Wednesday, December 29, 2010

What!? Sucha long time? Really?

Well... I guess I am back to writing a little bit then.

Sorry for the long pause.

Wednesday, October 27, 2010

Data volume and variety

At a meeting with one of our main clients’ referral the topic of data security shifted to the amounts of data at their disposal, therefore being very agile when it comes to obtaining reports, statistics and such. One of the main decision makers was pointing to the fact that they had close to 100 GB of data “perfectly safe” thanks to the systems and technologies acquired as of recent.

At one point during the discussion I asked what tools they were using for validating the wholeness of such data, making sure there were no duplicates, which interfaces they used to match diverse types of data and their respective packages to talk to each other, how they obtained updated statistics from such data, and a few other questions.
I started projecting the following:

“What if your data were not as c mpl te as y u t ink it is?”
“How do you make sure some of it do you make sure some of it is not duplicates is not duplicates?”
And so on…

Turns out the diverse types of data they posses are not standardized and most programs used have no way to communicate to each other. So, some information stored in database A is duplicated in database B; while some of such data is duplicated inside the same database. There is no policy or tool that guarantees the data is retrievable from backup and even from its original repository. And there is not Business Intelligence package or procedure to gather information from all these places to have instant reports on the financial health of the business or any other operation or department.

In other words, this is another instance of what we refer to as data rich, insight poor.

It was obvious that the IRR on all these expenses (not investments in this case) was of a negative value, an infinite amount, but in terms of time.

The main issue?
Business-type decision makers pointing to the IT-type ones as “not getting it.”
IT-type decision makers pointing to the Business-type ones as “not learning it.”

What is the catalyst for Marrying IT with Biz?
Training.

The least we can do is sit down the biz people for a day listening to IT: not about the technology insights or anything in terms of Terabytes, Gigahertz or Operating Systems; but rather on the reasons why a particular technology is better than the “inexpensive” or “popular” or “affordable” ones; and how those integrate –or not- with the rest of the existing applications.

And then sit down the IT people for a day listening to Biz: not about the budget projections or anything in terms of Marketing, Cost Containment or JIT Inventory; but rather on the reasons why a particular process is better than the “easy” or “accepted” or “cool” ones; and how those incorporate –or not- with the rest of the existing departments.

Once IT gets it and Biz learns it, all that data in your possession will be better able to provide information; its sole reason to exist.

Ready for the meeting?

Sunday, September 19, 2010

Cloudy with a chance of more clouds

From magazines targeting technology channels such as Computer Dealer News and IT In Canada, to business related such as Fortune Magazine and Bloomberg Businessweek the term “Cloud Computing” is everywhere.

It has dominated the IT Professional areas and obviously the developers’ world for a few years. And now it is transitioning to the business and government spheres. Why?
You just need to go to main business sites such as http://www.businessweek.com/ or http://economist.com/ or http://money.cnn.com/ and search for Cloud Computing to receive a list of recent and ever more updated articles about what it was, what it means, what it will be, and how big corporations are trying to outdo their rivals in this area; the new business opportunities it brings, and even how governments are taking advantage of such technologies.

Some of us have been using cloud computing for many years even without noticing it. Do you have a HoTMaiL or Yahoo! email address? A Facebook account? All those messages and pictures live on-the-cloud. You use any computer or device to access, create, change and delete your information while consuming others’ and interacting with these.

The Cloud Computing concept is the same, just applied now to businesses: access, store, create, change, distribute, and collaborate on content on the Web, using any device that connects to it and utilizes a Web browser or similar technology.

Most of us start with the simplest of Cloud-Computing services, such as messaging and on-line Backup: something similar to putting your foot in the water to know how cold it is. Then we start getting it and move to Hosted Email; then once we know about it and are comfortable with it we go for documents’ sharing, then software as a service, and later even paying for servers and computers utilization that we don’t even know where their physical location is. The variety of services and the constant growth of such services and number of suppliers make it more affordable and easier now. It will be a matter of some years that entire organizations will be running everything on-the-cloud.
Hard to imagine? Walk into the server room of your headquarters today and you’ll see hundreds of blinking lights, UPSs, servers, switches, routers, cables everywhere, and such; along with the air-conditioning units required to keep such place cool. Picture now the same room with just one small UPS unit, a modem, and a wireless router. That’s it.
In a few more years not even those three elements will be necessary because the urban wireless networks will provide connectivity. Perhaps we won’t even need computers on our desks, and a tablet or slate device will be our main means of working then.
It’s difficult to let go and think that all of our files and data could reside on-the-cloud instead of our servers, computers, external storage devices and portable and mobile units; but it starts to make sense, doesn’t it?

Better get your umbrella now.

Monday, August 16, 2010

Train people only when needed

It went like this:
- Sorry, I’m late for the meeting. There were a lot of cars on the streets today.
- Wait, do you drive here?
- Yes, of course. It takes me only 45 minutes most of the times
- You don’t live in 1234 Grand Avenue anymore?
- I still live there. Why?
- Well, have you thought about taking public transportation instead? When I lived close to your home I preferred that, it was a consistent 20 minutes commute, and way cheaper than driving and parking
- I do not know the public transportation system, but do know that schedules change a couple of times a year, so I prefer to drive
- Well… you can learn it pretty quickly and save time and money
- Look, if my car breaks or there is a definitely good reason to study such mode of transportation I will learn it and use it
- Saving time and money is not a good reason?
- I’m comfortable driving my car, alright? If a new law or the company requests I use any other means of transportation then I’ll research it; that time has not come yet, right? By now I’m fine this way
- Well… let’s focus on business then…

And so it is with our computer systems. Some people have shortcuts on their Desktop to get to what they need to open to be able to work. If the shortcuts disappear for any reason they do not know how to get from point A to point B anymore. Some others have a step-by-step document they follow on those tasks that are not a daily routine and forget easily. So, a device, and address or a name changes and the instructions or shortcuts have to be recreated for those users.

Training anyone? When I touch on the subject to decision makers -incredibly- most of them speculate that those employees that get the training will go to the competition. Others do not see the business value of having more IT-literate staff because; well… they already count on those instructions and shortcuts on their Desktops.

I do not know how much productivity is lost by people doing things the way they are used to, instead of knowing and applying different methods to get to their destination. However, I’m sure businesses would save lots of money (and most importantly, time) if personnel simply knew other ways to do such tasks. No need most of the times to pursue certifications or diplomas or titles; a very basic and/or introductory course can take care of most company’s wants.

Any way I see it, I prefer the 20 Vs. 45 minutes ride.

We could argue that “…that time has not come yet…” or anything similar. I might be totally wrong under your company parameters, but independently of field and size, somehow I strongly believe that time is here now.


What's worse than training your workers and losing them? Not training them and keeping them.
-Zig Ziglar

Saturday, July 31, 2010

Nothing Personal

On reviewing a few reports on the state of Internet Security, lately I have observed a pattern nobody seems to want to talk about. Perhaps the overuses of such issue and the constant reminders about it have become common and invisible signs for our IT-avert and strained eyes.

Here we go again: most security breaches both at home and at the workplace happen due mainly to human error.

Although I am also tired of repeating the same long list of safe actions on visiting Websites, opening email attachments, replying to certain messages and all that jazz; this time I would like to focus on something that should concern you: your personal information. Even better, these are only a few tips to protect your financial information.

1. Financial institutions will never contact you via email asking for your personal information, they already have it when you signed up the contract. Do not provide anything personal to messages that look legitimate; but are not.

2. Whether you receive electronic or printed statements for your credit cards and banking accounts, peruse them carefully every month, and clarify charges you don’t identify as soon as you review your statement.

3. Change passwords every few months, at least make an effort to change them every six months or annually. Select easy to remember passwords for you, but that are complex and difficult to guess for everybody else; a longer than 7 characters combination of numbers, uppercase and lowercase letters is best. Dare I suggest you base them on your name, the institution, a date and even perhaps a sequential number in a way that only you know? For example, I would set something like this for Uberbanken Bank: user name “hector_curiel” password “HC1999UberBank01”.

4. The same way you shred confidential paper based documents and expired credit cards, make sure no personal information is being given away when you dispose of external Hard Drives, USB flash drives, and obviously computers. Make sure the contents of such devices are erased and if at all possible, destroy the Hard Drives.

5. When connecting wirelessly to the Internet, make sure the signal you are using is encrypted. If not possible, at least make an effort not to transmit any confidential information in the form of email –or similar- messages; also avoid on-line banking when this is the case.

As you can see, all it really requires is a little bit of common sense. If you start educating yourself on best practices at work, at home, and when using public facilities; the virtual world will become a safer place for us all.
A simple search on the internet for what you want to know, and depending on your Internet literacy and needs, will take you to places such as these:
http://corp.support.com/blogs/post/7-common-sense-ways-protect-your-online-bank-account
http://www.tdameritrade.com/security/onlineSafetyTips/onlineSafetyTips.html
http://www.commonsense.com/internet-safety-guide/
http://ask-leo.com/how_do_i_stay_safe_in_an_internet_cafe.html

Enjoy and use the Web appropriately and you’ll help us all, starting with yourself.
Nothing Personal.

Saturday, July 17, 2010

Extracts from Computer Crime and Security Survey

This week I received the 14th Annual Computer Security Institute’s Computer Crime and Security Survey, Executive Summary. It is a long document with plenty of tables and graphs; along with much IT and Information Security related jargon that in reality only IS Professionals fully understand.

However, a few figures catch my attention on the Types of Attacks Experienced by businesses: while some assaults that only technically-inclined individuals can perform vary year after year; some easier to understand for the average person are worth mentioning.
The Exploit of wireless networks reduced considerably to only 7.6%.
The three more prominent types of “attacks”:
3. Insider abuse of Net access or Email @ 29.7%, down from almost 60% in 2007
2. Laptop/mobile device theft @ 42.2%, down from 50.0% in 2007
and
1. Malware infection @ 64.3%. Up from 52% in 2007 and 50.0% in 2008

How are you protecting your data on these regards?
Are your personnel being trained on and constantly reminded of best navigation and Internet use practices?
Are your portable devices secured through strong authentication and encryption?
and
Most importantly, what type of malware protection does your business utilize?

Average losses due to these attacks, although lower than the US$345,000.00 in 2007; are still high at US$234,000.00

I’ve seen companies still using “free” products believing it is cheaper to have these packages instead of proper protection for their assets.
I’m sure yours is not one of them. Is it?

Thursday, July 1, 2010

Send you a what?

So, tomorrow noon (July 2nd @ 12:00) marks the exact middle of the entire year. In case you are unaware of, this is the first decade of the new millennium.
And yet, just a few minutes ago I received a telephonic request for me to send a “FAX” …
Gosh! Don’t they have an email system, or at least one free Y! or HoTMaiL address?

I replied indicating that the last time I had the need to use a FAX machine was May of 1999. I would have a very hard time finding such machine around here. And, obviously, I suggested I would scan whatever physical document they were requesting and would send it via email if they provided an address. After three silent seconds that sounded as if the person on the other side of the line had discovered Radium, she said in a loud and –I’m sure- smiley voice: “That’s an EXCELLENT idea. Yes, please!”

As I see it, the only companies that push and promote FAX lines -and machines- are the telephone suppliers’ corporations. Aside from those, I honestly believe we should declare FAX machines defunct. If possible, before the end of the year.

If, by any chance you still own one of those relics, please know that:
+ You are wasting not only space, but also electricity, ink and paper; and damaging the environment.
+ If you have a scanner (67% chance), and your recipient has an email address (90%+ chance), you can kiss your F@# machine goodbye.
+ If you count on a MFP printer (most big copiers are or can be), you can kiss your F@# machine goodbye.
+ Some of these MFPs come with software that allows you to see the documents before deleting, storing, or printing them. You can kiss your F@# machine goodbye.
+ If you have a server with a modem, the server can act as a FAX recipient and also send, and the electronic documents can be managed easily: delete SPAM, keep the good ones in organized folders, etc. In brief, you can kiss your F@# machine goodbye.
+ There are many Internet-based companies that provide a FAX-to-Email service (and vice versa, if definitely unavoidable). Some are very affordable for low volumes of such documents. There are many options and plans and you can pay on-demand or a subscription fee; such prices will save you money by substituting that aged machine and the power and telephone line associated to it. So, you can kiss your F@# machine goodbye.

Think about this the next time the word FAX appears in your horizon. It would be lovely to see the Wikipedia definition of FAX as “A fax (short for facsimile) was a document sent over a telephone line. Fax machines existed, in various forms, since the 19th century and until the end of 2010, though modern fax machines became feasible only in the mid-1970s as the sophistication increased and cost of the three underlying technologies dropped…”

Believe me, you can kiss your F@# machine goodbye.