One of my favourite quotes from The Dark Knight; “You know what I’ve noticed? Nobody panics when things go “according to plan.” Even if the plan is horrifying!”

A little dramatic perhaps – not to mention some of the best acting of all time – but this directly applies to customer service.

Your clients don’t get anywhere near as angry if you come to them with a potential issue, it’s when they have to constantly chase you for resolution of a KNOWN issue that things go horribly wrong.  If your customer service is only ever reactive, you have failed, and if you can’t even react well, you are out of the game.

From my favourite website ever, www.despair.com;

customerdisservicedemotivator

Type in the phrase ‘customer service’ into Google and you’ll get over 8 BILLION results. There are institutions and college degrees dedicated to it, books by the thousand, and articles and blogs by the million (this one is very good; 8 Rules for Good Customer Service, by Susan Ward), yet how do organisations STILL get it wrong?

That’s easy, blame the CEO (or equivalent).

Just as a lack of a security culture is the CEOs fault, lack of a Customer Service culture is every bit as much on their shoulders.  As I stated incessantly; “Let’s be very clear; The CEO sets the tone for the entire company: its vision, its values, its direction, and its priorities.  If the organisation fails to achieve [enter goal here], its the CEOs fault, and no-one else’s.”

Replace “enter goal here” with “Customer Satisfaction”  and the rest is the same.

The symptoms of the inability of some organisations to provide good customer service (the CEO being the cause) can include;

  1. Poor selling techniques – if salespeople are not trained to sell only what the customer needs (not wants or even asks for), the organisation behind this salesperson will be unable to support the customers questions.  I don’t care how nice you are, or how great your products, if you’ve sold something the client doesn’t need, they will rarely buy from you again;
    o
  2. Poor products or services – there’s a fairly good chance that if your vendor does not provide good customer service, the other services and products provided by them are suspect, and should be reviewed.  Do your research, and ALWAYS ask for a proof of concept (POC) before you buy.  No POC, no purchase;
    o
  3. Black-hole communication – No-one wants to be yelled at, so if your calls and emails are going unanswered, there’s a very good chance you aren’t going to like the answer when you finally get them.  This is also an extension of 2.  And finally, forget how quickly the salesperson comes back to you BEFORE the sale, how are they immediately after?;
    o
  4. No Customer Service SLAs built in – in other words, if you have to ask for SLAs related to communication, or even something as simple as response times, there’s a good chance you won’t get the service you’re looking for;
    o
  5. Very low renewal rates – include this question in your RFP for new services and products, and have them prove it;
    o
  6. Limited, or no references – this one is too obvious  to expand on, but ignore industry awards, they are a farce.

An organisation that truly embraces a customer service culture will probably allude to it in their Vision Statement, and almost definitely in their Values.  Do business with only those organisations that take the term ‘partnership’ seriously, especially in security, and ANY company that bandies around the phrase ‘Trusted Partner’ needs to be taking client satisfaction to the next level.  Are they?

Good customer service is even simpler than security, and far less difficult to achieve, you just have to treat it as a foundation of doing business.  Your clients happiness is more important than your profit.  If you don’t believe that, you don’t care enough about them to give them what they need.

In one respect or another, we are ALL customer service reps, and this (to me) is the definitive guide to being a good rep; How To Win Friends And Influence People, by Dale Carnegie.

Yes I’ve read it …twice, and yes, I still have a lot of work to do 🙂

[If you liked this article, please share! Want more like it, subscribe!]

Some time ago I gave a presentation on BrightTalk titled ‘Insecurity Through Technology: Back to Basics‘ with the premise that the uncontrolled purchase of security technology to satisfy a perceived need may actually INCREASE your risk (go to Downloads if you just want the presentation).

Despite the crayon-esque diagrams, and the majority focus on PCI, I wanted to expand upon this concept in light of my current focus on simplifying security into “core concepts”, “appropriate / proportional security”, and “business-first”.

PCI lends itself as the perfect example of how a perceived need for technology can result in some very poor purchasing decisions.  Just look through the 12 sections of the PCI DSS and you may, in some form – and if you’re very unlucky – need ALL of the following; firewalls / routers, encryption, anti-virus, web application firewall, access control mechanisms, physical security measures, logging mechanism, vulnerability scanning, penetration testing, wireless scanning, file integrity monitoring, and a ton of ‘paperwork’.

All too often budgets are spent on items such as these at the beginning of a compliance project instead of when, and IF it’s really necessary. A lot goes into a compliance before you should be buying anything other than expert guidance or an education series.

The problem is on both sides of the sales process. The salesperson only knows how to sell either what they are being asked for, or more usually, as much as they possibly can. The purchaser has probably not done their proper due diligence and is asking the wrong questions. The best way to resolve this is if at least one side of the equation is aware of the The 6 Security Core Concepts, and follows the established good practice for the institution of a security program.

Analogy; If your doctor tells you you’re going to require an operation, you will of course learn all you can about the procedure. You may even become something of an authority in your condition (to laymen anyway). What you will NOT do is try to perform the operation yourself. Why would you treat cybersecurity any differently if you’re not an expert?

Know enough to ask the right questions, then let the experts take over. How do I…

  • choose the right technology?
  • ensure it can be integrated with current processes?
  • manage and monitor it?
  • measure it?
  • show the benefit to senior leadership?
  • …and so on…

If new technology is not properly configured, baselined, monitored, and maintained, you have added another potential vulnerability to your infrastructure. Any appliance is just another hardened server running an application of some sort, and should be treated the same way as the ones you build yourself.

Also, the more data you receive the more important baselining and tuning becomes, as you don’t want the important stuff to be obscured under layers of false positives. I do not believe there is room for Big Data analysis in security (per Don’t Get Me Started on ‘Big Data’), so integration of new technology with less-is-more security processes is paramount.

This has been, and will continue to be a theme throughout my blogs; 1) don’t buy anything until you know why you need it, 2) install nothing in production until you have figured out how to use and manage it, and 3) integrate all processes around it with a single overarching operations centre.

The threat landscape is intimidating enough without making things easier for the bad guys.

[If you liked this article, please share! Want more like it, subscribe!]

Truth be told, this post could be titled; ‘The Top Roadblock to Compliance, and The Other 9 That Result From It”, but per the excellent advice from a blogger far better than I “You can’t [stop readers cold] if you use cute, clever or confusing headlines.” I’m keeping it simple.

So what is this offending roadblock?

1. Lack of Management Buy-In

Sounds simple, in fact, it sounds like a cliche, and above all, it does not sound anywhere near as important as I’m making it out to be. But let me ask you this; If your manager doesn’t care about something, how much do YOU care about it?

Now extrapolate that from the CEO all the way down and you get something like this;

Management

If the CEO makes it clear that they don’t care about PCI, how much traction do you think achieving compliance is going to get? The project gets handed to the IT Manager (because it’s clearly an IT problem not a business one, right?), and PCI will receive no attention, very limited budget, and no respect.

That is, until they get breached and fined for the equivalent of gross negligence, and then the IT Manager gets blamed for slacking. Sounds familiar?

The CEO, as well as senior management, control the culture, and that culture had better include the importance of cybersecurity.

Let’s be very clear; The CEO sets the tone for the entire company; its vision, its values, its direction, and its priorities. If the organisation fails to achieve PCI compliance, it’s the CEOs fault, and no-one else’s.

And now for the other 9…

2. No Perceived Return on Investment (ROI)

While very closely tied to the 1st reason, this is distinct because it’s clear that few have accepted that there are actually benefits of PCI compliance (see Why PCI Isn’t ALL Bad). So even if the CEO does pretend to care, few will get behind the process in any meaningful way. Nor will they bother trying to fit PCI into their existing security program, which is the only way it makes sense.

3. No Dedicated PCI Project Manager

PCI compliance, like all security, is eventually a process, but achieving it for the first time should be a project with a dedicated internal resource. Ideally, that resource has nothing else to do except PCI, but that’s rarely practical. So until compliance is achieved, they will need considerable support from management, and some of their more mundane duties re-distributed.

4. Choosing the Wrong QSA 

Per my white paper on Selecting the Right QSA for Your Business, the choice of an assessor is extremely important. The right one can help you deal with almost all of these roadblocks, the wrong QSA may be the roadblock. It’s probably in your best interests to bring a security expert in first to prepare your security program and infrastructure for the QSAs visit. At the same time helping you to make not only PCI, but your entire security programme sustainable – and just as importantly – cost effective. And above all, appropriate to the value of the data to your business.

5. Thinking Policies & Procedures are Just Paperwork

Odd as it sounds, without solid documented and enforced policies, standards and procedures (Policy Set), there is no real way you can have the culture of security necessary to achieve the company wide backing necessary to run an effective PCI project. The Policy Set is a corner-stone of your security program and should received its due.

6. No Standardisation

This is a very broad subject, and includes configuration standards, change control, monitoring, patch management, the SDLC, vulnerability management etc. The PCI DSS allows sampling of systems during validation, but this must be earned. Without standardisation, there can be no sampling as there are no systems created and maintained identically.

7. No Centralisation

How organisations manage often hundreds of devices without some form of centralised management is beyond me. I have to assume it’s not done well. The QSA also has a very hard time granting the privilege of sampling if you cannot show centrally HOW you keep the systems the same. There are plenty of tools out there, and the benefits of them go way beyond PCI compliance.

8. Not Knowing Where to Start

At first this may seem obvious, and perhaps a little redundant, but bear with me. I have had a lot of experience with this little roadblock, so I know just how difficult it can be to overcome. The answer – as it was for me – is simple; Ask someone. Your QSA should be able to take you all the way through this process relatively seamlessly, but if you don’t have one yet, ask someone who has already achieved compliance for their organisation. I personally know dozens of people who are more than happy to spend time with PCI novices and share their experience and guidance. This is one of the easiest roadblocks to overcome if you keep your ego or shyness out of play.

9. “But we’ve always done it this way!”

Perhaps the most irritating phrase in the English language – with the possible exception of “What are you thinking?”, especially for a consultant. The business wants things to stay the same, they want the same access they’ve always had, and they want the same data. The fact remains that the vast majority of business processes have very short shelf-lives, so they should be reviewed regularly, and access to in-scope systems or data justified. I’ve found that adding PCI compliance expenses to their cost centres tends to get their attention.

10. No Budget

Not much you can do about this one, but it’s certainly worth trying to re-iterate that the security controls should be in place anyway, and that they fall firmly in the good practices introduced in my The 6 Security Core Concepts.

I didn’t know how to blog until I asked my wife, and I have no idea how to read legal-ese so I ask my Sister. If you want to be PCI complaint, or even better, be secure AND PCI compliant, ask someone who’s done it.

[If you liked this article, please share! Want more like it, subscribe!]

As you probably know, the PCI DSS is a minimum set of security controls that must be in place around anything that transmits, stores, or processes cardholder data. That’s probably why the card brands and the SSC get so irritated that even this basic set of good practices is so hard to achieve.

That said, unless you have a way of monitoring and maintaining your compliance within these baselines, it’s not only VERY difficult to stay compliant (let alone secure), it makes validation of your compliance an annual nightmare of gathering screenshots, log samples, and so on. I estimated that validation of controls can take up to 50% of the entire annual assessment cycle.

This is a tremendous loss of resource time, and does nothing for your ROI. So why DOES the PCI DSS only require an annual point-in-time validation and not validation of continuous compliance? Yes, you are accountable to stay compliant at all times, but you only have to validate it once a year, and – if you’ve earned it – on only a sample of your systems.

The answer is, they simply cannot go that far. Continuous compliance validation is far more difficult than achieving PCI compliance, and is firmly in the realms of good security practices. They can enforce minimums, they cannot enforce more than that and get the necessary acceptance.

So what IS Continuous Compliance Validation? “It is the near real-time notification of a variation from your baseline norms.” Or to put it another way; once you know what something should look like all day every day, you want to know if it changes from that.

For example, the PCI DSS specifies over 20 validation points for an operating system; e.g. business justification for all listening ports; access control; logging; FIM and so on. Once a year, you have to show your assessor that these validation points meet the DSS requirements, and that’s it for the YEAR! All too often, systems fall out of compliance within a matter of days.

Instead, what I propose, is that you should automate (as much as possible) the collection of that validation data, and compare it to not only the PCI DSS requirement minimums, but to ALL of your compliance / regulation / internal policies / standards. And not yearly, but hourly, daily, weekly, whatever makes sense. Wouldn’t you rather show your assessor a green checkmark for ALL of your systems than a dozen screenshots for a mere sample?

If this can be configured for just 50% of your in-scope devices, your entire annual validation burden will be enormously reduced. Plus, you also have a very convincing addition to your compensating controls for lack of FIM or AV (if applicable).

Best of all, you are now doing security as it was meant to be done; Enterprise wide, and Business As Usual.

Any operating system experts out there want to help me put this together?

[If you liked this article, please share! Want more like it, subscribe!]

Thanks to the more unscrupulous vendors, security is becoming as complex as the law. Privacy therefore is at the top of the list of sticky topics because it also involves both the law and security. More countries are effecting privacy laws than ever before, but just like in a regular business, functionality and security must be balanced to be effective.

I’m not going to list all of the ongoing privacy issues in the press, but the biggest two currently are; the Prism/whistleblowing/NSA scandal, and the EUs Data Protection Directive. While worlds apart in their impact and aims, they still raise a question that I’ve not seen addressed very often. Probably because there is no one right answer, but the question of how much privacy is too much should not be ignored or any semblance of balance is impossible. Also, it seems that unless we’re bashing the perceived bullies (Government, big business), there’s not much interest in this side of things.

So, Prism, summarised and paraphrased, is an anti-terrorism program that has unprecedented access to enormous amounts of personal data.

Proponents state that it’s necessary for national security, opponents state that it’s an abuse of power / attack on civil liberties and so on. But who’s right? If you choose a side – and to the extreme – you are either saying it’s OK for the Government to do whatever it takes to defend its people, and that the end justifies the means, or you’re saying that an individuals right to privacy outweighs the security of a nation. Clearly both of these positions are nonsense, but what is the right answer? It has to be somewhere in between., right?

However, to get the middle, both sides need to accept responsibility; Government for not becoming Big Brother-esque, and individual citizens for paying the price in personal privacy for the freedoms and conveniences we frequently take for granted.

For example, if you ask any victim of a terrorist attack, a hate crime, harassment, or a stalker-ex, whether or not they would have traded complete loss of privacy to avoid their pain, and I think the answer is a given.

However, now ask ME whether or not I would entirely relinquish MY privacy to prevent this from happening to someone else – which I would do in a heartbeat -, and you now have the gist of why this issue is so contentious (some are already calling it – terribly un-originally – Prism-gate). People want security, but they don’t want to accept the cost for it, which in todays plugged-in/online/Internet/information age, that cost is their privacy.

As for the EU Data Protection Directive, that’s about the far less glamorous subject of making sure organisations protect the data in their possession, and while less life-threatening, leads to the same question. This time it’s about [for example] the ability of an organisation to sell you stuff that you want, or didn’t even know you wanted but now you can’t live without (like the iPhone). They want to sell you stuff, you want your data protected or removed altogether.

Personally I want organisations to know EXACTLY what I like and don’t like. That way I’ll get less spam and pop-up ads regarding adult nappies/diapers and erectile dysfunction, and more on amazing gadgets and toys that will make my life complete. This requires absolutely enormous amounts of data, and is a true use of Big Data.

Not everyone agrees.

However, WE choose to plug in, we’re not forced. I have Linkedin, Facebook, Twitter, and more online bank / credit card accounts than I know what to do with. Sadly the accounts are mostly empty, but that’s not the point, which is why I have chosen these methods of communication and convenience to make my life better. Which they do…vastly.

We are not owed this functionality, we have a choice to use it or not. If you want it, you must pay for it.

How many of you read the privacy notices, or terms & conditions when you sign up for online services? No, me either, so I’m not going to complain if they go ahead and do exactly what they told me they were going to do.

I cannot speak to the law or politics, nor can I wax philosophically on human nature, but what I can talk to is personal accountability. You are owed nothing, except that which you earn. From your income, to your rights, to your karma, you get back what you put in. So perhaps what we should all do instead of complain, or demand that heads roll, is be a little more circumspect in our online interactions:

  1. Don’t post inappropriate comments on FB/Twitter or ANY form of social media or email. Assume that this information will NEVER go away;
  2. Limit your online banking and purchasing to known-good sites, check for HTTPS in the URL (secure transmission) , and CHOOSE A GOOD PASSWORD!;
  3. Make sure ALL of your online credit card / bank accounts have fraud and theft protection;
  4. Sign up for credit and identity monitoring services (I have two running, one US and one UK);
  5. Read the Terms & Conditions!;
  6. Do not even TAKE revealing or compromising pictures of yourself, or others, on any online-capable device …EVER (I think if I was to do that it would qualify as an offence against humanity, or maybe even a WMR (Weapon of Mass Revulsion));
  7. When you’re done with an online vendor, delete the account, and write to them invoking your right to erasure;
  8. Read my blog! 🙂

Personally, I LOVE the fact that London is full of cameras, I’m doing nothing wrong, and I feel better about my wife being out when it’s dark. I don’t care if some spotty geek in Fort Mead, MD is reading my personal email, or my FB posts, I’m not being seditious, or inappropriate, and if they derive pleasure reading about my wife and me discussing our 2012 taxes, good luck to him/her.

I want safety in the streets, safety for my country, AND the convenience of all that being online gives me, and if my privacy is the price I must pay, so be it. I trust the ‘official’ watchers infinitely more than the criminals or terrorists, but it’s MY responsibility to give NO-ONE access to more than I can afford to lose.

[If you liked this article, please share! Want more like it, subscribe!]