I’ve been nominated for a Security Serious Unsung Hero award in the Best Educator category. This will be awarded to a professor, lecturer or teacher who leads by example to inspire and motivate the next generation of cyber security professionals. I’m humbled to be considered. Thank you!
Join me at the event.
Over the past year I’ve worked as a core part of the KPMG’s Global Cyber Strategic Growth Initiative as the lead for service development activities, with a focus on working with member firms to deploy capabilities in order to ensure consistent delivery and quality across key growth areas.
I was responsible for the roll-out of cyber security services that included developing sales and delivery accelerators, accreditation requirements, learning pathways, vendor ecosystem and quality and risk management principles across EMEA, APAC and Americas.
To achieve this, I created a service development framework and worked with numerous stakeholders across the firm’s network: global deployment, service development leads, acquisition leads, risk management and key member firm cyber representatives and regional leads.
I also developed a method for the in-country adoption of deployed capabilities and supported both global and in-country risk team members in the evaluation of risk when taking services for client use.
I ensured the sustainability of deployed capabilities through the implementation and use of delivery frameworks and tools, and assigned ownership for the upkeep of deployed capabilities. I worked with member firms to promote the adoption of prioritised services; developed adoption timelines and targets for deployed service.
One of the existing aspects of the role was alliance, acquisition and investment integration support where I collaborated with the relevant stakeholders to deploy and embed offerings obtained through alliances to member firms while monitoring progress against agreed budgets, milestones, deliverables and benefits for capabilities being deployed.
By the end of the programme, I deployed Cyber Maturity Assessment, Identity and Access Management, Industrial Internet of Things Cyber Security, Privacy and Cyber Incident Response services to 19 countries around the world.
This resulted in achieving significant revenue and market share growth for cyber security services of my firm globally. KPMG International was also named a leader in information security consulting services in 2016 and 2017 according to Forrester Research.
The Psychology of Information Security – Resolving conflicts between security compliance and human behaviourPosted: November 26, 2015
In today’s corporations, information security professionals have a lot on their plate. In the face of constantly evolving cyber threats they must comply with numerous laws and regulations, protect their company’s assets and mitigate risks to the furthest extent possible.
Security professionals can often be ignorant of the impact that implementing security policies in a vacuum can have on the end users’ core business activities. These end users are, in turn, often unaware of the risk they are exposing the organisation to. They may even feel justified in finding workarounds because they believe that the organisation values productivity over security. The end result is a conflict between the security team and the rest of the business, and increased, rather than reduced, risk.
This can be addressed by factoring in an individual’s perspective, knowledge and awareness, and a modern, flexible and adaptable information security approach. The aim of the security practice should be to correct employee misconceptions by understanding their motivations and working with the users rather than against them – after all, people are a company’s best assets.
I just finished writing a book with IT Governance Publishing on this topic. This book draws on the experience of industry experts and related academic research to:
- Gain insight into information security issues related to human behaviour, from both end users’ and security professionals’ perspectives.
- Provide a set of recommendations to support the security professional’s decision-making process, and to improve the culture and find the balance between security and productivity.
- Give advice on aligning a security programme with wider organisational objectives.
- Manage and communicate these changes within an organisation.
Based on insights gained from academic research as well as interviews with UK-based security professionals from various sectors, The Psychology of Information Security – Resolving conflicts between security compliance and human behaviour explains the importance of careful risk management and how to align a security programme with wider business objectives, providing methods and techniques to engage stakeholders and encourage buy-in.
The Psychology of Information Security redresses the balance by considering information security from both viewpoints in order to gain insight into security issues relating to human behaviour , helping security professionals understand how a security culture that puts risk into context promotes compliance.
Information security professionals not only have to deal with change, more often than not they represent change. It might be changing the way a company manages access to its systems, works with third-parties or anything else.
To be effective with the change management process, security professionals should work with the business, demonstrating the value of security.
John Kotter in his book Our Iceberg is Melting tells a story about a penguin colony, which demonstrates basic principles of successful change management:
- Establish a sense of urgency
- Create a guiding coalition
- Develop a change vision
- Communicate the vision for buy-in
- Empower broad-based action
- Generate short-term wins
- Never let up
- Anchor new approaches into the culture
I just returned from my trip to Bangalore, India, where I was asked to deliver a series of training activities to the KPMG offshore teams. Spending a week there came with lots of wonderful insights.
First of all, India is a beautiful country. I didn’t really have a lot of time to travel around, but I still had a chance to visit the Bangalore Palace, drive up and down the Mahatma Gandhi Road, see the Parliament and many beautiful parks.
Moreover, apart from delivering training sessions myself, the local leadership organised a presentation for the UK team, where we were described the services they offer globally. I was impressed by the level of innovation and standardisation, which clearly demonstrate the rapid technological growth in India.
I’ve had a chance to work with some of the marvelous members of our offshore team before, and it was very valuable to finally meet them in person. I had an opportunity to interview a few people for a position in my programme and we are already on-boarding the successful candidate.
Not only I was able to share my knowledge and meet some lovely people, but I could enjoy a brief but wonderful taste of India and its warm hospitality. I’m sure the effectiveness of our communications and project work will increase substantially in going forward.
Imagine the following situation. A father with his son are driving to the camping site for the weekend. The deer was crossing the road and the car hit it. The father dies in the accident and the son is badly injured. He was swiftly brought to the emergency room and requires surgery. A surgeon enters the room, sees the boy and exclaims: “I can’t operate – this is my son!”.
How is it possible?
Think about it for a few moments…
Didn’t his father die in the accident? The answer is really simple. Read the rest of this entry »
A knowledge management system is an integral part of a modern organisation. It involves processes, people and technology that make sure information is not only kept in the individuals’ heads but is shared with the whole department. It is usually implemented in the form of an intranet portal which requires processes to maintain it and people to support it.
Because I believe having the right information at hand is crucial in making effective business decisions, I volunteered to take on the role of a knowledge management champion in my department. A knowledge management champion is the person who oversees the adequate operation of the system. In this case, to lead the project that would re-launch the system that wasn’t being fully used.
In my company, the knowledge management system is mainly intended to support the bid management process, where we respond with proposals to fulfill specific requests from our current or prospective clients. It is also used to assist project delivery when a piece of work is won.
As a first step, I managed a team of four to analyse the current state of the system and to gather feedback from the users to understand the limitations they felt they encountered. We discovered that the portal was hardly being used because some users were unaware of its existence, and many others found the navigation not very user friendly. This meant that the information stored in it was out-dated.I then developed a strategic plan to promote easy access to static information such as templates, proposals and engagement created data for the department. Several design changes were introduced based on feedback from the users.
Because the portal is only useful if it actually contains data that can be easily searched for, the next step was to collect as much information as possible from the department. We held multiple interviews with engagement managers to gather case studies and relevant data to add to the system. To ensure that the quality of the data collected was constant, we created a case study template consisting of three main parts:
- The client’s challenge: the problem the current or prospective client needs addressing.
- The approach: how the problem was tackled and solved
- Benefit to the client : the specific and measurable positive outcomes
When the design changes were implemented, the outdated data was removed and a sufficient amount of information was collected, everything was ready for the system’s re-launch. This re-launch was important enough to be given a presentation slot at the quarterly departmental meeting, where we talked about the improvements, encouraged the users to use the system and requested further feedback.
Though this successful project, as all projects, had a defined desired outcome due by a specific date, knowledge management never finishes and requires continuous improvement. It is now in the operational “run-and-maintain” state. New information is being uploaded to the portal and processes are in place to make sure it is maintained and information remains up-to-date.
I also organise regularly and participate in knowledge sharing events. I believe participating in such events and communicating lessons learnt to the rest of the team can help everyone to avoid mistakes we’ve made in our projects and improve the quality of deliverables.
Image courtesy of cooldesign/ FreeDigitalPhotos.net