Sunday, September 23, 2012

OC CIO Minutes September 13, 2012

1993-2012


Southern California/Orange County CIO Breakfast Round Table

September 13, 2012 meeting



Present: Mikael Elley, Sean Brown, Jim Sutter, Joel Manfredo, Jon Grunzweig, Jeff Hecht, Jennifer Curlee, Dave Phillips



The following is a list of topics and speakers through October:



10/11/12 CIO Compensation Ken Wechsler, Radford

11/8/12

12/13/12 Joel Manfredo

1/10/13 Controlling Project Costs Jon Grunzweig



Topic: IT Challenges of a startup organization



Sean Brown introduced our guest speaker, Mikael Elley, CIO of Fisker Automotive, makers of luxury high performance cars. Founded in 2007, Fisker’s mission is to create environmentally conscious vehicles with style, power and performance. The first is Karma Electric Vehicle, launched in 37 months. To get operational with Karma, they had to go from Start-up to Enterprise ‘overnight’. The strategic objective was to facilitate a lean organization, focus on cost and resource effectiveness, enable streamlined business objectives for better utilization of resources, applications and infrastructure. To do this they had to define objectives, set focus, set strategy, define roadmap, execute and measure. Mikael’s slides go into more detail as to how they did this, and I recommend you take the time to read them. He talked about some guiding principles for organization development. He ended up with a private cloud, which surprised some of our members, because public clouds are generally favored by start-ups. He explained that their basic philosophy was to grab all data for future sharing, and security of that data was paramount. He described the definition of business processes, led initially by IT but with buy-in and discipline through partnership with the business. They implemented SAP ERP in 16 weeks – again look at his slides – and have a road map through 2015.



We had a lively discussion and shared lessons learned. Perhaps the highlight came after the discussion when we all went down to the parking lot and had an opportunity to see, feel, and get in and out of a beautiful car.

Thursday, August 30, 2012

OC CIO Minutes August 9, 2012

1993-2012
Southern California/Orange County CIO Breakfast Round Table
August 9, 2012 meeting

Present: Joe Stein, Sean Brown, David Mann, Jon Grunzweig, Alison Wantanabe, Joel Manfredo, Keith Golden, William Zauner, Jim Sutter

The following is a list of topics and speakers through October:

9/13/12 IT Challenges of a startup organization Mikael Elley, Fisker Automotive
10/11/12 CIO Compensation Ken Wechsler, Radford

Topic: Innovation

Our subject for the breakfast roundtable was Innovation. Our speaker was Joe Stein, President, Simply Innovate, who has had leadership roles in IT and corporate transformations and innovation.

Joe began by demonstrating the paradox in the U.S. While 84% of companies agree that innovation is critical to the bottom line, only 15% are satisfied that the pace is adequate. At current trends, China will surpass the U.S. in patent filings. And, only 21% of companies have a designated head of innovation.

In IT, innovation is always occurring, both in delivering new solutions, as well as coping/enabling technological upgrades in the infrastructure. Joel mentioned that 70% of IT personnel rate themselves as late or last in adopting the latest technical offerings.

David explained that this was a result of CIOS wanting to avoid risk...that many technologies are oversold and are immature at their introduction. Jon echoed that it was another paradox...the need for reliable delivery requiring stability, balanced with need to insert disruptive technological change.

Joe outlined a process for innovation consisting of the following elements:
Identify (analyze, research)
Ideate (borrow, gather, brainstorm)
Filter (prioritize, rank)
Implement (project charter, project plan, implementation plan, test, rollout)

Joe listed the five pillars of innovation: culture, structure, idea nurturing, roadmap and "killing starving monkeys".

There was discussion of the difficulty in "killing starving monkeys" and most of the members of the round table recounted good and bad experiences in opposing certain projects or shutting down unsupported initiatives. Joel urged the group to rely heavily on the finance group and force them to step up to their role in demanding project justification. He also highlighted the need, as part of "branding" the IT leadership, to publicize success.

Joe cited Spigot's ICON....a free crowd sourcing software tool, useful in acquiring ideas. He emphasized that good project leaders were good people leaders as opposed to just being skilled with project tools.

Joe provided a comprehensive handout highlighting the points covered in the presentation. It can be found at: http://www.slideshare.net/occio

Tuesday, July 24, 2012

OC CIO Minutes July 12, 2012

Present: David Mann, Sean Brown, Jeff Hecht, Jennifer Curlee, Allison Watanabe, Joel Manfredo, Jon Grunzweig, Keith Golden, John Hahn, Colleen O’Higgins, Dave Phillips

We welcomed Colleen O’Higgins, UCI Donald Bren School of Information and Computer Sciences, to describe the goals, objectives and opportunities of its Corporate Committee. Her handout described the charter of the committee, its objectives, several of the engagement opportunities and plans for this next year. For more information, please contact Colleen at cohiggin@uci.edu, or Jon Hahn at jhahn@semtech.com.

The following is a list of topics and speakers through September:

7/12/12 Mobile Device Security David Mann
8/9/12 Innovation Joe Stein
9/13/12 CIO Compensation Ken Wechsler, Radford

Topic: Mobile Device Security

David Mann started by saying that there ia a diversity of mobile devices (Android, iOS, Symbian, Blackberry, Windows Phone, ….) which enable employees to work from “anywhere, anytime”. Security is a major problem because these devices can easily be lost or stolen, and many of the devices are employee-owned accessing corporate data. IT management is fighting an uphill battle because of the proliferation of devices, and the need to integrate mobile device management, device security and data protection. Device management includes keeping track of assets, ownership, and configuration (software and hardware). Device security includes keeping devices safe, password protection, virus & malware, remote wipe of lost devices, backup and restore. Data protection includes deciding what data is allowed on each device, and protecting the data at rest, in transition, or in use. David’s presentation was excellent, including his attachments, which I recommend you read:
”Securing end-user mobile devices in the enterprise – developing an enforceable mobile security policy and practices for safer corporate data” - IBM White Paper
“Tech Insights: Mobile Diversity - 7 Steps to Mobile Security” – J. Gold Associates
“ENISA – Smartphone Secure Development Guidelines”
His slides are at: http://www.slideshare.net/occio .

The Round Table discussion was cut short because we wanted to hear what Jon Hahn and Colleen O’Higgins had to say about the Corporate Committee.

Friday, June 29, 2012

OC CIO Minutes June14, 2012




Present:        Joel Manfredo, David Mann, Joe Desuta, Jeff Reid, Keith Golden, Sean Brown, Jim Sutter, Dave Phillips

We started the meeting by sharing fond memories of Paul Gray, Professor Emeritus at Claremont, a long time member of the group, who died recently.  Many of us had known Paul for many years, and we will miss his presence, his presentations and contribution to our discussions.

We welcomed a new member, Allison Watanabe, to her first meeting.

The following is a list of topics and speakers through September:

6/14/12         IT Service Catalog                       Joel Manfredo
7/12/12         Mobile Device Security                 David Mann, Neudesic
8/9/12           Mobile Application Development  
9/13/12         CIO Compensation                       Ken Wechsler, Radford

Topic:          IT Service Catalog

Joel Manfredo’s presentation was based on his experiences at the County of Orange data center, which provides IT services to 7 programs and 32 agencies and/or departments (see slide 3).  The services they provide are fairly standard - data center services, Help desk, network support, voice, security, application and data services, project management, and finance and contracts administration – but they transformed the way they provide these services to running a service delivery business.  This has taken lots of time (starting in April 2009) and effort, but the results are very good. Slide 8 describes the 5 phases and the method – plan, implement, absorb, measure – and the following slides the improvements within each phase. There is a wealth of information in these slides and I recommend that you take the time to work through them.  By Oct 2010 they had produced a mini service catalog, as a marketing brochure.  Version 1 of the Service Catalog was introduced in Oct 2011, and version 2 in Feb 2012.  Joel had copies available for us to see and we were impressed with their quality and professionalism.  Slide 48 lists a set of interesting conclusions and lessons learned.

We asked those present to tell us whether they provide all their IT services in-house, or use outsourced suppliers, and how do they measure the services provided.

Joe uses both, and has the best and worst of both approaches.  He agrees that you have to build your way up to Joel ‘s approach, and it takes time to get to a formal catalog of services.
Jeff uses all in house IT services, but they do not collect all the data necessary to produce all the reports.  It has taken him time to produce standard reports.  They do allocate costs, and they do try to be transparent.

Keith complimented Joel on his presentation.  He also does everything in house.  It is a continuous battle.  They do not allocate costs.

David said that in his prior company, they did not have a service catalog but they did go for total transparency.  He was very impressed with the professionalism of they Service Catalogs that Joel produced.

Allison said that in her prior company, they had to sell their services to the users.  They initially out-sourced all IT services but ended up bringing it all in house.
Joel's slides are at:   http://www.slideshare.net/occio/  .

Monday, May 28, 2012

OC CIO Minutes May 10, 2012


1993-2012
Southern California/Orange County CIO Breakfast Round Table

Present:        Rich Hoffman, David Mann, Sean Brown, William Zauner, Subbu Murthy, Jeff Reid, Keith Golden, Dave Phillips, Esther Delurgio, Jim Sutter

Thank you, Rich Hoffman, for an excellent presentation, and to Jim Sutter for taking over as meeting facilitator and meeting notes generator.

The following is a list of topics and speakers through September:

6/14/12         IT Service Catalog                       Joel Manfredo
7/12/12         Mobile Device Security                 David Mann, Neudesic
8/9/12           Mobile Application Development  
9/13/12         CIO Compensation                       Ken Wechsler, Radford

Topic:          Global IT Challenges

Rich Hoffman, Sr. VP and CIO of Avery Dennison, led a discussion of the challenges CIOs face in providing efficient and responsive IT products and services for an organization whose operations are spread all over the world.  He began by providing the context for his experience.  Avery Dennison, a $7B multi-line manufacturer which has grown through 145 acquisitions, and operates out of over 500 locations in 60 countries has 30,000 employees (19K IT users) and has to deal in 14 languages and support sales in 90 countries.  It’s products are organized into 4 major groups.  The paper label business is a cash cow, but revenues are declining, while the other groups are growing and have established unique, proprietary solutions.  The products and applications include:  materials for brand labeling and packaging; apparel and footwear labeling design; high definition graphic embellishments; price enabled management materials and systems; and specialized adhesives, coatings, films, and RFID technologies.  Rich showed a selected number of examples. The company has faced challenges in global pricing, brand consistency, and inventory and cost management.  Its strategy of growth by acquisition and highly virtual operations, has resulted in significant diversity in both business process and IT solutions. Rich’s organization has taken on these issues by establishing a major social network as part of an overall emphasis on improved communications; restructuring into a centralized IT group of about 1200, and attacking unnecessary variation in business process.  They use high definition video to help overcome the geographic dispersion, time zone issues, and the complexities associated with managing virtual teams.  They’ve collapsed call centers from 110 to 3, and many data centers to 2.  Rich stressed the increasing attractiveness of having data centers in the USA.  He believes that every major project needs dedicated, full-time communications professionals to avoid the “we don’t ever hear what’s going on” issue across the different locations.

As always, the roundtable members were very active in serving up questions about approaches to overcoming culture differences, standardizing, and selecting tools.  Rich’s candor and grasp of the complexity was very much appreciated by the attendees.

Monday, April 16, 2012

OC CIO Minutes April 12, 2012

1993-2012
Southern California/Orange County CIO Breakfast Round Table
April 12, 2012 meeting

Present: Jon Grunzweig, Jeff Reid, Keith Golden, Joe Desuta, Jeff Hecht

Thank you, Jon Grunzweig, for stepping in to make this presentation on short notice, and to Jeff Hecht for taking over as meeting facilitator, and meeting notes generator.
The following is a list of topics and speakers through September:

5/10/12 Global Company IT Challenges Rich Hoffman, Avery Dennison
6/14/12 Big Data Paul Gray, Claremont (Emeritus)
7/12/12 Mobile Device Security David Mann, Neudesic
8/9/12 Mobile Application Development
9/13/12 Ken Wechsler CIO Compensation

Topic: Building IT Teams

Jon Grunzweig started his presentation with some discussion about why teams don’t perform well. These include fear of conflict, lack of commitment, avoidance of accountability, inattention to results and absence of trust. Jon then moved on to how to build good teams. Throughout the remainder of the session there was a lot of interaction and discussion on what had worked and not worked for Roundtable members and the discussion went beyond building IT Teams into areas about how IT can be more effective in general. You can look at the presentation outline document for some of the specifics of the best practice things identified for building teams. Jon also provided some specific insights on his own ideas. Jon believes you need both a formal and informal approach and there is no one right way. Some of his key elements included having a plan, setting the example, being consistent, adapting and adjusting, setting the bar high and trying to get IT folks to shift from technicians to thinkers. Jon introduced an idea of using Themes where he discusses an idea with people for a while and trying to keep in front of people. He tries to repeat the message multiple times to drive it home. He provided us with several pages of Themes he’s used in the past and the group found many of them very useful. Jon believes keeping a little mystery or a certain incompleteness of information to the team can help be a motivator. There was a bit of discussion in the group about this and some discourse on the value of transparency versus withholding certain pieces of information strategically. An underlying idea in several parts of Jon’s presentation including ideas about marketing or branding IT and its activities both internal to the IT organization and to the business stakeholders. This was a very well done and thought provoking presentation/discussion. The handout materials are especially worthy of review (check out the Themes for sure). Nice job Jon.

Keith Golden suggested when you are staffing for teams there are times when you have to make a choice between a highly technical/specialized individual and one who gets along better with teams. This can be a hard choice since both are desirable. Keith believes there is value in creating some tension within teams and occasionally being unpredictable. This was echoed in Jon’s presentation about keeping some mystery. Keith has not had the flexibility he’d like to create all the incentive programs he wanted, e.g. making more of the IT folk’s compensation bonus based. He also mentioned using IT Town Hall meetings to be sure all the IT folks know what they are doing as a department. Keith believes quarterly planning is about the right time frame, creates real planning but is still short term enough to be flexible. He also likes the idea of holding back of information sometimes (the mystery idea again), especially in the budgeting area.

Joe Desuta puts a premium on aptitude and attitude in selecting team members. He prefers a highly motivated individual to a highly skilled one with a less excellent attitude. Joe talked about setting the bar high as a way to challenge the employees. During a discussion side bar IT Steering committees Joe expressed some frustration regarding his experiences with them. He is not in agreement on the air of mystery idea, instead thinking transparency and consistency in delivering the hard message has more value.

Jeff Reid has been experiencing some quick changes in priorities and direction based the specifics of his current organization. Part of that may be the economic times, part the size of the organization but it’s created a flux that can be hard to manage. It also takes a toll on teams whose goals change in mid-project. Jeff sees some of the value in the mystery idea but doesn’t like to see it when the information is associated with employment. In past positions he used to make sure the department did some fun activities but budget pressures have curtailed that. The presentation reminding him that getting back to that is important even with a very limited budget. Jeff has used the IT Town Hall meetings in the past as well and shared the idea of bringing in the head of a different department to those meetings. Jeff Hecht talked about how the marketing IT idea flowed through the presentation and agreed that it was something we should all be doing all the time. He was impressed with a lot of Jon’s ideas and especially liked the themes approach and many of the specific theme ideas in Jon’s document. He gets the idea of keeping some mystery in the process, not to be completely predictable, but also sees being as transparent as possible as a motivating force with the “we’re all in it together approach”. Jeff talked about the idea that you get the behavior you reward, so if want consistent performance you have to find a way to reward that consistency not just an extreme firefighting exercise.Good session –thanks to Jon for the presentation and all for the spirited participation. The presentation is at:
http://www.slideshare.net/occio/ .

Monday, March 12, 2012

OC CIO Minutes March 8, 2012

Southern California/Orange County CIO Breakfast Round Table
March 8, 2012 meeting

Present: Jeff Hecht, David Mann, Jim Sutter, Keith Golden, Jennifer Curlee, KJ Grinde, Sean Brown, Dave Phillips

We welcomed KJ Grinde, Edwards Lifesciences, to his first meeting.

The following is a list of topics and speakers through September:

4/12/12 Mobile Device Security David Mann, Neudesic
5/10/12 Global Company IT Challenges Rich Hoffman, Avery Dennison
6/14/12 Big Data Paul Gray, Claremont (Emeritus)
7/12/12 Developing IT Teams Jon Grunzweig, Majestic Realty
8/9/12 Mobile Application Development
9/13/12 Ken Wechsler CIO Compensation

Topic: New Security Challenges

Jeff Hecht started his presentation by noting how the security landscape had changed – it used to be hacking for fun, but now it’s much more serious. Millions of $ are at play, either through quick strikes or extended attacks. It’s getting to be hard to know who to trust. Still, most organizations rely primarily on signature based perimeter defenses.
Hacktivism is usually politically motivated, with humorous overtones, and has the capacity to be a solo activity. Recent attacks have targeted security companies like HBGary Federal (because of their investigations into a group called Anonymous) by that very group, much to their embarrassment. Another was on Sony by a teenager, George Hotz - Sony sued Hotz and Anonymous got involved in many more attacks. The cost to Sony is in the multiple 100M dollars range. Symantec is another example. Anonymous is a loosely run organization and one of the main actors, Hector Monsegur (Sabu), was arrested in June 2011, and he has revealed other members of the group. Another problem is Certificate Authority (CA) impersonation. A CA is supposed to provide digital protection by a combination of public and private keys. If trust in the private key is lost, then all guarantees are off. Jeff explained what advanced evasion techniques (AET) can do for you – I recommend that you spend a few minutes looking at his slides on this topic. Yet a more dangerous element is the Advanced Persistent Threat, where the attackers are willing to take the time to select the target (not just by chance), identify the potential gain, develop the attack approach often from within, and hide the evidence – check out Jeff’s slides on this one. He had 5 predictions for 2012 – first Android worm; loss of your personal data from a social network; political theater; SMBs are no longer immune; Mac malware will increase. What can we do to protect ourselves? Do the basics (not enough but still important); use layers; train employees on security; find someway to really identify someone; focus on protecting your crown jewels; watch what is going in and out. Great presentation!

KJ thanked Jeff and complimented him on a really current presentation. Anonymous has vowed to take down the Internet.

Jennifer noted that Anonymous was not a real organization, but a loosely connected group of individuals, whose fingerprints are well known.

Keith is still struggling with network modification and will address security next.

Jim noted that his client is very much into business intelligence, especially pricing by location, using whatever means are available, including hiring each other’s sales people.

David said that his company has a team focused on security, and they are trying to stay ahead of the game. The biggest threat is the human factor.

Good session – thank you, Jeff, for the presentation.

CIO PeerGroup Roundtable Membership

Current CIO PeerGroup Roundtable Membership is at http://peermembers.blogspot.com