Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Sunday, December 31, 2017

Alfidi Capital at LicensingLive! 2017

I attended Gemalto's LicensingLive! 2017 conference in Silicon Valley. I have never explored the software licensing ecosystem before, so this conference opened my eyes to a different monetization approach. Please note that Alfidi Capital does not have any software available for licensing. Here's another badge selfie for all of you to admire.

Alfidi Capital at LicensingLive! 2017.

A guru dude gave the first morning's introductory talk on software monetization. One key takeaway is that software licenses are now issued by dongle, enabling a cloud connection. Take heed of the cloud, folks, because Cloudonomics now applies to software licensing. The whole point of standardizing software licensing is to simplify pricing, speed go-to-market actions, decrease customer service touch points that cause errors, and increase revenue recognition. That's a lengthy menu of advantages for smart licensing. Check out Simon-Kucher and Partners' Global Pricing and Sales Survey for more details on how licensing impacts revenue; I can't link it here but you can seek it on the Web if you think it's important.

The conference got me wondering about who in a software vendor's organization should own the licensing decisions. It should probably not be the CFO. There's a case to make for either the CMO (it's part of the sales and customer service process) or COO (some service functions are a back-office process) to own licensing. I would argue that the predominance of customer contact should place it in the CMO's office, with input from whoever in the COO or CIO touches product R+D. Whoever owns product development must have a voice in its delivery decision. If business lines influence a preponderance of IT spending, it is difficult to argue against licensing being a sales and marketing function. Alternatively, the recent trend towards creating "Chief Revenue Officer (CRO)" positions acknowledges that revenue enhancement takes place in functions outside the marketing funnel. Let's see how organizations where CROs own licensing stack up against those where CMOs or COOs own the process. Yeah, I know, it's complicated. That's business.

The subscription sign-up process has friction points that a CRM app can streamline to ease prospect conversion. Subscriptions and licensing are an obvious source of business intelligence (BI), and I suspect that many enterprises do not fully utilize this source. Managing licenses in the cloud means moving the process into CRM but keeping contact with the rest of ERP, another point in the argument for the CMO to own the process. Generic license manager descriptions sure make it sound like a CRM function. One tip I picked up from a LicensingLive! participant is for the license management team (LMT) to "ship through ERP, renew through CRM." I think that says it all. People who live that quote's wisdom moved their licensing function from the COO's ERP into the CMO's CRM. Remember that the customer's CIO is the primary IT buyer in any organization, and they own the software asset management (SAM) practice to keep cost and risk under control. The buyer's CIO should be perfectly okay with vendors who treat licensing as a marketing-owned function, because it's part of a customer service experience they can understand.

I collected some other random LicensingLive! tidbits right here, in no particular order. Subscriptions and licensing can monetize SDKs and APIs. IDC's FutureScapes reports cover software business model monetization, so licensing practitioners may find that relevant. License management systems allow metered usage, time-based licensing, expiration alerts, and upgrade/upsell opportunities. Anyone who uses an antivirus subscription service is certainly familiar with the automated account alerts that such a system generates for each of those functions. I bet blockchain will be the next evolution of license verification. Licensing BI should pull from renewal rates and usage (by device, seat count, software module function, etc.) to discover unmet opportunities.

I had never even heard of Gemalto before attending this conference. Imagine my surprise to learn that they are a big player in cybersecurity solutions and SIM cards. The company's global market leadership position is reason enough for me to keep attending LicensingLive! I am now much smarter about how licensing adds value. Pay attention to what I've said here about BI in bold text if you really care about making money from licensing. I make it so easy for everyone, thanks to LicensingLive!

Saturday, December 30, 2017

Alfidi Capital at Data Connectors San Francisco 2017

I fondly remember my first Data Connectors conference a few years back, so of course I had to make a repeat appearance when the show returned to the San Francisco Bay Area in 2017. Tech sector trackers like yours truly get to hear straight from small firms that would otherwise fly under the radar at larger conferences. The concepts I discovered probably work best in a listicle, but I need to relate these things to my own experience in business. Prepare yourselves for some definitions.

Malvertising is a recent weaponization of the ad networks and pop-ups that the business world has grown to trust. Malware isn't just for spam email links anymore, and now it penetrates our networks through buffer overflows, code injections, and stack pivots. Root cause analysis (RCA) of malware  vulnerabilities means looking at gaps where firewalls should exist. Rectifying said gaps requires strong mobile threat defense within enterprise mobility management (EMM), because I suspect that mobile apps and platforms still do not receive the security attention they deserve. Mobile consumption of Web data now exceeds desktop consumption, but security spending in the mobile sector has not caught up.

One vendor at the conference had a very compelling demo on countering malicious profiles. Such demos are effective sales techniques for endpoint detection and response (EDR) solutions. The proliferation of mobile within enterprises means these solutions must now incorporate entity modeling for real-time simulation of all devices on the network. A complete network map gives network defenders information asymmetry over attackers. An end-to-end encryption (E2EE) system prevents a malicious profile attacker from breaking open a packet in the event they penetrate the network, and such an attempt is the kind of abnormal activity the security information and event management (SIEM) would catch.

Strong data security enables business continuity and disaster recovery (BCDR) plans. Regular BCDR auditing will establish a recovery time objective (RTO) and recovery point objective (RPO) as loss-minimization baselines. Lowering the RTO and RPO will save money, so a Cloudonomics analysis must show the ROI impact of spending on resilience solutions.

Virus publishers now produce viruses for sale at dirt cheap prices. They also offer customer service to buyers. Illegal enterprises have now adopted the practices of mature business models. It's ransomware-as-a-service on the dark Web. I believe there is a market for automated countermeasures that hit back at attackers, but there is legal risk because those active counterattacks may themselves be considered malware. The tech sector really needs to collaborate with the US federal government and sort this out.

Speaking of government help, the US's NIST maintains a National Vulnerability Database (NVD) for automating data security. The NIST also maintains a Computer Security Resource Center (CSRC) with a large library of standards publications. Anyone supervising an information security operations center (ISOC) should incorporate those database updates into their network defense protocols and drills. Building an ISOC from scratch starts with the CIS Critical Security Controls, aka the SANS Top 20.

Gartner's continuous adaptive risk and trust assessment (CARTA) interprets cybersecurity governance in the language of business practitioners. A good business rule management system (BRMS) makes adaptiveness easy by generating continuous analytics. The BRMS should produce user and entity behavior analytics (UEBA) tracking system anomalies.

The average time to detect an organization's data breach is measured in months, leaving a huge window of vulnerability. Just like the market for automated counterattacks, there is certainly a a market for automated forensics solutions that accelerate attack reviews to discover vectors and data anomalies. Sandboxing is one way to identify indicators of compromise.

The ISO/IEC 27001 information security standards should guide a CISO's design effort, along with the NIST, CIS, and CARTA approaches. The ever-helpful Gartner people also have a Market Guide for Mobile Threat Defense Solutions just in case the CARTA approach doesn't identify the most obvious vendors.

I will conclude with an observation about what sells in cybersecurity. Solutions vendors tout their deep learning automated analytics, advanced heuristics, and other factors appealing to people enamored with buzzwords. All such factors are amenable to optimization via machine learning (ML), which is fast becoming a fundamental investment. The CISO is the decision maker in security purchases, and must now have a minimal competence in data science just to accurately evaluate the effectiveness of ML-driven security solutions.

There's a lot to know for anyone who buys, sells, or operates cybersecurity systems. Organizations that get security right will make a lot of money. That is why I will continue to attend these Data Connectors events.

Friday, March 31, 2017

The Haiku of Finance for 03/31/17

Start some cyber tech
Find cyber channel partner
Cyber-lock it up

Mobile Monday's Cybersecurity for RSAC 2017

I have been poring over my notes from several recent business events I have attended, and I would be remiss if I did not share some key lessons from a Mobile Monday event that coincided with last month's RSA Conference 2017. I take my time to get this stuff right. The MoMo Silicon Valley team convened a cybersecurity panel on February 13, and I had to be there after being too busy too attend their sessions in 2016.

Alfidi Capital always notices Mobile Monday's cybersecurity events.

Cybersecurity startups are going to be a hot new investing trend for Silicon Valley venture capital. I now come away from these cybersecurity events convinced that startups with the strongest tech often have people with US military or intelligence community backgrounds. Those career fields are inundated with cyber practices that have life-or-death outcomes, so the challenge of running a cyber startup should be a piece of cake for those veterans.

It's great that the federal government sees the leverage it can apply in Silicon Valley's growing cybersecurity. Your tax dollars are hard at work in the DHS Silicon Valley Innovation Program, a companion of the Homeland Security Innovation Programs (HSIP). The assessed TAM for cybersecurity is over half a trillion dollars according to DHS, so expect a flood of VC investment into the types of portfolio companies that get some US government seed capital. Some VCs are of course stage agnostic investors, but they recognize that different stage companies have different needs. I despair to think that heavy late-stage funding still convinces some startups that they "need" gourmet catered lunches and expansive campuses.

The VCs on the MoMo panel liked retail and financial service verticals as target markets for cybersecurity startups, but I wonder which end of the enterprise is the best focus. I have long believed that apps are much more vulnerable to security breaches than enterprise infrastructure. Millions of people can download an app and ignore its security protocols, but an enterprise's internal geometry may have only a few thousand entry points to monitor (depending on employee headcount, server connections, etc.).

Rest assured that the US government is hard at work creating cybersecurity standards. The NSA's Simon (for hardware) and Speck (for software) ciphers level the playing field for new cyber entrants. I expect to see them mentioned in GitHub documentation for new IoT security apps. I also expect the smartest startups to identify leading managed security service providers (MSSPs) as targets to become their CustDev cases and early channel partners. A few Google searches reveal widely available lists of MSSPs.

There must be a market opportunity for a knowledge management (KM) cybersecurity dashboard that integrates different security tools and prioritizes a CISO's monitoring efforts. The difference between this type of enterprise solution and your PC's anti-virus solution is its integration of the cyber dashboards in use at all levels of the enterprise. The CISO should be able to monitor every business unit's IT tools and use gamification to encourage compliance. I look forward to finding a startup that can solve a CISO's monitoring pain points.

If anyone can figure out how to make cyber ideas work, it's the US government veterans I mentioned above who depart public service for the wilds of tech startup life. They should know what right looks like even if they got frustrated from working with things that obviously went wrong in the government. I hinted in my article on RSAC 2017 that I did not want to tip my hand about leveraging openly available public resources to launch tech startups. I know what I'm doing here, and I know how to get the right people involved. Keep watching the genius of Alfidi Capital for next-generation cybersecurity amazement.

Tuesday, February 28, 2017

Saturday, February 25, 2017

Alfidi Capital at RSA Conference 2017

I made my first-ever visit to the RSA Conference in 2017  because I really needed to catch up on the tech sector this year. The visual displays on the Moscone Center expo floor were phenomenal, as you can see in my standard badge selfie below. I was all set for some awesome cybersecurity action. I scored a free Expo Pass from a generous sponsor because I am still way too cheap to pay for anything. I still score massive wins after all these years tracking business.

Alfidi Capital witnesses the mighty RSA expo in 2017.

I sat in the front row for the first panel session and a local venture capitalist recognized me right away. I had not seen him for at least a year, so I obviously made some impression on him back then with my commentary. Anyway, the VCs held forth on the economics of countering hacking and the kinds of expertise they want to see in a cybersecurity startup before investing. It should come as no surprise that CISOs own a corporation's cybersecurity budget, so a security startup should focus their customer development on CISOs and nowhere else. The panelists with CISO backgrounds noted that they have longstanding trust relationships with sales reps who have hopped around different companies. Relationships matter even in tech, so startups should hire experienced sales people with huge contact lists if they want to win revenue. Startups will be disappointed to know that security solutions don't always scale well, so presumably large corporate customers have internal barriers that inhibit integration with other enterprise systems. Maybe automation can solve scalability, or maybe automation is another buzzword that VCs can chase for a year.

Executives addressed foundational controls.

The RSAC Innovation Sandbox was a hoot. RSAC users threw a bunch of words into a word cloud and the biggest ones were "data, cloud, risk, threat" in bold letters. If I had my own personal word cloud following me around, it would show words like "genius, brilliant, awesome" in big letters. One investor noted that total dollar-volume funding for cybersecurity startups was down in 2016 but later-stage funding was still keeping valuations high. The situation totally reminded me of the VCs' push for a cloud / mobile / Big Data confluence a couple of years ago because their portfolio companies in each specific sector were failing. Startups chasing those dollars now should know that innovation must address speed, because hackers' OODA loops operate faster than security professionals can respond. Get used to hearing phrases like "cognitive load" in startup pitch decks, because VCs want to fund solutions that add value through automation that reduces an IT team's cognitive load in managing cybersecurity functions. I think a startup that can demonstrate how the OWASP Benchmark Project validates its automated security solutions will have a big advantage in attracting venture funding. Any solution that can address processing encrypted data, particularly with cutting edge tech like homomorphic encryption, will garner a similar advantage.

People also implement foundational controls.

The Governor of Virginia came to tell us all about how cybersecure things are over in his state. He kept telling variations of a funny story about dolphins in his state's waters and how much Virginians loved them. I hope those dolphins are qualified cybersecurity professionals. I agree with the Governor's sentiment that state-sponsored education should offer more tech and less baloney, although he didn't use the word "baloney." That's one of my favorite words. Anyone who thinks there's no baloney in tech has never sat through a startup pitch fest. I did a Google search for the US's national STEM education standards and found the US Department of Education's K-12 standards page, so the STEM stuff may be in there somewhere. The NSF's STEM Education Data has gotten a lot more user-friendly since the last time I checked out its Science and Engineering Indicators report. The NEA surprised me with some useful STEM links; it's nice to see a union do something useful. Remember, folks, that arts education puts the STEAM into STEM.

Intelligence on threats must drive security decisions.

I was thrilled to listen to a security panel featuring cybersecurity legend Bruce Schneier. I have read his regular Crypto-Gram newsletter for years and he always has a fresh take on the biggest security trends. The panel addressed the emerging challenge of monitoring, maintaining, and certifying IoT products. It sounds to me like there are plenty of niches for security startups to make their cases. Industry will always sacrifice security for performance, so expect government regulation to drive security standards. Mr. Schneier mentioned how regulation has both fixed costs and marginal costs for solutions, and he somehow connected it to European Union regulations that will raise the marginal costs of producing IoT devices. It sounded like justification for US device manufacturers to on-shore more IoT device production here at home. I can see the walled gardens going up already in IoT thanks to security concerns. Here comes my awesome Alfidi Capital genius, folks. Secure models must connect trusted "walled gardens" (i.e., families of products from Google, Apple, and other big providers) to home IoT hubs (i.e., the coming smart home systems) that are certified under federated standards (i.e., cloud stack, network connectivity, and hardware all certified under some family of government-approved standards bodies). You heard it here first. Oh yeah, one more thing . . educating consumers on security never works! People ignore privacy settings and safety procedures, so regulation will have to build fail-safe protocols that make it difficult for non-expert users to leave themselves exposed.

Get used to hearing about securing ICS.

The RSA people livened up their conference by having actors and poets come out to introduce major themes. Hollywood actor John Lithgow gave an opening-day monologue with audience members raising their glowing wristbands. It worked as a performance art piece but I did not get a wristband. That's what happens when you only get an Expo Pass. A poet named Rives introduced a couple of cute musings on how ideas can represent data connections. I won't spoil his performance for you, so just go look up his TED talks.

Scripting in software is not like the movies.

I never miss a chance to hear Dr. Eric Schmidt from Google (aka Alphabet, its new corporate name) hold forth on tech stuff. His talk at RSAC mentioned Google's TensorFlow open-source AI library. Those Google folks are just non-stop innovators; it must be all the coffee they drink. Dr. Schmidt said he uses game theory to make strategic business decisions, especially when deciding to deploy tech that keeps Google at the center of a new ecosystem. It's no wonder why Google is so dominant if that's really how they think. Every company should be lucky enough to have geniuses running the show.

FireEye came out to the expo.

I acquired some good background information from the NIST Cybersecurity Framework presentation. It is destined to be the beta version of the federated standards system I mentioned above. Cybersecurity professionals need to know about the Center for Internet Security's critical security controls, the Center for Responsible Enterprise and Trade compliance standards, the CForum's development of the NIST framework, and the National Cybersecurity Center of Excellence's implementation of the framework. The framework's sponsors were fond of the Checklist Manifesto methodology, so there's a cue for startups that want to execute solutions in this space. Note that the Industrial Internet Consortium has its own security framework.

The final speaker that mattered to me was the phenomenal, incomparable, mind-blowing Dr. Neil deGrasse Tyson. Okay, I'll admit I attended other speakers but this guy was the real deal when it comes to pure, unadulterated genius. His genius probably ranks right up there with my own. I can't do justice to his blend of science wisdom, performance art, and comedic monologue with my meager words. Check out YouTube for tons of examples of his knowledge. It's all in the delivery. Dr. Tyson connected Albert Einstein's theories to lasers and gravitational waves during his RSAC talk. Previous eras had Dr. Einstein, and we are lucky to have Dr. Tyson among us today. His explanations of complex ideas make him a living national treasure. He should run NASA.

Read my blog article closely enough and you'll see how I spotlight hints for startups. I picked up a ton of printed information from expo floor presenters on technology implementation that I am not going to share in public. My intent is to attract entrepreneurs to some cool ideas and advise them on execution. I am not about to tip my hand in public lest potential competitors get a clue. Suffice it to say that anyone can track publicly available information on tech development, but only a genius such as yours truly can fit it all into a coherent business plan. Every conference I attend is by definition a massive winner, simply because I am there. Thank you RSA for enabling me to score in 2017.

Thursday, August 27, 2015

Hip-Pocket Ruminations For Crisis Management Teams

I participated in a crisis management tabletop exercise today courtesy of the San Francisco Bay Area InfraGard Chapter.  The local chapter of the Business Recovery Managers Association (BRMA) joined the fun.  I was familiar with the structure of facilitated scenario-based role playing from many years of US Army Reserve staff training.  The injects kept us thinking about how unpredictable a crisis gets for an enterprise.  My genius ruminations are below.

Knowing how critical business processes will cross functional silos is a key to assembling the crisis management team (CMT).  Prioritizing the processes that the enterprise must immediately sustain helps determine the resources the team will allocate in its earliest decisions.  Having a single senior person designated as the communications manager ensures that all messaging themes are centrally routed before release and that all senior executives stay on message.

Outsourcing some of the response effort in public relations (PR), third party logistics (3PL), or business intelligence (BI) means the enterprise gains a surge capacity to meet an existential threat.  One outsourcing risk is friction if the hired partners' IT systems are incompatible with the enterprise's systems, but the risk is worth taking.

The rehearsed crisis management plan should have escalation triggers in place so the CMT knows when decisions are beyond its authority.  Sending the big decisions to the C-suite keeps the enterprise's strategy in mind.  The business process recovery (BPR) team activates after the CMT has begun its work.  The CMT minimizes damage from ongoing problems, and the BPR team fixes what is broken as the crisis passes.

Crisis managers have plenty of resources for planning and training.  ISO standard 22301 governs business continuity.  Several competing organizations offer certifications in business continuity planning, so the choice may come down to which one adheres most to the ISO standards and is the least costly.  Having some members of a CMT get a couple of affordable certifications would not hurt.  Joining the US government's public-private partnerships like InfraGard, the Domestic Security Alliance Council (DSAC), US-CERT, and the National Council of ISACs (NCI) allows access to open-source threat intelligence.  Searching Google for case studies of the 1982 Tylenol crisis provides managers with the gold standard response.

Preserving an enterprise from a surprise threat is what boards pay executives to do.  Protecting employee lives and shareholder investments means designated crisis managers must write plans and run drills for multiple scenarios.  I no longer work for large enterprises but this InfraGard/BRMA joint exercise reminded me of how teams should work together.  The Alfidi Capital crisis management plan is to be as brilliant as possible while Armageddon rages all around.

Monday, June 08, 2015

Financial Sarcasm Roundup for 06/08/15

I played the role of catalyst tonight in a meeting with two San Francisco leaders who can really leverage each others' organizations.  That's more than I can say for the sorry parade of Wall Street executives and central bankers who keep blasting garbage into the world economy.  I am here to catalyze some sarcasm.

American CEOs aren't so bullish on the US economy's growth prospects after all.  More top honchos are waking up to the looming peak of record high corporate earnings.  That's still a tiny fraction of the collective C-suite.  The other chiefs are out playing golf, drinking, or nailing their secretaries.  Expect another survey revealing CEOs' opinions of themselves to be at record highs, with big bonuses to follow.

Extortionist cyberattacks are way up.  Adobe will face serious brand damage if it can't secure its Flash tech.  Good cyberdefense sleuths can trace the attacks back to Fu Manchu's terracotta army.  The folks on the other side of the Great Wall are plotting their next intrusion as we speak.  Lock your Google Wallet into your chastity belt.

San Francisco real estate is so pricey that even the slums should be getting rich.  I passed some boarded-up storefront in the Tendernob tonight.  It would probably rent for some gawd-awful sum to a VC-backed startup if the absentee landlord had the sense to convert it.  The dumbest startup ideas are still getting funded and they're blowing through cash like there's no tomorrow.

The weather in San Francisco was nice enough today that plenty of hot babes decided to wear revealing clothing.  Women around here have a high level of physical fitness.  That's something I really like about this town.  Keep those short sundresses coming, ladies.  I'll be around all summer.

Saturday, May 23, 2015

The Haiku of Finance for 05/23/15

Cost of cyber choice
Impacts enterprise budget
Pay to defeat hack

CIOarena IT Security Inspiration 2015

I secured a last-minute invitation to CIOarena's San Francisco conference last week.  I had to skip the last day of Apps World North America but that turned out to be the right call.  The CIO types held forth on security policies that enterprises must address.  I did not see any signs worth photographing nest to my handwritten name badge, so forget that Alfidi Capital tradition this time.  Just imagine the InterContinental Mark Hopkins San Francisco in all its glory.  My thoughts below reflect what I learned from the speakers.

I get my normal fill of updates on advanced persistent threats (APTs) through military-related news.  The private sector tracks the same open sources.  IT gatekeepers should think hard about what they reveal on LinkedIn to avoid becoming social engineering targets.  The APT attack process is sufficiently well-defined that proactive IT people can monitor data exfiltration and shut down exposed portals that display abnormal usage spikes.  Machine learning means automated IT security audits should develop predictive abilities after some critical mass of iterations.

I love the term "managed services."  It ranks right up there with "paradigm shift" and "game changer" for scoring points in after-work drinking games.  Outsourcing routine IT ops means inexperienced contract managers can hand managed services over to high-cost outsiders.  Watch out when senior managers start using the term in strategic planning when they need to cut headcount.  Enterprises seem to have challenges maintaining a robust configuration management database (CMDB).  I don't see how any outsourcing makes that challenge easier to handle.

I noticed that no one at the Apps World talks I attended mentioned any preference for HTML 5 or Javascript.  They may be keeping some tactics close to the vest.  I did not discern a clear preference at CIOarena either.  The choice of one over the other is probably clearer after a Cloudonomics analysis.  Listen up, IT people.  Cloudonomics is to IT/cloud/mobile what modern portfolio theory is to finance.  It is the defining framework for making asset allocation decisions.  Cloud and mobile pros must prove they can do the math before settling on a favorite tech.  CIOs can earn credibility with CFOs by being more agnostic toward programming choices.

I have no elegant solution to identity management problems.  Managing identities with MS SharePoint was simple enough when I was a knowledge management officer several years ago.  I can only suggest a way forward.  Building a 2x2 matrix to optimize identity management for each business unit would be a start, with number of identities on one axis and number of devices on the other axis.  The SBUs in the quadrant with the most of each get the closest scrutiny.  I also have no elegant solution for data lifecycle management.  Industry standards for data lifecycles and analytics frameworks are widely available.  Lifecycles will compress as speed becomes the critical factor in processing huge Big Data volumes.  High performance computing (HPC) will be a growth industry, given the need for speed in more organizations handling Big Data.

CIOarena met its stated goal of furthering my educational needs.  I can't speak for the other attendees, who did not appear to be taking notes.  I'm usually the only person who takes notes at these things.  I have no idea why other humans have so little interest in documenting what they know for further reference.  Maybe some top corporate people think they can blow through their careers without ever applying what they are supposed to learn.  That is not my style.

Tuesday, December 30, 2014

Alfidi Capital at Data Connectors San Francisco Tech Security Conference 2014

Data Connectors has a full schedule of tech security road shows across America.  I attended their Tech Security Conference this December when it rolled into San Francisco.  I had to get my fill of cyber defense knowledge while I filled up on free coffee.  My completely subjective reaction to the many highly qualified IT presenters will now follow.


The electronic recycling industry is seriously big business.  It gets bad press when some recyclers resell hardware without wiping hard drives.  That's how pirates access unencrypted personal data.  The best recyclers chop up every electronic component, recover metals, and process hard cases into plastic pellets.  The State of California Department of Toxic Substances Control (DTSC) knows all about processing hazardous e-waste.  Recyclers in this state must register with DTSC.  They should also apply OHSAS 18001 and the relevant ISO standards if they're serious about recycling.  Clearing and overwriting old hard disks are less complete safeguards than physical destruction.  I'll remember that the next time I turn in an obsolete laptop for recycling.

WiFi networks should have commonly available design templates.  Lack of such templates is one reason municipalities have been stymied in their efforts to create free WiFi infrastructure.  Wireless Networking in the Developing World has obvious solutions for countries that do not have to overcome legacy land line infrastructure.  The Network Startup Resource Center (NSRC) published a number of administrative guides for Internet architecture.  Public domain WiFi design is an under-resourced area in telecom.  More attention from open source designers would speed WiFi adoption.

Cyber security pros should talk more about being proactive.  Lockheed Martin's Cyber Kill Chain process is the best definition of how business intelligence fits into cyber security.  Brian Krebs' Spam Nation offers insights into unwanted emails as attack vectors.  Enterprises developing their own apps still leave them riddled with vulnerabilities for the sake of convenience.  They should change that approach before the huge amounts of bandwidth their apps require for sharing files and videos become attack vectors.

Experts on hand claimed the titles of CIO, CTO, and CISO are becoming interchangeable.  That is lamentable.  I say they should be distinct in an enterprise.  Come on, it's simple.  The CIO is the overall IT boss with the CTO, CISO, and Chief Data Officer (CDO) as direct reports.  The CTO's portfolio includes the IT infrastructure, SDLC, hardware LCM, and the lead effort on DevOps.  The CISO handles security for the network and devices.  The CDO develops the data supply chain and supports the CTO's DevOps.  I totally disagree with one speaker who claimed a CDO can replace a COO.  Really?  Maybe in some software firms, but not in the rest of the economy.

One person mentioned that poor data center architecture invites external threats.  NIST's Advanced Encryption Standard (AES) is at best a partial solution; data centers cannot ignore physical security.  Perimeter barriers and physical gaps are not scalable security measures in large organizations.  None of the speakers mentioned knowledge management (KM), but that drives security classification and network access privileges.  There is no one universal technology stack but several baselines exist.  An open UMA is one way to manage access to parts of a stack but IT people need a fuller understanding of that protocol's privacy implications.

Email retention policies can look to legal guidance that varies by sector.  California's email retention requirements are clear for its state government agencies but less clear for the private sector.  FINRA and the SEC have detailed guidance for data retention in the financial sector.  Once again, there is no universally applicable standard.  The EU invalidated its Data Retention Directive this year over privacy concerns.  I cannot locate any industry association source for a data retention standard.

Data loss prevention (DLP) requires data loss detection (DLD).  If you don't know something's gone, you won't know how to recover it.  The SANS Institute has a white paper on DLD and DLP open source tools; use their search function with those phrases for good info.  A Web search of "DNS vulnerability" brings up reports from the SEI CERT, IANA, and a few tech experts.  Prolexic's Quarterly Global DDoS Attack Report provides regular threat updates.  The IT community has learned to police itself of spoofing with the Open Resolver Project.  Plenty of thieves want to get their hands on enterprise data.

Collaboration opens up a whole new can of worms now that the cloud and BYOD are norms.  Cloud Security Alliance members should have some idea of how to use ISO 27001.  US-based multinational enterprises must also know ITAR and other US government export controls apply to their cloud services, as does FISMA if they do business with Uncle Sam.  The financial sector figured out collaboration long ago with its FIX protocol, so IT pros should check with the FIX Trading Community to watch information exchange done right.

The Ponemon Institute's annual Cost of Data Breach Study makes the IT community's case to CFOs for investments in network security.  Advanced persistent threats (APTs) have a defined life cycle that only a conscious actor can maintain.  NSS Labs and ICSA Labs do plenty of independent testing for platforms at risk of breach.  The Anti Virus Information Exchange Network (AVIEN) and the Anti-Phishing Working Group (APWG) share knowledge in the fight against cyber crime.

I have noticed that the "Ed Snowden look" of scraggly facial hair and wire rim glasses is popular among techies.  It's even in ads for tech sector companies.  Brogrammers can relate to that image but it may turn off women who want IT careers.  Getting more women - especially attractive ones - into cyber security would be a really great thing.  Attending these Tech Security Conferences is the place for them to start.  I'd be happy to escort them in myself, if you know what I mean.  

Wednesday, September 03, 2014

Tuesday, August 19, 2014

The Cost-Benefit Framework for Police Militarization in America

Police militarization is on many Americans' minds after the recent unrest in Ferguson, Missouri.  One very important aspect of this discussion is hard to find but deserves a public airing.  The cost of police militarization is hidden deep in budget lines at all levels of government.  Taxpayers bear this cost and should ask what benefits they receive in return.

The Defense Logistics Agency (DLA) Law Enforcement Support Office (LESO) administers the DOD 1033 Program, which provides free materiel to local law enforcement agencies that request it.  The LESO notes that it transferred over $449M worth of materiel in 2013.  That's about $1.43 per capita, assuming the entire cost was funded with current year appropriations.  The program began with the NDAA for FY1997, so any comparison with results should start at that year.

The materiel in question includes armored vehicles, body armor, night vision equipment, surveillance devices, and other implements intended for use in high-threat tactical situations.  It is appropriate to consider whether situations requiring such equipment have occurred with more or less frequency since 1997.  It is also appropriate to consider the cost of crime as an opportunity cost that more robust policing should mitigate.  Slate notes that intermittent efforts to calculate the costs of various crimes have periodically filled our knowledge gaps.  I did not see statistics in that article for the cost of high-threat tactical situations.  Mark Cohen's landmark 1998 study "The Monetary Value of Saving a High-Risk Youth" is focused on the cost-benefit relationship in crime prevention, not high-threat tactical situations.

Let's consider other tools.  The RAND Corporation's Cost of Crime Calculator allows citizens to compare the costs of crime in their neighborhoods.  RAND's "Hidden in Plain Sight" study concludes that investing in police personnel (i.e., the number and quality of the humans in the force) has a favorable cost-benefit result.  It does not specifically cover high-threat tactical situations or use of materiel, but it points the way to understanding how to frame them.  "Hidden in Plain Sight" compares the annual cost of crime in a locality to that area's gross municipal product (GMP), aka gross metropolitan product.  Analysts can thus isolate the cost of a singular high-threat tactical situation, such as arson damages from a riot or sales lost due to store closures during a protest, and compare it to GMP.  We can then compare that financial loss to the cost of DOD 1033 Program materiel used to mitigate said situation to determine a cost-benefit relationship.

Analysts have national data standards on crime costs.  The FBI's Uniform Crime Reports aggregate crime data for all US municipalities, now updated with the UCR Data Tool for searches.  The NIH study "The Cost of Crime to Society" outlines standards for sensitivity analysis and endogenizes intangible costs that will likely follow most violent criminal events.  Analysis of high-threat tactical situations should adjust the NIH's base cases for the cost of DOD 1033 Program materiel committed to violent crime incidents.

This framework is only the beginning of a cost-benefit analysis.  Every municipality should run the numbers for DOD 1033 Program materiel deployed in response to local violent incidents.  High-threat tactical situations such as riots, bomb threats, and active shooter hostage situations are infrequent but dramatic.  Anecdotal reporting suggests that police forces are inclined to use military-grade gear to perform routine functions, with little regard for utility, fuel cost, or maintenance needs.  Serving a search warrant is obviously cheaper on foot than in an armored personnel carrier.  Municipal police forces should ask themselves whether their community's criminal statistics justify requests for heavy gear that they may never need.  Citizens in a free society have a right to ask whether a gas-gazzling surplus MRAP has a better cost-benefit result than a standard police cruiser.  

Sunday, June 22, 2014

Compare US Cyber Threat Incidents To Mitigation

Two major cyber threat reports should keep security professionals busy for a while.  The Verizon Data Breach Investigations Report (DBIR) for 2014 includes data from US government cybersecurity organizations.  The US government's closest equivalent of this report is probably the OMB's annual FISMA report for 2014.  Let's compare and contrast.

The Verizon report revealed that accidents and insider misuse account for a significant percentage of the threat.  The OMB report revealed that cyber incidents are concentrated at six agencies, with the VA, HHS, and NASA as the top three impacted agencies.  The Defense Department experienced less than 10% of the federal government's cyber incidents but spends almost 90% of the government's cyber budget.  The remarkable part of that DOD spending is the 50% devoted to shaping the cyber security environment.  Note that HHS and the VA devote most of their cyber spending to detecting and mitigating intrusions, presumably from external threats.  If the majority of incidents are internal accidents and malice, as the Verizon report indicates, those agencies' cyber efforts are misdirected.

Consider the implications.  Uncle Sam is devoting the bulk of his cyber effort to what is very likely DOD's offensive capability in US Cyber Command and other special agencies.  He is also absorbing internal accidents and malice at three relatively less protected agencies, drawing from both reports.  The imbalance between targeting malicious foreign hackers and tolerating internal sloppiness is clear.  Consider that HHS and the VA are involved in managing a significant part of the US health care system.  The government's underattention to accidents and insider fraud in its health care cyber security places a significant portion of the US economy at risk.  There's a lot of very valuable data in the health care sector worth protecting.

The Alfidi Capital investment thesis does not account for the federal government's IT competence.  My analysis of several IT and telecom conferences in the past two years reveals that the mobile computing sector pays serious attention to app security.  Go back and read my stuff tagged "conference" to see how closely I've tracked this trend.  I've also tracked articles in Federal Computer Week that chronicle the government's immaturity toward IT policy.  Many FCW articles read more like tabloid coverage of whose career is hot as a federal procurement manager.  That Beltway culture is handicapping the federal government's approach to cyber security.

The big takeaway from these reports is that the federal government should think more like the private sector in mitigating cyber threats.  Vulnerability analysis precedes the response strategy and economic impact is always a major factor.  If the threats with the biggest economic impacts for the US are generated internally, then direct the response to human training and device management.  All of the federal agency CIOs need to have a copy of Cloudonomics open when they compute the budget lines they will request for cyber threat mitigation.  That may be too much to expect.  I'll wait for someone from the GSA's 18F digital innovation team to troubleshoot a comprehensive solution to this IT malaise.  In the meantime, I will mention the market opportunity in federal contracting to enterprise and mobile entrepreneurs I meet in the San Francisco Bay Area.  That's how I do my part for the nation.  

Friday, February 28, 2014

Checking Out HootSuite During RSA Conference USA 2014

I didn't have time for the RSA Conference USA 2014 this week, or the dissident TrustyCon that sprang up as a reaction to the IT security sector's problems.  The only RSA-related event I was able to squeeze into my calendar was a "Connect" event from HootSuite.  I first noticed HootSuite thanks to their Ow.ly URL shortener but they have other free tools I plan to check out.  You can all check out this awesome action shot I took at the event.


HootSuite is serious enough about building its ecosystem that it offers its own tutorials at HootSuite University and is sponsoring a certification program through the Newhouse School at Syracuse University.  I expect a lot more social media marketing companies to start partnering with brand name universities.  It will be the only way traditional universities can compete with the MOOC onslaught that is revolutionizing education.

I like the concept of a social media dashboard that integrates multiple channel feeds.  The linkbait theme of this HootSuite event was that "social media managers are dead," so companies offering integrated dashboards make social media marketing everyone's business.  Anecdotes about CEOs engaging their audience through social media make for good PR but the ROI of solving one person's problem is hard to measure.

Social media marketers have said that social media should be at the top of an enterprise's purchase funnel.  I never saw a purchase funnel depicted in my MBA marketing class.  That means I got a worthless MBA, but I realized that long ago.  I should have learned from free sources instead, like this McKinsey Quarterly article from 2009 on how messaging must move outside the purchasing funnel.  McKinsey has also discovered that the networked enterprise has a clear payoff.

I had to look up a few new terms I heard at this event.  Dashboard like HootSuite's are useful in "social media audits."  A Google search of that term leads to bunch of marketing offers and this ISACA definition of a social media audit that is probably the most objective view on the subject.  The audit's use of a people / process / technology paradigm mirrors a common definition of knowledge management.  Take heed, KM folks, because you need to work with the marketing department's social media team to make sure everyone is tracking the right channels.  Someone else mentioned "social DNA" but my search results returned more stuff like a proprietary plug-in than a broad new concept.  Lo and behold, KMWorld discussed social DNA in 2013.  I like that the KM community puts its fingerprints all over these social media concepts.  The whole social DNA scheme needs a clearer definition, and I suspect it describes the extent to which enterprise search and other sharing tools have permeated both an enterprise's internal IT architecture and its corporate culture.  Every marketer should know how to measure "effective reach" and social media now extends that reach to multiple new channels.  

Forrester has a succinct discussion of the three types of social media strategies.  I had never heard of the "hub and spoke" strategy but a Google search reveals plenty of opinions on its execution.  Once again, the obvious requirement for KM integration jumps out at me from the hub and spoke model.  I think a social media dashboard that integrates well with a KM suite (namely MS SharePoint) would be awesome in an enterprise.

I had an epiphany after listening to HootSuite's executives and clients discuss the metrics they use to assess audience engagement.  Recent reports on fraudulent likes and followers in leading social media platforms have been a hard wake-up for marketers committed to effective ad spending.  I suspect that shares and retweets are far less prone to dishonesty than likes and follows, because they require users to engage with content instead of with a static social media presence.  In other words, it's easier for a paid liker in some "like farm" in a developing country's Internet cafe to like a whole bunch of Facebook pages than it is for them to share a message from that page.  It's similarly easier for a paid shill to follow a Twitter account than to retweet useful content.  That's my original insight, fellow Web denizens.  Measure your audience engagement with metrics focusing on shared content and not some static page's artificially inflated reach.  Sharing quality content really works.

The folks in attendance were mostly in their mid-20s to early 30s.  Now I know who buys all of the overpriced denim wear I see at hip clothing boutiques all over the Bay Area.  It's these young techies working for mobile startups and social media marketing companies, and they have disposable income for expensive but trashy clothing.  I filled up on free food and drink, and chatted up a bunch of attractive women.  Those are my own personal audience engagement metrics.

Full disclosure:  I have no business connection to HootSuite.  No one paid me anything to write this article.  I may use HootSuite's free tools at some point in the future.  I like free things because I'm a cheapskate.