Showing posts with label Execution. Show all posts
Showing posts with label Execution. Show all posts

Monday, December 16, 2019

Mentoring Around The Time-Value of Cyber Delivery


A good cyber leader wants to meet expectations of their executive team but a great cyber leader wants to consistently exceed their expectations. The smart cyber leader has a chance to do this consistently within the context of delivery.


So how do we mentor cyber leaders to consistently exceed expectations?  

Monday, December 9, 2019

Mentoring Around Measuring Cyber Progress


Peter Drucker is famous for saying that you can only manage what you can measure. Nice thought but, by itself, not much help in terms of practical advice to the cyber security leader.



So how do we mentor showing progress?

Sunday, December 8, 2019

Kicking The Can Down The Road


Sometimes you might not have enough resources to do all of the things that really are important. 



We can model three types of execution: 


Critical projects tied to a commitment which has resources and a champion.

Key projects with resources that are important but for which you, as the senior cyber leader, might be the only champion.

Other projects that are important but without sufficient resources. 

Saturday, December 7, 2019

The Engagement Problem of Cyber Security Ownership


This post is part 2. Part 1 is “The Conceptual Problem ofCyber Security Ownership.


So, you decided to distribute ownership of securing business processes outside of the cyber security team within the standads set by the security team. You have a conceptual model. Now, we need to examine the mechanics of implementing that model.




Communications isn’t enough to transfer ownership to business process owners. If communications alone was sufficient, almost every cyber security team would have distributed ownership of cyber security by now. 


Communications infers one way directives. 


Easy to ignore proclamations. 

Monday, November 25, 2019

Mentoring Execution Improvements In Cyber Security


A key moment in the career of a cyber leader is when they realize the difference between simple activity and a planned set of work designed to mature the security program in a purposeful direction. 


Activity isn't a reliable metric for improvement within a security program. And, yet, activity seems to be a popular justification for more resources. We have to think like a business leader to understand why it might not be.

Sunday, November 24, 2019

Framing Data Security Conversations To Executives


Data is created, modified, moved and deleted as part of any number of business processes. These business processes and underlying technologies create transformative value for their organizations. The smart cyber leader will want to frame conversations with non-technical executives in a way that they can quickly grasp. 



A detailed explanation of NIST or other framework data security requirements probably is not the conversation format within you’ll find success. You won’t establish your expertise with execs with a deep dive into frameworks. 

Saturday, November 23, 2019

An Example Of Managing Massive Cyber Change


Think that you have a hard time of managing cyber security expectations and change? Compare your change to the change that became Patch Tuesday.



Love Patch Tuesday or hate it, I worked at Big Software Company™ before Patch Tuesday was a “thing”. Prior to Patch Tuesday, patches had to be released as quickly as possible. Large customers that paid large support had thi expectation and, worse yet, there was a great deal of internal pressure to release.  


The result was a whiplash of patches released on any night of the week including Friday and Saturday and patching teams having to work whatever hours were required to patch systems. Change was needed and no one recognized the need for change.  It was just what it was. 

I ran a high profile product team for four years and, the Sunday before thanksgiving, we generally had an egregious security defect reported. We’d spin up the team to release a patch before Thanksgiving so the team could get some time off. After the first year, it became clear that the reporter wa generally holding a second defect in their back pocket to report just after the release of the Wednesday patch. That would require calling the team back in.  


And then came Patch Tuesday. Our customers didn’t think that it would.  Heck, I didn’t think it would work.


But, now, the industry and executives would be hard to imagine a different cadence.That’s managing change effectively.   
 

So, if you think that any change is too big, compare it to Patch Tuesday.


I’d guess that your change pales in comparison. 


Follow me on Twitter for discussion and the latest blog updates: @Opinionatedsec1. Or, start your own discussion using #crazygoodcyberteams on twitter or Linkedin and I'll read it.


SEE ALSO




Sunday, November 17, 2019

Some Cyber Security Value In Frustration


Frustration is a great trailing indicator for cyber leaders as it generally occurs when we keep trying to do something that isn’t working. Frustration isn’t the problem. It’s a symptom.



We clearly would not want to take actions that intentionally increase frustration for others. That’s not the intent of finding value in frustration.  The intent is that we want to be vigilant of early frustration so that the source of frustration, that underlying issue, can quickly be sussed out and remediated.  


Once recognized, frustration can become a tool for continuous improvement. 

Saturday, November 16, 2019

Blue Team Building In Cyber Programs


There is a well known blue team problem in cyber security.


Blue teams defend everything.  

They have little hand in choosing the time or place of incidents.
A lot of threat surface area to defend.
And, too much to try to tackle at once.

Perhaps it’s time to change the dynamics.

Thursday, November 14, 2019

The Potential Downside of Cyber Metrics


You always get what you measure.That phrase or some paraphrase of it is usually meant to justify some positive change. 



For example, we were doing such-and-such activity before with poor results and then we started measuring and got better results.

This is a common statement and standard narrative in any cyber security program.

When the stakes are high, we want to be sure to turn the box green, finish within the right time boundary, or get results above the right percentage.

Wednesday, November 13, 2019

Rethinking Gaps In Cyber Security Programs


Think about cyber in business terms for a second. A description of a cyber security program without a clear statement of program gaps is like a balance sheet without a liabilities statement. 




And yet, somehow, gaps seem to be an often minimized part of our conversations with executives. 


Perhaps as cyber leaders, we choose to avoid hard conversations about program gaps because we want to be positive. Maybe we avoid them because we have some level of fear of executive reaction to hearing about gaps in the cyber security program in the context of past investments.