An Exponential Adoption Curve:
The Changing Face of Data Security in Partnering
Strategic Alliance Magazine — Q1 2018
Cover story by Cynthia B. Hanson
“Oh! What a tangled Web we weave,” Shakespeare might have intoned about the alliance management profession—and industrial business in general—had he lived in the present Age of Digital Transformation. The Internet of Things (IoT), artificial intelligence (AI), changing cryptographic and encryption security protocols, blockchain—understanding today’s interlinking digital drivers is tough enough without having to integrate them into complex, multi-partner, and multi-industry collaborations.
“Technology is changing so fast that we are in an exponential adoption curve. You have an acceleration at the end that goes into infinity,” says Ron Long, CSAP, alliance director, global industry solutions at software maker NetApp. “Artificial intelligence is making that change through machines based on patterns, and they are executing and driving the transformation.”
And leaving behind a wake of new security concerns, Long then warns. Many others agree with his assessment.
“The amount of digital disruption that is occurring—whether in IoT sensors, new business models, the amount of data being produced every day, and the introduction of the cryptocurrencies—is creating unlimited opportunities for threat factors … that bad actors can attack,” concurs Steve Benvenuto, senior director in the global security partner sales organization at Cisco Systems.
The digital ripple effect can make alliance waters difficult to read. Cumulative forces of change are converging to prompt alliance professionals to consider new business models and accompanying security protocols. Well they should. Innosight, a management consulting company, projects in the “2018 Corporate Longevity Forecast: Creative Destruction is Accelerating” that “at the current churn rate, about half of all S&P 500 companies will be replaced over the next ten years.” Eroding corporate longevity is “a ‘confidence bubble,’ in which leaders expressed high degrees of confidence they could transform but at the same [time] seemed to underestimate specific threats and opportunities.”
Underestimating threats and ecosystem opportunities could be the single most important mistake an alliance professional could make in the coming years. Consider the 2016 “BAE Systems Cyber Security Survey Report,” which found a gap “between companies’ perception of security preparedness and their actual ability to defend themselves from cyber threats.” The survey found that 96 percent of the 300 respondents from the financial services, insurance, and IT/tech industries believe their company’s information security and ability to protect data was good or excellent, while revealing:
The Nuts and Bolts of Creating Secure Systems
Responding to growing concerns about vulnerabilities in multi-party vendor relationships and collaborations, the National Telecommunications and Information Administration (a branch of the United States Department of Commerce and the principal adviser to the president on telecommunications policies) and the FIRST Vulnerability Coordination Special Interest Group (an international confederation of computer incident response teams) recently released Version 1.0 of the “Guidelines and Practices for Multi-Party Vulnerability Coordination and Disclosure.” Past efforts “have not adequately addressed the additional complexities of multi-party vulnerability coordination (multiple vendors and other stakeholders),” the introduction states. “The purpose of this document is to improve multi-party vulnerability coordination across different stakeholder communities. Multi-party coordination and disclosure involves multiple vendors and can also include coordinators, defenders, users, and other stakeholders.”
To address this growing security challenge, the document contains two parts: Guiding Concepts and Best Current Practices derived from a set of Multi-Party Disclosure Use Cases. The five use cases provide different security vulnerability coordination scenarios. The guidelines include best practices tips for multi-party coordination, such as:
The most important thing for any company entering a collaboration to remember is that they can never completely abdicate responsibility for security,” says Mike Chapple, associate professor of IT, Analytics & Operations and academic director, masters of business analytics, at the University of Notre Dame’s Mendoza College of Business. “Every collaboration, from engaging a vendor for cloud services to sharing data with marketing partners, falls under what cybersecurity professionals call a shared responsibility model. Both organizations have some responsibility for security, and the terms of the partnership agreement should clearly spell out who is taking care of each aspect of security.”
This is especially important in the case of regulated industries, where companies also need to make sure they are meeting all compliance obligations, he adds.
“When you have a complex regulation, such as PCI DSS [Payment Card Industry Data Security Standard], you’ll want to run down the checklist and agree, in writing, about who will handle each requirement and which will involve the participation of both parties. Partnerships also introduce new compliance burdens, such as managing HIPAA [Health Insurance Portability and Accountability Act] business associate agreements. Security should absolutely be an early part of the conversation in any technology initiative, including digital transformation initiatives. If you include security as a design requirement, you get much better results at a much lower cost than if you attempt to ‘bolt on’ security after the fact,” he concludes.
For Jawahar Sivasankaran, senior director sales, strategic partnerships for security at Cisco Systems, the most critical security planning considerations in multi-party collaboration fall into these categories:
When it comes to designing tools into the model, “what need to come together are infrastructure, data, and applications,” adds Sivasankaran, who leads Cisco’s security business development with strategic partners. “Those are the three technology pillars for multi-party collaborations. You then put the private and public cloud underneath that. It’s a big shift from the ‘90s, where you would set up an extranet. You just can’t isolate and do [these] things in the extranet model. They need to work seamlessly and not in isolation,” he states.
“Realistically speaking, alliance managers need to work within the confines of what already exists today, such as 20- to 30-year-old Internet technology and industrial systems like railroads that have been digitized—but not with the right security structure. The reality is, we don’t have a clean slate to start with. The two walls are different. The short answer is, we’ve got existing infrastructure to build upon, and blockchain will help,” he says.
The Blockchain Link and Evolving Tools
It’s a buzzword that has popped up in nearly every interview I conducted on this topic. Originally used as a platform for bitcoin, blockchain is a ledger technology that has evolved into multiple business applications (see “How Blockchain Adds Security to Supply Chains,” Page 26). It’s used for “streamlining operations and creating new opportunities,” according to the ZDNet article and video “Blockchain Explained in Plain English.” While it has broad applications for financial data, it can be used for healthcare, government, food safety networks, shipping, and many other applications because the blocks of information use cryptography to link transactions and secure data, increasing efficiency and reducing costs. The segments or “chains” are replicated throughout the system; corrupted portions can be restored.
IBM, a leader in blockchain technology, is actively involved in creating blockchain networks as well as collaborating with more than 100 startups, new tech companies, entrepreneurs, and existing IBM partners and clients. The networks use the open source Hyperledger Fabric with the IBM Blockchain platform built on top. Security, encryption, governance, and privacy are configured by the user.
“It’s permanent and encrypted at each block of the journey through the chain, so it is much more protected,” enthuses Janine Grasso, vice president, strategy and ecosystem development for IBM Blockchain. “Using blockchain will absolutely make the data within much more secure” than present data protection systems, she adds.
The framework is tailor made. Like individualized healthcare, blockchain networks must be constructed in unique arrangements depending on the needs of the various partnering entities. “Blockchain only hit the mainstream in 2017. We’re still learning, and it’s still evolving with different companies in the ecosystem,” says Grasso. “It’s moving faster than we even anticipated. Because there are so many different ways we can apply the technology, it’s making us rethink ways for partners and consumers to adopt it.”
She offers an example: In 2016, IBM and Walmart saw the need for creating a solution for the food industry that provides a clear trail in the event of contamination. They started a pilot with Dole, Kroger, Unilever—a total of nine food industry giants—to explore how blockchain technology could be used to trace potential food contamination from source to shelf. A mango grown in South America touches many points on its way to the store shelf as it goes through transportation, distribution, and retail points, she explains. “If it becomes contaminated, it would take weeks, even months, to figure out where it came from. With IBM’s blockchain solution, it can be determined where that mango came from in seconds, and what shelf it’s on.”
In terms of multi-partner collaborations, “the answer is blockchain,” emphasizes NetApp’s Long. “It’s the biggest change you will see in multi-industry collaborations … the most pervasive, multi-company digital security that is emerging on the market, the most pervasive tech that will transform the digital market we’ve had in the industry since the Internet. It is non-infrastructure dependent. It can be run through any platform. It takes the authentication and the data chain and makes it available across all different kinds of industries. It basically eliminates single point of failure.”
Think about before the Internet, when you went to telecommunication providers and bought a communication line that was connected to other lines in a point-to-point environment, Long explains. “When one point failed, there was no way to get around it. What evolved out of that was the routing protocol, which guaranteed that you could always get to where you wanted to go, because if there were blocks in the path, the software in the routes would route around that block. When the Internet came along, all communication protocols were on the grid. Blockchain is a data communication protocol—the blockchains are secure in their own right, and if someone tries to hack it, they can’t do it. You can’t break the chain. And those chains are populated all over the data communication infrastructure, so there are copies of it in other places,” he adds.
“If you look at trust boundaries, blockchain is a great answer to how to approach malware,” Sivasankaran adds. “You contain the problem within specific trust boundaries, so only a portion of the ecosystem gets impacted. Blockchain is one tool in the arsenal.”
Finding failsafe tools “is not easy,” he continues. “Even with one organization, it’s difficult to adapt and put the right tools in place. Multi-party collaborations get more complicated.”
Which means many companies are looking to simplify—and complex multi-partnering models provide that much more incentive. The demand has resulted in an upsurge in boutique software licensing companies and vendors. “The thing to keep in mind looking at any kind of collaboration is that organizations are not necessarily looking to acquire tech or products. They are looking to solve problems and acquire capabilities. That’s different than what’s traditionally been the way tech companies sell their offerings,” observes Joe Schramm, vice president of strategic alliances at BeyondTrust, which is presently working with partners to bring new managed-services offerings to market.
Onboarding Office Culture
Company culture is also key to a successful digital transformation. Some experts say it’s the most important component in getting your organization through the transitioning obstacle course—from communications to security compliance challenges. There are a number of things that you can do to improve compliance within a transitioning organization, offers Alex Blau, a behavioral scientist and a vice president at the New York nonprofit consulting firm ideas42 (see “Why Company Leaders Underinvest in Security,” Page 28.) “One is around making awareness programming more robust. Usually, organizations do awareness programming both because they earnestly want their teams to exhibit good cyber hygiene, but also because it’s one of those boxes you can check off to ensure the organization is in compliance with an existing security framework. However, because awareness is often treated as a box to check, organizations don’t really always do a good job.”
Unfortunately, awareness programming is often thought of as an annual requirement in which an employee “sits in front of a lecturer or some computer training module for an hour or so and learns about what they shouldn’t be doing with the company’s computers,” he continues. “But the best programs out there make awareness programming an ongoing part of everyday operations. They’re using simulated phishing tools, and providing teams ongoing feedback about their computer behavior and what they can do better. A good incentive program might nominate security champions within the organization and try to make security awareness more fun. There’s a lot that can be done in this space, but the big takeaway is to try to bring a security mindset into everyone’s everyday,” he concludes.
Schneider Electric embarked on a massive digital transformation initiative on Jan. 1, 2018—not only at the employee level, but also with customers and partners. The company renamed the IT department Schneider Digital and assigned a chief digital officer to create “a truly digital transformation.”
“Schneider is heretofore an analog business that we are digitizing—powered by people, process, and technology. The business that I am responsible for is a very people-intensive, process-heavy, but tech-light business,” explains Tony DeSpirito, CSAP, vice president, general manager operation services. “To succeed and scale this business, I need to bring more tech and digitization to these offers.”
Recently incorporated collaboration tools at Schneider are Skype for Business and Box—a competitor to Dropbox that is used for storage. Both can extend to the partner community. “When you think about … Box as a cloud-based security system and the information I have stored there—such as marketing, personally identifiable information, and payroll—Internet security should be inherent in any application, any collaborative, any kind of framework, and it should be designed in at the beginning,” he reflects. “Security officials should be brought in from day one. You need to build digital platforms with security inherently designed into the platform. I know what they could do if brought in on day one versus day one hundred. It’s much easier and much more cost effective if I have them available at day one rather than having them doing a vulnerability assessment later, when you may not be able to fix all of the vulnerability issues.”
The new technologies presented a learning curve at times, DeSpirito admits. “When adopting Box, it took me time to get used to and [adjust to] allowing a partner to access it,” he says. “You fear change; you like things the way they are. It’s not so much the complexity of digital transformation that’s challenging; it’s the cultural changes required and the pace at which you need to change,” he adds. “I work in the West Kingston, Rhode Island branch, and there is a culture in this building that’s part of a bigger culture of Schneider North America, which is part of Schneider Global. Those cultures win on a daily basis, no matter the strategy. You can’t discount cultural headwinds, uplift, or tail winds if people resist change,” which means digital transformation needs to be pursued wisely, he says.
Changing people’s behavior is really hard, Blau concurs. “People tend to stick with whatever the status quo is, which ends up looking like people ignoring or bypassing the … policies that an organization has put in place. One way that organizations can help make the transition a bit easier is to time the transition better,” he says, citing research on fresh start effects at the University of Pennsylvania by Katherine Milkman. “The idea is that people are more likely to follow through with goals and take action on ‘fresh start’ days, like the first of the year, or the beginning of the week, following a holiday, and even on birthdays. But what this implies is that organizations might be better off timing the rollout of their new policies on these ‘fresh start’ days, and getting their teams ready well in advance.”
Another important and underleveraged time is when a company is transitioning to new systems or people are being on-boarded. “There’s a huge opportunity to instill a security mindset as part of the new identity that they are forming, … but rarely do security teams take advantage of these moments,” he notes.
He then discusses what he calls last-mile problems, those additional issues even if you follow all of his recommendations: “As a behavioral scientist, what I generally try to understand is how the context in which people are acting can shape their behavior. While education can play a part in that, we often do things we know we shouldn’t do, so education isn’t really a foolproof investment,” he advises.
He provides the example of software updates, what security experts always say is one of the most important things people can do to keep themselves and their company safe. Yet security experts will acknowledge that updating is an inconsistent behavior: “We can understand why if we look at how updates are generally delivered. I bet most people have experienced getting an update prompt in the middle of a work day—a time when doing the update is inconvenient. The update prompt generally gives you two options, ‘update now’ or ‘update later.’ This simple design decision is likely what leads to people clicking the ‘update later’ button for days, weeks, or even months on end, when they should really just update the thing,” he explains. “Make a small change, and ask people to decide when they would like to update. A simple commitment intervention could help alleviate this procrastination process. But the bigger point is that if you have these last-mile problems, you often have to dig into the details to see what features of the workplace or interface environment are driving the behavior you ultimately want to change, and make small tweaks to more effectively guide better behaviors.”
Cynthia B. Hanson is a contributing editor to the “2017 Verizon Payment Security Report” and the Jones & Bartlett Learning Information Systems Security & Assurance Series books Legal Issues in Information Security and Fundamentals of Communication and Networking, first and second editions.
Let’s Collaborate.
Have a communications project that needs vision?
Let’s talk about how we can bring your story to life.