Showing posts with label #CIO. Show all posts
Showing posts with label #CIO. Show all posts

Thursday, 13 September 2018

Cyber Trends 2018

James McDowell and Camble Murray gave an interesting talk, at the Blackberry Security Conference, on recent trends in cyber security and what we can learn from the last 12 months.

Probably the most quotable aspect was how easy it is to social engineer an attack if the attacker targets people in Sales roles. Apparently, sales people are so eager to make a sale that "they will open anything" on an email attachment. They also claimed, that if the attacker uses "appropriate HR language", then it is quite easy to persuade an HR user to do so too. So there are some communities to focus on with communications and cyber awareness training. It also appears that some security professionals are starting to adopt psychological techniques such as NLP to re-inforce their approaches to building security cultures.

It seems that Ransom Ware and Email targeting for spear fish attacks remain the 2 most prevalent threats, mainly because of the economics of cost and return from such types of attack; generally perpetrators reckon to pick up quite significant returns for relatively modest outlays, given the general availability of many cheap attack kits and the ability to sustain high volumes of attacks, almost guaranteeing that some will succeed.

It also appears that attackers are increasingly using Facebook and other social media platforms to identify individuals who are susceptible to "clicking on things" and profile them for future attacks. So perhaps this is the time to educate people about separating their social media personnae from their work ones, making it much less easy to cross link them.

Th other notable point was the significant number of crypto currency exchanges and wallets which had been targeted for attack. There is something about saying that something is secure that invites the wrong type of attention.

The other big trend is the emergence of the term Cyber Resilience, which is really about how capable a business is in dealing with major security incidents and continuing to operate when under cyber attack. So whilst there is a strong need to deal with security basics systematically, there is also the need to design in security at both an environmental and a project level, when implementing new stuff, there is also the need to have a well oiled and rehearsed approach to managing the response to an attack. 

Saturday, 8 September 2018

Agile CIOs

The ever changing role of the CIO is often subject to much debate. Opnionons vary from the challenge of "why do we need a CIO?" to "CIOs should be driving our innovation and vision".

 A recent article by McKinsey - How to Become an Agile CIO - is a typical example. The authors,  Santiago Comella-Dorda, Quentin Jadoul and Swati Lohiya, set out 3 main aspects of An Agile CIO's role:


  • Architect / Technology Visionary

  • Driver of Knowledge and Talent

  • Problem Solver

Whilst they are obviously part of the role, I think that they do miss the point in a number of areas. The first is that the CIO should be taking the llead in helping build a positive business culture which avoids blame, encourages collaboration and focusses risk appetite around continuous innovation. This requires a good focus on the soft aspects of Employee Engagement, as well as some on providing supporting tools.

The second is on uniting the Senior Management Team and their teams in building common understanding of each other's problems and shared opportunities, as the basic pre-requisite for developing an Integrated Product Team approach, in which each IPT addresses the requirements, design and enhancement of End-to-End product processes (whether there are internal or customer facing products).

The third issue is being the corporate consience on balanced performance and investment; Businesses which operate as teams tend to be the best at developing and exploiting digital business models and sustaining a Digital As Usual ethos. This does require balanced investment and commitment of resources so that the orgnisation can not only address new business opportunities, but also improve exisiting products, maintain capability and protect itself (and its customers).

Friday, 1 June 2018

The Chief Data Officer

Many organisations are experimenting with the concept of a Chief Data Officer. Although according to Raconteur most are struggling with the concept as well as making headway with the concept of managing data for value.

It seems that there are a number of problems:
  • Business Understanding of the Role and Data Issues;
  • Resourcing, Funding and Provisioning Data Initiatives;
  • Current Starting Points for many Businesses with Poor Data Quality;
  • Focusing too much on compliance and not enough on Value.
Personally, I would suggest that there is a value staircase for Data Management starting with Compliance and Protection on the Bottom Rung and then progressing through Quality, Integration, Sourcing (external data feeds), Insight & Intelligence to Adaptive Control (involving use of machine learning, experimentation and up to the minute data feeds to optimise control).

It is difficult howver to obtain value if a business tries to progressively work its way upwards through this staircase if it attempts to do everything in the first one before attempting the next step. The scope is too wide. Instead busnesses need to prioritise a business problem or opportunity and address a vertical slice down this value staircase to deliver value quickly. Progression can be achieved by addressing the next opportunities and reviewing what is needed in each step to improve overall capability as each increment is implemented.

However, probably the biggest issue is the role. What is the difference between a CIO, a Chief Digital Officer, a CTO, a CSO, a Principal Data Archiect and a Chief Data Officer? These all overlap and are often confused in scope. Many businesses are handing the Chief Digital Officer role back to the CIO, so it may be time to do the same with the Chief Digital Officer, because if they are separated the CIO's role is hollowed out to just look at the plumbing and not the value to the business.

It is also important to delegate data quality and integrity to business managers responsible for exploiting data in their day-to-day operations. IT may provide the policy framework, tools and measurement framework for managing data quality, but line management needs to take responsibility and include data quality in their personal objectives, just like they do with budgets. Otherwise value will never be achieved.



Thursday, 12 April 2018

The Business of IT

I have re-released a book I wrote several years ago, on amazon "The Business of IT". It's a simple primer for the first time IT executive. Its premise is that you need to treat IT as a business within a business and manage for value. It covers most of the main concepts that a new time leader needs to be aware of and points out to many areas of established industry practice.

Thursday, 1 February 2018

Asia's Digital Dragons

Asia's Digital Appetite

According to experts in McKinsey, Asia is grabbing the opportunities available from digital to try and leapfrog traditional economic leaders in the west and compensate for historic lack of investment in infrastructure. They single out India, Indonesia and China as the countries with the most energetic approaches and the most innovation. They cite greater appetite for social media take up and openess to mobile and other new technologies as drivers to greater innovation.

This position is supported by Gartner's identification of Asia's 10 leading digital disruptors:

  • Tencent
  • AliBaba
  • Baidu
  • Ant Financial
  • JD.com
  • DiDi
  • Xiaomi
  • Yahoo Japan
  • Naver
  • Lufax

The interesting fact about this list is that it is dominated by Consumer oriented businesses. B2B opportunities are yet to be exploited. Even so, the power house that is AliBaba is reputed to dwarf western giants such as Amazon. So Asia is currently playing to its numbers and culture to establish scale.

Garnter recommends that western enterprises operating in Asia should consider adopting local platforms to guarantee penetration and better customer experience in Asian Markets.

Future Digital Directions in Asia

A recent survey of global CIOs by Logicalis showed that CIOs in the Asia Pacific area have been disappointed by slow progress overall in adopting digital business models. Like CIOs in other parts of the world they have seen typical barriers such as Organisational Culture, Scale of Investment, Legacy Infrastructure, Skills and Security holding them back.

However, overall they are typically planning to address them with moves to simplify and modernise infrastructure, work closely with other business colleagues to address specific opportunities, improve training, invest in culture change and generally increase security investments.

In doing so, they are preparing to lead change and more B2B services are likely to emerge, balancing Asia's digital economy.

Wednesday, 1 June 2016

Should The CFO report to The CIO?

Is it Time that the CFO Reported to the CIO?


Attending an industry event the other week, I was struck by the comment that "CIOs were moving out from under the shadow of the CFO". The event was presenting the results of a recent global CIO opinion survey conducted by Harvey Nash and KPMG. Other questions had focused on who is responsible for Digital Strategy and it appears that Marketing is now giving this role up and starting to hand it back to the CIO.
Any reader who has worked in the finance industry will have long ago understood that "Money is Information", reversing the old adage that information is money. Basically, since almost all currencies moved off the gold standard, money has become nothing more than a promise or just life's brownie points. Its value only exists, because we chose to assign it value as it has no intrinsic value of its own. These days it consists of little more than data stored on some medium or being transmitted from point-to-point in transactions.
If this were the only issue then the CIO's claim might be considered a little tentative. However, in the modern digital economy, many industry pundits are quoting the statistic that "80% of an enterprise's value lies within its IPR". This IPR normally being stored and managed in the form of information (or sometimes knowledge embedded within IT systems and IT enabled processes). Given that digital businesses now appear to be outstripping traditional models in terms of growth, profitability and survival, it is a good time to review the relationship in many enterprises between CIOs and CFOs, and many are beginning to question it.
Personally, I am not sure that either should report to the other. CIOs should be there to help grow and sustain enterprise value. CFOs have traditionally been there to husband and protect money, ensuring sensible separation of duties. My experience has been that CFOs tend to come in 2 types: those who control (and tend not to be that imaginative about how to grow a business) and those who are entrepreneurial (and tend to be a bit too lax about controlling money). The former type is a bad fit for IT, the latter may be a good fit for IT, but can be bad for the overall financial health of the business. 
I do think however, that there are things that CIOs can learn from CFOs, in terms of the way in which budgetary control is shared within a business, but with the CFO providing the governance framework and control. CIOs should be doing something similar with information governance, so that information quality is managed appropriately.
CIOs can give back too. Increasingly CFOs are expected to provide Management Information services based on management accounting and BI. there's a lot which CIOs can advise on there with respect to techniques for fast delivery and ensuring that information integrity is maintained.
Its time for genuine partnership to help grow the business.