Pages

Showing posts with label organizational goals. Show all posts
Showing posts with label organizational goals. Show all posts

Wednesday, October 8, 2014

Motivation, Engagement, and Leadership

One of the hardest things about my job is maintaining engagement and motivation in my team.

I'm sure many of you are nodding in agreement.  People are the hardest part of any leadership job, and for people like me who rose through the technical ranks people are a whole lot different to engage than routers, switches, servers, and SANs.

I know everyone has a story about the temperamental server that, if ignored, would slowly fail but with a little TLC and a periodic check would run happily forever.  There may even be a lesson inside those experiences.

My CIO is one of those rarefied technology people who can actually give a sense of warmth, closeness, and caring.  You can feel that she sincerely cares about the people around her.  In our staff meetings, we make time to talk about our company and organizational culture; the company's social contract and our perspectives on what the contract is telling us.  A few weeks ago she shared this link with us and asked for our perspective:

Is Your Company Culture Affecting Your Employee Engagement?

I read this article several times, picking up on new ideas both from the article and how companies are following, or not following, the principles presented.  As I thought about this article and looked back on back to presentations from CEOs, I remembered one of Flip Flippen's mantras for The Flippen Group: No organization can rise above the constraints of its leadership.

Employee engagement is inherently limited by the personality of company leadership.  That made me think about some of the ideas I'd heard from CEOs:

"A" people hire "A" people.  "B" people hire "C" people.

This CEO explained their perspective that "A" people were the top-level performers in the organization, the 5% doing 50% of the work.  "B" people were the 9-to-5 workers, the one who punch the clock and get a paycheck, fulfilling and even excelling at their duties but generally not exceeding them.  "C" people were the one barely scraping the minimums of their duties in quantity or quality, resulting in the need for additional work to complete tasks.

The CEO's view was that "A" players wanted to be surrounded by other "A" players, focused on accomplishing goals through whatever investment needed to get there.  "B" players didn't want to be shown up, such they would hire "C" players to ensure they looked good compared to others.  "C" players were of limited to no value.

He coached his leadership team to focus on the "A" people, work to eliminate the "C" people, and limit the influence of the "B" people.


I want my leaders to be aggressive, taking business away from our competition.

This CEO expressed that his ideal leadership team was made up of highly competitive, highly aggressive leaders.  He wanted a leadership team focused on wresting away business from the competition, taking calculated risks to attack the sales positions of competition and gain favorable market share.

This leader made it a point to talk about business ethics, focusing on the need to earn and retain business based on acceptable practices, a point he recognized as necessary given the highly aggressive nature of his team as they used (almost) any means necessary to gain the upper competitive hand.


I want Type A people, self-starters who seize problems and push people to drive them to conclusion.

This CEO explained that Type A personalities were the ones that got things done.  He coached his leadership on how to be Type A, how to identify a Type A player, and how to develop and promote Type A players into leadership positions.  It was his goal to build a team full of Type A people who wouldn't pause in the pursuit of company objectives.

Type B players, by contrast, were needed to do daily work, but the lack of pure drive for accomplishment meant they were best relegated to less senior positions.  The CEO coached his leadership to help develop assertiveness and need for achievement as a requisite for advancement into leadership of the company.


So, to be honest, I'd been affected by each of these presentations.  I let myself be somewhat swept up in their (much better presented) points of view.  Organizations are all about accomplishing goals, achieving new things.  By extension, clearly things like drive, assertiveness, aggressiveness, were the traits that made such possible.

I reflected on myself and others - am I an "A" player?  Are my team "A" players?  Am I aggressive enough?  Am I Type A?

For those of you at home keeping score:
- "A" Player: Not my call, but my leadership consistently says "yes"
- Aggressive: I have a small aggressiveness pool, which I tend to only I feel backed into a corner.
- Type A: No.  I'm a Type B.  One word: reflective.

My CIO sends this article, and I start to think.  29% of workers are actively engaged.  What percentage of the population is an "A person", "Aggressive / Competitive", and "Type A" (or could coach themselves to be close)?

I bet it's less than 29%.

I bet most companies are burning the Type A wick to cover their big productivity needs; a select few companies are figuring out how to unlock the other 71%+.

The comments from those CEOs show how a leader can hold back an organization.  You can't build a team of high-drive, high-aggressive, high completion-oriented people and expect it to stick together.  Such organizations are powder kegs; the explosions can be somewhat directed to rapidly accomplish a goal, but the harm the explosions cause results in those organizations splintering and failing to produce long-term results.

Start-ups are a great example.  Sudden bang, then wholesale replacement of staff and leadership to turn rapid initial progress into long-term value.  Failure to bring in long-term, sustainable staff will reduce value to the point of either company failure or acquisition for intellectual property rather than inherent value.

No one wants to buy a company that relies solely on overworking and stressing staff to accomplish its goals.

Life is a marathon, not a sprint.  So it is, or should be, in business.  Sprints may deliver an initial victory - assuming the finish line is close enough - but the marathon runner will ultimately surpass the sprinter's accomplishments and deliver victories over and over again.

The article made me realize that the long-term success of a company really comes down to the diversity of its leadership, a diversity that must be as broad as the people who work for that leadership.  Each employee needs different treatment and handling to coax the best out of each of them, and only complete appreciation and understanding will accomplish that goal.

So what does this mean?

The value of an individual is not based on easy-to-define categories.  There's no single magic formula for a high-performance team, or a high-performance individual - because there's no single formula for a person or team who can transform to be high performance.

The magic is awareness.  Be aware of the strengths and limitations of each employee.  Be aware of what motivates each employee.  Be aware of how each employee reacts and responds to work, life, and circumstance.

Be aware of how your statements and actions influence your employees; in other words, be aware of how your leadership may be inhibiting the growth and future of your employees.

Stay engaged with your team.  Build a means to communicate.  Use that opportunity to give feedback, good and constructive.  Use each individual's strengths to help them grow, adapt to manage their vulnerabilities to limit their impact on the future.

And don't be part of their problem.  No organization can rise above the constraints of its leader, and no member of a team can rise above the constraints of their organization.

Wednesday, June 25, 2014

Focus on Fundamentals

Ok.  Let's face it.  The fundamentals are hard.  They're also boring.

They're also fundamental; they're the foundation.  Nothing can survive (long) without a foundation, and success will ultimately be limited by the limitations of the foundation on which that success is built.


In bicycling, our foundation is called the "base".  Base is earned through long miles in the saddle riding at a consistent and moderate pace, repeated over and over.  The typical training plan has 2-3 months of this stuff, mile after mind-numbing mile, as much as 3-4 days a week, with length based on how long races will be later in the year.  60 mile races?  4+ hours on the bike getting in base.


So, yeah, it's hard, and it's boring.


Bicycling, and Information Security, are both like building a pyramid.  If you want to go faster, ride longer, you need to build a wider base first.  You need a solid foundation, one that will support you when the time comes to drive a break 70 miles into a 100 mile race.


Information Security is the same.  If you want to deliver better protection, higher capability, you need to ensure you have a complete and supporting foundation - fundamentals.  If there's cracks or missing sections, there's room for the whole system to collapse under the weight of the stacked stones.

That raises the (obvious) question: what is fundamental to information security?  You have to have Anti-Malware.  And a Firewall.  Mix in some Intrusion Detection, log analysis.

Fact: none of those are fundamental.

Seriously.  You don't need this.

Put down the pitchforks for a moment.  Use of technologies like these are absolutely required, they just don't make up the foundation of a solid information security program.


So what does?


The National Institute for Standards and Technology (NIST) has put together some excellent documentation about managing information technology and information security.  One of their recent products is the CyberSecurity Framework, a product that provides a clear and executable map to measuring information security risk in a practical and illustrative way.


One of the key components of NIST's model is the list of core functions: Identify, Protect, Detect, Respond, Recover.



The Sequence of Core Functions - Each Drives the Next

These are sequential risk-reduction, information security management functions.  Investment only provides mitigation to the right, such investment is best served further to the left.  That means your foundation is the item to the left: Identify.



You can only act on what you've delivered.
Stealing liberally from NIST's documentation, this is what Identify means:

Develop the organizational understanding to manage cybersecurity risk to systems, assets, data, and capabilities

Understanding is fundamental to information security, the level of understanding is the ceiling for any information security program.  And understanding is hard, we always want to fast forward past it to get on to the sexy part of information security (if such a thing exists).

But you cannot secure that which you do not understand.  So let's dive in:



Understand Business Strategy


Information Security cannot operate without alignment with business purpose and strategy.  Use this knowledge to capture (or develop) a list of Threats that apply to the business model, vulnerabilities of the business based on the line of work, then cross to find enterprise class risks.  It is here that technology and information risks can be latched.


This is where we'd capture "Risk Tolerance", and a good place for a short soap box.  Risk tolerance should be a dying term as it's typically used in place of "willing ignorance": a willingness to accept risk due to perception the risks can't manifest (i.e., don't apply).  Risk tolerance should be a business case, financial-driven decision based on potential losses and impact of manifest risk.  But I digress.


This is where the information security program will take root and where it'll find reliance and support as it delivers business cases for risk reduction; the Why of Information Security.



Establish Management Intent

Utilize the knowledge generated in understanding the business strategy to establish over-arching management intent.  This starts with the Security Policy; the policies, procedures, and standards designed to deliver controls that orient to the risks the organization faces. 


The quickest, easiest way to establish intent is to select a control framework and write it into Policy and Procedure.  This becomes a simple process of selecting controls that relate to the risk posture of the company, setting standards within those controls according to the level of risk, and establishing metrics and measurements to enable assessment of compliance to controls.


Intent should also integrate Information Security into other organizations, enabling upstream and downstream delivery of controls throughout the organization.  Information Security has cross-organizational concerns in Vendor Management, Human Resources Management, among others.


The intent of Intent is to establish the rules for how security will operate, aligned to the risks and strategies of the company; the How of Information Security.



Capture Inventory


This isn't a real Datacenter.

This is where the rubber meets the road in the statement "you cannot secure that which you do not understand."  In practical terms, this inventory is the list of stuff that needs to be protected.  There's a lot to think about, but they fall into a few broad categories with the depth of detail driving the maturity of downstream controls.  This is the "What" of Information Security.

Design and Architecture Assets: Network and system diagrams, the "as-built" for the technology system as a whole.

Physical Assets:  There are the traditional technology devices with a few added items.  Servers, laptops, mobile devices, printers, network equipment, security equipment.  Each should be uniquely identified via some electronic means, each should have pertinent information such as responsible part, purpose, and similar.


Service Assets: These are the delivered technologies supporting business functions, such as the HRMS, FMS, ERP, along with smaller services such as Reporting, Project Management, and other solutions.  These should have owning business organizations and/or responsible individuals associated to each.

Integration Assets: Flow diagrams showing the movement of information between services (information systems) and the relationships of business processes to information flow.

Software Assets: The list of approved operating systems and software packages utilized on the environment.

Information Assets: The types of information utilized and where they are intended to be located with owning business organization and/or responsible individuals.

Identity Assets: The complete list of individuals who should have some level of access to the technology systems with information on their role and area of responsibilities.

Access Control Assets: The complete list of defined access credentials for each service and system, and a complete list of the roles and privileges provided within each.

(It's hopeful, and hopefully likely, that the Identity and Access assets are already linked; else, this is low hanging fruit.  Get it done.)

Threats and Vulnerabilities: The last two are a little less palpable but no less important, the list of Threats and Vulnerabilities within the organization.  These are necessary to create a risk profile for the assets inventoried above, enabling decisions on how to deliver protection, detection, response, and recovery in appropriate measure.

Threat Inventory: A list of known potential sources of impact to the organization's technology systems.  This list should be based on the inventory generated above; i.e., threats that are specific to the technologies and services being consumed; and based on how the business is operated, linking threats to parties that may be interested in disrupting the services provided, such as organized crime for retail.

Vulnerability Inventory: A list of known vulnerabilities within the environment.  This should be developed by both technology (scanning) and research, and contain vulnerabilities that impact information security and the application of controls over technology such as environmental and human influences.


It is all about the fundamentals; it's not possible to implement an information security program without having a strong grasp on what needs to be secured, why it needs to be secured, and how it should be secured.  The Identification process provides the knowledge needed to define the necessary technical and procedural mechanisms of information security.


Sorry.  Obligatory.
Without having a solid foundation, vulnerability manifests in cracks, eventually manifesting as failure in controls and, possibly, failure in the information security program.

Sometimes in spectacular fashion.  The pyramid comes crashing down because of a single failed stone.

The investment in time in fundamentals will lead to a more successful program.  Take the time to figure out the gaps, act on them, and the program will be better for it.

Tuesday, May 13, 2014

On Intent

My first blog, my first post.

I've intended to start a blog for a long time, but I always found a way or reason not to do it.  I can be easily derailed; the last stutter before I started this blog was whether I would compose under a pseudonym or my real name.  I believe what I say, and such intend to be open and public about my thoughts; yet, as you can see, I decided not to follow my intent and have gone somewhat incognito.

Before that it was the decision which blog service to use.  I intend to use easiest to access, easiest to use service; instead, I found that Google had a blog engine and just ran with that.  Naturally, that means if you hunt around enough on Google+, you'll find me.

I intend to also make everything easy, which by my nature makes it all difficult at the same time.

I guess I live intentionally; to coin a phrase.  Sometimes I live intentionally to do what I intend; other times I intend to not to what I intended, break the mold and live outside what I would expect of myself.  All that means is that when I get outside the box I'm still walking familiar paths.  I'm still in the box.

Much of my life is spent in the idea of "intent".  The work I do can be described as "setting intent", the concept that I describe the attainment of certain, high level organizational goals, guiding the activities, means, and methods in accomplishing those goals.

I also measure (read: police) our attainment of those goals, but that's a conversation for another time.

The idea of organizational intent, leadership intent, is a powerful one.  Simple statements made in a single breath by someone with positional authority becomes work responsibilities for a team of staff.  Intent sets the stage for everything; it puts the focus on what is important, and de-emphasizes what isn't.  It tells us where we're going, why we're going, what we're going to, and how we're getting there.

Who: those dedicated to setting and achieving that intent.  Are you in?

Intent is powerful.  It provides meaning, purpose, it gives definition to what we do and understanding to why we do it.  And it applies everywhere.  I am an avid bicyclist; I intend to be faster than I am today, stronger than I am today.  That intent drives me, sometimes even consuming me.  I am unwilling to accept my limitations.  I am unwilling to live within the confines of my current abilities.  I intend to break through; get a few more seconds on the rivets before I pop (and then a few more); get a few more watts out of tired legs; stay on the wheel of that competitive racer for just a few more pedal strokes.

Intent is powerful.  It's also dangerous.

All too often, we fail to set or properly describe our intent.  We never know what we're trying to accomplish.  We never know what we need to accomplish it.  We never know how to get help, and others don't know what we're doing to offer to help.  Rudderless and windless.

When we set intent, we still must be intentional about it.  Intent is directive: it can be collaborative, engaging, community; or it can be individual, solitary; but must be a decision, and it must be action.  Intent is worthless when there is no decision to act; nothing accomplished, frustration results.

Spirits fly on dangerous missions
Imaginations on fire
Focused high on soaring ambitions
Consumed in a single desire
In the grip of a nameless possession --
A slave to the drive of obsession --
A spirit with a vision is a dream with a mission...
Rush, Mission

Together we'll find out how dangerous intent is, at least with regards to my intent to start a blog.  I intend to make this an interesting read, covering a variety of subjects within my interests.  I'll range from cutting-edge science (less about the field of science, more about significant discoveries) to application of technology, fitness and nutrition, musings on other subjects that might strike my fancy.  Oh, and bicycling; there'll be plenty of opportunity to read about my passion for the bicycle.

I don't intend to cater to everyone's interests, but rest assured if someone suggests a subject I'll have a few words to share about it.

Thanks for taking the time to read my inaugural post, I hope you'll join me as we start this journey.

-- TechieRoadie