Email Archiving Blog – LiveOffice cLOud Surfing

Boston Email Blunders Extend Beyond Mayor’s Office

By: Stephanie O'Neill | Posted: 2009-10-21

State public records law? What state public records law? Apparently Boston city leaders didn't get the memo ... or at least they didn't let old habits die when improper email deleting practices first came to light.

Last month, I wrote about a key member of Boston Mayor Thomas M. Menino's staff, Chief Policy Adviser Michael J. Kineavy, deleting emails without regard for state public records laws. The issue came to light when the Boston Globe requested copies of Kineavy's emails over a six-month period, which only returned 18 results. This led to the revelation that Kineavy deleted all of his email on a daily basis, without letting them be backed up, in direct violation of Massachusetts public records law.

But the saga continues ...

It turns out that many employees at Boston City Hall were deleting emails regularly - it was a common and seemingly acceptable practice for mailbox management. The problem is state public records law requires the city to preserve "all city email" for two years. Even more surprising, the Boston Globe discovered that a state judge warned Mayor Menino's administration that city employees were deleting email nearly a year ago, but no one did anything to stop it.

Now, Kineavy's computer is undergoing a forensic review, and who knows if city employees are still deleting emails. But I bet Mayor Menino wishes he had a seamless email archiving solution in place right about now.

  • Twitter
  • Facebook
  • Digg
  • Reddit
  • Delicious
  • FriendFeed
  • LinkedIn
  • Share/Bookmark

Careful, Hitting “Delete” Doesn’t Always Mean It’s Gone for Good

By: Stephanie O'Neill | Posted: 2009-09-15

I am constantly amazed that people, including public officials, still think they can completely delete things they send via email. Although you may delete email from your possession, you have no control over the recipients of those messages - or the recipients they may forward your messages to, and so on. Your company - or government entity, as the case may be - could very well have an email archiving solution in place that is automatic and seamless, and you may or may not know about it. The recipients' organizations are likely archiving as well. One thing is for sure: There is always a trail.

Boston Mayor Thomas M. Menino is finding out the hard way that deleting email is not a best practice. Two local city councilors and challengers of Menino in an upcoming Democratic preliminary election are asking the local attorney general and district attorney to investigate the routine deletion of emails by officials in Menino's administration, including those sent and received by one of his closest advisors, Michael J. Kineavy.

The controversy arose when the Boston Globe requested copies of Kineavy's email communications over a six-month period. The search returned only 18 results. The unusually low volume of email led to questioning by city officials and an admission by Kineavy that he doesn't allow his email to be backed up and deletes all of it on a daily basis, which violates state public records law.

The result of this investigation is yet to be determined, but whether or not an archiving solution was in place, chances are that some of those emails will turn up somewhere. An email archiving solution is a really great insurance policy for any organization, public or private, that may become the subject of an investigation or lawsuit - and it saves a lot of time and money in instances like the one brewing in Boston.

This isn't the first time we've seen a case like this, and unfortunately, it's probably not going to be the last. The bottom line? If you're trying to hide something, it will inevitably catch up with you, thanks to technology and the age of electronic communications.

  • Twitter
  • Facebook
  • Digg
  • Reddit
  • Delicious
  • FriendFeed
  • LinkedIn
  • Share/Bookmark

Digital Voicemail: Convenience or Compliance Risk?

By: Stephanie O'Neill | Posted: 2009-06-02

While convenient new technologies seem to emerge by the minute, compliance departments are continually plagued by the challenges they present. More than ever, many closely regulated industries are under a microscope-especially financial services. The Financial Industry Regulatory Authority (FINRA) expects its member firms to have policies and procedures in place to "monitor all electronic communications technology used by the firm and its associated persons to conduct the firm's business." Although email has been the primary focus of such regulations to date, more and more new technologies are coming into play.

So where does digital voicemail fit in? The short answer: digital voicemail is discoverable, and you should be prepared to handle it no differently than email when it comes to compliance.

No matter what type of voicemail system you have, the way the associated data is retained is likely under your control, which means it must adhere to your data backup and retention polices. Although unified messaging solutions are convenient, often delivering voicemail message notifications and audio files directly to your email inbox, they tend to pose the most challenges when it comes to retention and discovery. Some regulations, such as amendments to the Federal Rules of Civil Procedure, specifically callout "sound recordings" and specify that they must be reasonably accessible and not burdensome to produce (see FRCP Rule 26 and Rule 34); however, more and more courts are not accepting accessibility or financial burden as an excuse for failing to provide relevant data during discovery (see eDiscovery & Compliance Considerations with Unified Messaging).

Unfortunately, very few companies are prepared for discovery of digital voicemail and other audio files, which could end up costing them a significant amount if they end up in litigation. When it comes to discovery, it's only a matter of time until voicemail and other audio files are just as common as email communications. Whether you're prepared or not, your compliance obligations are expanding. Companies must ultimately assess their own risk and determine the best course of action to meet their specific compliance needs, but a little preparation goes a long way.

  • Twitter
  • Facebook
  • Digg
  • Reddit
  • Delicious
  • FriendFeed
  • LinkedIn
  • Share/Bookmark

One Man’s Take On Security in the Cloud

By: Dhaivat Pandit | Posted: 2009-05-21

An article on Network World caught my attention - a surprisingly decent addition to the ongoing debate about security concerns with the software-as-a-service (SaaS) delivery model. I realize that it's a legitimate concern, unlike those of which pertaining to global warming.

Genetically designed to be skeptical of any buzzwords, I accept that cloud services need more scrutiny. The only entity that knows more about my personal tendencies is my email account, and naturally I want it to be secure. I shudder to think what it takes to entrust your billing, operations or human resources needs to a third party vendor. When the services we're talking about are email archiving and compliance, I can totally see where the general feeling of skepticism comes from.

From the viewpoint of a cloud-based company, I can say that we're all too aware of what's at risk and that we work tirelessly to ensure that we can provide a service that is secure and reliable. As Jon Brodkin mentioned in his article, multi-tenancy is an integral component of cloud computing services. You can be at ease knowing that we take every measure possible to ensure that you and ONLY you can see what belongs to... you. To quote John Hammond from Jurassic Park, "No expense is spared."

  • Twitter
  • Facebook
  • Digg
  • Reddit
  • Delicious
  • FriendFeed
  • LinkedIn
  • Share/Bookmark

Don’t try pleading ignorant – Part II

By: Dean Nicolls | Posted: 2009-05-08

I began my first post by introducing the challenges faced throughout E-Discovery in terms of processes, so now we'll talk about the technology aspect.

On the technology front, you need a simple way to collect and index this information. When it comes to email, tape backups just don't cut it, since they can degrade over time (given that we're talking about physical media), and there's no easy way to perform intelligent searches. For example, say you want to get all of the email between John and Susie from January 2008 through April 15, 2009. With email archiving solutions, whether they be SaaS-based (hosted) or on-premise, all email and attachments are typically indexed when they are ingested into the archive, so you can easily search and quickly find relevant email threads. The ability to do your own searches and cull the list of potentially relevant email can literally save you tens of thousands of dollars in legal expenses. And, as an added benefit, you are in a much better position to evaluate the legal merits of cases, claims and likely defenses.

Keep this in mind. E-Discovery is by far the most significant cost driver when evidence in a case involves a large volume of electronically stored information (ESI). Accumulating data throughout the e-discovery process is inherently time consuming and costly. Locating the relevant data, collecting it and then preparing it for review by legal counsel are all integral parts of the routine. The most expensive part of that process is the cost of human review, which is driven by the number of documents requiring review, the hourly rate and the efficiency of the reviewers. This underscores the importance of creating and enforcing sound email-retention policies, storing your email in a central, searchable repository and ensuring that your company can quickly comply with discovery requests.

The demands of e-discovery now require companies and their attorneys to have a rudimentary understanding email archiving technology in order to increase their odds of mounting a successful and cost-effective defense. At a minimum, this'll at least help to avoid having your case thrown out because of ESI mismanagement.

  • Twitter
  • Facebook
  • Digg
  • Reddit
  • Delicious
  • FriendFeed
  • LinkedIn
  • Share/Bookmark

WHOA! You’ve got archiving in the cloud all wrong…

By: Dhaivat Pandit | Posted: 2009-05-06

I recently stumbled upon an interesting article on CNN Money and as a provider of software-as-a-service (SaaS) solutions, felt like saying a word or two.

Take this scenario for example. A typical small and medium business (SMB) such as an investment firm with roughly 50 employees is looking for an email archiving solution to address their storage needs. They'll have to choose between a traditional on-premise archiving solution or go through a "hip" SaaS provider.

When considering an on-premise solution, the following fixed costs should be considered:

Software

    • License(s)
    • Support and upgrades
    • Implementation
    • Health Check
    • Training

Hardware

    • Server(s)
    • Primary storage
    • Disaster recovery storage
    • Disaster recovery bandwidth
    • Maintenance
    • Space, power, heating and cooling

Personnel

Through the use of our nifty total cost of ownership (TCO) calculator, we can come up with some ballpark numbers for an on-premise solution which are shown below.

Now let's take a look at the TCO for a SaaS-based email archiving solution, which includes the following costs:

* Software Costs

o License
o Implementation

And just to be sure, let's compare the two results.

This case uses only 50 users, but even if we had 500, the savings are significant.

I could just let the numbers do the talking, but just as a last few last words, SaaS is not something the software industry came up with overnight (we are not THAT good). It has been around forever and is used in most industries such as travel (Travel-as-a-Service) and healthcare (Medicare-as-a-Service).

Think about the world without TaaS, to travel from LA to NYC we'll have the following options:

* Call an airline and eventually place an order for your ticket after being on hold for 15 minutes
* Buy a Gulfstream G5 and fly to NYC (Hey, a guy can dream)

But with TaaS, we can buy a JetBlue ticket online and hop on a plane that same day. And you even get free DirecTV. Maybe we should start offering that with our service, too.

  • Twitter
  • Facebook
  • Digg
  • Reddit
  • Delicious
  • FriendFeed
  • LinkedIn
  • Share/Bookmark

Exchange backups: Groundhog Day?

By: Nick Mehta | Posted: 2008-08-07

Do you remember Groundhog Day?  It was the 1993 Bill Murray film about a guy who relives a day of his life over and over again.  It featured the classic line:

This is one time where television really fails to capture the true excitement of a large squirrel predicting the weather.

In any case, I think the way we stick to the weekly tradition of full Exchange tape backups is like a bad recurring dream.  Lots of the same stuff over and over again.

Today, I spoke with the blogger and former storage CTO George Crump who had a great post on his blog, Storage Switzerland, about how full backups are becoming a thing of the past in general.

I think this is particularly true for email, where users and lawyers want and demand the granularity of a message - not the granularity of a tape.

Many clients backup Exchange every day with incremental backups and innovative disk-to-disk technologies and yet still perform full backups to retain data for legal discovery or data retention purposes.

If all of your data is in a hosted archive, full Exchange backups and retaining tapes for long periods of time become something admins can cross off of their ever-growing to-do list.  This saves tape media, tape storage and precious IT time.

So they can move on to the next day.

  • Twitter
  • Facebook
  • Digg
  • Reddit
  • Delicious
  • FriendFeed
  • LinkedIn
  • Share/Bookmark

To stub or not to stub

By: Nick Mehta | Posted: 2008-08-07

Bob Spurzem on the Ferris Research blog wrote a good post today on a method of archiving called stubbing.  Bob was referring to a recent Microsoft TechNet article on the topic claiming that Microsoft was recommending against stubbing.

Stubbing involves replacing items in the email server (e.g., Microsoft Exchange) with a stub or pointer that refers to the original message and attachments in the archive.

While a number of vendors try to make the issue black-and-white (i.e., stubbing is great or stubbing is bad), I personally think it's simply a tradeoff:

  • Pro: Stubbing allows the management of the message to remain in the normal folder structure, since the "stub" remains in Outlook and Exchange.
  • Con: However, Bob and others are correct that the stubs themselves over time can clog up Exchange and cause performance issues.  One of the main reasons for this is that item counts (i.e., how many messages you have) often drive performance bottlenecks in Outlook and Exchange as much as does mailbox size.

I think stubbing is great for giant enterprises that can manage some of the complexity in order to benefit from the folder integration.  However, for smaller organizations or ones with limited IT resources, the simplicity of pointing users to an archive folder or archive search tool often wins out.

Again, it's not a good-versus-bad situation but it's good to know the tradeoffs between the alternatives.

  • Twitter
  • Facebook
  • Digg
  • Reddit
  • Delicious
  • FriendFeed
  • LinkedIn
  • Share/Bookmark

One search to rule them all

By: Nick Mehta | Posted: 2008-07-30

In email archiving, there are basically two strategies for capturing messages:

  1. Capture everything OR
  2. Capture everything that matches a certain criteria (e.g., email older than 30 days is "stubbed" out of Exchange)

Method 2 is great, is very popular with on-premise email archiving products and has a number of advantages.

However, one of the big disadvantages is that the end-user in Outlook has two repositories:

  1. Email "younger" than 30 days lives in Outlook and is searchable by Outlook search tools
  2. Email older than 30 days lives in archive and is searchable by archive search tools

The user now has to figure out how old the email is that he's looking for and determine which repository to search. In many cases, he or she may not know for sure and therefore would have to search both. Finally, the search semantics (e.g., whether the engine searches attachments, how search terms are constructed, etc.) may differ between Outlook search and the archive.

Some on-premise vendors get around this by integrating their archive into a desktop search engine (like Windows Desktop Search) and allowing users to search the archive and Outlook from the desktop search engine. The challenge is that many users don't have or use these desktop search engines.

One of the nice things about method #1 (capture everything) is that the user has one place to search and no confusion over where his or her email is. Again, it's a tradeoff, but this method (full disclosure - of course, the method that LiveOffice uses) may be more usable for some users.

  • Twitter
  • Facebook
  • Digg
  • Reddit
  • Delicious
  • FriendFeed
  • LinkedIn
  • Share/Bookmark

Beyond the buzzword: SaaS and storage management

By: Nick Mehta | Posted: 2008-06-11

It's easy to get lost in your own little world. But life is very good at bringing you back to reality on a regular basis.

I remember going to a family function a few years ago. A very well-educated friend of my parents' who happened to be a physician asked me what industry I'm in. Having been a new, eager employee to what was then called VERITAS Software Corporation, and having drunk the Kool-Aid of our mission to change the world with our "No Hardware Agenda" strategy, I answered proudly that I'm in the storage industry. The doctor responded excitedly that he was looking to move and needed to find cheap "storage" for his furniture during the transition. He asked for my business card.

The reality is that even in IT, storage is often an after-thought. The two things I hear from people that are not deep into this stuff are: (1) storage is so cheap and (2) we have TONS of storage. Storage, storage everywhere but not a spindle to use.

Unfortunately, in on-premise email archiving deployments, storage often ends up becoming an after-thought as well. Customers purchase email archiving solutions (whether SaaS or on-premise) for the mailbox management, E-Discovery, compliance and other benefits. Given that, in most cases, the team responsible for email and/or legal drives the decision. Buying a new, energy-hogging storage cabinet to keep the office warm is the last thing on their minds.

I can't count the number of visits I've had where the customer gets to the realization that they are going to be creating tons of data and need a place to store it. If they're lucky, they bring their "storage expert" into the room who often hasn't been informed about the project at all. In most cases, for small-to-mid-sized businesses, there is no such role, so they have to learn as they go.

Some of the challenges I've seen customers, particularly ones with limited IT staff run into:

"We have extra space on the SAN." In most IT departments, there is some extra storage "somewhere." Many small-to-mid-sized on-premise email archiving deployments often start by leveraging the available storage in-house. Unfortunately, most organizations quickly realize that archives keep growing and often very rapidly overwhelm available internal storage. In addition, as you'll see below, archive storage needs to be very finely-tuned and nine-times-out-of-ten, what the customer has in-house won't work for the archive.

"How much storage do I need?" Sounds like an easy question. I guess you can ask the storage hardware vendor and let him or her tell you, but that seems like letting the fox guard the hen-house. In reality, the answer is "a lot" and "more every day." Most on-premise vendors have tools and white papers - in many cases, ones that involve 50-100 pages of reading - to answer the question precisely. Obviously you need to assess your mail volume, message size, retention period and other factors. The sizing is surprisingly arduous and complex.

"It's an archive so I'll just use cheap disk." One of the basic principals of archiving is that old email will be accessed less frequently by users and therefore it can be stored on cheaper (lower-performance) storage. In geek-speak, this means things like using Serial-ATA drives for archival instead of Fibre-Channel for production email. Unfortunately, people take this to an extreme and often think the whole archive involves cheap storage. In reality, most archives have three pieces of data: (1) archived emails themselves, often written as files, (2) high-level metadata stored in some kind of relational or XML database and (3) search indices. The archived email indeed can be stored on relatively-cheap storage (though see below for more on this). But the database metadata needs to be stored on high-speed disk, like any database. Furthermore, the search indices are often even more temperamental about disk I/O times. As a rule of thumb, the database and index data can end up being 10% - 50% or more of the original content size. So you end up needing to buy a significant amount of significantly-expensive disk. :)

"This #!@# archive is slow!" Despite the best of software engineering in on-premise products, they are dependant on storage hardware and its proper configuration. Usually you only figure this out when you have a huge E-Discovery or compliance request and need to search through and export thousands or even millions of email messages. The searches can be slow due to poor performance or misconfiguration of the area where indices are stored. But the actual bulk export of messages itself can be a nightmare if the storage isn't configured correctly. Indeed, this mass export use case is why you can't just use cheap disk for archival without thinking it through at all. And of course, this all happens when you've got a lawyer camped out in your office waiting for the data.

"How do I move all of this data?" This one is perhaps the scariest of all. The math is simple. Storage arrays last 3-5 years. Archived data is often retained for 5-10 years or longer. So now you have this array with 100s of GBs or TBs of data. How do you migrate it all to a new array? How do you preserve compliance in the process? And make sure it all works? And how long will it take? This migration problem is a ticking time bomb for many customers and there is no easy answer.

Obviously with Software-as-a-Service, storage is still complex, but the customer doesn't deal with it, we do. And for whatever strange reason, I find storage fun. I've got issues... :)

  • Twitter
  • Facebook
  • Digg
  • Reddit
  • Delicious
  • FriendFeed
  • LinkedIn
  • Share/Bookmark
   

Follow LiveOffice

Tags

Blogroll

Login