Getting Better Is The Goal

Keep Calm and Carry On PosterSometimes when we talk to potential clients we run into a strange dynamic: other people ask us why we would work with an already good cybersecurity program.

It seems that people expect cybersecurity consultants to work with demonstrably ineffective cybersecurity programs, apparently assuming that we only show up right after some kind of serious incident.

While this scenario has a shorter and easier sales cycle it is not our preferred way to work. Ineffective programs are generally ineffective through some combination of weak leadership, lack of talent and lack of rigor in the program. None of these issues is easy to fix, especially by outside consultants. That is why for conventional cybersecurity firms this scenario often leads to easy sales of training programs and other canned solutions but does not often lead to a great cybersecurity program.

The truth is that good programs are usually focused on self-improvement. Steady and prolonged improvement is rarely accidental. Working with already strong programs means providing those improvement-focused people with unique data to guide improvement in novel areas: talent and team dynamics.

This is why an already strong program would hire us: to get better in new areas. Our assessments give insight into the talent you have hired, not just their past performance or current skills. Our stakeholder interviews give insight into attitudes and clarity of messaging. Our 360 studies give insight into how leaders are perceived and how those leaders perceive their direct reports.

Do we work with cybersecurity teams who are in the throes of recovering or responding? Of course we do. Our tools and services provide a great basis on which to do the kind of soul-searching that these phases require. But we also work with teams who are doing well because the goal is always to be better tomorrow than you were yesterday. And you don't reach that goal because someone sold you a checklist of canned solutions. We sell you data about your people and guidance about turning that data into insight. You still have to do the work of self-improvement.

Wherever you stand today, cybersecurity is not a sprint; it is not even a marathon. It is a daily commitment. Mere compliance with current procedures is not enough. Good programs know that standing still is falling behind. Good programs need all the data they can get in order to get better. We can provide new data in new areas. Continual improvement is hard. We can help. Ask us how.

Comments