Sunday, 4 November 2007

7 Stages of Security Man - Part 5 - Management

I had craved a management position for some time, and getting it was somewhat of a coup for me. I was very quickly fast-tracked through an organisation where there were engineers with higher qualifications than I, but none with the breadth of experience, which was what was needed.

The security distributor I was employed by was being acquired by a much larger IT distributor, and the bigger we looked from the outside during due diligence, the better. I was made very high profile in a very short time. I wish I had started blogging then in hindsight, I had access to some of the best security engineers in the country, sales guys in every large SI, reseller and corporate in the UK worth talking about and all of them wanted to talk to me about security. In short, I had my finger on the pulse, and could even influence where security was going in specific and general terms. I loved it, and then we were acquired.

Acquisition is uncomfortable at the best of times. When you are a newly incumbent manager of people with more history in a company than you, it quickly becomes painful. When the overall manager who has employed you leaves, and then the MD, it becomes impossible to stay. I was offered a new position as a Product Manager in the newly formed company. It would have been easy, saying 'I think we should keep this and lose this' sucking up to vendors and resellers, etc. Real security easy-street, but it was not for me. I was losing the buy in of the engineers rapidly as more and more people left, and the new company wanted to use me as a figurehead which I was not prepared to be, it would have just pissed off too many people.

Luckily for me then, I was offered a job as a Product Manager in Barcelona at the same time. The choice was relatively simple, but with wide ranging implications for a newly married and settled man.

7 Stages of Security Man - Part 4 - Settling down

Working at Vormetric was fun, but I was never particularly mentally stretched. Whereas my previous job had been a constant learning experience I now had one product to learn everything about, or at least as much as I needed to sell it, which it turned out wasn't that much. However, I did start travelling, a lot. My particular most painful memory is flying to Munich for a 10am start, which meant leaving my house at 4am. I finished around 7pm in Munich and finally got back home to my cold damp flat in the UK at 1am the next day.

There wasn't much business coming in to be honest, and I had to take what I could, where I could, often at short notice. The market for file encryption in Europe is limited, it isn't really driven by PCI like database encryption is. It is very much event driven, and that is like looking for a needle in a haystack. Vormetric is a fantastic technology, but I think it is better suited to becoming a feature of something else as this is a much easier sale. Symantec (Veritas) would be the perfect acquirer as it is something they need and can't do as well themselves.

There was a lot of down-time between engagements, so around this time I decided to do something to keep me focused on security. Working at a vendor can make you very blinkered in one direction and I wanted a broader view. I studied for, took and passed my CISSP in 2 months. I wouldn't say it was easy, but I was in the right position to do it. I was very focused and knew what I wanted from it.

I had just moved into a new flat, a bachelor pad I suppose you could call it, although my ex-flatmate's sister was increasingly there, cramping my bachelor style. I suppose it's my own fault for proposing to her. It was around that point that I decided if I was to be a responsible married type, I would need to be a bit more home-based.

So, when I got a call from a local recruitment agent saying that there was a management position coming up at a distributor near me, I was really interested. When I went to interview to meet the Director of Client Services, I was immediately interested further. He was another genuinely nice guy, I knew I would get on with him from the second we started talking.

Saturday, 3 November 2007

On your doorstep...

I am. If you live in San Francisco that is. I'm staying at the Chancellor Hotel in Union Square all week.

More of my life story tomorrow, and maybe I'll pick another technology to write about now I'm here.

I was sitting on the plane opposite someone from Centrify, which is a technology I like very much, but he was too far away to strike up a meaningful conversation and I didn't like to say "I've been reading your PowerPoints over your shoulder" as an ice-breaker.

Maybe if someone from Centrify wants to get in touch I'll do something on them, but I'm meeting Kevin from Vontu on Thursday, so that might be a good one to follow up on too.

In San Francisco, the possibilities really are endless... but for now - I've just landed after a 10 and a half hour flight from London and an hour of driving around town looking for a way to the hotel. It's now 4am UK time. My head hurts. I need sleep.

Friday, 2 November 2007

7 Stages of Security Man - Part 3 - Confidence

I didn't particularly enjoy my time with the reseller, despite learning a lot about security. In fact, I think the fact that I wasn't enjoying myself was only saved by the fact that I really enjoyed the things I was looking at. The management was bad, I disagreed with the sales approach and my father ailed quickly. I was happy to get out, and planned to go traveling with my sister for a while, but as a last act of disappointment I was made to serve out my notice until the very last possible moment and missed the chance to join her in Monaco.
Thoroughly dejected, but full of interest in security and technology, I took a job as a network security administrator at a local MSP in Winchester, where I lived close to my mother who I had obviously worried about being on her own. The work was simple enough, but a fantastic ground for learning more about networks, security and most importantly, trusting people who I worked with. My boss at the MSP was a true friend, and has remained close ever since. He and his wife were at my wedding last year and we are still in regular contact.
I also had time to myself. I was doing shift work which allowed me to use the local gym in the mornings when everyone else was at work, or in the evenings before everyone got out again. I lived with a friend I had known for years, and we lived like students for a few months before we both stopped drinking. Neither of us has drunk again since for the good it did us! I also married his sister... last year sometime.
All of this lead to me becoming increasingly more confident with myself and in my abilities. My knowledge of the network became very broad, and my depth of knowledge in security meant that I was prepared for another challenge in the same area. I was beginning to get calls from recruiters (which now never stop), and when I got a call from Vormetric to be their SE in the EMEA region, I jumped at the chance.
They were interested in my previous experience with Ingrian of course, I was interested in the money. I'm still interested in the money of course, but now I also get to do a load of other stuff I picked up on the way too.

7 Stages of Security Man - Part 2 - Sentience

Having been in London for my first dismal job sufferance, I returned home to Winchester when my father became terminally ill in 2000. I was job-less and feckless (I didn't have a job and didn't give a feck) having lost all faith in human kindness at the bank, and didn't really want to do anything having had the news of my father's ill health.

My aunt was a careers officer for the local University at the time, and regularly sent me ideas of what I could try. I think she thought rather more of my abilities than I, or indeed any of my tutors had. One day however, I put my name down on the University jobs board, and received a handful of replies.

One such reply was from a guy who was setting up his own reselling business, and needed a technical person to help out. It turned out I had been at school with his wife and brother-in-law, and that was all the reference I needed. In the main we sold RSA SecurID and nCipher cards. We also dabbled in RSA Keon (urgh), Cleartrust (argh!) and various other minor annoyances. I quickly set up the network, saw in and out in rapid succession of around 10 sales people, learnt SecurID inside out, and got to grips with nCipher. At the same time my father became increasingly more ill and finally passed away in December of 2001.

Around this time however, we landed a large deal with nCipher, to install 20 cards at a large broadcaster in the UK. A company named Ingrian Networks (more of them later...) were using their cards in their new whizz-bang SSL device. They needed a strong reseller in the UK to help them conquer the market, and chose our little 4 man shop as it was at the time. I worked with the American SE very closely for some time, and we all thoroughly enjoyed ourselves. However, Ingrian did not see the sales they were expecting from us.

The relationship did not continue, but I was already out of the door by that time and on to pastures new. With my new found confidence in the network and now hooked on security devices, I joined an MSP, controlling financial websites across the world. Time to get my own back on the bankers...

Thursday, 1 November 2007

PacketTrap


Interspersed with my 7 Stages of Security Man posts I'm going to be talking a bit about new technologies which I'm looking at at the moment. In fact, now that I have 'Data Centric' up and running, I'm moving all my sensible, well thought out, pure security thought over there, and keeping all the ramblings and opinionated rantings over here. I wonder which will get the more subscribers?

I like little west coast tech companies, especially those who go on to become big global ones, if I have stock options. I don't (yet) have stock in PacketTrap, but who knows how well this write up will go?

I had a call from a company called PacketTrap tonight, based out in San Francisco, where I am flying on Saturday, but sadly I'm probably too busy at Ingrian corporate to go and visit them this time around. I've said I'll catch them at RSA instead, by which time they will be launching the Pro version of what I've just seen.

When I first saw PacketTrap, I had to ask myself why anyone would buy it. It has a number of tools, ping, portscan, DNS queries, whois, WMI scan, etc. built in to one device which you can sit on your network - but when I was a network admin (more on that later) I had all those tools on my laptop.
Aha, and there's the rub.
Just as routers became necessary to take the load off machines in a network, now a completely separate and distinct device is needed to investigate and manage the network. It's actually quite neat, and that's what you want in a complex network, some tidiness.

Every customer I've ever been in to has asked 2 questions (amongst others of course, just 2 would be silly):
"How do I manage 'it'?"
and
"What kind of reporting does it have?"
Nowadays of course we have silly devices which collect all the logs and make them into pretty pictures, just because the CFO needs something to put on his wall. We have devices which report in real time and send emails to the CIO about who's doing what with whom, where and for how long, with which instrument, because he needs something to show to the CEO when he's asked what he does all day. Reporting and management are king, they will always be king because the C-suite don't give a monkey's about what the techies are doing, they just care that something is being done and they can see the results of that. If they can then use that data to make something more efficient, or to show the shareholders that they aren't wasting money printing off reports all day, then it's gold stars for everyone.

In Silicon Valley, with a great sounding team of people on board, this start-up should do well. I think they will get some useful feedback and if they take it into consideration when producing the next 'Pro' release, we will start to see them at shows and in a network near us. The messaging will need to be right, but as long as they remember that no-one cares how much work the network admin has on, and he can automate it himself, but the CEO, CFO and CIO have all the power and money in the company, they have every chance of making this work as a product too, then maybe we can slip in something useful for the poor admin too.

PacketTrap launches on 7th November 2007, go visit their website for more info. My work here is done.

7 Stages of Security Man - Part 1 - Emerging

I've been suffering from 2 complaints which I have since found out are called 'up to my eyeballs in alligators' and 'Blogger's block' - thanks to Brian Honan for that one. shrdlu has suggested I get around it with Primal Scream Podcast therapy, but I'm not sure anyone's going to download that. Brian came back with the suggestion that I write about how I got to be where I am today, and I wondered if it might be kind of therapeutic, cathartic if not chaotic. I've had quite a few jobs, so I'm going to serialise them and pull out a few of the security and life lessons I've learnt along the way. Enjoy.

I've been in security for about 7 years now, and in networking before that, so 'IT' for nearly 10 years, since I left University with a quite useless degree in Physics which I vowed never to use. That's not to say Physics in useless, quite the opposite, that is to say that I had given all I had to spare to Physics by the time I left, and the loss to both parties was not great. Einstein I am not, but you probably realised that by now.

In the early days of my career I worked for an investment management bank in London, with a million legacy systems and every new piece of equipment you could possible sell to an idiot in a suit. Investment bankers are a vendor's dream, rich and stupid, unbelievably arrogantly stupid beyond belief in the main. They are the helpdesk monkey's nightmare for the exact same reasons however. I was shouted out day and night-shift for various reasons such as WHY ISN'T MY PRINTER ON? Er, try the plug mate. CHANGE MY PASSWORD, NOW! I just did fella, you just locked yourself out again because your cAPS lOCK's stuck on. Et cetera.

I rapidly got bored of the arrogance, I can't abide being pushed around, especially when it is by people more stupid even than I. Banking was not for me, much like it isn't for the vast majority of people who have any self respect. Clever people, great: push me around mentally and I'll bow to your superior brain, but idiots beware. And so on to my second job.

MadKasting