CIO interview: Kjell Rune Tveita, If Skadeförsäkringar

                           
When three insurance companies from Sweden, Norway and Finland merged around the turn of the millennium to form the biggest property and casualty insurance company in the Nordics, Kjell Rune Tveita was appointed to manage the IT integration, becoming CIO of the new company, If Skadeförsäkringar.

Tveita spent 18 months working on the IT integration of the unified organisation. “Some parts of merging three companies are easy, for example choosing one of three different financial systems, because companies report financial matters in pretty much the same way,” he says.

But other parts are more challenging, such as handling the enterprise resource planning (ERP) systems. “Different companies conduct their businesses in different ways,” Tveita adds. “So we had to start by defining our business, how we meet our customers' needs, how we build our products and what processes we are going to use.”

When it came to building the new IT set-up, Tveita focused on making sure IT became a natural part of the business. “One of the first things I did was to appoint an IT manager for each business area, who understood the business and also had a place on the board in that business area,” he says. “That turned out to be a very successful strategy, since it gave us a really good connection between IT and business.”

This strategy also gives one person 100% responsibility for IT, which Tveita thinks is very important. “IT boards, forums and steering groups can be useful for some clearly defined and limited projects, but when it comes to making sure IT activities function, you need people that are responsible,” he says. “They should not have IT as a sideline.”

If Skadeförsäkringar has 550 IT staff spread across Stockholm, Copenhagen, Turku, Helsinki, Riga and Oslo. “If we also count the employees of our partners, a total of 750 people are working with IT at If Skadeförsäkringar every day,” says Tveita. “IT is a big part of our business. Everything we do is digital; we do not have a physical product.”

The company’s core IT systems calculate its products and pricing. “We have built new systems for big parts of our business, but we are not finished yet – it will probably take another four to six years,” says Tveita. “It is very important for us to be able to construct a single Nordic ERP system, covering all our business areas, since that will enable us to conduct our business even better. There are no reasons why you should sell car insurance in a different manner in Norway than in Sweden.”

If Skadeförsäkringar still runs different ERP systems in some of the countries in which it operates. “This means we have to integrate with different ERP systems when we, for example, build a new internet sales solution, which makes the process more complex and demanding,” says Tveita. “But the main reason we want a single ERP system is that we are going to make product changes to make us more competitive.”

The company chose to build the new ERP system itself, since its core competency is to calculate and price risk, says Tveita. “There are off-the-shelf solutions for these kinds of task, and they have their benefits, too. But one of the arguments against off-the-shelf solutions is that they often include processes and ways of conducting the business.”

Other important IT systems for If Skadeförsäkringar are those used in its customer and claims centres. “We have a lot of development going on here, and that will never stop,” says Tveita. “Customers are always making new demands, and we want to keep coming up with new offers.”

If Skadeförsäkringar has decided to outsource all its IT operations, says Tveita. “Today we buy this primarily from Telenor, Tieto and Cisco, because IT operations are not our core competence. And when you can buy this as a service or in the cloud, you cannot compete on price or quality internally. Outsourcing IT operations was one of the first decisions I made.”

At first, IBM was the company's only outsourcing partner, but later it decided to divide the tasks between different suppliers. “No provider can be an expert on everything, so they work with subcontractors,” says Tveita. “It is better that we take responsibility and manage the different suppliers by compiling our own package of services.”

Today, If Skadeförsäkringar has 50 people working in its client organisation, ranging from purchasers and lawyers to technical experts. “The client organisation is very important – you have to have people who look at things strategically and point out a direction, for example that cloud is interesting,” says Tveita. “Then the suppliers can choose how to implement our needs.”

The most important cornerstone of the company's IT strategy is the stability of its IT systems, says Tveita. “Stability is the foundation for everything we do. There should never be any IT hassles for our workers or customers. Other cornerstones are cost-effective solutions, end-customer orientation in everything we do, and innovation, which drives excellence.”

Tveita puts a lot of effort into cultivating the culture of IT. “We call the culture: ’We make it possible’,” he says. “An important part of it is to get everybody to feel involved and assume ownership. The company also emphasises how important it is for everybody to keep themselves updated on what is happening out there in technology.”

One of the biggest challenges Tveita has faced as CIO is to attract and retain the right expertise in IT. “There is still a lack of competent IT people who also understand insurance,” he says. “We can easily buy IT knowledge from our partners, so in-house we do not want people who are 100% IT nerds – we want people with common sense, who can question the way we operate.”

DWP to tender for mainframe platform suppliers in contract worth up to £300m

                               
The Department for Work and Pensions (DWP) is on the hunt for mainframe services suppliers as part of its IT transformational programme.

The DWP plans to procure a full range of virtual machine environment (VME) services, including the “provision, installation, development, operation, maintenance, support transition and decommission of VME systems” in an initial four-year contract worth between £250m and £300m, according to a prior information notice (PIN) posted on the Official Journal of the European Union.

The PIN forms part of the department’s plans to deliver a service tower-based model, separating the IT components into different chunks to allow for greater competition and aligning its business needs.

The VME mainframe services have been fully managed by Fujitsu since the system was first installed in 1974. Most of the DWP’s critical IT systems still run on the proprietary operating system, originally developed by ICL before its acquisition by Fujitsu.

The PIN suggests the department could look to divide the services between suppliers, as the DWP is “examining the potential for disaggregating requirements to the smallest practicable packages that still deliver operational efficiency, while remaining broadly aligned to the tower model”.

“VME systems include application software, platform software, operating system, server hardware, storage hardware (including backup), datacentre LAN [local area network], datacentre interconnectivity and the provision of space in datacentre facilities and equipment from two separate locations, currently configured as active-passive,” said the PIN.

“It is intended that these services will be provided on a non-exclusive basis and suppliers may be required to work with other suppliers of similar or component services at the direction of the DWP.”

The move is in line with its DWP Revised SME Action Plan – May 2014, where the department promised to increase its spend with small to medium-sized enterprises (SMEs). However, the DWP has yet to decide if it wishes to divide the services into several lots or procurements, which – according to the document – will only be “communicated in any subsequent contract notice”.

The current VME estate includes two datacentres, 29 physical servers, 50TB storage, 3200 VME MIPS and approximately 24 applications that will require support.

Other IT “towers” include security, tooling and hosting services. All of these will be overseen by a service integration and management (SIAM) integrator. The DWP plans to host a supplier engagement day on 8 September 2015 to discuss its requirements.

Q2 DDoS attacks double in a year, says Akamai report

                                    
The number of distributed denial of service (DDoS) attacks in the second quarter of 2015 was double that in the same quarter in 2014, a report has revealed.

This is line with the previous two quarters, in which there was a doubling of the number of DDoS attacks compared with the equivalent periods the year before, according to the Akamai Q2 2015 State of the Internet Security Report.

And while attackers favoured less powerful but longer duration attacks during the second quarter of 2015, the number of dangerous “mega attacks” continued to increase, while the financial and retail sectors continued to be the most highly targeted by DDoS attacks, the report said.

In the April to June quarter, there were 12 DDoS attacks peaking at more than 100 Gigabits per second (Gbps) and five attacks peaking at more than 50 million packets per second (Mpps).

According to Akamai, very few organisations have the capacity to withstand such attacks on their own.

The largest DDoS attack of the quarter measured more than 240Gbps and lasted more than 13 hours, but the report said peak bandwidth is typically constrained to a one to two-hour window.

The quarter also saw one of the highest packet rate attacks ever recorded across the Prolexic Routed network, which peaked at 214Mpps.

That attack volume is capable of taking out tier 1 routers, such as those used by internet service providers (ISPs), the report said.

DDoS attack activity set a new record in the quarter, up 132% compared with the same quarter in 2014 and up 7% on the previous quarter.

Average peak attack bandwidth and volume increased slightly in the second quarter of 2015 compared with the previous quarter, but remained significantly lower than the peak averages observed in the second quarter of 2014, the report said.

SYN (synchronisation packets) and Simple Service Discovery Protocol (SSDP) were the most common DDoS attack vectors in the second quarter, each accounting for about 16% of DDoS attack traffic.

The proliferation of unsecured home-based, internet-connected devices using the Universal Plug and Play (UPnP) protocol continues to make them attractive for use as SSDP reflectors, the report said.

According to researchers, although SSDPs were virtually unseen a year ago, they have been one of the top attack vectors for the past three quarters.

SYN floods have continued to be one of the most common vectors in all volumetric attacks since the first Akamai state of the internet report for the third quarter of 2011.

Online gaming has remained the most targeted industry since the second quarter of 2014, consistently being targeted in about 35% of DDoS attacks.

Compared with the second quarter of 2014, there was a 122.22% increase in application layer DDoS attacks, a 133.66% rise in infrastructure layer attacks, and an 18.99% increase in the average attack duration.

However, there was an 11.47% decrease in average peak bandwidth and a 77.26% decrease in average peak volume. 

The report also highlighted several web application attack statistics, including the fact that exploitation of the Shellshock vulnerability was used in 49% of web application attacks in the quarter.

However, the report said 95% of the Shellshock attacks targeted a single customer in the financial services industry, in an aggressive, persistent campaign that endured for the first several weeks of the quarter.

Beyond Shellshock, SQL injection (SQLi) attacks accounted for 26% of all attacks, up 75% on the previous quarter.

In contrast, local file inclusion (LFI) attacks dropped significantly in the quarter, going from the top web application attack vector in the previous quarter to just 18% of attacks in the second quarter.

Remote file inclusion (RFI), PHP injection (PHPi), command injection (CMDi), OGNL injection using OGNL Java Expression Language (JAVAi), and malicious file upload attacks together accounted for just 7% of web application attacks.

“The threat posed by DDoS and web application attacks continues to grow each quarter,” said John Summers, vice-president, cloud security business unit at Akamai.

“Malicious actors are continually changing the game by switching tactics, seeking out new vulnerabilities and even bringing back old techniques that were considered outdated,” he said.

The Akamai report also highlighted the fact that popular website and blogging platform WordPress remains an attractive target for attackers who aim to exploit hundreds of known vulnerabilities to build botnets, spread malware and launch DDoS campaigns.

Third-party plugins go through very little, if any, code vetting, the report said. To better understand the threat, Akamai tested more than 1,300 of the most popular plugins and themes.

These tests found 25 individual plugins and themes that had at least one new vulnerability. In some cases, the plugin or theme had multiple vulnerabilities – totalling 49 potential exploits.

The Onion Router (TOR) project is a third area of risk highlighted by the report. Tor ensures the entry node to a network does not match the exit node, providing a cloak of anonymity for its users, and although Tor has many legitimate uses, its anonymity makes it attractive for malicious actors, the report said.

To assess the risks involved with allowing Tor traffic to websites, Akamai analysed web traffic across the Kona security customer base during a seven-day period.

The analysis showed that 99% of the attacks were sourced from non-Tor IP addresses (IPs). However, one out of 380 requests out of Tor exit nodes was malicious, compared with only one out 11,500 requests out of non-Tor IPs.

However, the report said that blocking Tor traffic could have a negative business effect and that legitimate HTTP requests to e-commerce-related pages showed that Tor exit nodes had conversion rates on a par with non-Tor IPs.