Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Monday, October 18, 2021

Scenario Planning vs Traditional Forecasting

Scenario Planning involves creating response plans for possible future scenarios.  In disaster recovery planning, scenario planning can be an invaluable tool where leaders imagine worst-case situations and develop mitigation plans to address them ("Scenario Planning: Full-Dress Rehearsal," 2003).  Scenario planning does not try to plan, rather, it tries to speculate possible scenarios or stories that can have any possibility of happening.  

 

Scenario planning for an organization has six steps (Tucker, 1999)

1.     Learn the future world perceptions of top decision makers

2.     Gather trends intelligence, and prioritize external forces

3.     Sketch scenarios

4.     Weigh scenario implications

5.     Consider warning indicator signs

6.     Check the organization’s relevance and vision

 

overhead view on business people around desk overhead view on young business people around wooden desk planning stock pictures, royalty-free photos & images


Traditional Forecasting uses historical data and observations to determine future plans.  It relies heavily on the availability of historical data and is often done either yearly or quarterly.  It assumes that the future will not be much different than the past.  Traditional forecasting can often be seen in financial sectors of businesses.  Companies often try to create budgets a year in advance based heavily on the previous year’s data.  


Close up Business people meeting to discuss the situation on the market. Business Financial Concept Close up Business people meeting to discuss the situation on the market. Business Financial Concept planning stock pictures, royalty-free photos & images 

Scenario planning can be extremely valuable for determining what-if and worst-case scenarios, and help companies know what they would do in a specific event.  However, it cannot help with long term projections that a company may need to present to stakeholders.  Traditional forecasting can fill that gap, but these forecasts can be rendered worthless in the face of a major unforeseen event.  

 

In my career, I am seeing the trend moving to more scenario planning, especially in the cybersecurity realm.  We lean heavily on scenario planning when creating disaster recovery plans.  But to fund those cybersecurity initiatives, I have to use traditional forecasting to present my yearly budget and request additional capital.  

 

References

 

Scenario Planning: Full-Dress Rehearsal. (2003). Info - Tech Advisor Newsletter

 

Tucker, K. (1999). Scenario planning. Association Management, 51(4), 70-75. 

Friday, October 1, 2021

Higher Education Cybersecurity in 2021 – key technologies and trends from Educause

Higher education had a whirlwind year in 2020 starting with the COVID pandemic, which continued through 2021.  Information Technology professionals in higher education are tired, but unfortunately, there is no reprieve on the horizon.  COVID brought forth remote work expectations that will continue to shape the future for years to come.  I’ll address one key technology and one key trend below to watch below based on the 2021 Educause Information Security report("2021 EDUCAUSE Horizon Report, Information Security Edition," 2021), with supporting forces explaining the urgency behind these issues.

 

Keep on fighting the good fight higher ed IT!  We are in this for the long haul, but we will be better for it.  

 

Key Technology – Endpoint Detection

 

Security incidents and ransomware are on the rise in higher education ("2021 EDUCAUSE Horizon Report, Information Security Edition," 2021).  Institutions are having to transition from response and recovery to prevention and identification strategies, including blocking malicious emails and controlling access.  This has promoted the need for endpoint detection and response.   

 

Two forces impacting the technology

 

Based on research from Absolute, over 70% of all security breaches start at endpoint devices, primarily through compromised credentials or degraded security systems ("2021 EDUCAUSE Horizon Report, Information Security Edition," 2021). Endpoint detection systems allow for remote remediation of security incidents, allowing for immediate mitigation of threats.  This greatly reduces the potential adverse effects of a cyber incident and has a significant positive impact on information security but can be costly and require a significant financial investment on behalf of the institution.  However, the cost of a potential cyberattack is daunting, with average data breach costs of 3.9 million, the potential for disrupted online learning, and can hurt an institutions’ credit profile (Seltzer, 2021).                    


 

Relevance for Information Security – Endpoint Detection and Response. [Infographic]. 2021 Educause Horizon Report, Information Security Edition. https://library.educause.edu/-/media/files/library/2021/2/2021_horizon_report_infosec.pdf?la=en&hash=6F5254070245E2F4234C3FDE6AA1AA00ED7960FB

 

Another force impacting endpoint detection is the increasing expansion of the Internet of Things (IoT). Students and staff bring a wide variety of devices on physical campuses daily, from smartphones to laptops and tablets.  However, the IoT will create new devices and technologies that we can expect consumers to adopt and use in their daily lives.  Gartner expects that IoT devices will increase by 43 billion by 2023 ("2021 EDUCAUSE Horizon Report, Information Security Edition," 2021), which will force the higher education industry to develop a plan to secure networks against non-University devices that need network access.

 

Key Trend – Remote work

 

Remote work was identified as an Uber Trend for in the 2021 EDUCAUSE Information Security Horizon Report because it has had far-reaching implications for information security and will continue to be a major force for years to come.  It also presents the question of the “new normal,” and how higher education will look in the future, particularly for higher educational institutions with all or most of their students classified as on-campus learners.  



Man on couch working on laptop with dog [photo]. Business Quick. https://bq-magazine.com/5-ways-you-might-sabotage-your-own-remote-work-efforts/


Two forces impacting the trend

 

One force impacting this trend is the control of devices allowed on a university network for business purposes.  For example, should colleges ban the use of personal devices for business work, or block personal devices from accessing staff networks?  If personal devices are allowed, should universities pay for endpoint protection for all personal devices that access the network, and be expected to be able to afford that expense?  If universities say only university equipment can be used, are they slowing down progress on business-critical work, and is that plan feasible in a new era of work-from-home employees?  

 

A second force impacting this trend is that many employees do not want to come back into the office. Working from home can give people better work-life balance and can allow hiring managers a deeper talent pool.  However, many higher ed employees at campuses with on-campus students need to return to their campus before students to ensure some normalcy.  But, there an be disparity among who returns and who stays as a work from home employee.  Slack’s “Remote Employee Experience Index” shows that only 12% of skilled workers plan to return exclusively to an on-site office ("2021 EDUCAUSE Horizon Report, Information Security Edition," 2021).

 

 

References

 

2021 EDUCAUSE Horizon Report, Information Security Edition. (2021). Retrieved 9/27/2021, from https://library.educause.edu/-/media/files/library/2021/2/2021_horizon_report_infosec.pdf?la=en&hash=6F5254070245E2F4234C3FDE6AA1AA00ED7960FB

Seltzer, R. (2021). Cyberattacks Pose Credit Risks for Higher Education. Inside Higher Ed. Retrieved 10/1/2021, from https://www.insidehighered.com/quicktakes/2021/03/31/cyberattacks-pose-credit-risks-higher-education

 


Sunday, September 26, 2021

Diary of a purposefully unreasonable and possibly annoying techie

A little about me - I've spent my life finding solutions to problems, and have found that my passion is rooted in using technology to help solve problems and create innovative solutions.  My background is in computer programming, project management, software design, integrations, and database programming and design.  In the past decade, I've been able to apply those skills and more of my soft skills into being a manager and leader, where I try hard to buck the status quo and develop new ways to solve old problems.  

I am often the person who asks why or why not.  I am OK with being around those that disagree with me, and initiate tough conversations in an effort to find solutions.  I would rather be seen as unreasonable and difficult than suppress questions that can trigger change.  I aggravate people who want to maintain their status-quo, and I work hard to anticipate the next need.

However, my REAL full-time job is that I am a mom of three kids and have been married to my husband for 15 years. I have twin 13 year-old boys (who look and act nothing alike) and an 8 year-old girl.  Between school work and activities, we don't stay still often.  Between basketball, baseball, football, piano lessons, and more, it can get very hectic.  We also have two dogs that probably know the word "snack" better than they know their own names.  

In the summer of 2020, I embarked on my newest journey - completing my Doctorate in Computer Science with a focus in Cybersecurity and Information Assurance.  Why?  Honestly, sometimes I still ask myself that.  But, I have a desire to constantly learn more about the field of computer science and information security, and I want to be part of the future of emerging technology.  Also, I am not ashamed to admit that there is some personal pride involved with adding the Dr. prefix to my name.  

As for what I'm doing here and what this blog will be - I'm not entirely sure.  It could be good, it could be crazy, and some of my ideas may prove to be hilariously wrong.  Only time will tell.  I started this as a requirement for my CS875 course, and my focus is documenting current innovations, predictions for the future in regards to tech, and ideas for a better world using technology.  I'm sure it will evolve to cover many different topics over time, as well as my personal research into tech and cybersecurity.  

"There are far, far better things ahead than any we leave behind." ~ C.S. Lewis