Earlier quoted context omitted.
It's almost as if making shareholder returns and CEO pay the only indicator of company success creates terrible consequences.
Long term shareholder returns are directly correlated to the long term company success. It's always such an odd criticism to think of "shareholder returns" as a pejorative.
US companies hit by 'colossal' cyber-attack
421–430 of 514 posts
Re: US companies hit by 'colossal' cyber-attack
#422Earlier quoted context omitted.
One could hope but I doubt it. CFO's gonna CFO and it's "cheaper" to outsource IT. I had one of these vendors really pushing me to "take a call" or "let them show me how they could cut costs". It was ALL about the costs. And I eventually called the CEO and said we would consider it if the company would take out a $100M bond that we could call on to repair any damage that occurred as a result of their managing our IT…
I keep reading over and over again indignant comments about "cost centers" on Hacker News and I think it's not a good term to use because I looked up the definitions and the only logical consensus I could find is that everything which isn't shareholder profit is a cost center. It's just rhetoric.
If you are looking at US curriculum, my experience is that you will see the discussion in terms of dollars and their "flow" through the firm from the customer and perhaps ultimately to a bank account (in the case of having positive cash flow) or how much 'short' the company is when it comes to a negative cash flow situation.
Understanding the cash flow dynamic for a company is critical to the company's success. If a company does not understand how they make money and how they spend money, they will not be able to manage themselves to a sustainable level.
As with engineering, it is a simplification to group "like" costs, and "like" revenues together. So for example all the money made by extended warranties and charging for repairs might be grouped as "service revenue." Similarly, all the money spent on leasing office space might be grouped of "real estate costs."
Every accounting program I have seen (and it isn't exhaustive of course, just consistent in my view), facilitates this grouping of costs into larger and larger groups. Depending on the size of the enterprise, the manager at a particular layer who had "profit and loss" responsibility could see a small number of these groups (which I have only ever heard referred to as either "revenue sources" or "cost centers") and they could get an idea of the health of their part of the business by seeing if their margin target (total_revenue - cost) / (total_revenue) was being met.
And at the managerial level, they typically would split their activities into ones that "improve revenue" or "cut costs." Doing either increases the gross margin which is what they are measured on by their manager, whether it is another person at the company or the board of directors. Because these are fundamentally an accounting thing, increasing money coming in by say raising the price of the product or restructuring pricing plans is called "growing top line revenue" because that usually the top line of a financial report. And when they cut costs or improve efficiencies so that they can make more product for less money, that is called "growing bottom line revenue" because the amount that gets subtracted from the top line is reduced and so the number at the bottom of the page gets bigger.
Finally, nobody is an expert on everything. And the larger the enterprise the wider the expertise needed to understand the costs and expenses of that enterprise. What is worse, is that sometimes the people in that role were experts at one time but the area where they developed their expertise has moved on and so they believe they know what is the right answer and don't bother to check. And sometimes they don't know the right answer but don't want to "look stupid" and they buy all the reasons the sales guy gives them for using their product as pass that along as justification without knowing the risks.
It adds up to a bad choice. And when that choice is to move to open offices (for example) the impact of losing productivity in people who cannot deal with that environment isn't readily apparent. And when it leads to outsourcing something which wouldn't be outsourced, the error might only become apparent when you're suffering a ransomware attack.
Meanwhile, best practices are slow to reach the curriculum and so there is a lag between people doing things poorly and it being taught as a bad thing in business school.
Re: US companies hit by 'colossal' cyber-attack
#423After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…
strategy: find SaaS corps responsible for catastrophic cyber-attacks and buy them on the the dip?
Re: US companies hit by 'colossal' cyber-attack
#424Earlier quoted context omitted.
I specifically have experience with Kaseya. I kicked and screamed to get us off of it, the IT people insisted it was top notch. So when I became CFO I fired them (outside company), not just for this, but it didn’t help. It’s bad software. 24/7 full low level access is exactly what it is. We had an add on that stored admin credentials in a JSON… so looking back on that, it seems this should have happened sooner.
The craziest part to me was their pushing of the vPro integrations.
Re: US companies hit by 'colossal' cyber-attack
#425One of Sweden's biggest grocery stores / supermarkets, Coop [1], is keeping all their 800 physical stores closed today, since their payment system is not working because of an IT-attack somewhere in their supply chain [2]. Connected to this attack? [1] https://www.coop.se/ [2] https://sverigesradio.se/artikel/coop-butiker-haller-stangt-...
A cashless society is scary. Cash should always be an option and the inventory system should be disconnected from the internet.
They likely closed to avoid issues with rejecting customers who didn't get the message. Or perhaps just to be on the safe side because they didn't know who the attack was aimed at.
Re: US companies hit by 'colossal' cyber-attack
#426I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.
Re: US companies hit by 'colossal' cyber-attack
#427Earlier quoted context omitted.
A lot of these companies are actually huge enterprises with dozens if not hundred(s) of cybersecurity consultants and engineers. All of them are CISSPs and GICSPs(I do put my CISSP in the signature when working in those places too though). I go through security reviews all the time with them, they have so many security processes that you get dizzy and on paper everything looks fine. They create security zones with ma…
>These people can tell you so much about the theory of security by heart that it will make you dizzy but then won't actually understand the underlying problems. I've thought greatest failure of many professionals in this field is in the "protect the network" perspective rather than "protect the data". While many of them fess up to "we can make it difficult but not impossible" to breach the network, that is not evince…
That's quite interesting. Where can I read more about that ?
Re: US companies hit by 'colossal' cyber-attack
#428Earlier quoted context omitted.
>Dude, if you look at Equifaxes and Solarwinds EBITDA/earnings statements following their respective breaches, you will clearly see that there has been no major impact to their bottom line. I'm looking at Equifax's 2018 statements right now. With Operating Revenue of $3.4 billion and profits of $850 million, they had $400 million of expenses related to the breach. "No major impact" my ass.
Roughly 10% of revenue is something, but not that big of a deal, especially since their overall revenue is up. Don’t you think stronger consequences than that should happen when a company unintentionally discloses tens of millions of people’s personally identifiable information that has been collected without any particularly explicit permission given by those people? Credit agencies hold a special place in the US ec…
And you would think that given their one job is to supposedly safeguard this info, the consequences would be more severe or we would re-think this entire business model of consumer credit, but our society is not capable of that kind of consumer advocacy. Likely due to some powerful interest's bottomline.
Re: US companies hit by 'colossal' cyber-attack
#429The Microsoft team at a company I used to work for tried to push this very software out onto all staff machines. Our Platform Engineering team managed to push back on it based on the grounds that it was a serious security concern and is essentially an "enterprise" backdoor. The following year the bulk of our team decided to resign move on to other employment - I was told Kaseya was rolled out to all machines shortly…
What software are you referring to? The article only mentions "VSA tool", and that does not ddg well.
They essentially are enterprise level back doors with good intentions.
Think firewall/antivirus/backup software suite run by a remote team.