Sunday, October 30, 2011

‘Lean startups’ can happen anywhere

Lean Startups and the entrepreneurial energy that fuel them, aren’t just limited to lone visionaries in garages or spare bedrooms.

In today’s hyper-competitive global economy, large organisations need to have startups under their roofs to survive and thrive.

A couple of decades back, some visionaries were floating the idea of “intrapreneurs,” motivated innovators within organisations that pull together ideas and resources to make new things happen.

In his latest book, Eric Ries, creator of the Lean Startup methodology, builds upon this idea, and outlines the 5 key principles that should make up the foundation of any lean startup effort and, tellingly, the key takeaway is that startups can happen anywhere, at anytime:

1. Entrepreneurs are everywhere. Ries argues that startups are everywhere, which he defines as an “institution designed to create new products and services under conditions of extreme uncertainty.” Groups of people working within Fortune 500 corporations or large government agencies, could meet the definition of a “startup.”

2. Entrepreneurship is management. Ries argues that “entrepreneur” should be a job title in all companies, regardless of ages and sizes.

3. Validated learning. The main purpose of a startup is to learn about customer needs. Run frequent experiments to see what ideas stick, and more importantly, which do not.

4. Build-measure-learn. A successful startup needs to operate within a continuous feedback loop. This loop consists of turning ideas into products, measure how customers respond, and “learn whether to pivot or persevere.”

5. Innovation accounting. Startup leaders still need to focus on the “boring stuff.” : measurement, milestones, and prioritisation of work. “This requires a new type of accounting for startups, and the people who hold them accountable.”

While startups may seem chaotic and more driven by passion than management, sensible and accountable management is still needed but the bottom line is that it can and will happen anywhere and everywhere.

Saturday, October 29, 2011

5 questions to improve your results!

Here are 5 great questions to help your business thrive in any economy:

  1. How many leads am I generating each day from my website / blog? Our sites should be a constant source of highly targeted sales leads. If your site is not currently generating as many leads as you can handle, you need to fix that immediately. I’m constantly amazed how many business owners pester people for leads at networking events, when their website or blog could be generating high quality leads for them every day.
  2. How easy would it be, for someone to write a manual, which explained how to do my job? Whilst every human being is of equal value, those in business with the highest commercial value do work that matters, which can’t be neatly explained in a manual.
  3. What am I doing, to ensure that the next 12 months will be better than the last 12 months? If business hasn’t been good over the past year, we need to change our direction. It’s way too easy to mistake movement for progress and end up working hard, doing the wrong things. If hard work alone were the secret to success, our grandparents would have been millionaires.
  4. If my business was perfect in every way, what would it look like? Write your answer down in as much detail as possible. Include everything, from; the type of projects you would be working on, your profit figure and the length of your working day, to the number of hours you would work each week and the location of your business. The clearer a picture you can build of your ideal business, the easier it becomes to direct your current business into that image.
  5. If my business were to stop trading on Monday, how easy would it be for my clients or customers to replace me? This is similar to question 2, but is focused on the unique value of your business. The easier it is for people to replace us as providers, the more volatile our client list will be and the harder we will find it to attract new clients.

Thursday, October 27, 2011

Institute of Risk Management issues new guidance on risk appetite

The Institute of Risk Management (IRM) has published new guidance on the subject of risk appetite and tolerance aimed at helping organizations better understand the risks they take when pursuing their strategic objectives.

IRM's guidance document has been endorsed by the Chartered Institute of Internal Auditors, the Chartered Institute of Management Accountants, the Institute of Chartered Secretaries and Administrators, The Chartered Institute of Public Finance and Accountancy and Alarm, the public risk management association.

IRM Deputy Chairman Richard Anderson, the main author of the report, explained: "Risk appetite today is a core consideration in any enterprise risk management approach for organizations of all types, yet there is little widespread understanding about what it means and how it can be applied. In the light of the explicit requirement in the UK Corporate Governance Code for boards to understand the nature and the extent of the risks that they face, IRM decided to take the lead on drawing together some practical guidance on the subject, aimed at board members as well as risk professionals.

We are particularly pleased that other respected professional bodies are supporting our work - risk is everyone’s business and a common understanding and approach helps us work together to address this challenging area."

Anderson continued, "Our underpinning precept is that organizations can only progress by taking those risks that they need to embrace and managing down those that they wish to avoid.

Our recommended approach to risk appetite, based on the wide experience of our members and also benefitting from an extensive consultation exercise earlier this year, is intellectually rigorous as well as highly practical.

We think we have managed to outline a process which should be proportionate to an organization's risk management maturity, capability and culture and, most importantly, supported by appropriate data.

Nevertheless, we do not think that this is the last word on the subject in such a fast-moving environment and we are extremely interested in receiving feedback on this work."

The IRM paper Risk Appetite and Tolerance is available for free download at http://www.theirm.org/publications/risk_appetite.html

Managing cloud risks

Adopting cloud computing may save money, but how does it change risk? The cloud allows the procurement of IT services from both internal and external suppliers to be optimized because the services are delivered through the Internet in a standard way.

The cloud is not a single model, but covers a wide spectrum from applications shared between multiple tenants to virtual servers used by one customer and hosted internally.

The key benefit of a cloud approach is one of scale; the cloud provider can potentially offer a better service at a lower cost because the scale of their operation means they can afford the skilled people and state-of-the-art technology necessary to deliver a secure service.

In general, a large cloud provider is likely to provide a better and more secure IT service at a lower cost than a small to medium sized enterprise could provide itself.

While the public cloud offers applications shared by multiple customers, the private cloud provides applications and infrastructure that are dedicated to a particular organization.

It allows organizations to outsource the management of their IT infrastructure while retaining tighter control over the location and management of the resources.

The price to pay for this is that the costs are likely to be higher than for a public cloud because there is less potential for economy of scale, and resilience may be lower because of the limit on service resources available.

The information security risks associated with cloud computing depend on both the service model and the delivery model adopted. The specific risks depend on the organization and their individual requirements.

The common security concerns across this spectrum are ensuring the confidentiality, integrity and availability of the services and data delivered through the cloud environment.

The approach to managing risks from the perspective of the cloud service user is one of due diligence - ensuring that the requirements are clearly understood, the risks are assessed, the right questions are asked and the appropriate controls are included in the service level agreements.

The principal information security related issues that organizations adopting cloud computing need to address are summarized below. Because of the wide spectrum covered by the cloud, their priority will depend on the cloud model adopted and the individual circumstances:

- Ease of purchase: anyone can buy access using a credit card. Your organization may already be using a cloud service without a proper assessment of the risk.

- Service contracts: those offered by cloud providers are often ‘take it or leave it’ and may contain less onerous obligations on the provider than a normal SLA. Key issues include: who owns the data, and how difficult would it be for you to get it back?

- Compliance: identify the business requirements for compliance with laws and regulations and ensure that the cloud provider is able to answer how they will meet these needs.

- Service location: identify the legal issues that relate to the jurisdiction of the geographic location of the cloud provider, the service and the data, and ensure that service contracts address these issues.

- Data security: identify and classify the business data that is involved and specify the security requirements for this data in terms of confidentiality, integrity and availability.

- Availability: identify the service availability requirements and assure that the provider is capable of meeting these.

- Identity and access management: specify the business needs for identity management and access control and assure that it will be delivered securely.

- Insider abuse of privilege: confirm that the cloud service provider has processes and technology to properly control privileged access.

- Internet threats: determine the level of protection needed against Internet-based threats and ensure they the steps to be taken both by the cloud provider and internally are adequate.

- Monitor: Within the cloud service, meet the business and legal requirements of the client while separating the data relating to different clients.

Taking a good governance approach, such as COBIT, is the key to safely embracing the cloud and the benefits that it provides. COBIT provides guidance to:

- Identify the business requirements for the cloud-based solution. This seems obvious but many organizations are using the cloud without knowing it.

- Determine if the functionality is currently provided by an existing internal service. If so what are the options?

- Determine the governance needs based on the business requirements. Some applications will be more business critical than others.

- Develop scenarios to understand the security threats and weaknesses. Use these to determine the risk response in terms of requirements for controls and questions to be answered. Risk IT: Based on COBIT provides an ideal framework for this.

- Understand what the accreditations and audit reports offered by the cloud provider mean and actually cover.

Cloud computing can reduce costs by providing alternative models for the procurement and delivery of IT services.

Many organizations have already adopted an outsourcing approach to internal functions that are not core and this approach naturally extends to IT.

However, they need to consider the risks involved in a move to the cloud and good governance provides a way for this.

For more information, visit www.isaca.org/cloud for a free ISACA white paper.

What makes a great risk manager?

Active Risk, conducted a major survey of risk professionals in mid-2011.

Phase One analysis, based on over 250 completed responses from around the globe, has shown some surprising results and provides important advice for organizations implementing enterprise risk management programmes.

As demands placed on risk professionals increase and evolve, this new research has given an insight into the types of individuals organizations need in their risk team to produce the best chance of meeting corporate and project risk objectives.

The research also provided an understanding to the training and development required to grow and retain risk professionals; strategies to improve the effectiveness of communications between risk managers and other departments such as sales, finance, contracts and projects and the actions necessary to reduce stresses on the risk team.

Risk professionals completed an online psychometric survey based on the well-established DISC profiling methodology and received a confidential personalized profile report in return.

The cumulative results were used to identify the main personality types active in the profession. Three groups emerged.

The largest percentage (60 percent) represented ‘Technicians’ with the characteristics for accuracy and logical action traditionally associated with risk managers.

More surprisingly over 30 percent of those who responded to the survey emerged as ‘Evangelists’ who are optimistic and inspiring leaders.

This new breed of risk manager could prove instrumental when imbedding a corporate risk culture.

Finally, just under 10 percent of risk professionals who took part in the survey were ‘Drivers’ with determined personalities more usually associated with sales professionals.

To participate in the confidential survey and to download the Phase One summary report, go to www.activerisk.com/risksurvey

NIST: New Guidlines for Conducting Risk Assessments

Risk assessment is the topic of the newest special publication from the National Institute of Standards and Technology (NIST).

Guide for Conducting Risk Assessments (NIST Special Publication 800-30, Revision 1), an extensive update to its original 2002 publication, is the authoritative source of comprehensive risk assessment guidance for federal information systems, and is open for public comments through November 4.

Overall guidance on risk management for information systems is now covered in Managing Information Security Risk: Organization, Mission, and Information System View (NIST SP 800-39), issued last March.

The updated SP 800-30 now focuses exclusively on risk assessments, one of the four steps in information risk management.

Information risk assessments help organizations:
  • Determine the most appropriate risk responses to ongoing cyber attacks or threats stemming from man-made or natural disasters;
  • Guide investment strategies and decisions for the most effective cyber defenses to help protect organizational operations (including missions, functions, image and reputation), organizational assets, individuals, other organizations and the US nation; and
  • Maintain ongoing situational awareness of the security state of an organization's information systems and the environments in which those systems operate.
The guidance in the revised publication has been significantly expanded to include more information on a variety of risk factors essential to determining information security risk, such as threat sources and events, vulnerabilities and predisposing conditions, impact, and likelihood of threat occurrence.

The publication describes a three-step process to help organizations prepare for risk assessments, successfully conduct risk assessments and keep assessment results up to date.

Guide for Conducting Risk Assessments also describes how to apply the risk assessment process at the three tiers of the risk management hierarchy outlined in Special Publication 800-39.

Sample templates, tables and assessment scales for common risk factors are provided for users to adapt to their own organizational risk assessments based on the purpose, scope, assumptions, and constraints of the assessments.

Guide for Conducting Risk Assessments (Special Publication 800-30, Revision 1) may be downloaded from here. Please send comments to sec-cert@nist.gov by Nov. 4.

Social engineering risks explored

Check Point has published the results of a new survey revealing that 42 percent of UK enterprises, and 48 percent internationally, have been victims of social engineering attacks, experiencing 25 or more such attacks in the past two years at a average cost of over £15,000 per incident.

The survey report, ‘The Risk of Social Engineering on Information Security’, shows the most common sources of social-engineering threats are phishing emails (47 percent) and social networking sites (39 percent).

The survey found that new employees (52 percent) and contractors (44 percent) were cited as the most susceptible to social engineering techniques, emphasising that hackers target staff that they suspect are the weakest security links in organisations, using social networking applications to gather personal and professional information on employees to mount spear phishing attacks.

According to the global survey of over 850 IT and security professionals, 86 percent of businesses recognise social engineering as a growing security concern.

A majority of respondents (51 percent) cited financial gain as the primary motivation of attacks, followed by competitive advantage and revenge.

The highest rate of attacks was reported by energy and utility organizations (61 percent) with non-profit organisations reported the lowest rate (24 percent), reinforcing gain as the key reason for attacks.

“Although the survey shows that nearly half of enterprises know they have experienced social engineering attacks, 41 percent said they were unsure whether they had been targeted or not.

Because these types of attacks are intended to stay below an organization’s security radar, the actual number of organisations that have been attacked could be much higher. Yet 44 percent of UK companies surveyed are not currently doing anything to educate their employees about the risks, which is higher than the global average,” said Terry Greer-King, UK managing director for Check Point.

Further findings from the survey report are:

  • The threat of social engineering is real – 86 percent of IT and security professionals (80 percent in the UK) are aware or highly aware of the risks associated with social engineering. Approximately 48 percent of enterprises globally (42 percent in the UK) surveyed admitted they have been victims of social engineering more than 25 times in the last two years.
  • Social engineering attacks are costly – Survey participants estimated each security incident costing anywhere between $25,000 and over $100,000, including costs associated with business disruptions, customer outlays, revenue loss and brand damage. 36 percent of UK respondents cited an average incident cost of over $25,000 (£15,000).
  • Lack of proactive training to prevent social engineering attacks – 34 percent of businesses do not have any employee training or security policies in place to prevent social engineering techniques (4 percent in the UK).
  • Financial Gains are the primary motivation of social engineering - Financial gain was cited as the most frequent reason for social engineered attacks, followed by access to proprietary information (46 percent), competitive advantage (40 percent) and revenge (14 percent).
While social engineering techniques rely on taking advantage of a person’s vulnerability, the prevalence of Web 2.0 and mobile computing has also made it easier to obtain information about individuals and has created new entry points to execute social engineering attacks.

Greer-King added: “An organization’s employees are a critical part of the security process as they can be misled by criminals, or make errors that lead to malware infections or unintentional data loss. Many organizations do not pay enough attention to the involvement of users, when, in fact, employees should be the first line of defence. A good way to raise security awareness among users is to involve them in the security process and empower them to prevent and remediate security incidents in real time.”

Read the report (PDF).