Unless by some ridiculous twist of fate you’re Novak Djokovic, Lionel Messi, or Steven Hawking (and their like) reading this, you are not the best at anything. Perhaps like me, even if you had spent your entire life practicing one thing you still would not have been the best.

Nor do you have to be.

World-class talent is exceptionally rare, but we humans have the unfortunate habit of holding ourselves up for comparison to these unique few. How could we possibly come up anything other than short?

A single skill or talent (see Choice: Love What You Do, Or Love Doing What You’re Good At?), properly developed, can take you far …IF you’re very good. But it’s the combination of your skills and talents that will enable you to excel at a far greater array of your life choices.

No-one, I mean NO-ONE can be you better than you can.

The challenge is; Who ARE you? What are your skills, your talents, your likes, dislikes, even aspirations? A disturbingly large portion of us spend our whole lives without answers to these questions, and we die never having achieved a fraction of our potential. Not someone else’s opinion of our potential, but our own sense of happiness and self-worth. Our feeling of achievement for a life that made a positive difference. At least to someone.

We have all come across people we simply can’t believe haven’t been fired yet, and we have all met people we are amazed are not doing significantly better. In my mind they have both committed the same ‘crime’; they have failed to understand themselves. These examples came from different angles, but the results are the same; neither is doing what they should or could be doing with their lives.

While I absolutely believe you must leave this life with regrets (A Life Without Regrets is a Life Without Mistakes) doing a poor job or never doing a great job should not be among them. Others can help – and usually love to do so – but only you can choose the right path.

There is a good chance I can beat Djokovic at darts (and perhaps several other non-athletic endeavours), and I likely know a lot more about payments security than Hawking. We all make our OWN choices in life, I am where I am because of mine, so why should I ever compare myself to them? Or to anyone else for that matter.

No, I have no-where near their money or their fame, but if I was to measure my life by those standards I have a lot more issues to address first. I am very good at what I do, but equally important, I know when I’m out of my depth. Like most people, I will never know EVERYTHING I’m good at, but I am self-aware enough to know when I should keep something going, or let it go entirely.

I have no problem being fired for being too opinionated, I would very much object to being fired for incompetence, but they are both very much my responsibility.

With self-awareness comes true personal accountability, only then can the regrets you have be the kind you want.

[If you liked this article, please share! Want more like it, subscribe!]

The following phrase occurred to me after conversations I had with two ex-colleagues. Both of whom also now happen to be very good friends;

“You don’t know what you don’t know, so how can you ever be sure you know enough?”

Both find themselves in a similar position; both have progressed in their careers at their respective organisations, and both have very recently received a significant bump in responsibility and work-load. Neither has EVER received the recognition they deserve, but both have dramatically improved things for their departments after taking over. They also replaced people on much higher salaries.

It’s very easy for me to rail on the senior management at those organisations about how they must show appreciation for their star performers. In both monetary terms, and the respect they have earned. But the fact remains that neither of these talented guys know their true worth.

Yes, their senior management are idiots, they probably always have been, but if my friends had been paying attention they would be in a better position to negotiate. If they had been laying the right groundwork over the course of their careers, no promotion would have been offered without the corresponding upward review of their compensation packages.

And the thing is, I know exactly how they feel. After 12+ at my last ‘corporate gig’ it was not until the last few years that I started to get it right. It took a further year after my departure for me to finally know my worth. The true value of my skill-set.

I also know exactly why it took this long; fear.

When I started a new career in my 30’s, I could not have known less about my chosen field of cybersecurity. My first two weeks as a Firewall Administrator consisted of my learning what a firewall was and faking my way to a couple of credentials. Over the next 5 years I worked my up to managing the department, which was then all taken away during a company merger. For the next 7 years I worked my way up from a brand new consultant to Director of 28 consultants across 14 time zones.

Yes, my compensation increased, but I very much doubt it was in-line with my market value. Why? Because I always doubted that I had learned enough in my career to have proven my value, to be worth more than my management were offering. Also, having spent so long at one place, my blind loyalty got in the way. I assumed I would be taken care of if gave it my all.

I could have gone on for years this same way, luckily the final decision was made for me. When I look back, I can see years of wasted time and misplaced loyalty, but if I’m really honest with myself, it was my own fear and laziness that really held me back. All I had to do was look around, have some conversations, and above all; stop being such a wuss.

I know it’s not as simple as I’m making out to be, we all have responsibilities (family, mortgage and so on…) but in the end, YOU are the one that sets your value, and if you’re not getting your due, YOU are the only one to blame. I had no choice in working this out, I was “laid-off”, but one of the most amazing upsides of a bad situation is that I’ll never be afraid again.

I know my worth, do you know yours?

[If you liked this article, please share! Want more like it, subscribe!]

Once again I have chosen a dramatic title to sucker you in. But seeing as it’s PCI related it’s never going to be even remotely exciting.

First; per the title, I’m not actually a QSA any more, but I have been in the trenches of PCI since before there were QSAs. Anyone remember QDSPs? I am therefore reasonably well qualified to write about it.

Second; by “PCI From the Other Side”, I mean that I found myself in a scenario where I was the one being assessed. The remainder of this blog is about that experience. It was truly eye-opening, and I hereby apologise to every client I’VE assessed over the last decade. I only now feel your pain.

But it’s not until you find yourself on the other side of the assessment fence that you can truly appreciate the challenges. I am both a PCI and cybersecurity expert, and even I had a hell of a time putting my organisation through the process. And I designed the infrastructure with compliance in mind!

My first challenge was finding a PCI compliant service provider (SP) who covered the vast majority of the infrastructure related processes. From configuration standards, to AV, to logging and monitoring I didn’t want to do anything in-house. I spoke to several service providers, and found myself guiding THEM in the design of their PCI services! Regardless, they were universally unhelpful, and if I had this much difficulty, what chance does anyone else have?

Even Amazon Web Services does a better job than every SP to whom I spoke. While AWS basically devolve almost every aspect of compliance back on the client, they at least break down the EXACT responsibilities for all parties. Yes, PCI DSS v3.X does a better job of making this a requirement, but it can still be very difficult to get the right information based on a vendor documentation. If you don’t ask the right questions, no SP seems anxious to provide them for you.

The second major challenge was the sheer volume of ‘paperwork’. Policies, Procedures and Standards make up roughly 35% of the PCI DSS requirements, and at least 47% of validation against all requirements involves review of some form of documentation. Even if it’s just a screenshot.

As an assessor, I would give my clients a spreadsheet that tells them what kind of document I need against any given requirement. They would then complete this with the document THEY believe meets the intent of the Testing Procedure. For my QSA I went one stage further and mapped my policies and procedures (including Section numbers!) against the Report on Compliance v3.X template itself.

Now these are Policies that I have mapped against the PCI DSS / ISO2700X/ CoBIT etc. I have even sold them to several clients to help with their compliance efforts, yet it took me several weeks get them where they needed to be. As for the Procedures and Standards, I had to create 24 separate documents to cover everything from Change Control to Vulnerability Management. This was NOT fun, or easy!

Like finding a Service Provider, I had a huge advantage over most people in charge of putting together their organisation’s documentation. If this was the pain I went through, I do not want to begin to imagine the pain for anyone not an expert. [Note: The ‘paperwork’ is critical not just to PCI, but to security in general, and should NEVER be done with just compliance in mind!]

I have written too many blogs about the problems with the PCI DSS to harp on about them here, and there were far more issues I faced than you want to hear about. Needless to say, if the SSC really want to train new QSAs, they should throw out their entire curriculum and put them in the client’s shoes for a day.

95% of them would fail.

Who am I kidding, 95% of CURRENT QSAs would fail, I almost did!

[If you liked this article, please share! Want more like it, subscribe!]

[This article is based loosely on the Dunning-Kruger Effect.]

Have you ever been part of a meeting where someone whom you suspect has no idea what they are talking about, is actually the one controlling the meeting’s outcome? Or the opposite; been part of a meeting where you KNOW someone in the room is an expert on the relevant subject, yet remains quiet? Now combine the two; the expert stays quiet while the idiot rambles on.

I’m sure at some point I’ve been both, and if I’m honest, mostly the idiot.

One of the many aspects of human nature is our susceptibility to bow to confidence. Con artists and organised religions alike (but I repeat myself) have preyed on this for millennia. Politicians, emperors, dictators, cult leaders, you name it, all have the ability to make us believe utter nonsense. We are invariably less influenced by what is said, than how it’s said, and by whom.

Those who can make you believe absurdities can make you commit atrocities.”
– Voltaire

The opposite aspect of this is that even if you are an expert on something, if you aren’t confident in your presentation, your knowledge and skill may be of little impact. Potentially, even if you did speak up, your hesitant manner would negate your audience’s trust in your message. That’s if they were even listening in the first place.

Yet another aspect of human nature is that we really don’t care about other people’s opinions. We are either pleased when people agree with us, or we’ll debate, argue, even fight with those who don’t. Our tolerance for alternative opinions, was well as our ability to adjust our own, only gets worse as we get older. We spend our lives surrounding ourselves with things that make us comfortable, all of which do nothing but reinforce our established beliefs.

I have long been a proponent of self-reflection. The ability to take an objective-as-possible look at yourself, maybe even from another’s perspective, is critical in being able to adapt to whatever the world throws at you. From my experience, there is a direct correlation between the ability to self-reflect and the ability to accept responsibility for both your life, and your actions.

Blaming others is a form of blind-faith, it suggests an infallibility that can never exist. Both experts and idiots are affected equally on this point, both negatively.

The lines between confidence and arrogance, faith and stubbornness, mentorship and patronisation are all blurry, and entirely dependent on the recipient’s perception, not the deliverer’s intent.  Self reflection / observation is the only way you can adapt to the person(s) opposite you, and without that adaptation your own needs will not be met. At least not in full.

While being aware of your tendencies does not equate to an ability to make immediate adjustments (as I know very well), we all have to start somewhere. Whether you’re an expert or an idiot, everything you do is in some way contextualised by those around you. It’s up to you to maximise your impact in a beneficial way.

In your personal life, do as you wish, but at work you are beholden to someone; employer, stockholders, customers, or just your immediate team. Neither the humble expert nor the confident idiot are any good to anyone.

Including yourself.

[If you liked this article, please share! Want more like it, subscribe!]

While on the one hand, few organisations take information security as seriously as they should, to blame merchants for not maintaining PCI compliance is akin to blaming the doctor for your illness. In non-cash payments the fault lies not with the merchant’s lack of security culture, but with the payment card ecosystem itself.

I understand the motivation behind this article; Maintaining PCI Compliance a Showstopper for Many Retailers, but it shows a spectacular lack of understanding of the real issues.

The branded-card payment technology is broken, pure and simple, and so far no-one in the card-payments arena has done much to fix it. Instead, they have all put the onus, and the cost, onto the end merchant, who then has two choices;

  1. Eat the cost
  2. Pass the cost on to their customer

Guess which happens 9 times out of 10?

But why should the merchant be wholly responsible for the protection of the cardholder data? Are credit cards core to their business? They shouldn’t, and no, are the respective answers; payment for services / goods rendered is core, the means by which they receive payment is ancillary, and in this case then, responsibility for securing the payment type should be on the payment service provider.

50 odd years ago certain card brands came up with an excellent concept; the payment card. Banks jumped all over it and started providing lines of credit through the medium of plastic and the concept exploded. Now credit cards are the de facto, and ubiquitous, form of non-cash payment accepted globally.

So ubiquitous in fact, that few people seem to question the fact that the system is inherently insecure, inefficient, inflexible and massively expensive to maintain. Not for the card brands mind you, but for everyone else. The only ones who cannot recoup their costs is the consumer.

I have no problem paying for the convenience of a non-cash payment mechanism, but as a business owner, I DO object to being the only one paying for security of cardholder data when the technology itself is broken and any innovation away from the current system is stifled until such times as the card brands can catch-up. Which they won’t at the rate they are going.

The card brands clearly want things to continue as they are, as do the issuers and acquirers for obvious reasons. Banks make money from branded cards by charging both annual fees and interest on lines of credit so they have no desire to change things. Large retail, who should have enormous power and influence over payments innovation have, for some reason, completely missed the point. So it’s left to the rest of us to make a difference.

The challenge is that ‘we’ are ignorant and are clearly quite happy to go along with whatever is given to us. If this seems harsh, just look at the above article again. Verizon SHOULD know better than to blame the merchants, but if they don’t, what chance to the rest of us have?

Until such times are the ‘merchants’ learn ask the right questions this type of nonsense will continue, and until we, the ‘consumer’, start demanding REAL alternatives, we have no-one but ourselves to blame.