I think most of us have either heard of, or experienced in some way, this statement; “Employees tend to rise to their level of incompetence.”. (Laurence J. Peter and Raymond Hull)

And some of us, if we’re completely honest, were guilty if it ourselves at some point [cough].

But what happens when it’s the person who started out at the top? By either point-in-time genius, or sheer dumb luck, they manage to take a small company into the big-time.

How do you tell the person at the top it’s time to step down?

There are 3 types of CEO:

o

  1. ‘CEOs’ who are very good at taking an idea to a level where they are noticed by larger companies who wish they had thought of the idea first. But that’s it;
    o
  2. CEOs who are gifted at taking a small company public, and making everyone lots of money. But that’s it; and
    o
  3. CEOs that can lead a company for the long haul. And yes, that’s it for them too.

The BEST CEOs know which they are, and have the ego-less foresight and common sense to step aside when their job is done. Unfortunately the rest end up driving their companies into the ground and taking their employees with them.

Which begs the question; Why is corporate social responsibility almost entirely outward facing?

I have long thought of our places of work as the new communities. Historically, we humans derived a great deal of our security, sense of belonging, and even a large chunk of our identities from the communities in which we lived. But, not any more. At least not in the major cities of the industrialised countries that represent the lion’s share of the people reading this. Physical communities have been replaced by the organisations where we spend increasing amounts of time, especially now that we’re never off-line.

Should CEOs be more accountable to the people they employ? Not for money, healthcare, career advancement etc, but for the more fundamental human needs expressed in the previous paragraph?

A business is not a democracy, and the CEO has no legal obligation whatsoever to do anything of the sort. But is it really so difficult? Security and a sense of belonging just takes a culture that places values on them. As for our identities, don’t we all love buying into a vision of the future? One in which we can believe?

And what’s so wrong with just saying thank you? A SINCERE thank you directly from the CEO to an individual will engender a 100 times more loyalty than an annual 3% cost of living increase.

In a global market where competitive advantages are measured in weeks, not years, and where people can telecommute from half a globe away, the most successful businesses will be the ones where they have the hearts of their people. Not a resignation of things never getting anything better. Innovation and creativity will only be shared within the company if their basic human needs are met, otherwise they’ll take their ideas with them to the competition.

I don’t know if I’ll ever have employees, but I would hope that I treat them with all the respect they deserve, and not as things to be used for my benefit.

[If you liked this article, please share! Want more like it, subscribe!]

We’ve all seen these signature blocks;

[Name], CISSP, CISM, CISA, QSA, CRISC, CGEIT, PCIP, ISO LA, ITIL, Prince II, blah, blah….

These acronyms belong in two places; your LinkedIn [and equivalent] profile, and your CV/Resume/Bio. They have no place in your email signatures, nor on your business cards.

It’s not like we studied for a number of YEARS to get a MSc, or PhD. We read a book, and passed a multiple choice exam. We didn’t even have to know how to IMPLEMENT what we learned, we just had to memorise and regurgitate. Most questions end up being a 50/50 guess anyway if you don’t actually know the right answer.

I’m not saying certifications are totally meaningless, they are a great beginning for those trying to break into the cybersecurity industry, but once in, it’s your experience that needs to do the talking for you. Or better yet, the clients you helped do the talking for you. Your certifications show that you have some commitment, and who knows, maybe you’ll even learn a couple of things that are useful. But these things don’t help you much when you’re face-to-face with a real client asking for your guidance, and all you can do is read from a book.

Learning anything new is messy. You’re clumsy at first, you make LOTS of mistakes, and you may begin to doubt yourself. But get past that first client, the one who you helped …eventually, the one who actually thanked you afterwards, and THAT’S when your learning really starts. You EARNED that, and it’s not a feeling you’ll ever get from an acronym or a book.

With security, there are no certification that really get to the fundamental point, the meaning behind all of this. I guess CISSP gets the closest because its 10 Common Bodies of Knowledge (CBKs) cover things from Risk Management to Business Continuity, but no-one really cares about that stuff at senior leadership level, it’s just detail.

What’s important is STAYING in business, growing, going international, going public, shareholders and so on, and not one certification out there helps you explain to the CEO how IT and IT security can help get them there. No certification ever will, it’s something you have to learn for yourself, and something that will change with every client with whom you work.

There are no certifications for, or shortcuts to, being a consultant who ‘gets it’.

I have likened security to insurance, but that’s not really fair. Selling security is like selling insurance, but in the end insurance is just risk mitigation, security is business enablement. Security is not the goal, and it’s easy to get caught up in the moment and forget why we are really there in the first place.

So, as for your signature blocks, far better I think is to have the number of years you’ve been in cybersecurity, and the number of clients you’ve helped. Something like;

David Froud

Years In Cybersecurity: 17, Clients Helped: Hundreds

Think it’ll catch on? 🙂

[If you liked this article, please share! Want more like it, subscribe!]

Few phrases annoy me more than ‘Trusted Advisor’, not because it’s a bad concept, but because it is most often used by people and organisations that have no right to do so.

Just because you sell security services or products, you are not trusted, or an advisor, you are a vendor. At most you are a consultant, and it’s not until your client has reached the Business as Usual phase in their security programme life-cycle can you begin to be a trusted advisor.

If you have taken your client all the way from your discussion over business goals to Business Continuity Management, then you are in the ball-park. If you have been instrumental in helping your client engender a security culture with senior management buy-in, you are close. Finally, if your client turns to you for guidance related to every aspect of their continued growth and evolution, then, and ONLY then, can you add Trusted Advisor to your resume/CV.

On the other hand, not every organisation is even READY for this level of interaction with security. Most see it as a necessary evil, with limited to no ROI, so trying to dazzle them with a concept such as this is a wasted effort. As in all things, you will have respect when you’ve earned it, and you will only have earned it when you have put the client’s needs at least on the level of your bottom-line.

I am not a believer in altruism (what’s the word for a one-word oxymoron?), and I fully accept business is about profit. What I AM against is profit above value, not EARNING your profit, and not leaving the client better off than when you started. Without ethical values you will never, EVER be a Trusted Advisor.

Besides, calling yourself a Trusted Advisor is like saying you have a great sense of humour, or you’re a good cook, it’s the RECIPIENTS of your service that must bestow this title on you. You don’t ask for thank you notes, it has to be voluntarily provided for it to mean anything.

To me, these are the qualities of a true Trusted Advisor:

  1. Knows their client’s business goals;
  2. Has helped gear the development of the security programme to ENABLE those goals;
  3. Works along-side the senior leadership to help to develop a security culture;
  4. Is an invited member of the Governance Committee;
  5. Is the first person called to help resolve Business vs. IT/IS challenges.

I used the word ‘help’ 3 times in 5 bullets. That should be a good indicator of the real nature of a Trusted Advisor more than anything else.

VERY rarely will you ever achieve this status, which is why it’s such a great goal to strive for with all your clients.

[If you liked this article, please share! Want more like it, subscribe!]

One of these days I will learn to do some proper research on my blogs in order to provide the links to materials that I only assume exists. I can say there are thousands of articles out there on presentation skills, and not quote a single one.

Not going to this time either, but when I type in ‘presentation skills tips’ into Google, I got 17.5M hits, so it’s out there.

This is not about HOW to present though, that’s been covered by people far better at it than me, this is about WHEN to present, or more specifically, when NOT to.

A phrase occurred to me today that I feel sure I’ve stolen (and more than likely corrupted) from someone else, but I can find it’s like;

“A good idea presented badly, is often less effective than a bad idea presented well.” 

To illustrate, I will go to the extremes.  Fascism is a VERY bad idea, but I know of two people in history that turned their entire countries to it.  Ending World hunger is a VERY good idea, but the altruistic pleas of those who dedicate their lives to it, fall on mostly indifferent ears.

How is this possible?  Well, the two Fascists I’m thinking of were incredibly charismatic (according to the history books), and understood human nature innately (exploitive).  The people who want to end world hunger are usually too busy working toward that goal to do the rounds, and the chances are, they are not much into oratory (givers).

Humans are basically good, and it’s not that we don’t care, it’s that we have our own lives to get through, and we are generally far more receptive to the concept of mutual benefit than we are towards ‘one sided’ charity.

So what does this have to do with presentations?  Let me ask you; Are you good at presenting, and do you enjoy it?

I can guarantee that more people THINK they are good at it than actually are, and that the ones that don’t enjoy it, never are.

So whom do you want presenting your business plan to angel investors?  Or whom do you want presenting your company’s proposal for a multi-million $/£/€ deal?  Right, someone who’s really good at it, but for some reason this is not always a prerequisite.

Presentation skills are up there with any skill you want for your business, from sales, to finance, to consultancy, to R&D, and should be every bit as important a entry on your CV/resume as your education and work experience.  Smart hirers even have their candidates perform a presentation during the interview process.  Candidates have 1 hour to create a 5 slide presentation, and 15 minutes to delivery it + Q&A.

I’m not saying don’t hire people who CAN’T present well, they may simply not have the experience, but you have to KNOW this both for your business’s sake, and the candidates.  If their job requires significant face-time with the client, the importance of presentation skills is almost paramount.

Every organisation needs a couple of people who are their ‘big guns’ in terms of presenting, and they should be brought out when the stakes are high.  Choosing your presenters by availability is asking for trouble.

If you are poor at presenting, this is the one time I will say work on your weakness, it will pay dividends.

[If you liked this article, please share! Want more like it, subscribe!]

I had a conversation the other day that reminded me of a blog post I had meant to write a while back.

When I found myself back in the job market, I realised that I had done nothing to prepare for what amounts to the inevitability of change. I had not written a CV/resume in 13 years, had not spoken to recruiters outside of the hiring process (for my team), and hadn’t interviewed once.

In almost 13 years, not once.

Quite a bit has changed in 13 years. For a start, I’m considerably balder, and fatter, but on the plus side I am also considerably more experienced. However, that experience – like luck – can be good OR bad, and it’s put into context one way or another by those you’ve met along the way. It’s what others think and say about you that makes all the difference, and they are connected as never before, which means a bad reputation can travel far and wide …quickly.

You could have the most polished CV on the planet, a LinkedIn profile second to none, and may even have a blog [cough], but if potential employers ask around (which they will) and get nothing but red flags, you are already at a disadvantage. Everyone you meet at work has the ability to help or hurt you down the road, just as you do to them. This is a power that should never be taken lightly, or abused.

I now see my connections as a safety net that I didn’t know I had. They rallied around me, called, emailed, laughed, gave glowing references, but above all, they reached out to THEIR contacts and passed the word.

It was not long before I was having conversations with people of whom I had never previously heard of, but now count in my corner. Most of these conversations didn’t lead to anything related to employment, but that’s OK, I now have a bunch more people to whom I can turn for guidance or advice in specific areas. Or even better, if they need anything, they know they can now ask me. Our skill-sets are shared, and we no longer have to know the answer to everything, because we know someone who does. That’s how it works; Ask.

However, this is not about what they can do for you. By all means ask for help when you need it, but if this is not mutual, it simply does not work. If you don’t care about the others in your circle, your connections will not last long.

There are a thousand books on networking out there, and you don’t have to be an extravert to do it. By nature I’m introverted, and derive my strength and sustenance from internal resources, but this does not stop me from being genuinely interested in others. Just in small doses, and very select people! 🙂

If there’s one accomplishment of which I am proud after ~13 at the same company, it’s to whom I still talk now, from both sides of the old fences.

So to my circle, I say thank you very much for everything.

How can I help you?

[If you liked this article, please share! Want more like it, subscribe!]