Mediaphyter - A Communications Cocktail


License plate. Tattoo. Cat? How far does YOUR company loyalty go?

A few weeks ago I was sitting in my VP of products’ office when he pulled up a news clip from a Canadian TV station. The video showed a baffled news reporter trying to determine the story behind a many-mirrored Vespa parked out on the street. Meanwhile I sat baffled trying to figure out why Anthony was showing me this video. “There is a point to this, I promise,” he said.

Soon I saw it. The news camera zoomed on the license plate of the Vespa:

The reporter speculated that the personalization was short for “for tailgate” (a worthy guess, I might add) but we, of course, knew immediately that the “4TGATE” was short for FortiGate, the flagship product and new generation network security gateway developed by our company, Fortinet. Drew Shearman, soon revealed to be the Vespa’s owner, came out and explained to the news crew the inspiration behind the many mirrors and the story behind the personalized plate.

The first thing I did was drop an email to Shearman — who works out of our Vancouver office — and introduced myself and told him I was dying to know his story. Certainly he had to have been with the company since its inception, hence his incredible loyalty. Nope. He’ll be with the company just one year next month. More than that, Shearman works on Fortinet’s front line as a customer support engineer. He spends his days supporting customers, partners and even our sales engineers who call in with technical questions. In other words, he works hard.

I finally asked him: “Why?”

“The FortiGate is a great product and it is inspiring working for Ken Xie and watching how far he’s taken this company in a very short amount of time. My management is great and we have a great team dynamic in support,” Shearman said. “I get a lot of questions about what my license plate means. I just tell them it represents a great line of network security appliances and the amazing company that I work for.”

(Quick disclosure: Yes, I work for Fortinet marketing. No, this is not a fabricated quote.)

I continued to be baffled yet now I was also impressed. I swear I am not as cynical as I appear and I’m as loyal to my company as the next person. I’ll put in insane hours if need be and I take my tasks to heart. But it’s never even crossed my mind to do such a thing. In my exploration for answers I threw out a question to my Twitter followers. I wanted to know how far their loyalty to their companies goes.

The answers were varied and I initially found not one person who shared Shearman’s enthusiasm. The majority of the respondents reported back that they would only do something so permanent if they launched and had at least part ownership in a company. I compiled a sample of my favorite answers below:

Finally, I found a couple folks who share Shearman’s enthusiasm for their companies or their professions. My friend Mike Dahn, PCI guru and co-founder of The Aegenis Group, sent me this picture of his license plate:

And then Dave Aitel, founder and CTO of security company Immunity, sent me a picture of Kostya Kortchinsky’s tattoo — ink that several of his team’s members share in common as homage to the company:

I never did find anyone to admit to naming a pet after his or her employer. I’m sure that person exists somewhere; he or she is simply not in my Twitter network. Until I find ‘em, I will continue to be impressed with Dahn, the Immunity team and Shearman. It takes a special type of person to commit oneself so publicly to a company or a brand. Clearly these companies are doing something right to instill such loyalty in their employees.

It is complete coincidence that the folks who step forward with tales of loyalty work in the security industry. Have a tale to tell? A picture to show? A cat to admit to naming after your company? Leave a comment and I will include them in a potential follow-up case study on how these types of companies are bringing about such employee loyalty.

(Photo Credits: Vespa courtesy of Drew Shearman; PCI DSS license plate courtesy of Mike Dahn; Kostya Kortchinsky courtesy of Dave Aitel. All photos used with permission.)



Security Twits are packin’ up, movin’ out
Jul 14 08, 8:45 pm
Filed under: Security, Social Media | Tags: , , ,

Well, not entirely. More like moving over. Zach Lanier (aka @quine on Twitter) has kindly offered to house the displaced Security Twits list and do a much better job of managing the updates than I’ve been able to do as of late. It’s been a wonderful experience that has allowed me to meet a fabulous amount of friends with whom I plan to stay in touch (and, let’s face it, “tweet” at like mad).

There’s been a lot of discussion about how this list should be managed now that it’s grown to such a mass. Some have suggested a wiki but that’s how this whole thing started — as a security group on Twitter Packs. It got way out of control and there were all kinds of non-security folks, and a lot of security PR people, adding themselves to the list. (Note: I work in marketing and have never put myself on the list). A discerning eye is critical in determining who should be on the list. Zach will do a great job on this, plus he’s a technologist like many of you. It makes sense that a community for security technologists and thought leaders be run by one of its own.

I’m still totally engaged with the security community and will help support Zach on the back-end, but he’ll be the guy to talk to moving forward regarding updates to your contact details, new additions to the list, etc. If you have general questions about Twitter or microblogging or social networking you can still, absolutely, come to me. If you have questions about security, well, you’re better off following some official Security Twits. ;-)



Security Twits - Represent on FriendFeed

There’s been a lot of hubbub the last few days about Twitter and Twit-Outs and Twitter Love Day and FriendFeed vs. Twitter (in the social media heavy weight match-up of the year! - sorry, had to say it). In the end we’ve all come to a warm and fuzzy place of peace, love and networking. So much so that I’ve learned to let my Twitter and FriendFeed habits, er experience, happily co-exist in my world.

Today, FriendFeed introduced “rooms.” Basically chat groups based on area of interest. Me being the social media geek, er fan, that I am I immediately noticed it as I refreshed the page. My next step was to create the Security Twits Room.

This room is less inclusive than the Security Twits list (which will soon be massively overhauled and moved to its own dedicated place) and is intended to be an interactive environment for security professionals and the people who love… security.

Join us.



Cutting Through the RSA Hype

I am pretty excited to have made guest appearance on the re-convening of The Security Roundtable. Posted yesterday, we recorded this conversation right after this year’s RSA Conference. I was joined by the hosts Michael Santarcangelo and Martin McKeay, as well as Dr. Anton Chuvakin and James Costello.

We had a great, open and honest discussion about this year’s event literally “beyond the hype.” There was no vendor promotion and no gratuitous back-patting. We talked about issues from stemming from impressions of RSA overall, relevancy of the show content, bloggers vs. journalists ethics at conferences and in general, live blogging and other conference coverage antics, the Security Bloggers Meet-Up and so on. We had a lot of fun and I appreciated the interaction. I think you will, too.

Give it a listen: The Security Roundtable



Security Bloggers Meet-Up: No Helmet Required

When I was four, my mom bought me a little red tricycle. I distinctly remember the bounce of joy I did about my grandparents’ living room when I opened it. I can also vividly look back at the painstaking process it was for my grandfather to assemble the darn thing. Socket A and wrench B and tassel C and blah blah blah. I just wanted to ride, to feel the wind in my hair at a whopping .010 miles per hour, and see the, um, driveway. I was even OK with the ugly flowered helmet I would be forced to wear.

This was my first true lesson in the concept of fruits of labor. I’ve had thousands of lessons or experiences since, however the most recent came in the form of the Security Bloggers Meet-Up at RSA Conference last week. While it was an event borne of a blogger brainstorm a few years ago, this year it became my baby – though I was certainly not alone in parenting it. We grew the event from around 50 attendees in 2007 to 100+ this year and we even added live video streaming (most of which was recorded). But in the end it still held true to its mainstay as an event designed by the bloggers for the bloggers to provide them a (fairly) marketing-free zone in which to discuss whatever was on their minds.

And speaking of the bloggers, here’s a list of most of the bloggers in attendance:

Thanks again to the security blogger community and the wonderful committee of sponsors and supporters (Alan Shimel, Martin McKeay, Rich Mogull, Richard Stiennon, Jeff Jones, Dave Berkowitz and Sonya Caprio) for not only joining in what turned out to be an amazing event, but trusting me enough to steer it in the right direction. It wasn’t quite the same feeling as the glee of zooming about on my little red trike, but it was still one heck of a fun ride. And this time, I didn’t even need a helmet.

(Soon to be cross-posted to the official event blog)



In Three Days

Security Bloggers MeetUp

Wednesday, April 9

6-8 p.m.

Virtual Event Details To Be Announced at Network Security Podcast

“See” you there!



Security Bloggers Meet-Up: Who’s coming with me?

One week from today the security blogger population will come together at a San Francisco hot spot for drinks, conversation and – who are we kidding? – maybe a little chaos. The Security Bloggers Meet-Up at RSA Conference promises to be quite the party with an estimated 140+ attendees from across the globe planning to join.

I’ve had a countless amount people ask me for the email contact list for the bloggers attending. Since I’ve been entrusted with this master list I’ve guarded it with my life. Alright, not quite my life, but I haven’t given it to a soul. But what I haven’t been guarding is the list of blogs that will be represented at the event (it’s even on a blog roll over on the official event blog).  

That said, leave a comment with a link to your blog if you are coming to the event and/or want to be on the blog roll. Or comment at the official blog. Or send us a message on the official Twitter feed. Or direct a carrier pigeon our way. Point being – let us know.

Finally, before we get into the RSA Conference frenzy, I want to thank some great people who helped to pull this all together: Alan Shimel, Martin McKeay, Rich Mogull, Richard Stiennon, Jeff Jones, Dave Berkowitz and my partner in crime, Sonya Caprio. If you’re coming, please be sure to buy them a (free) drink to say thanks! ;-)

Can’t wait to see everyone next week!

(Soon to be cross-posted to the official event blog)



Role Reversal and Cindy Brady… sorta.

So, I realized I’ve been bugging all of the bloggers to talk about the Security Bloggers Meet-Up at RSA Conference in a few weeks (gulp!) yet I’ve neglected to do it myself. I wish I could say that what prompted this blog post was my sense of responsibility and urgency, but the fact of the matter is that Rich Mogull and Martin McKeay lit a fire under me when they invited me to talk to them tonight on Network Security Podcast Episode #98.

I’m excited to have had the chance to talk about the private-yet-live-video-streamed event (which at this point has 100+ RSVPs) as well as the success that was SOURCE Boston, and about building a social networking community within the security industry. I’m quite passionate about the latter (well, about all three of these things I suppose) as well as other netsec issues — which will become more apparent as I have more time to devote to this blog.

The podcast experience was a bizarre one for me. As I continue to transition into a new role at my company and really search out my niche in this space, I’m finding myself facing a lot of role reversal. I initially went into public relations because I liked telling other people’s stories. As I’ve matured and become more educated in media and in technology and have moved out of a public relations role, I’ve become a person who wants to tell her own stories and express her own opinions and drive her own influence. Perhaps that’s part of why I am so excited about this social media movement within the security industry. But it’s still terrifying to go from a role in which I was behind the camera, so to speak, and slowly start moving in front of it (I kept imagining myself as Cindy Brady in the episode where she freezes when the “on air” light goes on). Yes, terrifying — yet invigorating.

I suppose the best thing to do is embrace it and keep on moving.  And perhaps stop watching “Brady Bunch” re-runs.

You can all razz me about this in a few weeks at the meet-up.



The Slow Death of Antivirus

Financially motivated malware is forcing anti-malware vendors to dramatically change their strategies – from remodeling their antivirus labs to the way they market their solutions. At least that is the take of Andrew Jaquith, Yankee Group analyst, who discussed this critical need for change during his SOURCE Boston talk: “Not Dead But Twitching – Antivirus Succumbs to the Scourge of Modern Malware.”

In an industry where security vendors self-congratulate and loudly beat their chests about what they claim to protect against, Jaquith states that current AV protection models are failing as zero day exploits become more sophisticated and malware creators become further incentivized by financial gain.

“Everyone is losing ground,” he said. “Public bravado belies private anguish.”

Jaquith talked about neosploit designer malware (one signature, one victim) and low-and-slow malware feeding denial of service-type attacks against AV labs as just two reasons that these labs need to consider changing their models.

“Most of the antivirus labs prioritize what they go after based on the infections they hear about,” Jaquith said. He went on to say that is only further driving the attackers to send a lot of tiny viruses and change the signature and content enough to slip under the radar.

Despite years of security investments, enterprises are still at a 99 percent penetration rate for antivirus and 63 percent of enterprises suffered a malware outbreak that impaired business. Vendors themselves are citing that they’ve had more malware samples in the last year than in the previous 10 years combined. Throwing more security research engineer bodies at the problem is not going to solve it.

“Today’s antivirus model is losing effectiveness,” Jaquith said. “The enemy is using its infinite ability to scale against the limited capabilities of the AV lab.”

But the biggest problem, he states, is that anti-malware industry itself, calling out the industry’s unwillingness to admit it is losing the battle, to band together, to hush the marketeers and to truly measure the effectiveness of anti-malware efforts.

“Either no one is telling or no one knows – how come no vendors can tell us what percent of anti-malware customers have actually been infected?” he asked.

Herd intelligence (using every endpoint as a collector) with behavior blocking, and taking the old antivirus prevention strategy and leveraging it as a detection strategy are solutions that he suggests.

“Security people think of prevention, detection and response. What AV is good at is protection and how it is marketed. If what you market is silver bullets you are damning yourself to live and die by prevention while the industry is moving to detection and response,” he said.

During his talk, Jaquith cited several vendors who claim to stop “all” malware threats or protect against “any viruses.” There’s a danger in that, he said, as no vendor can guarantee to stop all threats with antivirus solutions, especially with the mounting offenses that malware creators are taking against the AV labs. He pushed for more responsible marketing among all anti-malware vendors.

“Part of this is about the industry growing up. Some of this is tough love but it’s meant to suggest we’ll get beyond the silver bullet.”

(Cross-posted at the SOURCE Boston blog)



SOURCE Boston — Escape from the Con Monotony
Mar 11 08, 2:47 pm
Filed under: Security | Tags: , , ,

I’m sitting in the prep suite of SOURCE Boston with Stacy Thayer, Christian Rioux, Raffy Marty, Ryan Naraine, Adam O’Donnell, Rob Cheyne and Michael Maziarz. The energy among this cast of characters is intense yet positive. There’s a lot of excitement over the event, and while we might be a little biased (with the exception of Ryan, of course), it seems others have high expectations as well.

Earlier today Dennis Fisher over at Tech Target posed the question, “Can SOURCE Boston save us from boring security conferences?”

“But there’s a little bit of light at the end of the tunnel from a new conference called Source Boston that’s set for this week. The speaker lineup looks really solid and the topics are not your average big picture drivel. They’re getting down into the weeds to find some things that haven’t been covered a thousand times before.”

So come out to the con. It’s not to late to sign up, even for a day. There are cool evening networking events, too. If you can’t come check back here for coverage of the activities. Or follow us on Twitter @SOURCEBoston. At the very least, we can promise you won’t be bored.

(Cross-posted to the SOURCE Boston blog)