Just chatting with my wife the other day about mentoring, and she raised a very interesting, and valid, point. A coach and a mentor are two very different things, though often used interchangeably. This led to the thought that in the course of our careers, we may ask for (or settle for), and get, the wrong one. Or just as bad, the right one at the wrong TIME!

As I think she described it – bearing in mind she’s a lot smarter than me -, a coach is someone who teaches you to get better at the thing in which they are expert, but a mentor is someone who helps you get better at whatever YOU want to be better at doing. Even if the mentor is not an expert in it themselves. Another way of putting it, is that a mentor helps you think in different ways, understand things of which you have no prior experience, and guide you in scenarios through which you have yet to live yourself.

So which one do we need? Quite simply, both. The trick is to know when you need them, and you will never be able to do that if you don’t know what you want. Or just as importantly; what you are good at. I have posited several times (like in Loyalty vs. Personal Values, and Never Follow the Money), that unless you are ‘honestly introspective’, you will always have challenges that could so easily have been avoided.

Neither a coach, nor a mentor, nor anyone for that matter can help you if you don’t know what it is that YOU want. And if what you want is not realistic, you are basically wasting your time. I’m not saying don’t push yourself, but wanting to be a supermodel or astronaut is only OK for a tiny percent of the population. No offence, but if you’re reading this it’s unlikely you’re one of them.

Word of warning: There is a fine line between a true mentor and someone who wants you to become like them, don’t cross it. Emulation is OK in very few circumstances, and unless your actions stem from YOU as the foundation, they will come across as fake. No mentor will be perfect, they will have an ego, and be easily flattered by your request for help. This can lead them to advise you in ways that are simply not within you to emulate.

From my perspective, I will ask for a coach when there is something I really want to be able to do, and just can’t get my head around. But this will be very specific, and I will control the outcome. As for a mentor, I now have several people in my life who have already done things I am trying to do, and while the relationships are not ‘formal’ in terms of mentor / mentee, I love listening, and they love talking! 🙂

There is absolutely no stigma attached to asking for help of ANY sort, and those who don’t ask, will never achieve as much as those who do. Don’t be a pest, but don’t sit on your arse either.

[If you liked this article, please share! Want more like it, subscribe!]

I think most of us have either heard of, or experienced in some way, this statement; “Employees tend to rise to their level of incompetence.”. (Laurence J. Peter and Raymond Hull)

And some of us, if we’re completely honest, were guilty if it ourselves at some point [cough].

But what happens when it’s the person who started out at the top? By either point-in-time genius, or sheer dumb luck, they manage to take a small company into the big-time.

How do you tell the person at the top it’s time to step down?

There are 3 types of CEO:

o

  1. ‘CEOs’ who are very good at taking an idea to a level where they are noticed by larger companies who wish they had thought of the idea first. But that’s it;
    o
  2. CEOs who are gifted at taking a small company public, and making everyone lots of money. But that’s it; and
    o
  3. CEOs that can lead a company for the long haul. And yes, that’s it for them too.

The BEST CEOs know which they are, and have the ego-less foresight and common sense to step aside when their job is done. Unfortunately the rest end up driving their companies into the ground and taking their employees with them.

Which begs the question; Why is corporate social responsibility almost entirely outward facing?

I have long thought of our places of work as the new communities. Historically, we humans derived a great deal of our security, sense of belonging, and even a large chunk of our identities from the communities in which we lived. But, not any more. At least not in the major cities of the industrialised countries that represent the lion’s share of the people reading this. Physical communities have been replaced by the organisations where we spend increasing amounts of time, especially now that we’re never off-line.

Should CEOs be more accountable to the people they employ? Not for money, healthcare, career advancement etc, but for the more fundamental human needs expressed in the previous paragraph?

A business is not a democracy, and the CEO has no legal obligation whatsoever to do anything of the sort. But is it really so difficult? Security and a sense of belonging just takes a culture that places values on them. As for our identities, don’t we all love buying into a vision of the future? One in which we can believe?

And what’s so wrong with just saying thank you? A SINCERE thank you directly from the CEO to an individual will engender a 100 times more loyalty than an annual 3% cost of living increase.

In a global market where competitive advantages are measured in weeks, not years, and where people can telecommute from half a globe away, the most successful businesses will be the ones where they have the hearts of their people. Not a resignation of things never getting anything better. Innovation and creativity will only be shared within the company if their basic human needs are met, otherwise they’ll take their ideas with them to the competition.

I don’t know if I’ll ever have employees, but I would hope that I treat them with all the respect they deserve, and not as things to be used for my benefit.

[If you liked this article, please share! Want more like it, subscribe!]

Imagine being able to turn the oven on 20 minutes before you get home so it’s ready to start cooking… or taking a quick remote peek into your fridge/cupboards/bread bin to see if you need anything at the supermarket … or re-programming your air conditioning / heating while you’re on Holiday.

All of the above is simple, and already possible, just go here for a bunch of others; http://postscapes.com/internet-of-things-examples/. Some are incredibly far reaching, not to mention awe inspiring.

Along with the exponential increase in convenience, efficiency, and entertainment, is an equal increase in the cost to your privacy, security, and in some cases, your actual well-being. For example, this site http://www.vitality.net/glowcaps.html is about reminding you to take medications. What happens if you start to rely on this with your critical meds and someone ‘hacks’ it?

This blog is in no way a criticism or a doomsday prediction of the trend. I love this stuff and cannot wait until every aspect of my life is a blink, gesture, or eventually a thought away. However, whereas previously our lack of knowledge in basic self-defence principles related to the Internet could have caused embarrassment or the loss of a few quid, the Internet of Things could, quite literally, put your life in danger.

If YOU let it.

As a previous article If You Want More Privacy, Stay Off the Internet stated, the conveniences you crave have a price, and the price is only going to go up the more you expect from it. The Internet is like gambling, only bet what you can afford to lose.

It’s not about the RIGHT to privacy, we all have that as a basic Human Right, it’s that you cannot EXPECT privacy given the inherent insecurity of the medium, the criminal element, and good old fashioned stupidity.

You are not owed security, or perfection, so the due diligence is entirely yours, as is the ongoing maintenance and security monitoring of your new functionality. The things you will be able to do will be unbelievably tempting, but keep these points in mind:

  1. Start Small – don’t sign up for every new thing when it becomes available, you will never be able to track them all, let alone secure them.
  2. Keep it Simple – automated notification of the need for milk is harmless, automating insulin doses is not.
  3. Rely on Nothing – especially when your physical well-being is concerned. Always, ALWAYS have a back-up if your primary mechanism fails.
  4. Minimise the Impact – expose only what you don’t mind losing. Insure everything, especially your finances.
  5. Take Responsibility – blame yourself if things go wrong, don’t waste your time pointing fingers at others. This was YOUR choice, live with it.

Like everything that’s coming in the future, innovation has benefits matched equally by the downside. ‘Government’ will do its best to protect us through laws and regulations, but they will fail to keep up with OUR demand for functionality. Security experts will do their best to protect us, but they too will fail to keep up with the competitive rush to fulfil OUR demand.

Enjoy it, just be careful.

Personally I’m going to be interested in what ‘butt-dialing’ will look like in the next decade. You’ll probably come home to find your vacuum cleaner ordering pizza and watching porn.

Internet of THings

Transformational change has been defined as; “A shift in the business culture of an organization resulting from a change in the underlying strategy and processes that the organization has used in the past.

But this assumes that everyone in the organisation knows what the “underlying strategy” actually is, and what process(es) they should be following!

In the absence of active leadership, employees will tend to focus almost entirely on their day to day tasks without much thought as to how those tasks fit into the overall vision or success of the organisation. Lessons learned are lost, skills and innovation stagnate, and inefficiency is justified by “We’ve always done it this way.”

The old cliche; ‘Knowledge is Power’, is as true now as it’s ever been, but how that knowledge is gathered and shared is radically different. What was once accessible only to those with the passion and dedication to go get it, is now in your pocket. Information in context is knowledge, success however is in the correct application of that knowledge.

It follows therefore, that those with the most accurate information, and the greatest ability to apply it to a significant demand, will be the most successful. So why does this information sit on systems that receive little in the way of attention, care, or priority?

The answer lies in our nature; We tend to take for granted what’s always available. We don’t question running water, power, or access to the internet from our mobile phones, so the unbelievable mechanics of HOW those things happen are ignored in favour of enjoying the benefits of them.

Until they’re not there.

Information security, done properly, involves the mapping of every business process, every system/application/person, and every piece of information related to how an organisation does its business. It then goes on to suggest procedural efficiencies, accessibility improvements, and above all, how to keep it safe, and therefore relevant.

Change is happening faster and faster, and unless your business can keep up, you will be left behind.

In Daniel Burrus’s excellent article; “It’s Time to Change Your Outlook on Change” he states;

However, did you know that most of those changes that come “out of nowhere” are actually very visible months or even years before the change hits? You just didn’t notice it because you were too busy protecting and defending, too busy in the status quo, and too busy putting out fires. In fact, you were so busy that you didn’t spend any time looking into the visible future—the part of the future you can see.

The better your information assets are organised, the faster you can redirect them strategically, the easier you can absorb and correlate new information, and the better you are able to bring the resulting knowledge to bear on your future plans. Competitive advantages, especially in technology, are now numbered in the weeks and months, not years, so the most adaptable will invariably win.

Inspired leadership will always involve an element of foresight. Those with it will keep their organisation ahead of the competition, those without it will follow the latest buzz-words until their business is irrelevant.

Information security has always been seen as something that prevents innovation, slows down sales, and stifles growth. It’s time everyone saw it for what it is; a business enabler that protects the most important thing an organisation has…

Knowledge.

While this is most likely true in every industry, it is VERY true in cybersecurity.

Most organisations above the ‘corner store’ size have some form of ‘in-house’ IT support, even if it’s just the CEO’s brother-in-law, but only the larger organisation will have dedicated in-house security expertise. It’s simply too expensive.

However, most organisations need security expertise – usually when it’s too late unfortunately – so it’s crucial that they are able to define their specific needs in such a way as to attract the right suppliers of those services. Unfortunately, and all too often, the wrong questions lead to the wrong suppliers who provide the wrong services. If they gave you what you asked for, whose fault is it?

Instead, it makes sense to outsource the choice of your security services to someone best placed to judge; a security expert unhindered by organisational or employment commitments. i.e. they are not employed by a security company and are 100% ‘vendor neutral’ in terms of service or product ‘recommendations’.

Of course, you still have the problem of where to find this person, and ensure that they are the right person to make these choices on your behalf, and the responsibility for this due diligence must begin with the person most accountable. Whether this is the CEO, COO, or IT Manager or whatever, the individual who understands the business goals of the organisation needs to be the one asking the questions.

Many large organisations make the curious choice of allowing their purchasing departments to run the vendor selection process, often without specialist security input beyond the most basic of initial requirement definitions. This leads to an RFP that not only asks all the wrong questions, but also to reviews of the responses by people who don’t understand the answers. The choice is then often based on price and not capability turning the whole thing in a debacle.

You don’t allow your dentist to choose which law firm you use to represent you, why would you have anyone other than a security expert define your security solutions?

Even your in-house security team is under certain limitations, and cannot be truly objective with regard their choices. Whether it be pressure from above, fear of making a mistake, or vendor preference / bias, the choices are rarely the optimal result for the organisation. Nothing nefarious, just human nature.

The development of an overarching security program has many moving parts, and every step must be with a view to the end goals, the current needs (risk priorities), and the bit that’s often neglected; how each piece integrates with the next. The purchase of security services, and especial products/technology must be based on not only cost, but of how it will be installed, maintained, managed, monitored, and measured.

This can only be performed by a Governance function that has access to, and guidance from, a true security expert.

I can’t say that I’ve come across a service like this, perhaps I’ll start my own…

[If you liked this article, please share! Want more like it, subscribe!]