August 26, 2015

Success in CIO position increasingly tied to business expertise

What sets apart the CIOs who don't fit this pattern? Langer described 23 characteristics in his recent webinar, Strategic IT: The Transition Taking Place in the CIO Role. The material was based on research and interviews that he and his colleague Lyle Yorks conducted for their similarly named book. What the authors discovered is that the most successful CIOs have developedstrategy advocacy, or "a process through which technology leaders in organizations build on functional expertise." In other words, success in the CIO position has less to do with building their technology prowess and more to do with the ability to master other areas of expertise important to running a business.


Real-time computing: Gateway to the Internet of Things?

"... a real-time system is one that behaves deterministically, responding predictably to inputs or changes in the environment. Typically these are cyber-physical systems, used to manage a physical process. "Observers often confuse real-time computing with high-speed computing, such as financial trading or sports betting," adds Barnett. "The difference between high-speed computing and real-time computing is that with high-speed computing you are talking about averages -- you can say on average an operation takes a millisecond. But one time in a thousand it takes much longer. With real-time computing you are confident the operation took place within the deadline, or you know it didn't happen."


Scaling Mobile at XING: Platform, Framework and Domain Teams

Most of us have heard about Conway’s law. It claims relatedness of organizational structure (with its related processes) and produced system architecture - they go hand in hand. And that’s of course not a surprise. Consider a company with highly strict functional departments and lack of interdepartmental collaboration. Which kind of system would it produce? It would likely end up designing a set of isolated components, each exposing a unique and complicated interface. That’s an example of a causal connection between organizational structure and system architecture. What is actually interesting here is that this connection can be reversed! Meaning: you can influence changes in the organizational structures by reshaping your system architecture.


Cybersecurity in the Modern Age – Get with the 2020 Program

There has also been an evolution of the CISO, cyber gurus, and security management teams who feel they only need to understand the basic-fundamentals of what cybersecurity is, leaving the day-to-day interpretation for operational security to those lesser mortals who at times do their level best in the absence of any training, or real time investment. In fact, don’t take my word for it; look at some of those respectable organizations who have hit the press post some very successful compromises. Moreover, there are those who have suffered unauthorized incursions with the devil’s-luck of not being discovered, or suffering name and shame. On that subject, I have been unfortunate enough to follow some renowned CISOs in the industry into their departed organizations, only to find to my surprise fragile fabric of a security structure


Pragmatic Programming Techniques

The sensitivity analysis is an important step to evaluate the stability and hence the quality of our optimal solution. It also provides guidance on which area we need to invest effort to make the estimation more accurate. Mathematical Programming allows you to specify your optimization problem in a very declarative manner and also output an optimal solution if it exist. It should be the first-to-go solution. The downside of Mathematical programming is that it requires linear constraints and linear (or quadratic) objectives. And it also has limits in terms of number of decision variables and constraints that it can store (and this limitation varies among different implementations). Although there are non-linear solvers, the number of variables it can take is even smaller.


Five signs an employee plans to leave with your company’s data

“There’s potential but the practical applications are still a little immature,” says Jon Oltsik, senior principal analyst at Enterprise Strategy Group. “You can tune something to look for an attack that you know about, but what’s hard is to tune it to something you don’t know about. I can look at access patterns on repositories and how much people download and whether they save documents locally. But there’s always creative ways to work around that. A really dedicated, sophisticated adversary will quickly decipher where you’re not looking – and that’s the problem.” Or they will carry out a “low-and-slow” theft by regularly moving data to a repository over time, he adds.


Integrating a hybrid environment now a CIO core competency

"When you put applications in more than one place, you have to synchronize data," said Phil Shelley, president of Newton Park Partners, a Chicago-area consulting firm. Getting that synchronization right isn't easy, he said. And the closer it gets to happening in real time, the more complex the challenge can become. The challenges of a hybrid environment arise around several key areas: data, timing and networking needs, as well as resource provisioning -- that is, getting the time, money and personnel needed to do the integration work. ... "It is a more complicated world when you start moving components of your IT stack outside. There are obviously benefits to that, but it is a more complicated world. It gets harder when one side isn't in your company," Doug Shoupp said. Sometimes, an API may be all that's needed, Shoupp said, but that is rare.


How lack of trust destroys your team

Lack of trust destroys your team. That we all know, but Wayde shares how that phenomenon affected one team he worked with, and some antidotes to that process. In this episode we also mention a book dedicated to highly functioning teams: Patrick Lencioni’s The Advantage, and share 2 games you can play with your team to grow trust. Wayde is an Agile coach with TeamFirstDevelopment.com. He is interested in helping teams improve using the same techniques that Improv theater teams use to develop Great Team Players.


Survey Finds that Cybersecurity Incidents Rise as Supply Chain Risks Broaden

Clearly, businesses need to step up their assessments of third parties and supply chain partners. It is also essential that they stipulate the right to assess a supply chain partner’s security capabilities in contracts. Experience shows that organizations that do not legally plan for due diligence when executing contracts may not be allowed to perform adequate assessments when necessary. Also consider that as much as 20 percent of security spending is estimated to occur outside of the information technology (IT) function on services like cloud computing. Contracts executed outside of IT may not allow for due diligence and, in fact, they may require important information security and privacy safeguards.


With a Major Cybersecurity Job Shortage, We Must Act Like We Are at War

It also means cyber professionals are hopping from one job to another, leaving gaps in how their systems are protected, also increasing the likelihood of attacks. Finally, businesses are forced to train or hire unqualified employees to fulfill their cybersecurity needs. It’s no wonder 86 percent of organizations believe there’s a shortage of skilled cybersecurity professionals and just 38 percent believe their organization is prepared for a cyberattack, according to a January survey from ISACA, an international professional association focused on IT governance. The fear crosses over to government agencies as well, as we’ve seen with several high-level cyberattacks. For this reason, President Obama has been quietly recruiting top tech talent from companies such as Google and Facebook to increase the number of qualified cyber talent in Washington.



Quote for the day:

“Never follow anybody who hasn't asked "why" -- Aniekee Tochukwu

August 25, 2015

Data Mining Tools for Technology and Competitive Intelligence

In this study, four efficient tools for analyzing patent documents were tested: Thomson Reuterís Aureka and Thomson Data Analyzer, Biowisdomís OmniViz, and STNís STN AnaVist. All four tools analyze structured and unstructured data alike. They all visualize the results achieved from clustering the text fields of patent documents and either provide basic statistics graphs themselves or contain filters for performing them with other solutions. The tools were tested with two cases, evaluating their ability to offer technology and business intelligence from patent documents for companiesí daily business. Being aware of the state of the art of relevant technology areas is crucial for a companyís innovation process.


Mesosphere Expands Its Data Center OS for IoT Scale

Mesos, the kernel of the Mesosphere DCOS, is a 6-year-old Apache open-source project, conceived at the University of California, Berkeley, that was announced as a joint collaboration with Mesosphere at DockerCon EU in December 2014. The company has come a long way in the nine months since then, as more and more enterprises retool their data centers to run DCOS. Mesosphere DCOS is a highly scalable engine that enables the running of services and applications across a cluster of machines in a data center or cloud. It is highly container-driven. It combines the Apache Mesos cluster manager with a number of open-source and proprietary components and allows services to be deployed and managed through both a custom Web UI and command-line interface.


Brocade Unveils Easy-to-Use Analytics Platform for SAN Monitoring

Based on the Gen5 platform architecture that Brocade uses for its storage and networking products, the Brocade Analytics Monitoring Platform comes in a 2U form factor that can be configured with up to 24 Fibre Channel ports. The appliance itself sports two dedicated multi-core processors for frame processing and an onboard solid-state disk drive. From a software perspective, it runs an implementation of Brocade’s Fabric OS (FOS) that includes analytics capabilities and can be integrated with Brocade Network Advisor software. Rondoni said IT organizations can use the platform to generate customized reports to correlate and summarize trends and specific events.


How IoT Improves Hospitality

In-room tablets at hotels serve as media hubs, control centers, and information desks. Guest enters the room - curtains open, music plays and climate control switches on with option for guests to personalize these settings. Guests leave the room and the settings are reset to defaults, but guests' personalized settings can be saved and automatically applied upon future visits. Bathroom mirror as interactive display for news, weather and messages with ability to pair with smartphones or tablets. Eletro responsive fibers in pillows monitors blood pressure, sleep patterns and stress levels.


Why Do I Need A Data Lake?

The value and power of a data lake are often not fully realized until we get into our second or third analytics use case. Why is that? Because it is at that point where the organization needs the ability to self-provision an analytics environment (compute nodes, data, analytic tools, permissions, data masking) and share data across traditional line-of-business silos (one singular location for all the organization’s data) in order to support the rapid exploration and discovery processes that the data science team uses to uncover variables and metrics that are better predictors of business performance. The data lake enables the data science team to build the predictive and prescriptive analytics necessary to support the organization’s different business use cases and key business initiatives.


Windows 10: The smart person's guide

Windows 10 is Microsoft's effort to recapture many enterprise users who balked at Windows 8's mobile-focused interface and to finally move the last Windows XP and Vista holdouts onto a newer OS. Beyond the new features, security updates, and its platform-unifying design, Windows 10 marks a significant shift in how Microsoft's characterizes its flagship operating system. Microsoft is encouraging people to think of Windows 10 as a "service". Instead of releasing a new numbered version of Windows every few years, the company will continuously release new features and updates. Microsoft has committed to support Windows 10 for a decadeafter the July, 2015 launch.


The Importance of a Data Lifecycle Management Strategy

Companies that know and understand the similarities and differences across their information, data and storage media, along with their associated lifecycle management and tiered protection, can unlock value while removing complexity and costs to sustain growth. Organizations should start by revisiting information,data and storage media management, along with their corresponding lifecycles. Then, they should focus on what can be accomplished today in comparison to how processes worked in the past. This will allow companies to distinguish between their needs and wants. Businesses can then begin to remove costs by finding and addressing data protection complexities at the source, as opposed to cutting service.


New Standard Methodology for Analytical Models

Analytical models have greatly evolved both in the depths of the mathematical techniques as well as the wide-spread application of the results. The methodology to create analytical models, however, is not well described, as can be seen by the fact that the job of the analytic practitioners (currently called data scientists; older names are statistician, data analyst and data miner) involve a lot of tacit knowledge, practical knowledge not easily reducible to articulated rules2. This informality can be seen in many areas of analytical modeling, ranging from the project methodology, the creation of the modeling& validation data, the analytical model-building approaches to model reporting. The focus of this document is project methodology.


Seven Microservices Anti-patterns

Services were modeled based on business capability model and the first release went well. They were XML over JMS sync services and primarily focused on delivering the capabilities required for claims platform exposed to Agents, web and voice channel application. It gave us the ability to deploy frequent, small changes and A/B feature support seamlessly for our applications.When the requirements were incrementally added (and they always were) it was very hard to release the solution rapidly because of the integration complexity between applications and the consumers. Integration, functional testing, and production release required tight coordination.


How Cloud Redefined Data Center Resource Utilization

It’s important to quickly understand that cloud computing isn’t going anywhere. In fact, the proliferation of cloud computing and various cloud services is only continuing to grow. Recently, Gartner estimated that global spending on IaaS is expected to reach almost US$16.5 billion in 2015, an increase of 32.8 percent from 2014, with a compound annual growth rate (CAGR) from 2014 to 2019 forecast at 29.1 percent. There is a very real digital shift happening for organizations and users utilizing cloud services. The digitization of the modern business has created a new type of reliance around cloud computing. However, it’s important to understand that the cloud isn’t just one platform. Rather, it’s an integrated system of various hardware, software and logical links working together to bring data to the end-user.



Quote for the day:

"The final test of a leader is that he leaves behind him in other men, the conviction and the will to carry on." -- Walter Lippmann

August 24, 2015

Shifting to DevOps? Put your ducks in a row first

Historically, trying to measure "software quality" has been tricky because we've tried to measure attributes of the code, and the team delivering the code was not actually responsible for providing the ultimate customer-facing service. Personally, I think the only metrics that really matter are those related to the "consumer experience" of the system: percentage of successful API calls responded to in a reasonable amount of time, number of customer purchase transactions, number of applications successfully processed, etc. Of course, it's only fair to start measuring a team on these metrics if the team has a reasonable degree of influence on them. So, to some extent, this approach implies "DevOps" or "product teams" or whatever we want to call them.


Inside-Out versus Outside-In

The disruptive technologies of cloud-based applications, delivered through browsers and apps to a variety of devices, are all part of the external environment and linked to the role of front office. New business models are focused on taking these external capabilities and redefining how to find, win and deliver new forms of competitive offerings. Front office environments are focused on people who create value through external interactions to win and deliver business, people working Outside-In. This is unlike the back office where the focus is on process removing people and cost. Outside-In technologies enable the people in the front office to find and share the resource they need to improve their performance within these new business models. “The Future of Work” is a term used to describe the manner in which these new technologies are deployed in new optimal ways.


Big Data is Driving Health Care

In conjunction with mobility, big data is changing the way patients engage with their doctors and experience their treatment. Research has found that three out of five patients would choose telehealth visits over in-person appointments for minor check-ups and follow-ups. In PwC’s survey, more than 50 percent of respondents would feel comfortable sending a digital photo of a rash or skin problem to a dermatologist for an opinion. Not only is the technology for “virtual treatment” available, but 64 percent of surveyed patients expressed their willingness to adopt new, non-traditional ways of seeking medical attention. In a world where services are available in an instant, doctors must start treating their patients as a customer to continue to meet their needs. That includes opening the line of communication or easier visits and quicker treatment.


Firms’ lack of knowledge puts them dangerously at risk of cyber attacks

What makes new security risks particularly challenging is their fluid and dynamic nature; the rapid rate of change has proven to be increasingly difficult for organisations to keep up with. “It’s somewhat like being in a submarine with leaks that pop up in random places at random times”, Booch explains. “You have to be vigilant about not just reacting to security threats – any company has to be diligent about keeping up with the latest patches and attending to zero day exploits – but also to be proactive in seeking out potential risks”. The traditional and perhaps even stubborn mind-sets of those in the IT sector are slowing down progress in cyber securitisation, so accustomed are people to protecting their businesses and assets in a certain way. Yet this rigid approach is no match for hackers.


Framer.js for people who think things like Framer.js are weird and hard

You might think you need to be a JavaScript expert to use Framer, but in reality, Framer is doing a lot of the hard work by providing awesome documentation and familiar properties to interact with your design. CoffeeScript does you an additional favor and gets rid of all the icky JS syntax, so you can concentrate on making an amazing prototypes. Many of the properties used in Framer are exactly the same, or extremely similar to CSS properties. If you know basic CSS, Framer shouldn’t be too scary. ... If you want to accurately communicate high-fidelity interactions, a verbal description or napkin sketch isn’t going to cut it. After all, this is what you are an expert in — it’s worth learning how to use the tools that communicate your expertise.


CoreOS Adds Intel Container Security To Rocket

Among other things, the ability of Clear Containers to run on Rocket affirms CoreOS's design choice to map different "stages" for different operational characteristics for a container. CoreOS also implemented "pods" with its runtime. Pods allow multiple containers to function as a single logical service, even if the containers have been spread over multiple hosts in a cluster. ... "For the little function you need, you don't need the full QEMU layer," Sousou said, referring to the code for the emulation of a complete x86 machine that's part of a hypervisor startup. Intel stripped QEMU out of the KVM initialization process, along with multiple other minute adjustments, to take milliseconds out of the startup process.


Retail CIOs become heroes with the help of CMOs

That “hero vs. zero” attitude has shifted considerably in the past few years as the relationships between the CIO and CMO has matured, says Tom Litchford, vice president of retail technology at the National Retail Federation. “The whole idea is that the CIO and CMO really have to be attached at the hip,” he says. “As we go forward, there is less of the old feeling that “all I ever hear from IT is ‘no.’” The Forrester/NRF study reported improved relationships between the retail CIO and line-of-business colleagues such as the CMO. ... These issues go beyond technology into fundamental issues related to marketing and the entire organizational structure, so CIOs and CMOs must each bring their separate strengths to the table.


Automakers form alliance to bolster cybersecurity

Cybersecurity is a new issue for the industry, one handled by automakers in different ways. That varied and still-developing approach has fueled industry critics, including some lawmakers, who say the industry lacks a comprehensive solution to safeguard their customers. The immediate threat of malicious hackers wreaking havoc on connected cars appears to be relatively remote. The researchers who remotely controlled some Jeep Cherokee vehicle systems ... were highly sophisticated security experts who spent years developing the tools needed to complete the hack. Hackers seeking monetary gain have little current incentive to target cars. Even though vehicles can collect huge amounts of data, the auto industry has yet to monetize it in a major way


Banks hope cardless ATMs will get millennials to open accounts

The cardless ATM technology is the latest attempt by banks to persuade customers under 35 to open an account with them instead of migrating to their traditional competitors or the latest Silicon Valley startup that promises to help consumers borrow, manage, and invest money through their phones. Hudson-based Avidia Bank said earlier this week that it had introduced the new technology to the ATMs at its eight branches in Central Massachusetts. Salem Five Bancorp launched cardless ATMs this month at its 30 ATM machines, primarily on the North Shore. Twenty banks across the country, mostly regional and community banks, also have gone mobile, although the ATMs still accept traditional debit cards, said Doug Brown, senior vice president and general manager of mobile at FIS, the Florida banking technology firm that makes the mobile software for the ATMs.


Data and Analytics in the Cloud Is Real Today

Private and hybrid cloud implementations of data and analytics often coincide with large data integration efforts, which are necessary at some point to benefit from such deployments. Those who said that integration is very important also said more often than those giving it less importance that cloud-based analytics helps their customers, partners and employees in an array of ways, including improved presentation of data and analytics, gaining access to many different data sources and improved data quality and data management. We note that the focus on data integration efforts correlates more with private and hybrid cloud approaches than with public cloud approaches, thus the benefits cannot be directly assigned to the various cloud approaches nor the integration efforts.



Quote for the day:

“If it involves technology it is your fault if it breaks, The CIO should have seen it coming.” -- Earl Perkins

August 23, 2015

Applying Artificial Intelligence To Insurance Data

The first thing insurers should realize is that this is not an arms race. The winners will be the ones that take a measured and scientific approach to building up their machine learning capabilities and capacities and – over time – find new ways to incorporate machine learning into ever-more aspects of their business.  Insurers may want to start small. Our experience and research suggest that – given the cultural and risk challenges facing the insurance sector – insurers will want to start by developing a ‘proof of concept’ model that can safely be tested and adapted in a risk-free environment.


Intuit puts venerable Quicken up on the block

Intuit promised that it would continue to maintain and develop Quicken until it finds a buyer, adding that it plans to release the next edition, Quicken 2016 for Windows, and would keep working on the Mac version. Current users should see no interruption in their ability to use the software or its associated services, such as Quicken Bill Pay. "As we move through this sale, it's business better than usual," wrote Eric Dunn, who heads the Quicken unit, in an online statement. "As a standalone business, we'll focus solely on taking Quicken to the next level. And until we find that buyer, we'll continue to provide you with [the] dedicated, uninterrupted service and support you deserve."


Cyber-Risk Oversight: 3 Questions for Directors

Cybersecurity is no longer an emerging issue. Major headlines about breaches in both the public and private sectors have put the topic on every company’s agenda, regardless of size, industry or geographic location. Just like the management teams they oversee, corporate directors are very well aware of the ‘what’: the fact that cybersecurity is a significant threat. What they are looking for is the ‘how’: specific action they can take to be more effective in overseeing management’s activities. One independent director – a committee chair of a Fortune Global 100 corporation – recently told me: “Cybersecurity is uncharted territory. As directors, we have to depend on staff whose capabilities we aren’t equipped to judge, it’s difficult to measure progress and there’s no way to tell if we’re doing enough.”


Implementing the Huffman adaptive algorithm to compress graphics images

To apply Huffman adaptive encoding to the string we normally need to iterate through the string of character and perform encoding for each character in string. The main idea of the Huffman adaptive algorithm is that the encoding is initially performed starting with the “empty” Huffman tree, which contains no entries for the characters to be encoded and will further be modified by appending the new characters along with their codes during the encoding process. According to the basic concept of the following algorithm, the Huffman tree should be modified similarly during the either encoding or decoding process, because, in both cases, we need to generate the same codes for each character from the input character buffer regardless of whether encoding or decoding is performed.


Four Spheres of Lean and Agile Transformation

Agile is a method that is highly dependent on individuals and the way that they approach their work. It requires participants to take on new roles that they would normally not adopt. Leadership roles move from person to person, and each must have the freedom to commit to the team. These commitments often cross organizational boundaries. In a traditional development environment, managers set priorities and deadlines, but in an Agile environment, managers shift to a facilitation and enabling role. Managers become channels for success, creating new lines of communication and business relationships. They need to move away from their traditional command and control role. In an Agile environment, personal success is highly dependent on team success.


Computer/Social Science, Part 1: The Agile Book Club

One of the great engines of change in the software profession has been Agile. Not only has it transformed the way that development teams work, but it has had profound ripple effects across the entire software value stream. Agile is far more than a difference in batch size. The challenges Agile posed to traditional assumptions about planning in the face of uncertainty, the centrality of the team, the delivery of value, and other fundamental issues have affected everything from the inception of an idea to its eventual retirement. Testing, requirements gathering, rapid and continuous delivery, governance rules, customer collaboration, marketing, change management — all of these activities within the value stream, and more, have had to adjust to Agile.


Your IT strategy: If something’s worth doing, it’s worth doing properly

We see new systems and technology being dropped into the business – often ‘point solutions’ to solve a particular problem – without a proper diligence process to sense check for wider synergies. Time and again readiness assessments, training and business change are not well executed. This means that the business is not ready and new ways of working don’t get introduced. The net result is that the business stays in its comfort zone and introduces workarounds so it can maintain old practices – it fills gaps with manual processes and spreadsheets and does not use the new systems to enable the changes and release benefits.


Five indicators of a failing IT project

If the issues are spotted early, organisations can review the specification documents and rectify the project’s direction to ensure it meets the true requirements. With a fragmented process, companies can also find that on-going work causes issues in deliverables that have already been signed off and leads to live software breaking. Having good levels of communication and working with a third party are great ways to prevent problems occurring in the first place. The team can also increase success by employing an Agile project management approach that enables the team to gather stakeholder and user feedback on the product from the very beginning.


SEC CIO leads efforts to move agency to the cloud

"We want reusable highly scalable and flexible platforms," Dyson says. "We want to strengthen our cybersecurity and continuous monitoring posturing -- that's very important whether we're working on-prem or in the cloud." The determination of whether or not to roll out a SaaS application at the SEC "has a lot to do with timing," Dyson explains. The regulatory agency is charged with drafting and implementing rules for the securities industry, a process that is guided by deadlines mandated in statute or by the commission's own timetable. In that context, the consideration of a cloud deployment can become a question of whether or not the technology will support the agency's regulatory mission.


Agile 2015 – Industry Analyst Panel: Agile Trends and Future Direction

The use of Innovation Gameswas suggested as a way of helping the executives understand the new ideas, as well as using pilot programs and providing internal proof by starting small and showing the benefits.  An issue which was specifically identified was the fear of middle managers in many organisations as they see the significant changes that agile adoption results in for their roles. A common pattern is the reduction in the number of middle manager roles and the migration into more hands-on roles such as Scrum Master or Product Owner. There needs to be a clear transition path for these managers and the importance of strong executive support to overcome this resistance was strongly emphasised.



Quote for the day:

“Leaders are people who believe so passionately that they can seduce other people into sharing their dream.” -- Warren G. Bennis

August 22, 2015

5 Reasons Not To Buy An iPhone As Your Business Phone

The iPhone is popular, but it still only accounts for about 14% of worldwide smartphone market share as compared to Android’s 79%. In actual numbers, 1.1 billion Android-based phones are expected to ship in 2015 vs. 237 million iPhones. When I search Verizon Wireless’ website there are 9 iPhones available as compared to 29 Android options made by six different vendors from Google to HTC to Motorola to, of course, Samsung. Android is an operating system that can work on many different devices whereas iPhone’s operating system iOS only works on devices made by Apple. Even though I’ve decided to get another Samsung I like having the flexibility to choose other hardware devices that fits my and my company’s needs and I don’t get that with Apple.


Make the right choice between Hadoop clusters and a data warehouse

There's no doubt that Hadoop has a place in the enterprise, especially as big data applications take hold. But the venerable EDW has a well-established presence in data centers, and after years of refinement plays a significant role in meeting the reporting and analytics needs of most organizations. Does the emergence of Hadoop mean it's time to abandon the EDW? Some IT and data management professionals are aching to use Hadoop as a replacement for the data warehouse -- but are companies really prepared to abandon their decades-long investments in EDW infrastructure, software, staffing and development?


Initiation to Code

If you don’t take the time to check up on your mentees and listen to their concerns, travails, and triumphs, then you will have no metric for achievement. Employing agility as a mentor requires sensitivity, creativity, and solid communication skills. It also requires the foresight to see what your mentee should be aiming for, and the hindsight to see what your mentee has already accomplished. To establish a framework for gauging your mentee’s progress, consider the three phases every new team member goes through in some form. The first phase is total unfamiliarity and constant discovery; the second is a transitional period with a clear trajectory of progress; and the third is self-driven competence. In all three phases, remember that agility remains your most vital tool.


CISOs facing boards need better business, communication skills

According to a June study by Fidelis Security and the Ponemon Institute, 26 percent of board members admit to "minimal or no knowledge" about cybersecurity, and only 33 percent say that they are "knowledgeable" or "very knowledgeable." ... 70 percent of board members said that they understand the security risks to the organization, but only 43 percent of IT security professionals agreed that the board understood the security risks to the organization.. Only 18 percent of IT security professionals rated their companies' cybersecurity governance practices as very effective -- compared to 59 percent of board members. This is a difficult communications gap that needs to be addressed on both the board level and by CISOs themselves.


Why every website should switch to HTTPS

Two major problems exist for two different classes of websites. First, for larger websites that use many third-party services (ad networks, CDNs, etc.), all of those services need to support HTTPS before the main website can switch to HTTPS. Slowly, these services are starting to support HTTPS, which means it will be easier and easier for larger websites to switch to HTTPS. Second, for smaller/non-profit websites the process of getting and installing an HTTPS certificate is a pretty confusing process. New tools like SSLMate and Let's Encrypt are starting to make that process easier and more automated, so that making your small website HTTPS is a fast and easy process.


Strategy, Not Technology, Drives Digital Transformation

Executives who think they're in a technology arms race are focusing on the wrong area: The 2015 Digital Business Global Executive Study and Research Project byMIT Sloan Management Review and Deloitte identifies strategy, not technology, as the key driver of success in the digital arena. Conservative companies that avoid risk-taking are unlikely to thrive — and they'll also lose talent, as employees across all age groups want to work for businesses committed to digital progress. The report is available online and as a PDF, and the online version includes a Digital Business Interactive Tool with interactive charts to explore the data set.


Ashley Madison Breach Should Spark Security Conversation

Some security experts have noted that the breach could be a lot worse, at least in terms of compromising credit card information. According to Robert Graham's security blog: "Compared to other large breaches, it appears Ashley-Madison did a better job at cybersecurity. They tokenized credit card transactions and didn't store full credit card numbers. They hashed passwords correctly with bcrypt. They stored email addresses and passwords in separate tables, to make grabbing them (slightly) harder. Thus, this hasn't become a massive breach of passwords and credit card numbers that other large breaches have lead to. They deserve praise for this." However, the account names, street addresses, email addresses, and phone numbers used to register for the site were not encrypted.


A Phish Story

"When they target somebody, they have to set something up so maybe they'll send out an e-mail that says, 'Your PayPal has been compromised' or 'Your e-mail has been compromised.' ... "The hackers may not even say that the victims' e-mail has been compromised. They may just say, 'You've been locked out of your e-mail' or 'There's some maintenance that needs to be done on the e-mail server' or 'Click here for new information.'" Barney says never click on an unfamiliar link. Often, such links will lead to a site designed to look like a legitimate, trusted site but will have a slightly different Web address. Other times it may take the user to a blank screen. Either way, the hackers' goal is to gather information that will help them steal valuable data.


Five open source Big Data projects to watch

Take a look at the Apache Software Foundation's (ASF's) list of projects and you may feel overwhelmed. Between top-level and incubating projects, there are far too many to keep track of. Filtering down the list to Big Data projects may not help, because that "smaller" list is still quite long. And don't forget that there are several noteworthy open source projects that aren't even under the ASF umbrella to begin with. So, in the name of helpful triage, here are five projects to keep an eye on:


How to reduce IT complexity and increase agility

"Complexity is the result of a diversity of footprints, of tools, of workforce," says Christopher Rence, CIO of Digital River, a provider of e-commerce, payments and marketing services for merchants. Rence knows whereof he speaks: He's lived through three acquisitions in the last four years, and has seen the residue of the 20 acquisitions that the company has experienced since 1994. "One company we acquired had nothing but white-label hardware. It didn't have an asset value, but it was doing a lot of processing," Rence recalls. In preparation for conducting a strategic migration of the data through a gateway into a SaaS solution, "we had to do a full inventory of what those homegrown products were doing," says Rence. "It required understanding some of the undocumented knowledge.



Quote for the day:

“Whether driven by ambition or circumstance, every career gets disrupted.” -- Jay Samit