A quick disclaimer: I have nothing against TSA, despite the fact I’ve missed a flight in the past due to long lines at the security check… They are a symptom of a greater problem rather than the problem itself.
Now that we’ve put it aside let’s observe TSA’s mission statement (http://www.tsa.gov/who_we_are/mission.shtm):
“The Transportation Security Administration protects the Nation's transportation systems to ensure freedom of movement for people and commerce”
And vision statement:
“The Transportation Security Administration will continuously set the standard for excellence in transportation security through its people, processes, and technology.”
Sounds like TSA are heavy duty on security, right?
Well, I will not discuss transportation security (though debatable by some); however history tells us a slightly different story when it comes to information security…
Looking at the past 4 years:
2007 (http://bit.ly/aoChfI) – External hard drive containing data from approximately 100,000 archived employment records went missing from a controlled area at TSA.
2009 (http://bit.ly/5REHBu) – TSA accidentally posted a document containing highly sensitive information on its airport screening procedures on a government website.
2010 (http://bit.ly/dc2Nbu) – Poor security protocols lead to TSA fired worker sabotaging TSA’s databases containing information tied to the war on terror and other law enforcement activities.
While some might argue this is an unfortunate collection of non related incidents, I would seriously doubt it. With no intent of being harsh with TSA, this comedy of errors is an indication how security is perceived at TSA.
Starting point:
It will never happen to us! (Therefore no real controls, procedures or C-level directives are necessary)
Post incident #1:
Oops, it did happen. Ok, it will never happen to us AGAIN! (Must be a random statistic glitch, our current strategy is proving itself!)
Post incident #2:
Not again, No way! (Hmmm, at least we placed on each page of the manual the following: NO PART OF THIS RECORD MAY BE DISCLOSED TO PERSONS WITHOUT A 'NEED TO KNOW.')
Post incident #3:
Doh! Let’s bring in a data breach response services company to clean out the mess (http://bit.ly/c0loLq). (Addressing the collateral damage is probably going to solve the problem!)
Most of these types of incidents can be addressed today with existing controls. These are not operator errors, but a depressing example of the overall organizational/C-Level failure to enact security policies (much which are seemingly common procedures) that secures data and protects sensitive assets.
If C-level execs don’t get it they can simply view it as an insurance policy (ensuring bad things don’t happen). People get an insurance policy not because they plan to use it on a daily basis, but mainly because if something happens it can be substantial.
Another way to look at the statistics is organizations play a game of Russian roulette, assuming it will not happen to them (there is only one bullet and five empty chambers).
With the case of TSA - it looks like the cylinder is practically full…
Today I was riding with the four horsemen of the apocalypse, so I’ll finish with a positive tone:
Spring is here, happy (belated) equinox (http://bit.ly/2qHKU1)!
Tuesday, March 23, 2010
Friday, March 12, 2010
Brain dump
Last week I’ve participated in the RSA conference representing Cyber-Ark. It turned out to be a pretty busy week (your sympathy is appreciated).
This week as a slightly different exercise, we will switch roles (let’s call it un-blog post). Instead of me describing my insights, I will provide some raw data from the conference in a form of a brain dump. If any of this makes any sense to you please comment or ping me with your insights.
As with any brain dump - no order, priority or importance, just partial list of raw numbers/”facts”:
- 100% experienced cyber lose in 2009
- Top 3 stolen “items”:
3. Customer PII
- It is a standard Amazon account and can be used to purchase books or anything else…
This week as a slightly different exercise, we will switch roles (let’s call it un-blog post). Instead of me describing my insights, I will provide some raw data from the conference in a form of a brain dump. If any of this makes any sense to you please comment or ping me with your insights.
As with any brain dump - no order, priority or importance, just partial list of raw numbers/”facts”:
- Server Virtualization penetration in enterprise is estimated at 25%
- 6% of ID theft comes from password guessing
- IT spend 2/3 of their budgets on maintenance
- CIO survey – for 51% security is the greatest concern surrounding cloud computing adoption
- Information growth - 60% per year
- 1B mobile devices will be accessing the internet by the end of the year
- Survey of 2,100 companies (CIO, IT, CSO, etc.):
- 100% experienced cyber lose in 2009
- Top 3 stolen “items”:
1. Theft of IP
2. Financial/credit card data3. Customer PII
- During 2008 – 1.6M signatures (like previous 17 years combined)
- During 2009 – 2.9M signatures
- Customers said from their entire data only 1% matters
- 40% of employees private machines access work resources
- 10% of private machines are the primary working machine
- Some organization promoting personal devices for work (subsidize)
- Per Gartner – organization can save 9-40% on equipment cost
- Data breach - average loss per record is $204
- Data breach - average loss per incident is $6.75M
- 70% of physicians are afraid to place customer data in the cloud
- 56% of the malware written today is designed to steal data
- 42% of data breaches involve a 3rd party (service provider, consultant, etc.)
- Since 2008 there are more mobile devices accessing the internet than “fixed” devices
- By the end of 2011 there will be 5B users out of 6.8B people in the world…
- Projected data traffic increased 2009-2014 is by 3900%
- Videos will be 66% of mobile traffic by 2013
- Organization leveraging Amazon cloud services usually have one super admin account to purchase and manage their infrastructure:
- It is a standard Amazon account and can be used to purchase books or anything else…
As an epilogue to get your CPU working a quote by Marc Benioff:
“Why isn’t all enterprise software like Facebook?” It was the next iteration of the question he asked in 1999 (that spawned salesforce.com), “Why isn’t all enterprise software like Amazon.com.”Friday, February 26, 2010
No Internet or Laptop for you!
A couple of weeks ago I blabbered about a world with no IT resources. Since then I had a chance to discuss it with friends, especially the end device ownership part and thought it is interesting enough to share with others.
During the 15th century the Feudalism system was very common in Europe. The lucky ones played the role of lords and “life was good,” for the rest (vassals) the story was slightly different…
Let’s look at the employee-employer relationship back then. A common “compensation” package a vassal could expect would include a very small component of “salary” and a relatively large component of benefits consisting of food, clothing, housing, security, and possibly heritage rights. In return the lords practically “owned” them.
Therefore the equation was you (the vassal) will work your butt off for me (the lord) and in return I’ll give you everything you need to barely live + some change.
Through the years gradually the salary portion grew while the benefit component has gone down.
Looking at today’s common compensation package, it includes a large component of salary and a relatively small component of benefits. Food, clothing, housing, security, heritage rights? Are you kidding me?
This trend continues and will affect the “end device ownership” dilemma previously discussed.
Companies already take it for granted consumer employees will have internet access at home, so they are capable of continue working (if needed). Now who pays for the internet, electricity, etc.?
End devices are next in line (cell phone, laptop, tablet, etc.). Surprisingly we have an unusual case of common interest. Most consumer employees will be happy using their own device for both home and work activities. We already see today some companies funding the purchase of personal device for work.
As you are expected to show up to work dressed up, employers will mandate end devices capable of doing your work. The good news is as most/all the computing will happen in backend systems (virtual desktop solution), so the requirement for your device is going to be pretty basic.
If we’ll look at the futuristic equation (right around the corner) the employer (i.e. the lords) will give you (the consumer employee) salary only, and in return you’ll be responsible for everything needed to do your work (and obviously work).
Next week it is RSA conference week, therefore no post for you (but many sessions, meetings and dinners for me).
See you in a couple of weeks.
During the 15th century the Feudalism system was very common in Europe. The lucky ones played the role of lords and “life was good,” for the rest (vassals) the story was slightly different…
Let’s look at the employee-employer relationship back then. A common “compensation” package a vassal could expect would include a very small component of “salary” and a relatively large component of benefits consisting of food, clothing, housing, security, and possibly heritage rights. In return the lords practically “owned” them.
Therefore the equation was you (the vassal) will work your butt off for me (the lord) and in return I’ll give you everything you need to barely live + some change.
Through the years gradually the salary portion grew while the benefit component has gone down.
Looking at today’s common compensation package, it includes a large component of salary and a relatively small component of benefits. Food, clothing, housing, security, heritage rights? Are you kidding me?
This trend continues and will affect the “end device ownership” dilemma previously discussed.
Companies already take it for granted consumer employees will have internet access at home, so they are capable of continue working (if needed). Now who pays for the internet, electricity, etc.?
End devices are next in line (cell phone, laptop, tablet, etc.). Surprisingly we have an unusual case of common interest. Most consumer employees will be happy using their own device for both home and work activities. We already see today some companies funding the purchase of personal device for work.
As you are expected to show up to work dressed up, employers will mandate end devices capable of doing your work. The good news is as most/all the computing will happen in backend systems (virtual desktop solution), so the requirement for your device is going to be pretty basic.
If we’ll look at the futuristic equation (right around the corner) the employer (i.e. the lords) will give you (the consumer employee) salary only, and in return you’ll be responsible for everything needed to do your work (and obviously work).
Next week it is RSA conference week, therefore no post for you (but many sessions, meetings and dinners for me).
See you in a couple of weeks.
Wednesday, February 17, 2010
There is an App (war) for that
Once upon a time many, many years ago Apple has lost the OS = Operating System battle (at least the first round). Some believe the main reason was Microsoft’s smart platform play. The Redmond giant bet on building an open OS, not open source but rather a set of robust, easy to use, well documented, supported APIs. They figure out early in the game the simple ‘law of nature’ – easiness of creating applications cause more applications to be created which cause higher value to the underlying platform (OS) resulting in more money to the OS vendor (which is … Microsoft of course).
< Side comment - today in the era of Cloud Computing Microsoft is betting again on the platform, through their Azure offering.>
Fast forward to early 2008 (if I got it right), Apple has launched the AppStore (less than a year after launching the iPhone). Well, it seems Steve Jobs has done his homework. He created an ‘open’ platform (iPhone OS) and invested/promoted the AppStore concept (more than 150k apps and counting).
Apple in the role of Microsoft? Doh!
A different school of thought claims what Microsoft has done to the Macs, Google is doing now to the iPhone/AppStore. Apple still has a one HW-one SW strategy; as far as they’re concerned apps can only run on their HW. Google is making friends with many HW vendors and their Android OS/apps can run on a slew of devices. While Google only has to focus on the SW, Apple needs to be best at both fronts (HW & SW) in order to continue dominating the market.
Though a history fan, why do I open with a history lesson?
News from early this week: ‘Biggest mobile operators join forces on app store project’. It was all over the media (e.g. http://tiny.cc/ktgxp). Should we assume the battle on the apps has just begun?
Of course not! This battle is as old as the Operating Systems. Mostly it was the OS owners fighting for position (Microsoft, Apple, Google, etc.), however occasionally others get greedy (given the size of the turf). It is easier making money selling services/apps in the mobile space, mainly as users are used to paying extra for extra. PC consumers expect everything to be provided as a service (over the internet) and for free. When was the last time you paid for services/apps?
While these 24 carriers claim their motivation is pure - ‘developers will be able to go to one place to get their applications distributed instead of having to go through multiple application approval processes’ (Yeah right…), it is clear they are after piece of the action. Apple’s appStore and Google's Android Market are being challenged by mobile network operators (per article).
Apple’s appStore, Google's Android Market and recent initiative (by mobile network operators) are all about consumer apps, but what about the enterprise?
If I’m an enterprise bought into Apple’s vision and seeking to provide customized (business) apps for my staff, how do I achieve it? How can I enable the iPhone in a similar fashion to laptops? I just want to have my own apps catalogue (similar to my software catalogue solution).
Is it time for a ‘private app store’ for enterprise unlike the ‘public app stores’ previously discussed?
Well, the first signs are here: ‘Google to open app store for business software (http://tiny.cc/W5Hwc). Sounds like the right direction, isn’t it? Despite the promising title it is actually not really what I was looking for. It is mainly a marketplace for business applications focusing (as a first step) on Google Apps (rather than Android Market).
As for enterprise app store solutions, the Apple/Google of the world will probably approach it as an extension of their consumer solution. This will leave the door wide open for security vendors to address question such as access control, application governance etc.
So do we have an App (store) for that?
< Side comment - today in the era of Cloud Computing Microsoft is betting again on the platform, through their Azure offering.>
Fast forward to early 2008 (if I got it right), Apple has launched the AppStore (less than a year after launching the iPhone). Well, it seems Steve Jobs has done his homework. He created an ‘open’ platform (iPhone OS) and invested/promoted the AppStore concept (more than 150k apps and counting).
Apple in the role of Microsoft? Doh!
A different school of thought claims what Microsoft has done to the Macs, Google is doing now to the iPhone/AppStore. Apple still has a one HW-one SW strategy; as far as they’re concerned apps can only run on their HW. Google is making friends with many HW vendors and their Android OS/apps can run on a slew of devices. While Google only has to focus on the SW, Apple needs to be best at both fronts (HW & SW) in order to continue dominating the market.
Though a history fan, why do I open with a history lesson?
News from early this week: ‘Biggest mobile operators join forces on app store project’. It was all over the media (e.g. http://tiny.cc/ktgxp). Should we assume the battle on the apps has just begun?
Of course not! This battle is as old as the Operating Systems. Mostly it was the OS owners fighting for position (Microsoft, Apple, Google, etc.), however occasionally others get greedy (given the size of the turf). It is easier making money selling services/apps in the mobile space, mainly as users are used to paying extra for extra. PC consumers expect everything to be provided as a service (over the internet) and for free. When was the last time you paid for services/apps?
While these 24 carriers claim their motivation is pure - ‘developers will be able to go to one place to get their applications distributed instead of having to go through multiple application approval processes’ (Yeah right…), it is clear they are after piece of the action. Apple’s appStore and Google's Android Market are being challenged by mobile network operators (per article).
Apple’s appStore, Google's Android Market and recent initiative (by mobile network operators) are all about consumer apps, but what about the enterprise?
If I’m an enterprise bought into Apple’s vision and seeking to provide customized (business) apps for my staff, how do I achieve it? How can I enable the iPhone in a similar fashion to laptops? I just want to have my own apps catalogue (similar to my software catalogue solution).
Is it time for a ‘private app store’ for enterprise unlike the ‘public app stores’ previously discussed?
Well, the first signs are here: ‘Google to open app store for business software (http://tiny.cc/W5Hwc). Sounds like the right direction, isn’t it? Despite the promising title it is actually not really what I was looking for. It is mainly a marketplace for business applications focusing (as a first step) on Google Apps (rather than Android Market).
As for enterprise app store solutions, the Apple/Google of the world will probably approach it as an extension of their consumer solution. This will leave the door wide open for security vendors to address question such as access control, application governance etc.
So do we have an App (store) for that?
Tuesday, February 9, 2010
A world with no IT Resources – Should Admins get nervous?
The reality of organization’s IT resources (starting with SMBs) as we know it is about to dramatically change. The Cloud movement along with the new “Consumer employee” phenomenon (employee at day, consumer at night) drives organizations to reduce ownership of IT resources. Eventually IT resources free.
How is it going to work (most of the technology is already available)?
1. Server infrastructure
Entire server infrastructure will run in the cloud (pick your favorite vendor)
2. Employees workspace
Desktop virtualization will run on the cloud server infrastructure
3. Applications
SaaS where possible, else application virtualization on top of the cloud server infrastructure
4. Desktop/Laptop/endpoint device
That’s where things become interesting. Since your workspace is virtualized all that is needed is a device with basic capabilities to connect (e.g. browser). Now if the “consumer employee” prefers using his own cool/customized/private/latest/greatest device anyway, why should the organization buy an extra one? Instead, every several years (e.g. 3Y) the organization will grant each employee with an allowance (e.g. $3k) to purchase a personal device (desktop, laptop, netbook, tablet, etc.). While I think the real revolution is going to happen around the device ownership, I will leave this topic to my next post (stay tuned).
Information protection is going to become key in the described setup. As data will reside elsewhere (in the cloud or personal devices), controlling who can access it, who has accessed it and where is it, are going to be critical capabilities for future security solutions. Think about asset management and even identity management in this hybrid world…
I’m no prophet, by all means, but the day is coming and we better accept (even embrace, God forbid) the changing landscape and start preparing.
Now regarding my opening question (should IT personnel become nervous in this world with no IT resource) - of course not! Their current role will change/expand, rather than spending most of their time deep in the infrastructure (such as AD configuration/administration), they will be instrumental with this virtual/cloudy infrastructure. Vendor selection and ongoing benchmarking will occupy a greater portion of their time.
Are you convinced by now? I must be missing something and be happy to hear your take.
How is it going to work (most of the technology is already available)?
1. Server infrastructure
Entire server infrastructure will run in the cloud (pick your favorite vendor)
2. Employees workspace
Desktop virtualization will run on the cloud server infrastructure
3. Applications
SaaS where possible, else application virtualization on top of the cloud server infrastructure
4. Desktop/Laptop/endpoint device
That’s where things become interesting. Since your workspace is virtualized all that is needed is a device with basic capabilities to connect (e.g. browser). Now if the “consumer employee” prefers using his own cool/customized/private/latest/greatest device anyway, why should the organization buy an extra one? Instead, every several years (e.g. 3Y) the organization will grant each employee with an allowance (e.g. $3k) to purchase a personal device (desktop, laptop, netbook, tablet, etc.). While I think the real revolution is going to happen around the device ownership, I will leave this topic to my next post (stay tuned).
Information protection is going to become key in the described setup. As data will reside elsewhere (in the cloud or personal devices), controlling who can access it, who has accessed it and where is it, are going to be critical capabilities for future security solutions. Think about asset management and even identity management in this hybrid world…
I’m no prophet, by all means, but the day is coming and we better accept (even embrace, God forbid) the changing landscape and start preparing.
Now regarding my opening question (should IT personnel become nervous in this world with no IT resource) - of course not! Their current role will change/expand, rather than spending most of their time deep in the infrastructure (such as AD configuration/administration), they will be instrumental with this virtual/cloudy infrastructure. Vendor selection and ongoing benchmarking will occupy a greater portion of their time.
Are you convinced by now? I must be missing something and be happy to hear your take.
Tuesday, February 2, 2010
If you have the same problem for a long time, maybe it is a fact not a problem…
Recently the topic of weak passwords (= hacking made easy), has reared its ugly head once again.
You probably mumble now – please don’t let it be yet another passwords related post, we already know our passwords are weak, hackers can (and will) share our identity and we are all going to die…
Unfortunately I could not resist.
As long as users are responsible to create their own passwords, it will not matter how high the security walls are built. Let’s face it - we all want the ultimate user experience, just let me use the service without the entire authentication mumbo jumbo. When it comes to passwords, most of us create simple passwords, don’t change them at all, and use similar passwords for all our accounts (where possible). And BTW – since forgetting passwords is a hassle we tend to conveniently write it on a piece of paper or simply save it in a file on our computer (the sophisticated among us might even “hide it” by not placing it on the desktop).
Through the years many vendors attempted to tackle this issue introducing a slew of solutions - secret questions, images, graphics, second passwords, and the list go on and on. These are all just sophisticated passwords (password 1.0, password 2.0 or password 3.0), still subjected to the users will/motivation.
Security experts in the audience will explain that regardless of password strength or rotation frequency, hackers will manage to break them. Terms such as session hijack or Man-in-the-middle will be used to further scare us. I must admit it is all true, however with so many identities out there you simply need to be slightly better than your neighbors to postpone destiny (like the well known joke about two friends, a jungle, a hungry lion and a pair of running shoes). In addition, a large customer recently confessed that changing passwords every 90 days addressed a very large portion of their identity problems. Today I read that Twitter asks users to reset passwords after possible phishing attack (http://tinyurl.com/yhmn9y8).
So why do we consistently write about it for years and years? Is it because there is no solution for the problem? It keeps changing on us? The solutions provided by vendors are not valid anymore?
Well, as I have already stated the root cause of this problem is us, the (lazy) users. Once this parameter will change the problem will simply go away (flying angles play harp, rainbow in the background).
A quick recap:
Problem – weak passwords = hacking made easy
Root cause – us, the (lazy) users
Solution – replace us, the (lazy) users
Problem solved, moving on!
How can we replace us, the (lazy) users in a process intended to authenticate us (the …)?
While there are many solutions out there strengthening user authentication (e.g. out of band), I’ll mention two ways to better manage authentication:
1. Software replaces users – software manage the entire authentication process, including password generation (a non-lazy program will ensure password strength), maintenance (frequently modify) and seamlessly login. Implemented right this will address the challenges previously described and improve security while reducing the hassle.
2. Behavioral characteristics – base authentication on user’s behavioral characteristics/patterns, rather than parameters subjected to his will. Answer the question “who he is” (I’m not referring to physical aspect such as fingerprint) rather than “what he knows”.
Consumers are mainly concerned with their own identity. For enterprise the problem is a hairy one. Organizations measure everything using the “risk lenses” (and they should), therefore not all identities are born equal. While most identities are associated with “real” employees, some such as shared administrative accounts are not tied to any particular “real” identity. The paradox is that while the number of these accounts is relatively small the risk associated with their capabilities is huge.
Recently we’ve heard of a financial services company with poor password management controls for shared administrative accounts that resulted in a data breach affecting 1.2 million of their customers. The realization of this challenge contributed greatly to the spike of the PIM (privileged Identity Management).
My recommendation for organizations is: “worry when you should worry, don’t worry when you should not worry”. Brilliant, isn’t it? A more professional way to put it will be: your security controls should be proportional to the risk. While providing better password management capabilities and controls for the entire organizations has value, you lose focus on your priorities. Focus stands for better controls in a timely manner for the high risk accounts.
You probably mumble now – please don’t let it be yet another passwords related post, we already know our passwords are weak, hackers can (and will) share our identity and we are all going to die…
Unfortunately I could not resist.
As long as users are responsible to create their own passwords, it will not matter how high the security walls are built. Let’s face it - we all want the ultimate user experience, just let me use the service without the entire authentication mumbo jumbo. When it comes to passwords, most of us create simple passwords, don’t change them at all, and use similar passwords for all our accounts (where possible). And BTW – since forgetting passwords is a hassle we tend to conveniently write it on a piece of paper or simply save it in a file on our computer (the sophisticated among us might even “hide it” by not placing it on the desktop).
Through the years many vendors attempted to tackle this issue introducing a slew of solutions - secret questions, images, graphics, second passwords, and the list go on and on. These are all just sophisticated passwords (password 1.0, password 2.0 or password 3.0), still subjected to the users will/motivation.
Security experts in the audience will explain that regardless of password strength or rotation frequency, hackers will manage to break them. Terms such as session hijack or Man-in-the-middle will be used to further scare us. I must admit it is all true, however with so many identities out there you simply need to be slightly better than your neighbors to postpone destiny (like the well known joke about two friends, a jungle, a hungry lion and a pair of running shoes). In addition, a large customer recently confessed that changing passwords every 90 days addressed a very large portion of their identity problems. Today I read that Twitter asks users to reset passwords after possible phishing attack (http://tinyurl.com/yhmn9y8).
So why do we consistently write about it for years and years? Is it because there is no solution for the problem? It keeps changing on us? The solutions provided by vendors are not valid anymore?
Well, as I have already stated the root cause of this problem is us, the (lazy) users. Once this parameter will change the problem will simply go away (flying angles play harp, rainbow in the background).
A quick recap:
Problem – weak passwords = hacking made easy
Root cause – us, the (lazy) users
Solution – replace us, the (lazy) users
Problem solved, moving on!
How can we replace us, the (lazy) users in a process intended to authenticate us (the …)?
While there are many solutions out there strengthening user authentication (e.g. out of band), I’ll mention two ways to better manage authentication:
1. Software replaces users – software manage the entire authentication process, including password generation (a non-lazy program will ensure password strength), maintenance (frequently modify) and seamlessly login. Implemented right this will address the challenges previously described and improve security while reducing the hassle.
2. Behavioral characteristics – base authentication on user’s behavioral characteristics/patterns, rather than parameters subjected to his will. Answer the question “who he is” (I’m not referring to physical aspect such as fingerprint) rather than “what he knows”.
Consumers are mainly concerned with their own identity. For enterprise the problem is a hairy one. Organizations measure everything using the “risk lenses” (and they should), therefore not all identities are born equal. While most identities are associated with “real” employees, some such as shared administrative accounts are not tied to any particular “real” identity. The paradox is that while the number of these accounts is relatively small the risk associated with their capabilities is huge.
Recently we’ve heard of a financial services company with poor password management controls for shared administrative accounts that resulted in a data breach affecting 1.2 million of their customers. The realization of this challenge contributed greatly to the spike of the PIM (privileged Identity Management).
My recommendation for organizations is: “worry when you should worry, don’t worry when you should not worry”. Brilliant, isn’t it? A more professional way to put it will be: your security controls should be proportional to the risk. While providing better password management capabilities and controls for the entire organizations has value, you lose focus on your priorities. Focus stands for better controls in a timely manner for the high risk accounts.
Tuesday, January 26, 2010
Please stay alive while we upgrade the software
An unbelievable, yet true story:
A family member was going through a severe medical situation requiring a daily life saving treatment. Treatment took place at the hospital using an expensive medical device. After two weeks of therapy he was asked to skip the next couple days of treatment. Sounds a bit strange given the fact it was a life saving procedure, doesn’t it? Confused, he inquired for the nature of his doctor’s request and was given the answer that device is down for two days due to a software upgrade (of the equipment).
Can you believe it? Critical (life saving) medical infrastructure is down for days due to software upgrade!? It must be a bad joke…
This story is an indication of the criticality of software applications in our lives. Recently there was a big discussion about the impact of a cyber terror attack knocking down the internet. Without getting into a lengthy debate I feel we are past the turning point. Software has become critical part of our lives, especially with regards to some commercial/enterprise applications. Based on the story above it can even be a life saving medicine.
Despite the importance of software, in many cases the overall quality of the package is lacking. We have all heard the stories about vendor locking and challenges some customers have with upgrading commercial software (as well as enterprise software). It always looks like install and upgrade are an afterthought rather than a core capability (similar phenomenon with security and even management capabilities). Occasionally the approach is “once it is up and running - you will get all this great functionality…” This phenomenon is much more common with large software vendors with stronger leverage (i.e. bargaining power) over their customer base.
So how can we align quality with criticality to improve this situation?
A major benefit SaaS vendors bring to the market has to do with their state of mind as companies. Unlike the common perception of SaaS companies as software companies, they are not. SaaS companies are actually SERVICES companies, which happens to develop\market\sell a product. Their state of mind is of a services organization. A CEO of such a company recently told me: “if the service we provide is not good enough, we can (and will) be fired every day”. This refreshing perception of the role of software applications (and software providers) keeps these companies close to (and dependent on) their customers and might be the panacea for the quality (or lack of) delivered. I believe it might even have a positive impact on more traditional software vendors.
So if you are a software vendor, keep in mind the “services state of mind”. But most important – stay healthy!
A family member was going through a severe medical situation requiring a daily life saving treatment. Treatment took place at the hospital using an expensive medical device. After two weeks of therapy he was asked to skip the next couple days of treatment. Sounds a bit strange given the fact it was a life saving procedure, doesn’t it? Confused, he inquired for the nature of his doctor’s request and was given the answer that device is down for two days due to a software upgrade (of the equipment).
Can you believe it? Critical (life saving) medical infrastructure is down for days due to software upgrade!? It must be a bad joke…
This story is an indication of the criticality of software applications in our lives. Recently there was a big discussion about the impact of a cyber terror attack knocking down the internet. Without getting into a lengthy debate I feel we are past the turning point. Software has become critical part of our lives, especially with regards to some commercial/enterprise applications. Based on the story above it can even be a life saving medicine.
Despite the importance of software, in many cases the overall quality of the package is lacking. We have all heard the stories about vendor locking and challenges some customers have with upgrading commercial software (as well as enterprise software). It always looks like install and upgrade are an afterthought rather than a core capability (similar phenomenon with security and even management capabilities). Occasionally the approach is “once it is up and running - you will get all this great functionality…” This phenomenon is much more common with large software vendors with stronger leverage (i.e. bargaining power) over their customer base.
So how can we align quality with criticality to improve this situation?
A major benefit SaaS vendors bring to the market has to do with their state of mind as companies. Unlike the common perception of SaaS companies as software companies, they are not. SaaS companies are actually SERVICES companies, which happens to develop\market\sell a product. Their state of mind is of a services organization. A CEO of such a company recently told me: “if the service we provide is not good enough, we can (and will) be fired every day”. This refreshing perception of the role of software applications (and software providers) keeps these companies close to (and dependent on) their customers and might be the panacea for the quality (or lack of) delivered. I believe it might even have a positive impact on more traditional software vendors.
So if you are a software vendor, keep in mind the “services state of mind”. But most important – stay healthy!
Subscribe to:
Posts (Atom)
