Oliver Oehlenberg /blogs/author/oliver-oehlenberg/ Digital Experience Innovation & Acceleration Wed, 10 Sep 2025 08:28:07 +0000 en-US hourly 1 https://wordpress.org/?v=7.0.2 Leveraging Observability Data for Downfall and Inception Vulnerability Analysis /blogs/downfall-and-inception-observability/ Thu, 07 Sep 2023 12:07:20 +0000 /?p=73628 In early August 2023, both Intel and AMD confirmed vulnerabilities in their CPUs. Specifically, a security expert named Daniel Moghimi at Google discovered a vulnerability dubbed “Downfall” () in Intel’s chipset. This vulnerability allows attackers to exploit it, potentially gaining access to data from other applications or memory areas. Similarly, researchers Daniel Trujillo, Johannes Wikner, and Kaveh Razavi from ETH Zurich discovered a comparable exploit in AMD’s chipset, which they named “INCEPTION” ().

Fortunately, both exploits have been classified with a severity rating of “Medium” by Intel and AMD. The risk only becomes significant if an attacker manages to execute a piece of code on the vulnerable computer. This can happen, for example, through malware. Once executed, this code can read sensitive information, such as passwords, from the compromised device.

The situation becomes more dangerous when the vulnerable computer is used by multiple individuals, such as in a cloud-based environment. In such cases, a legitimate user can intentionally or unintentionally distribute the code and thus gain access to other users’ data.

How many computers are affected in my organization?

The challenge when that happens for corporate administrators and security officers is to figure out exactly what this means and how many computers in your organization are affected. This becomes especially crucial as both Intel and AMD are already rolling out firmware updates to address the security gap. Prompt installation of these updates is paramount.

Organizations using observability solutions like Ä¢¹½¶ÌÊÓÆµ now have a powerful tool to gain insights into the vulnerability landscape. In the example shown below, I leveraged data from the desktops/laptops to automatically create a list of affected devices. To achieve this, I configured Ä¢¹½¶ÌÊÓÆµ Aternity to retrieve and evaluate additional information such as CPUID and MCU (for Intel) from the CPUs. In practical terms, you only need to import a Custom Device Attribute Monitor into the configuration of Aternity and access the corresponding dashboard. The advantage here is that the CPU data can seamlessly analyzed alongside existing observability data.

Observability Data for Downfall and Inception Vulnerability Analysis

At a glance, it’s evident that 60% of the devices are undeniably affected by the security vulnerability, while an additional 17% require manual inspection due to undetermined firmware versions, yet the CPUs are classified as “affected.”

Plan and monitor your next steps

Some hardware vendors, like Lenovo, already released BIOS or firmware updates to to mitigate this risk. For instance, Lenovo provided an update (Version 1.54) for the ThinkPad T14s Gen 2i. However, here’s where the challenge arises. IT organizations must plan, execute, and validate the successful deployment of these updates. Many companies rely on automatic updates facilitated by hardware manufacturer tools, but the visibility into their effectiveness or user permissions isn’t always clear. This is where observability data becomes invaluable.

Observability Data for Downfall and Inception Vulnerability Analysis

In our example above, we have 16 Lenovo T14s Gen 2i devices, with only one device having the necessary BIOS version to address the vulnerability, while the others have various versions. With this information, the IT department now knows that 15 devices require prompt updates. To facilitate this, the Ä¢¹½¶ÌÊÓÆµ Aternity Remediation Action can be employed.

Observability data can switch on the lights

If you already use Ä¢¹½¶ÌÊÓÆµ Aternity, look for the CPU Vulnerability Analysis Dashboard in the Aternity SE Dashboard Library or reach out to your Ä¢¹½¶ÌÊÓÆµ technical contact. Installation of the Custom Attribute Monitor is essential, and you’ll need a free Custom Attribute within your environment. Further details can be found in the Description page of the Dashboard. In the examples above, we utilized data from desktops and laptops, but observability data can also be sourced from servers in your data center, enabling similar analyses for your server landscape.

If you would like to learn more about Ä¢¹½¶ÌÊÓÆµ, visit our site, and existing users may log in to access the  Visit these pages for further readings on the Intel Advisory, and the AMD Advisory,

]]>
Exploring the Evolution of Digital Workplace Monitoring /blogs/the-user-experience-monitoring-evolution/ Fri, 14 Jul 2023 12:08:00 +0000 /?p=22084 Alluvio by Ä¢¹½¶ÌÊÓÆµ at VWE 2023How is monitoring for the workplace evolving?

The Virtual Workplace Evolution (VWE) stands as one of Germany’s of the largest desktop events, where customers, partners and vendors convene to exchange experiences and share insights on the digital workplace. The special feature of this event is the networking aspect. In presentations, companies share their strategies on how they are tackling current challenges, while solution providers showcase how their technologies are evolving.

Employee experience is omnipresent

The significance of employee experience permeated throughout the event. Companies such as Lufthansa, one of the largest airlines in Europe, have reported how they have transitioned from outsourcing to insourcing, leveraging cloud technologies and standardization for the workplace. In doing so, it has become increasingly clear how important it is to involve employees and stakeholders in the process. TUI Group, a German leisure, travel and tourism company which has realigned its global infrastructure for a hybrid workplace, also emphasized the importance of close stakeholder alignment.

Instead of relying on Microsoft 365, Kärcher, a leading manufacturer of commercial, industrial and consumer cleaning equipment, started using Google Workspace. This transition was executed swiftly yet cautiously, ensuring the inclusion of employees throughout the process.

User Experience Monitoring has arrived on the market

In addition to many companies, a number of software vendors were also represented at the VWE. Among them, the User Experience Monitoring sector had a strong presence, with representatives from ControlUp, Nexthink and Ä¢¹½¶ÌÊÓÆµ. A few years prior, Ä¢¹½¶ÌÊÓÆµ Aternity was the sole User Experience Monitoring vendor present at VWE. This surge in representation stems from the fact that considering user experience and employee experience has become indispensable for the successful implementation of IT projects, making this type of monitoring increasingly prevalent on the market.

Monitoring evolves into observability for the desktop

Alluvio managed devices on VWE 2023However, traditional user experience monitoring also has its limitations, and Ä¢¹½¶ÌÊÓÆµ Aternity in particular is at the forefront of addressing these constraints. Collecting data from end devices and enriching it with survey data, if necessary, is no longer enough. To successfully plan and implement IT projects, the needle must be found in the “haystack” of data. IT must have a clear understanding of what it is looking for. The same is true when companies troubleshoot with desktop monitoring tools. While the data is there, it must be enriched and interpreted using expert knowledge.

My presentation at the VWE highlighted that the future of employee and user experience monitoring lies in observability. Data may need to be enriched from other systems and automatically pre-analyzed and given context so that companies can derive the necessary added value from it. Observability also enables proactive interaction with the data, such as using flow charts to define which actions should be executed when analyzing or resolving specific situations.

Observability and IT data can support ESG and sustainability initiatives

This observability and IT data can also be leveraged to support ESG and sustainability goals. For instance, User Experience Monitoring data can indicate whether an end device remains operational throughout the night without any interaction or active computing work. With this data, various actions can be automatically triggered.

For example, in case the employee only switched off the monitor and left the workstation, the data constellation can be used to automatically execute actions. For instance:

  • The employee can receive a pop-up or survey the next day, reminding them to shut down their computer at night to conserve energy.
  • Additionally, IT could offer an automatic configuration change to put the computer to sleep when not in use for an extended period.

IT can also perform automatic evaluations to determine in advance how much energy or COâ‚‚ can be saved through this feature.

Extend PC lifecycle to 5 to 7 years

HP, as a device manufacturer, addressed ESG and sustainability at the VWE, and demonstrated that workplace devices can be utilized for up to 7 years, thereby reducing the COâ‚‚ footprint. Colleagues also emphasized the importance of ensuring that the PC’s performance does not adversely affect the user experience. This is precisely where observability plays a crucial role. The video below, “IT Asset Cost Reduction for Digital Workplace Teams,” gives a glimpse into the possibilities:

Until next year

The next Virtual Workplace Evolution takes place on June 19-21, 2024 in Berlin. We are already looking forward to reconnecting with our colleagues and industry peers for an inspiring exchange of experiences!

]]>
How Observability and IT Data Can Unlock ESG Success /blogs/how-observability-solutions-can-unlock-esg-success/ Mon, 26 Jun 2023 12:09:00 +0000 /?p=21675 Blocks spelling out ESGCompanies are increasingly placing a bigger emphasis on sustainable activities across their business domains. Recently, the term ESG, which stands for environmental, social, and governance, has gained significant traction. ESG serves as a comprehensive framework for assessing a company’s business practices and performance in relation to sustainability and ethical issues. Additionally, it provides a way to measure business risks and identify opportunities.

While sustainability, ethics, and governance are generally considered non-financial performance indicators, the role of an ESG program is to ensure accountability and implementation of systems and processes to manage a company’s impacts, such as its COâ‚‚ footprint and the way it treats employees, suppliers, and other stakeholders.

The challenge of accurate figures

To establish a trustworthy ESG initiative, businesses must acquire accurate and reliable data from different fields. This challenge is particularly evident in the realm of IT, as illustrated by the following example:

Organizations that maintain their own data centers have the capability of accurately reporting the energy usage of these facilities. By leveraging their personal power circuits and electrical meters, this reporting can be done with great accuracy. However, determining the power consumption of workstation computers, monitors, and printers becomes more challenging, especially when they are located in home offices rather than the company’s own buildings. As a result, estimating the energy consumption of workstation computers is the common practice. Unfortunately, many companies simply take the maximum electricity consumption or published average values for their calculations, leading to highly inaccurate results.

While this inaccurate data is sufficient in providing an overview of the situation, the goal of ESG programs, however, is to drive improvement while considering the cost/benefit. For example, simply replacing an old desktop PC with a modern mini-PC is not necessarily a more sustainable solution. It’s important to account for the COâ‚‚ footprint associated with manufacturing new computers. The key instead is to understand whether users can achieve the same user experience with their existing PCs as with a new one, or if a small upgrade will help enhance efficiency and sustainability.

Observability brings the necessary insights

And this is where Observability helps. Observability represents the next stage in the evolution of IT monitoring and is being implemented in various aspects of IT. The information obtained from this source may find be leveraged in ESG initiatives, especially to make more precise assessments and to better evaluate the cost/benefit question.

This application extends beyond the workplace, where it can help determine how user-friendly and efficient older computers are and whether they should be upgraded or replaced when necessary. It can also identify which applications generate particularly high levels of network traffic, which in turn lead to a corresponding COâ‚‚ impact from the data centers across data networks. With Observability data, it becomes possible to assess, plan, and execute data center consolidations or cloud migration with regards to ESG goals.

Using IT data for the ESG perspective

Woman at computer looking at IT dataIT departments, alongside Observability solution providers like Ä¢¹½¶ÌÊÓÆµ, can make valuable contributions to various ESG initiatives. The data gathered in IT can be harnessed and used for sustainability projects to achieve measurable successes that are also cost-beneficial. It is important to tailor the parameters used in the calculations to the specific situation of each company, considering variables such as the CO2eq/kWh value and energy costs differ from country to country and company to company.

Before starting large ESG projects, IT departments can achieve success with small “quick wins.” It is easy to analyze whether a server in the data center is still operational but no longer in use. Another starting point is to determine whether users are shutting down their computers at the end of the work day or putting them in sleep mode. If not, a simple change to the settings can ensure that the computer is automatically sent to “sleep” after a few minutes of idle time. However, since sustainability is also about fostering awareness, it can be equally effective to make users aware of specific situations automatically to educate them about the impact on the environment.

The data from IT’s observability tools brings more context to sustainability projects, and thereby leads to the discovery of quick wins and opportunities for improvement.

]]>
Improving Digitized Work Processes with DEX /blogs/improve-digitized-work-processes-dex/ Thu, 22 Dec 2022 13:15:00 +0000 /?p=19451 In my last blog article, I drew the comparison between the engine warning light in a car and IT monitoring. But what does that mean in detail? An excellent example is Digital Employee Experience (DEX): This is the warning light that indicates whether IT users are happy with IT or whether there are problems. Most of the time, the biggest dissatisfaction does not come from the fact that the device used is too slow. Most users are not IT experts. They expect a working environment to function as they know it from their computer at home. Designed digitized work processes must be put into use without a great deal of learning effort, and more importantly–that must work.

What is Digital Employee Experience (DEX)?

Companies use email surveys to learn how users feel about their IT services. As the digitalization of many work processes makes IT increasingly important, it is mandatory for IT to perform well in these surveys. However, surveys are only ever a snapshot, which makes monitoring the Digital Employee Experience (DEX) increasingly important.

In these situations, the user’s experience is directly measured on the device itself (for example, a laptop or desktop). The focus is not on checking whether the end device is technically busy or functioning properly. The question is whether users can work fluidly with the applications. It should also be analyzed whether digitized work processes in the applications are perhaps too cumbersome or simply take too long.

Make workflows and digitized work processes visible

frustrated users

At my bank this year, I experienced firsthand what it means when workflows in applications are broken. In my case, it took far too long:  I actually just wanted to open a depot for my daughter so that I could regularly save for an ETF fund. Our bank has digitized the entire process so that all compliance aspects are met, and the bank advisor doesn’t forget a single point.

One would think that opening a depot should therefore be quick. However, the system had several problems:

Since my daughter is still a minor, permission from my wife and me had to be entered beforehand. This meant that our bank advisor had to fill out additional forms digitally. This sounds easier than it was, as something didn’t work in almost every form or took an extremely long time to save. In the end, I was at the bank for over an hour to open a simple depot.

Why is a broken workflow not only an IT issue?

Now, looking at this experience in more detail, some problems are obvious:

  • Very few customers are willing to wait that long and might consider switching banks next time.
  • Faulty workflows or processes don’t just put a strain on IT. Our bank advisor was more than uncomfortable that this didn’t work and she had to apologize to the customer.
  • Digitization should simplify processes and accelerate them, especially in times of a shortage of skilled workers. The goal should be to enable existing employees to do their jobs better and faster. If this isn’t taken into account, productivity will decrease as a result of digitization instead of continuing to rise.
  • Since internal support processes sometimes take a very long time, the relevant IT employees or application managers are notified of these problems far too late. Often, support tickets are no longer opened because the employee concerned does not have the time.

Making workflows technically visible

In our Ä¢¹½¶ÌÊÓÆµ portfolio, there are two products that can make workflows visible:

Ä¢¹½¶ÌÊÓÆµ Aternity is suitable for any type of application (e.g. a classic application or web application) used by employees:

Ä¢¹½¶ÌÊÓÆµ UJI (User Journey Intelligence) is a solution for web applications that helps you understand how people (both internal and external) use them:

In principle, Ä¢¹½¶ÌÊÓÆµ can therefore make workflows visible from any application. In the simplest case, for example, it monitors how long it takes to open the calendar in Microsoft Outlook. The example with my bank is a complex case where several pieces of information from a workflow need to be monitored. An error message is displayed, for example, showing “Form A” has been used and how the user got into this form. At the same time, it is also possible to record how long it takes to save the form.

Aternity Workflow Monitoring

An important aspect is that the measurements provide context to technical elements in order to determine where a fault lies, if any. Not every problem is due to a problem in the application. IT has become so complex that the end device itself, the network or components in the data center/cloud can also be the cause of a poor experience. That’s why Ä¢¹½¶ÌÊÓÆµ combines experience and workflow data with technical data from different perspectives.

EMA Value Leader 2022

In light of this, EMA has ranked us as a Value Leader in the EMA Radar for Digital Employee Experience this year (2022).

If you like what you see and want to try it out for yourself, you can download a free trial here to experience it firsthand. Talk to us if you have any questions!

]]>
When an Engine Warning Light Goes On /blogs/engine-warning-light/ Fri, 25 Nov 2022 13:42:00 +0000 /?p=19335 Engine Warning Light

While on our summer vacation this year with our Volkswagen Van (“Bulli”), the engine warning light came on. Unfortunately, it was still over 700 km to our destination in the south of France. Everyone has experienced something like this, and everyone has the same questions: What does this mean now? Do we have to stop? Where can we find a Volkswagen garage in France, or might we even make it to our destination? Or, do we even have to stop immediately?

And furthermore, what does an engine warning light have to do with IT and monitoring?

How an engine warning light relates to IT and monitoring

Volkswagen Diagnosis System
(c) Volkswagen

If you think about it, we encounter situations just like this in IT as well. Usually when a “warning light” goes on somewhere in an organization, this information is immediately sent to the IT staff responsible for resolving the issue, at which time very similar questions arise as the ones asked on our vacation: What does this mean? Has something completely failed? What effect does this error message now have for the company, our employees and customers?

As with a car, troubleshooting now begins. In modern vehicles, fault diagnosis can almost only be done by the manufacturer or an authorized partner. What is always the same, however, is that a specialist must now evaluate this error message, request further information and data, and then diagnose it either using their expertise or a knowledge base. If a diagnosis is not possible, further specialists or the manufacturer must analyze the problem. Once the diagnosis is ensured, then work can be done to resolve the problem.

How can diagnosis time be reduced?

When an IT failure has an impact on the productivity of employees, or even on customers, a diagnosis must be made as quickly as possible so that a solution can be implemented right away. This is called reducing MTTR (Mean-Time-To-Repair). But how can this be achieved?

Usually, the most difficult challenge in the entire process is making a quick and correct diagnosis. This requires expertise, knowledge of one’s own environment, a structured approach and a lot of experience. Only experienced and specialized employees can use targeted questions to gather all the information needed for a rapid search for the cause—and this is where Ä¢¹½¶ÌÊÓÆµ IQ comes into play.

Ä¢¹½¶ÌÊÓÆµ IQ, Ä¢¹½¶ÌÊÓÆµ’s cloud-native, SaaS-delivered unified observability solution, automatically analyzes problems before any IT staff receive a report. In this process, the “expertise” of the staff is transferred into Ä¢¹½¶ÌÊÓÆµ IQ via a low-code UI. The result is a dashboard/report that contains all the necessary information about a problem, so IT engineers can diagnose it faster, without having to do extensive research.

Get results faster with fewer clicks

Ä¢¹½¶ÌÊÓÆµ IQ enables IT departments to work very much in the same way as authorized car repair garages. Car manufacturers have transferred their expertise to the diagnostic systems so that the engineers receive a pre-analyzed evaluation of a fault or issue in order to quickly start repairing the vehicle. In some cases, car manufacturers also refer directly to a “knowledge base article” on how to resolve the problem.

While Ä¢¹½¶ÌÊÓÆµ IQ isn’t quite there yet, Ä¢¹½¶ÌÊÓÆµ is already working on the next stage to have problems resolved automatically. Until then, Ä¢¹½¶ÌÊÓÆµ IQ has one goal: to keep IT staff from “digging” through a large amount of dashboards and data for a solution. In order to save time and resolve issues faster, IT will pre-analyze problems, much like garages do.

below to see how Ä¢¹½¶ÌÊÓÆµ IQ reduces alert fatigue and Mean-Time-To-Repair:

If you like what you see and want to try it out for yourself, you can download a free trial here to experience it firsthand. Talk to us if you have any questions!

]]>