Analogy: A family member needs surgery, and you have two doctors in a side-by-side bake-off. One is respected, enormously experienced, and expensive. The other is fresh out of residency, inexperienced, and cheap.

Whom do you go for?

Unless you’re a sociopath, you pay for the one with the greatest expectation for success. So by a similar (though far less life threatening) extension, why would you cheap out on your choice of QSA? Or any consultant that matter?

Not only that, you probably expect the same results from every QSA, right? They all went through the standard training, so they should all be the same, right?

Are all doctors the same?

Like any profession, you have a MINIMUM standard to achieve before you start. For QSAs it’s 5 years in security (no-one lies on CV’s/resumes, right?), OR a CISA/CISM/CISSP (anyone can read a book and pass a multiple choice test), AND pass the QSA test. I can, quite literally, take ANY person and get them to a point they can pass that test in one week.

Instead of focusing the QSA test on their domain knowledge (networking, encryption, policy formation etc.) it focuses on merchant / service provider levels and a bunch of other stuff that does not test the consultant’s security or auditing skills in any fashion that makes sense to me. Can they read a firewall ruleset to determine if they have met the intent of requirements 1.X? Can they look at a netstat and see if their OS configuration standards are being followed per requirements 2.x?

The answer to those questions is; not necessarily, and while I cannot think of one security consultant who is an expert on all 12 DSS sections (I suck at encryption and anything to do with coding for example), you need someone with real-world experience to measure your compliance against not only the standard, but its intent. And if that intent does not align with the goals of the business in question, the process falls apart.

When it comes to PCI, you’re paying for experience / guidance / been-there-done-that, otherwise you’re better served doing it yourself. At least you know the business better than the QSA ever will.

I wrote something resembling a white paper on Selecting The Right QSA For Your Business a few months ago, and will be building on this process over the next few months. Anything is simple if you know how to do it, but that’s the point; YOU probably don’t know how to do PCI, nor would you then know the right questions to ask to find someone who does.

This may sound like I’m trying to push you into hiring only the expensive guys, but that’s not it, it’s never just about the money, it’s about VALUE for, and appropriate USE of, money. The issue most often is that businesses choose their QSA based on price. They didn’t want to do PCI compliance in the first place (believe me, no-one WANTS to do PCI), and therefore settled for the lowest bidder.

In my fairly significant experience, the cheapest QSA up front rarely ends up being the cheapest in the end. These are the top 5 things to watch out for, and reflect the SOPs of some of the less scrupulous vendors;

  1. Scope Creep – A proposal written in such a way that you THINK you’re buying what you need, but you end up having to buy additional services from them to finish the job;
    o
  2. Cheap Labour – You get what you pay for, and if you pay pennies, you’ll get the least experienced QSA at their disposal (this one serves you right by the way);
    o
  3. Pushing Other Services or Products – Some of the larger QSAs have entire suites of products and services they try and push your way. They will sell the QSA for cheap hoping to massively up-sell/cross-sell the more profitable managed services / products etc. This is permissible under the SSC regs., but hardly best practice, and in some cases even ethical, especially when the products don’t even support your compliance;
    o
  4. Lack of Appropriate Guidance – Achieving PCI compliance the first time is a project, staying complaint is a process. At no time during the assessment should there be roadblocks that are a direct results of the QSA’s inexperience. Projects that should take months often take years, and the additional costs can be significant;
    o
  5. The True Cost of Compliance – Usually the most significant cost of a PCI project is the labour cost of internal resources. Performed correctly, PCI can have significant benefits in terms of improved security posture, but unless the resources are used efficiently, the cost to the business can be very significant, especially in terms of availability for initiatives related to transformation or innovation.

In the end, you will get what you pay for, and if you have not chosen your QSA based on best-fit, you deserve what you get. Choosing a QSA / consultant is relatively simple, and I believe that It Takes A Consultant, To Hire A Consultant.

If you need help, do your homework, then ask the opinion of someone with zero vested interest.

[If you liked this article, please share! Want more like it, subscribe!]

We’ve all seen these signature blocks;

[Name], CISSP, CISM, CISA, QSA, CRISC, CGEIT, PCIP, ISO LA, ITIL, Prince II, blah, blah….

These acronyms belong in two places; your LinkedIn [and equivalent] profile, and your CV/Resume/Bio. They have no place in your email signatures, nor on your business cards.

It’s not like we studied for a number of YEARS to get a MSc, or PhD. We read a book, and passed a multiple choice exam. We didn’t even have to know how to IMPLEMENT what we learned, we just had to memorise and regurgitate. Most questions end up being a 50/50 guess anyway if you don’t actually know the right answer.

I’m not saying certifications are totally meaningless, they are a great beginning for those trying to break into the cybersecurity industry, but once in, it’s your experience that needs to do the talking for you. Or better yet, the clients you helped do the talking for you. Your certifications show that you have some commitment, and who knows, maybe you’ll even learn a couple of things that are useful. But these things don’t help you much when you’re face-to-face with a real client asking for your guidance, and all you can do is read from a book.

Learning anything new is messy. You’re clumsy at first, you make LOTS of mistakes, and you may begin to doubt yourself. But get past that first client, the one who you helped …eventually, the one who actually thanked you afterwards, and THAT’S when your learning really starts. You EARNED that, and it’s not a feeling you’ll ever get from an acronym or a book.

With security, there are no certification that really get to the fundamental point, the meaning behind all of this. I guess CISSP gets the closest because its 10 Common Bodies of Knowledge (CBKs) cover things from Risk Management to Business Continuity, but no-one really cares about that stuff at senior leadership level, it’s just detail.

What’s important is STAYING in business, growing, going international, going public, shareholders and so on, and not one certification out there helps you explain to the CEO how IT and IT security can help get them there. No certification ever will, it’s something you have to learn for yourself, and something that will change with every client with whom you work.

There are no certifications for, or shortcuts to, being a consultant who ‘gets it’.

I have likened security to insurance, but that’s not really fair. Selling security is like selling insurance, but in the end insurance is just risk mitigation, security is business enablement. Security is not the goal, and it’s easy to get caught up in the moment and forget why we are really there in the first place.

So, as for your signature blocks, far better I think is to have the number of years you’ve been in cybersecurity, and the number of clients you’ve helped. Something like;

David Froud

Years In Cybersecurity: 17, Clients Helped: Hundreds

Think it’ll catch on? 🙂

[If you liked this article, please share! Want more like it, subscribe!]

While this is most likely true in every industry, it is VERY true in cybersecurity.

Most organisations above the ‘corner store’ size have some form of ‘in-house’ IT support, even if it’s just the CEO’s brother-in-law, but only the larger organisation will have dedicated in-house security expertise. It’s simply too expensive.

However, most organisations need security expertise – usually when it’s too late unfortunately – so it’s crucial that they are able to define their specific needs in such a way as to attract the right suppliers of those services. Unfortunately, and all too often, the wrong questions lead to the wrong suppliers who provide the wrong services. If they gave you what you asked for, whose fault is it?

Instead, it makes sense to outsource the choice of your security services to someone best placed to judge; a security expert unhindered by organisational or employment commitments. i.e. they are not employed by a security company and are 100% ‘vendor neutral’ in terms of service or product ‘recommendations’.

Of course, you still have the problem of where to find this person, and ensure that they are the right person to make these choices on your behalf, and the responsibility for this due diligence must begin with the person most accountable. Whether this is the CEO, COO, or IT Manager or whatever, the individual who understands the business goals of the organisation needs to be the one asking the questions.

Many large organisations make the curious choice of allowing their purchasing departments to run the vendor selection process, often without specialist security input beyond the most basic of initial requirement definitions. This leads to an RFP that not only asks all the wrong questions, but also to reviews of the responses by people who don’t understand the answers. The choice is then often based on price and not capability turning the whole thing in a debacle.

You don’t allow your dentist to choose which law firm you use to represent you, why would you have anyone other than a security expert define your security solutions?

Even your in-house security team is under certain limitations, and cannot be truly objective with regard their choices. Whether it be pressure from above, fear of making a mistake, or vendor preference / bias, the choices are rarely the optimal result for the organisation. Nothing nefarious, just human nature.

The development of an overarching security program has many moving parts, and every step must be with a view to the end goals, the current needs (risk priorities), and the bit that’s often neglected; how each piece integrates with the next. The purchase of security services, and especial products/technology must be based on not only cost, but of how it will be installed, maintained, managed, monitored, and measured.

This can only be performed by a Governance function that has access to, and guidance from, a true security expert.

I can’t say that I’ve come across a service like this, perhaps I’ll start my own…

[If you liked this article, please share! Want more like it, subscribe!]

Few phrases annoy me more than ‘Trusted Advisor’, not because it’s a bad concept, but because it is most often used by people and organisations that have no right to do so.

Just because you sell security services or products, you are not trusted, or an advisor, you are a vendor. At most you are a consultant, and it’s not until your client has reached the Business as Usual phase in their security programme life-cycle can you begin to be a trusted advisor.

If you have taken your client all the way from your discussion over business goals to Business Continuity Management, then you are in the ball-park. If you have been instrumental in helping your client engender a security culture with senior management buy-in, you are close. Finally, if your client turns to you for guidance related to every aspect of their continued growth and evolution, then, and ONLY then, can you add Trusted Advisor to your resume/CV.

On the other hand, not every organisation is even READY for this level of interaction with security. Most see it as a necessary evil, with limited to no ROI, so trying to dazzle them with a concept such as this is a wasted effort. As in all things, you will have respect when you’ve earned it, and you will only have earned it when you have put the client’s needs at least on the level of your bottom-line.

I am not a believer in altruism (what’s the word for a one-word oxymoron?), and I fully accept business is about profit. What I AM against is profit above value, not EARNING your profit, and not leaving the client better off than when you started. Without ethical values you will never, EVER be a Trusted Advisor.

Besides, calling yourself a Trusted Advisor is like saying you have a great sense of humour, or you’re a good cook, it’s the RECIPIENTS of your service that must bestow this title on you. You don’t ask for thank you notes, it has to be voluntarily provided for it to mean anything.

To me, these are the qualities of a true Trusted Advisor:

  1. Knows their client’s business goals;
  2. Has helped gear the development of the security programme to ENABLE those goals;
  3. Works along-side the senior leadership to help to develop a security culture;
  4. Is an invited member of the Governance Committee;
  5. Is the first person called to help resolve Business vs. IT/IS challenges.

I used the word ‘help’ 3 times in 5 bullets. That should be a good indicator of the real nature of a Trusted Advisor more than anything else.

VERY rarely will you ever achieve this status, which is why it’s such a great goal to strive for with all your clients.

[If you liked this article, please share! Want more like it, subscribe!]

One of my favourite quotes from The Dark Knight; “You know what I’ve noticed? Nobody panics when things go “according to plan.” Even if the plan is horrifying!”

A little dramatic perhaps – not to mention some of the best acting of all time – but this directly applies to customer service.

Your clients don’t get anywhere near as angry if you come to them with a potential issue, it’s when they have to constantly chase you for resolution of a KNOWN issue that things go horribly wrong.  If your customer service is only ever reactive, you have failed, and if you can’t even react well, you are out of the game.

From my favourite website ever, www.despair.com;

customerdisservicedemotivator

Type in the phrase ‘customer service’ into Google and you’ll get over 8 BILLION results. There are institutions and college degrees dedicated to it, books by the thousand, and articles and blogs by the million (this one is very good; 8 Rules for Good Customer Service, by Susan Ward), yet how do organisations STILL get it wrong?

That’s easy, blame the CEO (or equivalent).

Just as a lack of a security culture is the CEOs fault, lack of a Customer Service culture is every bit as much on their shoulders.  As I stated incessantly; “Let’s be very clear; The CEO sets the tone for the entire company: its vision, its values, its direction, and its priorities.  If the organisation fails to achieve [enter goal here], its the CEOs fault, and no-one else’s.”

Replace “enter goal here” with “Customer Satisfaction”  and the rest is the same.

The symptoms of the inability of some organisations to provide good customer service (the CEO being the cause) can include;

  1. Poor selling techniques – if salespeople are not trained to sell only what the customer needs (not wants or even asks for), the organisation behind this salesperson will be unable to support the customers questions.  I don’t care how nice you are, or how great your products, if you’ve sold something the client doesn’t need, they will rarely buy from you again;
    o
  2. Poor products or services – there’s a fairly good chance that if your vendor does not provide good customer service, the other services and products provided by them are suspect, and should be reviewed.  Do your research, and ALWAYS ask for a proof of concept (POC) before you buy.  No POC, no purchase;
    o
  3. Black-hole communication – No-one wants to be yelled at, so if your calls and emails are going unanswered, there’s a very good chance you aren’t going to like the answer when you finally get them.  This is also an extension of 2.  And finally, forget how quickly the salesperson comes back to you BEFORE the sale, how are they immediately after?;
    o
  4. No Customer Service SLAs built in – in other words, if you have to ask for SLAs related to communication, or even something as simple as response times, there’s a good chance you won’t get the service you’re looking for;
    o
  5. Very low renewal rates – include this question in your RFP for new services and products, and have them prove it;
    o
  6. Limited, or no references – this one is too obvious  to expand on, but ignore industry awards, they are a farce.

An organisation that truly embraces a customer service culture will probably allude to it in their Vision Statement, and almost definitely in their Values.  Do business with only those organisations that take the term ‘partnership’ seriously, especially in security, and ANY company that bandies around the phrase ‘Trusted Partner’ needs to be taking client satisfaction to the next level.  Are they?

Good customer service is even simpler than security, and far less difficult to achieve, you just have to treat it as a foundation of doing business.  Your clients happiness is more important than your profit.  If you don’t believe that, you don’t care enough about them to give them what they need.

In one respect or another, we are ALL customer service reps, and this (to me) is the definitive guide to being a good rep; How To Win Friends And Influence People, by Dale Carnegie.

Yes I’ve read it …twice, and yes, I still have a lot of work to do 🙂

[If you liked this article, please share! Want more like it, subscribe!]