×
[searchandfilter taxonomies="search"]

Appsian Customer, Hackensack Meridian Health, Honored as PeopleSoft Innovator at Oracle OpenWorld

By Scott Lavery • October 24, 2018

This week, Hackensack Meridian Health (HMH), a New Jersey-based not-for-profit health care organization (and Appsian customer) was identified as a PeopleSoft Innovator for their use of PeopleSoft Fluid UI for HCM Employee Self Service; including the successful native implementation of Appsian’s two-factor authentication solution.

With an initiative to make PeopleSoft available to their 33,000 users via the open internet, HMH began an adoption of Fluid for HCM in early 2018. A “mission critical” objective to this project was pairing Fluid with a solution that provided secure access, while also limiting the amount of clicks and passwords required for users to access PeopleSoft.

HMH turned to Duo as the selected two-factor authentication platform, but still required a solution that natively integrated into PeopleSoft to extend Duo’s functionality. Appsian’s PeopleSoft Application Security Platform was evaluated and quickly selected as the right solution to ensure HMH’s project to make PeopleSoft available to the open internet (via Fluid) was successful.

As an Innovator, Hackensack Meridian Health has been included in the new PeopleSoft Innovators section on www.peoplesoftinfo.com and was announced as an Innovator during the 2018 Oracle OpenWorld conference.

To learn more about Appsian’s solutions for PeopleSoft security, please email us at info@stgappsian.wpengine.com or your can simply Request a Demo

Put the Appsian Security Platform to the Test

Schedule Your Demonstration and see how the Appsian Security Platform can be tailored to your organization’s unique objectives

Appsian Name Change FAQ

By Scott Lavery • September 11, 2018

Can’t find your answer? Email us at info@appsian.com

Why are you changing your brand?

We are rebranding in order to position our organization as a leading security and user experience provider for PeopleSoft customers. The new name reflects our mission to make PeopleSoft exceptional and our commitment to invest in our existing software platform.

Does the new name signal a change in offering?

No. We will continue to enhance our security and UX offerings. We plan to accelerate investment in our platform and partner with Oracle to help PeopleSoft customers achieve a better ROI from their investments in PeopleSoft.

In addition, we will continue to work with our partners to ensure they reference Appsian consistently.

What does this change for our existing customers?

Nothing changes other than the name.  Our customers should expect the same great service and products as they have grown accustomed to receiving from our organization.

Will we be changing the website and email?

Yes, our new wesbite will be Appsian.com. All of our employee email will transition from …@greyheller.com to …@stgappsian.wpengine.com.

Will the support portal be changing?

The support portal URL of https://support.appsian.com/login will continue to work, but officially the URL will change to https://support.appsian.com/login.  You will notice the branding of the portal will change to support our new name and e-mail notifications will reference the new Appsian URL. Your login ID and password will remain unchanged.

Do we need to update your existing legal contract?

No, all existing legal agreements will stay the same. If you have any specific question, please reach out to shawn.socha@appsian.com

Does this move impact Larry Grey and Chris Heller’s roles in the company?

No, there will be no change in their roles. Chris will continue to be the CTO driving the Security and UX platform. Larry will continue to lead of solution and engineering efforts.

Put the Appsian Security Platform to the Test

Schedule Your Demonstration and see how the Appsian Security Platform can be tailored to your organization’s unique objectives

California Raisin’ the Bar on Data Privacy

By Scott Lavery • July 23, 2018

June was an interesting legislative month in the state of California. 

In the face of an impending ballot initiative that would’ve imposed stringent privacy rules around the retention and use of consumer data, the state legislature stepped in and drafted an alternative privacy law that, in its current form, appears to be a GDPR-lite set of regulations.

Before we discuss the components of the resulting California Consumer Privacy Act of 2018, it is interesting to speculate as to why state legislators stepped in to stop the ballot initiative.  I see three primary factors driving that decision:

1) The ballot initiative contained a provision that specifically prohibited companies from giving away applications (games, etc) in return for the right to monetize the user data of those applications (a common practice.)

2) The ballot initiative imposed draconian penalties on violators

3) Introducing the law via legislation enables the state to evolve and clarify the bill as needed, whereas if implemented via the ballot initiative, it would be much harder to change.

I think we can safely assume that the lobbying of the tech industry led to the scuttling of the data monetization restrictions and the re-examination of penalties.  The California legislature changed the focus of the initiative to follow a version of the already implemented GDPR regulations.

So, in a first for the United States, we have the California Consumer Privacy Law of 2018, which goes into effect on January 1, 2020.

As I mentioned, the regulations are more similar to GDPR than not, but do currently leave out some of GDPR’s more stringent requirements.  The California law contains three key components (and these relate to data associated with any resident of the state of California):

  • Consumers have the right to know what information is being collected about them.
  • Consumers have the right to know why that data is being collected.
  • Consumers have the right to know who that data may be being shared with / sold to.

Many questions arise when looking at these regulations.  Primarily, what is the mechanism that a consumer can employ to obtain this information?

I believe that between now and January 1, 2020, California legislators will be working to better define the scope of the law, the associated penalties and the paths to consumer enablement.

But the law is coming, and it represents the Unites States first real comprehensive attempt to protect consumers and their private information.  I fully expect more states to model similar regulations.

In our next post, we will dive into the differences between GDPR and the current form of the California law.

Put the Appsian Security Platform to the Test

Schedule Your Demonstration and see how the Appsian Security Platform can be tailored to your organization’s unique objectives

Ensure a successful Fluid Enablement project with PeopleUX

By Scott Lavery • July 3, 2018

With the support for PeopleSoft 9.1 ending earlier this year (Jan 2018), most PeopleSoft customers are busy upgrading to PeopleSoft 9.2. As you upgrade to v9.2, Fluid becomes the inevitable frontline UI of your PeopleSoft applications. Consequently, upgrading to Fluid is a significant investment in terms of time, effort, and skilled resources. We at GreyHeller feel that the operational disruption and added investment that come with these upgrades are an extremely worthwhile endeavor for your journey toward a modern UI for PeopleSoft HCM, CRM, Financials, SCM and more. That being said, if productivity and engagement are the benchmarks for success with a UX/UI project, shouldn’t you do everything in your power to ensure your upgrade is fully enabled?

It should be acknowledged that a lack of certain best practices can prevent you from achieving your end goal of delivering the user experience you intended – and your users have come to expect from modern applications. Here are some tips to identify indicators that can potentially have a negative impact on your efforts of achieving a flawless adoption of PeopleSoft Fluid UI:

Fluid is the future – get with it!

Before we get into the details of ensuring a successful Fluid enablement project, let’s address the most crucial question first – Why is making the transition from Classic to Fluid important – and why now? The answer lies in Oracle’s announcement of the traditional Classic UI being on a retirement schedule. Oracle’s support doc ID 2238983.2 illustrates the timeline for pages that will be “desupported” at the end of each year. Since, Fluid is going to be the frontier of all PeopleSoft applications upgraded to 9.2, adopting Fluid has become a necessity for organizations to stay current with PeopleSoft.

Inconsistency can prove to be the death of a positive UX

A Fluid adoption should be a project centered around your end-users. Whether you are in the middle of a Fluid adoption or haven’t embarked upon it yet, it is important to consider the specific business needs of your users carefully (i.e., how are you intending them to work and on what mobile devices.) With the end goal of a Fluid upgrade being PeopleSoft applications that are readily available on mobile devices and with a streamlined user experience – it is ultimately user engagement that will prove to be the defining benchmark for success. However, the selective roll-out schedule of Fluid pages can potentially create an inconsistent UX in the interim, as users are likely to encounter existing Classic pages throughout a workflow. The result being (despite your best intentions) a UX that fails to deliver a 100% consistent experience. After all, inconsistency can prove to be the death of a positive UX.

Fluid requires new development skills

Fluid UI uses the same architectural foundation as the Classic layout. However, building design components in Fluid requires extra development work, meaning the required acquisition of skills such as HTML, CSS, JavaScript, etc. To ensure optimum preparedness for your Fluid enablement project, you need to have developers who are well versed in PeopleTools along with these additional skills. To fulfill project requirements, you can choose to invest your time and money in training existing team members or (like most organizations) you can hire new resources. However, the time spent in acquiring skilled resources can slow down the progress of your Fluid enablement project.

Consider the diversity and abundance of mobile devices.

A myriad of mobile devices are released every year, all with different screen sizes and resolutions. To compliment all the available device variables, your UI needs to be responsive. A truly responsive UI is the most critical parameter in mobilizing an application, thus allowing it to fit perfectly on any form factor. Fluid is an adaptive UI which means that it was designed to fit a predetermined set of form factors, i.e., small, medium, large and extra-large. Since there’s an abundance of mobile devices available on the market, and each one of them comes with different display standards, the pre-set form factors might not display content cleanly on every available screen.

How you can make Fluid UI exceptional with PeopleUX

PeopleUX by GreyHeller delivers a fully responsive and consistent user experience regardless of your current version of PeopleSoft. No matter what your upgrade status or your underlying UI (Classic/Classic Plus or Fluid), PeopleUX re-renders the existing HTML without impacting the original PeopleCode – creating a user experience that is visually engaging and uniform throughout the application. PeopleUX optimizes workflows with usability and intuition in mind, allowing users to execute transactions quickly and efficiently without requiring any additional training or technical support.

 A seamless and consistent user-experience allows users to be more productive no matter where they work or what device they use. The best part – PeopleUX can be implemented in a short span of time (60-90 days*) without any operational disruption or intermittent consistency. Lastly, PeopleUX saves you time and boosts Fluid adoption project ROI by eliminating the need to hire or train developers!

Interested to know more about making the Fluid experience truly exceptional? Request a free demo to speak to a PeopleSoft user experience specialist today, or write to us at info@devappsian.wpengine.com

As a BONUS opportunity – join us on Wednesday July 18th for our latest webinar where you can see for yourself how you can ensure a successful Fluid adoption – Register Today!

Put the Appsian Security Platform to the Test

Schedule Your Demonstration and see how the Appsian Security Platform can be tailored to your organization’s unique objectives

PeopleSoft and GDPR: Accelerate Breach Detection and Remediation

By Scott Lavery • June 25, 2018

The European Union’s General Data Protection Regulation (GDPR) came into effect on May 25th, 2018 and made a far-spreading impact on how organizations record, manage and process personal data of European citizens. As an organization leveraging PeopleSoft, you house personally identifiable information (PII) on hundreds of pages, making your PeopleSoft applications a crucial variable in regards to sustaining GDPR compliance. Even though the security of your PeopleSoft applications has always been your priority, GDPR just upped the ante! Non-compliance with several clauses in GDPR can potentially knockout significant profit margins – 4% of global revenue or € 20 million to be precise.

Discover a data breach? The clock is NOW ticking!

Imagine all the chaos a data breach brings – the investigation, remediation, financial liabilities, and the overwhelming task of drafting an internal and external communication plan. The timeline of this process was previously driven by your organization – now that GDPR is in effect, communications with affected parties and relevant regulatory agencies all must be completed before the GDPR hourglass empties, i.e., in 72 hours. GDPR’s mandate is a clear message that the ‘wait and see’ approach that organizations could once get away with is no longer going to work! To establish compliance with GDPR, organizations need to evaluate all possible means that data can be breached, leaked, or manipulated and focus on equipping their PeopleSoft applications with internally layered security features, most specifically enhanced logging, in an effort toward being proactive rather than reactive.

Step 1 to GDPR compliance is getting to know your data

Your PeopleSoft applications are inherently built with robust security features, but modern threats demand data security be taken beyond the standard User ID/Password model. Under GDPR, more PII translates to more liability. Therefore, it’s crucial that organizations:

  • Establish measures to track the lifecycle of sensitive data in their PeopleSoft applications
  • Define control protocols on how and by whom PII is accessed
  • Limit unnecessary exposure of sensitive information

For access controls to be effective, each user’s activity and transaction data must be available for tracking and monitoring by security teams so they can identify and remediate a breach effectively and efficiently.

High-level logging is NOT enough

Unfortunately, out-of-the-box PeopleSoft applications are only capable of high-level logging (login and log out instances), and that information is not sufficient for identifying what specific data fields may be compromised, who has viewed it, and when a user may have viewed specific data. This context is necessary for piecing together the narrative for effectively remediating a breach, and thus, making the initial steps towards complying with GDPR.

How GreyHeller’s Application Security Platform can solve the challenge

The key to preparing your PeopleSoft applications for GDPR is equipping them with advanced and robust security measures, that not only help you prevent a breach but allow you to detect and react to it promptly. With GreyHeller’s Application Security platform (ASP) organizations can effectively control the unwanted exposure of PII and accelerate breach detection and remediation. ASP enables security teams to gain maximum influence over what data is accessed, by whom, and how it is used.

Record each transaction as it happens

Designed to log field level transaction activity, ASP provides you with all the details you need to identify a data breach in time and fulfill the requirements imposed by GDPR. The logging features record all transactions within PeopleSoft on a granular level, providing information on what data was accessed, where it was accessed from, user ids and IP address effected and more.

Seeing is believing

The ASP also features an integrated analytics extension that uses the enhanced logging data to populate and display access activity on engaging dashboards. Comprising of elegant charts, graphs, and maps – these dashboards can be grouped by usage patterns, access trends, geographical locations, etc. to gain a holistic picture of user activity in a single view. The dashboards are equipped with deep drill-down capabilities, allowing security teams to investigate the activity and perform root-cause analysis thoroughly.

We are here to answer any questions you may have – Get a free security consultation for GDPR compliance today or write to us at info@devappsian.wpengine.com.

Put the Appsian Security Platform to the Test

Schedule Your Demonstration and see how the Appsian Security Platform can be tailored to your organization’s unique objectives

Best Practices for Approaching Oracle Cloud Applications – March 29th Gartner Report

By Scott Lavery • May 8, 2018

Gartner recently released a report addressing the speculations around Oracle’s on-premise and cloud ERP applications. Focusing on Oracle ERP customers’ frequently asked questions, the report is aimed at helping CIOs make informed decisions on whether Cloud applications are a viable replacement for their on-premises suites. Here are the most important takeaways and highlights from the report:

On-premises ERP suites are not at the “end-of-life” stage.

From thousands of client interactions, Gartner concluded that Oracle’s ERP customers are unsure about Oracle’s commitment to its on-premises suite. To put their doubts to rest, Gartner highlighted several factors that reiterate Oracle’s continued investment in their on-premise applications:

Revenue from on-premise applications remains strong

“Oracle’s on-premises suites are not at the end-of-life stage” assures Gartner. “Oracle receives the majority of its software license revenue from customers paying for maintenance, and new sales of its on-premises products,” (68% and 65% in 2016 & 2017 respectively). According to Oracle’s co-founder Larry Ellison, “Oracle spends over $5 billion per year on research and development (R&D) and continues to invest in all its on-premises application products.”

Fluid symbolizes the future for (on-premise) PeopleSoft 

Specific to PeopleSoft, the report mentions that the “…extended Support timeline for PeopleSoft is stated through at least 2027,” and with the launch of enhancement features such as Fluid UI for PeopleSoft, Oracle continues to demonstrate its continued investment in their existing on-premise ERP applications.

Best Practice: Map Your Business Requirements Against the Maturity of Oracle’s Cloud Applications

According to Gartner, Oracle’s cloud applications are the inevitable future of ERP functions, but having been released to different timetables, cloud applications have differing levels of maturity and may not (at this time) offer true parity to Oracle’s legacy, on premise suite. As a best practice, Gartner recommends that decision-makers must consider the development roadmap of the respective cloud applications and avoid confusing the desire to source a new technology with the objective of fulfilling a specific business requirement. In other words, stating that “a full ‘rip and replace’ of your current applications may not be your best option.” Gartner goes on to urge customers to map business requirements carefully against the maturity of Oracle’s cloud applications and ensure that present day business objectives can be met so costly and unexpected change management can be avoided. In addition, the report offers a detailed outline of various situations and subsequent appropriate actions for ERP customers using Oracle’s on-premise suites.

Best Practice: “Take the postmodern approach”

Gartner emphasizes that the decision to move to the cloud must be based solely on the value proposition cloud applications offer over existing on-premises applications. While talking about moving to Cloud applications “as part of a business transformation initiative” Gartner asks decision makers to be aware of “the risks and limitations of recent releases.” Instead of a complete “rip and replace” Gartner suggests a “postmodern approach,” where an organization could decide to replace only parts of their on-premises footprint. Gartner also advises Oracle customers to not “assume that the level of expertise that exists for application support and implementation services for on-premises suites also exists for cloud applications.”

Summary

As stated above, while the future appears to be headed towards the cloud, the fact remains that a “look before you leap” approach is recommended. A cloud migration project must begin with a  thorough evaluation of your business objectives in order to ensure proper alignment between the cloud technology you are adopting and the expected results. Change management can add significant cost and disruption to a project, and while complete elimination of change management is impossible, the more evaluation you undergo prior to the start of a migration project – the more likely to avoid “budget busting” surprises.

So, consider the postmodern approach – what objectives do you need to achieve today vs. what do you need to achieve 5 years from now? Are there specific ERP functions that are working just fine today? If not, are there lightweight optimizations that can be done in the meantime to enhance current functionality? Gartner recommends a postmodern approach in order to avoid a scenario where you go “all in” on the cloud and are left to address an unexpected mess.

Appsian is here to help you make PeopleSoft exceptional. Email us at info@stgappsian.wpengine.com and let us know how PeopleSoft can be working better for you today!       

Access the full version of the report HERE

Put the Appsian Security Platform to the Test

Schedule Your Demonstration and see how the Appsian Security Platform can be tailored to your organization’s unique objectives

Universities are wasting $60K/mo. (avg.) by NOT having a SAML Single Sign On for PeopleSoft

By Scott Lavery • May 3, 2018

Did you know that…

A *2014 Forrester study of a major US-based University showed that over 50% of user password resets could not be completed via self-service – thus resulting in (approx.) 890 calls to support per month (avg.)

  • The study further concluded that “the average help desk labor cost for a single password reset is about $70.”
  • 890 calls to support each month means IT is wasting $62,300 each month, resetting and troubleshooting user password issues

View Data Sheet

*https://solutionsreview.com/identity-management/forrester-passwords-are-here-to-stay-heres-how-to-deal-with-it/

Put the Appsian Security Platform to the Test

Schedule Your Demonstration and see how the Appsian Security Platform can be tailored to your organization’s unique objectives

The Keys to Avoiding a Failed PeopleSoft SSO Project

By Scott Lavery • April 19, 2018

In a previous blog ‘Time is Money’ we discussed what lacking a PeopleSoft-integrated SSO is costing your organization.

By now, we all should fully understand what the recurring password recovery cycle is costing organizations in terms of lost end-user productivity and excessive calls to the IT help desk. Organizations can use a single sign-on (SSO), to establish a centralized authentication system that allows IT to manage support costs and efficiently perform password database provisioning. An SSO also greatly reduces user downtime associated with password reset and recovery.

Off-the-shelf SSO solutions DO NOT work with PeopleSoft

There are numerous vendors who promise that the same SSO that you implement across all of your enterprise applications will also work seamlessly in your PeopleSoft environment. Unfortunately, when it comes to implementing that off-the-shelf SSO in PeopleSoft (specifically) those projects are destined for failure. The reason being that off-the-shelf SSO solutions rely on SAML based technology as an identity federation standard – and there’s no native SAML support in PeopleSoft. Unaware of this fact, SSO vendors will assume that PeopleSoft supports SAML (similar to your other applications) and eventually hit a roadblock during implementation/testing. This complication typically results in the recommendation of added customizations and web server(s) in order to save your PeopleSoft environment from being alienated from the rest of your enterprise applications.

The downsides of fitting a square peg in a round hole

Off-the-shelf SSO solutions need to go through extensive customizations in order to have any communication with PeopleSoft. Firstly, organizations need to build extensive frameworks to integrate SAML based identity providers (ADFS, Shibboleth, etc.) with PeopleSoft using a reverse proxy configuration. These custom developments require procuring and setting up additional infrastructure (hardware, web server(s), etc.) – resulting in prolonged project timelines and budget overruns. Secondly, these customizations (once implemented) are fragile, difficult to troubleshoot and require constant intervention – especially during PeopleSoft updates.

PeopleSoft Single Sign-On – a square peg for a square hole

Organizations can save both time and money by opting for an integrated SSO, exclusively designed for PeopleSoft. For years, the demand for a native SSO utilizing SAML identity providers was a hot topic in the Oracle community – fortunately, this solution is now a reality. Being the only native SSO solution for PeopleSoft, PeopleSoft Single Sign-On by GreyHeller allows organizations to support SAML-based authentication technology without any customizations or additional infrastructure. PeopleSoft Single Sign-On eliminates the need for end-users to utilize multiple (weak and easy to remember, but easy to crack) passwords and empowers them to seamlessly transition between PeopleSoft applications using a single, strong login credential. It also empowers IT teams to centralize authentication management and makes it easy for them to provision password databases as employees come and go in the organization.

Once implemented, PeopleSoft Single Sign-On enables your employees to:

  • Authenticate PeopleSoft sessions via the leading identity providers such as: ADFS/Office 365, Shibboleth, or OKTA
  • Access PeopleSoft via deep link navigation (sent by email or other enterprise communication channels)
  • Utilize PeopleSoft links from a 3rd party portal

When it comes to your enterprise applications, opt for the peg that fits rather than hammering the one that doesn’t into a shape that partially fits! To learn more – request a live demo of PeopleSoft Single Sign-On with an Appsian Solutions Expert email us at info@stgappsian.wpengine.com.

Put the Appsian Security Platform to the Test

Schedule Your Demonstration and see how the Appsian Security Platform can be tailored to your organization’s unique objectives

Now Introducing PeopleSoft Security Analytics (Preview Available)

By Scott Lavery • February 5, 2018

GreyHeller is proud to announce the arrival of

PeopleSoft Security Analytics

 

Next-generation software providing actionable insights into how your PeopleSoft data is being accessed – where and by whom.

Enterprise data security professionals understand that identifying potential cyber-crime hinges on one’s ability to spot trends within data. After all, your system isn’t filled with red lasers (think Mission Impossible) that once tripped, sets off a series of blaring alarms. Successful cyber criminals have all the time in the world to formulate their strategy, gather what they need to access your system, and take what they want! Unfortunately, you don’t have all the time in the world to stop them!

GreyHeller’s PeopleSoft Security Analytics software visualizes the data trends that tell the story of how, where, and by whom your data is being accessed:

  • Access volume by IP
  • Geographic location of access
  • Access trends by data sensitivity level
  • Access trends by user privilege level

Data visualization solutions are essential for understanding the granular details that can be the difference between a secure system and a catastrophic data breach. In order to help you be proactive before you’re forced to be reactive – we are providing a sneak peek demonstration at PeopleSoft Security Analytics:

 Wednesday February 14th at 1:00 PM CST (11AM PST.)

Register Today

 

Can’t wait until February 14th? Demonstrations are available with advanced notice. To schedule your demonstration, GO HERE and a solutions representative will be in touch!

Put the Appsian Security Platform to the Test

Schedule Your Demonstration and see how the Appsian Security Platform can be tailored to your organization’s unique objectives

Request a Demo

Start your free demo

"Learn how you can reduce risk with rapid threat protection, audit response and access control. All from a single, comprehensive platform"

Trusted by hundreds of leading brands