Showing posts with label chief digital officer. Show all posts
Showing posts with label chief digital officer. Show all posts

Thursday, 13 September 2018

Cyber Trends 2018

James McDowell and Camble Murray gave an interesting talk, at the Blackberry Security Conference, on recent trends in cyber security and what we can learn from the last 12 months.

Probably the most quotable aspect was how easy it is to social engineer an attack if the attacker targets people in Sales roles. Apparently, sales people are so eager to make a sale that "they will open anything" on an email attachment. They also claimed, that if the attacker uses "appropriate HR language", then it is quite easy to persuade an HR user to do so too. So there are some communities to focus on with communications and cyber awareness training. It also appears that some security professionals are starting to adopt psychological techniques such as NLP to re-inforce their approaches to building security cultures.

It seems that Ransom Ware and Email targeting for spear fish attacks remain the 2 most prevalent threats, mainly because of the economics of cost and return from such types of attack; generally perpetrators reckon to pick up quite significant returns for relatively modest outlays, given the general availability of many cheap attack kits and the ability to sustain high volumes of attacks, almost guaranteeing that some will succeed.

It also appears that attackers are increasingly using Facebook and other social media platforms to identify individuals who are susceptible to "clicking on things" and profile them for future attacks. So perhaps this is the time to educate people about separating their social media personnae from their work ones, making it much less easy to cross link them.

Th other notable point was the significant number of crypto currency exchanges and wallets which had been targeted for attack. There is something about saying that something is secure that invites the wrong type of attention.

The other big trend is the emergence of the term Cyber Resilience, which is really about how capable a business is in dealing with major security incidents and continuing to operate when under cyber attack. So whilst there is a strong need to deal with security basics systematically, there is also the need to design in security at both an environmental and a project level, when implementing new stuff, there is also the need to have a well oiled and rehearsed approach to managing the response to an attack. 

Friday, 1 June 2018

The Chief Data Officer

Many organisations are experimenting with the concept of a Chief Data Officer. Although according to Raconteur most are struggling with the concept as well as making headway with the concept of managing data for value.

It seems that there are a number of problems:
  • Business Understanding of the Role and Data Issues;
  • Resourcing, Funding and Provisioning Data Initiatives;
  • Current Starting Points for many Businesses with Poor Data Quality;
  • Focusing too much on compliance and not enough on Value.
Personally, I would suggest that there is a value staircase for Data Management starting with Compliance and Protection on the Bottom Rung and then progressing through Quality, Integration, Sourcing (external data feeds), Insight & Intelligence to Adaptive Control (involving use of machine learning, experimentation and up to the minute data feeds to optimise control).

It is difficult howver to obtain value if a business tries to progressively work its way upwards through this staircase if it attempts to do everything in the first one before attempting the next step. The scope is too wide. Instead busnesses need to prioritise a business problem or opportunity and address a vertical slice down this value staircase to deliver value quickly. Progression can be achieved by addressing the next opportunities and reviewing what is needed in each step to improve overall capability as each increment is implemented.

However, probably the biggest issue is the role. What is the difference between a CIO, a Chief Digital Officer, a CTO, a CSO, a Principal Data Archiect and a Chief Data Officer? These all overlap and are often confused in scope. Many businesses are handing the Chief Digital Officer role back to the CIO, so it may be time to do the same with the Chief Digital Officer, because if they are separated the CIO's role is hollowed out to just look at the plumbing and not the value to the business.

It is also important to delegate data quality and integrity to business managers responsible for exploiting data in their day-to-day operations. IT may provide the policy framework, tools and measurement framework for managing data quality, but line management needs to take responsibility and include data quality in their personal objectives, just like they do with budgets. Otherwise value will never be achieved.