfully constrain adoption as the benefits of IoT technology with respect to convenience and efficiency continue to grow more apparent. Consumers and governments, however, are likely to clash on consumer protection issues, said Ankur Laroia, strategic solutions leader at Alfresco. “Here in the U.S., while consumers may favor strong privacy regulations, the current administration and Congress do not appear to be on the same page,” he stated.

Skills & resources : In the past several years, technical challenges and IT/OT integration are just some factors that held back IoT adoption. In the coming year, expect technical hurdles to fade. “Plug-and-play IoT will replace expensive, lengthy, super-technical installations that have inhibited adoption,” said Dave McCarthy, director of products at Bsquare. “There could be a reduction in data scientists as deployment is simplified.”

To some extent, IoT deployments could follow in the footsteps of the traditional internet, which began to scale with the introduction of Apache, Windows Networking and WYSIWYG website editors. The debut of plug-and-play IoT could have a similar effect, enabling organizations to extend IoT deployments beyond critical systems, McCarthy said. “Success will lead organizations to explore other areas IoT can help deliver better business outcomes,” he explained. “Most companies focused on their most mission-critical equipment as part of their first wave of adoption. As they gain confidence in their IoT solution, these companies are now looking to expand their capabilities deeper into that set of equipment or widening their deployment to include less critical assets.”
But for many IoT deployments, data scientists and security experts will remain indispensable. “Our board of director studies show that talent and culture are top challenges for all functional leaders including CIOs,” said Peter Sondergaard, executive vice president of research & advisory at Gartner Inc. in a keynote address at the Gartner Symposium in Barcelona. To get around the hurdle, many enterprise companies will be forced to consider non-traditional strategies such as hiring freelance data science and security talent in addition to deploying artificial intelligence and machine learning tools to help fill the gap.  

Increasing the 'G': Cellular connectivity is an increasingly popular option for many industrial IoT and agricultural implementations, but in 2018, fewer IoT projects will rely on 3G connectivity amidst the shift to technologies such as 5G and Cat-M1. “2018 will be the year Cat-M1 gets to scale, with a series of deployments being announced by mobile operators worldwide,” said Dermot O’Shea, co-CEO of antenna designer Taoglas. Verizon, for example, now won’t allow devices to connect to anything but LTE, so any new deployments have to be LTE-based. It’s a safe bet LTE will become dominant for IoT deployments.
Also AR, VR of the IoT world : There are a growing number of companies testing the use of augmented reality tools such as the second iteration of Google Glass or the Microsoft Hololens for industrial and maintenance applications. Expect this trend to accelerate in 2018. “AR/VR will make its mark on IoT,” said McCarthy. “Whether using full virtual reality to simulate responses to conditions in the field or augmented reality to put more information in front of equipment operators, new ways of interacting with IoT data will emerge.”

While the possibilities are impressive, it could be years before such technologies become mainstream in industrial settings. For one thing, many industrial facilities lack pervasive high-speed wireless networking functionality, which can limit the functionality of sophisticated industrial AR systems. Complicating matters, VR and AR technology have been relatively slow to mature. The term “virtual reality” dates back to the 1980s, yet Gartner still sees the technology as being two to five years away from the “plateau of productivity” stage in its famed hype cycle model. Meanwhile, many AR-based projects for industrial applications are pilot programs.

New ideas like Micro-location will be a star technology of 2018. In one respect, it is surprising that a technology like GPS — with a resolution of roughly 10 to 50 feet — could have such a dramatic impact on how we navigate. While GPS accuracy is improving to rival the positioning aspects of smartphones, highly precise location accuracy — down to the centimeter level — will be a breakthrough technology of 2018, said O’Shea. He says he anticipates “a wealth of new use cases that require low-latency, real-time applications.” Ultra wideband technologies deployment will help drive applications such as crowd and warehouse management and logistics. “Outdoors, GNSS antennas will take applications such as navigation, unmanned aerial vehicles (UAVs), surveying, precision agriculture and connected cars to the next level, and will provide automobile manufacturers the technology they need to drive the autonomous vehicle forward,” O’Shea says.

In 2017, a growing number of networking companies such as Cisco and Juniper Networks began to step up their marketing for automated networking tools such as software-defined networking, arguing that the tools could help their customers scale IoT initiatives. Expect this trend to gain momentum as the numbers of enterprise and industrial companies with hundreds, thousands or more connected devices increases, making managing them with traditional resources untenable.

Corey Nachreiner, CTO at WatchGuard Technologies has a similar take, predicting the problem of IoT botnets will pressure governments to regulate IoT device makers. “IoT device adoption continues to skyrocket, adding billions of new network endpoints every year,” he said. “Attackers continue to target these devices due to their weak or non-existent security, both in development and deployment.”
One consideration is that the source code for one of the biggest botnets in history, Mirai, is freely available on the internet, enabling attackers to modify and improve the code to launch fresh exploits. “For example, the Reaper botnet actively exploits common vulnerabilities in IoT devices to gain access to the devices instead of relying on a hard-coded credential list,” Nachreiner said. “As attacks continue to grow in effectiveness, the damage they cause will grow until the IoT manufacturing industry is incentivized or forced to add stronger security to their products. Be on the watch for a major IoT botnet attack in 2018 that finally causes governments to address IoT security.”

Security concerns, Enterprise companies will see security breaches as a cost of doing business—while stepping up their defenses. There has perhaps been no year where security incidents  have been as widespread as in 2017. While the Equifax breach was the biggest breach of the year, it seemed that few organizations were spared, including the NSA and Deloitte, which itself has a security consulting business. “The old saying will be proven correct: The only two kinds of companies are those who have been breached and those who don’t yet know that they’ve been breached,” said Simon Jones, evangelist at Cedexis. “As the attack vectors in the shape of IoT devices proliferate, traditional defense mechanisms will fold like a deck of cards, and breaches will come thick and fast.” Despite the increasing numbers of security breaches, many enterprise companies continue to deploy IoT technology as a part of digital transformation efforts. As a result, a growing number of firms are beginning to anticipate that they will be targeted. A total of  54 percent of cyber security professionals expect  their organization will suffer a successful attack in the next year, according to the Cyber Security Trends of 2017 Spotlight Report from Herjavec Group. “Data Breaches Will Increase in Frequency and Scope in 2018. The reality is that we can expect data breaches to only increase in frequency and scope in 2018,” Laroia said. As a result of the situation, Jones also anticipates an uptick in defense mechanisms that are specifically constructed to keep IoT devices out. 

Mike Bell, EVP IoT & devices at Canonical says he expects industrial companies to take a cue from the consumer space by triggering a growing number of device updates to download automatically. The need to keep industrial IoT devices updated is tantamount, given they can easily remain in use for 10 years and sometimes longer. “The ability to keep these devices updated and secured over that time frame is critical, but many of them have weak security, weak password solutions, no way to patch or install OS updates,” Bell said. Unless the industrial realm ups its game, Bell expects two or three large-scale “botnet-style attacks on IoT-related hardware in 2018.”

Medical devices & advances : New medical devices will emerge as a vulnerable hacking target. Not long ago, few medical devices would qualify as examples of the Internet of Things. Now, connected medical devices abound. There is also an uptick in medical data trafficking on the black market. Hackers are stepping up attacks on connected medical devices such as IV pumps, heart rate monitors and X-ray machines, said Xu Zou, CEO and co-founder, ZingBox. Zou predicts an uptick in cyberattacks on healthcare systems in 2018 that specifically target medical devices because many have paltry security while also opening the door to a larger network. The stakes are high: A successful attacker can disrupt and paralyze healthcare providers from offering critical care, he warns. “As WannaCry demonstrated, the inability to provide patient care can be more damaging to healthcare providers than even losing patient records.” 

Agile development picks up in hardware and manufacturing, but the Holy Grail will be services. A decade ago, a typical software release could take a year or two. Now, many software development teams are in the habit of pushing out new code on a daily basis. While hardware design and manufacturing has become more efficient over the years, it hasn’t moved nearly as quickly as software. Expect the pace to pick up in 2018, said Rich Rogers, senior vice president, IoT Product & Engineering at Hitachi Vantara. “The pace of technology will accelerate, and hardware manufacturers will utilize incoming IoT data around how products are deployed and consumed, regional needs and vertical industry insights to directly influence how products are designed and manufactured in a more real-time manner,” he explained. “Just-in-time manufacturing will not simply be which options that a vehicle needs, it will begin to influence the options themselves.”

While hardware production and manufacturing will likely continue to grow more nimble in 2018, they will continue to get commoditized, said Arora of CloudLeaf. In fact, software is becoming increasingly commoditized, as well. In 2018, expect to see more industrial companies seek market differentiation by marketing services and experiences rather than traditional products or services.
Lets understand/ analyse  the security aspects as well , With the talk of various “CPU bugs” in the news over the past few days, many customers across the industry are wondering how these vulnerabilities affect IoT. In response to significant press coverage and online speculation, Google’s Project Zero security research team, who initially discovered the issues, today released details of various vulnerabilities ahead of the originally coordinated disclosure date of January 9, 2018.

Three variants of this “side channel” attack have been confirmed, grouped into two categories, known as “Spectre” and “Meltdown“. Google has also created a website dedicated to both vulnerabilities which details in technical terms the scope and impact of the issues. Both categories of exploits stem from newly discovered vulnerabilities within the speculative execution engines found in many modern x86- and ARM-based processors that help enable efficient out-of-order execution of CPU instructions.

To briefly summarize the technical details; these vulnerabilities enable non-privileged applications running locally on a machine to access areas of memory normally reserved for the operating system kernel. The practical impact is that any application running on a system, may be able to access normally off-limits data, such as passwords, security keys, or other sensitive information stored in-memory on the local machine. These vulnerabilities are particularly relevant to multi-tenant/shared hosting environments, including major cloud vendors such as Google, Amazon, and Microsoft, though mitigation efforts are currently in progress or completed for all aforementioned vendors.

While the impact is not limited to Intel CPUs, as originally reported and speculated, the more serious Spectre category of vulnerabilities, does currently appear to be affect nearly all recent Intel’s x86-64 CPUs and a selection of ARM-based processors as well. While Microsoft, along with the Linux Kernel developers have already patched the most serious aspects of the vulnerabilities, these fixes do come with an as-yet-undetermined performance penalty. Current speculation indicates as much as a 20-30% decrease in performance for database-focused workloads, with a smaller 5-10% decrease in performance for more typical enterprise applications, and a <5 applications.="" decrease="" desktop="" for="" span="" style="mso-spacerun: yes;" typical=""> 
 

In terms of applicability to the IoT domain, several factors should be considered. As these vulnerabilities are not so-called “remote exploits”, the impact is mostly limited to environments where sensitive applications are running alongside externally-accessible applications within the same physical system. Typical IoT deployment scenarios tend not to have external-facing services exposed directly from IoT devices, therefore as currently understood, the immediate impact to deployed assets may be minimal. However, as any application developer can attest, there is no such thing as bug-free code. Therefore until all affected systems receive patches for these new vulnerabilities, customers should evaluate any external-facing applications and consider the risks should those applications be exploited and gain access to protected kernel-space memory.