Google's BeyondCorp to Accelerate U.S. Govt's Zero Trust Journey - Build What's Next
Blog

Google’s BeyondCorp to Accelerate U.S. Govt’s Zero Trust Journey

3007

Of your peers have already read this article.

3:00 Minutes

The most insightful time you'll spend today!

Security attacks from 2020, raised concerns on the exploitability of the govt resources. U.S. Federal agencies to improve security are directed to implement Zero Trust architectures. Learn how Google's BeyondCorp accelerates this journey.

In May, the White House issued an Executive Order aiming to improve the nation’s cybersecurity defenses and requiring US Federal agencies to develop plans to implement Zero Trust architectures in alignment with National Institute of Standards and Technology National Institute of Standards and Technology (NIST) guidance. This Executive Order also calls on agencies to accelerate cloud adoption, with a preference for cloud capabilities that implement or advance the adoption of Zero Trust

Zero Trust moves front and center 

The White House guidance is timely and necessary given the surge of ransomware and other cyber attacks over the past year targeting remote workers and VPNs, software supply chains, identity infrastructure and email, and various critical infrastructure sectors. These attacks have raised concerns about cyber-risk across the board, including pervasive IT monocultures that persist, unquestioned, despite their exploitability by attackers. 

White House

This order ties together multiple strands of US cybersecurity best practices and policy that have evolved over the past decade, including stronger identity and access controls, expanded use of encryption and authentication, increased monitoring and visibility, and prioritizing high-value IT assets. Yet the urgent challenge of cybersecurity requires more than simply adding to the existing proliferation of cyber tools or ratcheting up traditional measures around hygiene and compliance. The Administration’s focus on Zero Trust marks a critical shift to prioritizing architectures in which the strategic coordination of layered cyber defenses drives improved cyber outcomes.  

In many ways then, the demand for accelerating the adoption of Zero Trust in federal IT is not a new requirement, as departments and agencies are already implementing many of the core technical components that can contribute to achieving the goals laid out in the executive order.  

What is new, however, is the fact that Zero Trust, when done right, is primarily an outcomes-oriented approach to security. Successfully implementing Zero Trust can drive down cyber risk, transform the daily security experience of users, reduce management complexity and toil for IT managers, and improve the overall productivity of the workforce. 

Outcomes, not just technology 

Successfully implementing Zero Trust is not about the individual technology components and inputs themselves.  Instead, what matters most is how security components are integrated and orchestrated to achieve and enforce a simple set of core principles: 

  • Connecting from a particular network must not determine which services you can access
  • Access to services and data is granted based on what we know about you and your device
  • All access to services must be authenticated, authorized and encrypted.  

Using this set of principles as our north star, Google began our Zero Trust journey, with BeyondCorp, over a decade ago, under similar circumstances to those driving federal cybersecurity policy now. Google had been targeted by nation-state cyber attacks (Operation Aurora), and in the aftermath, we recognized that providing remote access with VPNs was not sustainable or efficient for business performance, especially at a time when Google’s global workforce was growing rapidly. Something had to change.

To improve our security posture and user experience, we had to reimagine our infrastructure and production networks. This ultimately drove innovations in how we protect our supply chains and resulted in a complete rethinking of the scale, analytics and visibility needed to fully modernize and transform enterprise security. The journey forced us to consolidate redundant systems, understand usage patterns better, and transform how people experience security day to day.

Safe Cybersecurity

A shift in technology and a change in mindset

When we developed BeyondCorp, we had to reimagine our infrastructure and production networks in order to affect a better security posture and user experience. This ultimately drove innovations in how we protect our supply chains and resulted in a complete rethinking of the scale, analytics and visibility needed to fully modernize and transform enterprise security. 

Moving to a Zero Trust approach drastically changed how Google’s end users did business and reduced the toil on both individual users and IT professionals to do their part to secure the enterprise, further fostering  the innovation, architectures, operational integrations and best practices we see today. Now, the layered defenses and invisible security our users experience have been incorporated into Google’s secure cloud offerings, so our customers can experience the same benefits and provide their users with a secure and productive work environment. 

Leadership for a cross-team journey

Of course, change isn’t trivial, especially in government. A shift in behavior, user experience, collaboration, tools and infrastructure requires planning, change management, and executive support.  To make the Zero Trust journey a success, organizations need the long-term focus and vision of leadership to drive meaningful change. For traditional security and technology leaders, accelerating the journey to Zero Trust will require them to think less tactically and and act more strategically, in order to focus more on outcomes and less on inputs, and to integrate, harmonize, orchestrate and automate what were previously standalone IT and security efforts.  For non-technology leaders, their engagement and leadership is essential – and much more likely – given the visible benefits to collaboration, culture, and the business from what could otherwise be seen as a technology-centric initiative.      

Done right, Zero Trust brings a sea change from how most people experience security.  The crossroads of the Zero Trust journey present organizations with two clear choices: stick with an old and not-so-secure security model that’s clunky and burdensome, or adopt a new model that’s more intuitive, easy, and secure.  

Jump start your own journey

Today, the same opportunity exists to transform government security, operations, and organizational models by implementing Zero Trust. By sharing lessons learned from Google’s BeyondCorp journey and building core security capabilities into many of our cloud products, our goal is to help government agencies  accelerate their own Zero Trust journey, transforming the security posture of their highest value and most-critical applications and data.  

To learn more, watch our on-demand sessions from the Google Cloud Government Security Summit,

About the authors

Dan Prieto previously served in the White House as Director for Cybersecurity Policy on the staff of the National Security Council.  He also served as CTO and Director of the Defense Industrial Base Cybersecurity Program in the Office of the Department of Defense CIO.

Max Saltonstall tells stories about Google Cloud, how we use similar Cloudy tools inside Google, and what diverse solutions Cloud’s many customers have created. At Google he’s worked within DoubleClick, Corporate Engineering, Staffing and the Cloud CTO Office.

Trend Analysis

Connected Data is the Lifeblood of Today’s Retailers: IDC’s 2022 Research

4683

Of your peers have already read this article.

4:00 Minutes

The most insightful time you'll spend today!

The 2022's National Retail Federation (NRF) highlighted emerging themes and technologies dictating the retail industry. The way ahead is in digital along with a mix of physical stores, customer focused web apps, Metaverse and hybrid channels!

For a look ahead at the trends that will animate the retail industry this year, let’s take a look back at the 2022 National Retail Federation (NRF) “Big Show” in NYC.

Attendees at January’s event were treated to tangible examples of how retail challenges are being solved today, including new solutions to help them parse customer expectations and buying patterns, adapt stores into omni-channel experience hubs, and improve data visibility and actionability.

NRF 2022 also took the “omni-channel everything” theme of last year’s show to the logical next level: Enabling the best hybrid experiences. The message came through loud and clear of the importance of integration and interoperability in this new hybrid world – making everything work well together.

The need for modern digital infrastructure to enable this blending of physical and digital retail smoothly is paramount. To that end, technology vendors demonstrated how digital transformation initiatives, such as contactless and real time IoT and mobile applications, need to be built on cloud, edge, and secure connectivity to allow retailers to achieve the modern seamless hybrid retail that today’s consumer wants.

Other prominent themes and technologies highlighted at NRF included: extending engagement in the metaverse, sustainability, physical and digital security, and the agility and adaptability imperative.

The Metaverse and Hybrid (Omni-channel) Experiences


Today, the metaverse is an extension of our lives, enhanced by technology, which exists as a series of virtual worlds. In the future, the metaverse will be an interconnected, endless world where digital and physical lives fully converge. Imagine waiting for an appointment at a real booth on the NRF show floor while your avatar roams a fully fleshed-out digital NRF, meeting other virtual attendees, stopping for coffee at the digital Starbucks, and paying for a coffee that an in-the-flesh Starbucks employee brings to them. Digital and physical selves merge seamlessly in the metaverse, as the worlds draw closer together.

In the metaverse, brands have a digital presence, too. Nike filed seven trademarks late last year, including those for “Nike,” “Just Do It,” and its swoosh logo, and posted openings for virtual designer roles, indicating its intent to make and sell virtual branded sneakers and apparel. It subsequently purchased RTFKT Studios, a company that already makes and sells NFTs and digital sneakers. (In one collaboration with teenage artist FEWOCiOUS, the company sold 600 pair/NFTs of sneakers in just six minutes to the tune of more than $3.1 million.)

The metaverse also opens possibilities for gathering data about consumers and product demand. Imagine a sneaker drop in the virtual world. Certain styles of new kicks sell like gangbusters, giving the brand insight into what might sell IRL, intelligence that leads to trend-right production and less inventory headed for markdown or landfills. The metaverse can be a vehicle for more sustainable operations.

The metaverse further bridges the narrowing gap between digital worlds and physical worlds. Most consumers aren’t outfitting an avatar, but they are moving between online and offline and expect retailers to accommodate those hybrid omni-channel journeys seamlessly. Those demands have accelerated around last-mile delivery and experiences such as buying online and picking up in store (BOPIS) or at curbside, shopping in store and returning merchandise online, adding items to a BOPIS purchase when at the store, or communicating a substitution to the third-party grocery delivery service

Hybrid experiences open opportunities to please the consumer in new ways, but they also add expense and complexity. The need to meet this demand while enabling profitability was a major theme behind many of the technologies discussed at NRF. These included artificial intelligence (AI) for recommending the right product, return logistics software for defining and guiding product-specific reverse logistics workflows, order orchestration and fulfillment applications for omni-channel shopping, and last-mile delivery visibility for optimizing customer experience, to name a few. Also on display were task management applications help to improve and optimize in-store employee engagement, as well as touch-free applications to allow for faster payments and customer self-service checkout. RFID continues to improve inventory accuracy and inventory locating on the shelf, throughout the store, and the supply chain.

Sustainability


NRF 2022 saw a strong focus on sustainability. An NRF/IBV study released at the show highlighted the significant embrace of sustainable shopping by consumers. According to the survey, 62% of shoppers are “willing to change their purchasing habits to reduce environmental impacts.” About half indicated a willingness to pay a premium – on average a 70% premium – for sustainable products and brands.

Retailers are working to improve sustainability and reduce carbon footprint across operations by using sustainable sourcing through the supply chain, the store, and even returns. Tech vendors unveiled a variety of solutions enabled by cloud/edge, AI, computer vision, and IoT/RFID to allow retailers to effectively measure and record their environmental efforts, with the goal of reducing their impact.

Several cloud and digital infrastructure providers showcased sustainability clouds and other technology aimed at asset management with the goal of reducing energy consumption, water usage, waste. Examples included using IoT sensors to reduce water usage, optimizing re-use of store assets, and dashboards that allow retailers to accurately monitor and measure carbon output. However, such sustainability solutions can be most successful when running on the next-generation digital infrastructure that helps retailers better compete and differentiate in today’s omni-channel world.

Physical and Digital Security


According to a 2021 NRF survey, 57% of U.S. retailers reported the pandemic led to an increase in organized retail crime, while 50% reported an increase in shoplifting. When IDC’s Future Enterprise Resiliency & Spending Survey, Wave 10 (November 2021) asked retailers which digital infrastructure investments would provide the greatest strategic advantage in 2022, their #1 response was “cybersecurity and recovery investments.”

A wide range of technology vendors acknowledged retailer concerns with regards to security, fraud, and loss prevention:

  • Networking, connectivity, and edge vendors highlighted multilayer security solutions that promise to protect data from a range of IoT applications that utilize customer and associate data. Many offer security consulting services to address varied threats including ransomware, retail crime, and loss prevention.
  • Security and e-commerce security vendors showcased solutions to prevent fraud and abuse in e-commerce applications as well as omni-channel applications such as BOPIS and curbside pickup, using AI-based analysis for identifying “bad”/risky customers and mitigating risk.
  • Cloud vendors highlighted how retail clouds provide consistent, reliable identity management and data security.
  • POS/payments/store technology vendors emphasized their ability to handle payments securely from any platform with multifactor tokenization, improved identity techniques such as biometrics and voice authentication, as well as AI-enabled and computer vision solutions for loss prevention at checkout and at the door.

The Agility and Adaptability Imperative


On display at the show were multiple flavors of the digital infrastructure technology that retailers need to achieve agile, personalized, data-driven, integrated seamless operations across the many channels of today’s retail landscape. The emphasis was apt. More than half of retailers plan to boost investment in business agility and operational agility over the next 12 months, according to IDC’s Future Enterprise Resiliency & Spending Survey, Wave 10 (November 2021).

Technology vendors highlighted their connectivity investments to enable business and operational agility and their technology investments for better ease of integration, scalability, and the ability to more easily swap out or mix and match applications with integrated platforms, open systems, hybrid cloud, and retail industry clouds.

Vendors also showed off infrastructure to better harness data while enabling its visibility, maximizing its value, and providing the data-driven personalization essential for competitive advantage and differentiation. Highlights included fast, secure connectivity, 5G and Wifi-6, and edge- and cloud-enabled data and AI platforms to generate real-time insights – all designed to enable today’s omni-channel retail.

Advice for the technology buyer


Retailers should consider these key themes from NRF 2022 when making technology investment decisions for 2022 and beyond. To avoid lagging behind those retailers already moving toward thriving into the future, take action to:

  • Enable the seamless, contactless omni-channel approach that today’s consumers want and expect.
  • Replace legacy infrastructure that was not built to handle the modern retail environment that requires the agility and adaptability to seamlessly connect rapidly increasing volumes of data securely and more quickly than ever.

Whether sustainability, adaptability, the metaverse, or security are top concerns, addressing business needs holistically and strategically should be job #1.

Continue the conversation by downloading our Transforming retail and CPG markets whitepaper today.

Blog

Ubuntu Pro Images Now Available on Google Cloud

4825

Of your peers have already read this article.

2:00 Minutes

The most insightful time you'll spend today!

Google announces the general availability of Ubuntu Pro images on Google Cloud. The new version of Canonical's Ubuntu includes security updates, expanded coverage, and integration with Google Cloud features to better the customers' experience.

Today, we’re pleased to announce the general availability of Ubuntu Pro images on Google Cloud, providing customers with an improved Ubuntu experience, expanded security coverage, and integration with critical Google Cloud features. In partnership with Canonical, we’re making it even easier for customers that have fully embraced open source to ensure security and compliance for their most mission-critical and enterprise workloads.

With Ubuntu Pro on Google Cloud, you  now have access to features like:

  • 10-year lifetime security updates – Canonical backs Ubuntu Pro for 10 years with security updates and a guaranteed upgrade path.
  • FIPS & CC-EAL2 certification – Ubuntu Pro includes components that meet requirements from entities like FedRAMP, HIPAA, ISO, and PCI.
  • Open-source security coverage – Protect your most important open-source workloads including MongoDB, Apache Kafka, Redis, NGINX, and PostgreSQL.
  • Multi-version availability – Pro images are available for the three most popular Ubuntu Server distributions: 16.04 LTS, 18.04 LTS, and 20.04 LTS.
  • Kernel Livepatch – Kernel patches are delivered immediately without having to reboot your VMs.
  • Optional CIS and DISA STIG profiles – Choose from two leading profiles to harden your environment according to industry benchmarks.
  • Cloud-based pricing – Ubuntu Pro does not require a contract, and pricing tracks with the underlying compute cost depending on the instance type.

Extended Security Maintenance (ESM) for Ubuntu 16.04 LTS with Ubuntu Pro

Availability of Ubuntu Pro images is especially important if you’re an Ubuntu 16.04 LTS customer and want extended security maintenance (ESM) for your virtual machines but don’t want to upgrade to Ubuntu 18.04 LTS or Ubuntu 20.04 LTS versions immediately. ESM is included with Ubuntu Pro 16.04. You can move your workloads from Ubuntu 16.04 LTS VM instances to Ubuntu Pro 16.04 instances to continue receiving ESM and all the above-mentioned benefits, without having to test your applications on a new version of the OS.

gojek.jpg

Gojek has evolved from offering just ride-hailing to a suite of more than 20 services today, serving everyday solutions for millions of users across Southeast Asia.

“We needed more time to comprehensively test and migrate our Ubuntu 16.04 LTS workloads to Ubuntu 20.04 LTS, which would mean stretching beyond the standard maintenance timelines for Ubuntu 16.04 LTS. With Ubuntu Pro on Google Cloud, we now have the ability to postpone this, and in moving our 16.04 workloads to Ubuntu Pro, we benefit from its live kernel patching and improved security coverage for our key open source components.”—Kartik Gupta, Engineering Manager for CI/CD & FinOps at Gojek

“With the launch of Ubuntu Pro on Google Cloud, we build on our joint investments with Google to optimize Ubuntu performance on Google Cloud, and add comprehensive security patching and Long Term Support for another 30,000 open source packages—the widest range of security-maintained open source on the planet,” said Mark Shuttleworth, CEO of Canonical. “As the world moves to open source for everything, Canonical offers the safety net of security maintenance that enterprises count on to unleash their developers.”

Getting started

Getting started with Ubuntu Pro on Google Cloud is simple. You can now purchase these premium images directly from Google Cloud by selecting Ubuntu Pro as the operating system straight from the Google Cloud Console.

To learn more about Ubuntu Pro on Google Cloud, please visit the documentation page and read the announcement from Canonical.

Blog

Latest News: Secure Digital Infrastructure Services with Apigee Advanced API Security for Google Cloud

4467

Of your peers have already read this article.

3:30 Minutes

The most insightful time you'll spend today!

To help customers more easily address their growing API security needs, Google Cloud is announcing the Preview of Advanced API Security, a comprehensive set of API security capabilities built on Apigee, our API management platform.

Organizations in every region and industry are developing APIs to enable easier and more standardized delivery of services and data for digital experiences. This increasing shift to digital experiences has grown API usage and traffic volumes. However, as malicious API attacks also have grown, API security has become an important battleground over business risk.

To help customers more easily address their growing API security needs, Google Cloud is announcing today the Preview of Advanced API Security, a comprehensive set of API security capabilities built on Apigee, our API management platform. Advanced API Security enables organizations to more easily detect security threats. Here’s a closer look at the two key functionality included in this launch: identifying API misconfigurations and detecting bots.

Identify API misconfigurations


Misconfigured APIs are one of the leading reasons for API security incidents. In 2017, Gartner® predicted that by 2022 API abuses will be the most frequent attack vector resulting in data breaches for enterprise web applications. Today, our customers tell us application API security is one of their top concerns, which is supported by an independent study from 2021 by Fugue and Sonatype. The report found that misconfigurations are the number one cause of data breaches, and that “too many cloud APIs and interfaces to adequately govern” are frequently the main point of attack in cyberattacks.

While identifying and resolving API misconfigurations is a top priority for many organizations, the configuration management process can be time consuming and require considerable resources.

Advanced API Security can make it easier for API teams to identify API proxies that do not conform to security standards. To help identify APIs that are misconfigured or experiencing abuse, Advanced API Security regularly assesses managed APIs and provides API teams with a recommended action when configuration issues are detected.

Advanced API Security identifies misconfigured API proxies, including the missing CORS policy.


Advanced API Security identifies misconfigured API proxies, including the missing CORS policy.
APIs form an integral part of the digital connective tissue that make modern medicine run smoothly for patients and healthcare staff. One common healthcare API use case occurs when a healthcare organization inputs a patient’s medical coverage information into a system that works with insurance companies. Almost instantly, that system determines the patient’s coverage for a specific medication or procedure, a process which is enabled by APIs. Because of the often-sensitive personal healthcare data being transmitted, it is important that the required authentication and authorization policies are implemented so that only authorized users, such as an insurance company, can access the API.

Advanced API Security can detect if those required policies have not been applied, an alert which can help reduce the surface area of API security risks. By leveraging Advanced API Security, API teams at healthcare organizations can more easily detect misconfiguration issues and can reduce security risks to sensitive information.

Detect Bots


Because of the increasing volume of API traffic, there is also an increase in cybercrime in the form of API bot attacks—the automated software programs deployed over the Internet for malicious purposes like identity theft.

Advanced API Security uses pre-configured rules to help provide API teams an easier way to identify malicious bots within API traffic. Each rule represents a different type of unusual traffic from a single IP address. If an API traffic pattern meets any of the rules, Advanced API Security reports it as a bot.

Additionally, Advanced API Security can speed up the process of identifying data breaches by identifying bots that successfully resulted in the HTTP 200 OK success status response code.

Advanced API Security helps visualize Bot traffic per API proxy.


Financial services APIs are frequently the target of malicious bot attacks due to the high-value data that is processed. A bank that has adopted open banking standards by making APIs accessible to customers and partners can use Advanced API Security to make it easier to analyze traffic patterns and identify the sources of malicious traffic. You may experience this when your bank allows you to access your data with a third-party application. While a malicious hacker could try to use a bot to access this information, Advanced API Security can help the bank’s API team to identify and stop malicious bot activity in API traffic.

API Security at Equinix


Equinix powers the world’s digital leaders, bringing together and interconnecting infrastructure to fast-track digital advantage. Operating a global network of more than 240 data centers with a 99.999% or greater uptime, Equinix simplifies global interconnections for organizations, saving customers time and effort with the Apigee API management platform.

“A key enabler of our success is Google’s Apigee, delivering digital infrastructure services securely and quickly to our customers and partners,” said Yun Freund, senior vice president of Platform at Equinix. “Security is a key pillar to our API-first strategy and Apigee has been instrumental in enabling our customers to securely bridge the connections they need for their businesses to easily identify potential security risks and mitigate threats in a timely fashion. As our API traffic has grown, so has the amount of time and effort required to secure our APIs. Having a bundled solution in one managed platform gives us a differentiated high-performing solution.”

Getting started


To learn more, check out the documentation or contact us to request access to get started with Advanced API Security.

To learn more about API security best practices, please register to attend our Cloud OnAir webcast on Thursday, July 28th, 2:00 pm PT.

Case Study

Google Maps Platform Can Elevate FinTech Experience with Less Risks and Higher Security

4736

Of your peers have already read this article.

3:00 Minutes

The most insightful time you'll spend today!

Financial services firms can use Google Maps Platform for higher CX, better security and lesser risk! See these two case studies of fintech companies responding to customers preferences and our technical guidance on utilizing Google Maps Platform.

The financial services industry is changing—an estimated $68 trillion in wealth transferring from baby boomers to millennials.1 This means financial service providers will have to deliver the speed, ease-of-use, technological sophistication, and tailored services that millennials have come to expect. In fact, half of all millennials are willing to switch to a competing institution if it offers a better digital experience.2 This and many other trends are driving unprecedented growth for mobile Fintech experiences in banking, digital payments, financial management and insurance.3

Google Maps Platform financial services solutions

To help you respond to customer’s changing demands, we’re launching financial services solutions that can help you improve your customer experience, security and operations. We’ve outlined the technical guidance and APIs you need to build out three financial services solutions: Enriched Transactions, Quick and Verified Sign-up, and Branch and ATM Locator Plus. We’ve also highlighted two use cases that customers are using our APIs to solve: Contextual Experiences and Fraud Detection. 

Clarify financial statements with Enriched Transactions solution

Transaction statements are often hard for customers to understand, using abbreviations like “ACMEHCORP” instead of customer-facing names like “Acme Houseware”. Our Enriched Transactions solution clarifies these transactions and makes them instantly recognizable by adding the merchant name and business category, a photo of the storefront, its location on a map, and full contact info. Making transactions easier to recognize not only boosts consumer confidence, with reported increases in NPS of 15% or higher, but decreases costly support calls by approximately 67%.4

In addition, you can help customers easily visualize a series of transactions by adding the merchant name to the transaction amount and date, and displaying their transactions on a Google map. This enables you to give customers insights about where and how they spend money. See the guide to implement Enriched Transactions today.

Enriched transactions - before
Before: Traditional transaction summary
Enriched transactions - after
After: Enriched Transactions view

Enable faster sign-up with Quick and Verified Sign-up solution

Manually entered addresses can lead to lowered conversions, erroneous customer data, and costly delivery mistakes. Our Quick and Verified Sign-up solution makes sign-up faster, suggesting nearby addresses with just a few thumb taps—cutting sign-up time by up to 64% and increasing conversion rates by up to 15%. 

The solution also provides one additional level of address verification that helps reduce the risk of fraudulent account sign-ups—and companies have decreased fraudulent account setups by approximately 30% through using geospatial data to verify customer identities.4  See the Quick and Verified Sign-up solution guide to get started today.

  • Faster sign-ups 1An application form requires an address
  • Faster sign-ups 2Autocomplete quickly suggests addresses
  • Faster sign-ups 3Select the address with visual confirmation
  • Faster sign-ups 4Address verification options are presented
  • Faster sign-ups 5Location permission is granted by the user
  • Faster sign-ups 6The address is verified

Help customers visit you with Branch and ATM Locator Plus solution

74% of customers now search for specific details prior to their visit, which makes detailed, accurate profiles for each location a must.5 Our Branch and ATM Locator Plus solution enhances your own websites and apps with the same information shown about your branches and ATMs on Google Maps. Include hours of operation, available services, user reviews, photos of the location, driving directions and more.

Financial services companies using geospatial data to provide additional information (e.g. opening hours, available services, etc.) on branch and ATM services have seen a 14% increase in Net Promoter Score (NPS), and a 7% decrease in customer support calls.4  Implement Branch and ATM Locator Plus today using the guide or build it in minutes with Quick Builder.

  • ATM locator 1Customers can enable location permissions, or enter their address
  • ATM locator 2Quickly enter the address with Autocomplete
  • ATM locator 3Nearby location listings, ranked by distance and ETA
  • ATM locator 4Map view and directions

Enable offers and rewards with Contextual Experiences                    

Real-time, geo-targeted offers can power deals, rewards, and cash-back programs—all visualized with rich Google Maps. By combining the insights of purchase histories with customer opt-in to location-based features, companies can implement the Contextual Experiences use case to enable personalized offers and rewards programs that drive engagement with brands while putting money in customers’ pockets at the same time.This is a win for banks and their customers, validated by encouraging metrics like NPS rating boosts of 8% or higher, and an increase of 8% or more time spent in-app.4  Learn how Current uses Google Maps Platform to create innovative customer rewards programs with location intelligence.

Contextual experiences 1
Present nearby offers
Contextual experiences 2
Connect the customer to the offer they want

Detect suspicious transactions with Fraud Detection

With the Fraud Detection use case, companies can use customer opted-in mobile device location to flag suspicious activity based on geographic distance, such as an ATM withdrawal that is far from the customer’s phone. Our APIs can also help companies recognize suspicious transaction patterns such as a purchase made at a location that is physically distant from a recent transaction. 

Financial services companies that use geospatial data to verify customers’ identities have reduced fraudulent transactions by approximately 70%, and false positives in fraud detection by 45%, on average.4  Learn how Starling Bank uses Google Maps Platform to enable real-time notification of transactions and their locations, and enhance data-driven decision-making.

Start elevating customer experiences, reducing risk and increasing efficiency today with our financial services offerings. Visit our financial services solutions page to learn more about how to start implementing these solutions.

For more information on Google Maps Platform, visit our website.

Blog

One Goal for Google: Get PQC Ready

2898

Of your peers have already read this article.

3:30 Minutes

The most insightful time you'll spend today!

Team Google is working with many enterprises to ensure they are crypto-agile and to help them prepare for the PQC transition. We’re well into a multi-year effort to migrate to post-quantum cryptography that is designed to protect sensitive data.

The National Institute of Standards and Technology (NIST) on Tuesday announced the completion of the third round of the Post-Quantum Cryptography (PQC) standardization process, and we are pleased to share that a submission (SPHINCS+) with Google’s involvement was selected for standardization. Two submissions (Classic McEliece, BIKE) are being considered for the next round. 

We want to congratulate the Googlers involved in the submissions (Stefan Kölbl, Rafael Misoczki, and Christiane Peters) and thank Sophie Schmieg for moving PQC efforts forward at Google. We would also like to congratulate all the participants and thank NIST for their dedication to advancing these important issues for the entire ecosystem.

This work is incredibly important as we continue to advance quantum computing. Large-scale quantum computers will be powerful enough to break most public-key cryptosystems currently in use and compromise digital communications on the Internet and elsewhere. The goal of PQC is to develop cryptographic systems that safeguard against these potential threats, and NIST’s announcement is a critical step toward that goal. Governments in particular are in a race to secure information because foreign adversaries can harvest sensitive information now and decrypt it later.  

At Google, our work on PQC is focused on four areas: 1) driving industry contributions to standards bodies;  2) moving the ecosystem beyond theory and into practice (primarily through testing PQC algorithms); 3) taking action to ensure that Google is PQC ready; and 4) helping customers manage the transition to PQC. 

Driving industry contributions to a range of standards bodies 

In addition to our work with NIST, we continue to drive industry contributions to international standards bodies to help advance PQC standards. This includes ISO 14888-4, where Googlers are the editors for a standard on stateful hash-based signatures. More recently, we also contributed to the IETF proposal on data formats, which will define JSON and CBOR serialization formats for PQC digital signature schemes. These standards, collectively, will enable large organizations to build PQC solutions that are compatible and ease the transition globally.

Moving the ecosystem beyond theory and into practice: Testing PQC algorithms

We’ve been working with the security community for over a decade to explore options for PQC algorithms beyond theoretical implementations. We announced in 2016 an experiment in Chrome where a small fraction of connections between desktop Chrome and Google’s servers used a post-quantum key-exchange algorithm, in addition to the elliptic-curve key-exchange algorithm that would typically be used. By adding a post-quantum algorithm in a hybrid mode with the existing key-exchange, we were able to test its implementation without affecting user security. 

We took this work further in 2019 and announced a wide-scale post-quantum experiment with Cloudflare. We worked together to implement two post-quantum key exchanges, integrated them into Cloudflare’s TLS stack, and deployed the implementation on edge servers and in Chrome Canary clients. Through this work, we learned more about the performance and feasibility of deployment in TLS of two post-quantum key agreements, and have continued to integrate these learnings into our technology roadmap.  

In 2021, we tested broader deployment of post-quantum confidentiality in TLS and discovered a range of network products that were incompatible with post-quantum TLS. We were able to work with the vendor so that the issue was fixed in future firmware updates. By experimenting early, we resolved this issue for future deployments.

Taking action to ensure that Google is PQC ready

At Google, we’re well into a multi-year effort to migrate to post-quantum cryptography that is designed to address both immediate and long-term risks to protect sensitive information. We have one goal: ensure that Google is PQC ready. Internally, this effort has several key priorities, including securing asymmetric encryption, in particular encryption in transit. This means using ALTS, for which we are using a hybrid key-exchange, to secure internal traffic; and using TLS (consistent with NIST standards) for external traffic. A second priority is securing signatures in the case of hard-to-change public keys or keys with a long lifetime, in particular focusing on hardware, especially hardware deployed outside of Google’s control. 

We’re also focused on sharing the information we learn to help others address PQC challenges. For example, we recently published a paper that includes PQC transition timelines, leading strategies to protect systems against quantum attacks, and approaches for combining pre-quantum cryptography with PQC to minimize transition risks. The paper also suggests standards to start experimenting with now and provides a series of other recommendations to allow organizations to achieve a smooth and timely PQC transition.

Helping customers manage the transition to PQC

At Google Cloud, we are working with many large enterprises to ensure they are crypto-agile and to help them prepare for the PQC transition. We fully expect customers to turn to us for post-quantum cloud capabilities, and we will be ready. We are committed to supporting their PQC transition with a range of Google products, services, and infrastructure. As we make progress, we will continue to provide more PQC updates on Google core, cloud, and other services, and updates will also come from Android, Chrome and other teams. We will further support our customers with Google Cloud transformation partners like the Google Cybersecurity Action Team to help provide deep technical expertise on PQC topics. 

Additional References:

More Relevant Stories for Your Company

Whitepaper

Google Cloud Leads the Pack Among Data Security Vendors: Forrester

In its 25-criterion evaluation of data security portfolio providers, Forrester identified the 13 most significant ones and researched, analyzed, and scored them. Here's a summary of what Forrester said about Google Cloud Google puts cloud and cloud security at the center of its strategy. Capabilities from Google Cloud Platform, G Suite,

Research Reports

IT Leaders are Prioritizing Organizations’ Sustainability Goals: Study Finds

The global-wide interruptions of the coronavirus pandemic provided the opportunity for businesses to take a closer look at how we work, learn, live, and consume. With work stoppages and quarantine orders in place, carbon emissions and pollution levels saw significant reductions, highlighting how business and environmental sustainability are linked. As

Blog

Google Cloud’s Metric Scope Makes Multi-project Monitoring Simple

Customers need scale and flexibility from their cloud and this extends into supporting services such as monitoring and logging. Google Cloud’s Monitoring and Logging observability services are built on the same platforms used by all of Google that handle over 16 million metrics queries per second, 2.5 exabytes of logs per month, and over

E-book

Security in the Cloud: Google’s Answer

Protecting a global network against persistent and constantly evolving cyber threats is one of the most important challenges faced by Google Cloud. So, how does Google’s global network protects seven different global businesses, each with over 1 billion customers, including popular Google services such as Google Search, YouTube, Maps, and

SHOW MORE STORIES