Advancing control and visibility in the cloud

At Google Cloud, we work tirelessly to give our customers increasing levels of control and visibility over their data. Today in London at Next UK, we’re announcing new capabilities for data encryption, network security, security analytics, and user protection designed to deliver on that promise. External Key Manager: Store and manage encryption keys outside of Google CloudWe give enterprises a broad range of encryption options so you can appropriately balance risk, control, security, and operational complexity when protecting your cloud workloads.Google Cloud encrypts customer data at-rest by default and offers customers multiple options to control and manage their encryption keys. Today, we’re pleased to announce the next level of control with our new External Key Manager. Coming soon to beta, External Key Manager works with Cloud KMS and lets you encrypt data in BigQuery and Compute Engine with encryption keys stored and managed in a third-party key management system deployed outside Google’s infrastructure. External Key Manager allows you to maintain separation between your data at-rest and your encryption keys while still leveraging the power of cloud for compute and analytics.To make this new service easy to implement, we are working with five industry-leading key management vendors: Equinix, Fortanix, Ionic, Thales and Unbound. Key Access Justifications: Decide when and why your data can be decrypted We believe that trust in the cloud is created through transparency. Google Cloud led the industry in providing meaningful transparency into provider access to customer data, and now we’re extending that transparency to use of encryption keys. Key Access Justifications is a new feature that will work with External Key Manager. It provides a detailed justification each time one of your keys is requested to decrypt data, along with a mechanism for you to explicitly approve or deny providing the key using an automated policy that you set. Using External Key Manager and Key Access Justifications together, you can deny Google the ability to decrypt your data for any reason. As a result, you are the ultimate arbiter of access to your data–a level of control not available from any other cloud provider. Key Access Justifications is coming soon to alpha for BigQuery, and Compute Engine/Persistent Disk and covers the transition from data-at-rest to data-in-use. Customers interested in becoming early adopters can sign up here.These new encryption innovations complement other recently released encryption options:Customer-managed encryption keys for Cloud SQL, now generally available (GA)Customer managed encryption keys for GKE persistent disks, a beta feature for Google Kubernetes Engine (GKE)Application layer secrets encryption in GKE, a GA feature which enables envelope encryption for your Kubernetes secretsKey import for Cloud HSM, a GA feature which lets users generate and use their own keys with Google Cloud’s managed HSM serviceCloud HSM availability in all Google Cloud regions and multi-regions (with the exception of global multi-region)All these updates offer you more control over how your data is protected.  Defend against internet threatsWhen you stand up applications on Google Cloud, you benefit from DDoS and web attack protection at Google scale. Google Cloud Armor works with our global Cloud Load Balancing infrastructure and provides always-on attack detection and mitigation so you can run your business without interruption. Today, we’re pleased to announce Cloud Armor’s new web application firewall (WAF) capabilities to help protect applications against targeted and distributed internet threats. You can now configure Cloud Armor policies with geo-based access controls, pre-configured WAF application protection rules to mitigate OWASP Top 10 risks, and a custom rules language to create custom Layer-7 filtering policies.Cloud Armor also now integrates with Cloud Security Command Center (Cloud SCC), notifying customers of suspicious application traffic patterns directly in the Cloud SCC dashboard.Collect and inspect network traffic at scaleAs networks grow in complexity, monitoring traffic helps you manage performance and security. In public cloud environments however, capturing network traffic reliably at scale for monitoring has been a challenge. Our new Packet Mirroring service, now in beta, allows you to collect and inspect network traffic for Compute Engine and GKE; it’s available for all machine types in all of our regions. With this service, you can use third-party tools to more proactively detect threats, better respond to intrusions with signature-based attack detection, and better identify zero-day attacks with anomaly detection. For more, watch this video.We’ve built an ecosystem of partners so you can use Packet Mirroring with third-party tools of your choice, including products from Awake Security, Check Point, Cisco, Corelight, cPacket Networks, ExtraHop Networks, Flowmon, Ixia by Keysight, Netscout, and Palo Alto Networks.Protect G Suite and Cloud Identity usersGoogle’s Advanced Protection Program is our strongest protection for users at risk of targeted attacks. In the enterprise, this includes IT administrators and executives. Today, the Advanced Protection Program is starting to roll out to G Suite and Cloud Identity customers. With the Advanced Protection Program for the enterprise, we’ll enforce a specific set of policies for enrolled users including security key enforcement, blocking access to untrusted apps and enhanced scanning for email threats. Learn more.We’re also introducing app access control, helping you reduce the risk of data loss by limiting access to G Suite APIs to third-party apps you trust. You can also more easily manage and restrict which Google APIs are available for use by third-party and customer-owned apps, and see which apps are verified by Google. Learn more.Benefit from unique Google threat intelligence in Cloud Security Command CenterWe continue to build products that help our customers benefit from the techniques we’ve developed to defend Google. Whether you are using Cloud Security Command Center to improve your security posture on GCP, or Chronicle Backstory to monitor your data on premise or in other clouds, we’re packaging threat detection and prevention capabilities that are available only from Google, and giving them to you.Event Threat Detection, now in beta, helps you detect threats targeting your cloud resources using logs, so you can send incidents to your SIEM (Security Information and Event Management system) for further investigation. Event Threat Detection relies on Google threat intelligence to help you spot and stop threats before they result in business damage or loss. Security Health Analytics helps you prevent incidents by identifying potential misconfigurations and compliance violations in your GCP resources and suggesting appropriate corrective action.As we continue to innovate and simplify security management on GCP, Event Threat Detection and Security Health Analytics will be bundled in a Premium Edition of Cloud Security Command Center with other new capabilities that help you meet industry compliance requirements, catch web application vulnerabilities, detect compromised VMs, and discover other threats. The Premium Edition will give you a comprehensive, easy-to-deploy set of tools to protect your cloud resources. To learn more about how to use Cloud Security Command Center, check out our recent video series. Chronicle: security analytics wherever your apps are deployedChronicle’s Backstory product was designed by former Google security professionals to enable anyone to use the types of techniques we use to detect threats and investigate security incidents. It brings world-class strengths in data analytics to your security data, privately and easily.Many organizations leverage a mix of on-prem environments and multiple clouds to run their applications, making it difficult to collect and store security telemetry from various systems and tie individual events together for analysis. Backstory, our flagship offering for hybrid security analytics, offers you this level of intelligence. With just a few clicks, in minutes, you can aggregate and analyze your security telemetry wherever your apps may run, and where they might run in the future.Be sure to check out the Chronicle booth during Next UK to learn more!Learn moreWith these capabilities, we continue to innovate and empower Google Cloud customers with advanced security functionality that is easy to deploy and use. Learn more about our entire portfolio of security capabilities in our Trust & Security Center.
Quelle: Google Cloud Platform

Understanding your options for data residency, operational transparency, and privacy controls on Google Cloud Platform

At Google Cloud, the privacy and security of customer data are primary design criteria that underpin all the services we offer. At Google Cloud Next UK, we offered a series of commitments to our European customers that our platform will offer tools to meet their strict needs and preferences for enterprise data residency, operational transparency, and privacy controls. While this post focuses on our European customers, these requirements are not unique to Europe. Cloud users around the world have similar needs, and these principles apply to customers in every region. This post aims to provide further technical clarity around options customers have for configuring services to meet these requirements when using Google Cloud. Configuring where your data is stored and where users can access it fromGoogle Cloud offers you the ability to control where your data is stored. Today you can choose to store your data in regions based in the UK, Belgium, Germany, Finland, Switzerland, and the Netherlands, with more regions announced and several others in-motion. When you choose to configure resources in these locations, for our key services, “Google will store that Customer Data at rest only in the selected Region” per our Service Specific Terms. To strengthen these controls further, Google Cloud offers Organization Policy constraints which can be applied at the organization, folder, or project level. You can limit the physical location of a new resource with the Organization Policy Service resource locations constraint. When coupled with Cloud IAM configuration to enable or disable services for sets of users, you can prevent your employees from accidentally storing data in the wrong Google Cloud region.You also have the ability to control the network locations from which users can access data by using VPC Service Controls. This product allows you to limit access to users in a specific region. You can even enforce this constraint if the user is authorized according to your Cloud IAM policy. Using VPC Service Controls, you create a service perimeter which defines the virtual boundaries from which a service can be accessed, preventing data from being moved outside those boundaries.Controlling where your encryption keys are storedIf you are using Cloud KMS, your cryptographic keys will be stored in the region where you deploy the resource. You also have the option of storing those keys inside a physical Hardware Security Module located in the region you choose with Cloud HSM. We recently announced beta availability of External Key Manager, which allows you to store and manage keys in a third-party key management product deployed outside of Google’s infrastructure. Using a third-party product allows you to place it in a geographic location of your choice. Controlling cloud administrators’ access to your dataOn Google Cloud Platform, you configure Cloud IAM permissions to limit access by your own administrators. We also allow you to control access by Google Support and Engineering personnel. Access Approval allows you to require explicit approval before Google employees access your data or configurations on Google Cloud Platform (unless those accesses are necessary to resolve a current service disruption or security incident or required by law). This product complements the visibility provided by Access Transparency, which generates near real-time logs when Google administrators interact with your data, including the office location of the administrator and the reason for the access. Coming soon, you’ll be able to enforce specific attributes for administrators who are allowed to access your data or configurations—including the geographic region from which they are operating and other compliance-relevant attributes. Finally, we recently announced Key Access Justifications, a feature that works with Cloud KMS and External Key Manager. This feature provides a detailed justification each time one of your keys is requested to decrypt data, along with a mechanism for you to approve or deny key access, using an automated policy that you set. Using all of these products and features together, you can deny Google the ability to decrypt your data for any reason. As a result, you are the ultimate arbiter of access to your data–a level of control not available from any other cloud provider.Putting it all togetherThese capabilities create a solution that gives our customers control over the location of their data and overall access to that data – by Google or by anyone. With these considerations addressed, our customers in Europe and around the globe can confidently build mission critical workloads on Google Cloud. Even so, we’re not done yet: we continue to invest in data privacy and security innovations to anticipate the future needs of our customers so that they can adopt  GCP today knowing that they are fortified for the future..To learn more about the capabilities you can take advantage of, read our whitepaper and visit our Security site.
Quelle: Google Cloud Platform

Deepening our commitment to European businesses

Since launching Google Cloud in Europe in 2012, we’ve been inspired by all the ways enterprises in the region are transforming their businesses in our cloud. We continue to deliver new capabilities to support our European customers and bring the cloud to more organizations. In the last year, we added to our existing cloud region footprint of Belgium, Finland, Germany, the Netherlands, and the UK by launching our new cloud region in Zurich, and announced plans for another new region in Poland. We also expanded our compliance certifications, most recently adding HDS, TISAX, and obtaining an ISAE 3000 report (relating to FINMA compliance) to our growing list. And we’re growing our ecosystem of partners which are key to customers in Europe such as Accenture, Atos, Deloitte, HCL, SAP, and many others. And all the while, we’ve maintained our strong commitment to clean energy, matching our entire annual electricity consumption with renewable energy.  This week, we welcome thousands of customers, partners, business leaders and developers to Google Cloud Next UK in London—our largest Google Cloud event in Europe. On a personal note, I’m excited to round out my first three months at Google Cloud with my first Next, and I look forward to listening deeply to our customers and learning from their cloud journeys. Our commitment to our European customersEurope’s ambition for a successful digital transition is something we have always strived to support and enable. Our cloud is designed to fully empower European organizations’ strict data security and privacy requirements and preferences. Where data resides, who has access to customers’ data, and protections for the privacy and security of customers’ data is central to our offering. With the capabilities we offer and are introducing, Google Cloud customers can store data in a European region, ensure data is not moved outside of Europe, and prevent users and administrators outside Europe from accessing their data. They can manage their own encryption keys, ensure the keys are stored in a European region, and store their encryption keys outside Google Cloud’s infrastructure. They can also receive a detailed justification each time a key is requested to decrypt data, and deny Google the ability to decrypt their data for any reason. You can learn more by reading our security blog post.These capabilities reflect our belief that customers should have the strongest levels of control over data stored in the cloud in addition to the highest level of security. For insight into what this commitment to customers means from a technical perspective, please see our post, “Understanding your options for data residency, operational transparency, and control on Google Cloud Platform” How our European customers are building on Google CloudWe continue to be inspired by the many ways Google Cloud customers across Europe leverage the capabilities of the cloud to transform their businesses. From digital natives building a technology business, to retail companies that have been around for more than 100 years, we are here to support these European organizations in their quests for innovation and growth on a global scale. Here are a few of our favorite stories from the past 12 months:WPP, the world’s largest advertising holding company, is using Google Cloud to help them do everything from building a media planning stewardship system, to using AI tools like image recognition and natural language processing to improve campaigns. By incorporating cloud technology into WPP’s daily practices, teams can speed up their time-to-insight and uncover new opportunities for clients. Learn more in our WPP blog post.The UK’s Department for Transport (DfT) oversees 24 separate agencies and public bodies to support the movement of people and goods. Its digital team delivers technology across DfT’s operations and supports the department’s broader modernization goals, which often requires it to search through and consume data produced by its constituent agencies. DfT needed to modernize its core technology stack to support digital transformation, which is why it’s working with Google Cloud. It’s anticipated that by June 2020 the department will operate as a cloud-first organization. Read more on Department for Transport and the cloud in our DfT blog post.With a growing fleet of 325 aircraft that cover more than 1,000 routes across 158 airports, easyJet is one of Europe’s most popular airlines, so a helpful mobile experience for its customers is a key priority. Powered by Dialogflow, Google Cloud’s natural language understanding tool for building conversational experiences, easyJet partnered with technology company Travelport to develop Speak Now, a new feature on easyJet’s mobile app. Speak Now lets customers ask questions to determine exactly what they’re looking for—from destinations, to dates and times, to airports they want to fly from. Find out more in our easyJet blog post.Customer experience and network data are key assets for Vodafone, one of the world’s leading telecom and technology services companies. It’s working with Google Cloud to transform its data operations to further improve services, engage customers, and create powerful new products. Learn more by reading Vodafone blog post.Just Eat, the popular online food ordering and delivery service, turned to Google Cloud to power sophisticated consumer recommendations on both its app and website. It also makes heavy use of features offered by Google Cloud Platform, including BigQuery for running analytics on its customer data set and Cloud Pub/Sub for messaging app users with relevant offers in real-time. Ride-hailing service Kapten has been skyrocketing in popularity in Paris and is now in the process of expanding to new cities in France and across Europe. To support its growth, Kapten has migrated its microservices-based architecture to Google Cloud to take advantage of Google Kubernetes Engine (GKE), where it now runs 135 microservices. Now that it benefits from the orchestration layer offered by GKE, Kapten no longer needs to spend time developing the tools to manage these microservices and find workarounds.Clothing retailer AllSaints had already embraced G Suite to ensure strong collaboration between corporate offices and retail locations. This year, they embarked on an ambitious migration to Google Cloud Platform as well. Moving to a microservices architecture on Google Cloud helped them cut costs by half and improve page load times by 32%, resulting in increased online sales. These compliment the wealth of stories we’ve shared throughout the past 12 months, from Deutsche Börse Group, Sanofi, The Telegraph, Sainsbury’s, Lush and many more. We look forward to learning more from these and other customers throughout Next UK.Looking aheadToday’s announcements and updates are part of our ongoing commitment to make Google Cloud the best place for digital transformation for European organizations—across infrastructure, platforms, and industry-specific solutions that enable businesses to move faster. Learn more by reading stories from our customers, in Europe and beyond, or visit our website.
Quelle: Google Cloud Platform

How the John Lewis Partnership is transforming customer experiences with Google Cloud

The John Lewis Partnership, comprising of the John Lewis & Partners department stores and Waitrose & Partners shops, is an innovative company on many levels. When the first John Lewis & Partners department store opened on Oxford Street, London, in 1864, few could have imagined the business would have grown so much in the last 150 years. What’s driven its longstanding success are quality products, a focus on exceptional customer service, and a forward-looking company culture. Indeed, challenging the status quo is part of the fabric of the company. For many years a traditional brick-and-mortar retailer, John Lewis & Partners is now a cutting-edge digital innovator, with revenue steadily increasing from its digital channels. This has meant bringing the choice, quality, and responsiveness from its physical stories to the online world in unique ways.To achieve this, the company works with Google Cloud. John Lewis Partnership first engaged with Google in 2014 to improve the way Partners worked together, on and off the shop floor, with productivity solutions from G Suite. More recently, the company created a centralized data platform with Google Cloud to break down data silos across the organisation, providing the foundation for a more omnichannel approach to customer insights and service.Today, the John Lewis Partnership is taking this even further, with new initiatives to help deliver great experiences for customers, whether on an app, website, or browsing in-store:  E-commerce transformation—John Lewis & Partners’ growing digital revenue streams  are underpinned by a popular website and a suite of mobile applications. However, as with any online business, staying relevant is key, and being able to run regular tests for content, layout, and user experience is a must. Working with Google Cloud, John Lewis & Partners is now building a better web experience for customers, including simpler internal processes to make changes, which is already paying dividends.Partnership Data Platform (PDP)—To grow a business that thrives for many years to come, John Lewis & Partners is building a data management platform on Google Cloud to automate decision-making and facilitate access to data across a much broader range of products. The platform serves as the basis for artificial intelligence (AI) and machine-learning (ML) projects, allowing for more accurate customer insight and segmentation, and enabling smarter service and better experience. This is a long-term project, serving as the cornerstone of John Lewis & Partners digital transformation strategy.Andrew MacInnes, CTO of the John Lewis Partnership says: “Innovation is in our DNA. Our enduring strength is built on our uncompromising focus on the customer, for which we need a dynamic way of meeting changing expectations. We believe that the benefits of AI and ML have the ability to transform our business. Building this capability from the ground up would have been impossible for us, and this is why we needed Google Cloud as a partner. Google is helping us to continue innovating around the customer experience, enabled by the cloud.”The opportunities opened up by innovations in AI and ML also raised questions for John Lewis & Partners about how to align modern data science techniques with its people-centric culture. It was essential for new data initiatives to be implemented in an ethical and congruent way. “We describe this new approach as ‘human digital’; it’s not about replacing the personal qualities our customers like, but reinforcing them with intelligent use of data,” Andrew added.The company has large scale ambitions for its data platform. It wants to migrate more applications and data to Google cloud, and to increase the scope of AI-powered tools. “Fundamentally, we’re trying to put data at the heart of everything we do, supporting our business’ ability to operate over the next decade as the retail landscape shifts,” says Andrew. “Having Google Cloud on this journey with us means we’re able to move quickly while taking less risks and staying true to our company culture.” We look forward to supporting them in that journey.
Quelle: Google Cloud Platform

Key Access Justifications: a new level of control and visibility

As enterprises move to and operate in the cloud, they want to control when and how their data is accessed. At Google Cloud, we believe that customers should have the strongest levels of control over data stored in the cloud in addition to the highest levels of security. While there has always been strong demand for control, the technical capabilities to provide it in a meaningful way are extremely challenging to build without making unacceptable tradeoffs in service functionality. We have made significant progress on this front and want to share more about it with you. Today we’re excited to announce Key Access Justifications, a new capability that works with our External Key Manager to allow our customers to be the ultimate arbiters of access to their data on Google Cloud Platform (GCP). To bring this capability to the market, we had to address a number of challenging problems and architect our systems so we can deliver granular control, while still retaining much of the flexibility and functionality that you look for when moving to the cloud.Using Key Access Justifications together with our newly announced External Key Manager product, you’ll receive:Visibility into every request for an encryption key that permits data to change state from at-rest to in-use, with a justification for that requestA mechanism to explicitly approve or deny decryption using the key in the context of that request, using an automated policy that you set (via third-party functionality)A commitment from Google Cloud to protect the integrity of our controls and the justificationsWe chose these features because we want you to have visibility into requests for access to your data, understand the reasons for those requests, and be able to selectively permit or deny them. Google Cloud believes we have attained this through the combination of our Customer Managed Encryption Key, External Key Manager, and Key Access Justifications products. For customers to have confidence in this product and similar solutions, we believe that:Data must be encrypted at restCustomers must have a way to store and manage encryption keys outside of Google’s technical infrastructure Customers must own and hold the encryption keys needed to decrypt their dataCustomers must be able to monitor when a request is made for a key needed to decrypt their data, review the reason for the request, and be able to make a choice about whether to provide access to the key or deny it Reasons for key requests must provide enough information so that customers can understand what is happening to their dataCustomers must be confident in the integrity of the solutionWe believe that External Key Manager together with Key Access Justifications is the first cloud solution that delivers on these requirements, making customers the ultimate arbiter of access to their data.Key Access Justifications is coming soon to BigQuery and Google Compute Engine/Persistent Disk, and covers the transition from data-at-rest to data-in-use in these services. This product will be available to a select number of External Key Manager enterprise customers. A detailed blog post about External Key Manager is also coming soon. If you are interested in becoming a potential early adopter, enter your information into this form.
Quelle: Google Cloud Platform

Vodafone calls for transformative insights, Google Cloud answers

Telecommunications are essential to modern societies and economies. Consumers expect to be connected to an increasing number of devices—smartphones, home equipment and even pet monitors—wherever they are. At the same time, telecommunications also underpin the growth of a range of industries and public services, powering their ability to collect data in an era of connected devices, and enabling them to leverage networks to create new products and services. With the proliferation of artificial intelligence (AI) and 5G networks, leaders are taking this transformation to the next level, reinventing their operations to gain competitive advantage in the digital age.Digital VodafoneVodafone, one of the world’s leading telecom and technology services companies, is at the forefront of this transformation. Vodafone serves 625 million customers on owned and partner networks in 66 countries. The company’s customer and network reach drive its mission to provide the technology and services to create inclusive digital societies in its countries of operation, while also halving its environmental footprint. As part of its ‘Digital Vodafone’ transformation program, the company is working with Google Cloud to build a global big data platform spanning a large number of markets. By leveraging real-time analytics from that ocean of data, Vodafone will have the ability to create powerful new products and services based on deeper customer insight, to engage customers (who opt in) with better, more personalized support, and to leverage its anonymized network data to help tackle important societal issues.Creating a data oceanThe project is complex and multi-faceted. Vodafone’s existing on-premises group data platform is a shared service consisting of eight clusters with more than 600 servers and is used in 11 countries. The platform relies on legacy Hadoop architecture that lacks the agility or scalability to support demands for analytics and an increasing list of innovation projects.To begin, Vodafone will perform a large-scale migration of its global data into our highly secure public cloud. It will also create a custom platform for data performance that lets disparate data from across the organization be aggregated into one ‘data ocean’ (rather than multiple data lakes), within which analytics and business intelligence can take place. Once complete, the speed with which Vodafone will be able to run queries will enable it to gain real-time insights, providing new levels of agility, scalability and cost-effectiveness. Vodafone NeuronRather than lifting and shifting existing workloads into the public cloud environment, Vodafone has integrated Google Cloud tools into its custom ‘Neuron’ platform. Vodafone built Neuron on Google Cloud Platform (GCP), and is in the process of rolling it out to 11 countries. The insights from Neuron are being used to support a range of applications. For example, Vodafone’s ‘Gigabit Networks’ are increasingly optimized by AI to push capacity to where customers need it most; and real-time analytics enable Vodafone to push personalised commercial offers to customers—such as a data top-up—when they are most likely to buy.According to Simon Harris, Group Head of Big Data Delivery at Vodafone, Neuron will become the driver for AI and business intelligence for all of Vodafone globally. “Neuron serves as the foundation for Vodafone’s data ocean and the brains of our business as we transform ourselves into a digital tech company. Not only will we be able to gain real-time analytics capabilities across Vodafone products and services, it will also allow us to arrive at insights faster, which can then be used to offer more personalized product offerings to customers and to raise the bar on service.” The collaboration with Google Cloud, Harris adds, has been invaluable in shaping the operation. “Many of the leading analytics tools such as TensorFlow have been developed by Google, so having their managed service expertise has helped us to optimize our implementation.” At the dawn of a new age in connectivity, Vodafone is building the capabilities to be ahead of the curve. We’re proud to be supporting Vodafone on that journey.
Quelle: Google Cloud Platform