Showing posts with label process. Show all posts
Showing posts with label process. Show all posts

Thursday, July 30, 2009

The Changing Role of HR now and in the Future

Human Resource functions and responsibilities are changing and intensifying at a faster pace and to a greater degree than many other areas of the corporate organisation.

Once relegated to the back office and concerned mainly or exclusively with transactional processes and functions, HR organisations are taking a greater role in strategic business activities.


Efficiency remains the foundation of HR. More transactions must be completed at a lower cost, while processes are becoming increasingly complex to manage.

A typical 10,000 employee company handles more than a million employee related transactions annually, each of which costs in the region of 50 Euros.

The top 10 recruiters in Europ report that they are placing 35k to 95k employees annually. Managing the recruitment pipeline, the selection process, and the induction process is a complicated endeavour.

At the same time, however, leading HR organisations are looking far beyond the execution of HR transactions, to a more value-added and strategic focus.

These organisations are aligning human resources and workforce planning functions with the overall business strategy, to help increase profit margins and support long term goals.

The study analyses several dimensions; staffing, cost, organisational model, IT deployment, and best practice adoption. The following key conclusions demonstrate how companies are meeting today's human capital challenges;

1) As a first step, HR managers strive to optimise the efficiency of transactional processes by standardising, automating and integrating business processes, based on Best Practice process and technology models.

2) Optimising transactional processes frees up resources that allow HR organisations to invest in more strategic functions that facilitate business growth and increase employee productivity.

3) Centralising and consolidating HR operations in a shared services environment helps increase the effectiveness and efficiency of the HR processes.

4) Outsourcing, while used frequently for transactional processes, does not always drive top performance, either in cost or service quality. Organisations need to carefully evaluate the value, performance and cost benefit trade off in outsourced versus in-house service delivery.

5) Information Technology continues to provide the basic foundation for efficiency and acts as the key driver for efficectiveness and future innovation.

Leading organisations recognise that IT supports the development of many best practices and they continue to invest in IT to integrate systems, data and processes across the enterprise.

Briefly, the study finds that the best human capital management organisations are constantly re-assessing their processes, to strike the correct balance in the drive to optimise efficiency, cost and service delivery in a continually changing global environment.

Top performers in this area balance the traditional demands that drive company profits and growth and help prepare for future innovations.

Wednesday, July 29, 2009

Project failures and Change Management strategy

Tight budgets have upped the ante in what IT projects organisations choose to pursue this year, and in some cases the executive involvement in those projects has substantially increased as a result, consultants and practitioners say.

Yet the executive contribution to project and portfolio management (PPM) at large enterprises is more often about communication and change management strategy than other parts of the process.


Project Portfolio Management

Executives are involved with managing the project portfolio or adjusting priorities among projects at less than 20% of organisations with more than 1,000 employees. Rather, those duties are most often performed by IT directors or governing bodies.

Instead, the executive's role is one of communicating a vision and driving a change management strategy that will result in greater user and organizational acceptance of the projects selected for development.

Lead by Example
There is more riding on the executive's decisions in the project management space than ever before. The executive can't just delegate project management responsiveness to the staff because he must lead by example.

Organisational Change
Organisational change management is crucial. Before rolling out new PPM solution from anyone consider having a soft launch, configuring resource pools and providing training for resource managers, senior leadership team members and project managers.

Change Management
Change management should be the starting point because the overall project management strategy will succeed or fail based on this.

A change management strategy formally introduces initiatives to everyone affected by them, and should also introduce any new roles or expectations to team members to get everyone on the same page at the same time.

Creating a Change Culture
Creating a culture where everyone understands their roles, responsibilities and expectations from the get-go increases the chances for project success and it reduces surprises.

Indeed, surprises are one reason for project failures, which persist despite governance and tools like PPM software to keep projects on track. It regularly comes down to the fact that the business didn't realise the impact the change was going to have, and therefore didn't plan for it.

Project Success rates
Research on project success rates found that 24% of projects are cancelled part-way through or delivered and not used. Surveys showed that just 11% of large organisations complete all projects in their development queue; the majority (54%) report an abandonment rate of 1% to 10%. The final third don't even finish 11% to 50% of their projects!

Consolidation
Consolidation can go smoothly if you lay out an extensive workflow for change management prior to or during the implementation process. Pay special attention to the rigorous standardisation that needs to take place while developing a realistic timeline.

Small Changes
Start out by changing small things; changes grow in complexity as the organisation works toward its goals. Remember, you need to be able to crawl before you can run. Whenever you are changing business culture you first need to plan out the procedure for it, or else the tools will just sit there, unused and unwanted.

Starting point
Change management should be the starting point because the overall project management strategy will succeed or fail based on this but too much process can also be a problem, resulting in a slow death "by a thousand cuts".

Approval Points
Before the recent economic crisis, there were two or three approval points to get a project going. Now it feels like the number of stringent checkpoints has increased, leaving new, creative projects to die on the vine before they even have a chance.

Tight Budgets
Tighter budgets have led many organisations to add tight checkpoints for proposals, aimed at weeding out unnecessary or unrealistic projects before they even start. Although these processes can prevent wasting time and money on projects that don't provide a lot of value, they also stifle innovation and discourage new ideas. Finding the middle ground can be difficult.

If there are too many approval points, people get frustrated and throw up their hands in premature defeat but if there is not enough, the engagement can fizzle out.

A Vision
Developing a vision that meets business objectives and the needs of stakeholders can be the first step in finding that happy medium. Start basic, envisioning a plan that doesn't necessarily require a lot of tools and processes but has better stakeholder alignment and overall clarity into what the business problem is that you are trying to solve.

Balance in all things
Strike a balance by staying open to the potential for project adjustments along the way while also following Lean Six Sigma methodologies and ITIL best practices. You can run Lean Six Sigma in parallel to the business processes of the project and you can streamline every project to fit into this overall strategy.

Keeping costs down
At the end of the day, executives are trying desperately to keep operational costs and spending under control while still making progress on IT strategies. They need very honest and accurate information on the projects rolling up to them. It's very important not just for managing IT but also for engaging the stakeholders and the entire business leadership team. It is one of the IT executive's most important responsibilities.

Tools are not the answer

You can have the most expensive and beautiful project management tool out there, but without the support of the management and your project team, it just won't happen.

The Sacred Cows of Roles, Process and Metrics

A View on Sacred Cows
There has long been some academic argument, theoretical disconnect and the occasional raised tension between the dedicated followers of business intelligence /performance management (BI) and those that stand behind business process management (BPM).

KPI and data evangelists sometimes view process advocates as bureaucrats no longer tuned to the dynamics of changing businesses, and are now more interested in outcomes than processes.

Meanwhile, the process faithful have worked incrementally and under a long-held premise that 'where business/technology initiatives fail, there’s normally a clumsy process to blame'.

Inside Process Initiatives
By their very nature, inside process initiatives draw little attention, being as they are usually secretive. The greater effect of business process outsourcing (BPO) has already shifted workforces for scale.

What started with call centre outsourcing, sooner or later touched internal departments for travel, payroll, time and expense, software development/maintenance and even CRM or other customer-facing applications.

Process and Data Converge
In the last few years we’ve seen the process and data worlds merge to the point where process conference speakers actually discuss business intelligence and vice versa. It’s that tentative connection of processes and KPIs (or service levels for BPO providers) that has led to some recent rationalising thoughts on soft skills and the beginning of what might someday become a wider and mor comprehensive use of on-demand employment.

Executive Ambitions and Goals
We have been learning about executive ambitions and goals inside global corporations. These normally culminate in the establishment of internal priorities for employees and the outsourcing of everything else. We have to be more thoughtful now and need to consider that data centre managed service offerings are replacing not only IT infrastructure, but also their discrete IT functions.

Where is this leading?
Well, as service based infrastructure and process providers move deeper up and into the enterprise, old roles are slowly moving towards silo containment and tiers of competence. This leads more and more towards the virtual external providers whose value has becomes more nad more commoditised over time.

Driving or Steering SMEs
This use of comoditised outsourced suppliers is what is driving or steering small and mid-sized organisations and feed the continuous discussions to appraise and determine if even key undertakings like business intelligence are effectively outsourced to service providers.

Corporations' Citadel Approach
The larger corporations are not going to be outsourcing business intelligence or even key data functions anytime soon. Having said this, the previous years of rapid organic growth has created a jumble of capital assets, business architecture and roles in enterprises, which are becoming less controllable and therefore less defensible to maintain in-house.

Proven Competency
If you accept that BPO vendors have demonstrated and proven their competency, it may be more likely that core competencies will be begrudgingly and tentatively handed over to process owners inside the organisation, to manage internal and external resources.

Controlled Handover
This handover is already happening in a controlled way at companies like HP, Ford and Cisco. We already have people managing this transition, in the form of project and program managers, whose roles are enjoying elevated backing and status.

The Future
There is still some work to be done but there is good reason to believe that, improved operational metrics, performance management and business intelligence, will bring with it the mover and shakers of the process and on-demand movements. We just have to keep to the path, fight the fight and hold the faith.

Tuesday, February 3, 2009

PM for Network Professional

Good Timing is the key to Good Project success!
Professionals know what they know and network professionals are typically well-versed in the technical aspects of networking: protocols, router and switch configuration, server deployment and management, and so on.

Conversely, we don't always know what we don't know and our colleagues, the network pros, are rarely trained on how to manage projects. Fortunately, most of the problems that networkers face in projects can be addressed and mitigated against using standard project management methodologies and techniques.

Consider the effect of some Probability and a little influence from Evolutionary learning can have on your projects. If you are not proficient in something but do it often and long enough and are determined enough, sooner or later you will start to have a greater degree of success or a lesser degree of failure. Design and install networks long enough, and you'll be sure to have some of those projects go awry due to predictable, 'unforeseen' 'surprises'. Two words that you do not want to use in your monthly Project Progress Report. Two words that clearly depict the reasons why you should be applying Project and Risk management methodologies.

....and then they put the phone lines in!

Sometimes the infrastructure you need, such as power in a communications room, is not ready when you need to install an Ethernet switch. Other times, your network equipment vendor may seem to be perpetually on "back order" with the one module you need. Or perhaps it's the all-too-familiar "scope creep" when users decide they need greater wireless coverage than they asked for at the beginning of the project, without increasing costs of course.

Managing network projects is not an exercise in fortune telling, far from it. When analysed the core components for network projects are just like any other project, IT or otherwise: There is an objective, a time line, a budget and expectations of those who will benefit from the network once it is completed.

Professional project managers command good salaries because they understand these processes. Executives know that certified project managers are less apt to have projects run away from them. Attaining project management certifications such as the Project Management Institute's Project Management Professional (PMP) could be just as valuable to you as a network professional as a Cisco Certified Internetwork Expert or a Microsoft Certified Systems Engineer but you don't have to earn the full PMP certification to reap some benefits.

Applying a few simple project management tips will quickly earn you a reputation for delivering network projects on time and within budget and this is the sort of reputation that opens doors.

Quick Fix is leading but .............!


Triple constraints; I once saw the following on the wall of a drive-in oil-change service: "You can have it done cheap, fast or right; pick two." This is true of all projects, and it illustrates the so-called "triple constraints" rule: projects are subject to cost, schedule and performance parameters. Changing one will affect at least one of the remaining two. e.g. when installing a network for a local bank branch office to allow for Internet access and e-mail. The project includes configuring a Microsoft Exchange server and installing a virtual private network firewall for security. You included labor in your project schedule and quote to ensure that the project is done in two months, as requested.

One week into the project, the bank announces acceleration in plans, the office network needs to be done in three weeks instead of two months.Your staff is already fully devoted to this and other projects. You can't cut out functionality because the office still requires all of the network connectivity and e-mail functionality. What can you do?

The only way to accommodate is to add more staff, either by paying overtime to your employees or subcontracting another IT firm. Either way, the cost will go up, yet the bank will likely baulk at the new cost. At that point, armed with the understanding of the "triple constraints" principle, you as a network pro knowledgeable in project management concepts can calmly explain why the request to change time will increase the overall network project cost.

......there be monsters here!
Project charter and scope; To reduce the likelihood of the network project growing uncontrollably, make sure that everyone understands the project deliverables, what the network will provide, how long it will take and at what cost. Your key constituencies here are the project sponsor and the network administrator.

By following project management methodologies, this can be accomplished by starting from the general (project charter) and migrating to specifics (project scope).

For network projects, the project charter could be simply "provide network connections for the new Shelbyville Bank and Trust building at 3 Main Street." Details including the number of connections, security protections needed and services desired are best left to the project scope. The scope simply supports the goals defined in the charter while providing more details; it is not a complete network engineering plan in itself.

You can create an initial cost estimate for the project from the scope. When the scope is broad or when there is only a charter, precise estimates are not possible.

A good option, is to take a network project of comparable scope that you worked on previously and use that as a basis for the estimate. It's also wise to not give a single figure estimate but rather a range, say maybe 50 percent on either side of the estimate derived from historical knowledge. As the scope is more clearly defined, refine the cost estimate by changing the midpoint as appropriate and reducing the range size.

Project schedule; Once scope is known, a project schedule should be determined. You'll already know the two most important project points: the beginning,following soon after the project scope is approved and the end, when the network is in place as requested by the sponsor. It's up to you to fill in the blanks.

Here's where a project management software package such as Microsoft Project really comes in handy. It can tie all aspects of the project together by providing a relatively easy way to create the plan for the network installation. Setting up the project plan can take some time at the beginning, but it will pay dividends many times over the course of the network project.

When planning network projects, break the project into the following six phases:

  • Information gathering—scope, existing infrastructure
  • Purchasing decisions—which switches, routers, firewalls, servers and so on are needed
  • Ordering equipment
  • Configuring and installing the servers and network equipment, and testing connectivity and functionality
  • Customer acceptance
  • Documentation

However, you decide to manage your network project, breaking it into smaller miniprojects makes the overall project more manageable. Suppose you know from experience that you generally receive network equipment from your supplier four weeks from order. Furthermore, you know that it typically takes two weeks to configure and burn in the equipment and another two weeks to install and test. So, start from the end of project date and count backward eight weeks; that then becomes your milestone date for ordering the equipment.

Scope creep. Performance constraints can also change, and in networking, they are usually on the side of more functionality, not less. Scope creep is a change in project requirements after the project has been planned and is under way.

A common example of scope creep that every network professional I know has experienced, is when the customer decides he needs more network capacity (number of jacks) than what you planned for at the beginning of the project. I like to inform customers upfront about the magic number: 24. Many vendor enterprise workgroup switches have a minimum of 24 Ethernet ports (some allow 48). Pass the magic number, or a multiple thereof, and expect the project's cost to increase (refer back to the "triple constraints" rule).

Of course, changing the number of connections does not just affect network electronics costs. Additional cable drops and possibly patch panels for terminations may be needed. An increase in electronics (switches or servers) may require heftier uninterruptible power supplies and may increase heat generation, forcing an upgrade of the HVAC design of the communications room or data center. It's clear to see that expanding the project requirements increases its cost, which is a problem when budgets are limited and fixed.

These problems exist because all involved with the project; the sponsor, network administrators and the other stakeholders (end users, equipment vendors, cabling contractors, customers), assumed that everyone was in agreement at the beginning of the project. But this was not the case. When all parties agree on and understand the scope at the beginning of the project, it is less likely that scope creep will occur.

Finally, should the scope still need to change, simply create a new cost estimate and timeline to accommodate the scope modification. Changes are not necessarily all bad, as long as all involved understand the effects that any changes may have.

Closing out a project. Once the network infrastructure is completed, there are still three major tasks to accomplish before the project can be closed. The first is rather obvious, ensuring the network functions as the customer intended. The customer should perform as many business-related tasks as possible to test the infrastructure and formally sign off accepting the project when complete. The latter will prevent end-of-project scope creep as well as provide a milestone for you to close the chapter on this project.

The second job, too often neglected, is to fully document the network. Remember, one of the goals when the project scope was created was to ensure the manageability and supportability of the network. Network drawings, router configurations, circuit numbers, server disk partition information, IP address assignment—anything and everything that was pertinent to the successful completion of this project should be documented and stored where it can be easily retrieved.

Finally, network projects rarely go exactly to plan, and sometimes surprises occur that could really not have been foretold. A postproject review, particularly of what went wrong, will help prevent the same mistakes from happening on a future project. I recall one network installation in which a concrete slab was poured before conduits were installed, necessitating cutting the slab to install the conduits. The lesson learned was to include regular on-site network infrastructure inspection dates as tasks in the network project plan.

For more information; You don't have to be a certified project management professional to take advantage of project management techniques to aid in your network projects - but it helps!

There are numerous Internet resources related to project management, including the following:
The Project Management Institute is the source of the Project Management Professional as well as other certifications. In addition, Prince2 is the preferred project management methodology and certifications in Europe, particularly in the U.K.

Stop your IT Projects getting canned

To weather the current economic maelstrom, enterprises are not only reducing head count but also are cutting back on ambitious or long-term projects in IT. Knowing how best to keep your IT project in the pipeline could mean taking a cue from those best versed in achieving project approval: Project and risk management business consultants.

Companies are cutting back significantly this year. They're under more than usual pressure to optimize every dollar, to either stop the bleeding or start the recovery. The key to retaining business is to build /re-enforce customer loyalty. This is demonstrating that continuing with your current initiatives should not only cut their costs but also help generate additional revenue.

What's true for consultants is equally true for IT managers looking to kick-start an internal project or to keep their project funding flowing. Those who are best at proving the value of their projects will win. And when it comes to uncertain times, keeping your project off the chopping block can end up saving your future and enhancing your career. There are many ways to do this and I would like to suggest a few.

Benjamin Disraeli
Benjamin Disraeli, is reputed to have said that there are three kinds of lies: lies, damn lies, and TCO/ROI calculations for IT projects.

Clearly, no professional right-minded company will pour money into IT without a strong business case. There has to be a payback and that final payback is that the business will get something beneficial in return. Before you can be a part of this, you will have to address the issue of choosing the right metrics and presenting them well.

Calculating the true return on investment goes beyond demonstrating cost reduction or bottom-line enhancement. Those days are gone. Today's executives are no longer likely to let simplistic metrics pull the wool over their eyes, after all, presenting statistics and compiling business cases is part of their job too. You have to provide something they can sell on to their people.

ROI dismissals
As we move deeper into belt-tightening, we are seeing more and more ROI calculations being dismissed. Most ROI calculations from vendors are flawed toward magical and large returns, and most calculations from users are too simplistic and unreliable. Bottom line: accountants don't believe them and cannot use them anymore.

Though numbers can't be rejected entirely, the kind of numbers you use should vary depending on the ultimate goals of the project. Despite being a great decision-making tool, ROI is often a misleading indicator for deciding whether a project should be pursued or not.

Case Studies Testimonials
Reliable case studies showing how other organisations implemented similar projects successfully and achieved positive results, may have more credibility with cynical management teams rather than simple ROI projections. All you have to do is find the appropriate cases.

Hard or Soft?
If the project aims to reduce head count, inventory, or transaction costs, so-called hard ROI numbers may be sufficient but for projects with less measurable aims, e.g. improving the business environment or coping with service provision changes in the competitive landscape, soft ROI, e.g. the increase in growth potential or business value as a result of improved relationships, comes into play.

Thus, positively demonstrating the beneficial value of your project can prove tricky, but if you focus on added and hidden value in these areas and make a strong case, you will significantly improve the likelihood that your IT project doesn't get canned.

Helicopter views
But don't focus too narrowly on your project's niche lest you lose sight of the big picture.
IT managers always need to step back and look at the impact their project could have on the entire organisation. You need to look at the cost of lost opportunities. What are we not going to be able to do, in terms of people, hardware, software, training and other monetary issues, all because we took on this project?

Will we be able to do more of what we do well or do what we do more effectively? Will this give the company, service or product a competitive edge in the marketplace? It can't just be a cool thing to do anymore.

Business needs direct IT
The true business need meets the true ROI. If the business has asked IT for a helping hand in a project, that should be enough. If you're doing an IT project that is either not driven by the business or does not have direct bottom-line financial impact to the company, you should not be doing the project in the first place. Would you have the business or IT shop do an ROI on something as basic as an e-mail server? No one would tell you that because there is no ROI, therefore we don't need it. The business need bypasses the requirement for IT to sell an ROI back to those who requested it in the first place.

Customer loyalty
Building and re-enforcing customer satisfaction and loyalty is paramount in troubled times. Despite the cost, executives will approve high risk investments because the cost of not doing the project in terms of dissatisfied and lost customers, can be far greater than the addition of new IT capabilities. Projects that reduce customer retention costs or increase the efficiency of marketing campaigns are more likely to get a green light.

Making it real
Even the most ruthless, cost-slashing IT project can die a swift death if it's pitched in language your accountant can't understand. Be aware that everybody talks and thinks about TCO and ROI just a little differently, depending on their view. It may help to manage the differences in understanding by the creation of a glossary or terms definition, distributed to the key executives.

Language
As the PM, you are the communicator and you need to have a sound understanding of whatever language your company works in. Do they use internal rate of return, payback period, time to value? Sometimes business leaders don't always sync up to the value language of the company. If capital is involved, you need to understand the process your finance department uses to approve the budget and get it into the language they speak.

Keeping it real
Business case assumptions must be thoughtful and clearly supported in terms an accountant will understand. Include metrics on power usage, maintenance contracts, and head-count savings. These often can't clearly be seen until the next fiscal year. Accountants crave short term gains and cost-control drivers that help manage long-term planning.

If you can show payback for an IT investment over 18 months or less, even better. Accountants love to recover the cost of expensive volatile technical assets before they're fully depreciated. They know the rapid rate of obsolescence in high tech toys, the lock-in tactics and the long licensing traps.

Don't stick your neck out
Embrace Optimism when you can. All projects rely on assumptions and the associated risks. The bigger the project, the bigger the risks. The key to getting your project approved is simply to do your homework. Study, analyse and assess the risks rather than assuming the best and being surprised by the worst.

Positive risk management
Planning for a positive outcome needs implementing better risk management, plus the provision of accurate financials, supported by proven program management methodologies and earned value. Also, you will gain more oversight and control with smaller and more frequent milestones.

It's better to be transparent and realistic about everything but base your budget contingencies on sound risk management analysis and assessment. You should never presume to receive 100 percent of a project's costs initially when you don't know 100 percent of the project requirements. Manage the risks and issues as you go and adjust your expenditure according to your project plan, risk management actions and develop a positive outlook in the team. Look for positive risks; opportunities and assess them as you would a negative risk, fully.

Building a project
PMs and IT managers will find it more palatable to take a staged or phased approach when pushing ambitious projects, one that relies on shorter, clearer milestones with conditional metrics tied to future funding. If you cannot get funding for the whole project because of skepticism of deliverability or payback, ask for phased funding. Each phase can have a checkpoint where progress is measured and funding for the next phase is approved or denied. If the business isn't happy with progress or results, there is much less risk.

Messy eaters
Try scaling back and down to move forward. Keeping your project off the pig swill scrap heap may mean settling for a digestible piece of the pie instead of the whole thing. That way you don't kill the chef and you can always go back for more later.

Even a broken clock is correct twice a day!

Dirty Laundry - leaking Security

Oh what a tangled web....
Your security providers cannot, and will not, tell you the whole truth about their security business because security is a state of mind. An illusion based on perception and relativity.

We accept the need for security service providers to specialise in the protection of our functioning environments and see their task as preventing or reducing unacceptable risk. You would be very naive to think they do this for altruistic reasons. The goal of the security market is to make money and they are doing very well, thank you.

As with all profit focused companies; 1) Security companies specialise in niche markets and have varying degrees of success in these markets 2) There are universal weaknesses in the structure that are not being addressed because;
  • the technology or algorithms are not sophisticated enough, yet
  • the market won't pay the price in restricted access, additional filters /controls that slow throughput and diminish transfer speeds
  • they are chasing a shape-changing, highly motivated and relentless attacker, some of which are government sponsored
  • Others
Here are some secrets of the security industry and practical ways to command honesty from your trusted security providers.
  • Antivirus certification omissions - One of the biggest secrets in the industry is that, while antivirus tools detect replicating malicious code like worms, they do not identify malcode e.g. nonreplicating Trojans. Although Trojans have been around since the beginning of malicious code, there is no accountability in antivirus certification tests. Today Trojans and other forms on nonreplicating malcode constitute 80% or more of the threats businesses are likely to face. Antivirus accountability metrics are simply no longer reflective of the true state of threat.
  • There is no perimeter - If you want to fight on the perimeter then you need to define where and what the perimeter is. Is the endpoint the perimeter i.e. is the user the perimeter? Is it not more likely that the business process is the perimeter, and the information itself forms part of the perimeter too. It is unlikely that you design your security controls with no base assumption on establishing a perimeter. The mistaken assumption we tend to make is that we have established controls at the perimeter and are therefore secure. Unfortunately for many types of threats, we could be very wrong.
  • Risk management applies - Risk management threatens vendors. Risk management really helps an organization understand its business and its highest level of risk. However, your priorities don't always map to what the vendors are selling. Vendors focus on niche markets and individual issues so you will continue to buy their individual niche products. If you don't have a clear picture of your risk profile and priorities, vendors are obliged to set them for you. Trusted security partners will provide options for assessing your risk posture and help you develop plans to make the most security impact for the least cost and complexity. Security needs to conform to and support your business priorities. Too often, vendors want your business to conform to their product portfolio.
  • Vulnerable People are more of a risk than weak software. - There are 3 areas to be considered where security is vulnerable; 1) software 2) weak configuration and 3) people. The lion's share of the security market is focused on the so-called software vulnerabilities but not so much on the other 2 areas. The people factor is the largest uncovered area of risk. This is malicious code that doesn't leverage a vulnerability but rather leverages the vulnerable person. e.g. downloading a dancing skeleton for 'a spooky good time' (this was a trick employed by Storm), social engineering, spear phishing, etc. While we still need to find software vulnerabilities and patch them, we must understand that an organization is only as strong as its weakest link (the user). And more attention needs to be paid in mitigating the other two ways beyond software.
  • Can Compliance threaten security - Compliance in and of itself is a good thing but it does not equal security. At the very least it's a resource and budget conflict and it can split our focus. Compliance is there to raise and maintain the minimum standard of security, but in its weakest form, it only maintains the minimum requirements.
  • What is easy to measure is not always the most valuable - If you have 15 software vulnerabilities last month and record that 12 of them have been patched, is this a true reflection of your effectiveness. It is much harder to measure how effective end user training was to make administrators immune to social engineering attacks. You need to be compliant, but don't allow your entire risk strategy to sit back and relax, based on it.
  • Vendor blind spots allowed for Storm - Storm is being copied and improved. The Storm era of botnets is alive and well, nearly two years from when it first appeared. How is this possible? 1. Botnets thrive in the consumer world where there is little money for innovation. Storm and its controllers know and survive on this. They are making money out of everything from spam to pump-and-dump stock scams. 2. They seem to be able to eat antivirus techniques for breakfast. A lot of the techniques and innovations used by Storm are not new; they are just being leveraged artfully against the blind spots of antivirus certifications and antivirus vendors. 3. Malcode does not need vulnerabilities. Most of the Storm recruitment drives have leveraged social engineering and play off of a holiday or sporting event. Go team!
  • Product v Process - Security protection has established itself as a huge professional business. "Technology without strategy is chaos". The security market is too focused on the latest red hot top box or super scorching technology. The shear volume of security products and the rate of change has super-saturated most organisations and exceeded their ability to keep up. Organizations realize only a fraction of the capabilities of their existing investments. Furthermore, the cost of the product is often a fraction of the cost of ownership. There was a time when you could "do it yourself." But the simple days of Virus meets Antivirus are long gone. Highly effective organisations are embracing professional and managed security services to extend and augment their in-house expertise. By focusing your in-house expertise on what you know best i.e. your business, the scale comes from teaming with third-party expertise. This will be increasingly necessary in these tough economic times.
The primary goals for executives is to squeeze cost, whilst maximising profit and reducing complexity. Today we are seeing a massive convergence in the security market. In a guard-dog eats guard-dog world there are soon only going to be a few big dogs left and a bunch of smaller mutts. Will the consolidation dogfight lead to better efficiency or will it lead to a vendor lock-in?

As company leaders and executives continue to squeeze and simplify, they will face many choices. Simply following the reduction of vendors by consolidation, may fail to meet their needs and balance their fragile cargo; cost, complexity and risk. Do vendors have a responsibility in this equation? Will they rise to the challenge? True risk management can show how and where you can adjust and prune appropriate solutions,

The key is using risk management methodology to drive responsible simplification of business processes and to take control of the future.

Sunday, January 4, 2009

HR - New Start Integration

DIS - Dynamic integration support in a rapidly changing, cost conscious and fast growing enterprise

The dynamic integration support process will supplement and enhance the services provided by the organisations stressed-out HR staff and management team. The consultant addresses the volatile requirements of stakeholders both in the rapid uptake of candidates and in their effective integration into the new environment. The consultant decreases the time taken to assimilate new staff and embed them into the team and organisation, maximising their effectiveness and motivation throughout.


Chief Executives

Dynamic integration in a rapidly changing 'cost conscious' enterprise is able to support and supplement the HR staff in addressing the 'cost versus talent' argument by supplying focused coaching skills to candidates that may be less qualified, less experienced or unused to the new environment that they find themselves in. Free from this responsibility, the HR team can then concentrate on sourcing candidates with the greatest potential and the right motivation to grow without worrying about precision skills matching and the integration of candidates that may have different or unmatched energy levels and personalities from the incumbent team.


Hierarchy awareness and Buy-in

The DIS process also requires that the managing environment and team understand the changing team dynamics and that they are also positively managed through this period. Working on behalf of the organisation and the team, the DIS process ensures the rapid uptake of new skills and knowledge by the candidate. Supplying the provision of a mentor to manage the changes and to mitigate or resolve any risks or issues, envisaged or arising. The consultant will establish a buffer or de-militarised zone to allow the free flow of dialogue and negotiation, minimising disruption to the team’s effectiveness and to managerial goals.


Performance enhancements realised

It is vital to be able to positively manage the organisational expectations coming from forthcoming changes in staffing levels and the introduction of new skills and personalities. The organisation must maintain team and goal cohesiveness and remain focused on moving forward, not at the same pace but with greater efficiency, greater capability and rapid growth. To do this you need to increase effective integration rates and decrease staff fall-out and turnover. The loss of experience from an organisation is taking the life blood out of it, in the form of loyalty, commitment and hard-won knowledge. Thus compelling them to make the same mistakes over and over again and sustain losses repeatedly.


Finance Officers placated

By supporting the management from within, the stakeholders’ expected benefits, established goals and ROI can be truly realised and even exceeded with the correct level of coaching and mentoring, targeted at the right people, time and place.


Operational success

Left to their own devices a new candidate and the installed team will take up to 3 months to fully integrate and become truly effective to the organisation. The first 6 weeks will find the candidate isolated and floundering to find knowledge and develop new skills on his own initiative whilst the installed team circle around them, sizing and testing this new guy. No organisation can afford to wait that long for a return, especially if it is ‘disappointing’. If you are left wondering why the increase in numbers does not relate to a direct increase in revenue, we have the answers for you. We will be happy to support you. Contact me on kenwbudd@lycos.co.uk


Team integration issues - example

As a new start, it is at this time the candidate will bond with, or be be-friended by, one or some of the team but not all. This may not be with the positive thinking, forward thinking group that you would want them to join. In fact it is more likely to be with other members of the team that have become isolated and withdrawn.

If this trend continues then the team dynamics will start to move in the wrong direction, because every new candidate will be drawn to, recruited by or be-friended by, the ‘outsiders’. The team will start to experience a new division instead of an integration. A divided team is very un-focused, difficult to re-unite and the devil to manage effectively.


Cause and effect

Circumstances like this lead to overloading or repeated distraction of the next level of management, keeping them away from their core activities. Instead they find themselves increasingly involved in ‘territorial’ disputes and trivial ‘personality’ clashes. The intended growth of the organisation is diverted or worse, stalled and, because of the push on recruiting and taking on of new staff, suddenly you now have greater overheads.Unless rectified the company is heading for a self-destructive downward spiral.

Your operational managers are faced with issues that began a long time back and have now become established and possibly cultural. In the words of the Irish philosophers ‘If you were trying to get to Dublin city quickly, I would not have started from here!’