Vulnerable AWS Lambda Function – Initial Access in Cloud Attacks

June 10, 2022 | 233 views

cloudsecurityalliance
Our security research team prepared to explain a real attack scenario from the black box and white box perspective on how a vulnerable AWS Lambda function could be used by attackers as initial access into your cloud environment. Finally, we show the best practices to mitigate this vector of attack.

Serverless is becoming mainstream in business applications to achieve scalability, performance, and cost efficiency without managing the underlying infrastructure. These workloads are able to scale to thousands of concurrent requests per second. One of the most used Serverless functions in cloud environments is the AWS Lambda function.

One essential element of production raising an application is security. An error in code or a lack of user input validation may cause the function to be compromised and could lead the attackers to get access to your cloud account.

About AWS Lambda function
AWS Lambda is an event-driven, serverless compute service which permits the execution of code written in different programming languages and automates actions inside a cloud environment.

One of the main benefits of this approach is that Lambda runs our code in a highly available compute infrastructure directly managed by AWS. The cloud provider takes care of all the administrative activities related to the infrastructure underneath, including server and operating system maintenance, automatic scaling, patching, and logging.

The user can just use the service implementing their code and the function is ready to go.

Security, a shared pain
From a security perspective, due to its nature to be managed by the cloud provider but still configurable by the user, even the security concerns and risks are shared between the two actors.

Since the user doesn’t have control over the infrastructure behind a specific Lambda function, the security risks on the infrastructure underneath are managed directly by the cloud provider.

Using AWS IAM, it’s possible for the user to restrict the access and the permitted actions of the lambda function and its components. Misconfiguration on permission over IAM roles or objects used by the Lambda function might cause serious damage, leading attackers inside the cloud environment. Even more importantly, the code implemented into the Lambda function is under user control and, as we will see in the next sections, if there are security holes into the code, the function might be used to access the cloud account and move laterally.

Attack Scenarios
We are going through two attack scenarios using two different testing approaches: black box and white box testing, which are two of the main testing approaches used in penetration testing to assess the security posture of a specific infrastructure, application, or function.

Looking at the Lambda function from a different perspective would help to create a better overall picture of the security posture of our function, and help us better understand the possible attacks and the related risks.

Black box vs white box
In Black box testing, whoever is attacking the environment doesn’t have any information about the environment itself and the internal workings of the software system. In this approach, the attacker needs to make assumptions about what might be behind the logic of a specific feature and keep testing those assumptions to find a way in. For our scenario, the attacker doesn't have any access to the cloud environment and doesn’t have any internal information about the cloud environment or the functions and roles available in the account.

In White box testing, the attacker already has internal information which can be used during the attack to achieve their goals. In this case, the attacker has all the information needed to find the possible vulnerabilities and security issues.

For this reason, white box testing is considered the most exhaustive way of testing. In our scenario, the attacker has read-only initial access in the cloud environment and this information can be used by the attacker to assess what is already deployed and better target the attack.

In this attack scenario the attacker found a misconfigured S3 bucket open to the public where there are different files owned by the company.

The attacker is able to upload files into the bucket and check the files configuration once uploaded. A Lambda function is being used to calculate the tag for each file uploaded, although the attacker doesn’t know anything about the code implemented in the lambda.

We can be pretty confident there is an AWS Lambda function behind those values. The function appears to be triggered when a new object is created into the bucket. The two tags, Path and Size, seem to be calculated dynamically for each file, perhaps executing OS commands to retrieve information.

We can assume the file name is used to look for the file inside the OS and also to calculate the file size. In other words, the file name might be a user input which is used in the OS command to retrieve the information to put in the tags. Missing a user input validation might lead an attacker to submit unwanted input or execute arbitrary commands into the machine.

In this case, we can try to inject other commands into the file name to achieve remote code execution. Concatenating commands, using a semicolon, is a common way to append arbitrary commands into the user input so that the code would execute them if the user input isn’t well sanitized.

Mitigation
We have seen the attack scenario from the black box and white box perspectives, but what can we do to mitigate this scenario? In the proposed scenario, we covered different AWS components, like S3 buckets and AWS lambda, in which some security aspects have been neglected.

In order to successfully mitigate this scenario, we can act on different levels and different features. In particular, we could:

Disable the public access for the S3 bucket, so that it will be accessible just from inside and to the users who are authenticated into the cloud account.
Check the code used inside the lambda function, to be sure there aren’t any security bugs inside it and all the user inputs are correctly sanitized following the security guidelines for writing code securely.
Apply the least privileges concept in all the AWS IAM Roles applied to cloud features to avoid unwanted actions or possible privilege escalation paths inside the account.
Let’s have a look at all the points mentioned above in detail on how we can enforce those mitigations.

Disable the public access for the S3 bucket
An S3 bucket is one of the key components in AWS used as storage. S3 buckets are often used by attackers who want to break into cloud accounts.

It’s critical to keep S3 buckets as secure as possible, applying all the security settings available and avoiding unwanted access to our data or files.

For this specific scenario, the bucket was publicly open and all the unauthorized users were able to read and write objects into the bucket. To avoid this behavior, we need to make sure that the bucket is available, privately applying the following security settings to restrict the access.

Spotlight

Plex Systems, Inc

The Plex Manufacturing Cloud ushers in a new era of ERP with a complete system designed to power today’s modern manufacturer.

OTHER ARTICLES
CLOUD SECURITY

What Is Cloud-Native and Why Does it Matter for CI

Article | July 11, 2022

Continuous intelligence (CI) relies on the real-time analysis of streaming data to produce actionable insights in milliseconds to seconds. Such capabilities have applications throughout a business. In today’s dynamic marketplace, new CI applications that use data from various sources at any given time might be needed on very short notice.The challenge is how to have the flexibility to rapidly develop and deploy new CI applications to meet fast-changing business requirements. A common approach employed today is to use a dynamic architecture that delivers access to data, processing power, and analytics capabilities on demand. In the future, solutions also will likely incorporate artificial intelligence applications to complement the benefits of traditional analytics. Increasingly, cloud-native is the architecture of choice to build and deploy AI-embedded CI applications. A cloud-native approach offers benefits to both the business and developers. Cloud-native applications or services are loosely coupled with explicitly described dependencies.

Read More
CLOUD SECURITY

Why Microsoft Should Spinoff Its Cloud Business

Article | July 6, 2022

Microsoft currently features old-school solutions that are growing relatively slowly (Office and Windows) and new cloud solutions that are growing tremendously (Dynamics 365 and Azure). If the company stays in its current form, Microsoft stock will keep steadily advancing. But because the company’s total top and bottom lines are never going to increase much more than 30% or 35% per year, the shares are never going to deliver truly huge returns. But that would change if the company was to spin off its rapidly growing cloud businesses. In such a scenario, the current owners of Microsoft stock would receive shares in a cutting edge cloud services company (let’s call it Azure), and shares in a company focused on providing old, mostly PC-based software to businesses and consumers.

Read More
CLOUD SECURITY

Intelligence Giant Upgrading its Cloud Technology

Article | July 8, 2022

With the huge amounts of data in all fields, a future in the cloud is imperative to help deal with this explosion of data, especially in the field of intelligence technology. This is the reason why the US Central Intelligence Agency is updating its cloud technology. The agency has recently released a draft request for proposal for its Commercial Cloud Enterprise contract.The C2E tens of billions contract will be a multi-award commercial cloud computing contract with a five-year base period and two five-year options for a period of performance of up to 15 years, according to nextgov.com.In a March 2019 presentation by the Directorate of Digital Innovation, a division of the CIA, the department outlined its vision for C2E. It would be broad and include infrastructure, platform and software cloud services supporting a broad range of users, with a variety of security clearances and a worldwide presence, as reported by techcrunch.com. The principal C2E Program objective is to acquire cloud computing services directly from commercial cloud service providers with established records for innovation and operational excellence in cloud service delivery for a large customer base,the department stated in the presentation.Apparently, the agency prefers to avoid all the attention that the Pentagon’s JEDI cloud procurement process got, and quietly go about its business.

Read More

AWS tags US$235 million to expand its cloud infrastructure in Latin America

Article | February 10, 2020

Amazon Web Services (AWS) is raising its stake on cloud computing infrastructure in Latin America. Proof of this is that the IT company will use R$1 billion (around US$235 million) to expand its data center in Sao Paulo. These millions will be used for its Data Processing Center located in that part of Brazil. In addition, a portion of these US$235 million will also be used to increase the services it offers to both public and private parties.The move gives reason to suggest that AWS is upping the ante in the future of startups and tech in the region that rely on cloud services to develop their own products.It launched its cloud center in Brazil in 2011 but it’ll be getting some beefing up thanks to these funds. Moreover, AWS has two Edge networks in São Paulo and two in Rio de Janeiro. As well as one in each of the following cities: Bogotá (Colombia), Buenos Aires (Argentina), and Santiago (Chile).The objective of all of this is to be the region’s prime provider of cloud infrastructure and beat out its competition AKA, Google Cloud Platform and Microsoft’s Azure.

Read More

Spotlight

Plex Systems, Inc

The Plex Manufacturing Cloud ushers in a new era of ERP with a complete system designed to power today’s modern manufacturer.

Related News

CLOUD APP DEVELOPMENT, CLOUD APP MANAGEMENT, CLOUD DEPLOYMENT MODELS

GreenPages Introduces FinOps and Cloud Cost Optimization Solution to Help Organizations Maximize IT Investments

Globenewswire | March 30, 2023

GreenPages, a nationally recognized leader in cloud and cybersecurity services, today introduced a new turnkey managed solution designed to help organizations maximize their IT budgets, gain greater insights into their technology and telecom capital expenditures (CapEx), and enhance their information security posture. The new FinOps and Cloud Cost Optimization solution combines GreenPages proprietary FinOps software, Cloud Lighthouse, business VoIP tools from industry-leading telecom providers, and technology expense management (TEM) solutions into an "as a service" solution. CloudLighthouse is a cloud cost optimization tool that enables deep visibility into multi-cloud and hybrid cloud environments. Exclusively available from GreenPages, CloudLighthouse monitors Amazon, Microsoft, and hundreds of other IaaS and SaaS providers to deliver real-time usage reporting visualizations. “Arguably every business today, regardless of size or industry, is seeking greater visibility into, and control over, their IT expenditures,” said Jay Pasteris, CIO and CISO, GreenPages. “GreenPages’ new FinOps and Cloud Cost Optimization bundle helps customers prioritize budget allocation on revenue-generating initiatives and consolidate cloud and telecom spending, while empowering IT, finance, and operations teams to utilize highly accurate and real-time spending data to make strategic business decisions. It also delivers greater visibility into shadow IT activities, which increase the chance that vulnerabilities go undetected by already overworked security teams.” The new bundle enables organizations to reallocate and consolidate IT vendors to maximize budgets, visualize cloud, telecom, and other business expenses to prioritize spending and accelerate business growth. This bundled solution is backed by GreenPages’ comprehensive professional services which continuously assess customers’ IT infrastructure and operational processes, ensuring the delivery of positive business outcomes mapped to their specific requirements. According to data from Enterprise Technology Research (ETR), CIOs and other IT decision-makers originally expected 8 percent budget growth going into 2022. However, ETR’s most recent Macro Survey of more than 1,500 IT decision-makers revealed that expected IT budgets for 2023 will grow at 4.6%. In this current cautious spending environment, GreenPages’ new bundles meet pent-up demand for solutions that will optimize cloud spending, and identify and eliminate vendor and solution redundancies. The new FinOps and Cloud Optimization bundles are offered in two different tiered options to match customers’ specific requirements and budgets, and support on-premise or remote environments. They include: Standard – For mid-market customers needing automated monitoring of their multi-cloud and hybrid cloud environments and enterprise toll-free voice solutions for reliable and cost-effective customer and supplier communications, GreenPages is bundling Cloud Lighthouse with Enterprise Toll-Free solutions from top telecom providers. GreenPages will integrate these numbers into business phone and contact centers to support communication across world-class voice networks. Premium – For mid-market and large enterprises, this option includes all features from the Standard bundle along with automated Technology Expense Management Solutions. By bundling these three solutions, GreenPages is providing visibility and control over the ordering, auditing, and invoicing for customers’ IT and telecom assets—everything from the cloud servers and laptops to the mobile carriers that employee-owned devices connect to when traveling for business. About GreenPages GreenPages is an innovative, digital-first IT and cybersecurity firm that plans, implements, and manages secure, high-performance digital operating environments for leading companies nationwide. It is uniquely positioned with extensive technology expertise in security and cloud to deliver complete infrastructure solutions that enable companies to drive business outcomes and compete in the digitally-driven economy.

Read More

CLOUD APP DEVELOPMENT, CLOUD SECURITY, CLOUD DEPLOYMENT MODELS

Kore.ai Launches Kore.ai AgentAssist for Service Cloud Voice

Kore.ai | February 23, 2023

On February 22, 2023, Kore.ai, a conversation AI platform provider, launched its solution Kore.ai AgentAssist for Service Cloud Voice on Salesforce AppExchange. This solution would benefit its customers with CRM automation, driving user engagement. It would empower customers with AI-powered intelligent virtual assistants to manage their lead generation and sales processes. The conversational AI virtual assistants (IVAs) active on applications would enable users to access those applications through simple voice and text commands. In addition, the IVAs would process a request instantly and present the information within a fraction of a second, accelerating business operations. Its IVAs recognize user intent, tone and sentiment through contextual intelligence and natural language understanding. The solution Kore.ai AgentAssist for Service Cloud Voice is directly available on AppExchange, as it has now integrated with Salesforce company. Launching this solution on the Service Cloud Voice platform would drive contact center productivity. It would automate manual tasks and support agents for customer engagement with contextual information and suggestion for future actions in real-time scenarios, giving enhanced AI user experience. Salesforce AppExchange is a renowned enterprise cloud marketplace that connects software developers, companies, and entrepreneurs worldwide. It interacts with customers of all sizes across various industries for ready-to-install apps and assists Salesforce-certified consultants in solving all kinds of business problems. The statistics say it has achieved about 10 million customer installs, approximately 117,000 peer reviews and more than 7,000 listings. CEO and Founder of Kore.ai, Raj Koneru, said, "The world is fast moving toward an AI-first framework, and we want to provide the best AI solutions to every Salesforce CRM user through this partnership." He added, "The Kore.ai open architecture and no-code platform framework enables an easy integration that brings the benefits of multichannel, conversational experience to Salesforce's exceptional CRM processes. This transforms customer engagement, automation and user interactions with enterprise systems in ways unforeseen before bringing absolute delight." (Source – Cision PR Newswire) About Kore.ai Headquartered in Orlando, Florida, Kore.ai, an IT consulting and services company, chatbot platform builder services, bot platform builder services, AI, NLP, enterprise bots, dialog design, bot marketplace, b2b bots, b2c bots, b2e bots, ML, AI Chatbot and bots, Enterprise and Intelligent Virtual Assistant, Conversational AI, Digital UX, HR Support, IT Helpdesk, Conversational Banking and Commerce, Conversational Agent, experience optimization platform, work-assist, and smart-assist. It has made innovations in Natural Language Understanding (NLU), offering advanced human-to-machine interactions as virtual assistants. Through conversational digital interactions, it has transformed enterprise transactions with their customers, employees, and partners, since 2013.

Read More

CLOUD SECURITY

Workspot Extends Innovative Center of Excellence to Partners Through its Cloud Alliance Program

Businesswire | March 24, 2023

Workspot, the Cloud PC company, announced today that its world-class Center of Excellence (COE), a unique customer advocacy program led by a team of the foremost virtual desktop and public cloud experts, now incorporates the expertise of its Cloud Alliance partners, expanding the reach of the program to drive customer success. With its white-glove Cloud PC implementation framework, the COE has earned Workspot a Net Promoter Score of 80 in its most recent customer survey – the very best in class. With today’s complex enterprise requirements, most customers are not internally equipped with the unique blend of end user computing and multi-cloud skill sets needed for successful Cloud PC implementation. In response to customer needs, Workspot packaged the three key cornerstones of a successful Cloud PC implementation – people, product and process – to form the COE. Now this same, proven framework can be used by Workspot’s elite Cloud Alliance partners, incorporating each partner’s unique capabilities for serving customers. “Six years ago, with the deep expertise of Workspot’s Customer Success Team, it took us only a week to deploy our Workspot cloud workstations and realize value, unlike the months it took to get just one desktop running with on-prem VDI,” said Israel Sumano, Senior Director of Infrastructure at Southland Industries. “Since then, the Center of Excellence has delivered the expertise and innovative tools that enable us to collaborate closely with Workspot on strategic initiatives that make our business more agile and secure. Workspot’s COE is like nothing else I’ve experienced in the virtual desktop industry, and we continue to realize tremendous value from this unique relationship.” “Workspot’s Center of Excellence delivers fast time-to-first-value and ROI for enterprise Cloud PC customers” said Mike Strohl, CEO Entisys360. “As a member of the Cloud Alliance Program, we’ll complement the COE processes and tools with our vast expertise with virtual desktops, thereby enabling us to deliver tremendous value to our customers.” Spearheaded by VP of Customer Success and former Workspot customer Matthew Davidson, the Workspot COE brings together the industry’s best end user computing and cloud experts for an unmatched implementation experience. “When I sat in the customer seat, the customer success team was one of the strongest selling points for Workspot’s Cloud PC solution during the evaluation process,” Davidson reflects. “Ultimately, I was so inspired by the ease of the implementation that I joined the Workspot team to help other companies streamline their digital transformation with Cloud PCs.” To provide expert guidance throughout the implementation process, Workspot leverages Workspot Watch, the company’s big data collection and analysis system, which continuously provides insights into Cloud PC performance and connectivity, proactively identifying root causes and behavioral patterns often before customers are even aware of a problem. In addition to its state-of-the art tools, Workspot uses customer-centric processes and methodologies to ensure long-term success. Between its ADIME methodology, onboarding services, outstanding customer support, customer success update meetings and executive business reviews, Workspot delivers a carefully defined process aimed at business uptime, addressing new requirements and innovating collaboratively. “The Center of Excellence is the foundation of the Workspot Cloud PC success formula,” said Amitabh Sinha, Co-Founder and CEO of Workspot. “Now our Cloud Alliance Partners bring their deep expertise to the COE as well, ensuring a high-quality experience for our joint customers as we deploy Cloud PCs into Microsoft Azure, Google Cloud Platform, and Amazon Web Services.” About Workspot Workspot is the only cloud-native solution that delivers enterprise-class Cloud PCs. This innovative service lets IT securely stream the right compute capabilities for each user, on any device, anywhere they want to work. As the only Cloud PC solution that operates across all the major public clouds - Microsoft Azure, AWS and Google Cloud - Workspot is uniquely positioned to address today’s remote work challenges by providing a multi-cloud and multi-region approach. Simple to deploy, scale and operate, Workspot’s award winning Cloud PC solution benefits IT as well as end users with a seamless work experience that enhances productivity while maintaining the highest performance standards for intensive workloads.

Read More

CLOUD APP DEVELOPMENT, CLOUD APP MANAGEMENT, CLOUD DEPLOYMENT MODELS

GreenPages Introduces FinOps and Cloud Cost Optimization Solution to Help Organizations Maximize IT Investments

Globenewswire | March 30, 2023

GreenPages, a nationally recognized leader in cloud and cybersecurity services, today introduced a new turnkey managed solution designed to help organizations maximize their IT budgets, gain greater insights into their technology and telecom capital expenditures (CapEx), and enhance their information security posture. The new FinOps and Cloud Cost Optimization solution combines GreenPages proprietary FinOps software, Cloud Lighthouse, business VoIP tools from industry-leading telecom providers, and technology expense management (TEM) solutions into an "as a service" solution. CloudLighthouse is a cloud cost optimization tool that enables deep visibility into multi-cloud and hybrid cloud environments. Exclusively available from GreenPages, CloudLighthouse monitors Amazon, Microsoft, and hundreds of other IaaS and SaaS providers to deliver real-time usage reporting visualizations. “Arguably every business today, regardless of size or industry, is seeking greater visibility into, and control over, their IT expenditures,” said Jay Pasteris, CIO and CISO, GreenPages. “GreenPages’ new FinOps and Cloud Cost Optimization bundle helps customers prioritize budget allocation on revenue-generating initiatives and consolidate cloud and telecom spending, while empowering IT, finance, and operations teams to utilize highly accurate and real-time spending data to make strategic business decisions. It also delivers greater visibility into shadow IT activities, which increase the chance that vulnerabilities go undetected by already overworked security teams.” The new bundle enables organizations to reallocate and consolidate IT vendors to maximize budgets, visualize cloud, telecom, and other business expenses to prioritize spending and accelerate business growth. This bundled solution is backed by GreenPages’ comprehensive professional services which continuously assess customers’ IT infrastructure and operational processes, ensuring the delivery of positive business outcomes mapped to their specific requirements. According to data from Enterprise Technology Research (ETR), CIOs and other IT decision-makers originally expected 8 percent budget growth going into 2022. However, ETR’s most recent Macro Survey of more than 1,500 IT decision-makers revealed that expected IT budgets for 2023 will grow at 4.6%. In this current cautious spending environment, GreenPages’ new bundles meet pent-up demand for solutions that will optimize cloud spending, and identify and eliminate vendor and solution redundancies. The new FinOps and Cloud Optimization bundles are offered in two different tiered options to match customers’ specific requirements and budgets, and support on-premise or remote environments. They include: Standard – For mid-market customers needing automated monitoring of their multi-cloud and hybrid cloud environments and enterprise toll-free voice solutions for reliable and cost-effective customer and supplier communications, GreenPages is bundling Cloud Lighthouse with Enterprise Toll-Free solutions from top telecom providers. GreenPages will integrate these numbers into business phone and contact centers to support communication across world-class voice networks. Premium – For mid-market and large enterprises, this option includes all features from the Standard bundle along with automated Technology Expense Management Solutions. By bundling these three solutions, GreenPages is providing visibility and control over the ordering, auditing, and invoicing for customers’ IT and telecom assets—everything from the cloud servers and laptops to the mobile carriers that employee-owned devices connect to when traveling for business. About GreenPages GreenPages is an innovative, digital-first IT and cybersecurity firm that plans, implements, and manages secure, high-performance digital operating environments for leading companies nationwide. It is uniquely positioned with extensive technology expertise in security and cloud to deliver complete infrastructure solutions that enable companies to drive business outcomes and compete in the digitally-driven economy.

Read More

CLOUD APP DEVELOPMENT, CLOUD SECURITY, CLOUD DEPLOYMENT MODELS

Kore.ai Launches Kore.ai AgentAssist for Service Cloud Voice

Kore.ai | February 23, 2023

On February 22, 2023, Kore.ai, a conversation AI platform provider, launched its solution Kore.ai AgentAssist for Service Cloud Voice on Salesforce AppExchange. This solution would benefit its customers with CRM automation, driving user engagement. It would empower customers with AI-powered intelligent virtual assistants to manage their lead generation and sales processes. The conversational AI virtual assistants (IVAs) active on applications would enable users to access those applications through simple voice and text commands. In addition, the IVAs would process a request instantly and present the information within a fraction of a second, accelerating business operations. Its IVAs recognize user intent, tone and sentiment through contextual intelligence and natural language understanding. The solution Kore.ai AgentAssist for Service Cloud Voice is directly available on AppExchange, as it has now integrated with Salesforce company. Launching this solution on the Service Cloud Voice platform would drive contact center productivity. It would automate manual tasks and support agents for customer engagement with contextual information and suggestion for future actions in real-time scenarios, giving enhanced AI user experience. Salesforce AppExchange is a renowned enterprise cloud marketplace that connects software developers, companies, and entrepreneurs worldwide. It interacts with customers of all sizes across various industries for ready-to-install apps and assists Salesforce-certified consultants in solving all kinds of business problems. The statistics say it has achieved about 10 million customer installs, approximately 117,000 peer reviews and more than 7,000 listings. CEO and Founder of Kore.ai, Raj Koneru, said, "The world is fast moving toward an AI-first framework, and we want to provide the best AI solutions to every Salesforce CRM user through this partnership." He added, "The Kore.ai open architecture and no-code platform framework enables an easy integration that brings the benefits of multichannel, conversational experience to Salesforce's exceptional CRM processes. This transforms customer engagement, automation and user interactions with enterprise systems in ways unforeseen before bringing absolute delight." (Source – Cision PR Newswire) About Kore.ai Headquartered in Orlando, Florida, Kore.ai, an IT consulting and services company, chatbot platform builder services, bot platform builder services, AI, NLP, enterprise bots, dialog design, bot marketplace, b2b bots, b2c bots, b2e bots, ML, AI Chatbot and bots, Enterprise and Intelligent Virtual Assistant, Conversational AI, Digital UX, HR Support, IT Helpdesk, Conversational Banking and Commerce, Conversational Agent, experience optimization platform, work-assist, and smart-assist. It has made innovations in Natural Language Understanding (NLU), offering advanced human-to-machine interactions as virtual assistants. Through conversational digital interactions, it has transformed enterprise transactions with their customers, employees, and partners, since 2013.

Read More

CLOUD SECURITY

Workspot Extends Innovative Center of Excellence to Partners Through its Cloud Alliance Program

Businesswire | March 24, 2023

Workspot, the Cloud PC company, announced today that its world-class Center of Excellence (COE), a unique customer advocacy program led by a team of the foremost virtual desktop and public cloud experts, now incorporates the expertise of its Cloud Alliance partners, expanding the reach of the program to drive customer success. With its white-glove Cloud PC implementation framework, the COE has earned Workspot a Net Promoter Score of 80 in its most recent customer survey – the very best in class. With today’s complex enterprise requirements, most customers are not internally equipped with the unique blend of end user computing and multi-cloud skill sets needed for successful Cloud PC implementation. In response to customer needs, Workspot packaged the three key cornerstones of a successful Cloud PC implementation – people, product and process – to form the COE. Now this same, proven framework can be used by Workspot’s elite Cloud Alliance partners, incorporating each partner’s unique capabilities for serving customers. “Six years ago, with the deep expertise of Workspot’s Customer Success Team, it took us only a week to deploy our Workspot cloud workstations and realize value, unlike the months it took to get just one desktop running with on-prem VDI,” said Israel Sumano, Senior Director of Infrastructure at Southland Industries. “Since then, the Center of Excellence has delivered the expertise and innovative tools that enable us to collaborate closely with Workspot on strategic initiatives that make our business more agile and secure. Workspot’s COE is like nothing else I’ve experienced in the virtual desktop industry, and we continue to realize tremendous value from this unique relationship.” “Workspot’s Center of Excellence delivers fast time-to-first-value and ROI for enterprise Cloud PC customers” said Mike Strohl, CEO Entisys360. “As a member of the Cloud Alliance Program, we’ll complement the COE processes and tools with our vast expertise with virtual desktops, thereby enabling us to deliver tremendous value to our customers.” Spearheaded by VP of Customer Success and former Workspot customer Matthew Davidson, the Workspot COE brings together the industry’s best end user computing and cloud experts for an unmatched implementation experience. “When I sat in the customer seat, the customer success team was one of the strongest selling points for Workspot’s Cloud PC solution during the evaluation process,” Davidson reflects. “Ultimately, I was so inspired by the ease of the implementation that I joined the Workspot team to help other companies streamline their digital transformation with Cloud PCs.” To provide expert guidance throughout the implementation process, Workspot leverages Workspot Watch, the company’s big data collection and analysis system, which continuously provides insights into Cloud PC performance and connectivity, proactively identifying root causes and behavioral patterns often before customers are even aware of a problem. In addition to its state-of-the art tools, Workspot uses customer-centric processes and methodologies to ensure long-term success. Between its ADIME methodology, onboarding services, outstanding customer support, customer success update meetings and executive business reviews, Workspot delivers a carefully defined process aimed at business uptime, addressing new requirements and innovating collaboratively. “The Center of Excellence is the foundation of the Workspot Cloud PC success formula,” said Amitabh Sinha, Co-Founder and CEO of Workspot. “Now our Cloud Alliance Partners bring their deep expertise to the COE as well, ensuring a high-quality experience for our joint customers as we deploy Cloud PCs into Microsoft Azure, Google Cloud Platform, and Amazon Web Services.” About Workspot Workspot is the only cloud-native solution that delivers enterprise-class Cloud PCs. This innovative service lets IT securely stream the right compute capabilities for each user, on any device, anywhere they want to work. As the only Cloud PC solution that operates across all the major public clouds - Microsoft Azure, AWS and Google Cloud - Workspot is uniquely positioned to address today’s remote work challenges by providing a multi-cloud and multi-region approach. Simple to deploy, scale and operate, Workspot’s award winning Cloud PC solution benefits IT as well as end users with a seamless work experience that enhances productivity while maintaining the highest performance standards for intensive workloads.

Read More

Events