Been composing this blog for several months now, and it started when I was thinking about how superstitions begin; It’s bad luck to walk under ladders, or it’s 7 years of bad luck if you break a mirror for example.  And then it occurred to me that these superstitions were probably the only way to scare children into, or out of, certain behaviour.

Walking under ladders, well duh, things fall OFF ladders, so don’t walk under them, and mirrors used to be really, REALLY, expensive, so telling children that breaking them would have horrific consequences makes a lot of sense (in a very negative way of course). I’m surprised that playing with matches didn’t become a superstition, but then again, household-use matches were not readily available until the 1800’s.

Unfortunately, these things have a way of sticking around long after the original cause is either meaningless, or worse, is twisted and perverted by those with a vested interest in the status quo. ‘Heretics’ were burned at the stake for suggesting that the Earth revolved around the Sun, and not the other way around*, and ‘witches’ were similarly killed in horrific ways when they suggested that herbal remedies were better than leaches and other forms of bleeding. Priests and Doctors respectively were very protective of their power.

Human nature has changed very little since then, only societal laws and the more progressive ‘norms’ keep the peace.

I have for years likened information security to insurance, in that no-one wants to spend money on it, but they know it’s a cost of doing business. And more recently I have likened security to the law, because it’s becoming so complex in terms of regulation / legislation / standards etc, that’s it’s often out of reach for the organisations and individuals who need it most.

Now I find myself likening security to superstition, because from the way we’re going, it won’t be long before being in security will have the same stigma as being a tax auditor, a parking enforcer, or a lawyer. QSAs are almost there already because the entire concept of PCI is so limited, but there is no reason true security professionals should not be seen in the same light as those responsible for driving revenue growth or competitive innovation.

Security departments are something people go out of their way to avoid, or to circumvent. They are seen as the department-who-says-no, who will stifle innovation and good ideas, and generally do the one thing that would label them heretics; get in the way of revenue.

Nothing could be further from the truth, as no other department has the knowledge and DESIRE to do the things that make staying is business possible:

  1. Innovation: It’s the 2000s, the vast majority of innovation now is in technology. Who else is best placed to pick the RIGHT technologies to ensure that innovation is implemented in a way that enhances the organisation and not just adds risk?
    o
  2. Business Transformation: Competitive advantage in the information age is now measure in weeks and months, not years, organisations without the ability to adjust critical business processes quickly and appropriately will be left behind. What other department has the knowledge of exiting processes to enable the adjustments?
    o
  3. Revenue Protection: Can you think of anything worse than seeing all your revenue disappear into the hands of regulators because your focus on selling failed to take into account that your processes for doing so were completely inappropriate. I understand completely the pressures, but revenue generation is not about doing what it takes, it’s about doing what’s right.
    o
  4. Reputation Protection: I could have put this under revenue protection, but wanted to break this out as corporate reputation goes way beyond just revenue, and my OCD will not allow for an even number of bullet points. Damage of reputation through loss of data C.I.A. can have long-term negative effects on a business, just ask CardSystems who went from $25M / annum to out of business in less than 1 year after their breach.
    o
  5. Infrastructure Investment Optimisation: OK, long title, but consider that the amount of money spent on PCI is already in the multi-billions, when a huge chunk of that could have been save by adjustments in PROCESS. Technology purchase is the last resort of a true security professional.

I really don’t have an answer to HOW we can ensure our reputations remain unsullied, and there are a lot of so called security experts out there giving the rest of us a bad name, but I think the worst thing to do is fall back one of the phrases I hate most in this world; “It is, what it is.”

Actions speak louder than words, and I will never stop trying to show my clients that security is something to be embraced, not avoided.

Forward this to all your friends or you’ll have 3 years of bad luck.

My rather unusual theory; that too much privacy might actually reduce your security, stems from a few things:

1) Security is all about baselines, and anything that falls outside of those baselines should be prevented, or at least investigated;

2) Everything you do in life is based around one thing; your identity. Relationships, work, and everything you do over the Internet is a direct reflection of all the things that make you, you. It’s the AUTHENTICATION of your identity that enables your everyday actions online. It also exposes your data, and;

3) The one thing that has no place in pro-active security; Big Data, actually has an enormous role to play in your privacy and the security of your identity. Somewhat counterintuitively, it’s the big data that provides the baseline from which your identity can be protected.

Most of us know that your spending patterns are what the banks / card brands use to detect potential fraud, but this data is only a small part of your identity, the sum of which includes (but is not limited to); your location, work history, financial history, family and friends, likes and dislikes, and pretty much everything you’ve ever posted online.

What if your identity could be profiled? Not in the negative way used to profile ‘possible terrorists’, but in a way that prevents someone else from being you. For example:

1) Why would you buy an international airline ticket if you don’t have a passport, or if you have never previously left your own country?;

2) Would someone start posting hate filled messages on FB /Twitter etc. if all they’ve posted previously are funny cat stories?;

3) Would someone change address and order new credit cards if nothing in their ‘profile’ suggested they were moving?;

4) Would someone go on a spending spree, when their ‘profile’ suggests a lifetime of frugality?;

…and so on.

The answer to all of these questions, is maybe, and except for 2., they most certainly should not be stopped from performing these legitimate actions, but there COULD be a greater degree of due diligence on the part of the organisations fulfilling these requests to confirm identity first. This is only possible if they have access to a profile from which to make these necessary decisions.

The profile does not have to contain all of your deepest darkest secrets, but enough of your identity has to be available for organisations to make judgment calls. Yes, this could be used for targeted marketing (not everyone is covered by the GDPR), and yes, bad people will always find ways of using a ‘profile’ for more nefarious reasons, but we already HAVE many forms of profiling that we take for granted; credit scores, CV/resumes, social media content, circle of friends, clubs / associations and so on.

The use of these existing profiles for good and bad is not so much in the individual components, it’s in the whole, and it’s one of the rare instances where the whole is in fact greater than the sum of its parts. However, the more information that’s out there should lead to a safer profile due to numerous overlapping and cross-referenced checks and balances, all of which report back to you.

Of course, there will always be those who instantly assume this will become an Orwellian dystopia and move to a cabin in the woods, and there will be those who see it as a utopia and jump in head first. The answers for the rest of us lie somewhere in-between, and will evolve over time.

This generation is already making it happen in my opinion, with the prevalence of social media entire lives are being documented online, and the apparent lack of common sense when it comes to posting compromising selfies suggests that our idea of what’s ‘private’, is not theirs. What my generation cares about, cannot be forced upon the next, and our values cannot dictate how the next generation leads their lives, but what we CAN do is design an identity framework that turns privacy into what it’s always been; a form of ‘currency’ for which YOU need to take full responsibility.

Spend too much and you’ll have no identity to call your own, spend too little and you’ll be left behind.

What you want, and what we don’t currently have, is a choice.

[If you liked this article, please share! Want more like it, subscribe!]

You may be asking if these are not the same thing expressed different ways, but I make the following distinctions:

Loving what you do is about the field you are in, the detail of the day-to-day, or your chosen industry sector. For example; nurses, fire fighters, teachers, research scientists, professional athletes and so on, all love what they do. They love it whether or not they are the best at it, and would keep doing it even if it meant they will never be highly successful in material terms.

To love doing what you’re good at means that it does not matter the field you are in, it is not a passion in and of itself. It means that you are doing something at which you excel, thoroughly enjoy, and would keep doing regardless of the industry sector in which you currently find yourself.

It has taken me 46 years to realise that I have not missed out on anything by not having a passion related to any topic. I always envied people who knew from the age of 6 they wanted to be a dentist, or a soldier, or what not. To me, NOT having a passion meant I was destined to only ever be average at something, because I assumed that without passion, I would never have the energy or interest to be the best.

I don’t even have a hobby.

Recently however, I came to the realisation that there are at least two forms of passion; passion-in-the-thing, and passion-in-the-process. Passion-in-the-thing relates directly to loving what you do (e.g. nurse), and passion-in-the-process relates to loving to do what you’re good at (e.g. fix broken things). One is not better than the other, but while passion-in-the-thing usually becomes obvious at a very early age, passion-in-the-process can go a lifetime without being realised.

If you let it.

I am 100% in the passion-in-the-process camp, which will become obvious when I make the following statement; I actually don’t care about information security.

What?! (you gasp) You write a blog that positively DRIPS with passion (or angst, depending on your point of view), how can you say you don’t care?!

Because it’s not information security I care about, it’s the PROCESS of simplifying a difficult concept until it’s available and understood by those who need it that gets me going. Simplifying is a passion, and helping people and organisations get the BENEFIT of security is a passion, security itself is not. I could just as well be in advertising (for example) and love my job, but I’m neither creative enough, nor do I have the patience / inclination to start my career all over again.

Why this is so exciting to me, and why I bothered to write this blog in the first place, is that ANYONE can do what they’re good at! In my experience, only a few people ever find a true passion for something specific, and fewer still make a career out of it, but if you can take the WHAT out of the equation, and replace it with HOW, this becomes available to everyone. I think I’m right in saying that, almost by definition, there is no scale in passion, you have it or you don’t (like Billy Connolly’s “F&%$ off, he hinted!“). This makes both forms of career passion equal.

Actually, I should say that everyone who makes the effort to understand themselves can do this, but so few do. I touched upon this in one of my earlier blogs; Never Follow the Money, but I missed the point when I suggested that more introspection is required to find the things you’re good at, and to focus on those. Yes, you should absolutely do that, but unless you accept passion-in-the-process as an equal alternative to passion-in-the-thing, you will probably still be discontent with your choices. Perhaps assuming that your life will really only start when you find someTHING you love.

It does not have to be a thing.

Finally, the best part about all of this is that it’s NEVER too late in your career for you to discover either of these passions, but only passion-in-the-process is something you can work towards right now, today, you just have to stop using a lack of passion-in-the-thing as an excuse not to get what you want, whatever that may be.

[If you liked this article, please share! Want more like it, subscribe!]

If you are reading this while on public transportation, at a bus stop / train station, look up, and look around. How many people are looking at a mobile device of some kind? 40%? 50%?

Now, how many of those are children? Or if you’re a parent, does your child have a smartphone? A PS3/Xbox? And finally, how much time do you think these kids are spending on those devices?

It’s bad enough that I, a 46 year old ‘technology professional’ spend an inordinate amount of time plugged-in and not exercising, it’s quite another to see a 10 year old who’s overweight and completely disconnected from the world around them.

So, whether you are proponent of the Internet of Things or not, I see it as a perfect opportunity to ensure that children see technology as the privilege it is, and not as an expectation, and certainly not as something to be taken for granted. No child has earned the right to waste away in front of an electronic device, they can do that later if the wish, and once they are out on their own paying their own bills. Like me.

The proposition: With innovations around micro-sensors, geo-location and a whole host of other inputs, it should be relatively trivial to measure the amount of exercise your child is getting on a daily basis, and tie that directly into the amount of ‘play time’ they get on their smartphones or video games. The more exercise they do, the more time they have, and when your time is up, the video games are locked out, and your smartphone reverts to phone only.

You could even build in an ‘management station’ where parents could set tasks, chores, grade requirements etc, and the more the child does, or the better they perform, it all works its way into more time playtime on their electronics. Of course, this will all need to be fun as well, there’s no point in teaching the next generation that exercise is itself a boring chore, but every child has to learn that everything has a price, even if that ‘price’ is something that’s actually good for them.

It would however, be very important not punish a child that finds a way to beat the system. Any creative method they have to ‘cheat’ is an indication of a burgeoning talent. For example, a child who..:

  • …gets their friends to wear their sensors to exercise on their behalf shows someone with creativity, influence, and leadership skills.
  • …works out how to ‘double up’ on their sensor input shows skills in problem solving, efficiency generation and engineering.
  • …hacks the system and re-wires either the input mechanism or the underlying application is going to start the next Google.

While you clearly can’t allow their breaking of the rules to continue, gearing their e-playtime bonuses to rewards for solving similar challenges is a way to make the whole thing not only fun, but a learning lesson as well.

Children are extraordinarily creative when not suppressed by adults, so why not let them have at it while at the same time ensuring that they stay healthy?

Obviously this technology would have just as many benefits to adult health as well, and I have literally dozens other ideas for its application, but I’ll leave that to people with a little more time on their hands. I think a company name of e-PlayTime would work very well…

After giving the title question a little thought, you probably fall into one of three camps:

  1. You were immediately able to choose which one you preferred based on your own interpretation of the two emotions, or;
  2. You were confused because you can’t separate one from the other, or;
  3. You immediately chose one because you think it leads to the other

There are no wrong answers here, this is way too personal an issue, but I have been pondering the difference between the two for a while now, and in light of one fact; I have be happy more times than I can count, but have been content only once.

I’m lucky, I’m genetically predisposed to being happy (see Can Happiness be Genetic?). Not all the time obviously – just ask anyone who’s ever worked for me – and quite frankly, I’m glad. No offence if you’re one of them, but people who are always happy are irritating, especially the ones who are clearly faking. I’m happy when my wife makes pancakes, or her queso sauce, so a good day is never far away!

But contentment, that’s something completely different, and I can remember the one time I was content in great detail. I won’t bore you with full detail, but I was driving down the DC Beltway, alone, and this strange feeling came over me. At first I was a little nervous and almost pulled over, but then I realised what it was and managed to revel in it for about 10 seconds before it went away.

That was 20 years ago.

The only reason I share that is because I could not help but think that being content is the ultimate feeling, and thought how great it would be if everyone felt that way all the time. But then it occurred to me that there is one other human trait that will probably never allow for permanent contentment in any but a select few; curiosity. Not just basic curiosity, like; Who won the World Cup in 2010? But the deep down human curiosity that has driven our species to create, to explore, and to question our very existence.

I now feel that to be content, you must either have no curiosity  (or are basically just lazy and unimaginative), or be in a position that you are doing every day the things at which you excel, and enjoy. The reason so few of us ever ARE content is that we have settled for a life focused on the wrong things, and have allowed the human habit of compartmentalising to pigeon hole us into mediocre lives with neither contentment at the end, nor as much happiness as we deserve on the way.

Example 1; I don’t work hard for money, I work hard so that I don’t need more money to take financial worries off the table. Money itself should never be the goal.

Example 2; I care nothing for titles, and my self-worth is not driven by having any form of power over others, but I have seen people stay in jobs they hate because they got a fancy title and hollow respect. Not more money, or even more responsibility, just the title.

The only way I will ever be content again is if I have the freedom to do every day what I do best. I know I’m good at simplifying things, as well as making things that are inefficient, efficient. I also know that I’m absolutely crap at being diplomatic in the face of ignorance, and my impatience with office politics has led me to starting my own business out of necessity, not choice. It is therefore my responsibility to myself to create the environment best suited for me, and it’s clear that that will never happen following someone else’s dream, or worse, their greed.

In hindsight, I have never taken a backward step in my personal life or career, because I was always very much aware that wherever I ended up, I would use whatever skills I have to their maximum effect, and just as importantly, downplay or avoid the things I will never do well. Some say that’s happiness, and perhaps they’re right, but I think that doing the things that make you happy more than the things you don’t, IS contentment. Of a fashion anyway.

Curiosity, ambition, and a whole host of other attributes that we humans have, all seem to be the very antithesis of contentment, but I disagree, it’s focusing those attributes in the wrong direction(s) that’s the problem. You owe it to yourself, and yes, to those who care about you, to find contentment in whatever form that takes for you.

Finally, I think that every bit of happiness I feel means I’m doing something right, so while contentment is probably a far off place, I at least know I’m on the right path.

 

PS – For the curious, the answer is Spain.