Brightfly Awarded “Most Connected Customer” at SXBW

Newsflashes

Brightfly Awarded “Most Connected Customer” at SXBW

3 Comments 24 March 2010

On behalf of Brightfly, Brandon Dunlap, our managing director of research, accepted the “Most Connected Customer” award from the Small Business Web at South By Southwest [SXSW] last week. The award seemed to come as quite a surprise to him. “When I was asked if I could attend, the South By Small Business Web party as a Guest of Honor, I had no idea what was in store”, said Dunlap. Maybe that explains the kilt.

In a rare glimpse behind the curtain, Brightfly’s technological underpinnings for much of their outreach and research efforts were showcased. In doing so, Dunlap got to meet many of the founders of the very applications used by Brightfly everyday. “It was quite a pleasure to connect with folks like Michelle Riggen-Ransom from BatchBlue, Taylor Mingos from Shoeboxed, , and Scott McDaniel from SurveyGizmo. Coming from a small business myself, we share many of the same challenges and so they understand exactly what our business needs.”

We deeply appreciate the award and the chance to forge deeper ties with the members of the Small Business Web community. “And thanks for the great laptop bags!” added Dunlap, who after 100,000 air miles last near, destroyed two bags himself.

Creating the Security Business

Uncategorized

Creating the Security Business

No Comments 23 March 2010

When you are first starting out in redefining how you are operating your security program in a customer-centric context, you need to think about a few key concepts familiar to any new business.

What business you are actually in?

Do you want to be perceived, and perhaps more importantly, do you want to operate, as the carrot or the stick? In other words, do you want to play the role of the enforcer or the motivator/enabler? All too often our profession seems to lean towards that of the enforcer. Or, in many cases, more like a first responder. We have historically been very reactive in our approach to managing security. As a matter of fact, we have built entire product  areas on managing event streams for purely reactionary purposes (like the IDS and SIEM markets).

While these are worthwhile monitoring concepts and shouldn’t be ignored, there is a vast ocean of untapped opportunity around a more consultative and proactive approach.

Who are your customers?

Just like a start-up, you need to identify who in your organization (and in some cases, those beyond your organization) are your customers. Don’t forget to include those parties that you only see occasionally, such as external auditors, and possibly even suppliers or other business partners. Your information can be a valuable part of their engagement with your organization as well.

This is a critical component to deciding the next step, which is what services and products (i.e.; packaged information for decision support you are offering and how best to ensure that it is useful to the recipients.

Choosing your product and service mix.

Now that you have decided who would be consuming your value-added information, it’s time to identify what makes up your product and service portfolio. The best place to start is to look at the controls spreadsheet that your internal and external auditors use to track the control objectives and activities they are responsible for testing.

While it isn’t a comprehensive set of controls for your security program, it is the minimum set of functions that you should look at for building out your business model. It also comes “pre-loaded’ with a target market and allows you to start building a rapport with the consumers of the information you are providing so that you can make sure that you package it correctly and deliver it in a manner that makes it easier for them to use.

Here is the slide deck that accompanies this portion of the Competitive Compliance curriculum we have developed. Feel free to spread the link around, or even download the PDF of the deck if you find it useful. As always, your feedback is greatly appreciated. Not just on how this site can be improved, but also what other content or ideas you’d like to see in the curriculum or content on this site.

Virtualization Compliance Roundtable

Newsflashes

Virtualization Compliance Roundtable

No Comments 22 March 2010

Please join Brightfly’s Managing Director of Research, Brandon Dunlap, as he moderates “The Curious Case of Compliance in a Virtualized Environment”, a one hour online roundtable brought to you by as part of (ISC)2‘s ThinkT@nk series. This highly interactive and vendor neutral event is being held March 25th, 2010 at 12:00pm EDT.

The panelists include the following security luminaries:

You’ll find this session will deliver practical advice well worth the time invested in attending, not to mention the Group A CPE credit!

To register your attendance to this enlightening and informative event, just click the button below.

Register Here
The Curious Case of Compliance in a Virtualized Environment
(ISC)2 Secure Chicago 2010

Newsflashes

(ISC)2 Secure Chicago 2010

1 Comment 11 March 2010

Please join Brightfly’s Managing Director of Research, Brandon Dunlap, on May 11th in Chicago, IL for “Fact Not FUD-Managing What You Can Measure” as part of (ISC)2‘s Security Leadership Series. In this highly interactive (and some would say, controversial) session , you’ll learn about a new “business model” for security operations and the metrics you should be tracking to manage your programs effectively.

The event will be held at the Donald E Stephens Convention Center:

5555 North River Road
Rosemont, IL
60018

Brightfly would like to thank the generous supporters of (ICS)2‘s Security Leadership Series. Thanks to them, this event is free to (ISC)2 members and only $99 for non-members.

Just click the button below to register for the event. Hurry, they fill up quickly!

Register Here

© 2010 Brightfly, Inc.

Powered by You, the Community.