<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
>

<channel>
	<title>The Security Catalyst&#187; Martin Fisher</title>
	<atom:link href="http://www.securitycatalyst.com/author/martinfisher/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com</link>
	<description>Michael Santarcangelo delivers Awareness that Works™</description>
	<lastBuildDate>Tue, 06 Jul 2010 08:52:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<!-- podcast_generator="Blubrry PowerPress/1.0.9" mode="advanced" entry="normal" -->
	<itunes:summary>Michael J. Santarcangelo, II is a human catalyst. An expert who speaks on information protection â including compliance, privacy and awareness â Michael energizes and inspires his audiences to change the way they protect information. His passion and approach gets results that change behaviors. 

As the voice of optimism in an industry of doomsayers, Michael has recently completed his first book, Into the Breach (www.intothebreach.com), which provides the wisdom and answers executives need to defend their organization against breaches while discovering how to increase revenue, protect the bottom line and efficiently manage people, information and risk.

In this podcast series, Michael shares ideas, research and strategies for your success. 
</itunes:summary>
	<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://www.securitycatalyst.com/tsc_icon.png" />
	<itunes:owner>
		<itunes:name>Michael Santarcangelo | The Security Catalyst</itunes:name>
		<itunes:email>michael@securitycatalyst.com</itunes:email>
	</itunes:owner>
	<managingEditor>michael@securitycatalyst.com (Michael Santarcangelo | The Security Catalyst)</managingEditor>
	<copyright>Copyright 2009 The Security Catalyst. All Rights Reserved. </copyright>
	<itunes:subtitle>A catalyst for engaging, empowering and enabling individuals; turn insiders into allies who reduce business risk!</itunes:subtitle>
	<itunes:keywords>security, risk, privacy, compliance, breach, awareness, training, catalyst, confidentiality, integrity, availability, cissp, cism, cisa, cpp</itunes:keywords>
	<image>
		<title>The Security Catalyst&#187; Martin Fisher</title>
		<url>http://www.securitycatalyst.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securitycatalyst.com</link>
	</image>
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Technology" />
	<itunes:category text="Education" />
		<item>
		<title>Leading from the Front: Casting Vision &#8211; The Foundation of Effectively Disrupting the Organization</title>
		<link>http://www.securitycatalyst.com/leading-from-the-front-casting-vision-the-foundation-of-effectively-disrupting-the-organization/</link>
		<comments>http://www.securitycatalyst.com/leading-from-the-front-casting-vision-the-foundation-of-effectively-disrupting-the-organization/#comments</comments>
		<pubDate>Wed, 31 Mar 2010 10:15:54 +0000</pubDate>
		<dc:creator>Martin Fisher</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[leadership]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vision]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2867</guid>
		<description><![CDATA[By Martin Fisher Think back to the best leader you&#8217;ve ever followed. For me, it was my Professor of Military Science when I was in ROTC during my college stint. Look at him and at first you&#8217;d see him as an “average” Army officer. He&#8217;d had a bunch of good assignments, some not so good [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fleading-from-the-front-casting-vision-the-foundation-of-effectively-disrupting-the-organization%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fleading-from-the-front-casting-vision-the-foundation-of-effectively-disrupting-the-organization%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>By Martin Fisher</strong></p>
<p>Think back to the best leader you&#8217;ve ever followed.</p>
<p>For me, it was my Professor of Military Science when I was in ROTC during my college stint.</p>
<p>Look at him and at first you&#8217;d see him as an “average” Army officer. He&#8217;d had a bunch of good assignments, some not so good assignments, and was finishing up his career teaching young men and women the finer art of leadership. If you only knew him casually you&#8217;d be wondering why all of these young men and women were so dedicated to the program, the Army, and (in a lot of ways) to him.</p>
<p>The reason I did was simple: the Major was able to describe a vision to me of what the Army could be, what I could be, what all of us – together – could accomplish. He told the stories of what he felt we could do in such clear and compelling language that we were enthusiastic to do some pretty (in retrospect) amazing things. Things that, outside of the context of the vision, made absolutely no sense&#8230;like jumping out of perfectly good airplanes while still in flight&#8230;like marching through mud, dust, and pollen for kilometer after kilometer&#8230;like lying in cold rain for hours waiting for the &#8216;bad guys&#8217; to show up&#8230;and so on and so on.</p>
<h3>Casting Vision: It&#8217;s Not Just A Sales Job</h3>
<p>Without a compelling vision a leader is hamstrung.</p>
<p>They can push and pull the levers of the team, they can make adjustments to the machine that is the team – but they cannot get the team to reach it&#8217;s full capability. Without a compelling vision the leader is simply reacting to events instead of shaping the events and circumstances. The leader, without a vision, is not really leading at all.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p>Just to be clear – we&#8217;re not talking about the simple “performance management” task of assigning goals and objectives to individuals and ensuring that there is a cohesive flow to them. We&#8217;re not talking about “mission statements” or “purpose statements” (although they may enter the conversation later). We&#8217;re not even talking about how to justify the capital expenditure needed to get the “new system” online.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p>When we talk about casting vision we&#8217;re talking about being able to tell a story that accomplishes some very specific goals.</p>
<p><span style="text-decoration: underline;"> </span></p>
<h3>Acknowledge What Is</h3>
<p>Any vision must start at the beginning.</p>
<p>You must be able to acknowledge the good, the bad, and the ugly about the current situation. You have to be completely honest about where you are coming from. To do otherwise begins with a foundation that cannot support even the most compelling vision.</p>
<p>Vision, built on false assumptions or denial of the past, collapses in on its own weight. That being said, don&#8217;t flagellate yourself (or the team) unnecessarily either.</p>
<p>As Sergeant Joe Friday says “Just the facts”.</p>
<p><span style="text-decoration: underline;"> </span></p>
<h3>Describe What Is To Come</h3>
<p>Vision, at it&#8217;s simplest, is a story describing how things should (or can) be.</p>
<p>The story needs enough detail without going to deep. It needs to be lofty and idealistic without sacrificing a real sense of reality. The story needs to reach out to your team and show them that they can be much more than what they are today.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p>But a simple vision is, many times, not enough.</p>
<p>Vision needs to take into account what you want your team to accomplish and also show how that plays into the goals and aspirations of the larger team. Vision, especially for larger teams, needs to be large and sweeping and dramatic and dynamic.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p>Most importantly, the vision must be Yours.</p>
<p><span style="text-decoration: underline;"> </span></p>
<h3>Demonstrate Your Belief</h3>
<p>Only you can effectively get your vision off the ground.</p>
<p>If you do not share it convincingly, if you cannot show that you believe it in the deepest fiber of your being, if you cannot demonstrate you are willing to sacrifice personally to make the vision appear then: You. Will. Fail.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p>Think back to when you knew the boss was simply mouthing words that the boss thought you wanted to hear. Recall when you could tell exactly which motivational book the boss was parroting. Remind yourself of all those times that you knew (and I mean, YOU KNEW) the boss wasn&#8217;t believing what they were saying.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p>Do you want to be that?</p>
<p><span style="text-decoration: underline;"> </span></p>
<h3>Make The Mental Shift Yourself First</h3>
<p>Once you&#8217;ve communicated the vision to your team you must make the mental shift in all your communications, thoughts, and presentations and ensure that the tenets of your vision are constantly and consistently communicated.</p>
<p>You need to make your vision, no matter what it is, the focal point of all your activities. You must be “living the vision” every day in every way.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p>Once your team sees that you believe, once they know that you are not just “saying words”, once they realize that the vision is for real – then you can move on to the next (and, to me, most fun) step.</p>
<p><span style="text-decoration: underline;"> </span></p>
<h3>Help The Team See And Act On The Vision</h3>
<p>Once the team sees that you believe and that you are willing to act on the vision they will be prepared to begin really looking at the vision the way you do and will start to act on it in ways that they think will help bring it about.</p>
<p>Your job is easy – you get to be a cheerleader, mentor, and disciplinarian all in one. You get the chance to reinforce the vision with team members and experience what I think is one of the coolest parts of leadership: you get to see your team members grow as people and you get to see your team grow in it&#8217;s capabilities.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p>But that growth doesn&#8217;t “just happen”&#8230; In our next episode we&#8217;ll talk about how to take your vision and use it to build a stronger team.</p>
<p><span style="text-decoration: underline;"> </span></p>
<p><span style="text-decoration: underline;"> </span>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fleading-from-the-front-casting-vision-the-foundation-of-effectively-disrupting-the-organization%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fleading-from-the-front-casting-vision-the-foundation-of-effectively-disrupting-the-organization%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/leading-from-the-front-casting-vision-the-foundation-of-effectively-disrupting-the-organization/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Leading from the Front: Bringing Planned Disruption To The Organization</title>
		<link>http://www.securitycatalyst.com/leading-from-the-front-bringing-planned-disruption-to-the-organization/</link>
		<comments>http://www.securitycatalyst.com/leading-from-the-front-bringing-planned-disruption-to-the-organization/#comments</comments>
		<pubDate>Tue, 23 Feb 2010 11:16:11 +0000</pubDate>
		<dc:creator>Martin Fisher</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[leadership]]></category>
		<category><![CDATA[management]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2750</guid>
		<description><![CDATA[By Martin Fisher What is the most important job/function of a leader? Inspire the team? Use resources effectively? Make tough decisions? Set an example? Develop others? All of these are good answers and are important things for a leader to be sure they are accomplishing in an organization. But none of these is the most [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fleading-from-the-front-bringing-planned-disruption-to-the-organization%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fleading-from-the-front-bringing-planned-disruption-to-the-organization%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><strong>By Martin Fisher</strong></p>
<p>What is the most important job/function of a leader?</p>
<ul>
<li>Inspire the team?</li>
<li>Use resources effectively?</li>
<li>Make tough decisions?</li>
<li>Set an example?</li>
<li>Develop others?</li>
</ul>
<p>All of these are good answers and are important things for a leader to be sure they are accomplishing in an organization.</p>
<p>But none of these is the most important answer.</p>
<p>The number one job of a leader – the reasons leaders exist – is to bring change to organizations.</p>
<p>“That&#8217;s silly!” – is a common reply I hear when I make the statement.</p>
<p>“Leaders only bring change if change is what the organization needs. They assess the situation, analyze their resources, and only make changes if there is a reasonable chance of the change improving the organization.”</p>
<p>My response to that, in the words of my teenaged daughter, is  “Pssh!”.</p>
<h3>Change:  If you aren&#8217;t doing it, you&#8217;re doing Leadership wrong.</h3>
<p>Effective leaders are never satisfied with the status quo.</p>
<p>Of course, leaders will continue to celebrate good performances, boast the capabilities of their team, and value the circumstances they find themselves in. But more, a leader has the ability to see and accept the organization as it is and form a clear vision for how the organization can (and should) be.</p>
<p><strong>Leadership, a friend once told me, is the where the science of the possible meets the art of the dream. </strong></p>
<p>Leadership is the nuanced ability to see what could be and come up with the plan to create it out of what is already in existence. Effective leaders almost instinctively realize that slow and incremental change is a prison and that the only escape is dramatic and disruptive change.</p>
<h3>Leadership is “Disruptive change?”</h3>
<p>That&#8217;s crazy talk!</p>
<p>Look at all the people who lost or almost lost everything to disruptive change: New Coke&#8230;Webvan&#8230;the Pontiac Aztek&#8230;Hooters Air&#8230;</p>
<p>Only a fool or a liar would say there is no risk to disruptive change. But there are things you can do to minimize that risk:</p>
<h3>Think, Rethink, and Rethink Again</h3>
<p>The leader has to be completely honest with themselves about the environment they operate in, the resources available, and the chances of the disruptive change actually taking effect.</p>
<p>This thinking must be complete, honest, and is not done until the leader understands the environment completely.</p>
<p>The leader then needs to find a small group of trusted other leaders that they can toss the idea to with the intent of these other leaders shooting it so full of holes that almost nothing remains.</p>
<p>Whatever is left &#8212; whatever survives the onslaught &#8212;  forms the base of the next round of thinking. Once the thinking is done the thoughts have to be able to be put into simple and actionable statements:</p>
<ul>
<li>Changing the organizational structure? Then create a org chart to talk to and demonstrate.</li>
<li>Changing processes?  Then show a picture that details before and after with the benefits.</li>
<li>Changing the mission? Then create a succinct mission statement and show what is being changed and why.</li>
</ul>
<p>Whatever the change, come up with a picture (1 slide, please, not a full deck – that&#8217;s for later) that can be used to explain the “why and how” of the change.</p>
<h3>Talk the Team Through The Change</h3>
<p>The worst thing to do once the thinking is done (you think) and the picture is ready is to simply dump the change on the team.</p>
<p>One of the biggest (and, sadly, most common) mistakes leaders make is to forget that, while the leader has been thinking through this change for weeks, the team just got told of the change and needs time to process and unpack it. They deserve the chance to see what the change is, how it impacts them, ask questions, and get answers.</p>
<p>The effective leader is able to effectively communicate the change to the team.</p>
<p>Using the picture of the “how and why” to show the team how the change will impact them and how it helps getting team goals accomplished.</p>
<p>Then step back, listen, and engage in the conversation. Remember – the team knows the system and might reveal something to tweak the change. In fact, this could be the difference between success and failure.</p>
<p>“That sounds an awful lot like sales! If I wanted to do sales I&#8217;d of taken that job with my cousin at the furniture store!”</p>
<h3>Is it like sales?</h3>
<p>Well, if “sales” means influencing people to see things from different perspectives – then yes.</p>
<p>But I prefer to think of it as “Casting A Vision” – which is what we&#8217;ll talk about next time.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fleading-from-the-front-bringing-planned-disruption-to-the-organization%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fleading-from-the-front-bringing-planned-disruption-to-the-organization%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/leading-from-the-front-bringing-planned-disruption-to-the-organization/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Solution: Leading People, Managing Objects, and Accomplishing Goals</title>
		<link>http://www.securitycatalyst.com/the-solution-leading-people-managing-objects-and-accomplishing-goals/</link>
		<comments>http://www.securitycatalyst.com/the-solution-leading-people-managing-objects-and-accomplishing-goals/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 11:00:48 +0000</pubDate>
		<dc:creator>Martin Fisher</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[career]]></category>
		<category><![CDATA[change]]></category>
		<category><![CDATA[leadership]]></category>
		<category><![CDATA[teamwork]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2687</guid>
		<description><![CDATA[by Martin Fisher Those who know me have come to expect me to “correct” them whenever they say “manage people”. “Objects are managed, people are led,” is my usual retort. Sometimes I am met with a blank look, sometimes with a exasperated grimace, and sometimes (and not nearly often enough) by a questioning stare. “What?” [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-solution-leading-people-managing-objects-and-accomplishing-goals%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-solution-leading-people-managing-objects-and-accomplishing-goals%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><strong><a href="http://www.securitycatalyst.com/wp-content/uploads/2010/01/leader.jpg"><img class="size-full wp-image-2689 alignright" title="leader" src="http://www.securitycatalyst.com/wp-content/uploads/2010/01/leader.jpg" alt="" width="300" height="224" /></a>by Martin Fisher</strong></p>
<p>Those who know me have come to expect me to “correct” them whenever they say “manage people”.</p>
<p>“Objects are managed, people are led,” is my usual retort. Sometimes I am met with a blank look, sometimes with a exasperated grimace, and sometimes (and not nearly often enough) by a questioning stare.</p>
<p>“What?” the quizzical friend often asks. “There&#8217;s not a difference worth mentioning.”</p>
<p>Nothing could be further from the truth and nothing, in my opinion, has done more to impede the progress of the information security profession.</p>
<p>The abject failure of leadership, from senior ranks, through middle management, to front-line supervisors has led to a culture that glorifies “meeting expectations”, extols the virtue of “accomplishing goals”, and is satisfied with “getting the job done”. Don&#8217;t get me wrong – these things are important – but they miss the vital difference: That a dynamic leader can take a group of people and almost always “exceed expectations”, “surpass goals”, and “get the job done better” and still have a happier team and more satisfied customers.</p>
<p>“How does that happen?” asks the still-quizzical friend, “Isn&#8217;t meeting expectations what we&#8217;re here for? Isn&#8217;t that enough?”</p>
<p>Sadly, it isn&#8217;t enough.</p>
<p>All people appreciate leadership. Everyone inherently wants to belong to a team that accomplishes exceptional results. Nobody wants to be in an organization that doesn&#8217;t excel.</p>
<h3><span style="font-family: Arial, sans-serif;">The key to this is the Leader.</span></h3>
<p>Leaders determine, by applying their leadership talents, just how far the team will go. Setting a goal and managing to that goal ensures that any additional capability is forever lost. Managing to a goal guarantees that the exceptional capability that is native to any team will be lost in a desire to just do “enough”. When we manage people, instead of lead them, we are condemning ourselves to forever experience sub-optimal results, never knowing what could have been accomplished.</p>
<p>“But my team is happy and my customer is satisfied. Doesn&#8217;t that mean I&#8217;m succeeding?” asks the friend as their frustration with the conversations grows. “You&#8217;re making more out of this leadership thing than it really is, aren&#8217;t you?”</p>
<p>This is the point where the friend has reached an almost Matrix-esque moment&#8230;</p>
<p>“Take the blue pill and this conversation ends. Everything goes back to the way it was and you can believe anything you want to believe. But take the red pill, and I&#8217;ll show you how you can take the leadership skills and talents you have and use them to transform yourself and your team. I&#8217;ll teach you how to truly get more done with more satisfaction.”</p>
<p>Which pill, my friend, will you take?
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-solution-leading-people-managing-objects-and-accomplishing-goals%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-solution-leading-people-managing-objects-and-accomplishing-goals%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/the-solution-leading-people-managing-objects-and-accomplishing-goals/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Leadership Challenge in Today&#8217;s Security Environment</title>
		<link>http://www.securitycatalyst.com/the-leadership-challenge-in-todays-security-environment/</link>
		<comments>http://www.securitycatalyst.com/the-leadership-challenge-in-todays-security-environment/#comments</comments>
		<pubDate>Fri, 11 Dec 2009 15:01:36 +0000</pubDate>
		<dc:creator>Martin Fisher</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[leadership]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2593</guid>
		<description><![CDATA[Management is doing things right; leadership is doing the right things. ~Peter Drucker Leadership. It&#8217;s talked about a lot in today&#8217;s information security conferences and books – but how much of it is really happening? Do we, as professionals, really embrace leadership and its inherent risks, rewards, and challenges?  Or, on the other hand, do [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-leadership-challenge-in-todays-security-environment%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-leadership-challenge-in-todays-security-environment%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p align="right"><em>Management is doing things right; leadership is doing the right things. ~Peter Drucker </em></p>
<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/hands_in.jpg"><img class="alignright size-medium wp-image-2594" title="Strength in Numbers" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/hands_in-300x211.jpg" alt="Strength in Numbers" width="300" height="211" /></a>Leadership. It&#8217;s talked about a lot in today&#8217;s information security conferences and books – but how much of it is really happening?</p>
<p>Do we, as professionals, really embrace leadership and its inherent risks, rewards, and challenges?  Or, on the other hand, do we really embrace the status quo with its inherent frustration, ennui, and demotivating drag?</p>
<p>Don&#8217;t get me wrong – leadership in any field is hard. I&#8217;ve led teams that have done such diverse missions as application development to firefighting to deploying the varied weapon systems in platoon of main battle tanks&#8230;and I have come the believe that effectively leading teams in today&#8217;s information security environment is one of the most difficult tasks I&#8217;ve ever taken on. As I look back, around, and forward I&#8217;ve made a few conclusions.</p>
<h3>Too much focus on the status quo</h3>
<p>I wish I had a nickel for every time I heard a “leader” describe a “good day” as one where nothing went wrong, nothing broke, and (truth be told) nobody even noticed she or her team were there.</p>
<p>Why?</p>
<p>I think because for so long the business has seen information security as the “Department of &#8216;No!&#8217;” that any time we fly above the radar we get smacked – or at least that&#8217;s the fear. If the systems run today just like they ran yesterday we call that a win and hope that they&#8217;ll work tomorrow just the same way.</p>
<p>This primal desire for the status quo is one of the most significant issues that chains down information security leaders today and it&#8217;s a topic I&#8217;ll address in more detail later – but suffice is to say that the status quo is rarely, if ever, the ally of a successful leader.</p>
<h3>Insane focus on a small group of miracle workers</h3>
<p>We have developed an almost unnatural dependence in information security on the work and thinking of small groups over very smart people. We rely on that small cadre of “go-to” guys to design and build our systems, respond to incidents, and help develop policies and procedures – but we rarely leverage that small group of folks to develop larger and larger teams of security oriented co-workers.</p>
<p>Whether we realize it or not we begin to live in a cultural echo chamber where everyone listens to the same presentations at the same conferences, reads the same blog post, and anyone who dares speak out against the conventional wisdom for any reason is suspect&#8230;</p>
<h3>The Status Quo of the Mojo</h3>
<p>The last major impediment I&#8217;ve seen is a synthesis of the first two. When you combine an overvaluing of the status quo with an over-dependence on small groups the almost inevitable outcome of a culture of “Please $DIETY, don&#8217;t let me screw this up!”</p>
<p>Leaders and their teams become so averse to anything negative (especially if it&#8217;s outside the accepted norms of the team) that the goal of the team slowly and immutably transforms from providing the best security for the organization to a goal of not wanting to be caught screwing anything up. This fear (and that&#8217;s what it is) leads teams to fall into the trap of wanting to build systems that are “perfect” and “unhackable” and resisting efforts to design or implement systems that don&#8217;t meet these standards.</p>
<p>The natural progression of this fear eventually leads to leaders and teams developing and attitude that is occasionally indistinguishable from despair. You&#8217;ll hear or read comments like “Why should I deploy $SecurityTechnology? HD Moore could hack it in 5 minutes. Rsnake could get root and own me 25 ways from Sunday.”</p>
<p>Rarely will the speaker or writer of such comments even seem to evaluate whether or not $SecurityTechnology will actually help the organization as part of a complete security plan. Defeat, as the philosopher said, is complete even before a shot is fired.</p>
<h3>What can we do about it?</h3>
<p>For the next dozen or so posts I&#8217;m going to address these issues head on and provide you with a (potentially) counter-cultural view of your role as a leader and hopefully challenge you to rise the amazing challenges we face today in information security.</p>
<p>The light you see coming at you – it’s not a train. Trust me.</p>
<p>What are your leadership goals for 2010? Share you challenges and successes in the comments…
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-leadership-challenge-in-todays-security-environment%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fthe-leadership-challenge-in-todays-security-environment%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/the-leadership-challenge-in-todays-security-environment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Have a workable plan, or else&#8230;</title>
		<link>http://www.securitycatalyst.com/have-a-workable-plan-or-else/</link>
		<comments>http://www.securitycatalyst.com/have-a-workable-plan-or-else/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 11:04:49 +0000</pubDate>
		<dc:creator>Martin Fisher</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[incident response]]></category>
		<category><![CDATA[leadership]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2168</guid>
		<description><![CDATA[by Martin Fisher As we continue to discuss the Basic Truths of Incident Response Leadership, we&#8217;ve briefly gone over the three Basic Truths as well as done a deeper analysis of  “Succeeding By Planning to Fail”. This brings us to: Basic Truth #2: Have A Workable Plan, or Else As an Incident Response Leader, one [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fhave-a-workable-plan-or-else%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fhave-a-workable-plan-or-else%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>by Martin Fisher<span style="font-family: Times New Roman; font-size: small;"><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/10/1072216_engineering_plans_1.jpg"><img class="alignright size-full wp-image-2447" title="1072216_engineering_plans_1" src="http://www.securitycatalyst.com/wp-content/uploads/2009/10/1072216_engineering_plans_1.jpg" alt="1072216_engineering_plans_1" width="300" height="225" /></a></span></p>
<p>As we continue to discuss the  Basic Truths of Incident Response Leadership, we&#8217;ve briefly gone over  the three Basic Truths as well as done a deeper analysis of  “Succeeding  By Planning to Fail”. This brings us to:</p>
<p>Basic Truth #2: Have A Workable  Plan, or Else</p>
<p>As an Incident Response Leader,  one of the most valuable parts of your role is to create, test, exercise,  and (when called upon) execute Incident Response Plans (IRPs).   IRPs run the gamut from a Post-It note on the wall listing contact phone  numbers, to plans that take up several 3-ring binders on a shelf somewhere.   Plans can be long or short, detailed or vague, paper or electronic,  automated or manual&#8230;you get the picture.  What makes a good plan  different from a not-so-good plan can be summed up in a few ways.</p>
<p>First, can you execute the  plan using only the resources that you legitimately would have access  to during the incident?  We&#8217;ve all seen plans that call for using  network analyzers that aren&#8217;t accessible to the organization or that call  for numbers of personnel that just don&#8217;t exist.  You may have written  plans that assume that the responding team has skills and experience  that your current team just doesn&#8217;t have (I have).  The key  is to map out the current skills and capabilities of your team and employ them  as best you can to meet the anticipated incident.</p>
<p>As you identify resources available  to you, it pays to be creative.  Can other teams identify folks  who could temporarily be available during an incident (think of it as an in-house  “volunteer fire department”)?  Do you have relationships with  designated outside incident response consultants? Do you have relationships  with local, state, or federal law enforcement?  In today&#8217;s business  environment, Incident Response Leaders need to be creative in identifying  resources that can assist during a response cycle.</p>
<p>Second, you have to test the  plan.  This sounds so intuitive, but many plans never get past the  written-down stage before they are needed in an incident, because no  leader stepped in to ensure that the plan would work as designed.   One of the most effective testing plans for an IRP is also the least  expensive – the simple “Talk Through”, where all of the designated  players sit at a conference table (pizza is optional, but highly recommended)  and talk through the plan, noting any foreseen problems or issues.   The team needs to be encouraged to not only point out potential problems,  but brainstorm solutions they can implement as-is since (as we talked  about in Basic Truth #1) you can only plan on the resources you have,  not the resources you want to have.</p>
<p>Plan testing needs to be redone  each and every time the plan is modified, or at some regular interval  (at least annually).  Testing can be announced or (my personal  favorite) unannounced.  The time spent testing can help the  Incident Response Leader assess not only the plan, but the team assigned  to execute it.  The feedback loop should encompass applications,  hardware, processes and procedures, as well as people.  Everything  is fair game.</p>
<p>Lastly, you need to continually  exercise your plan.  This, while not as intuitive as testing,  is something that many organizations fail to do, claiming “it&#8217;s too  hard” or “it&#8217;s too disruptive” or “it&#8217;s already been  tested, why should I do an exercise?”  Having performed incident  response on plans that have been exercised and plans that have  not, I can tell you with complete assurance that plans that have been  exercised are executed more smoothly, with fewer problems and a better  resolution.</p>
<p>Exercises can range from a  talk-through (similar to testing but without the constant feedback  loop) to a full-on exercise using live equipment.  Talk-through exercises  can help in quickly familiarizing a team with a new (or newly updated)  plan.  Talk-through work will also quickly point out assumptions  that, while seemingly accurate in testing, don&#8217;t fit the way  the incident response team works.  All other things being equal,  I believe that talk-through exercises offer the highest return for time spent  in any aspect of prepping for a incident.</p>
<p>Full-on exercises, as powerful  and complete as they are, can be very hard to accomplish.  Most  organizations cannot fully replicate their production systems (even  using virtual machines).  These exercises, when they can be done  at all, are usually done in development or test environments and generate  most of their value by allowing teams to actually assess and interpret  adversary actions and data.  These exercises are an Incident Response  Leader&#8217;s best chance to simulate the stress and activity of a  real incident.</p>
<p>Taking all of this into account,  it&#8217;s clear that the Incident Response Leader must be able to create,  test, and exercise an IRP to be able to effectively respond during the  inevitable incident.  By creating plans designed around available  resources, qualifying the plans with testing, and regularly exercising  the plan, you can ensure that you and your organization will be ready  when the inevitable incident occurs.</p>
<p>But it&#8217;s not over yet.  Once you&#8217;ve gotten this far you still have one vital task to accomplish.   We&#8217;ll cover that in the last article on the Basic Truths of Incident  Response Leadership.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fhave-a-workable-plan-or-else%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fhave-a-workable-plan-or-else%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/have-a-workable-plan-or-else/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Communicating with Your Boss</title>
		<link>http://www.securitycatalyst.com/communicating-with-your-boss/</link>
		<comments>http://www.securitycatalyst.com/communicating-with-your-boss/#comments</comments>
		<pubDate>Thu, 03 Sep 2009 11:00:16 +0000</pubDate>
		<dc:creator>Martin Fisher</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2170</guid>
		<description><![CDATA[by Martin Fisher As we looked at the first two of the three Basic Truths of Incident Response Leadership (“Assume You Will Fail” and “Have A Workable Plan”), we focused on activities that the Incident Response Leader does with the incident response team being led.  The final truth involves the other direction on the organizational chart&#8230; [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fcommunicating-with-your-boss%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fcommunicating-with-your-boss%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><span style="font-family: Times New Roman; font-size: small;">by Martin Fisher<a href="http://www.securitycatalyst.com/wp-content/uploads/2009/08/phone.jpg"><img class="alignright size-full wp-image-2303" title="phone" src="http://www.securitycatalyst.com/wp-content/uploads/2009/08/phone.jpg" alt="phone" width="300" height="157" /></a></span></p>
<p><span style="font-family: Times New Roman; font-size: small;">As we looked at the first two  of the three Basic Truths of Incident Response Leadership (“Assume  You Will Fail” and “Have A Workable Plan”), we focused on  activities that the Incident Response Leader does with the incident  response team being led.  The final truth involves the other direction  on the organizational chart&#8230;</span></p>
<p><span style="font-family: Times New Roman; font-size: small;">Basic Truth #3: Communicate  Your New Posture To Your Boss</span></p>
<p><span style="font-family: Times New Roman; font-size: small;">Once you&#8217;ve changed your mindset  about getting compromised, and you&#8217;ve reviewed, tested, and (hopefully)  exercised your plans, you are going to enter what is, for some people,  the most challenging Basic Truth – explaining what you&#8217;re doing to  your boss.</span></p>
<p><span style="font-family: Times New Roman; font-size: small;">Now, to be honest, you should  be regularly talking with your boss.  Organizations rely on middle  level managers to have frank, open, and honest discussions with more senior  leaders so that the organization&#8217;s efforts are aligned with the overall direction of the business.  The role of the Incident Response Leader is to not  only train &#8220;down&#8221; the organizational chain but to educate &#8220;up&#8221; the chain  as well.  The best way to do this is through regular conversations.</span></p>
<p><span style="font-family: Times New Roman; font-size: small;">The potentially tricky issue  is that you may have to “un-do” years of senior leader assumptions  about the incident response approach of the organization.  As difficult  as you may have found it to “Assume You Will Fail”, your boss –  who is probably much less directly connected to the daily realities  of incident response – is going to potentially be much more resistant  to change that assumes that problems will occur.  Hopefully you&#8217;ve  been hinting, nudging, guiding, and educating your boss during this  process, and this will not come as a surprise (because as a general rule, surprises  to your boss are a bad thing).</span></p>
<p><span style="font-family: Times New Roman; font-size: small;">As you educate your boss, you  may need to back up and re-teach some of the the basics of information  security and risk management.  Your boss may need some catch-up  on risk management and analysis.  If so, you&#8217;re in luck because  there will be that much less to un-learn.  Over several meetings, take the  time to ensure that your boss understands the “why” of what you&#8217;re  doing before you start into the “how” of what you&#8217;re doing.   Take the time to demonstrate to your boss that you not only understand  the business of Incident Response, but that you understand the business  of the organization and your role in it.</span></p>
<p><span style="font-family: Times New Roman; font-size: small;">Take the time to talk through  the benefits of “Assuming You Will Fail” by pointing out that  the organization cannot afford “perfect” security, but can afford  a quality incident response team to respond to and mitigate any issues.   Through discussion you can reframe, redefine, and provide your team  with realistic goals and objectives that senior leadership understands  and will buy into.</span></p>
<p><span style="font-family: Times New Roman; font-size: small;">This conversation sets you  up for the key discussion – formalizing the performance expectations  of you and your team; setting up and documenting exactly what  you will do and how you will be measured; and how (most importantly) the  organization will define your and your team&#8217;s success.  If you do this  well, you will have turned what previously would have be considered a  failure into what is a significant win for the organization, your  team, and you.</span></p>
<p><span style="font-family: Times New Roman; font-size: small;">Accepting and acting on the  Three Basic Truths of Incident Response Leadership will enable you to  better serve your organization, your team, and yourself.  I&#8217;d love  to hear from other IR leaders to see how this works for you.</span>
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fcommunicating-with-your-boss%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fcommunicating-with-your-boss%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/communicating-with-your-boss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Succeeding By Planning to Fail</title>
		<link>http://www.securitycatalyst.com/succeeding-by-planning-to-fail/</link>
		<comments>http://www.securitycatalyst.com/succeeding-by-planning-to-fail/#comments</comments>
		<pubDate>Thu, 20 Aug 2009 11:00:20 +0000</pubDate>
		<dc:creator>Martin Fisher</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2166</guid>
		<description><![CDATA[by Martin Fisher As security professionals, it&#8217;s hard to admit to to our bosses (and ourselves) that all of the work we&#8217;ve done to prevent compromise sometimes isn&#8217;t enough. We don&#8217;t like to think about the possibility that the money and time invested in technology might not prevent an incident from occurring. That&#8217;s why I [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsucceeding-by-planning-to-fail%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsucceeding-by-planning-to-fail%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>by Martin Fisher<a href="http://www.securitycatalyst.com/wp-content/uploads/2009/08/break_in_the_wall.jpg"><img class="alignright size-full wp-image-2224" title="break_in_the_wall" src="http://www.securitycatalyst.com/wp-content/uploads/2009/08/break_in_the_wall.jpg" alt="break_in_the_wall" width="300" height="224" /></a></p>
<p>As security professionals, it&#8217;s hard to admit to to our bosses (and ourselves) that all of the work we&#8217;ve done to prevent compromise sometimes isn&#8217;t enough.  We don&#8217;t like to think about  the possibility that the money and time invested in technology might not prevent an incident from occurring.  That&#8217;s why I proposed, in my previous article, the following basic truth for Incident Response Leadership:</p>
<p>Basic Truth #1: Assume You Will Fail</p>
<p>One of the issues we face in Incident Response is how we frame success and failure.  Too often we define our success with phrases like, “we&#8217;ve never been hacked” or, “our systems have never been breached”.  These phrases fly in the face of the fact that no system is 100% secure.  They dismiss the fact that a sufficiently motivated (or lucky) intruder can get in.</p>
<p>So, re-framing and redefining &#8220;success&#8221; is key to actually being successful.  How do we do that?</p>
<p>First, we have to publicly acknowledge to our bosses, peers, and team that we expect that some small percentage of hosts and devices on the network will someday become compromised.  It could be malware, it could be an intrusion; it could be almost anything. We need to help our teams and bosses realize that it&#8217;s not only okay to find these flaws, but that it&#8217;s actually a vital part of keeping our environment secure.</p>
<p>Second, we have to have a set of plans, procedures, and technology in place that allow for continuous monitoring and detection of problems in the environment.  As leaders, we need to push for thorough and repeated examination of our environments and celebrate each and every compromised system our teams identify, contain, and eradicate.  We must inculcate a philosophy that finding “nothing wrong” is more a sign that detection systems and processes need improvement, than it is a sign of successful prevention.</p>
<p>Lastly, and most importantly, we have to build the right networks of people, processes, and capabilities to make the most of the monitoring and planning.  As Incident Response Leaders, our most critical mission is to build effective individuals and teams that can stand up to the pressures of Incident Response.</p>
<p>But, you ask, how do I do this?  It isn&#8217;t easy – but Incident Response Leadership rarely is&#8230;</p>
<p>To start the process, you need to sit down and honestly assess your network. Bring in some trusted outside advisers if you need to. Are you really keeping anti-virus updated on all of your systems?  Are you deploying operating system and application patches in a timely fashion?  Are your IDS/IPS systems workable?  How much screening do your firewalls really do?  If you put on your blackhat – how many ways could you penetrate your network?</p>
<p>Once you&#8217;ve completed the process of seeing exactly how secure (or insecure) your environment really is, take a deep breath.  The natural response to this kind of in-depth assessment is to think that the world is collapsing and that only huge amounts of effort can ever fix it.  Remember, you aren&#8217;t here (necessarily) to fix those infrastructure issues right now; you are here to develop the ability to respond to incidents right now.</p>
<p>Now, take the list of perceived weaknesses and map out, using existing resources, how you intend to respond to this kind of incident.  Don&#8217;t develop detailed plans right now – that comes later. Just identify how you can respond with what you&#8217;ve already got.  A quick spreadsheet should do the trick here.</p>
<p>Next, invite your boss to have a cup of coffee with you.  Let the boss know what you&#8217;ve been doing and the relative assessment of the network (remembering that the sky, more than likely, isn&#8217;t really falling).  Show the boss how you intend to respond to the potential incidents using your map.  The key to this meeting is being calm, professional, and not sounding like a) Chicken Little or b) you are about to ask for a ton of new resources.  You need to show how you are going to realign your existing resources (which have been good enough so far, right?) to meet the challenge.</p>
<p>The key part of that conversation is to start the process of setting realistic expectations with the boss.  Share the truth that you&#8217;re doing everything you can; that a lucky and/or motivated adversary could still compromise the system; and that, being the Incident Response Leader that you are, you are going to develop the plan and the team to identify, contain, and eradicate any and all intrusions.</p>
<p>Once you&#8217;ve got buy-in from your boss you&#8217;re ready to tackle the next Basic Truth: Have a Workable Plan. But that&#8217;s for the next article.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsucceeding-by-planning-to-fail%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fsucceeding-by-planning-to-fail%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/succeeding-by-planning-to-fail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Incident Response Leadership: Basic Truths</title>
		<link>http://www.securitycatalyst.com/incident-response-leadership-basic-truths/</link>
		<comments>http://www.securitycatalyst.com/incident-response-leadership-basic-truths/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 11:00:10 +0000</pubDate>
		<dc:creator>Martin Fisher</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2163</guid>
		<description><![CDATA[by Martin Fisher An organization might spend hundreds of thousands of dollars to implement just one security infrastructure. Millions of dollars can be spent creating a security environment that provides an extensive defense against all nature of attacks and threats. But the true value of that substantial investment can never be realized until one relatively [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fincident-response-leadership-basic-truths%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fincident-response-leadership-basic-truths%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p>by Martin Fisher<a href="http://www.securitycatalyst.com/wp-content/uploads/2009/07/signpost.jpg"><img class="alignright size-medium wp-image-2172" title="signpost" src="http://www.securitycatalyst.com/wp-content/uploads/2009/07/signpost-300x200.jpg" alt="signpost" width="300" height="200" /></a></p>
<p>An organization might spend  hundreds of thousands of dollars to implement just one security infrastructure. Millions of dollars can be spent creating a security environment that provides an  extensive defense against all nature of attacks and threats.  But the true value of that substantial investment can never be realized until one relatively low-cost – but critically important – item is addressed: Incident Response Leadership (IRL).</p>
<p>Incident Response Leadership is the primary task of the management of incident response teams.  IRL begins with the creation of incident response plans that minimize the impact of any given incident to the management and leadership of the actual response team during an incident.  IRL continues through the recovery/cleanup process by assessing where the incident response plans can be improved.</p>
<p>Effective Incident Response Leadership also recognizes three basic truths. Until your organization embraces these truths, there will be an artificial ceiling on how effective the security program can be&#8230;</p>
<p>Basic Truth #1: Assume You Will Fail</p>
<p>Ask yourself this quick question: “How many compromised hosts are on my network?”</p>
<p>If your first gut response was “none” then you might have some rethinking to do.  It&#8217;s natural to develop a sense that all of the money, effort,  and resources it took to build your security environment will keep all of the evildoers at bay.  But if you (and the team you lead) begin to operate under the assumption that nothing bad can happen, you will either miss it or  react inappropriately when the inevitable incident occurs.</p>
<p>Compromised hosts can take many different forms.  It may be a file server that&#8217;s functioning as a SPAM relay, it could be a workstation that is part of a bot network, it may be a database server that has a rootkit installed.  There are a multitude of methods and techniques to identify and locate hosts using firewall logs, DLP, anti-virus, and so forth.  It&#8217;s a major IRL responsibility to allocate resources to this work.</p>
<p>Basic Truth #2: Have A Workable Plan, Or Else</p>
<p>How many of us really do regular exercises of our incident response plans?  Exercising workable plans that give your team the direction it requires and the flexibility it needs is a low-cost, high-payback activity that builds esprit de corps and keeps your team sharp and ready.   Lack of a workable plan will delay your response, make forensic investigations more difficult, and cost you time and money you didn&#8217;t need to spend.</p>
<p>There are always challenges to the drive to exercise plans.  “Why waste time on this?”, “We&#8217;re too busy.”, and peer leaders not making matrixed resources available are a constant refrain that IRL needs to overcome.</p>
<p>Basic Truth #3: Communicate This To Your Boss</p>
<p>Telling your boss you are assuming you will fail can be a tough conversation.  The only way to survive it with any sense of dignity and professionalism is to create a series of dialogues with your leadership to explain your incident response program, methods, and assumptions.  You can make this a career enhancing discussion by demonstrating your knowledge of the needs, objectives, and goals of the business.  You will be able to set realistic expectations for your team and be able to clearly communicate what it will take to move your team to the next level. Demonstrating the fact that success is defined by effectively leading your team through the entire range of security tasks (prevention, detection, response) and not by simply  saying “don&#8217;t get hacked”, will enable you to truly succeed to the benefit of your organization.</p>
<p>Over the next several articles we&#8217;ll dive deeper into each of these Basic Truths, and show realistic steps and obtainable objectives to improve your Incident Response Leadership.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fincident-response-leadership-basic-truths%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fincident-response-leadership-basic-truths%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/incident-response-leadership-basic-truths/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
