In 2013 I was made redundant from a company where I had worked for the previous 12.5 years. I had grown with the company from the 14th person to join (as a firewall admin) to a position leading 28 people across 14 time zones in a company of over 1,000.

I subsequently discovered that I was basically unhirable, so I started my own consulting practice, which I thoroughly enjoyed. I then joined a very small start-up for a year, which I thoroughly enjoyed, and went back to my own practice.

I swore up and down that I would never go corporate, ever again. I convinced myself that there was never enough freedom, or room for innovation, or ability to make a difference in a large organisation to EVER go back. Not that ‘corporate’ would ever have me back.

Now here I am, at the end of my 3rd week at an organisation that is bigger by far than any I have ever worked for previously.

…and I’m thoroughly enjoying it.

Many times in the course of my blogs I have expounded on the need for self-reflection, on being honest with yourself enough to know when something was entirely your fault, and to adjust your career choices accordingly. Well clearly I had mistaken ‘corporate’ for my own inability to effectively create the change needed to stop me from being made “redundant”.

While I’m not saying I now have that ability, as I will always have a big mouth, when you’re in an organisation who ALL seem to want the change you’ve craved your whole career, it’s a feeling unlike I’ve ever experienced at work. I’ve never needed, or even particularly wanted, to be part of a team growing up, I now find myself in one.

…and I like it.

Frankly I’m not even sure why I’m writing this blog, except perhaps as a tip for those who find themselves in a position where they cannot decide on what’s the right place for them to work. Corporate, start-up, self-employed, or somewhere in between. Every one of my jobs had its benefits, and had its downsides, and I’m under no illusion that this one will be the same. The only difference this time, is that I have now seen both sides of the fence.

It’s not the fence that matters, your skills and talents have no fences.

The only reason I think that corporate fails to attract the truly entrepreneurial is that they are still very attached to job titles and descriptions, effectively pigeon-holing a person into a role that will always limit them. It’s the organisations that go looking for talents to fill known functional gaps, but then get out of the person’s way, that will attract the game changers.

Not saying I’m a game changer, but my title was only assigned to complete a field in the HR system, and my job description was a run-down of the challenges my new organisation was facing. And in just 3 weeks I have not only learned more than I did in the last 6 months, I have a learning curve ahead of me for which I can see no end.

I loved running my own business, and have no regrets about the start-up, but this little adventure is a revelation that has me very excited for the future. And the lesson I learned from all this?;

Don’t limit where you look for your next job, just ask the right questions.

[If you liked this article, please share! Want more like it, subscribe!]

[Ed. June 2016: Clearly this gig did not work out, but I am still not against trying again for the right organisation.]

This blog could just as easily be titled “Information Security Needs Teachers, Not Technology”, but I’ll pick on technology vendors some other time. Then again, it could also be teachers vs. anything-else-you-care-you-mention, because there is nothing in security that cannot be made easier, better, cheaper, more sustainable etc by someone who passes on their skills to those who need them the most.

Their customer.

Teachers are rarely recent graduates of X University, or theoretical researchers at Y organisation (Gartner, Forester et al), and especially not a lot of PCI QSAs I’ve come across, teachers are the people who sit in front of their clients day in and day out trying to make themselves redundant. I use the phrase; “If you can’t do what I do at the end of this contract, I’ve failed.”

Even in 2016, information security expertise is a depressingly rare commodity, with few organisations able to afford the full, or even part-time retention of SMEs in-house. Instead, the vast majority of organisations hire consultants to help them through their security and/or compliance challenges. In and of itself this makes perfect sense, I have no issue with it, and have in fact made a career out of providing these services.

My issue is with those consultants who don’t teach their clients to do what the consultant was hired to do, perhaps with the assumption that the client will have no further need for the consultant’s input once the job is done. The fact is, if the client doesn’t renew the contract, it’s because either 1) they don’t care enough to accept the guidance given; 2) the consultant drained their available budget, or; c) the consultant didn’t know what the Hell s/he was doing.

In a previous blog (The 4 Consultant Types: Know Which You Are, Know Which to Ask For) I detailed the 4 consultant types:

  1. The ‘Auditor’: Extremely detail oriented, and can (and do) write massively detailed reports on exactly what you’re doing wrong. And that’s it.
  2. The ‘Assessor: Still very tied to the written instructions, but are better able to read the intent of the situation, and are subsequently better able to tell you why a things is not right. And that’s it.
  3. The ‘Consultant’: I reserve this title for people who are able to not only explain simply what you are doing wrong and why it’s wrong, but what you should be doing AND provide several options on how to fix it. That’s it for them too.
  4. The ‘Teacher’: These rare folks are able to enormously simplify the challenge at hand, and teach the client to fix it themselves. And not just once, whatever the solution was, the Teacher will show the client how to maintain the fix, and how to implement a cycle of continual improvement in line with business goals.

The silly thing is that a good security teacher will never be out of work, no matter how hard they try to pass on their skill-set. Whatever s/he was hired to do for the first contract is invariably just scratching the surface of the work that needs to be done. A consultant may be asked to come back to repeat a task, but a teacher will be invited to help the entire business move forward.

Every security teacher aspires to be invited to take part in an organisation’s Governance committee, where the IT side and the business side have real conversations. Some call this a Trusted Advisor, but frankly I’ve never seen one who was not a teacher first.

If I was any good at predicting the future, I would be writing this from my yacht in the Caribbean, and not from my kitchen in Southwest London. That said, I do get to work mostly from home, so maybe I’m doing something right.

While my predictions for 2016 will necessarily be as narrow as my field of expertise, there is a lot going on that will eventually change we the way everyone performs many of their daily functions. Probably not this year, and maybe not within the next 5, but once they DO begin to change, there will be no looking back. This is a good thing, and well past its time.

Prediction 1: Identity Management will begin to replace single-factor authentication ANY single form of authentication is inadequate, and even multi-factor and multi-mode authentication is of limited use. For the Internet of Things, payments, or any other transaction to take place securely and accurately in the future, identities must be seamlessly and mutually introduced. Authentication only provides the what-of-you (and usually only in one direction), not the who-of-you, the full function of ‘distributed transactions’ (i.e. mobile based) requires both.

Prediction 2:Identity Management will be decentralised onto consumer mobile devices as a corollary of prediction 1, the control of identities and authentication will decentralise from individual credential stores (user databases) to APIs and/or block chain-esque distributed ledgers that create authentication and identity mechanisms on-the-fly. The level of information provided will be agreed and controlled by the consumer prior to any transaction taking place, and must be mutually assured. i.e. the receiver of the authentication must themselves authenticate, unlike almost all e-commerce today.

Prediction 3: HOW you pay will become increasingly irrelevant you have a value in the bank you want to spend, you should not have to care HOW you get to that value as long as you are getting the best deal to do so. Third Party ‘Money Management’ Services, APIs, and even regulations like the Payment Services Directive 2 (PSD2) here in the EU are forcing traditional financial institutions to open their books. You’ll open ONE application, regardless of which retail store you’re in, comparison shop against price and ratings, and your app wil choose not only the best price and rewards, but the best WAY to pay, all behind the scenes. Credit / debit / direct debit will mean little to you, nor should it, the only thing that matters is that we will eventually stop paying the price of plastic.

Prediction 4: Value-Add Services and Customer Service will be the only differentiators with the enormous competition available to the global economy, price and quality will have little impact on the purchase decisions you make, they will be much the same. Brand loyalty (even if this exists in the future) will instead be driven by the services provided around the products you want; from instant coupons, to ratings and reviews, to reward and loyalty choices, to availability and payment terms, these will be made available instantly in a multi-function app (much like, or even the same as, prediction 3) for consumers to make an educated choice of vendor. But the Customer Service provided throughout the entire consumer journey will be the ultimate differentiator, and any vendor not treating their customer like royalty will be out of the game, regardless of everything they may do well.

Incidentally, this is also why mobile payments have yet to reach anything like their true potential, they are no better than the plastic they will replace.

Prediction 5: Loyalty Programs will begin to centralise I think we can all agree that there are simply too many loyalty and reward programs out there. Every coffee shop, retailer, airline and hotel have their own points scheme, few of which are interchangeable. How many points would you say you have floating around out there that you will likely never use? It just makes sense that the single app provider (per predictions 3 and 4) will begin centralising and normalising any point scheme available. This will be very difficult, but will be their differentiator to which app provider consumers choose.

While these may seem very narrow in focus, perhaps even of little relevance to the ‘masses’, the payments industry alone is a multion-TRILLION £/$/€ industry and the opportunities for innovation and/or investment almost limitless. We already have the device upon which all of these future trends will rely, all we need now are the APIs and Third Party Providers to bring it all together.

Unfortunately we still equate our value with money, and have done for millenia. Money itself is irrelevant, and you work in order to obtain the things you need to survive / be happy, so HOW that transaction is effected should be irrelevant. The above predictions should get us back on track.

Technology and even regulation is pushing simplification down to the consumer, this can only be a good thing.

Done correctly…

Whatever side you are on in the whole privacy debate, you have probably heard variants of the following two arguments:

  1. I don’t care if the Government reads my emails while looking for bad guys, I have nothing to hide, and I feel safer knowing they are doing something; or
    o
  2. There is no evidence that mass digital surveillance has any positive impact on the reduction of crime or terrorism, so my individual right to privacy (UDHR, Article 12) is more important.

Privacy-is-everything advocates will say things like; “Saying you don’t care about the right to privacy because you have nothing to hide, is no different than saying you don’t care about free speech because you have nothing to say.”, or “You can’t give away the rights of a minority, even if you vote as a majority.”

Privacy-as-a-currency advocates will counter with things like; “Saying mass surveillance has no proven benefit is like saying laws are ineffective, you have no idea how many crimes were prevented for fear of being caught.“, or “The minority has no right to impose their will on the majority when personal safety is at stake.

It makes no difference what side you are on, I will not change your mind, and you will not change mine, but we each must pay the same cost for the conveniences and functionality we have come to expect. And accept the responsibility for our choices.

The Internet and now mobile devices have completely changed the way we do business, interact with family and friends, buy stuff, and according to Ian Morris in “The Decline and Fall of Empires”, they will even ‘help’ change our biology;

“As social development rises ever higher, revolutions in genetics, computing, robotics and nanotechnology are beginning to feed back into our biology, transforming what it means to be human.”

Yet we somehow have this expectation that both the Internet and mobile devices are human rights in and of themselves, that we can do whatever we want on them and through them yet still have an expectation for privacy. Governments aside, how can we be so naive?

From my overly simplistic perspective, the world is made up of three kinds of people:

  1. The Good – We don’t have to worry about the good, their lives are spent taking care of whatever it is they care about, which is always in-line with established societal norms / laws, and regardless of the area of influence (i.e. immediate family, community, country, or global);
    o
  2. The Bad – They care nothing for societal norms, they want, so they take. They care nothing for your right to privacy, and outside of instances of gross incompetence, their actions fall almost entirely within your ability to point fingers if you are a victim. IF you can catch them;
    o
  3. The Ordinary – Basically decent, perhaps with a little ‘moral flexibility’ thrown in, who may not like the Bad guys, but understand them enough not to be shocked when they do bad things. These are the majority, and the smarter ones prepare for the worse case scenario.

Laws and rights are written to protect everyone, but not everyone can be protected in the same way. I have contended many times that the more ‘out there’ that’s known about me, the less someone else can pretend to BE me. My life’s story is the equivalent of a public ledger, and any anomalies immediately obvious. This is true for my blogs, my social media, my payment history, and hopefully, even my identity itself.

Of course, there are many people who, quite literally, think I’m 100% wrong, an idiot, or both.

Whatever course YOU choose cannot be seen entirely within the context of your rights, especially ones you are spending every moment you are online.

[If you liked this article, please share! Want more like it, subscribe!]

[Ed. Found this, thought it was well done; Amazing Mind Reader Reveals His ‘Gift’]

Feeling lazy, this is a re-blog, but the last few weeks at work has made this especially relevant;

I started when I was thinking about how superstitions begin; It’s bad luck to walk under ladders, or it’s 7 years of bad luck if you break a mirror for example.  And then it occurred to me that these superstitions were probably the only way to scare children into, or out of, certain behaviour.

Walking under ladders, well duh, things fall OFF ladders, so don’t walk under them. Mirrors used to be really, REALLY, expensive, so telling children that breaking them would have horrific consequences makes a lot of sense. I’m surprised that playing with matches didn’t become a superstition, but then again, household-use matches were not readily available until the 1800’s.

Unfortunately, these things have a way of sticking around long after the original cause is meaningless. Or worse, is twisted and perverted by those with a vested interest in the status quo. ‘Heretics’ were burned at the stake for suggesting that the Earth revolved around the Sun, and not the other way around. ‘Witches’ were similarly killed in horrific ways when they suggested that herbal remedies were better than leaches and other forms of bleeding. Priests and Doctors respectively were very protective of their power.

Human nature has changed very little since then, only societal laws and the more progressive ‘norms’ keep the peace.

I have for years likened information security to insurance, in that no-one wants to spend money on it. They just know it’s a cost of doing business. And more recently I have likened security to the law, because it’s becoming so complex in terms of regulation / legislation / standards etc, that’s it’s often out of reach for the organisations and individuals who need it most.

Now I find myself likening security to superstition, because from the way we’re going, it won’t be long before being in security will have the same stigma as being a tax auditor, a parking enforcer, or a lawyer. QSAs are almost there already because the entire concept of PCI is so limited. However, to me, there is no reason why true security professionals should not be seen in the same light as those responsible for driving revenue, growth, or competitive innovation.

Security departments are something people go out of their way to avoid, or to circumvent. They are seen as the department-who-says-no, who will stifle innovation and good ideas, and generally do the one thing that would label them heretics; get in the way of revenue.

Nothing could be further from the truth, as no other department has the knowledge and DESIRE to do the things that make staying is business possible:

  1. Innovation: It’s the 2000s, the vast majority of innovation now is in technology. Who else is best placed to pick the RIGHT technologies to ensure that innovation is implemented in a way that enhances the organisation and not just adds risk?
    o
  2. Business Transformation: Competitive advantage in the information age is now measure in weeks and months, not years or decades. Organisations without the ability to adjust critical business processes quickly and appropriately will be left behind. What other department has the knowledge of existing processes to enable the adjustments?
    o
  3. Revenue Protection: Can you think of anything worse than seeing all your revenue disappear into the hands of regulators because your focus on selling failed to take into account that your processes for doing so were completely inappropriate. I understand completely the pressures, but revenue generation is not about doing what it takes, it’s about doing what’s right.
    o
  4. Reputation Protection: I could have put this under revenue protection, but wanted to break this out as corporate reputation goes way beyond just revenue, and my OCD will not allow for an even number of bullet points. Damage of reputation through loss of data C.I.A. can have long-term negative effects on a business. Just ask CardSystems who went from $25M / annum to out of business in less than 1 year after their breach.
    o
  5. Infrastructure Investment Optimisation: OK, long title, but consider that the amount of money spent on PCI is already in the multi-billions, when a huge chunk of that could have been save by adjustments in PROCESS. Technology purchase is the last resort of a true security professional.

I really don’t have an answer to HOW we can ensure our reputations remain unsullied, and there are a lot of so called security experts out there giving the rest of us a bad name. But I think the worst thing to do is fall back one of the phrases I hate most in this world; “It is, what it is.”

Actions speak louder than words, and I will never stop trying to show my clients that security is something to be embraced, not avoided.

Forward this to all your friends or you’ll have 3 years of bad luck.

[If you liked this article, please share! Want more like it, subscribe!]