Recent Posts

Showing posts with label Intellectual Property. Show all posts
Showing posts with label Intellectual Property. Show all posts

Wednesday, April 2, 2014

The Crime-Business Balance

Is it responsible to ignore crime if you think you have a just reason?  

The Cost

http://www.standard.co.uk/
Business operators look at risks and decide how much of it to tolerate. Part of tolerating a certain amount of risk can also mean revealing a willingness to take losses for the sake of generating sales and absorbing market share. This balance is famously summed up as "the cost of doing business." This cost is typically measured in dollars but to gain those dollars, you have to give something up.  What that something is may not be quantifiable but it is real.  Such is the nature of risk taking.

Fight or Flee

A trade-off lumped into "the cost of doing business" is tolerating a certain amount of crime.  We commonly hear of employee theft or shrinkage.  We hear of malingering and filing false worker's compensation claims.  Not every loss due to crime can be stopped but for the most part, they are confronted and mitigated everyday by professionals who work hard to protect their business from this financial erosion.  These issues exist as a result of criminal behaviors of individuals and to ignore these issues, would be ruinous. Anything less than a total concerted effort stop this behavior is not the norm. Unless, however, that effort to stop the behavior impacts market share. Take for example, the interesting decision by Microsoft to cease internal investigations related to theft for the sake of market share.

Investigation Compromised Business

Not long ago, Microsoft uncovered the theft of a source code for one of their products.  They were able to track down the source of the leak through an internal investigation.  The Microsoft investigators "cracked" the case by legally accessing a Hotmail account of someone involved in the scheme.  An ex-Microsoft employee was subsequently charged in Federal court for this theft of a trade secret.  Despite the investigative success, the case revealed Microsoft's access to and review of their customer's Hotmail account.  Despite this practice being the legal right of Microsoft, the appearance of backlash over the perceived privacy violation resulted in a policy change at Microsoft. So, instead of conducting their own internal investigations involving stolen property (intellectual or physical) the company "will refer the matter to Law Enforcement if further action is required."

Law Enforcement to the Rescue

By passing investigations along to law enforcement, Microsoft is banking the invasion of their customer's Hotmail accounts via search warrant will deflect any ill will toward the company as they would have to be compliant with the law.  This makes it sound better to the privacy concerned customer and Microsoft sees itself as being on the moral high ground of the privacy issue.  It really reveals how much Microsoft perceives privacy to be a critical market share driver.  This is where the trade-off for this policy change gets dangerous. Regardless of their motivation for the change Microsoft is also gambling that the public servants in Law Enforcement can adequately protect their intellectual secrets.  This is a tremendous vote of confidence for local law enforcement and hopefully, for Microsoft's sake, they have the talent and resources to do the job.

One Risk for Others

Even if law enforcement is up to the task, this shift in policy still leaves gaps. For one, Microsoft is potentially giving up critical time by passing this along. Law enforcement, no matter how much access they have, will still not be as quick to respond as company investigators.  Another issue would be this knowledge is now known to criminals. They know where the weakness lies and have gained valuable time to move information out of the company. Finally, and most importantly, what if a criminal act impacts the stability of a platform?  Microsoft may have the ability to stop this issue but because of an internal policy, they pass it to an outside source.  In the mean time, a critical event occurs and a system is compromised.  Hopefully, Microsoft built protections into their policies and procedures to prevent this from happening.

Win - Win?

In the end, "the cost of doing business" is a slippery slope especially when it comes to finding a balance between market share and tolerated losses.  It is revealing how privacy issues in the marketplace have altered this equation. What may be lost are the voices of those customers who would rather lose a certain level of privacy to ensure a stable service from a company that does not yield to criminals for the sake of market share.

Tuesday, November 12, 2013

Securing Your Business

Aligning security efforts with business goals sharpens results

Hindered by stale perceptions

For some business thinkers, security expenditures remain an overhead that falls into the category of "the cost of doing business".  But getting past the old standard of thinking of security as a necessary evil to embracing it as a valuable business asset means shaking off an outdated understanding of what needs protected. Security programs that can recognize new and developing threats do well to preserve their relevance.  But the programs which also tie in business acumen are that much more valuable.

It is only getting bigger

The industry expects operational security spending to continue to increase over the next 5 to 7 years. Reasons for this trend include the continued globalization of operations and work force growth.  There is also an increase in the frequency of disruptions encountered by businesses on many fronts. From agenda centric movements to domestic violence, these diversions consume time and money for businesses.

Security is just like any other business unit

Given the growth in security expenditures, it is evident that a more sophisticated view of security is required. Fortunately, aligning the operational needs of a business and its security requirements is no different than any other business evaluation.   The first step is to match security efforts with the goals of the business.  And once established, they need to be measured in order to manage their performance.  This is simple shift in thinking coupled with bringing security considerations to the boardroom can expand its value proposition beyond being compulsory. 

Experts in security must be business centric

To elevate security thinking to the point where it is considered a profitable endeavor it is first necessary to evaluate business vulnerabilities at a high level.  C-level thinkers need to synthesize diverse variables including financial goals, risk aversion, technology, market trends and ROI to come up with a risk profile for their company.  On a technical level, security consultants such as CSI must be able to understand the high level perception of the risks and then apply the correct security solution to the problems.  Additionally, the solution must be measurable so it can be proven to be worthy over time.  It must also be dynamic in that it can change (rapidly if necessary) to meet the ever changing risk landscape.
Picture from sporcle.com

Expanded security coverage

While turnstiles and night watchmen will probably always exist, modern security thinking goes well beyond this paradigm.  The competitiveness and complexity of business today has pushed security professionals into new disciplines.  Here are a few examples of critical business needs that are now met by security programs:  
  1. Protection of intangible assets. More companies than ever are defined by their intellectual property or their brand reputation.
  2. Natural and man-made disasters. A recent study revealed that almost half of all major companies do not have a business continuity plan.
  3. The remote workforce. Technology has freed these workers from a controlled office setting.  Companies must now consider the safety and security of their mobile human assets.  
  4. Business partner risk sharing. Interdependent companies need to communicate and coordinate security responsibilities. This is especially acute in supply chain oversight.  
  5. Security Technology. Data in the form of camera analytics and biometrics do more than protect.  Businesses now leverage intelligence gathered from these platforms.
Savvy business thinkers will find value in their security programs by turning their efforts into a competitive advantage.  But once security has a seat at the table, it is no longer business as usual.  Dynamic results will be demanded as programs must not only protect the business but prove their worth though measurable outcomes.