Showing posts with label Article Review. Show all posts
Showing posts with label Article Review. Show all posts

Thursday, September 5, 2013

Successful Digital Strategy: Bridge the gap between CIO and CMO

CIO & CMO doesn't trust each other, IT doesn't provide fast turn-around!

Business is largely about competition and, even within organizations, a healthy dose of rivalry between colleagues can be a good thing. However, a survey just conducted by Accenture Interactive (see The CMO-CIO Disconnect) points to a downright unhealthy relationship in many C-Suites which can do nothing but damage to firms. 

At a time when many executives say that improving digital reach will be a significant differentiator for their companies, research shows that two of the most important digital leaders — the Chief Marketing Officer (CMO) and the Chief Information Officer (CIO) — do not trust each other, understand each other, or collaborate with each other.

That is very bad news for their businesses and, not incidentally, for their own careers. When IT and marketing departments work at cross-purposes, the results are inefficiencies and mishaps and it is customers who suffer. Potential buyers simply don't have the time or energy to do business with a company that makes things harder for them.

To begin to mend the CMO-CIO relationship, it's important to understand the source of each side's frustrations. CMOs' answers to survey questions make it clear that they view IT as an "execution and delivery" provider, instead of as a strategic partner. CMOs do not believe they are getting fast enough turnaround on projects and adequate quality from the IT departments. Because many CMOs do not believe they are getting the service they want from their IT departments, many bypass the IT department and work with outside vendors. Forty-five percent of marketing executives say they would prefer to enable marketing employees to operate data and content without IT intervention.


For their part, IT executives believe marketers make promises they can't keep and do not provide them with adequate information on business requirements. The CIOs believe the marketing teams often do not understand — or appreciate — data integration or IT standards. Nearly half (49 percent) of CIOs say marketing pulls in technologies without consideration for IT standards. Forty-seven percent say the marketing team lacks understanding of data integration.


CEOs and others in the C-suite should not turn a blind eye to this tension, hoping for it to resolve itself. It is crucial for companies to instill more collaboration and understanding across the functions.

Here are five suggestions for supporting a CMO-CIO relationship that will ultimately benefit customer experience and drive sales:

Identify the CMO as the "Chief Experience Officer."
This is more than simply a change in nomenclature It is a constant reminder to the CMO that the job doesn't end with branding and advertising. The CMO must design and drive a customer experience that is consistently first-rate, at every touch point within the company — a goal that lays more emphasis on the role of IT and the need to reach a deeper understanding.

Signal that IT is the strategic partner to marketing
The CIO cannot be viewed as only the chief technology platform provider; the role must be elevated to a strategic member of the C-suite.

Get the two leaders working from the same playbook
Already, CIOs and CMOs spend more than 30 percent of their respective budgets on technology. It is time for them to agree on key business levers for marketing and IT integration, such as access to customer data and speed to market along with security, privacy, and standardization.

Change the skill mixes
Make sure the marketing department becomes more tech savvy and the IT department better understands marketing. Again, coming together around the consumer and customers will help to breakdown internal silos and align agendas. Upgrading their skills will help both departments make better decisions about technology and understand its impact on business outcomes.

Develop trust by trusting
It is time for leaders in organizations to extend their trust to — and accept it from — business units beyond their own.

Wednesday, November 28, 2012

Chinese Capabilities for computer Network Operations and Cyber Espionage

Chinese Cyber Threat in the Open

When people are discussing nation-state cyber threats against the U.S. in public, they often do so in whispers, assuming that all information is classified. However, it may come as a surprise to many the amount of information that currently exists in the public domain.

One example of this can be found in a compelling report compiled this year for the U.S.-China Economic and Security Review Commission, called “Occupying the Information High Ground: Chinese Capabilities for computer Network Operations and Cyber Espionage,” the paper covers such provocative topics as the Chinese strategic view of cyber warfare, how they’re organized, distinctions between state sponsored and criminal activity, to name just a few.

This paper makes several interesting observations (which will be explored in later posts). Some of them include:

  • Effects of early Chinese Computer Network Attack preparation may not be observable until after conflict erupts.
  • The U.S. lacks comprehensive policy on response to large scale network attack if there is not definitive attribution.
  • Beijing may use cyber policy and legal frameworks to create delays in US command decision making and response in the event of conflict.

While this paper pulls information from a number of sources, it is also possible to gain some insight into potential targets – at least from an industrial espionage standpoint – just by looking at what the Chinese government openly states it will do.

A good place to delve even more deeply into this topic is China’s own “12th 5-Year Plan.” This is the guiding document for the country’s economic plan and they stick pretty close to it. A good analysis of the plan as it pertains to energy can be found here.

Based on the volume of news and other analysis, it can be assumed that industrial espionage is culturally rampant in China. If that’s the case, it also seems inevitable that someone over there will be targeting (the typically more mature) U.S. assets and operations to enhance their own industrial capabilities.

In reading through the KPMG paper above it becomes apparent that Hydro Electric utilities may be targets for cyber espionage:

  • 3 out of 7 strategic investment areas in the 5 year plan relate to energy: clean energy, energy conservation, and clean energy cars
  • Hydroelectric is an area targeted for high growth
  • China’s big 5 power looking at overseas investments…including renewable energy

While there is no actual technical data (logs, reports) supporting the fact that Hydro is being targeted for cyber attacks, and the KPMG paper focuses primarily on business perspectives as opposed to cyber, it is these “open source” business perspectives that guide us toward identifying which cyber assets and information might be potential upcoming targets.

Friday, July 9, 2010

PleaseRobMe website highlights information security threat

The PleaseRobMe website has been launched detailing the whereabouts of social network users, highlighting the fact they are not in their homes.

PleaseRobMe.com was created by Dutch developers who say their website is intended to raise awareness, not to promote burglary.

Co-creator, Boy Von Amstel, told the BBC; "The website [PleaseRobMe] is not a tool for burglary. The point we're getting at is that not long ago it was questionable to share your full name on the internet. We've gone past that point by 1000 miles."

The website uses a compilation of feeds from social networking sites such as, Twitter and Foursquare to update their page labeled; ‘Recent Empty Homes’. A statement on the PleaseRobMe website said; “The danger is publicly telling people where you are. This is because it leaves one place you're definitely not... home. So here we are; on one end we're leaving lights on when we're going on a holiday, and on the other we're telling everybody on the internet we're not home.”

Charity organisation, Crimestoppers, has urged people to think carefully before revealing information on the internet, a spokesperson told the BBC; "We urge users of Twitter, Facebook or other social networks to stop and think before posting personal details online that could leave them vulnerable to crimes including burglary and identity theft."

Thursday, March 12, 2009

Some tips on successful ATM fraud and to protect yourself!

ATM Fraud devices such as skimmers, physical key-loggers, Card Reader/writer are freely available

A bank-machine hacker who reportedly was arrested earlier this month in Turkey gave would-be fraudsters tips on how to install rogue card-reading devices, including advising them to target drive-through ATMs (automated teller machines) and avoid towns with fewer than 15,000 residents.

I basically think fraudsters tips are widely available on internet - all users need to do is bit of research. What we need is fraudsters prevention tips which we will hardly find on internet.

The hacker, who went by the handle "Chao", reportedly was arrested earlier this month in Turkey. He was one of the most well-known ATM hackers in the world, according to Uri Rivner, head of new technologies for RSA Consumer Solutions.

Chao sold fake faceplates that fraudsters could attach to the card slots in ATMs. These "skimmer" devices can read the magnetic stripe of every customer's ATM or credit card, and are often used in conjunction with a hidden camera that watches people enter their PINs (personal identification numbers), Rivner says. Alternatively, criminals can attach an extra keypad on top of the one in the machine and capture the PIN that way, he adds.

After collecting this data over a period of time in these devices, the fraudster can remove the devices and use the information to make counterfeit ATM and credit cards that can be used in stores and ATMs. There are other such devices that can send the information to a nearby computer via wi-fi, he adds. Fraudsters also commonly produce counterfeit cards using information stolen directly from bank and credit-card databases. Overall, card counterfeiting is one of the major types of fraud against ATM and credit card issuers, representing roughly 30% of their fraud losses in the US and other part of the world.

Credit card skimmers are available on ebay quite easily. Once, the fraudsters has the credit card details they can use that details to make duplicate credit card using magnetic card writer device called MSR 2006 or other similar devices.

In an animated online video commercial for his skimmers, Chao provided a glimpse into the world of ATM hacking with a series of tips for potential customers who would buy and install his products.

Picking an ATM to target with this scheme requires watching the surrounding area for days or weeks and taking notes on foot traffic and other characteristics, Chao says in the video. Among his tips are these:

— don't install a skimmer in the morning, because people are more vigilant then;

— determine where a person would have to stand to keep an eye on everything happening on that block;

— avoid blocks where more than 250 people per day walk through, because of the danger of detection;

— don't install skimmers in towns with fewer than 15,000 people, because people in those towns know what their ATMs look like;

— avoid areas with small shops open 24 hours a day, because there may be surveillance cameras and vigilant shopkeepers;

— don't set up in areas where a lot of illegal immigrants live;

— places with a lot of tourist traffic are good;

— look for affluent neighbourhoods and drive-through ATMs;

— ATMs near cash-only bars are a good bet for lots of customer activity.

These tips are basically common-sense. Do you think fraudsters will install skimmer in a town where there is only 2 ATMs and everybody knows each other?

It's fairly rare for a consumer to be a victim of skimming, but Chao's tips indicate consumers are probably safer if they use ATMs at their own banks or financial institutions, says Enterprise Strategy Group analyst Charlotte Dunlap. The safest course would be to use machines inside the bank, though that's not practical for most people's schedules, she notes.

Consumers also should keep tabs on their account activity, via statements or the web, and report any abnormal activity, Dunlap advises. Consumers typically are protected from this type of theft, as they are with a lost or stolen credit card, she says.

I have been reading about ATM-fraud for last 10 years now. I have done enough research to write a book on this topic. All i can say this information is widely available on internet. People using forums, irc channels and groups to trade this information.

I always advise my readers, users, friends and colleagues with the following tips to protect themself from ATM fraud:

- cover your keypad with other hand when entering your PIN

- carefully monitor your credit card statement

- always look around before using ATM machine

- Avoid using ATM machines at pubs, clubs, petrol stations, etc

- Always try to use ATM machines located at banks

- When using merchant, make sure you don’t let your card go away from your sight ( Credit card skimmers can also be installed at merchant POS machines )

- Always pay attention and use little bit of your common sense

- Any transaction which you are unable to recognize – contact your bank immediately

- Reduce your ATM – withdrawal limit to minimal

- Always use bank teller counter to withdraw cash as they manually verify the card-holder

Please contact me if you have any questions.

Tuesday, May 6, 2008

Microsoft Vista - Secure OS Not Failure

Vista's 11 Pillars of Failure - Interesting, Let's have a look!

According to PCmag's John C. Dvorak Microsoft Vista has 11 Pillars of Failure. I am quoting Vista's 11 Pillars of Failure headings from the article and putting my comments. The full article can be read from here.

  1. Market Confusion: I don't think there was any Market confusion at the time of Vista release. I do agree with you guys that Microsoft is not big in marketing there products but still they didn't left any stone unturned.

  2. Code Size: Oh, Come on! Yes, Vista has too big code size. But, it's secure and has less patches then other operating system.

  3. Missing Components: Microsoft is considering an update of WinFS for Vista. Don't know, what's happening in this field!

  4. Laptop-battery life drain: Now, laptop-battery will decide the fate of Operating System? That's funny!

  5. HHD fiasco: I think people are still not fully aware of this one. I suppose, HD industry has started taking initiative in this field for some time now.

  6. Bogus Vista-capable stickers: I haven't experience or heard anything like that. Have you?

  7. Missing drivers: Well, initially there were problems with the drivers. I didn't see any issues lately.

  8. Conflicting advice: I think author didn't do his research properly. Microsoft did launch dedicated Upgrade Advisor. Please refer here.

  9. XP mania: I agree, people are still in love with Microsoft XP. I will say again, Microsoft Vista focused more on security and advance features then XP.

  10. Mediocre rollout: I slightly disagree with this one. Microsoft, i know little that they are not best in marketing but they did their best in providing the best roll out solution for Microsoft Vista.

  11. Performance: Yes, i agree Microsoft Vista is slow and have performance issues. But, if we use good and high speed hardware. Performance is not too bad. After all, Microsoft Vista is far more secured and better Operating System available in market today.

Conclusion: Well, I think author hasn't done proper research before publishing this article. I personally think, Microsoft Vista is the most secure OS available in market to date. According to Jeff Jones, Windows Vista One Year Vulnerability Report, it clearly shows that Vista has fewer patch release then other Operating Systems. I agree, Vista hasn't done well in market yet. In future, i think this will change as people will get more security awareness.