When first notified that your role is at risk for redundancy, your first feelings are an equal mixture of disbelief and panic. This fades into being upset, then angry, then numb.

This is almost identical to breaking up with a boyfriend/girlfriend, though I have to assume a lot less kissing and hugging had been previously involved.

You may even try to work something out with your employer; apply for other jobs internally, write long rambling documents about what you COULD do, and how you could help if you stayed. It’s only natural to try everything.

But you have to ask yourself some VERY hard questions, and you may not like the answers; Did this happen to just you, or was your layoff one of many? Do their reasons make sense? Your introspection will pay off eventually, and allow you to move on much faster than if you hold on to your pain, and/or sense of injustice.

Besides, it may well be redundancy was their way of being NICE, they can always fire you…

The longer you have been in an organisation, the harder this is, and it’s natural to feel a little bitter and resentful. Venting to your friends is one thing, it’s even healthy in small doses, but venting to everyone you talk to, or in writing, or worse, in your next interview, will do nothing but hurt you.

Don’t do it.

You will be asked about why you left your previous employer, and because redundancy is a part of business, don’t raise any red flags by being derogatory or negative. Nor do you have to go the other way and say how much you enjoyed the previous job, that just makes your interviewer feel as though he/she is your second choice.

Be factual, and move on.

Once your redundancy has been finalised, and you have accepted the reality of it, get busy. Revamp your CV (which should always be up to date), revamp your LinkedIn profile, and start calling people. It’s not until something like this happens that you realise just how many people you know out there, and just how many will bend over backwards to help you. Reconnect, find a recruiter you trust, and see what’s out there.

There seems to be equal opinions on whether you should take some time off (if you can afford to), or jump right back on the saddle. Ignore everyone (except your spouse, that’s a bad idea) and do what’s right for you.

You can also try blogging, even if it’s just for a while, there is nothing quite like writing things down to put clarity into your thoughts. You will also find that it helps crystallise in your mind what you want to do next. Have a read of this post again, and bear it in mind when choosing your next adventure; Never Follow The Money

But what happens when your company is in the middle of laying people off, and you think you may be next?

You have to be even more careful, as you may just put yourself in a position to BE laid off that you were not in before! You are worried, so your motivation and morale slip, then your attention slips, closely followed by loss of productivity. This will be noticed, and you have now put yourself firmly in their radar in a negative way.

I’m not saying don’t start looking around for something else, in fact you should ALWAYS be open to opportunity, but you still have a job to do, so do it well.

I don’t know what the statistics are, it’s too nice outside to bother with research, but I’d say over the course of your careers you will be fired once, and laid-off once. So assume it will happen to you at some point and be ready for it.

[If you liked this article, please share! Want more like it, subscribe!]

Yes …mostly.

Not that the question is even relevant, like it or not, cyber insurance is already here and will only continue to grow.  The number of regulations that reserve the right to levy  fines – some potentially astronomical – is growing to the point that they will feature large on any list of business risks. Or at least they should.

The challenges bringing this to market are numerous, but mostly on the insurance company side.  Security is almost the definition of risk, it’s incredibly diverse, and forever changing and expanding.  And not important enough yet.

With car insurance for example, the more cars you have in the road, the slower everyone has to go, so you actually REDUCE the risk.  What once was a few very costly collisions, is becoming more fender-benders.  So, just up your no-claims bonus and even those claims will reduce.

The more computers and smart phones on the Internet, the more data you have everywhere, and the risks grow almost exponentially.

How do you insure that?  If you don’t know security well, how do you write the policies?  How do you perform appropriate due diligence on a concept that’s new to everyone?  How do you perform PROPER due diligence in the face of stiff competition?

There are policies out there already, but these have been driven by specific regulations (PCI, or HIPAA for example), are aimed mostly at the smaller organisations, and are very much off-the-shelf affairs with limited – in some cases VERY limited – due diligence.  In fact, the pressure is on to make it as simple as possible or you’ll lose the deal; if your insurance company has a 12 page questionnaire, and your competition has only 1 (assuming price and T&Cs are the same), where will the buyers go?

Of course, the competition may end up regretting their stupidity later, but new insurance types are a very rare occurrence, and no-one wants to lose out on a revenue stream.

But what happens when VERY large organisations wish to insure themselves against the potential fines of the General Data Protection Regulation (GDPR), where 2% of global revenue is at stake?  When multi-millions are on the line, a one page questionnaire that asks nothing about security will not suffice.  What does that due diligence look like?

I believe it will run the gamut from some limited external vulnerability scanning in the case of smaller e-commerce, to an onsite audit in the case of a Fortune/FTSE 500.  The better your security, the cheaper your policy.  This may save pennies for smaller organisations, but would be of real significance to the larger ones.

However, I have always compared selling security to selling insurance; no-one wants to spend the money where there’s no positive ROI i.e. MAKING money.  But the ‘negative’ ROI can be just as important, where not LOSING money on fines, forensics, reputational damage, client loss etc can be every bit as meaningful.

Now combine selling insurance FOR security, and you’ve lost almost before you start.  That is of course until the costs of loss far outweigh the costs to insure.

Poor security drives the need for regulation, the regulatory fines will drive the cyber insurance market, which in turn will drive the security market.  Eventually I would hope that organisation understand that they have brought this on themselves by not taking security and privacy seriously. Until they do, the burden of regulatory audit and the associated cost of mitigation will continue to rise in the face of public demand.

Regulation and cyber insurance are just symptoms of poor security, and as I have stressed many times, this is a cultural issue stemming from the senior managements lack of involvement and/or caring;

Let’s be very clear; The CEO sets the tone for the entire company: its vision, its values, its direction, and its priorities.  If the organisation fails to achieve [goal], its the CEOs fault, and no-one else’s.

Replace “goal” with “low security overhead”  and the rest is the same.

Sensing a theme here?

The CEO can single-handedly reduce the costs of security, I wonder why so few are paying attention…

One of my favourite quotes from The Dark Knight; “You know what I’ve noticed? Nobody panics when things go “according to plan.” Even if the plan is horrifying!

A little dramatic perhaps – not to mention some of the best acting of all time – but this directly applies to customer service.

Your clients don’t get anywhere near as angry if you come to them with a potential issue, it’s when they have to constantly chase you for resolution of a KNOWN issue that things go horribly wrong.  If your customer service is only ever reactive, you have failed, and if you can’t even react well, you are out of the game.

From my favourite website ever, www.despair.com;

customerdisservicedemotivator

Type in the phrase ‘customer service’ into Google and you’ll get over 8 BILLION results. There are institutions and college degrees dedicated to it, books by the thousand, and articles and blogs by the million (this one is very good; 8 Rules for Good Customer Service, by Susan Ward), yet how do organisations STILL get it wrong?

That’s easy, blame the CEO (or equivalent).

Just as a lack of a security culture is the CEOs fault, lack of a Customer Service culture is every bit as much on their shoulders.  As I stated incessantly; “Let’s be very clear; The CEO sets the tone for the entire company: its vision, its values, its direction, and its priorities.  If the organisation fails to achieve [enter goal here], its the CEOs fault, and no-one else’s.

Replace “enter goal here” with “Customer Satisfaction”  and the rest is the same.

The symptoms of the inability of some organisations to provide good customer service (the CEO being the cause) can include;

  1. Poor selling techniques – if salespeople are not trained to sell only what the customer needs (not wants or even asks for), the organisation behind this salesperson will be unable to support the customers questions.  I don’t care how nice you are, or how great your products, if you’ve sold something the client doesn’t need, they will rarely buy from you again;
    o
  2. Poor products or services – there’s a fairly good chance that if your vendor does not provide good customer service, the other services and products provided by them are suspect, and should be reviewed.  Do your research, and ALWAYS ask for a proof of concept (POC) before you buy.  No POC, no purchase;
    o
  3. Black-hole communication – No-one wants to be yelled at, so if your calls and emails are going unanswered, there’s a very good chance you aren’t going to like the answer when you finally get them.  This is also an extension of 2.  And finally, forget how quickly the salesperson comes back to you BEFORE the sale, how are they immediately after?;
    o
  4. No Customer Service SLAs built in – in other words, if you have to ask for SLAs related to communication, or even something as simple as response times, there’s a good chance you won’t get the service you’re looking for;
    o
  5. Very low renewal rates – include this question in your RFP for new services and products, and have them prove it;
    o
  6. Limited, or no references – this one is too obvious  to expand on, but ignore industry awards, they are a farce.

An organisation that truly embraces a customer service culture will probably allude to it in their Vision Statement, and almost definitely in their Values.  Do business with only those organisations that take the term ‘partnership’ seriously, especially in security, and ANY company that bandies around the phrase ‘Trusted Partner’ needs to be taking client satisfaction to the next level.  Are they?

Good customer service is even simpler than security, and far less difficult to achieve, you just have to treat it as a foundation of doing business.  Your clients happiness is more important than your profit.  If you don’t believe that, you don’t care enough about them to give them what they need.

In one respect or another, we are ALL customer service reps, and this (to me) is the definitive guide to being a good rep; How To Win Friends And Influence People, by Dale Carnegie.

Yes I’ve read it …twice, and yes, I still have a lot of work to do 🙂

[If you liked this article, please share! Want more like it, subscribe!]

Some time ago I gave a presentation on BrightTalk titled ‘Insecurity Through Technology: Back to Basics‘ with the premise that the uncontrolled purchase of security technology to satisfy a perceived need may actually INCREASE your risk (go to Downloads if you just want the presentation).

Despite the crayon-esque diagrams, and the majority focus on PCI, I wanted to expand upon this concept in light of my current focus on simplifying security into “core concepts”, “appropriate / proportional security”, and “business-first”.

PCI lends itself as the perfect example of how a perceived need for technology can result in some very poor purchasing decisions.  Just look through the 12 sections of the PCI DSS and you may, in some form – and if you’re very unlucky – need ALL of the following; firewalls / routers, encryption, anti-virus, web application firewall, access control mechanisms, physical security measures, logging mechanism, vulnerability scanning, penetration testing, wireless scanning, file integrity monitoring, and a ton of ‘paperwork’.

All too often budgets are spent on items such as these at the beginning of a compliance project instead of when, and IF it’s really necessary. A lot goes into a compliance before you should be buying anything other than expert guidance or an education series.

The problem is on both sides of the sales process. The salesperson only knows how to sell either what they are being asked for, or more usually, as much as they possibly can. The purchaser has probably not done their proper due diligence and is asking the wrong questions. The best way to resolve this is if at least one side of the equation is aware of the The 6 Security Core Concepts, and follows the established good practice for the institution of a security program.

Analogy; If your doctor tells you you’re going to require an operation, you will of course learn all you can about the procedure. You may even become something of an authority in your condition (to laymen anyway). What you will NOT do is try to perform the operation yourself. Why would you treat cybersecurity any differently if you’re not an expert?

Know enough to ask the right questions, then let the experts take over. How do I…

  • choose the right technology?
  • ensure it can be integrated with current processes?
  • manage and monitor it?
  • measure it?
  • show the benefit to senior leadership?
  • …and so on…

If new technology is not properly configured, baselined, monitored, and maintained, you have added another potential vulnerability to your infrastructure. Any appliance is just another hardened server running an application of some sort, and should be treated the same way as the ones you build yourself.

Also, the more data you receive the more important baselining and tuning becomes, as you don’t want the important stuff to be obscured under layers of false positives. I do not believe there is room for Big Data analysis in security (per Don’t Get Me Started on ‘Big Data’), so integration of new technology with less-is-more security processes is paramount.

This has been, and will continue to be a theme throughout my blogs; 1) don’t buy anything until you know why you need it, 2) install nothing in production until you have figured out how to use and manage it, and 3) integrate all processes around it with a single overarching operations centre.

The threat landscape is intimidating enough without making things easier for the bad guys.

[If you liked this article, please share! Want more like it, subscribe!]

Humans as an entire species are never going to agree 100% on anything, ever.  I don’t care if it’s religion, politics, privacy, or margarine over butter.  There will ALWAYS be people on either side of every fence.  Try to imagine the worst thing in the world, and there will be someone out there doing it, or cheering on those who do.

At best, we can come to a majority agreement, but that will only ever be regionalised by either geographic location, or racial beliefs and bias.

So why has Prism caused such a stir?  Are you actually surprised this was going on? There are those who want access to data, and those who want to protect it.  There are those who want to use the data for the common good, and those who want to use it for their own profit, or worse.  And “Some men just want to watch the world burn.”

I’m not overly interested in your opinion, just as you’re not overly interested in mine.  I’m OK with that.  The only time we have an interest in this stuff is either when people totally agree with us, or – in our arrogance – we feel like trying to change the opinions of others.  Like we’re the ones who are right.

In the end, the bad guys (in whatever form ‘bad’ is for you) only have access to what we gave them.  An exception to that rule is when an organisation loses stuff they should be protecting.  Like in a breach for example.  Preventing this from happening is what I, and many others, have devoted our careers to, but the most we can ever achieve is a slight reduction in the risk to your privacy, and possibly some form of compensation for you if your privacy is lost.

Yes they should protect data, and should be liable for not doing so, but if a thief wants it, it’s gone.

While you have every right to expect privacy, and I agree with the laws and regulations supporting that privacy, you cannot EXPECT privacy given the bad elements.  Analogy; the law protects me against being mugged, but I don’t put myself in places or situations where mugging is more likely.  I may be the victim, and have all the rights of the victim, but I’m still missing my wallet.

This will not apply to the Prism case, where there will be no class action suit against the government, and whatever smoke and mirrors they come up with to reassure you that it will never happen again, it’s just that, smoke and mirrors.

The key to your personal privacy has always, and will always, rest with you.  You are responsible for your data, and whinging about governmental abuse of power is not going to change the fact that you posted stuff on FB, you took inappropriate pictures, and YOU chose to share your bank account details to an online provider of services etc.

Do I think the NSA was right in what they did, or if that moron Edward Snowden was right in what HE did?  That’s irrelevant, because I have nothing online in any form that would embarrass me if it were revealed, or unprotected (by deferred lability) if it was stolen.

Can you say the same?

[If you liked this article, please share! Want more like it, subscribe!]