Friday, March 5, 2010

5 Tips for Giving a Great Presentation

In my role at Solstice Consulting, I do a lot of presenting on topics that interest me, case studies on project successes, and Solstice's domains of expertise. While my audience has ranged in size and background and the content is different each time, I have found a few prensentation techniques that seem to apply to all situations.

  1. Be confident no matter how unprepared you feel. Projecting confidence is a sure fire way to build credibility with your audience and help ease your nerves.
  2. Dress smart and confident. What you wear impacts how you feel about yourself. Splurge on that smart suit or stylish shirt.
  3. Be interesting and engaging. Pull people into your world with stories, anecdotes, and humor. The more they laugh, the more they'll like you, and the more they will remember you.
  4. Read the room and get a pulse on the audience. When you feel things are going south and people loosing interest, start asking them questions to keep them engaged. Get them talking and learning from each other. Your audience will appreciate your facilitating knowledge sharing. And they might have the content or answers that you don't.
  5. Keep the slides light on text. The more text the more tempted you are to read directly from the slide. Use key phrases and words. This helps keep the presentation conversational when you use your own words and stories to deliver the content.

As always, I'd love to hear your thoughts. What are some techniques that work for you?

Tuesday, March 2, 2010

The Information Security Profession: Today and Beyond

The information security profession is changing. I've been asked to present my perspective at NetSecure on how the profession is changing and what's driving the change. If you can't make it to the event, here is a sneak preview of my presentation.

Monday, February 1, 2010

Shedding Light on the Information Security Landscape: An Interview with Sandra Toms LaPedis, Area Vice President and General Manager, RSA Conference

The Information Security landscape is changing. In the face of dealing with more sophisticated threats, these recessionary times are driving innovation like never before. Sandra Toms LaPedis, Area Vice President and General Manager, RSA Conference , sheds light on information security challenges, technology trends driving the CSO agenda, and how today’s environment is creating opportunities.

1. What are the top organizational challenges facing security professionals today?
The number one challenge is that IT departments are currently working with fewer resources. While Gartner research shows that IT budgets will be up in 2010 by 3.3 percent, the industry will still be playing catch-up with 2009’s 5.2 percent decrease. And according to the U.S. Bureau of Labor Statistics, 9.4 percent of the population is currently without a job – with California being hit particularly hard at a rising 12.4 percent. Unfortunately, many security practitioners are in these ranks.

With these limited resources and the loss of talented security professionals in IT departments across the country, no one is minding the proverbial store. Many organizations are left with stripped-down departments that have fewer people watching for threats. We know more issues can occur during these times of economic hardship, so having more eyes on the security posture of an organization is more important than ever before.

2. What are the top three technology concerns for organizations?

Based on the abstracts that were submitted and the agenda we have set for RSA Conference 2010, we see that three particular areas of concern are cloud security, security in the face of consumerization and mobility and cyber warfare.

3. How is today's business environment impacting how security challenges are addressed?

In July 2009, we surveyed nearly 150 C-level executives and professionals charged with directing, managing and engineering security infrastructures within their respective organizations to find out their pain points for the coming 12 months. Fifty-seven percent of respondents cited budgetary constraints as their biggest concern. This means organizations have to get creative with the way they protect their infrastructure since they have fewer dollars to spend. This may include finding new tools that address multiple issues, learning how to make what they currently have adapt to changes in the landscape or architecting new solutions.

4. How has the current environment created opportunities for security-focused service providers? Is today's environment driving innovation?

Recessionary periods drive the most innovation. Especially today, when entrepreneurs and developers have so much technology to get them started, industrious individuals are required to be more creative and resourceful. You can simply look at events like TechCrunch50 and DEMO to see that technology professionals are capitalizing on missed opportunities by debuting truly innovative products and solutions.

The information security industry is no exception. Codes are becoming more malicious, botnets are getting smarter and attacks on corporations and nation states have become more frequent – such an environment is ripe for information security innovation. At our Innovation Sandbox program we showcase and honor companies and individuals that are at the cutting edge of security innovation and have the most promise for offering a solution to the information security industry’s most pressing issues. On February 8 we will select 10 finalists from a pool of 40+ submissions to compete for the title, “Most Innovative Company at RSA Conference 2010.” With this program we plan to highlight the entrepreneurial spirit of the security industry while also giving early stage companies a venue to be seen by their peers.

5. What have you seen in terms of innovation in security?

In the last year we’ve seen new companies address the security concerns associated with the proliferation of cloud computing and virtualization in IT architectures, as well as significant advances in the way organizations can secure their employees’ mobile devices. The list goes on and on, but there is a need for so much more – which is why Innovation Sandbox is such an important program, and why information security professionals sharing best practices at RSA Conference becomes a business imperative.

This year we’ve had companies submit products that can emulate a phishing attack on an employee to provide education on how to identify risks via email, solutions that address the security risks associated with password resets and products that have turned authentication as we know it on its head by integrating image recognition to the fold.

Sandra Toms LaPedis, Area Vice President and General Manager of RSA Conferences, joined the company in 1998 and is responsible for the global promotion and successful execution for the Conference. This includes content, strategy, logistics, industry relations, brand extensions and partnerships.

Monday, January 25, 2010

4 Point Plan for Testing Mobile Websites

When building a website targeted for mobile platforms, having a good testing strategy is one of the keys to ensuring end-user satisfaction. The mobile context is different than desktop. With so many different devices with varying capabilities it can be challenging to develop functionality that works well on all. Here's a 4 point strategy to use when determining how to test your mobile website:

1. Define testing scope
There are many variables at hand when considering the mobile context - device capabilities, operating system, propietary browsers, carrier network performance - it's difficult to test every aspect thoroughly. Mobile testing is about focusing your efforts. Hone in on your intended audience, do your homework on devices the majority of your end-user base will be using. Build a testing plan around your target audience's device hardware, operating system, browser, and network. Utilize alternatives to native device testing to cover other user populations (i.e. mobile test emulators, see below).

2. Test functionality first on a desktop
Get the functionality working first then focus on cross device, cross operating system compatibility. Dealing with all the possible issues at once - basic functionality, OS and browser specific graphic design issues - can be time consuming. Keeping your testing focused on functionality first then look and feel and navigation will avoid wasted energy.

3. Utilize mobile emulators

Once the functionality works as expected, test the user experience on emulators. Emulators exist to test specific operating systems, browsers, and devices. If you aren't familiar, emulators run on your desktop and emulate the mobile OS and mobile browser environment. Here are a few of the most popular:

It's not always a slam dunk installing these so be sure to allocate time for installing all required components and configuration.

The W3C also has a great resource for validating the mobile friendliness of a website. As mentioned in my previous blog - 3 C's in Moble Website Design - The World Wide Web Consortium (W3C) is founded on the principles that the web should be accessible to all and on as many devices as possible. To realize this, the W3C body of knowledge has developed technical standards and best practices for the development, design, and content authoring. Simply enter your website URL into the W3C MobileOK checker and the checker validates your site against the mobile best practices as defined by the W3C.

4. Test on native devices
Finally, execute testing on the native devices, operating systems, and browsers outlined in your testing plan. At this point all functionality issues should be worked out and your testing is focused on user experience and useability on specific devices.

The basic principles of desktop application testing apply to the mobile web context as well. A good plan and focused execution will help reduce post-production issues and eliviate end-user frustration.

What are you doing to test your mobile websites? Comments and discussion welcome!

Friday, December 11, 2009

The 3 'C's in Mobile Website Design

One of the key movements in ensuring a consistent, meaningful, and overall enjoyable mobile website user experience is subscribing to the principles developed by the W3C - The World Wide Web Consortium - for mobile application development. The W3C is founded on the principles that the web should be accessible to all and on as many devices as possible. To realize this, the W3C body of knowledge has developed technical standards and best practices for the development, design, and content authoring. These standards are in the spirit of creating a "One Web" environment that is available on any device.

Creating mobile-friendly user experience can be challenging . The hardware and network capabilities of the end-user create constraints that should be considered when creating mobile content. The "One Web" principle attempts to level the playing field for all. Remember the 3 "C"s for mobile web development:

  • Content - the page layout and information architecture
  • Context - the reason a visitor is coming to the mobile site and their environment at the time of visit
  • Capabilities - the functionality native to the device for viewing the mobile website
Here are a few best practices to consider before building your next mobile website:

The type of content relevant to the desktop user may not be as applicable to the user on-the-go. Visitors on a mobile device aren't interested in browsing. Forget the notion of the "web browser" and think "web finder". Page layout, information architecture, and content syntax are the pillars of keeping a mobile website relevant and accessible for the mobile user.

Minimal navigation (preferably a top nav bar) is a best practice, so is keeping content as accessible with as few clicks as possible. Don't bury content too deep in the site. Keeping in mind that the mobile visitor has a very specific goal (i.e. an address, account information,traffic reports) put that content up front and make it easy to navigate. Less really is more when navigating a mobile website.

What is the mobile site visitor's goal? Understanding who the visitor is, why they are coming to the site, and the context in which they are arriving at the site is critical. Even the best mobile user experience fails if the content and context aren't spot on. For example, a bank cusomter accessing their bank account from a mobile device are probably not interested in learning about new product offerings. But rather, quickly locating a balance, performing a funds transfer, or paying a bill on-line. Keeping the content layout goal oriented and specific to the goals of a mobile user will create a useful web property for your customers.

Keep the site entry point URIs (Universal Resource Identifier) short. Typing a long string can be cumbersome on a mobile device. And it's important to consider that entry points may be from an email or text received on the mobile device.

Device capabilities are a huge consideration in mobile web development. While the W3C guidelines are based on device-neutral practices they also recognize the importance of checking for device capabilities (whenever possible) and fully exploiting them to enhance the end-user experience. Just as in the desktop world where all sites don't function the same in all browsers, the device a mobile site is accessed on can have a huge impact on the quality of the end-user experience if not handled programmatically. A few things to consider:

  • Not all devices support style sheets. Organize content so that it can be rendered in a an easy to navigate way without style sheets

  • Graphics and scripting capabilities- create text based alternatives for all embedded images and plug-ins

  • Color contrasting capabilities- information should be able to be conveyed with or without color.

  • Bandwidth is another consideration. The more graphically rich and content intense the longer it may take to render the site (and quite possibly,the more it will cost the end-user).

Limit user input requirements as input mechanisms on mobile devices can be small and cumbersome to use. Tabbing and creating pre-selected values are best. Where possible avoid free-text fields.

I've been in web development for most of my career and though the mobile outlet creates new challenges and opportunities, the basic planning and due dilligence required to make a site successful are the same no matter the outlet. Would love to hear about the challenges you've overcome launching your mobile website. Please add your comments below.

Thursday, December 3, 2009

Security sells: leverage your security program to boost sales

In today's competitive environment, with the increasing need to show a unique value proposition, a stellar information security program can offer a company a unique differentiator to discuss with their prospective customers. The information security function (along with IT) is typically viewed as a cost center, not a revenue generating arm of the organization. Security tactics are often viewed as a must-do line item to check off the list, not as a competitive advantage. Well, I'd like to change that mindset.

As an information security professional, it can be frustrating when achievements aren't recognized outside of the immediate team (let alone external to the organization). The problem isn't that security achievements are less important than other project achievements. On the contrary, security projects are often mission critical to helping companies avoid negative press, million dollar fines, and the loss of customers. The problem centers around lack of understanding of the value of security initiatives, and how they tie to servicing customers or generating company revenue.

Here are some thoughts on how information security professionals can shine a light on achievements, and position their work as differentiators a company can use to use to generate more revenue.

Sell Your Strengths: Think about what your company's security strength is and sell it. I'm not talking about giving away the keys to the farm and talking about HOW you are doing things. That would defeat the purpose of having security controls in place. But the basic standard of keeping the bad people out and enabling the authorized users to securely do business has many interesting facets, and there are many ways to achieve this level of security.

I like to call this the art of information security: What your company is doing + How they are doing it = The differentiator

Is it a sophisticated physical security turnstile badging system leveraging the latest technology to reduce manual intervention? Is it enabling your company's regulatory compliance through cutting edge processes and technology? Whether you are in the business of securing bank account information, human resources files, medical records, or customer credit card information, talk about what you are doing that makes your information security program a key to reducing operational waste and gives employees the time to focus on meeting customer expectations.

Case-in-point, one of my clients, a Fortune 500 bank for high net worth individuals and corporations, has a world class access control program in place. Their information security group designed a set of identity management (IdM) processes based on securely enabling business functions. To gain operational efficiencies in system access request and set up, they customized a leading IdM technology and automated much of their IdM workflows.

Why is this important to a bank customer? The SVP of Information Security can tell you why. He can articulate the value that this brings to a bank customer in terms that are meaningful to a customer -- speed of access to critical account reporting applications AND the reassurance that only those authorized are seeing the account information. He's called on by relationship managers to help sell the value of doing business with this bank and communicate the edge this institution has over another. The SVP has the soft skills necessary to navigate a conversation with clients and prospects. And the instinct to know what aspects of the information security program matter most to each client. These soft skills are really the differentiator for his company's information security organization. It's not just about what a security organization is doing but also about how they tie it back to meeting customer expectations.

Develop Soft Skills: Let's face it, information security is technical, and as a result the people that are really passionate about security tend to be very technical. But when that passion comes out in a way that's easy to understand and meaningful to those on the receiving end, you've got a value proposition worth telling would-be customers. The challenge is developing the soft skills necessary to communicate that value proposition. As an information security manager, it's just as important to develop the communication and soft skills in your staff as it is to keep them technically trained and abreast of the emerging threats. These soft skills also come in handy when communicating to executives the funding required to execute your security program goals and why they are important.

I recently had the pleasure of hearing Sara Santerelli, Chief Network Security Officer at Verizon, speak at a conference in October. Sara spoke about the duty that information security managers have to articulate a security program less in terms of tactics and more in terms of long term strategy. This helps executive management understand the drivers, which in turn gains their support and the funding necessary to execute. She also hit on the importance of alignment of your security plan with business goals and defining the trade-off between the cost associated with your security initiatives and the risk of not doing them. All of this articulation requires soft skills and big picture thinking.

Information security is a compelling value proposition if communicated in meaningful terms to prospective customers. In some situations, the CSO can be viewed as an extended arm of the sales team. Whether the title is CSO or VP of Information Security, the people within an information security organization can really help sell the benefits of doing business with the company. In a climate where standing out in the crowd matters, companies should look to their CSO for the extra push needed to turn a prospect into a customer.

How does your information security program help differentiate your company? Comments welcome!

Monday, November 30, 2009

How Information Security Can Help You Sell More Business

As an IT professional, have you ever thought of the Chief Security Officer function as an extended arm of the sales organization? Maybe you should. Whatever the title - CSO, VP of Information Security - these guys and gals can really help sell the benefits of doing business with your company. The number one value prop they can tell your existing clients and prospects - Here's why your sensitive information is safer with us than the competition. These guys can explain why. In today's competitive environment, with the increasing need to show differentiation and a unique value proposition, information security seems like a no-brainer to talk about. Here are a few tips for developing your Information Security Organization into a key differentiator for your company.

Sell Your Strengths: Think about your company's Security strength and sell it. Now, I'm not talking about giving away the keys the farm and talking about HOW you are doing things. That would defeat the purpose of having security controls in place. But the basic standard of keeping the bad people out and enabling the authorized people to securely do business has many interesting facets and there are many ways to achieve security. I like to call this the "art of information security" - What your company is doing + how they are doing it = differentiator. Is it a sophisticated physical security turnstile badging system leveraging the latest technology to reduce manual intervention? Is it enabling your company's regulatory compliance through cutting edge processes and technology? Whether you are in the business of securing bank account information, human resources files, medical records, or customer credit card information you can talk about what you are doing and how you are doing it that makes your Information Security Program a key in your company's ability to meet customer expectations.

Case-in-point, one of my clients, a Fortune 500 bank for high net worth individuals and corporations, has a world class Access Control program in place. Their Information Security group designed a set of Identity Management processes based on securely enabling business functions. To gain operational efficiencies in system access request and set up, they customized a leading IdM technology and automated much of their IdM workflows. Why is this important to a bank customer? The SVP of Information Security can tell you why. He can articulate the value that this brings to a bank customer in terms that are meaningful to a customer - Speed of access to critical account reporting applications AND the reassurance that only those authorized are seeing the account information. He's called on by relationship managers to help sell the value of doing business with this bank and communicate the edge this institution has over another. The SVP has the soft skills necessary to navigate a conversation with clients and prospects. And the instinct to know what aspects of the Information Security Program matter most to each client. These soft skills are really the differentiator for his company's Information Security organization. It's not just about what a security organization is doing but also about how they tie it back to meeting customer expectations.

Develop Your People: Let's face it, Information Security is technical. The people that are really passionate about security tend to be very technical. But when that passion comes out in a way that's easy to understand and meaningful to those on the receiving end you've got a value proposition worth telling would-be customers. The challenge is developing the soft skills necessary to communicate that value proposition. As an information security manager it's just as important to develop the communication and soft skills in your staff as it is to keep them technically trained and abreast of the emerging threats. These soft skills also come in handy when communicating to executives the funding required to execute your Security program goals and why they are important. I recently had the pleasure of hearing Sara Santerelli, Chief Network Security Officer at Verizon, speak at a conference in October. Sara spoke about the duty that information security managers have to articulate a security program less in terms of tactics and more in terms of long term strategy. This helps executive management understand the drivers, gains their support, and the funding necessary to execute. She also hit on the importance of alignment of your security plan with business goals and defining the trade-off between the cost associated with your security initiatives and the risk of not doing them. All of this articulation requires soft skills and big picture thinking.

Information Security is a compelling value proposition if communicated in meaningful terms to your customers. I would love to know how you are talking about your Information Security program and how it helps differentiate you. Comments welcome!