Monday, November 11, 2013

We have been hacked !

Not too long ago I had this interesting encounter with a CIO in a highly agitated state talking to someone on the phone while pacing the corridor of a hotel. He looked up to acknowledge my presence and continued the tirade, his face changing shades of red I never thought possible. I waited for him to complete his conversation (more of a monologue) and then asked him the reason for his state of mind. He stated that the information security of his company had been compromised and he was still discovering the extent of damage.

Information security has always been one of those investments that are like an insurance policy every organization takes to protect them. The number of threats has been going up since the internet became intertwined into the enterprise fabric; with the complexity increasing and external attacks rising in sophistication, solutions have evolved attempting to stay abreast of the game. Security budgets have been rising steadily and so have been instances of successful breaches to companies big and small.

In the older days of IT deployments, basic anti-virus was deemed adequate; today they encompass almost every device and mode of communication used by enterprises, partners, vendors, and the corporate road warrior. Even manufacturing process controls and industrial equipment were targets of some attacks which left many companies and governments struggling. Every day we hear of new data compromises, phone taps, social media sharing agreements leaving individuals and their shares exposed to the world.

Using surveys and incidents everyone talks about a majority of the threats being internal attributable to recalcitrant employees or contractors; many have also been victims of social engineering that coerced sensitive information from gullible staff. Thus building moats around the castle largely served as preventive measures for the external snooper. Despite this the industry feasting on the FUD (Fear, Uncertainty, Doubt) factor, has continued to corner the hapless CISO and CIO to make significant investments though not without reason as highlighted by many attacks and data leaks.

Based on identified security measures and advice from vendors and partners and in conjunction with his business leaders, my CIO friend had put in all the available technology at his disposal; audits and other exercises had declared his enterprise to be secure. He had also followed all the good practices and undertaken the path towards popular security certification. Despite all this his fortress had been breached and he was now at the receiving end to justify why all the heavy artillery could not secure the company.

The extent of damage was not too high with a few noncritical servers being breached, but they raised an alarm internally. The CIO in damage control mode had to address the issues it raised. A systemic exercise and root cause investigation revealed that these servers were adequately protected with all the controls that the security team had put in place. The breach was discovered to a compromised password which had been gained using social means. The hapless user who knew no different had shared his credentials.

All the policies, processes and technology were no match for the human frailness which exposed the company. My friend controlled the damage as much as he could and was wondering how to prevent recurrence of such an attack in the future. His training courses and promotional material to all the employees talked about refraining from such behavior; the hackers obviously wielded higher convincing powers. As frustration poured out on sympathetic shoulders, I could only offer him words.

When information security gets compromised, what should companies do ? Whether it happens due to ignorance inside or brute force from the outside, any breach can impact company credibility, image, and customers. The resultant impact is dependent on the industry, size and position in the market. I believe that CIOs and CISOs should build in steps on internal and external communication which should be executed without fail. Damage control is as important as the technology solution; after all, the weakest link in the chain is human.

Monday, November 04, 2013

Chief Introvert Officer

One of the common perceptions about CIOs is that they are introverts, they like to keep their mouth shut and rarely speak up in meetings or conferences or for that matter anywhere at all. Socially they are people unfriendly and communicate only with their kith and kin and that too in tongues that are not listed in the languages of the world. The geeky and nerdy persona of the IT populace has been slow to dissolve largely fueled by consumerization of what was earlier the stronghold of the chosen tech few.

Technology and various things attached with IT are no longer mystic and find print space in the digital world and mainstream business and social publications. Across age groups and social strata the adoption of smart devices (phones, tablets and everything in between) led to discussion on apps moving away from enterprise to marketplace/store, now cost a Dollar or more shedding many zeros to insignificance. Complexity associated with writing apps was dispelled by teenagers putting big enterprise software to shame.

Written to death the “alignment” with different parts of the company, CIO and IT shed the comforting façade to embrace the language of business. They rose to the occasion and reversed the belief that they could not take on lateral roles or get a seat on the table. In fact many today know technology as much as their business brethren even when they still lead the technology function. They also know where to source the skill or answer to the next challenging and disruptive hype as and when it raises its head.

CIOs share stage with other CXOs and leaders with equal ease discussing and debating macro-economic trends, customer centricity, or strategic directions. They are not waiting in the wings to be called to action; they are seizing the initiative to find revenue improvement, cost and process efficiencies or for that matter how to retain market share. M&A is no longer complete without their involvement, nor is divestment; CIOs have taken on HR, Supply Chain, and Finance along with their existing portfolio with ease.

Why is it that this perception has not changed despite the fact that new age CIOs are different from their ancestors by a huge margin ? What contributes to continued opinion of the CIO’s personality ? Are CIOs really introverts who love technology to no end ? Is evolution restricted to a few CIOs who have transitioned or has it gained critical mass with the majority now walking on the right side ? Or is it that the title has now been conferred on the undeserved IT Manager by virtue of his/her being the senior most IT professional in the company ?

I surveyed my network of CIOs and asked a few friends to do the same to qualify the numbers from all they knew to carry a title of CIO or equivalent. They were asked to rate and create two buckets; CIOs and IT Heads yet to portray characteristics now associated with CIOs. While the result may have been subjective, it helped in classification that started making some sense. We discussed and debated and unanimously agreed on some; the list had a 30:70 split with the smaller segment being CIOs.

The reasons were varied and we believed that we did a fair assessment; anyone with less than 10 year experience or company revenue below a mark was not tagged; the balance was the total set. We then looked at the 30% and observed that 80% of the set were quite vocal and articulate; they were well placed and rarely found themselves tongue-tied. They had truly overcome the perception and their reputations preceded them; whenever they were invited to any gathering like magnets they attracted others to themselves.

I have rarely found the confident and articulate to be introverts or the other way round; semantically that is the definition of extrovert and that ability and confidence comes from success. Articulation is another matter with some reveling in smaller groups and some at ease in all settings. The question really is “Is being introverted a bad thing ?” I don’t think so; it is a behavioral trait which sometimes chooses you. I believe that for a leader what matters is the right attitude and the ability to get results !