Monday, October 7, 2024

Artificial Intelligence



Artificial Intelligence has taken the world "by storm."  Of course, stories abound regarding abuses from the chat-bots themselves (grabbing your proprietary data or processes in order to share those insights with your competitors!) or abuses from hackers using the technology.

We believe a controlled roll-out of AI via a cloud  environment (isolating your on-premise and "unshared cloud data" from the AI system) is an excellent alternative and invite your inquiries regarding our solution for your organization!



Saturday, March 23, 2024

Cyber Security for Energy Sources

Energy runs our world.  Light switches enable 24-hour productivity.  Devices and machines of all types enable consumer, commercial and government activity.  Of course, communication (other than face-to-face) is also reliant on energy.


In 2021 Colonial Pipeline demonstrated US vulnerability to hacking networks, paying over $4 million (75K in Bitcoin) to a Russia-based organization after shutting down operations ... to regain access to data (the US government later recovered about half of that ransom).


How can the United States government... and, indeed, multinational corporations with a global footprint... address this risk?  While guaranteeing security against all future attacks isn't possible, we believe a cloud-based "3-Domain Architecture" can improve security of data, computing and energy systems.


Recent comments suggest "zero trust" has fallen from the talking point attention it once had.  That said, development processes, secure behaviors (that help avert "social engineering" attacks) and examination of supply chains (security testing of those components prior to final ship -- of product -- to customers) remain key to maintaining maximum security and avoiding loss to ransomware or other cyber attack.



Sunday, February 18, 2024

Cyber vulnerability in Healthcare

                      

Have we done what we can do to prevent malware attacks on our health systems?  Connecticut Attorney General William Tong was notified recently of a summer 2023 attack that may have affected 109,728 people in that state .. a breach confirmed on only 3 hospitals.

“As you are aware, on August 1, 2023, Prospect Medical learned of a data security incident that disrupted the operations of some of its Information Technology (“IT”) systems. Prospect Medical immediately took steps to secure its systems, contain the incident, and notify law enforcement. Additionally, a third-party forensic firm was engaged to conduct an investigation.”

Data stolen included "patients’ names, addresses, dates of birth, diagnoses, lab results, medications, insurance, and financial data."

Would Joel Vengko suggest that Hartford Health is immune to any such attacks?


According to a March 2023 article in LRV Health, "Joel Vengco started his thesis during the third year of <his> MD-PhD program ... the beginning of the end of his time in medical school, <transforming> his career path ... <to> using data to transform the healthcare industry." Dr. Vengko is focused on innovation, but he isn't ignoring cyber security.

Fierce Healthcare reported in December 2023 that "As of mid-December, the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) had received 541 notices of data breaches affecting more than 500 individuals during 2023. Among these were incidents that compromised the information of millions, or even tens of millions, of individuals, as was the case with this summer’s high-profile breach at HCA Healthcare."

So Marty Paslick, CIO of HCA, would have to admit that "attacks forced healthcare providers to adjust their workflows or interrupt services due to lockups of their computer systems."  The Fierce article goes on to quote Mike Hamilton, CIO at Critical Insight, to the effect that  the risk of attack is obviously “escalating, and that the tactics are changing....” 

"Beyond the threat to patients’ lives, these incidents can have a lasting impact on the financial health of a provider organization."  Proactive work is essential... inspiring eWISE focus to help... specifically in the domain of obsolete devices (which pose a large vulnerability unique to the healthcare industry).



Thursday, February 23, 2023

Protecting Health Data

A single hospital has  tens-of-thousands of devices.  The scope of that management challenge is truly daunting... even for organizations with a fairly standard array of devices, tracking "visitors" and staying up to date on patches for devices that practitioners WANT on the network is overwhelming.  Let's get the obsolete devices OFF THE NETWORK... and  the data that you can't easily place in your EHR can be stored securely  in  the cloud... ready for  "fine grained" access when your  employees, health partners and payor partners need it.

"Fine Grained" means only those authorized access can get to that data.  We won't reinvent your Identity Management System(s)... instead we will  leverage  what you have!  "How?"  you ask.  Send me an email (informally at pete.godston@gmail.com) or give me a  call (826-200-0056) and we will walk you thru the 3-Domain Architecture implementation for your strategic  cloud  choice (yes, we can support AWS, Azure and Google Cloud, with consideration to  Oracle  Cloud in the event you are a Cerner customer today).

Thanks for reading!  Hope to talk with you soon!





Thursday, May 26, 2022




What a year..

Personally, the most trying.. coping with this "pandemic," including being there for teenage daughters... but more substantially the loss of my father ... then within a week lost my long-standing companion, Cocoa, a Labrador Retriever (the last two completely unrelated to this pandemic furor). 

Professionally, found myself marveling at the collective unwillingness (inability?) of many sectors to welcome intellectual honesty around cloud capability.  I walked away from the enticing option of "check-box" certification (I have a Harvard MBA, for God's sake!) exams in favor of implementing the tech (just because your staff or new hire has a certification doesn't mean they can efficiently implement a solution appropriate for your environment)... yet in spite of very loud public whining about a scarcity of cloud implementation skills, no one I didn't have a personal relationship with five years ago was willing to meet to review findings.

True, I'm not on any Gartner matrix.  But doesn't everyone agree Gartner is a pay-to-play domain?  Are we really okay with a model that favors India's Brahmin class over our own innovation (no, not just me... spent some time with a few engineering innovators who finally concluded "my baby is ugly" and left a brilliant solution to keep customers happy in another domain.

Tuesday, February 9, 2021

eWISE AgileHealth©



The IT landscape at mid-to-large health organizations is dominated by electronic health record systems (EHR), a market led by Cerner, EPIC and Meditech.  Innovative applications to support health care (addressing COVID, other CRISPR DNA therapies/research and so much more) are available on Amazon Web Services (AWS), Azure and Google Cloud platforms.  The eWISE AgileHealth© approach enables secure access to data, appropriate integration of new data and enables integration to the millions of health devices (and providing vendors) that are modern health care.  Are you ready to visit the 3-Domain Architecture?




Christmas 2018

 



Spending a few days with my favorite person in the world, daughter Annika.  Danish pancakes for din-din Christmas day and for breakfast two days later.  Steak, peas and baked potatoes the day after Christmas.  Lots of Nintendo Switch, video blog from Danny Gonzalez... and a few other activities.  Cocoa says, "woof."





Wednesday, May 30, 2018

Russia/Ukraine Update



Watch for the Third Edition of my book,Navies, Petrol and Chocolate, due in February 2021 (on Amazon in paperback and ebook).

Fearing a move of Russian troops to the Ukraine border,  western forces have exercised in Estonia.  Russia's 2018 exercise happened in the East... The Russian seizure of three Ukraine cargo vessels vicinity the Kerch Strait in late November 2018 was an unhappy display (seized sailors and ships weren't returned for many months).  Russian naval exercises happened in 2020... what's next?





Wednesday, May 9, 2018

What does Kim want?


Granted, scoring a meeting with the President of the United States is a coup no North Korean leader has scored in the history of the country, but what (beyond more status enhancing activity) does Kim Jung Un want from the upcoming meeting with Donald Trump?

Here is a crazy idea:  he wants general elections to select a president of both Koreas.   Assume that the North (25% of the population who worship the man today) votes  as a block and the south (the remaining 75%) splits between several (two or more) candidates...Un wins!!




Korean population density


A worthy project for Gallop, the polling company.  Informed scholars believe Kim becomes irrelevant  the moment he allows a new government to undermine his northern authoritarian regime.  At the top of a democratically elected organization, with his secret police suddenly able to run rampant across the peninsula... uh oh!  What do you think?





Saturday, May 5, 2018

Privacy


The Fourth Amendment to the United States Constitution specifically protects:  "The right of the people to be secure in their persons, houses, papers, and effects, against unreasonable searches and seizures, shall not be violated, and no Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."

A woman I recently met was calling anyone  using Facebook an idiot, because "your data is open for abuse and examination."  We choose to share information on Facebook, I  replied.  What about banks, landlords and others with access to financial transaction data (because they pay for it)?   What about data, in your medical record, that hackers are sharing with the global criminal community?

Granted, hackers are criminals.  But are your health organizations really doing, what they should, to protect against (or quickly detect) a hack?  Likely not...

Banks and other organizations with access to your financial records are not criminal.  Yet they have unfettered access to your financial records and accounts, in the name of understanding your creditworthiness and making robust financial decisions.

[from Wikipedia] Article XIV of the Massachusetts Declaration of Rights [stated even before the 4th Amendment to the US Constitution, that]: Every subject has a right to be secure from all unreasonable searches, and seizures of his person, his houses, his papers, and all his possessions. All warrants, therefore, are contrary to this right, if the cause or foundation of them be not previously supported by oath or affirmation; and if the order in the warrant to a civil officer, to make search in suspected places, or to arrest one or more suspected persons, or to seize their property, be not accompanied with a special designation of the persons or objects of search, arrest, or seizure: and no warrant ought to be issued but in cases, and with the formalities, prescribed by the laws.

In the internet age, we need to enact laws to protect citizens from probing commercial and government entities, and punish these abuses with civil and perhaps criminal penalties....

Tuesday, February 27, 2018

Cyber Vulnerability

                               

A few weeks ago several scary hardware vulnerabilities surfaced to illustrate how sophisticated hackers have become.  Spectre and Meltdown hacks use manipulation of central processing unit cache (yeah, the "CPU" is one of the key chips on your computer's motherboard).  These hacks use a detailed understanding of cache memory functionality to steal data from applications on your computer or perhaps from elsewhere on your network (thanks to Carbon Black for this illustration regarding the workings of CPU cache/processing).

Some patches have been published, but these hacks are very hard to block.  In spite of assertions that we haven't seen this malware "in the wild," when you contemplate what this kind of hacking vulnerability means, you begin to realize how vulnerable computers are, in general, and understand the "rocket science" some of these hackers can bring to the table.

Computers.  Yes, the MRI and heart monitor in your hospital are computers.  Every device on your network.  Obviously desktop, laptop and mobile computers (including your phone) are also computers.

So what do you do about this?  Of course, install firewalls and enact your system's onboard security features.  Keep up-to-date on operating system patches (yikes... you might be forced to tolerate dog-slow performance or upgrade to the new phone!) ... but if you are responsible for any size organization, you should also monitor your network a bit more carefully.

Even  if your firewall can't stop a hack (pieces of malware infiltrate your network, then reassemble once inside, for example), you can detect unwanted data transmissions or peculiar performance characteristics (yes, even that sophisticated malware causes suspect hacked CPU behavior).

Thanks for reading.

Friday, December 15, 2017

Russian adventurism




Every year for a number of years, Russia has run a substantial military exercise on the border of Ukraine.  Putin is wary of overcommitting, but Russian decision to declare victory and pull troops from Syria, enables a more  aggressive  "exercise" this summer.  

Europe hasn't welcomed Ukraine into NATO (or even  the economic European Union) and is dependent on Russian oil/gas.  US sanctions haven't been adequate to drive a Russian decision to pull forces from Donbass or Crimea, Ukraine.  Without  "boots on the ground," Russian forces will be capable of overwhelming Ukraine resistance.  Here is a graphic showing how the US can help: this approach provides US Reserve and Active forces, minimizing a commitment while adding substantial "teeth" to Ukraine forces, which are also arrayed across the country (although not in sufficient  number to stand up to Russian forces we see participating in the annual  Zapad exercises).


Materials on the 2018 Zapad exercise haven't emerged yet, but details on last year's Russian exercise are here.  Placing units in Ukraine before a Russian occupation will stop such an occupation without bloodshed,  while waiting until after a Russian occupation cedes the country to Russia.  Decisive action makes any leader popular:  Putin is running for reelection in March 2018.

Saturday, November 11, 2017

Veterans' Day



Sitting in the IHOP having enjoyed the Veteran's Day Special.  A day late for the publicized special, but they gave it to me.  "Amazing" and "huge thanks" to the Sterling IHOP team!

There are over twenty two and a half million veterans in America today (only a  little over 2 million Americans serve on active duty at one time).  So 7%. of our population are veterans.  Less than 10% of our veterans are women (less then 1% of the total population, or a bit over 1% of the total female population).

From ABC News:

In the decade since the Sept. 11, 2001, terrorist attacks on the World Trade Center, 2,333,972 American military personnel had been deployed to Iraq, Afghanistan or both, as of Aug. 30,2011. Of that total, 1,353, 627 have since left the military and 711,986 have used VA health care between fiscal year 2002 and the third-quarter fiscal year 2011.

The VA's Iraq and Afghanistan Veterans of America, a non-profit whose mission is to improve the lives of veterans, points out that 38 per 100,000 of all Iraq and Afghanistan veterans using VA health care committed suicide during latest data available. There is very little information about veterans not using VA health care. Compare that to 11.5 deaths per 100,000 for the general public. (Quote ends here).

I find myself annoyed when I see a Facebook posting about the Veterans' suicide statistic (there are a lot of such posts).  Why?  Am examining the response... First, while I led a battalion to Iraq and have worked hard to correct our DOD mis-steps (which I saw during service or outside of it) let me say I have given far less than many of my vet colleagues.  Many vets deployed to combat multiple times and suffer from dramatic health issues due to service or perhaps circumstances that pre-existed or evolved since service: I am pretty healthy for a 56yo white guy.

Many vets struggle with unemployment or underemployment.  Turns out, veterans with disabilities fare better than disabled Americans without vet status ("The working-poor rate for Veterans with a disability is 7.9 percent compared to 4.4 percent for those with no disability.  Non-Veterans with a disability have a working-poor rate of 16.0 percent compared to 8.9 percent for those with no disability." The Veteran Working Poor Nov 2017). 

I am working on a start-up and several revenue generating activities after leaving an excellent job and my marriage several years ago.  The larger public is kinder to veterans than in the Vietnam era... public thanks are frequent.  But there are many generalizations that colleagues, friends and relatives heap upon a veteran.  

Better aware than not.  But... we don't consider ourselves "pity cases."  We are proud to have served.  But (speaking for one, at least) we are distressed to be heaped with all of our vet brothers and sisters (in spite of the sense of camaraderie we feel for those others).  Very few of us are cleanly classified according to our "MOS" (military occupational specialty), and were under the impression that, upon departure from service, we would be entitled to that fierce American independence and uniqueness that we fought to protect.  Yet somehow we can't shake these generalizations.

The pictures of soldiers walking through airports to applause bring tears to our eyes also.  But we (mostly) are no longer under the care of "big Army" (Navy, Air Force, USMC, fill in your service) and find ourselves cut off from the other circles we thought we would be joining upon exit of service.

Psychologists say we all feel more alone than was commonly believed.  So maybe this isn't special for veterans.  I have blamed a harsh Uniformed Code of Military Justice for the suicide rate.  But maybe that suicide rate is more about the permanence that we citizen soldiers find in our choice to serve.  Permanence of the negatives, in contrast to the fleeting positives.

Yes, thank a veteran today.  But more important, ask him or her where he/she was born.  Did he/she serve longer or shorter than expected?  How does he/she enjoy being a civilian?  How does he/she like his/her job?  What are his/her dreams/aspirations beyond the service?  Make a friend.  Extend a hand if one is needed.  He/she would extend one to you, if you needed.  Pretty sure of that.

Tuesday, August 22, 2017

Best Business Book

                                            

In the year the US elected its first Reality TV President, how can I not include Daymond John's The Power of Broke book in a list of 2017's best?  John extolls the virtues of building a business on a shoestring.  The "Shark Tank" star has accomplished much, and "his" show has done for the VC process what President Trump's show has done for him... well, not quite!!  My own experience cycling through two distinct entrepreneurial ideas in one year, very much underfunded, certainly invites admiration and suggests wisdom abounds with this approach.

The Subtle Art... by Mark Manson is one I probably should have read a few years ago.  For all the challenges of my marriage and last well paid "gig," in retrospect my family (and I) would be much better off if I had muddled along with an attitude of humor and gratitude (hadn't given a F*ck), rather than seizing the discomfort to quit these two things, engage a financially draining software start-up and write my second nonfiction title (Navies, Petrol and Chocolate: Why Ukraine Matters).  Believe the Trump administration is coming around to a workable policy in Ukraine, but am uncertain that my book had a role there.  It  was a huge sacrifice to write... sacrifices for more than myself.

So Good They Can't Ignore You (Cal Newport) has got to be a fundamental of life and business.  Yes, true passion emerges after hard work, which  invariably is given to you by others, driving  passion and more hard work.  I am excited where eWISE LLC is leading me, contemplating the cyber intrusion detection AND response policy threads. 

Let me end this blog with several caveats:  I have read more fiction this year than business books.  Although Navies ... is a nonfiction book, I also published my first novel (Ukraine Skies, Baltimore Lights) and spent time with some avant garde fiction for inspiration.  Thus, there was little time for reading business material and this review are really a  "to read" list, not a "have  read" list.


Friday, June 2, 2017

Intrusion Detection and Response


There is a rather large universe of solutions to address hacker risk.  You can buy products (hardware and software) claiming to prevent attacks to your hardware, software or network, you can buy services or you can find a collection of both.

Complex networks, like we find in an individual hospital (or even a larger clinic, not to mention a complex of such organizations) are rife with vulnerable network citizens, while solutions are often complex or expensive to implement.  "We need to move forward, but what is the next step?" you ask...

You have made investments that are a component of your most cost effective solution, moving forward.  You might have also made investments that didn't work out, or can be replaced with a more effective (and more cost effective) solution.  Let's trim those outgoing payments... and build a flexible set to manage moving forward.

Key to all of this is understanding your inventory of network citizens, insuring network logs are "watching" in/out-going traffic for all, effectively screening those logs, and taking prompt, effective action to address a hack.

When can we start?



Sunday, May 21, 2017

Naming


What is in a name?  Immediate warm feelings, or the opposite... a singular tag that links you to an idea, a capability, an experience?

Turns out, moments before I was mobilized in 2007, someone began using my eWISE name.  They ran a search while I was in Iraq, then registered in 2008.

So I have returned to eWISE.  We have been a Virginia Limited Liability Company for some years, although the focus has recently changed to cyber intrusion detection and response for the medical sector.

Our offering is a hardware/software/services package, recognizing there are some security benefits to hosting the software solution "in house," although we will certainly leverage the cloud for sections of the offering.

eWISE LLC has posted real estate and book sale revenues in 2016.  We imagine the cyber offering will dwarf these other income streams in 2017 (although am hoping Ukraine Skies book and game revenues also contribute to our economic well-being), building to something substantial in 2018. 

Thanks for reading!



Friday, May 5, 2017

Fact or Fiction?

My Zimbio   Ukraine Skies, Baltimore Lights is fiction.  That said, there are some names that I've taken from reality:  HR McMaster, formerly President Trump's NSC, appears as himself, albeit junior in rank, commanding the Second Armored Cavalry Regiment.  Colonel Mullaly is the name of someone I worked for, although the character isn't the same person.

Cleopatra is a real person in history.  I had a vibrant argument about the dates of Cleopatra's reign/life with a woman last night (thanks Vicki!).  According to Wikipedia, Cleopatra died thirty years before the birth of Christ, of suicide.

My book alleges she was a vampire and was "boxed" and transported to Ukraine, through Jerusalem, around 30AD.  The man responsible for transporting her, who I have named Taigen Sessai, after a samurai monk general who lived in 1500AD, met Pontias Pilate and Jesus during his "mission" to bring Cleo's sealed box to Ukraine.

In my novel, Sessai is also an immortal.  At the time he transports Cleo and meets Jesus, he is about 500 years old.  After depositing Cleo in the Ukraine cave, where she was supposed to sleep for eternity, Sessai meanders around Europe fighting in famous battles and learning about clocks and time.


He runs across a samurai sword (called a "katana") in one of the battles, and decides he wants one.  So he travels to Japan, which is where he is in 1500AD (remember, my character is immortal), when he meets the real Taigen Sessai.  In my novel, "the real Sessai" is assassinated as a teenager, so my immortal/vampire character assumes his identity, wins the battles attributed to his namesake and keeps that name for the rest of "his eternity."

Interesting?  I hope you think so, and buy my book on Amazon!

Find Ukraine Skies, Baltimore Lights here.  


Thursday, February 2, 2017

NATO Update

My Zimbio  The US did not push for more Russian concessions regarding Ukraine at the July G20 Summit, although President Trump had a "firm" meeting with his Russian counterpart.  The Wall Street Journal reported on February 2, 2017, that "NATO Scraps Ukraine Security Meeting." Although Russia and Russian-backed separatists are escalating violence from Donbass, Ukraine, President Trump had suggested dropping sanctions on Russia as recently as a few months ago, while Europe (from the NATO alliance) cancelled talks with Ukraine about including it under a missile-defense system.

Shelling in 2017 has killed a dozen Ukrainian Soldiers, wounding many more and damaging water, electricity and heating for 17,000 people in Avdiivka.  Europe is reluctant to help in spite of "The Organization for Security and Cooperation in Europe's Special Monitoring Mission in Ukraine" report that fighting is severe as any that it has observed in Donetsk, Ukraine (WSJ, p.A8). 

Secretary of Defense Mattis continues his supportive words for NATO.  Secretary of State Tillerson is on record strongly supported the Minsk Accords, the formal ceasefire in Ukraine to which Russia nominally agreed (picture below of Ukraine Foreign Minister Pavlo Klimkin with Secretary Tillerson some weeks after the comment about the Minsk Accords).  When Ukraine President Petro Poroshenko visited Washington DC recently, an informal meeting came together with President Trump himself.




In Syria, Russia is meeting its goals to keep Assad/naval ports in place, while in Ukraine, casualties continue to mount... we trust the Trump administration will continue to push for progress in Ukraine.

Sunday, January 8, 2017

Innovation Letter

My Zimbio  In "an open letter from Tech Sector Leaders," one hundred forty five Silicon Valley big shots expressed concern before the election that Donald Trump will invite disaster for innovation.  They thought his policies would undermine key dynamics that help the US retain a global innovation lead.  Oops!  The Donald recently met with these folks (minus one or two) to insure communication channels are open.

You may recall "the Valley" leaders were calling for 1) progressive immigration policy; 2) free and open exchange of ideas and unfettered internet architecture; and 3) continued government investment in infrastructure, education and scientific research.

While this letter certainly preaches "motherhood and apple pie" values on the surface and inspires us to examine Trump's policy suggestions more carefully, it comes from people who don't care a shred about the majority of people gravitating to Trump.  Another letter I read before the election comes to mind: a Walt Disney IT professional wrote to share his career predicament when he, like hundreds of colleagues, was displaced by a crew from India.  If this man wanted any severance at all, he (and the other Disney employees who were being fired) would train the new comers how to do his/her job and "go quietly into the night."

People voting for Trump want help, need help, against people like these Silicon Valley "silver spooners."  These Valley people don't just want innovation, they want exclusive right to drive capital to their projects and innovations that profit them.  They want the ability to hire indiscriminately in a negotiation against hi cost employees (in many cases).  They also want to control how investments in infrastructure, education and research are made, so they may forward their progressive political agenda.  Trump may not "do things their way."  Indeed, he surely won't "do things their way."

We might be well advised to attack legal and financial impediments to innovation (such as Sarbanes Oxley and Obamacare legislation) rather than adopting self serving proscriptions against Trump.  How can we work together to improve our business climate  and national competitiveness?  Will Trump get it right?  We shall see...


Saturday, January 7, 2017

Books

My Zimbio Three years ago, based on advice from James Altucher, I published my first book.  Two years ago I set out to write my next book, based on concerns about Russian adventurism in Ukraine.  On Monday, my third book (a novel) will "go live" on Kindle (you can buy a paperback today on Amazon).

Amazon has pretty good support for authors, including the opportunity to post a very functional author page.  Blog support doesn't work smoothly with Google's "blogger" but you have found this anyway,  haven't you?

I've produced web sites to support the Navies, Petrol and Chocolate and Citizen's Guide to Marksmanship titles.  Am also considering partnerships with Sabaton, the Swedish heavy metal band (with Poltava song) and the Royal Stockholm Opera Chorus (or Neeme Jarvi's version here), which has produced Tchaikovsky's Mazeppa opera, both supporting Navies, Petrol and Chocolate.

Thanks for reading.