Few phrases annoy me more than ‘Trusted Advisor’, not because it’s a bad concept, but because it is most often used by people and organisations that have no right to do so.

Just because you sell security services or products, you are not trusted, or an advisor, you are a vendor. At most you are a consultant, and it’s not until your client has reached the Business as Usual phase in their security programme life-cycle can you begin to be a trusted advisor.

If you have taken your client all the way from your discussion over business goals to Business Continuity Management, then you are in the ball-park. If you have been instrumental in helping your client engender a security culture with senior management buy-in, you are close. Finally, if your client turns to you for guidance related to every aspect of their continued growth and evolution, then, and ONLY then, can you add Trusted Advisor to your resume/CV.

On the other hand, not every organisation is even READY for this level of interaction with security. Most see it as a necessary evil, with limited to no ROI, so trying to dazzle them with a concept such as this is a wasted effort. As in all things, you will have respect when you’ve earned it, and you will only have earned it when you have put the client’s needs at least on the level of your bottom-line.

I am not a believer in altruism (what’s the word for a one-word oxymoron?), and I fully accept business is about profit. What I AM against is profit above value, not EARNING your profit, and not leaving the client better off than when you started. Without ethical values you will never, EVER be a Trusted Advisor.

Besides, calling yourself a Trusted Advisor is like saying you have a great sense of humour, or you’re a good cook, it’s the RECIPIENTS of your service that must bestow this title on you. You don’t ask for thank you notes, it has to be voluntarily provided for it to mean anything.

To me, these are the qualities of a true Trusted Advisor:

  1. Knows their client’s business goals;
  2. Has helped gear the development of the security programme to ENABLE those goals;
  3. Works along-side the senior leadership to help to develop a security culture;
  4. Is an invited member of the Governance Committee;
  5. Is the first person called to help resolve Business vs. IT/IS challenges.

I used the word ‘help’ 3 times in 5 bullets. That should be a good indicator of the real nature of a Trusted Advisor more than anything else.

VERY rarely will you ever achieve this status, which is why it’s such a great goal to strive for with all your clients.

[If you liked this article, please share! Want more like it, subscribe!]

I have been threatening to write a white paper on How to Sell Security for a few years now, but only recently have all the pieces fully come together in my head, and I have had the time to get them into a semblance of order.

The more charitable amongst you will say things like; “Sounds great in theory, but I’m not sure it’s practical.”, or “Very idealistic, good luck with that.” The less charitable will call me all manner of things that equate to me having a colon-esque viewpoint

Fair enough, I’ve never had to run an entire business, and I don’t have investors or shareholders breathing down my neck. However, I know security, and I know what the sale of security services and products SHOULD look like if you’re looking to maintain a long-term partnership with your client base, and you truly have their best interest at heart.

Even I will agree that some of the concepts in the white paper ARE idealistic, and probably impractical in most sales departments – especially American ones – but I have written the paper from a ‘security-purist’ point of view, and with the desire to enable BUYERS of security services and products to choose an organisation that will provide them the best service and value.

Mostly, I’m trying to properly define what it means to be a ‘Trusted Advisor’, and phrase too often bandied around by people and organisations who are neither of those things, let alone both.

Anyway, decide for yourself whether or not I’m truly off the mark, and I look forward to your feedback.

Click here, or go White Papers to get the download.

There are 2 types of Qualified Security Assessor (QSA):  The ‘also-QSA’, who was a security consultant long before PCI, and had performed much of the work as detailed in the Security Core Concept blogs.

Then there are the ‘just-QSAs’ who managed to read a book, pass the CISA/CISM/CISSP exam, and qualify for the ever-so-difficult QSA training. They have delivered nothing but PCI ever since.

In case it’s unclear; first one good, second one bad.

Well, bad for you if you’re one of the ‘justs’, and bad for your clients if you’re all they have to rely on.  You won’t learn how to do security properly, or be able to provide consulting services regardless of the data type, compliance regime, or industry sector. Your clients will never get anything other than tick-in-the-box compliance.

PCI has a shelf life, and I imagine that at the current rate of payments innovation, you have only a few years to diversify. After that there is no way you will be able to maintain your current compensation package. Without some significant experience in non-PCI security areas, your usefulness is limited.

Progress will be difficult if you work for a ‘just-QSA-Company’, because you HAVE nothing else to do. You may want to seriously consider working for a security company that’s in the ‘also’ category.  There are many.

You probably have a training budget too, so spend it.  ISO Lead Auditor, CIPP/X, CLAS (UK), ITIL, Prince II, while not all security specific, are most certainly relevant. Relevant to providing the kind of  guidance that is in depressingly short supply.  If you can use this training to your current company’s benefit, great. If you can help them design non-PCI services, you are way ahead of the game.

However, there is a better than average chance that your career preferences will fall more on one side or the other of ‘business-focused’, or ‘technical-focused’. It’s important therefore that you NOT try to embrace all 6 core concepts at once.  Even security experts need to specialise.

What we are all working towards is an understanding that IT and IT security are business enablers, not a roadblock. PCI is ‘just an expense, with limited to no return on investment’, or at least thats how it is mostly seen.  Our job is to put security into a business context so that the benefits are clear to every level of the organisation.

The CEO cares about the bottom line, s/he does not care about the detail until that detail gets in the WAY of business.  This is why there is so little management buy-in when it comes to security and compliance.  If we can show that a well run IT infrastructure enables business transformation, innovation, enhanced efficiency and so on, we’ll have demonstrated our worth.

THAT’S our job, not just protecting credit card data with a minimal set of security controls to which you had no input.

The fundamentals of security have never changed, and won’t any time soon. So if you take the time to get back to basics, you’ll future-proof your career.

Security is simple, it’s not easy, but it is simple.

The very word ‘security’ conjures up feelings of safety, honesty, and integrity.

Business Ethics on the other hand conjures up this;

Business Ethics

[The irony is, I completely stole the ‘Demotivator’ idea from www.despair.com!]

The phrase ‘business ethics’ itself is used as an example of an oxymoron, like ‘military intelligence’, ‘happily married’, and ‘PCI compliance’. But that’s because it is not well understood by the vast majority of the population. After all, how do you teach morality?

Business ethics is the difference between right and wrong. Not in terms of business decisions, but in terms of accepted societal norms; don’t steal, don’t lie, don’t dump toxic waste and so on. Corporations should be every bit as accountable to society as are the individuals themselves. We shun adulterers, thieves, letting agents and so forth, yet we allow Amazon/Google/ et al to get away with enormous tax shelters.

Negative connotations aside, business ethics is almost the same as Corporate Social Responsibility (CSR). I think most people will agree that more responsibility is better than less.

Unfortunately, the security industry has just as many ‘profit-before-service’ CEOs as any other industry sector/vertical. But to me this is somehow worse, like a crooked cop.

As security professionals, we have an enormous amount of influence over our clients. This is the Information Age, and we are the ones who are supposed to help them protect their data. From intellectual property to personal information, the impact of loss can be very severe at both the corporate, and personal level.

Dramatic though this is, if a company goes out of business because of a data breach, the livelihood of every family of every employee is affected. And what about identity theft? This can be absolutely devastating to the victim.

Yet despite this responsibility, it is still seen as ‘just business’, with no thought to either the short term best interests, or the long term sustainable growth of our clients.

What are the Signs?

o

Here are a few warning signs of whom to avoid:

  1. The organisation has no obvious vision or values – This I have mentioned a dozen times at least, and is a direct reflection of the CEO’s lack of vision and values.  Perhaps worse than this, is an organisation that either OUTSOURCES the development of their vision statement, or asks their employees what is should be.  See Loyalty vs. Personal Values.
    o
  2. The other organsation’s vision and values don’t match those of YOUR organisation – just as individuals can be incompatible, so can companies.  If yours is passionate about community outreach, or being ‘green’, or charitable contributions, and your partners aren’t, this could lead to conflict in the area of business ethics.
    o
  3. They try and sell you as much product as possible without making any effort to put this technology into context. Usually with the necessary consulting wrappers. See Insecurity Through Technology.
    o
  4. Their products are sent to market long before they are ready and they don’t work as advertised. Or they don’t support your compliance efforts.  That said, the due diligence is entirely your responsibility, and an assessment of a product is really quite simple. See Vendor Due Diligence: Assessing Cloud / Service Providers as an example.
    o
  5. Ex-employees are less than flattering, or – hopefully for them –  just say nothing.

Sustainability is a direct extension of business ethics, and you owe it to both yourself, and your organisation to ensure that you are doing your part.  Companies are the new communities, so there is no such thing as “It’s only business.”

[If you liked this article, please share! Want more like it, subscribe!]

One of these days I will learn to do some proper research on my blogs in order to provide the links to materials that I only assume exists. I can say there are thousands of articles out there on presentation skills, and not quote a single one.

Not going to this time either, but when I type in ‘presentation skills tips’ into Google, I got 17.5M hits, so it’s out there.

This is not about HOW to present though, that’s been covered by people far better at it than me, this is about WHEN to present, or more specifically, when NOT to.

A phrase occurred to me today that I feel sure I’ve stolen (and more than likely corrupted) from someone else, but I can find it’s like;

A good idea presented badly, is often less effective than a bad idea presented well.” 

To illustrate, I will go to the extremes.  Fascism is a VERY bad idea, but I know of two people in history that turned their entire countries to it.  Ending World hunger is a VERY good idea, but the altruistic pleas of those who dedicate their lives to it, fall on mostly indifferent ears.

How is this possible?  Well, the two Fascists I’m thinking of were incredibly charismatic (according to the history books), and understood human nature innately (exploitive).  The people who want to end world hunger are usually too busy working toward that goal to do the rounds, and the chances are, they are not much into oratory (givers).

Humans are basically good, and it’s not that we don’t care, it’s that we have our own lives to get through, and we are generally far more receptive to the concept of mutual benefit than we are towards ‘one sided’ charity.

So what does this have to do with presentations?  Let me ask you; Are you good at presenting, and do you enjoy it?

I can guarantee that more people THINK they are good at it than actually are, and that the ones that don’t enjoy it, never are.

So whom do you want presenting your business plan to angel investors?  Or whom do you want presenting your company’s proposal for a multi-million $/£/€ deal?  Right, someone who’s really good at it, but for some reason this is not always a prerequisite.

Presentation skills are up there with any skill you want for your business, from sales, to finance, to consultancy, to R&D, and should be every bit as important a entry on your CV/resume as your education and work experience.  Smart hirers even have their candidates perform a presentation during the interview process.  Candidates have 1 hour to create a 5 slide presentation, and 15 minutes to delivery it + Q&A.

I’m not saying don’t hire people who CAN’T present well, they may simply not have the experience, but you have to KNOW this both for your business’s sake, and the candidates.  If their job requires significant face-time with the client, the importance of presentation skills is almost paramount.

Every organisation needs a couple of people who are their ‘big guns’ in terms of presenting, and they should be brought out when the stakes are high.  Choosing your presenters by availability is asking for trouble.

If you are poor at presenting, this is the one time I will say work on your weakness, it will pay dividends.

[If you liked this article, please share! Want more like it, subscribe!]