Showing posts with label budget. Show all posts
Showing posts with label budget. Show all posts

Wednesday, September 23, 2009

Economic Budget Savings: Maintenance Cuts

To help save money, IT groups are being asked to cut back -- in some cases, dramatically -- on their maintenance contracts with vendors. So instead of paying a premium for vendors to, say, fix any problems in key software and hardware within four hours, a 24-hour turnaround might have to suffice instead. Sometimes things stay broken until IT staffers can figure out the fixes themselves. And in the meantime, ITers involved say, they just hope that their business users will not notice any ill effects.

Jim Milde, executive vice president of global services for Boston-based IT services company Keane Inc., estimated that of his largest customers -- in pharmaceuticals, insurance, finance, government and transportation -- around 10% are cutting maintenance costs in various ways.

pennies

This trend is being seen in pockets all over the industry, IT staffers and industry analysts agree. But given the sensitivity of the issue, and often the politics involved, most ITers would speak about it only on the condition that they not be identified.

Why cut?

Lauren Whitehouse of Enterprise Strategy Group in Milford, Mass., said companies "have to do what they have to do" to get by today. By cutting or renegotiating maintenance pacts, companies trim costs so that they can perhaps avoid or reduce layoffs or still have money to spend on innovative new projects that will help grow the business when the economy does rebound, Whitehouse said.

"Hypothetically, 70% of your budget is for keeping the lights on and 30% is for moving the business forward" strategically in the future, she said. "So you look at the 70% to see what you can squeeze out there so you can keep the strategic stuff going."

For many clients, service-level cuts are "the last straw," Keane's Milde said. "We've seen clients go at rate reductions or cutting baseline support, but it's always with the caveat that they want to keep the trains running."

One IT staffer, a software engineer for a $1.5 billion Midwestern sporting goods manufacturer, said maintenance cuts came to his company after lots of other paring was done, including layoffs of about 20% of the IT staff.

What's being cut

In the past, the sporting-goods IT staffer said, a typical IT maintenance contract purchased by his company specified that if a piece of equipment failed, the vendor would have someone on site within four hours to replace or repair it, he said. "Now, our philosophy is that if it breaks, we'll just go to the store" and buy a replacement.

"As recently as two years ago, whenever you bought anything -- software or hardware -- whatever the maintenance agreement was, you bought it all," the engineer said. "That is totally seen as a luxury now that can no longer be afforded."

Savings can be substantial. The sporting-goods maker paid $30,000 for one application and another $16,000 for an annual maintenance agreement on the application, but now maintenance has been cut altogether. And, he said, "We're cutting those kinds of things across the board."

Another user, an IT manager in the financial services industry and a board member of The Computer Measurement Group, said that while maintenance cuts are being made at his firm, they are occurring only in less important areas -- in human-resources systems, for instance, or Internet access for employees.

One CIO, Jim Prevo of Green Mountain Coffee Roasters Inc. in Waterbury, Vt., said he's not cutting maintenance contracts at this point, but that he can see the wisdom in it as an approach for some.

"It could make sense," Prevo said in an e-mail reply to a query. In general, maintenance contracts "should be based on business requirements. If the cost of downtime is reduced due to business decline, then it might make sense to spend less for uptime. Also, if you drop second shift [work], for example, you wouldn't necessarily need certain coverage for that shift in terms of help desk or assurances the systems are all working at night."

Halfway measures

The sporting-goods firm has also cut maintenance contracts on the network side. In the past, two providers were paid to maintain network redundancy and zero tolerance for failure. That's been cut to one, and now the company accepts outages of up to four hours under the new, cheaper contract.

The sporting-goods maker also used to have a policy that when an IT manufacturer declared a product had reached the end of its life cycle, maintenance contracts might be continued until a replacement plan was created. "Now the plan is to just run it until it breaks," then decide whether to replace it, the engineer said.

Jack Santos, a CIO executive strategist with the Midvale, Utah-based Burton Group, said that he's not seeing a lot of his clients taking these actions yet. "That's more the exception than the rule" so far, Santos said. "That's not to say it's a bad idea."

He has, however, seen small to midsize firms reduce third-party help desk services for nights and weekends. "Often times employees aren't happy about it, but given the economic conditions if it's the difference between a workforce reduction and an inconvenience, they'll take the latter."

Where cuts are not being made

The only places where the sporting-goods firm avoided maintenance cuts altogether were in customer-facing applications, including customer Web portals, which generate revenue for the business. If the Web portals go down, "then our U.S. dealers can't order parts for our products," which cuts revenue, the engineer explained.

As for the financial-services firm, "if it's critical and customer-facing, even in these cost-cutting times, that will not be changed," the manager said. "Anytime you have any regulatory obligations, there is no way that you ... have that luxury to save money there."

In the non-critical areas, "maybe you can cut in areas such as turnaround time" for support and repairs, the financial-services manager said. "You can still look for cheaper solutions, but you'd look for them with a guarantee for the same level of service."

Pain points: Effects on the business

A network accelerator, which compresses traffic to get more speed over the network, recently broke at the sporting-goods firm. IT couldn't call the vendor to fix it, the engineer said, because there's no longer a maintenance contract on it. So his company began looking for a used replacement on eBay. "We lived without the extra speed while it was being replaced; everything just slowed down," he said. The device has since been replaced.

For their part, end users "were noticing the cuts," he said. "The network slowed down. . . and people don't like that." That caused new trouble tickets to be generated due to speed complaints, which overloaded the IT staff with even more work.

"They're generally OK when they're told it's going to hurt," he said of cuts and their effects on company workers. "Then when it hurts, they don't like it. We spent some time in meetings where we had to remind people that they agreed to this" when the cuts were looming. "Everyone wants a fuel-efficient car, but they still want it to go fast."

"Different groups [of users] inside a company might negotiate for different service levels, and the squeaky wheel gets the grease," consultant Whitehouse said. When IT services are shifted around due to budget and maintenance cuts, the users suffering the greatest cuts are the ones who are most unhappy and most vocal. "I'm sure this goes on on a regular basis," she said. "I think it's more pronounced this year because of the general cuts."

Green Mountain's Prevo pointed out that cutting back on maintenance in areas including security could make corporate IT systems more vulnerable in some cases.

Maintenance cuts can cause noticeable performance hits for users, Keane's Milde said. "Sometimes mistakes happen and sometimes balls are dropped. We definitely have had that happen at a couple of customer accounts," he explained. "It's fairly clear, it takes a certain amount of resources to support a certain number of applications."

In the end, maintenance cuts mean that end users will have to solve many of their own IT problems, including finding answers to questions online rather than dialing a help desk, Milde said.

Going forward

The engineer's guess is that in the future, killing maintenance on software won't happen as much inside his sporting-goods company. "Vendors have been lobbying us really hard" to reinstitute the maintenance contracts, "giving us discounts, and are starting to soften policies and prices to try to get us back." In the future, maintenance contracts will once again become the norm in his company as new gear is purchased, he believes. "For the old stuff that's already in place, [though,] I don't see it coming back."

At the same time, there's a bad precedent for IT departments in getting adequate performance out of a lowered budget, Whitehouse said. "Companies don't want to show they can do the same with less because they'll get less next year." The biggest risk is not ever getting back to the pre-cut levels.

Burton Group's Santos said he's also seen changes driven by the tough economy in server virtualization popularity, "since consolidation of servers directly impacts hardware maintenance costs, as well as floor space and energy costs. That has been a very positive trend."

Another thing Santos expects to see are on-the-fly price cuts for maintenance contracts as companies reduce workers and seek corresponding reductions in the IT licenses and services they are buying now. As workers are added again, contracts can quickly be readjusted upward to cover new users, he said.

Even with the dramatic cutbacks needed to cope with the economic climate, however, there might be a silver lining, Santos says.

Companies don't want to show they can do the same with less because they'll get less next year.
Lauren Whitehouse, consultant, the Enterprise Strategy Group

"Some companies are probably overcutting -- they're going to lose staff, they're going to lose the commitment from their vendors," Santos said. "There's no question about that. But I think the large majority are doing the right thing and doing what they should have been doing in the good times. From 2003 to 2006, when times were easier, they were not being as observant and conservative. They should have paid more attention."

Monday, September 21, 2009

Project Management Adds Real Value and Cost Savings to Organisations

Project management is certainly not overhead. Project management, if implemented and performed in a structured and professional manner, adds real value by reducing waste, controlling costs and improving performance.

Good portfolio management will reduce waste by weeding out projects that should never be started. Often we start these projects and later cancel them after wasting effort and money.

Practicing good project management in the area of initiation, planning and execution will greatly increase the success rate and performance of your project execution. Resources will be better utilised and the team will be more communicative, motivated and organised.

This will reduce duplication of effort, control costs and ensure that risks, issues and dependencies are dealt with in an optimal and effective manner, maximising effort and minimising waste.

Performing proper project closure, and learning good lessons from our past successes (and occasional mistakes), will improve the performance and effectiveness of future projects.

Finally we need to monitor, review and control our projects. We learn in six sigma that you do not improve what you do not measure.

Taking metrics during each phase of your product development process is key to learning and improving your future performance. You can start taking these measurements at any time.

As you improve your implementation of project management you will also see an improvement in the performance of your projects. These project improvements will provide a 'gearing' effect and the same amount of effort as before, will create a greater momentum and more energy in the implementation of your projects. Simply by the introduction of good, strong project management methods.

With due regard for the creation of real value from dilligent effort, the Project Manager's mantra follows Vaughan's Equation: VO > EI (Value Out is greater than Effort In) You will find that strong project management follows this equation, very closely and will always be well worth your time and effort to implement.

Project management is certainly not overhead. I hesitate even to include the word in the same sentence to avoid establishing a subconscious association.

Project management, if implemented and performed, by a professional, in a structured and professional manner, adds real value by reducing waste, controlling costs and improving performance.

Project management provides better ROI, lower TCO and better TQC.

Sunday, August 2, 2009

Do Not Neglect Your Workforce: Your Future Depends on it

IT executives are constantly challenged to retain skilled IT employees and attract new talent whilst, keeping the budget square and the cost of labour in line with recession-related staff cuts.

In the midst of all this brinkmanship, juggling and balancing, they have to remember that neglecting the IT workforce will definitely damage the long term prospects of the company and themselves.

Do not cut your staff out of your IT budget:
It is clear that the majority of organisations do not plan to add staff in the coming months. Nearly two-thirds of those asked say that IT hiring has been put on hold until the 1st Quarter 2010, and the rest said they expect to increase head count modestly, in the same timeframe and only to replace shrinkage.


The problem is that despite the need to contain costs, the greatest priority in IT departments is the need to maintain and update skills, whilst at the same time adding enough staff to help support their companies' business. This is clearly more important in times of rapid growth and expansion but needs to be taken into account.

The Biggest Piece
Consider that the HR budget is the largest part of the IT budget, one of the primary challenges for executives and HR leaders, will be finding ways to better control those labour costs while engaging and retaining the workforce, effectively.

Morale
In addition, the current trend to restrict and reduce compensation and potential benefits coupled with additional workload will continue to stress and de-moralise the current IT workforce at many companies, and IT leaders need to be aware of retaining their key talent to ensure a potential for recovery from the current recession.


It will take time for the economy to stabalise and re-establish a new normal, the impact of this recession will continue to affect the organisation's bottom line, as well as on the overall job market. This will tempt companies to consider making further cuts in workforce-related spending.

Key Skills

Additional cuts, despite the budgetary need, could be false economy or at worst, a very big mistake. Certain IT skills remain in demand despite numerous IT professionals looking for work during the downturn. Key skills areas such as Oracle, SAP (All Flavours but particularly HR), Java EE, Microsoft .Net, SOA, Java and PeopleSoft (SAP-HR) continue to be sought after.


IT managers find it difficult to fill positions for enterprise architect, database administrator, project managers, ERP programmer/analysts, Internet/Web architects and Web application programmer positions. The issue isn't about the number of candidates available for hire, but rather their quality and skill profiles.It is ironic, because these are the very skills needed to implement the efficiency driven ERP system suites that are being put forward as essential to transform organisations in a crisis.

Dilemma

Here is the dilemma for IT executives. First you need to invest in powerful ERP Systems to transform, and re-shape an inefficient organisation but you don't have the skills on board to manage it, you do not have the skills to maintain it and your budget is so restricted that it does not allow for a quantum leap in demand for re-training. Even if you did re-train everyone, once they were trained they would be snapped up by other organisations!

IT Consultants

The good news is that the ERP System are being introduced and implemented by willing outsourced IT Consultancy group allied to the company, which is great in the beginning but unless your people can quickly gain the knowledge and skills required to manage the systems, then the consultants will be with you for a very long time ,at a huge cost to the organisation.


You have to ask yourself, "Where are the savings and benefits now?" and "What's my position and prospects for the future in all this?" Discuss!

Monday, April 27, 2009

Do not skimp on replacing old laptops

Your Business may not survive it!
Not replacing laptops can prove very costly. You will need additional service cover against losses and breakdowns, because the warranties have expired, not to mention the lost productivity in using a three year old model. Keep your laptops up to date and in the new budget. If there are cuts to be made then this not the time or the place.

Companies are trying to cope with reduced IT budgets and are postponing the purchase of new laptop computers but they are making a big mistake.

Extending the use of laptops two years beyond the traditional three-year lifetime cost companies an average of $/Euros 1,050 per machine, more than the initial replacement cost.

The additional costs will include a hype in repair costs simply due to old age, normal wear and tear and the end of three-year warranty periods.

For each laptop user that is using the outdated equipment, it costs the company about $/Euros 9,600 in lost worker productivity over the two-year period.

Many companies are keeping a tight control over new purchases because of the recession. Some forward-thinking companies have taken the more positive step of replacing some user laptops with less expensive smartphones or other handheld devices. Such devices can be far more cost-effective for users who are only using laptops to access e-mail.

The replacement of corporate laptops with mobile devices should grow significantly over the next decade. In fact, it is predicted that in less than 10 years, the majority of Internet users will be accessing the Internet via a mobile device instead of a laptop or desktop.

Mobile devices are now being seen as mission critical but organisations are not quite at the point where they are completely confident about replacing laptops with smartphones. They are looking seriously at it and planning to research the potential gains in efficiency.

Tuesday, April 7, 2009

Re-thinking IT Security in tough times

The current economic downturn is forcing a corporate change and metamorphosis that, when combined with ever broadening security threats, presents information security groups with an opportunity to radically change their identity and add more value to the business.

To capitalise on the moment, security groups need to reassess their approach, add visibility and transform the very role of security.

It is good timing because maintaining security during tough economic times is critical. Besides external threats that evolve even more rapidly in economic downturns, business slumps increase the probability of disgruntled employees striking out using intimate knowledge of corporate systems.

Risk is further exacerbated by the fact that, since the last economic crisis of this magnitude, companies have become far more reliant on information technology systems, which are now highly complex and essential to sound operations.

Your current security path represents existing programs, capabilities, processes, etc. The goal is to create a parallel path that influences existing practices and allows you to refine a new strategy without disrupting current expectations. In time, the new path will become a dominating force and take you in a new direction.

Step 1: Tuning the Approach
During the last decade security has been virtually defined by compliance. For many companies, it has been less about security than it has been about ensuring that certain regulatory demands are being met. Unfortunately, compliance does not necessarily enable the business, align with core initiatives, and alone may not thwart debilitating attacks.

Understanding this, some security groups have strived to use compliance efforts to improve their security posture.

Unfortunately, not all companies see the value of such activities and instead simply see compliance as a cost of doing business.

You have to convert the security practices that fall under the banner of "mandated for compliance" into specific activities that resonate with the business. For example, a predominant force in business is time to market and the rapid conversion of investments to revenue generation. This can materialize as a new service, application, communication platform, network or alliance. The key to tuning your approach is to optimize security features to help the business move more quickly, reduce barriers or accommodate a requirement quickly.

Key to being able to accomplish this is institutional knowledge within the security group and leveraging and combining resources in ways that benefit the business as much as it does security, for example: supporting secure coding practices through collaboration with the development team, optimizing standard builds to stand up servers more quickly, security testing as part of performance testing, or utilization of directory services to support streamlining of access controls for a new partner.

Fundamentally, it is about operating in a risk/reward model. Prioritize activities based on risk as well as where the greatest opportunities are for the business. By becoming intimate with business goals and mapping against elements of risk, what begins to surface is a common thread that demonstrates a point where the business and security goals become more closely aligned.

A good place to start is within the project management arena, where risks to the initiative or life cycle will become apparent, in addition to helping identify critical paths and what is most important or critical to the business unit. By using information of this nature, combined with institutional knowledge that the security group possess, you can begin to interpret demands and risks in business initiatives and quickly find areas of common ground.

Step 2: Adding Visibility
Security groups typically make security efforts visible to executive management by presenting security metrics, risk dashboards, and the like. However, along the way, many encounter some key challenges.

The first challenge is that the measurements are only focused on security and typically do not provide insights to other aspects of security operations that demonstrate effectiveness. For example, a dashboard may present compliance risk, operational risk, technical risk and current threats. It is assumed that keeping the values in an optimal or desired range means that security is doing its job.

However, company executives are increasingly focused on efficiency, effectiveness and overall alignment to business initiatives. They want to know how well these objectives are being met, what influence they have had on other key business performance indicators (such as time to market, customer retention), and how resources and other valuable assets are being utilized.

Executives are concerned about inefficient or wasteful activities and want to ensure all activities focus on the bottom line. Presenting to the board a risk dashboard can be helpful to demonstrate your alignment to security concerns, but that's only one part of the equation in the eyes of executives. The more effectively security can reduce the need to translate security results into something meaningful for the business, the better.

The second challenge relates to the "gap" factor. The gap refers to the difference in what security is providing to executives as visibility and the ability for the security group to influence the system to enact change.

For example, a report may demonstrate that the number of vulnerabilities in Internet-facing applications is increasing significantly quarter over quarter. However, the security group may not have the capacity or capability to reduce that number to a reasonable value. As a result, some senior security managers find themselves tasked to correct an issue they simply do not have the ability to accomplish.

In short, information from the security program is misaligned with its ability. Some use this to justify investments that would address the gap. But unfortunately this pattern is growing increasingly ineffective as business owners demand more accountability. The solution is to create a security program that not only presents good and bad trends, but more importantly, has the ability to have a meaningful impact in changing them.

The challenges can be summarized as providing visibility into more than security in security terms, but also in a manner that is more readily digested by executives and easier to align to business goals. Secondly, build a security program that not only produces meaningful information relative to security and business metrics, but also has the inherent capability to institute change and thereby meet expectations.

Providing additional visibility to existing risk-based perspectives can be enormously valuable. To accomplish this, you need to become more intimate with what resonates with the executives -- the measurements they focus on day in and day out, the performance indicators they study beyond the financial ones. Each company is different and each business unit may have a different spin. Moreover, many may seem like the furthest thing from security, such as shipping metrics, warehousing, capacity indicators, system use or even collaboration indicators. You have to look behind these to begin to see where security can begin to mimic the same philosophies.

From a security perspective, look to report on areas within your domain of influence and help reflect how well you're running as a business. It can be as simple as resource utilization, project involvement or performance quality scores from your peers.

From there you can start tying to other reported information and trends, such as the planned decline in effort to perform regular vulnerability testing, but an incline in report quality and effectiveness, essentially demonstrating that you are meeting security and business objectives. Or show how, through collaboration activities (which have been measured) and modifications to technologies, you've helped reduce the number of security related helpdesk tickets. These are, of course very basic. Nevertheless, the point is to find related information between what you are doing for security and how well you are doing related to business expectations.

This approach helps form your new path for security, drawing from your original strategies and enhancing them. Start small, test the waters and seek mentorship within the organization. As more confidence grows in providing additional perspectives on activities, you can move into closing the gap.

Step 3: Service orientation
By this point you've learned how to orchestrate your core competencies to help the business reach its goals using a risk/reward method. And you've started experimenting with adding visibility to the executives on alignment. As a result, the identity of security is beginning to shift. It may not be obvious, but it's happening. However, this is a critical stage and the time to innovate. Once executives see something they like, they want more, expectations increase, and that "good job" turns into "what have you done for me lately?"

One of the common pitfalls is not following through to ensure a foundation exists to keep up with new expectations. As a result, massive ground is lost and you're back to square one.

Adopting a service orientation can help you continue to move forward. Service orientation has three primary objectives:

1) Convert tactical best practices that were once hidden within compliance efforts into business services that can be consistently utilized.

2) Close the gap between what you can control/influence and what you're reporting on.

3) Create a foundation for building a highly agile security approach.

The key is to learn from experimental practices in tuning activities and report on additional metrics and indicators relative to business goals. For the development of security services, it's the tuning of the approach that provides the information you need to get started.

In the most simple of definitions, a security service is a well-formed package of related processes, technologies and capabilities that has a predictable outcome that is needed or in demand by the business. What makes security services differ from traditional security activities is input.

Just about everything requires input to feed a process to produce an output. For security, the input is usually "self-assigned," meaning the business must meet a specific policy or some other documented requirement to have security perform an action. For example, a policy may read, "Any material change to an Internet-facing application requires a penetration test." That's a sound approach, but it's reactive and misses the opportunity to gain valuable insights to underlying business needs and goals.

While looking for risk/reward scenarios, you will see a pattern emerge and the tuning efforts outlined above should help you identify opportunities to incorporate specific business attributes into what you're performing.

The basis for security services is taking advantage of this pattern. In fact, you're doing this today to some degree. For example, an application is due for a test, but you've learned that the changes relate to one of several roles defined in the system. As a result, you may limit testing to that one area because of your knowledge and comfort with the application from previous tests. Now, extrapolate this to all things in security. It's less about simply doing what you do and more about giving the business additional opportunity to feed the process in order to refine the activity -- or service in this case -- to the business need.

The next important characteristic of security services is how people, processes, tools, methods and technology are architected to perform the service relative to input and output. This is a lot easier to say than to do. Organizations tend to approach these elements as independent or loosely coupled. Moreover, some security architectures and frameworks facilitate segmentation, making alignment of them seem alien and uncomfortable.

One challenge is internally developed standards that are either overly comprehensive or too granular. Successful implementation of security services typically starts with reviewing the standards and looking at them as a common foundation to services as opposed to specific elements for a given security function.

As with all things of this nature, a slow and methodical approach wins the race. Don't try to create a services model over night. Take what you've learned in tuning, couple it with something you're already doing today (such as vulnerability testing, patch management, identity management, data protection, monitoring), and then pilot a services approach with a friendly business unit.

As this approach begins to solidify, several interesting things start to happen. The identity of security and perceived value continues to shift in a positive direction. Nevertheless, you will quickly realize that you have far more capabilities to measure operational details of your organization, and more importantly -- you inherently have more influence over them as a result.

This essentially slams the door on the gap. Services facilitate the risk/reward model, they make it possible to organize activities specific to demand, provide the means to measure those activities more effectively, and allow for the controlled management of each element to ensure that what is being reported can be influenced. This can be a perfect storm, but you're not done. To truly transform, you have to close the loop with governance.

Step 4: Governance Loop
The "governance loop" is the final step and provides the opportunity to realize real transformation. To this point, you've tuned, experimented, tested and created the early stages of services and are beginning to rely on the new path and less on the old one.

This has helped increase visibility, initial alignment to the business and promotes effectiveness. Nevertheless, at this point, time becomes your enemy -- without governance, the services will eventually break down. Governance, interestingly, provides the mechanism to ensure expectations are being met, but also the means to promote adaptability, closing the loop with the business.

Governance acts as the bonding agent between ebbs and flows in the business, compliance, risk and security activities. More importantly, this is where risk/reward is measured and fed back into the system to instigate change. It is also important to realize that risk (management, assessments, reporting) has played a pivotal role throughout the journey, and governance is the means to realize full potential. Risk remains at the top of the pyramid, but now with services underlying it, supported by governance, it can move far closer to the business.

In short, governance is analogous to "inspect what you expect" and influence change. That means creating a set of responsibilities and practices with the goal of providing direction as well as ensuring objectives are achieved and resources are used responsibly. In so doing, measurements from the oversight of security not only ensure efficient and effective execution, but also facilitate change in the program through intimate connections with risk management and the business offering feedback into the system.

In some companies governance is associated with enforcement. Although partly true, a security group empowered by services and close interlinks with overall enterprise governance through risk management activities will be able to put governance to work for them. This is similar to how, over the last several years, many security organizations have changed their perspective of the audit group.

Historically seen as a regular and painful exposure of operational weakness in security, audit processes are now being seen as a way to strengthen security. It's turning what is usually thought of as a negative into a positive force. The same is true with governance processes that are outside of the control of the security group or where security is part of a governance committee.

Nevertheless, an important aspect is to understand that the security group is ultimately responsible for its activities -- good and bad. Therefore, it is recommended that governance be reflected in the security services and program owned and operated by management resources within the group. This is not a replacement for enterprise governance -- rather, it's an extension focused on the betterment of security.

Organizations need security more now than ever, and as a result, are more receptive to security as a community. What you do with that attention today could have enormous influences on the future of security within your company. Although times are tough, don't assume this means opportunities don't exist. The economy will correct itself and businesses will emerge stronger and with a new sense of determination and demands for operational maturity. Taking advantage of what appears to be short-term focus on security for long-term gains is the crux of the opportunity, and opportunity favors the prepared.

This article is by James Tiller, author of The Ethical Hack and Technical Guide to IPSec VPNs, and contributing author on several other books, including the Official (ISC)2 Guide to the CBK, is vice president of security services for BT in North America. He consults with organizations globally on how security can enable business. You can reach him at james.tiller@bt.com.

Wednesday, March 4, 2009

Babies can't do an adult's job

Walking by the netbook display at PC World, Media Markt and others, you're likely to hear cooing and exclamations of how cute the little baby laptops are.

Beware, if you take one home, your new baby is not yet fully grown and it is barely on solids. It has not built up enough of the resources to do the work that a stan
dard Momma and Poppa notebook or Laptop can do. Its got some growing to do.

Cheeky new Netbooks are just about the only thing these days that are generating any kind of excitement in the hardware market space. The visual appearance and form factor is appealing to many. The idea of having a good workhorse laptop that can carry your workload at half the size and weight is a dream, but I am sorry it has yet to come true.

With a 10-inch screen, these babies are much smaller than the standard-sized notebook, and yes, much lighter. They are also quite a bit cheaper too. Some are as inexpensive as €200, while others can get as expensive as the €1,000 range. Take note, there is a good reason why they are cheaper.

It's hard to walk by a netbook display at a consumer electronics store without hearing someone coo-ing at them and talk about how cute they are, as if they really were little baby notebooks.

Their magnetic appeal to consumers, means that netbooks have been doing their part to boost sales and make PC manufacturers happy. If you look at the earnings report of any PC maker who makes netbooks, you'll notice that netbook unit sales are just about the only thing growing at a healthy pace. This year other hardware sales look positively bleak, with Gartner now forecasting a decline of almost 12 percent in 2009, the worst in IT history.

Although netbook sales seem to be increasing, some in the industry say that netbooks are suffering a greater return rate than other PCs. If that is the case we can predict an increase in th enumber of netbook orphanages opening up. Netbook for sale. 1 disappointed owner!

  • On the consumer side, it's said that once users get the machines home and play with them for a little while, they soon realize the smaller machines can't do all the things that their more Momma and Papa (standard-sized and standard-priced) notebooks can do. The very inexpensive netbooks generally come with Linux, an well respected operating system in the techie world but still a little unfamiliar to the Microsoft masses.
  • On the enterprise side distributors say netbooks have yet to take hold.
So what's the real story? Can that little baby PC do the big jobs you need it to do? Is there a place anywhere for the netbook in 2009? Is it a serious business contender? Consider this;

Screen size. The size really negates th eus eof Windows style operating systems because you only have space for 1 window. Do your users want to run multiple applications and have more than 1 window open at one time? Do they use spreadsheets? Well, while the netbook's small form factor makes it convenient to tote around, but you will not be able to see everything you need to see. Certainly not at the same time and that can get very frustrating.

Storage. To save space, most netbooks are shipped with a small amount of solid state memory rather than a rotating hard drive. This makes sense in a world where memory prices are always falling and solid state, is faster and more reliable. However, many users have become accustomed to more than 100GB of memory and even in netbooks with hard drives, those users may be disappointed.

Processor performance. You would be foolish to buy a PC that isn't dual core, at least. That is, unless your looking at a netbook. Most standard notebooks come with a dual core processor, either from Intel or AMD, but most netbooks use Intel's Atom single core processor. Intel has said that Atom processors have about half the performance of Intel Celeron processors. Party on!

The other features you and your customers have gotten used to have also been downsized or bypassed. You can get the Microsoft Vista Premium OS on some of these notebooks, and you can buy an external DVD player and an additional external hard drive but by the time you have financed that, you could have configured a standard Momma and Poppa low-end laptop that comes with a higher-performance processor.

Some companies are coming out with some interesting new innovative netbooks, including ones with an ARM processor and a detachable keyboard, making it appear more like a tablet notebook.

In Summary. Unless you want what the netbook really is (a lightweight client that functions well in a cloud computing environment for tasks such as e-mail and Web browsing, but is not as capable of heavy lifting) you are probably better off with a standard Momma and Poppa notebook for a few euros more.

If you want something cute and cuddly around the office that can be easily picked up and taken anywhere, there are other more appropriate and interesting things.