<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
xmlns:rawvoice="http://www.rawvoice.com/rawvoiceRssModule/"
>

<channel>
	<title>The Security Catalyst&#187; Trish Smith</title>
	<atom:link href="http://www.securitycatalyst.com/author/trishsmith/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com</link>
	<description>harnessing the human side of security</description>
	<lastBuildDate>Wed, 25 Jan 2012 15:57:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<!-- podcast_generator="Blubrry PowerPress/2.0.4" -->
	<itunes:summary>harnessing the human side of security</itunes:summary>
	<itunes:author>The Security Catalyst</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://www.securitycatalyst.com/wp-content/plugins/powerpress/itunes_default.jpg" />
	<itunes:subtitle>harnessing the human side of security</itunes:subtitle>
	<image>
		<title>The Security Catalyst&#187; Trish Smith</title>
		<url>http://www.securitycatalyst.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securitycatalyst.com</link>
	</image>
		<item>
		<title>Five common myths about technology and productivity</title>
		<link>http://www.securitycatalyst.com/2010/04/five-common-myths-about-technology-and-productivity/</link>
		<comments>http://www.securitycatalyst.com/2010/04/five-common-myths-about-technology-and-productivity/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 10:00:07 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2925</guid>
		<description><![CDATA[by Trish Smith Since the Industrial Revolution, people have assumed that more technology = more productivity. If the mimeograph is good, the photocopier must be better! If faxes are good, scanners are better! If email is good, texting is&#8230;well, you get the idea. While these are (or were) useful tools, the belief that anything shinier [...]]]></description>
			<content:encoded><![CDATA[<p><strong>by Trish Smith<a href="http://www.securitycatalyst.com/wp-content/uploads/2010/04/1189220_chinese_dragon.jpg"><img class="alignright size-full wp-image-2927" title="1189220_chinese_dragon" src="http://www.securitycatalyst.com/wp-content/uploads/2010/04/1189220_chinese_dragon.jpg" alt="" width="225" height="300" /></a></strong></p>
<p>Since the Industrial Revolution, people have assumed that more technology = more productivity. If the mimeograph is good, the photocopier must be better! If faxes are good, scanners are better! If email is good, texting is&#8230;well, you get the idea.</p>
<p>While these are (or were) useful tools, the belief that anything shinier and newer is going to automatically make â€œthe jobâ€ (whatever job that happens to be) easier, quicker or more enjoyable is deceptive.</p>
<p>Here are five common myths about technology and productivity that most of us probably believe, to one extent or another.</p>
<h3>Myth #1: Constant connectivity is a good thing.</h3>
<p>We&#8217;ve all worked in those offices â€“ where every employee expected to be reachable at every moment, and several hundred emails a day is par for the course. There are jobs and projects where that level of connectedness is necessary, but those are few and far between.</p>
<p>For everyone else, that level of â€œchecking inâ€ stifles, rather than encourages, creative thinking and productivity. After all, when most of the workday is spent emailing other members of the team and checking in with the boss, how is there any time left to actually do the job?</p>
<h3>Myth #2: Email is better. For everything.</h3>
<p>As much as email has changed our lives for the better, the idea that email works for every situation is patently false. Angry customer? Potential client? You might be better off reaching out to them via phone.</p>
<p>Work on curbing that reflexive need we all seem to have, to use email for any and every communication.</p>
<p>There are countless stories about conflicts that were caused â€“ or aggravated â€“ by a misunderstood email. If you want to avoid causing these types of situations in the future, remember that there are definite times when email is a bad idea: when you&#8217;re emotional, when you&#8217;ve wronged someone (an emailed apology can sometimes be perceived to be as insulting as the original affront), when you&#8217;re unsure what you want, or when you simply have nothing to add.</p>
<p>Email is nothing more than a tool â€“ a potentially useful one. But like any other, it can be misused.</p>
<h3>Myth #3: Everyone is as computer-literate as I am.</h3>
<p>This is a myth that&#8217;s become more and more prevalent as the years have passed. After all, computers have been a part of our society for the past twenty years. How could any adult not have become fairly computer literate in that time?</p>
<p>Sure, in the beginning, there were holdouts â€“ usually older people who had spent most of their adult life without computers. But now, when our own grandparents have computers, it&#8217;s assumed that everyone must be at least somewhat capable of using the basics â€“ email, word processing, and the web.</p>
<p>Well, it&#8217;s simply not true.</p>
<p>The â€œdigital divideâ€ &#8211; the divide between those with access to technology and those without â€“ is still there, shrinking though it might be. Those who are especially likely to be on the wrong side of this divide include low-income persons, the less educated, and children of single-parent households, particularly those who live in rural areas and central cities.</p>
<p>Business owners, politicians, and anyone who&#8217;s trying to reach the general population need to realize that potential customers and constituents may not be able to access email or a website, or order products online. We&#8217;re not all on the bleeding edge â€“ or even the cutting edge.</p>
<h3>Myth #4: Computers have replaced the pen.</h3>
<p>This myth is related to myth #2, about email always being better. But it goes beyond that. The belief that â€œcomputers are betterâ€ often creates the belief that there is no place for pen and paper. But there are at least three times when pen and paper are superior to computers:</p>
<ul>
<li><strong>Visual learners.</strong> For those of us who are visual learners, we benefit from using a whiteboard, flip chart, or even a pad and paper to physically map out our ideas.</li>
<li><strong>Speed.</strong> It is sometimes faster â€“ and more productive â€“ to scribble away on a piece of paper. Not every idea requires starting up the computer and creating a document. There&#8217;s something to be said for a small notebook for jotting down ideas.</li>
<li><strong>Tactility</strong>. There&#8217;s at least two sensory processes (touch and sight) involved in the writing-down of ideas on a piece of paper, that we don&#8217;t experience in the same way when we use computers. That experience can be essential to the thought process, and can&#8217;t be replaced by typing on a keyboard.</li>
</ul>
<h3>Myth #5: Newer is always better.</h3>
<p>The rate of technology development is increasing exponentially. The time it takes for new hardware or software to appear on the market has gone from years to months. Last year&#8217;s â€œcutting edgeâ€ cell phone has already been surpassed by at least one newer model. Laptops purchased in 2008 have been surpassed at least twice by sleeker, faster versions.</p>
<p>But before running out to replace that â€œoldâ€ cell phone or laptop, think carefully.</p>
<p>If the newer version hadn&#8217;t come out, would the current versions still be enough? Are they able to get the job done?</p>
<p>This applies to businesses as well as individuals. Making purchases based simply on the fact that a â€œnew versionâ€ now exists is a waste of money. Of course, there are times when newer technology is necessary to the business (such as with new versions of operating systems, which have important security updates). And who doesn&#8217;t love unwrapping that box with the brand new computer? But to assume that just because a newer version comes out, we need it, is an incorrect â€“ and expensive â€“ fallacy.</p>
<p>Ultimately, it&#8217;s up to us to decide how technology will bring us success in our lives and our careers. Remember that technology is a tool, like any other. How we use it â€“ or how we let it use us â€“ will be an important step toward that success.</p>
<p>Are you holding on to any of these myths? Have you overcome any of them, and if so, how? Share with us in the comments â€“ we&#8217;d love to hear about it!</p>
<p>ï»¿</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/04/five-common-myths-about-technology-and-productivity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Managing extroverts and introverts</title>
		<link>http://www.securitycatalyst.com/2010/04/managing-extroverts-and-introverts/</link>
		<comments>http://www.securitycatalyst.com/2010/04/managing-extroverts-and-introverts/#comments</comments>
		<pubDate>Thu, 01 Apr 2010 12:40:04 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[leadership]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2883</guid>
		<description><![CDATA[by Trish Smith It is important to understand personality types and traits when working with and managing other people (check out my article about that here). There are two traits with the strongest influence on personality style. An understanding of these provides advantages for managing and communicating â€“ advantages that are essential for success. The [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2010/04/1024035_yin_yang.jpg"><img class="alignright size-full wp-image-2885" title="1024035_yin_yang" src="http://www.securitycatalyst.com/wp-content/uploads/2010/04/1024035_yin_yang.jpg" alt="" width="300" height="193" /></a>by Trish Smith</p>
<p>It is important to understand personality types and traits when working with and managing other people (check out my article about that <a href="http://www.securitycatalyst.com/2010/02/personality-types-your-key-to-better-business-relationships/" target="_self">here</a>). There are two traits with the strongest influence on personality style. An understanding of these provides advantages for managing and communicating â€“ advantages that are essential for success.</p>
<p>The two types?</p>
<p>You guessed it: extrovert and introvert</p>
<p>While the words introvert and extrovert are used often â€“ and often used to justify behavior â€“ it is useful to take a step back and consider the two types in a different light.</p>
<p><strong>The extrovert</strong><br />
Extroverts are known for their assertive and outgoing nature. But extroverts aren&#8217;t assertive just because they like telling people what to do; they actually thrive on external sources of energy.</p>
<p>They seek out human interaction and lean toward the gregarious. They enjoy activities that give them the opportunity to interact with larger groups, both business and social, such as conferences, parties, community activities, public demonstrations, and highly active membership groups â€“ all strong sources of energy they can feed on, amplify and contribute to.</p>
<p>In the workplace, extroverts are less likely to find reward in individual projects. They enjoy work that involves large groups and will engage in activities that introverts might consider risky, such as public speaking and assuming leadership positions. They are often comfortable expressing opinions confidently and vocally. This can give others the impression that extroverts have a greater self-image, which is not always the case.</p>
<p><strong>The introvert</strong><br />
Classically, introverts tend to be more reserved in behavior. But consider this: introverts generate their own energy â€“ and sometimes need to step back in order to do it.</p>
<p>They seek out fewer social interactions; this does not mean they are asocial, but rather that they prefer interacting with smaller groups or individually than with larger groups. They also take more pleasure in solitary activities such as reading and writing than their extroverted counterparts.</p>
<p>At work, introverts enjoy projects that allow them to work on their own or in small groups. They tend to prefer working on one project at a time (or on fewer projects at one time), and will be more likely to observe a situation before jumping right in. They tend to speak only after they can validate what they are about to say. Introverts need time alone to &#8220;recharge&#8221;; it is essential they be provided with opportunities to do this.</p>
<p><strong>Successfully managing the two personality types</strong><br />
It&#8217;s important to leverage extroverts&#8217; innate sociability. Their outgoing nature makes them naturals as salespeople, account managers, or in any other position where they deal with clients, potential clients, and other members of the organization â€“ where they can thrive on available energy.</p>
<p>Take advantage of their leadership tendencies by providing them with opportunities to take the reins on projects.</p>
<p>Extroverts often make very good team members, so don&#8217;t feel that it&#8217;s necessary to always put them in a leadership position. Often, extroverts in team situations will serve to improve the energy of fellow team members.</p>
<p>Introverts, by contrast, usually prefer to be given projects they can manage individually, or with one or two others. They also tend to be more detail-oriented, and do better with projects that do not require them to perform many tasks simultaneously. Use their high level of focus to the business&#8217;s (and their) advantage. Introverts can often be quite taciturn until they produce desired results, so do not assume that lack of communication means they are not concerned with the outcome of the project; quite the opposite. Much of the processing that introverts do is internal, so they sometimes forget to communicate progress on the project to others.</p>
<p>As a team, these two temperaments can balance each other out well, if each can remember that the other has different work styles. Extroverts might find introverts&#8217; natural analytical style to be too confining, and introverts might consider extroverts&#8217; risk-taking to be too reckless. But if each can remember that the other has something to bring to the project, and that &#8220;different&#8221; can be beneficial, then these kinds of partnerships can be worthwhile &#8211; and even educational &#8211; for everyone involved.</p>
<p>Have you ever been in a position to manage these two temperaments? How have you used their natural strengths to the project&#8217;s advantage? And do you recognize yourself as one or the other &#8211; or do you feel you have elements of both extroversion and introversion in your own personality? Share with us in the comments!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/04/managing-extroverts-and-introverts/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Personality types: Your key to better business relationships</title>
		<link>http://www.securitycatalyst.com/2010/02/personality-types-your-key-to-better-business-relationships/</link>
		<comments>http://www.securitycatalyst.com/2010/02/personality-types-your-key-to-better-business-relationships/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 11:00:31 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2737</guid>
		<description><![CDATA[by Trish Smith If there&#8217;s one lesson Michael Santarcangelo has taught me, it&#8217;s that security (and business) aren&#8217;t just â€œabout businessâ€. They&#8217;re about people. People who we get along with, people who we (as much as we might not like to admit it) don&#8217;t always get along with. But unless we&#8217;re Steve Jobs, we don&#8217;t [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2010/02/284743_card_index_box.jpg"><img class="size-full wp-image-2738 alignright" title="284743_card_index_box" src="http://www.securitycatalyst.com/wp-content/uploads/2010/02/284743_card_index_box.jpg" alt="" width="300" height="225" /></a>by Trish Smith</p>
<p>If there&#8217;s one lesson Michael Santarcangelo has taught me, it&#8217;s that security (and business) aren&#8217;t just â€œabout businessâ€. They&#8217;re about people. People who we get along with, people who we (as much as we might not like to admit it) don&#8217;t always get along with. But unless we&#8217;re Steve Jobs, we don&#8217;t have much choice who we need to interact with (and I&#8217;ll bet even Steve has to deal with people he doesn&#8217;t get along with too well, sometimes).</p>
<h3>Itâ€™s about the people, stupid.</h3>
<p>This article shares information to become more flexible, adaptable, and resilient in dealing with others.</p>
<p>Imagine the power of being able to predict, prevent, and resolve conflicts.  How about improving communications with co-workers, clients, and peers?</p>
<p>This might sound like a pretty big claim, but when learning about personality and how it determines the ways people interact, this information is invaluable.</p>
<h3>What is a â€œpersonality typeâ€?</h3>
<p>In modern psychology, there are two ways to think about personality: â€œtraitsâ€ or â€œtypes.â€ Personality trait theories suggest two people can both be extroverts, but be very different in terms of how strong the trait is in their personality (for example, Bob and Mike might both be extroverts, but the trait is much stronger in Mike than it is in Bob). This view of personality sees it as existing along a continuum, rather than as an â€œeither/orâ€.</p>
<p>â€œPersonality typeâ€ approaches suggest people either have a characteristic or not. An individual is an introvert or an extrovert, assertive or passive, someone who works well in groups or not. This view is the more popular one among those who study personality today, and as such, is the one we&#8217;ll explore in more depth.</p>
<h3>Defining the Type</h3>
<p>The most common instrument to measure personality type is the Myer-Briggs Type Indicator (MBTI). It&#8217;s widely used by businesses (and individuals) to better understand personality. It usually consists of about 70 questions that ask you about your likes, dislikes, opinions, and personality characteristics. It then groups people into several â€œtypesâ€ based on four personality traits:</p>
<ul>
<li>Extroversion/introversion (need external contact to recharge, or time alone?)</li>
<li>Intuition/sensing (trust more in own feelings or in external observations?)</li>
<li>Thinking/feeling (the dominant force relied upon to make decisions?)</li>
<li>Judgement/perception (the need to organize life or let the chips fall as they may?)</li>
</ul>
<p>Although it would be useful to be able to administer this test to everyone we deal with day-to-day (as impractical as that might be), it&#8217;s not necessary.</p>
<p>Usually, it&#8217;s enough to simply understand which of the different personality types someone is, and keep that in mind when dealing with others. For example, recognizing that a team member is closer to the â€œjudgementâ€ end of the judgement/perception scale will help explain why they need to research and plan out every move of the project.</p>
<p>We can understand other people&#8217;s personality differences without making value judgements. John isn&#8217;t trying to drive you crazy by going with his feelings on a decision; he&#8217;s simply on the â€œfeelingâ€ end of the thinking/feeling scale, and that&#8217;s how he makes decisions.</p>
<p>This knowledge reduces frustration and improves approach to others â€“ especially if an action is needed on their part.</p>
<h3>Learning how to type others</h3>
<p>So how do we figure out which personality type someone is?</p>
<p>We can&#8217;t very well hand everyone a Myers-Briggs test (although if the topic is brought up, it&#8217;s likely that at least one person in the group will volunteer not only that they have taken the test, but what their result was: That they are an â€œINTJâ€, for example).</p>
<p>Observation is the key to success.</p>
<p>People&#8217;s personality comes out in a variety of ways, even when the person isn&#8217;t aware. Everything from personal style (how they dress), to their environment (how they set up their office), to social signals (verbal and nonverbal communication), reveals information about what personality type they are.</p>
<p>Want to type someone out?</p>
<p>Listen.</p>
<p>Watch.</p>
<p>Observe the things people are doing.</p>
<h3>Recipe for Success</h3>
<p>Then it&#8217;s simply a matter of being conscious of others&#8217; personality styles and how your own (yes, you have a personality style too!) interacts with theirs, for good or for ill.</p>
<p>If you can do this successfully, it becomes easier to do all those neat things  mentioned earlier â€“ become more flexible in dealing with others, resolve conflicts, and improve communication with everyone.</p>
<p>So tell us &#8211; do you try to be aware of different personality types in your day-to-day life? Has knowing someone&#8217;s personality type ever helped you in your work, or has the converse ever happened &#8211; not being able to understand another&#8217;s personality style negatively impacted your business? Share with us in the comments!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/02/personality-types-your-key-to-better-business-relationships/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Strategies and guidelines for developing a motivational strategy</title>
		<link>http://www.securitycatalyst.com/2010/01/strategies-and-guidelines-for-developing-a-motivational-strategy/</link>
		<comments>http://www.securitycatalyst.com/2010/01/strategies-and-guidelines-for-developing-a-motivational-strategy/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 11:00:52 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2698</guid>
		<description><![CDATA[by Trish Smith Happy New Year!Â Has the year started with a bang, full of passion and excitement? Or is motivation lagging? Last month we explored the concept of motivation and why employees&#8217; motivation is important. As the year brims full of potential, the timing is perfect to develop and implement a motivational plan for your [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2010/01/raised-hands.jpg"><img class="size-full wp-image-2700 alignright" title="raised hands" src="http://www.securitycatalyst.com/wp-content/uploads/2010/01/raised-hands.jpg" alt="" width="300" height="225" /></a>by Trish Smith</p>
<p>Happy New Year!Â Has the year started with a bang, full of passion and excitement? Or is motivation lagging?</p>
<p>Last month we explored the concept of motivation and why employees&#8217; motivation is important. As the year brims full of potential, the timing is perfect to develop and implement a motivational plan for your employees.</p>
<p>While there is no one-size-fits-all plan for improving employees&#8217; motivation, there are some proven guidelines that simplify the process and lead to success. There are five factors considered essential to a successful program:</p>
<ul>
<li>Flexibility</li>
<li>Increase positive behavior</li>
<li>Decrease negative behavior</li>
<li>Provide constant feedback and a framework for teaching skills</li>
<li>Be an overall positive approach</li>
</ul>
<p><strong>Is the problem really about motivation?</strong></p>
<p>Before developing a motivational system, determine whether the problem is actually motivation. Could it be something else, such as lack of access to the tools needed to do the job, or the working conditions of the job itself?</p>
<p>These aren&#8217;t motivational issues and cannot be fixed with a motivational system. These and other environmental challenges need to be addressed beyond motivation.</p>
<p><span style="font-family: Calibri; font-size: small;"><strong><span style="font-family: Arial, sans-serif;"><span style="font-size: small;">No Limits?</span></span></strong></span></p>
<p>Improving motivation is an investment. Investments have limits â€“ so what is the organization is willing to do to improve employee motivation? While this often boils down to cash, sometimes other investments can be beneficial, too. Regardless of the answer, it is essential to ask.</p>
<p>There is nothing more demotivating than to be promised something, only to find out afterwards that the company can&#8217;t or won&#8217;t do it.</p>
<p><span style="font-family: Calibri; font-size: large;"><em><strong><span style="font-family: Arial, sans-serif;"><span style="font-size: small;">Steps to create a motivational system</span></span></strong></em></span></p>
<p><span style="font-family: Calibri; font-size: large;"><em><span style="font-family: Arial, sans-serif;"><span style="font-size: small;"><span style="font-family: Georgia, 'Times New Roman', 'Bitstream Charter', Times, serif; font-style: normal; font-weight: normal; font-size: 13px;"><span style="font-family: Calibri;"><span style="font-size: small;"><span style="font-family: Arial, sans-serif;"><span style="font-size: small;"><strong>1.</strong></span></span></span></span><span style="font-family: Calibri;"><span style="font-size: small;"><span style="font-family: Arial, sans-serif;"><span style="font-size: small;"><strong> </strong></span></span></span></span><span style="font-family: Calibri;"><span style="font-size: small;"><span style="font-family: Arial, sans-serif;"><span style="font-size: small;"><strong>Analysis</strong></span></span></span></span></span></span></span></em></span></p>
<p>The analysis is focused on determining what factors are in scope. Will efforts be to:</p>
<ul>
<li>Implement a program based on 	performance?</li>
<li>Develop new ways to satisfy 	employees&#8217; needs?</li>
<li>Change discipline policies?</li>
<li>Create new opportunities for 	employee learning?</li>
<li>Make the organization more 	receptive to employee feedback?</li>
</ul>
<p>These are starting points â€“ and the program will likely be a blend. The key during the analysis is to focus on where improvements will occur.</p>
<p>Without focus, the risk is of turning the program into just another ineffective &#8220;flavor of the month&#8221;, and making the chances of any future, well-intended change programs less successful.</p>
<p>Including employees in this process is critical to its success. After all, they&#8217;re the ones who best explain what would improve their motivation. Making them allies in the effort to create a workplace where they can bring their best will increase the chances of program success.</p>
<p><span style="font-family: Arial, sans-serif; font-size: small;"><strong>2. Development</strong></span></p>
<p>This is the nuts and bolts of the system. Use all the resources at hand to develop the actual motivation strategies and specific methods, such as developing a new feedback system for employees to share ideas, a new continuing education program, or a recognition system for outstanding customer service. Make sure to involve relevant managers, executives, decision makers and influencers in the plan. Buy-in is important: the last thing the company wants is to roll out a new program without approval, only to have it shut down before it even gets a chance to work.</p>
<p><span style="font-family: Arial, sans-serif; font-size: small;"><strong>3. Materials</strong></span></p>
<p>What materials are needed to support the program and engage people? Does it require new forms (electronic forms might be a strong option), a new company wiki, or a new guidebook?</p>
<p>Make sure to enlist the skills and talents of anyone who can help you in this area, including HR, IT, and administrative support. Michael often talks about finding and amplifying the good; when it comes to developing an effective program that truly engages people, this can be accomplished by letting them participate in the development <strong>and improvement</strong> of the materials.</p>
<p><span style="font-family: Arial, sans-serif; font-size: small;"><strong>4. Monitoring</strong></span></p>
<p>The goal is to get it right the first time. But even if that happens, monitoring is an important, often overlooked, element. Monitoring provides insights and guidance necessary to make changes and help the system evolve.</p>
<p>When considering what and how to monitor, include goals, objectives, and criteria for their success. If possible, set dates by which the goals and objectives must be met.</p>
<p>Develop methods for people to track their progress in the program, or by which others (for example, their supervisor) can track progress.</p>
<p>Remember to focus on effectively tracking behaviors, not attitudes; goals and objectives need to be things that are quantifiable, not vague concepts. &#8220;Number of staff attending afternoon meeting&#8221; can be more easily tracked than a vague concept like &#8220;employee attitude&#8221;.</p>
<p><span style="font-family: Arial, sans-serif; font-size: small;"><strong>5. Training</strong></span></p>
<p>Conduct training with management staff. After all, they are the ones primarily responsible for employee motivation, and the ones who can best observe motivation levels. Make sure the team understands the purpose of the program; that it&#8217;s not to punish employees, or to create a falsely positive atmosphere, but rather to deliver those things that employees feel are most important to their work, in order to create a workplace that employees can do their best work in.</p>
<p><span style="font-family: Arial, sans-serif; font-size: small;"><strong>6. Implementation</strong></span></p>
<p>Simply put, it&#8217;s time to roll out the program. In smaller organizations, it&#8217;s possible to do this in a centralized manner, but for larger organizations it requires a phased approach. Regardless of how, it&#8217;s vital to initiate the program in a way that shows people it&#8217;s fully supported and an integral part of the organization&#8217;s processes.</p>
<p><strong>7. Follow-up</strong></p>
<p>Hold regular meetings to evaluate the program&#8217;s progress. Incorporate employee feedback in the program, and make changes to it as needed. The program will need adjustment as time goes by, as motivation is a journey, not a destination, and what works for one employee at one point in time may not work for them six months later.</p>
<p>Flexibility &#8211; the first of the five criteria &#8211; is key to success.</p>
<p>Implemented a motivational program? Starting one? Leave us a comment &#8211; we&#8217;d love to hear about your own journey.</p>
<p>Sources:</p>
<p>http://docs.google.com/viewer?a=v&#038;q=cache:S4_J9QwXOJYJ:slo.sbcc.edu/wp-content/uploads/motivation.pdf+how+to+develop+motivational+system&#038;hl=en&#038;gl=us&#038;sig=AHIEtbTiEUmbld3vu7u73h2v5wNcLi3N0Q&#038;pli=1</p>
<p>http://docs.google.com/viewer?a=v&#038;q=cache:ltZWfJqyQIQJ:www.mooseheart.org/pdf/PacketOfEffectiveSkills.pdf+how+to+develop+a+motivational+system&#038;hl=en&#038;gl=us&#038;sig=AHIEtbQ-2Sr1PVmIJi7fvM2NstQPZX0ZhA</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2010/01/strategies-and-guidelines-for-developing-a-motivational-strategy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When your employees don&#8217;t want to come to work anymore</title>
		<link>http://www.securitycatalyst.com/2009/12/when-your-employees-dont-want-to-come-to-work-anymore/</link>
		<comments>http://www.securitycatalyst.com/2009/12/when-your-employees-dont-want-to-come-to-work-anymore/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 13:36:46 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[catalyst]]></category>
		<category><![CDATA[leadership]]></category>
		<category><![CDATA[motivation]]></category>
		<category><![CDATA[team]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2622</guid>
		<description><![CDATA[What happens when people lose their motivation at work? Less efficient use of resources Less creative solutions (at a time when creativity is even more vital) Less productivity And worse, the possibility of security breaches and risks. Some companies learned this lesson the hard way: TMobile in the UK , Greengrocer.com, and the Office of [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/12/833690_laddertoheaven.jpg"><img class="alignright size-full wp-image-2604" title="833690_laddertoheaven" src="http://www.securitycatalyst.com/wp-content/uploads/2009/12/833690_laddertoheaven.jpg" alt="833690_laddertoheaven" width="225" height="300" /></a>What happens when people lose their motivation at work?</p>
<ul>
<li>Less efficient use of resources</li>
<li>Less creative solutions (at a time when creativity is even more vital)</li>
<li>Less productivity</li>
</ul>
<p>And worse, the possibility of security breaches and risks. Some companies learned this lesson the hard way: TMobile in the UK , Greengrocer.com, and the Office of the Attorney General of Maryland.</p>
<p>When employees lose motivation, they become less of exactly what the company needs: A creative, productive contributor. Worse, they might become angry and disgruntled, causing a loss or theft of essential company information.</p>
<h3 style="font-size: 1.17em;">Motivation â€“ I know it when I see it</h3>
<p>So what is this abstract concept called &#8220;motivation&#8221;? Is it like love &#8211; hard to define, but easy to recognize?</p>
<p>According to Webster&#8217;s, to motivate is to &#8220;provide with an incentive, move to action, impel&#8221;. Motivation is, put simply, giving others a reason to do something: To do their job well, to be creative, and to be an asset to the company.</p>
<p>Now that we&#8217;ve defined it, can we describe it? What are some common motivators? Some things that have found to be effective motivators are:</p>
<ul>
<li>Positive reinforcement</li>
<li>Effective discipline</li>
<li>Fair treatment</li>
<li>Satisfying employee needs</li>
<li>Setting work-related goals</li>
</ul>
<p>Notice something missing from the list?</p>
<p>If you assumed that â€œmore moneyâ€ would be a lock, it turns out it isn&#8217;t. The Minneapolis Gas Company completed a 20-year study of motivation. They asked 44,000 employees what they desired most from a job and found that, surprisingly, wages were not highest on the list. Job security was, followed by advancement, type of work, and pride in the company.</p>
<p>But even without the study, we all know that providing motivation is a good thing. The challenge is â€œhow?â€</p>
<p>I&#8217;ve listed some basic concepts of motivation to help you devise a system to give employees what they need, so they can contribute their best work:</p>
<h3 style="font-size: 1.17em;">1. Be the change</h3>
<p>Employees won&#8217;t be their most creative, energized selves &#8211; they won&#8217;t be assets to the organization &#8211; unless you are, first. As the Minneapolis Gas Company found, intangibles rank higher than wages, and they start with your attitude and energy. Simple actions can start the process. Ask yourself: &#8220;If I were one of my own employees, would I see myself as an asset to the organization? Does the work I do reflect my most innovative thinking?&#8221; Some ways you can start being the change you want to see are:</p>
<ul>
<li>Welcome challenges. See them as opportunities, not as limitations. After all, without challenges, we don&#8217;t get a chance to exercise our skills and talents to their fullest potential.</li>
<li>Ask if there are better or different ways something can be done. Good innovators practice creativity; they generate solutions, ideas, and concepts in every aspect of their lives.</li>
<li>Be curious, ask questions, and develop problem-solving skills by practicing them.</li>
<li>Take action &#8211; have confidence in your ideas, and dare to express them. Don&#8217;t fear failure; it&#8217;s inevitable, and the only way we learn. Above all, be persistent &#8211; don&#8217;t give up.</li>
</ul>
<p>Remember, the positive energy and creativity of your team start with you.</p>
<h3 style="font-size: 1.17em;">2. Size the motivation to the person</h3>
<p>Despite what some people might try to tell (and sell) you, there&#8217;s no &#8220;one-size-fits-all&#8221; system of motivating employees. Each person is different, as is each organization. The key to effective motivation is to discover what moves each person to be their best and to be an asset to the company.</p>
<p>How?</p>
<p>Start by asking. Then stop to listen. Watch the quiet moments. Then continue the discussion.</p>
<h3 style="font-size: 1.17em;">3. Motivation is a journey, not a destination.</h3>
<p>People and organizations change; what works for the employee and the company at one point might not be as effective months later. By listening to and observing employees, motivations can be adapted to their needs.</p>
<p>Treating motivation as a one-time event or a destination leads to a situation where it would have been better to do nothing at all. Commit to the journey and reap the rewards (and continue to read Security Catalyst to get ideas and support).</p>
<p>It might be dangerous and harmful to assume employees are motivated by &#8220;more money.&#8221; The &#8220;trick&#8221; is to figure out exactly what will move them to become greater assets to the company, then give it to them. In my next article I&#8217;ll explore in greater detail how to develop a motivational plan for your employees, and ways to overcome some common challenges in developing such plans.</p>
<p>What challenges have you experienced with motivation? What successes have you had? Share in the commentsâ€¦.</p>
<p><em>Sources:</em></p>
<ul>
<li><em>Merrian-Webster&#8217;s Online Dictionary: http://www.websters.com</em></li>
<li><em>Accel Team Development: http://www.accel-team.com/motivation/</em></li>
<li><em>The Journal of Extension: http://www.joe.org/joe/1998june/rb3.php</em></li>
<li><em>The Free Management Library: http://managementhelp.org/guiding/motivate/basics.htm)</em></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/12/when-your-employees-dont-want-to-come-to-work-anymore/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How Not to Sell</title>
		<link>http://www.securitycatalyst.com/2009/09/how-not-to-sell/</link>
		<comments>http://www.securitycatalyst.com/2009/09/how-not-to-sell/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 13:05:46 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[selling]]></category>
		<category><![CDATA[service]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2301</guid>
		<description><![CDATA[by Trish Smith Â Â Â  Recently, I had an experience in the &#8220;non-tech&#8221; world that I think has parallels to many people&#8217;s experiences with technology, so I thought I&#8217;d share it with you. Several weeks ago, my husband and I decided that we had had enough of our mattress; it was only four years old, but [...]]]></description>
			<content:encoded><![CDATA[<p>by Trish Smith Â Â Â  <a href="http://www.securitycatalyst.com/wp-content/uploads/2009/09/1152597_paid_invoice.jpg"><img class="alignright size-full wp-image-2357" title="1152597_paid_invoice" src="http://www.securitycatalyst.com/wp-content/uploads/2009/09/1152597_paid_invoice.jpg" alt="1152597_paid_invoice" width="300" height="200" /></a></p>
<p>Recently, I had an experience in the &#8220;non-tech&#8221; world that I think has parallels to many people&#8217;s experiences with technology, so I thought I&#8217;d share it with you.</p>
<p>Several weeks ago, my husband and I decided that we had had enough of our mattress; it was only four years old, but it was a memory foam mattress that developed a distinct body impression on my husband&#8217;s side. It was uncomfortable, to say the least. The furniture company that sold it to us is a store located here in town, so we had them come out and take a look at the mattress to see if it was defective. Sure enough, when they inspected it, they determined that it was, and that they would reimburse the purchase price of the mattress (with a store credit, of course). At this point we needed to buy a new mattress, and this is where the story goes south.</p>
<p>We already knew we wanted to purchase a &#8220;traditional&#8221; mattress, and not another memory foam mattress (we might be slow learners, but we&#8217;re not THAT slow). When we entered the furniture store, we were imediately pounced upon by a salesperson, who escorted us to the mattress department and asked us what we were looking for. We explained the situation with the store credit, and told him that we had decided to purchase a non-memory foam mattress because of our recent experience.</p>
<p>At this point, I should explain that we were not entirely against a memory foam mattress. If we could have found one with a good warranty and reliability, we might have purchased it. But instead, the salesman proceeded to try to &#8220;hard sell&#8221; us a $3,000 mattress (which was $1,300 above the amount of the store credit). When I indicated that we wanted to try to stay close to the amount of the store credit and that we weren&#8217;t entirely sold on &#8220;newfangled&#8221; latex foam, considering our last experience, the salesman made an obnoxious remark about latex actually being an old technology (since it&#8217;s been around for thousands of years). At that point, if the store credit situation hadn&#8217;t forced us to buy the mattress at that store, I would have gone to a different store and they would have lost my sale (which ultimately turned out to total around $2,000).</p>
<p>So what&#8217;s the lesson here? It&#8217;s obvious &#8211; regardless of whether your job is to sell technology to the public or to provide IT services to your organization, DON&#8217;T HARD SELL. Believe me when I tell you that your client will recognize this tactic from a mile away, and will run in the opposite direction.</p>
<p>But what is a &#8220;hard sell&#8221;? According to Wiktionary.com, it&#8217;s &#8220;a sales technique of pressuring the potential buyer to agree to a purchase&#8221;. It implies that, instead of providing customers with valid reasons for making the purchase, and helping them understand how the product will improve their jobs or their lives, salespeople simply subject customers to high-pressure tactics to get them to agree to the sale.</p>
<p>We&#8217;ve all been victim of the hard sell. Our society has even developed a stereotype of the hard seller: The car salesperson. Most of us recognize when we&#8217;re being pressured to buy something, and our first instinct is usually to run the other way. It doesn&#8217;t matter if the salesperson is an expert in the field; we don&#8217;t like being made to feel as though we &#8220;have to&#8221; do something by another person (even if we really <em>do</em> have to do something). It might be our contrary nature, but it doesn&#8217;t matter if the salesperson knows more than the us (or just thinks he does); it doesn&#8217;t even matter if what we&#8217;re being sold is something we really do need. We will walk away from a hard sell.</p>
<p>So how do you avoid making a hard sell? Explain, explain, explain. Even if what you&#8217;re dealing with is a highly technical product, and the person you&#8217;re selling it to isn&#8217;t very technologically savvy, there are always ways to explain something in a way the customer will understand. Follow the therapeutic mantra, and &#8220;start from where the customer is&#8221;. Remember that when you don&#8217;t do this; when you instead attempt to pressure a client into a sale because you &#8220;know better&#8221;, I can guarantee you one thing:</p>
<p>Apply pressure tactics, and you can kiss that sale goodbye.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/09/how-not-to-sell/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>We&#8217;ve come a long way, baby&#8230;Or maybe not</title>
		<link>http://www.securitycatalyst.com/2009/08/weve-come-a-long-way-baby-or-maybe-not/</link>
		<comments>http://www.securitycatalyst.com/2009/08/weve-come-a-long-way-baby-or-maybe-not/#comments</comments>
		<pubDate>Thu, 27 Aug 2009 13:05:25 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[change]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2262</guid>
		<description><![CDATA[by Trish Smith Although at times I complain about it, I do truly enjoy my status as the only person in the Catayst writers&#8217; group without a formal background in IT. I believe that it does, as Michael tells me time and again, give me a unique perspective on the field. It is from that [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/08/1141307_desert_road.jpg"><img class="alignright size-full wp-image-2263" title="1141307_desert_road" src="http://www.securitycatalyst.com/wp-content/uploads/2009/08/1141307_desert_road.jpg" alt="1141307_desert_road" width="300" height="224" /></a>by Trish Smith</p>
<p>Although at times I complain about it, I do truly enjoy my status as the only person in the Catayst writers&#8217; group without a formal background in IT. I believe that it does, as Michael tells me time and again, give me a unique perspective on the field.</p>
<p>It is from that perspective that I write my articles; none more so than today.</p>
<p>Recently, I had the not-so-pleasant experience of trying out different software for my blog. I run a personal website that I&#8217;ve recently expanded from a simple blog to a source for information on cooking and food preservation. Not only did I have some immediate needs for the new information I was puttting on the blog, but I also anticipated having needs that my current software (WordPress) would not be able to fulfill (things such as fillable forms, searchable lists, and more). At least, not in any easy or elegant way.</p>
<p>So the search began. I investigated two other website-building options: Joomla and Drupal. Well, to be perfectly honest, I only truly investigated Drupal; I looked into Joomla briefly and determined that it wouldn&#8217;t fit my needs. More precisely, I tried Scribd and found that it was too difficult for me to grasp quickly (of course, this is just my own experience; others may find they absolutely love it).</p>
<p>I spent an entire day exploring Drupal; I downloaded it and installed it on my server, and then began building my website.</p>
<p>Twenty-four hours later, I&#8217;m back on WordPress (much like a misbehaving spouse, grateful to their partner for giving them a second chance after having strayed: &#8220;Oh WordPress, I&#8217;m so sorry and it will NEVER HAPPEN AGAIN.&#8221;), and appreciating it more than ever.</p>
<p>So what have I learned from this experience that you could learn from (because really, why else woud I write about it if not to help all of you out)?</p>
<p>First, I learned that &#8220;more complex/difficult/advanced&#8221; does not necessarily mean better. I thought that the increased flexibility (and as a result, increased complexity) of Drupal would be an advantage to building my website, but this is not always the case. Think of this phenomenon as occurring on a curve; not enough flexibility will hinder you, but more flexibility is useful only to a certain extent. After that point, more flexibility/complexity will begin to get in your way just as much as not enough of it will.</p>
<p>Second, I learned (firsthand) the adage about test-driving software on a local host (such as your desktop computer) before installing it on your server (and deleting your old software). If things don&#8217;t work out, you&#8217;ll have a LOT less work to do. Think of this as a safety net, just in case you need to change back. I would have easily saved myself four or five hours of work, even though some of the work was unavoidable because I changed my theme.</p>
<p>Third, I learned that failure is always an option. Specifically, I learned not to be so tied to the success of any new venture that I can&#8217;t admit that it&#8217;s not working, and that I need to try something else (or even return to my old software). Perhaps a better way to think of it is not as failure, but as a way to explore and determine the best option for you and whatever you&#8217;re developing. Would it have been better for me (and my website) to stick with Drupal, becoming increasingly frustrated with my own inability to grasp it (and becoming increasingly vociferous about it on Twitter, which really helps no one)? In this case, giving up the Drupal experiment was the best option (for me and for all 1800+ of my followers on Twitter).</p>
<p>Finally, I learned the best lesson of all: Try it, try it all, because it&#8217;s the only way you learn. I may have switched back to WordPress from Drupal, but I&#8217;ve taken the lessons I learned from my Drupal experience and used them to improve my website on WordPress. And ultimately, isn&#8217;t that the lesson we should learn in all our endeavors &#8211; on- and offline?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/08/weve-come-a-long-way-baby-or-maybe-not/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Revisit the basics</title>
		<link>http://www.securitycatalyst.com/2009/07/revisit-the-basics/</link>
		<comments>http://www.securitycatalyst.com/2009/07/revisit-the-basics/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 11:00:48 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=2179</guid>
		<description><![CDATA[by Trish Smith As our clients and customers naturally become more computer savvy, we often assume that they know (and remember) the basic tenets of security, including good &#8220;password hygiene&#8221;: Ensure that your password is difficult to guess, that it is never given to an unauthorized party, and that it is changed on a regular [...]]]></description>
			<content:encoded><![CDATA[<p>by Trish<a href="http://www.securitycatalyst.com/wp-content/uploads/2009/07/ABC.jpg"><img class="alignright size-medium wp-image-2180" title="ABC" src="http://www.securitycatalyst.com/wp-content/uploads/2009/07/ABC-300x264.jpg" alt="ABC" width="300" height="264" /></a> Smith</p>
<p>As our clients and customers naturally become more computer savvy, we often assume that they know (and remember) the basic tenets of security, including good &#8220;password hygiene&#8221;: Ensure that your password is difficult to guess, that it is never given to an unauthorized party, and that it is changed on a regular basis. But something happened today that reminded me that even the more knowledgeable among us can forget to be cautious when we are online.</p>
<p>I was on Twitter this morning (my username there is @Astrogirl426, if you&#8217;d like to add me to your follower list) when I began seeing tweets about a new service called &#8220;Twitviewer&#8221;. This service offered to let Twitter users find out who had recently viewed their Twitter page. Curious, I clicked the link and was sent to the Twitviewer home page, where I was prompted to enter my Twitter username and password.</p>
<p>Hopefully, this is the point at which anyone with a moderate amount of experience online would stop and think, &#8220;Hmm, this might not be a great idea. Let me wait and see if this service turns out to be legit.&#8221; Let me state here that there ARE some legitimate Twitter services that require you to enter your username and password to access them (TwitPic is just one of several). However, a brand-new service that requires your login information should always be approached with caution &#8211; if for no other reason that to see if any reports of &#8220;suspicious activity&#8221; surface.</p>
<p>Unfortunately, over the next few hours I saw quite a few of the people I follow on Twitter using the service (I knew this because the service sends out an automatic tweet from the individual when they use it for the first time). Sure enough, later in the afternoon I began reading warnings from Twitter against giving Twitter login information to this service.</p>
<p>So what did I learn from this? What can YOU learn from this? That even as people become more sophisticated about computers in general, and security in specific, we need to revisit the basics with them from time to time to remind them that these lessons are still important, and still relevant. And if you were one of those who used the Twitviewer service &#8211; change your password!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/07/revisit-the-basics/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting to Know&#8230;.Me</title>
		<link>http://www.securitycatalyst.com/2009/05/getting-to-knowme/</link>
		<comments>http://www.securitycatalyst.com/2009/05/getting-to-knowme/#comments</comments>
		<pubDate>Wed, 27 May 2009 11:00:53 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[background]]></category>
		<category><![CDATA[writer]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1871</guid>
		<description><![CDATA[by Trish Smith As an avid blog reader, I often find myself wanting more information about the writers of the blogs I read. Most of the blogs I read are personal blogs, and so I learn most of what I want to know through the blog content itself. But on a professional blog, such as [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/05/question.jpg"><img class="alignright size-medium wp-image-1873" title="question" src="http://www.securitycatalyst.com/wp-content/uploads/2009/05/question-300x300.jpg" alt="question" width="300" height="300" /></a>by Trish Smith</p>
<p>As an avid blog reader, I often find myself wanting more information about the writers of the blogs I read. Most of the blogs I read are personal blogs, and so I learn most of what I want to know through the blog content itself. But on a professional blog, such as this one, you rarely read much about the writers. I know that the bios of the Security Catalyst writers do give you some information, but I&#8217;m sure you&#8217;ve caught yourself wondering, from time to time, just who we are.</p>
<p>In that spirit, I&#8217;m devoting this month&#8217;s blog posting to a little &#8220;Getting to know you (or rather, me)&#8221; session. Hopefully by the time you&#8217;ve finished reading this, you&#8217;ll know a little more about me and about why I became a Security Catalyst writer.</p>
<p>My computer experience began in 1990, when my high school installed a computer lab and began offering various programming courses. I quickly discovered that, although I wasn&#8217;t interested in becoming a programmer (a course in C++ confirmed it), computers could be very useful to me. Unfortunately, personal computers were still at a fairly early stage, and didn&#8217;t offer much by way of everyday usefulness. My first computer was a Commodore 64; I love to horrify my teenage nephews with stories about how we used to have to use tapes (which looked exactly like audio tapes) to store programs. It wasn&#8217;t unusual for it to take an hour for a game we wanted to play to download off the tape, frequently including some corruption of the data that forced us to repeat the entire process. Thus, at this point computers were (for me, anyway) still largely used for playing games and noodling around with Basic programming (I can still write a mean program loop using IF &#8211; THEN). But I believe that by beginning my computer education as a kid, I didn&#8217;t cripple my quest for information with the fear that I might &#8220;break something&#8221; (which, in my experience, is the biggest barrier to most people becoming comfortable with computers).</p>
<p>My experience with, and exposure to, personal computing continued through college, where computers finally became fast enough and powerful enough to be more than just a toy. This is where they began to make my life as a student easier.</p>
<p>I continued using computers through graduate school, along the way graduating to a 386, then a 486, and then finally (finally!) moving to a Mac. You&#8217;d never know it from my devotion to Apple computers, but when I first began using Macs (spurred by a then-boyfriend&#8217;s proficiency in them and easy access to his then-blazing-fast laptop) I resisted them vigorously. It didn&#8217;t take me long, however, to discover their appeal, and barring some necessary forays into the world of Windows PCs for work (and to fix my husband&#8217;s PC from time to time), I&#8217;ve stayed with them ever since. One little-known secret: Apple computers are great for those of us with compulsive tendencies. When I owned a Windows machine, I was forever &#8220;cleaning up&#8221; my computer by deleting all the weirdly-named little files that were installed on my hard drive with new programs. Inevitably, the files I deleted were ones I needed to run some essential piece of programming. So the fact that Mac programs tend to be fairly self-contained is a definite plus for us OCD-types.</p>
<p>The other significant aspect of my experience on computers has been my &#8220;online&#8221; experience, or what the kids today call &#8220;social media&#8221; (and yes, that was said firmly tongue-in-cheek). I began my own social media exposure on Compuserve, in chatrooms and private IM. I remember the beginning of AOL (and oh, how we all loathed it then, too), and IRC, and even farther back, BBS&#8217;s. I have that to thank for my own lack of crippling awe over websites such as Twitter, Facebook, and MySpace.</p>
<p>So generally speaking, my comfort level with computers (and, by extension, with computer people/geeks/techies/what-have-you) was developed through years of exposure to computers, and through the realization that they really aren&#8217;t very intimidating at all (computers, that is; computer geeks are sometimes an entirely different story).</p>
<p>This is probably the simplest reason that I&#8217;m here, the only non-tech person writing in a sea of tech writers. I suspect I should be more intimidated than I am; but as I said, a long education in and exposure to computers have removed most of my sense of awe. Fortunately, they haven&#8217;t removed my interest in and fascination with them, which is the other reason I&#8217;m here. I see all of this as your benefit: My non-tech perspective on the tech world, my lack of awe, and my continuing fascination with and interest in computers are all characteristics I gladly use in service of you, our devoted readers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/05/getting-to-knowme/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>A Multipart Letter to Employers of Security Professionals â€“ Part 2</title>
		<link>http://www.securitycatalyst.com/2009/04/a-multipart-letter-to-employers-of-security-professionals-%e2%80%93-part-2/</link>
		<comments>http://www.securitycatalyst.com/2009/04/a-multipart-letter-to-employers-of-security-professionals-%e2%80%93-part-2/#comments</comments>
		<pubDate>Fri, 24 Apr 2009 11:00:33 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[learning]]></category>
		<category><![CDATA[teaching]]></category>
		<category><![CDATA[training]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1468</guid>
		<description><![CDATA[by Andrew Hay My name is Andrew Hay and I, like many of my colleagues, work for an organization in an information security function. If you recall from my previous article, I attempted to impress upon you the need for organizations to support the continuous learning of their employed security staff. This article builds on [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/03/22_01_5-u-s-army-helmet_web.jpg"><img class="alignright size-medium wp-image-1469" title="22_01_5-u-s-army-helmet_web" src="http://www.securitycatalyst.com/wp-content/uploads/2009/03/22_01_5-u-s-army-helmet_web-300x200.jpg" alt="22_01_5-u-s-army-helmet_web" width="300" height="200" /></a>by Andrew Hay</strong></p>
<p>My name is Andrew Hay and I, like many of my colleagues, work for an organization in an information security function. If you recall from my previous article, I attempted to impress upon you the need for organizations to support the continuous learning of their employed security staff. This article builds on the first article by explaining the need to support your employees&#8217; training and certification goals.</p>
<p>One way to think about the costs of training your employees is to consider how much the United States invests in training individuals in the various branches of the military. The average cost to train a soldier is roughly $40,000 USD (http://wiki.answers.com/Q/What_is_the_cost_of_training_a_soldier_in_the_military). This figure doesnâ€™t include the ongoing costs to learn new equipment, technologies, and to help them advance in their careers. That figure equates to roughly $400,000 USD for a career soldier serving in the most basic capacity. The United States military prides itself on is the competence of its personnel, which is fostered by training, training, and more training.</p>
<p>Allowing your employees to attend training does not need to cost $400,000, though. Some organizations, such as the SANS Institute, offer work-study programs that allow you to attend a 6-day course in exchange for assisting the instructor, working at the bookstore, or helping with other miscellaneous conference activities. A nominal fee is charged but it is far less expensive than paying the full fee.</p>
<p>The old adage states, â€œThose who canâ€™t do, teach.â€ But one of the best ways to ensure knowledge is kept current is to learn how to teach the concepts to another person. This forces the teacher to become more knowledgeable himself and, in most cases, learn the answers to questions or problems he himself might have had. One way to promote this skill is to support transfer of information sessions. Supporting employee transfer of information helps the business in several ways. It shows employees that their knowledge is valued and that you view them as an expert on particular topics. Interpersonal learning also lowers the overall cost of training for your organization and helps practitioners work on valuable communication and presentation skills â€“ something that most organizations agree is lacking in many security professionals today.</p>
<p>In subsequent articles in this series, I will help you understand the other options for supporting security practitioners within your organization. With this knowledge you can ensure that your employees are being equipped with the tools they need to effectively manage the overall security of your business.<br />
<strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/04/a-multipart-letter-to-employers-of-security-professionals-%e2%80%93-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Coming Out of the &#8220;Cave&#8221;</title>
		<link>http://www.securitycatalyst.com/2009/04/coming-out-of-the-cave/</link>
		<comments>http://www.securitycatalyst.com/2009/04/coming-out-of-the-cave/#comments</comments>
		<pubDate>Mon, 13 Apr 2009 11:00:07 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1451</guid>
		<description><![CDATA[by Trish Smith As recently as five years ago, if you worked for the tech department of most organizations, your job responsibilities were pretty clear-cut.Â  You were expected to fix the hardware when it broke, &#8220;fix&#8221; the software when someone crashed a program, and install updates and software as necessary. The skills required were cut-and-dry, [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/03/cave.jpg"><img class="alignright size-medium wp-image-1456" title="cave" src="http://www.securitycatalyst.com/wp-content/uploads/2009/03/cave-226x300.jpg" alt="cave" width="226" height="300" /></a><strong>by Trish Smith</strong></p>
<p>As recently as five years ago, if you worked for the tech department of most organizations, your job responsibilities were pretty clear-cut.Â  You were expected to fix the hardware when it broke, &#8220;fix&#8221; the software when someone crashed a program, and install updates and software as necessary. The skills required were cut-and-dry, and the surprises were pretty minimal. As far as information security was concerned, it was usually enough to simply hand down security measures and escape back to the sanctity of the IT &#8220;cave&#8221;.</p>
<p>We&#8217;ve come a long way, baby.</p>
<p>In the past few years, everything about the field has changed. Not only do job descriptions look drastically different, but the environment in which those jobs are taking place has changed. Budgets are smaller, the threats to organizations are greater, and the skills that are required have broadened. People in general are also more tech-savvy, which makes the job both more and less difficult. On one hand, IT is dealing less and less with people who are completely unfamiliar with computers and the internet; on the other, a little bit of knowledge can be a dangerous thing. People sometimes know just enough to create problems, and not enough to be able to fix them on their own.</p>
<p>In addition, we&#8217;ve come to the realization that it&#8217;s no longer enough to simply possess technical skills; IT workers now need to work with the rest of the organization to make security measures more successful. As I&#8217;ll discuss further below, success is much more likely when members of the organization are included in the process, rather than simply having security measures foisted upon them.</p>
<p>However, what this means for infosec employees is that they need a whole new set of skills, including the ability to communicate the value of what they do to fellow employees and to management. Job security is far from guaranteed for any member of the organization. Involving the rest of the organization in the development of security measures ensures buy-in from the organization for the measures and makes the success of these measures far more likely (and by extension, of the IT department as well).</p>
<p>How does involving those being affected by security measures in the process, make those measures more likely to meet with success? First, simply by going to the employees themselves to get information about they do their jobs, security measures become more specific to the people they&#8217;re actually supposed to help. A system that is designed around the people who are going to be using it is far more likely to be effective than one that isn&#8217;t.</p>
<p>Second, as people become more involved in the experience of creating these security processes, their fear of the measures that are introduced is diminished, making them more likely to comply and to be successful with such measures. They become partners in the security effort, and invested in its success.</p>
<p>True, change can be scary. But the opportunities inherent in such change make this an exciting time for the field. It&#8217;s not so bad out here after all.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/04/coming-out-of-the-cave/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A Multipart Letter to Employers of Security Professionals</title>
		<link>http://www.securitycatalyst.com/2009/03/a-multipart-letter-to-employers-of-security-professionals/</link>
		<comments>http://www.securitycatalyst.com/2009/03/a-multipart-letter-to-employers-of-security-professionals/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 11:00:21 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1350</guid>
		<description><![CDATA[by Andrew Hay My name is Andrew Hay and I, like many of my colleagues, work for an organization in an information security function. What Iâ€™d like to impress upon you is the need for organizations to support the continuous learning of their employed security staff. The field of security is a constantly evolving entity [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/03/conference.jpg"><img class="alignright size-medium wp-image-1352" title="conference" src="http://www.securitycatalyst.com/wp-content/uploads/2009/03/conference-300x225.jpg" alt="conference" width="300" height="225" /></a></p>
<p><strong>by Andrew Hay</strong></p>
<p>My name is Andrew Hay and I, like many of my colleagues, work for an organization in an information security function. What Iâ€™d like to impress upon you is the need for organizations to support the continuous learning of their employed security staff. The field of security is a constantly evolving entity and, to that end, requires its practitioners to be able to adapt. Most practitioners take the time to increase their knowledge by reading blogs, books, and papers in their spare time and by joining local security organizations. Some, depending on their geographic location, even pay out of their own pocket to attend local or domestic security conferences.</p>
<p>If your employees are taking the time to enhance their knowledge &#8211; knowledge that will inevitably be used to help protect the organization &#8211; shouldnâ€™t the organization match that contribution?</p>
<p>That is the point of this, and future, articles. I would like to help you understand how you can contribute to the protection of your organization by assisting with the professional development of your security staff.</p>
<p>The first way to assist your employees is to allow them to attend industry conferences. Conferences are the best way for security practitioners to meet their peers, share war stories, and learn from the best minds in the industry. Many organizations are hesitant to send their staff to conferences due to the cost but the average entrance cost of a big ticket conference is roughly $1,500USD, excluding flights, hotels, and meals. Youâ€™ll note how I mentioned the extra costs â€“ flights, hotels, and meals â€“ as a separate line item. Often, the cost of the conference isnâ€™t the pain point, itâ€™s the associated costs incurred by those attending.</p>
<p>Attending a security conference does not need to be expensive, however. Several organizations, such as ISSA, ISACA, OWASP, and many others, offer local low cost one- or multiple-day conferences that cater to practitioners in a particular geographic area. The conference content is excellent, the employee has the opportunity to network with peers, and the employer need not worry about huge travel-related expenses.</p>
<p>Ideally, the business should budget for one major conference, which may or may not be local, and one or two local conferences per budget year. This nominal investment not only helps bring cutting edge knowledge back into the organization, it also boosts the employeesâ€™ view of the organization that they work for.</p>
<p>In subsequent articles in this series, I will strive to help you understand the other avenues for supporting security practitioners within your organization. With this knowledge you can ensure that your employees are being equipped with the weapons to effectively manage the overall security of your business. Until next time.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/03/a-multipart-letter-to-employers-of-security-professionals/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Gaining and Maintaining Professional Momentum During Difficult Times</title>
		<link>http://www.securitycatalyst.com/2009/03/gaining-and-maintaining-professional-momentum-during-difficult-times/</link>
		<comments>http://www.securitycatalyst.com/2009/03/gaining-and-maintaining-professional-momentum-during-difficult-times/#comments</comments>
		<pubDate>Fri, 13 Mar 2009 11:00:14 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1357</guid>
		<description><![CDATA[by David McCartney While Iâ€™ve always been blessed with employment, I havenâ€™t always been given opportunities to advance my career and myself through the employer. During professional dry spells that can result from economic or job limitations, it can be a major challenge to gain or maintain your professional momentum. Knowing how to leverage affordable, [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/03/opnbook.jpg"><img class="alignright size-medium wp-image-1360" title="opnbook" src="http://www.securitycatalyst.com/wp-content/uploads/2009/03/opnbook-300x200.jpg" alt="opnbook" width="300" height="200" /></a>by David McCartney</strong></p>
<p>While Iâ€™ve always been blessed with employment, I havenâ€™t always been given opportunities to advance my career and myself through the employer. During professional dry spells that can result from economic or job limitations, it can be a major challenge to gain or maintain your professional momentum. Knowing how to leverage affordable, easily accessible resources has served me well several times and broken the â€œprofessional funkâ€ Iâ€™m sure most of us have suffered from or seen at some point.</p>
<p>Investing in yourself is a lifelong process that only requires a desire to improve.</p>
<p>In-Person Networking Opportunities<br />
To start, look for local security gatherings in your area. Professional organizations such as the ISSA, ISACA, and Infraguard will typically let you attend as a guest for a minimal cost, giving you a chance to figure out if you can benefit from each other (yes, from each otherâ€¦ more on this below). I suggest you check out a variety of organizations before determining which, if any, you should join or become associated with.</p>
<p>Besides professional organizations, donâ€™t discount less commercialized gatherings as well. Do you have a local Hacker Space, 2600, or DefCon chapter? I highly recommend checking out these communities as well. Although they may not always be something youâ€™d list on your resume, the knowledge and experience gained will likely prove invaluable.</p>
<p>Once youâ€™ve found an organization that fits your personality and interests, try to find ways that you can contribute. While it is unlikely youâ€™d be able to quickly join early on in a leadership capacity, look for opportunities where you can contribute. Chances are, someone would enjoy learning what you know, so see if you can invest in others by lecturing, teaching, or mentoring. In addition to firming up your knowledge on a topic, youâ€™ll increase your visiblity amongst your peers, possibly opening up other advancement opportunities as well. Furthermore, by not just focusing on yourself, you wonâ€™t dwell on your situation, which is empowering in itself.</p>
<p>Online Networking Opportunities<br />
Many articles cover social networking in depth, so I wonâ€™t spend too much time here. Know that the boon has created many ways to increase your awareness of events to advance and enhance yourself. Look for ways to increase your professional networking and education through sites like Twitter and LinkedIn by watching for local events like BeanSec in Boston, Cowtown Computer Congress (CCCKC) in Kansas City, or the Security MBA (Masters of Beer Appreciation) in Columbus. These sites may also announce regional conferences and summits that can be affordable educational events.</p>
<p>Additionally, security-minded communities such as the Security Catalyst Community at http://www.securitycatalyst.org provide excellent discussion opportunities where people come together to help and assist each other. From the site:<br />
The Security Catalyst Community is designed to support those responsible for protecting information by:</p>
<p>1. Providing a professional, supportive environment to ask for help<br />
2. Foster a culture that welcomes ideas; share your experiences and insights regardless of your experience<br />
3. Share your passion and blend your energy with others<br />
If you are not already a member, you are missing out!</p>
<p>Training<br />
There are extensive opportunities to increase your security knowledge on the interweb. Depending on your budget and space constraints (as well as significant- other agreeability), gathering some old equipment to experiment on may be practical. If space or budget limitations come into play, donâ€™t discount using virtualization technology. Remember, very few things are a replacement for hands-on experience.</p>
<p>Need an idea on what to study? Explore online training videos through resources like The Academy Pro/Home (http://www.theacademypro.com/, http://www.theacademyhome.com/). Work through projects like the De-ICE.net PenTest LiveCDs (http://heorot.net/livecds/). Again, these communities are great places to contribute as well! Similarly, remember to explore your local library for books on topics you might be interested in. The materials might not be bleeding-edge, but that doesnâ€™t mean the information isnâ€™t valuable.</p>
<p>Lastly, another way to easily continue your ongoing education and training is to subscribe to podcasts and blogs. Many of the people and resources you encounter through In-Person and Online Networking may have involvement in an online presence where your energies could be valuable. Look for opportunities to give feedback and contribute in an area youâ€™re passionate or curious about.</p>
<p>Hopefully Iâ€™ve given you some new ideas on ways to further yourself without breaking your budget. Iâ€™ve leveraged many of the resources listed above, so I know they can be effective if you want them to be.</p>
<p>Do you have other ideas or approaches on how to gain or increase your professional momentum? If so, Iâ€™d love to hear about them. By sharing our ideas and experiences we can continue to help each other improve, raising the bar on the security community as a whole.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/03/gaining-and-maintaining-professional-momentum-during-difficult-times/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Technophobe, or something more?</title>
		<link>http://www.securitycatalyst.com/2009/03/technophobe-or-something-more/</link>
		<comments>http://www.securitycatalyst.com/2009/03/technophobe-or-something-more/#comments</comments>
		<pubDate>Wed, 11 Mar 2009 11:00:11 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1133</guid>
		<description><![CDATA[by Trish Smith Why do people fail to address security issues? We use the word &#8220;technophobe&#8221; to describe people who are leery and sometimes fearful of technology, but this is a misleading over-generalization. I believe there is another issue at work. We use highly specialized language, or lingo, in many areas, including information security. To [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/03/letter.jpg"><img class="alignright size-medium wp-image-1324" title="letter" src="http://www.securitycatalyst.com/wp-content/uploads/2009/03/letter-300x219.jpg" alt="letter" width="300" height="219" /></a>by Trish Smith</strong></p>
<p>Why do people fail to address security issues? We use the word &#8220;technophobe&#8221; to describe people who are leery and sometimes fearful of technology, but this is a misleading over-generalization. I believe there is another issue at work.</p>
<p>We use highly specialized language, or lingo, in many areas, including information security. To anyone not familiar with this area, the language can be alienating. But even the &#8220;plain language&#8221; we use can be unintentionally off-putting.</p>
<p>Language influences the way we think, whether we like (or even realize) it or not. Influencing the way an issue is perceived often becomes an exercise in semantics. Years ago, a study was done that looked at the effect of language on people&#8217;s perceptions. When different words &#8211; &#8220;hit&#8221; versus &#8220;smash&#8221;, for example &#8211; were used to describe the scene, observers changed their evaluation of how fast a car was traveling when it impacted an object. This study showed quite clearly how language affects even such &#8220;objective&#8221; perceptions.</p>
<p>But how does this impact our work as security professionals? How does this knowledge improve (or make worse) the process for our clients, our colleagues, and ourselves? Understanding the impact of language on our perceptions of our world, then, is one key to helping others become more willing participants in the security process. But more specifically, how does language prevent people from fully participating in the process?</p>
<p>One deceptively innocuous way is through the use of the word &#8220;data&#8221; to refer to the information we&#8217;re protecting. Clients are often told that part of their job is to &#8220;protect data&#8221;. The problem with that is with the connotation of data as cold, distant, and impersonal. It probably doesn&#8217;t help that Data is also the name of a character that&#8217;s an artificial life form on the Star Trek television series: Cold, distant, and impersonal. Data are abstract; they&#8217;re meaningless to people&#8217;s everyday lives. After all, outside of the tech world, how often do people use &#8220;data&#8221; to refer to themselves? Data are numbers and letters in a computer, as meaningless as code to the average, non-tech-oriented person.</p>
<p>Reframe it as &#8220;protecting information&#8221;, though, and it becomes meaningful. People now feel a connection to what they&#8217;re being asked to protect. Thus, they assign it a value. Things that are abstract and unknowable have no real value to people; but information is something they feel a connection to. It&#8217;s something they can understand, something they can perceive value in. Given the choice (or even if they&#8217;re not given the choice), people will not spend their time (which also has value) protecting something they perceive as valueless. And therein lies one of the major dilemmas in information security. Ask someone to protect something that they see as valuable, and they will probably do it even if they don&#8217;t receive an immediate reward. Ask the same people to protect something they see as having no value, and their desire to protect it drops dramatically, regardless of the reward you offer them.</p>
<p>Additionally, &#8220;data&#8221; implies it&#8217;s a computer issue, something for the tech department to worry about. It&#8217;s &#8220;not my job&#8221;, but rather part of the mysterious, unknowable (for most) world behind the door marked &#8220;IT&#8221;. People feel they have enough work to do as it is; if they think they need to learn something more (and a highly technical skill set at that), they&#8217;ll resist. So they distance themselves. Information, though, is everyone&#8217;s responsibility, regardless of position or department. Everyone manages some sort of information, no matter who they are in the organization.</p>
<p>Language can connect us; it can make us part of the process in ways nothing else can. We need to be aware when we use language that isolates people from the process. Small changes, such as moving from using the word &#8220;data&#8221; to the word &#8220;information&#8221; to describe what we&#8217;re asking people to protect, might seem a ridiculously insignificant step. But it might be the first step in helping our clients see information security as everyone&#8217;s job, and themselves as valuable participants in the process.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/03/technophobe-or-something-more/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Online Security for Kids: How the New York Times article got it wrong</title>
		<link>http://www.securitycatalyst.com/2009/02/online-security-for-kids-how-the-new-york-times-article-got-it-wrong/</link>
		<comments>http://www.securitycatalyst.com/2009/02/online-security-for-kids-how-the-new-york-times-article-got-it-wrong/#comments</comments>
		<pubDate>Mon, 09 Feb 2009 11:16:30 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[child safety]]></category>
		<category><![CDATA[cyber safety]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1082</guid>
		<description><![CDATA[By Trish Smith On January 13, 2009, the New York Times ran an article by Brad Stone on their website entitled, &#8220;Report Calls Online Threats to Children Overblown.&#8221; In this article, the Mr. Stone discussed a recent report by the Internet Safety Technical Task Force (a task force created by 49 state attorneys general to [...]]]></description>
			<content:encoded><![CDATA[<p><strong>By Trish Smith</strong></p>
<p><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/02/red_card.jpg"><img class="alignright size-medium wp-image-1083" title="red_card" src="http://www.securitycatalyst.com/wp-content/uploads/2009/02/red_card-201x300.jpg" alt="red_card" width="201" height="300" /></a>On January 13, 2009, the New York Times ran an article by Brad Stone on their website entitled, &#8220;<a href="http://www.nytimes.com/2009/01/14/technology/internet/14cyberweb.html?_r=2" target="_blank">Report Calls Online Threats to Children Overblown</a>.&#8221; In this article, the Mr. Stone discussed a recent report by the Internet Safety Technical Task Force (a task force created by 49 state attorneys general to look into the issue of sexual solicitation of children online). This task force examined, among other things, social networking sites such as Facebook and MySpace, to assess the extent of sexual solicitation of children by adults.</p>
<p>The task force (which was led by the Berkman Center for Internet and Society at Harvard University) found that bullying among children is, in fact, a far greater threat to them than sexual predators. It also found that when teenagers do become involved with sexual predators online, they are typically willing participants and already at risk because of their home environments or risky behaviors, such as substance abuse.</p>
<p>Leaving aside the questions raised by that last sentence (is a child not a victim as long as he or she is a willing participant? Is a predator less a predator because his underage victim agreed to participate?), I realized after reading the article that Mr. Stone missed the boat entirely.</p>
<p>How did that happen? Well, first consider the following question. What was the point of this article? Admittedly, Mr. Stone may have simply decided to report what seemed to be an important news story. He probably thought he was writing a factual article, not editorializing. However, his opening sentence communicates the message of his article quite clearly: &#8220;The Internet may not be such a dangerous place for children after all.&#8221;</p>
<h3>So is <em>this</em> the true story?</h3>
<p>Â </p>
<p>The idea that the internet is actually safer for kids than we thought it was? Before you answer that question, first consider this one: How safe SHOULD the internet be? How safe do we want it to be for our kids? As the mother of a five-year old, I can say from my own experience that there is no such thing as &#8220;too safe&#8221;. There is also no such thing as &#8220;not so dangerous&#8221;.Â </p>
<p>Articles (and reports) such as these seem predicated on one thing: the idea that we can reduce risk, for ourselves, for our kids, for those we care about. The logical conclusion of that argument is that someday, somehow, with the right technology, we can reduce risk down to nothing. But the truth of the matter is that we cannot. Risk cannot be eliminated; it can only ever be managed. And so the idea that the internet is not &#8220;as dangerous&#8221; as we thought it was, is a non-argument. It implies that there is an acceptable level of risk to our kids on the internet, and that once we reach that level of perceived safety, we can reduce our safety measures. But no responsible parent is likely to say, &#8220;Well thank goodness, the internet isn&#8217;t so dangerous! Now I can let my pre-teen daughter roam the chat rooms unsupervised.&#8221; It does nothing to help parents make decisions about how to protect their children, whether the chance of something happening is 1% or 100%.. As far as helping those who most need information, this article fails miserably.</p>
<p>Â </p>
<h3>So what DO parents and other caretakers need?</h3>
<p>Â </p>
<p>We don&#8217;t need to be told that our fears are unfounded, when we know that the level of risk will always be too high, simply by the very nature of the internet. We need, instead, to be given ways &#8211; proven ways &#8211; to protect our children from the dangers that we know are out there. We need tools that will allow the internet to provide an experience that&#8217;s educational, entertaining, and that doesn&#8217;t put our children in harm&#8217;s way. If Mr. Stone had written an article about that, he&#8217;d have captured the real story of child safety on the internet.</p>
<p>Â </p>
<p><em>Note from Michael Santarcangelo: This an other reasons have led to the creation of our &#8220;Building the Family Safety Net&#8221; seminar and our soon-to-be launched &#8220;Family Safety Net Salon.&#8221; Look for more details this Spring (and an invitation to join before the public launch).Â </em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/02/online-security-for-kids-how-the-new-york-times-article-got-it-wrong/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>The key to successful organizational change</title>
		<link>http://www.securitycatalyst.com/2009/01/the-key-to-successful-organizational-change/</link>
		<comments>http://www.securitycatalyst.com/2009/01/the-key-to-successful-organizational-change/#comments</comments>
		<pubDate>Tue, 27 Jan 2009 11:16:15 +0000</pubDate>
		<dc:creator>Trish Smith</dc:creator>
				<category><![CDATA[Catalyst Considerations]]></category>
		<category><![CDATA[change]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/?p=1022</guid>
		<description><![CDATA[By Trish Smith The recent activity in the economy has brought to the public&#8217;s attention some controversial issues regarding how organizations change (or in this case, how they don&#8217;t). The 700 billion dollar bailout (just for a start) of the financial and automotive industries has focused the spotlight on a very specific issue in the [...]]]></description>
			<content:encoded><![CDATA[<p><strong><a href="http://www.securitycatalyst.com/wp-content/uploads/2009/01/change.jpg"><img class="alignright size-medium wp-image-1025" title="change" src="http://www.securitycatalyst.com/wp-content/uploads/2009/01/change-300x225.jpg" alt="change" width="300" height="225" /></a>By Trish Smith</strong></p>
<p>The recent activity in the economy has brought to the public&#8217;s attention some controversial issues regarding how organizations change (or in this case, how they don&#8217;t). The 700 billion dollar bailout (just for a start) of the financial and automotive industries has focused the spotlight on a very specific issue in the arena of organizational change management: externally directed change vs. internally directed change.</p>
<p>Every day, in industries around the world &#8211; financial, manufacturing, health, education, IT &#8211; change efforts are initiated. One of the most critical factors determining the success or failure of these efforts is whether the change was initiated from outside the organization (government agencies and legislative bodies) or from within (Boards of Directors, departments within an organization, or individuals). Unfortunately, significant change is often initiated from without, despite the fact that experience shows us that change from within is more effective, longer lasting, and more efficiently implemented.</p>
<h3>Why drive change from within?</h3>
<p>Why are internally driven change efforts more successful than externally driven change efforts? There are several reasons for this. The most important is the fact that nearly every organization, even one in need of major change, has the resources, knowledge, creativity, and drive needed to successfully implement a change effort. Failing to tap into those resources is not only wasteful, but communicates to the members of the organization that their abilities and knowledge are not valued.</p>
<p>Additionally, when change is driven from within by those at the upper levels of the organization, employees feel a connection with the change effort at every level of the organization. Their perception that there is buy-in on the initiative by those at the highest levels will lead to them committing to it more fully. Conversely, if employees feel that the &#8220;head honchos&#8221; are not fully committed to the effort, they will not fully commit to it themselves, and the initiative will fail.</p>
<p>Finally, for change to be truly persistent, it must be rooted within the culture of the organization. Organizational culture determines how people within the organization do everything from handling customer complaints to celebrating birthdays. The reality is that whether the culture is positive or negative, healthy or unhealthy, it will drive the manner and methods of everything that is done within the organization. Any change that is not connected to the organization&#8217;s values, beliefs, and behaviors will not succeed. A significant change initiative must, therefore, be solidly connected and in sync with the culture for it to succeed.</p>
<h3>Three reason to initiate change internally?</h3>
<p>1. To profit from employees&#8217; skills, creativity, and resources.</p>
<p>2. To ensure a sense of buy-in at every level of the organization, which leads to employee commitment to the change.</p>
<p>3. To connect change on the deepest level with the culture of the organization, helping to ensure the success of the effort.</p>
<p>Successful change must be directed from within. Other factors also impact the effectiveness of a change effort, but without an internally-driven endeavor, such efforts cannot succeed, and valuable time and resources will be wasted. Perhaps this is a lesson that Citibank and GM could bear to learn.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/2009/01/the-key-to-successful-organizational-change/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

