Private Enterprise and Social Media

In one of The Wall Street Journal‘s frequent debate articles, this time about whether businesses should allow employees to use social media at work, a couple of comments made by the pro-use debater jumped out at me.

When I first began helping companies use Twitter and Facebook more than a decade ago, every organization started with this question: how can we use social media without compromising our security and privacy obligations?

The answer to this question seems straightforward, yet the debater equivocated.  While a business needs access to social media for its advertising and other communications with current and future customers, the plain fact, made all the more plain with recently revealed misbehaviors of Facebook and Twitter, is that businesses cannot use social media without severe risk of compromising their security and privacy obligations.  The business models of social media like Twitter and Facebook depend on exploiting exactly those privacy data, and those enterprises—and not only Twitter and Facebook—have shown themselves incapable of maintaining security regarding those data.

And this one:

The same kind of risk/benefit assessment applies to the use of personal social-media accounts by employees.

While it is true that companies can reduce risk if they ban personal social-media use during business hours, discourage employees from making any online references to their work and maybe even ban personal smartphones from the workplace, that is a terrible idea for the same reason companies now embrace social-media marketing: you can’t be a successful company in the social-media era unless you accept some level of social media-related risk.

This is just flat wrong.  In the first place, there’s no reason at all an employee should be conducting personal business on company time and company equipment.  Normal breaks and lunch hours answer the first part, but it’s still company equipment.

More importantly, the claim of no success without employees on social media is wrong.  I worked for one of the most successful defense contractors in the world in our niche of the industry.  Along with hundreds of fellow employees I worked behind a cipher lock.  No radios (and so no cell phone), no personal tablets or laptops or the like, we were air-gapped from the Internet.  We survived the isolation.  In fact, we thrived in that environment, and so did our company.  Companies that don’t do classified work still do proprietary work.  There’s no more need for those employees to access the Internet than there was for us.  They’ll thrive, too.  Saying a business just must surrender and accept social media-related risk is nothing but a quitter’s attitude.

And: any company is better off operating short-handed than operating with an employee who will put the company at risk with his own security errors, especially if those errors flow from doing personal business on company time or equipment.

Thirty Days

That’s when NATO’s newly expanding rapid response force would be ready to act when called upon.

The alliance is planning to establish a pool of around 30,000 soldiers who could be operational within 30 days. They would be armed with several hundred fighter jets and ships, according to high ranking NATO diplomats cited by the paper [Welt am Sonntag]. The new troops would be in addition to the already established NATO Response Force (NRF), which has around 20,000 soldiers.

This would be risible if it weren’t so incompetent.  It took 36 days for Germany to overrun Poland with numerically inferior forces at the start of last century’s WWII.  It took Germany 46 days to overrun France with numerically and technologically inferior forces at the start of that war.

Russian forces may remain numerically inferior, but they’re not technologically inferior.  Beyond that, 21st century forces are much faster and strike with much greater precision and with much greater power.

A “rapid” response force that can’t be ready for 30 days likely won’t find a fight to enter.  Such a response time harks back to WWI and prior wars where mobilization occurred first and took several weeks to complete.  Today’s force-on-force war will begin with a limited mobilization at most and a running start.  And I’ve elided the likely parallel cyber attack that will be fought to the detriment of communications, even impacting the target’s sensor systems’ ability to say that an attack is underway.  That cyber attack will shorten further the response time available.

A nation or a bloc that forms a “rapid” response force that can’t be ready for 30 days isn’t taking the matter seriously.

Most of What They Wanted

Recall that, in a breathtaking attack on Italy’s democracy, the nation’s President Sergio Mattarella vetoed formation of the coalition government that hard-Left 5Star Movement and hard-Right League, as the two winners of Italy’s elections, had formed because Mattarella didn’t like the coalition’s choice for Economics Minister, Paolo Savona.  Mattarella held Savona personally unacceptable over the latter’s disdain for the euro and for the European Union.

5Star and League have formed a new coalition, and it seems that Mattarella has approved the new coalition.  The coalition’s Econ Minister will be Giovanni Tria, an economist from the Tor Vergata University.  Tria has “criticized the eurozone, saying it had failed to achieve the convergence of the different economies;” he doesn’t seem that far from Savona’s position or from the coalition’s, just perhaps a bit more politic in expressing it.

Also, far from being banished to the sticks, Savona also will get a position in the new government: Minister for European Affairs.  The position has no formal portfolio, but he’ll still be in a position of influence and in the venue for which he was found ill-suited by Matterella.

Maybe Mattarella is figuring out that he’s President of Italy, not a mucky-muck of the EU.

Cybersecurity

A quick thought on this threat to our personal financial wellbeing, our companies’ wellbeing, and our collective wellbeing.  The Wall Street Journal ran an article on the subject earlier in the week, and this bit jumped out at me [emphasis added].

To better understand how far we have to go in creating a cybersafe culture, consider this: if you were taking a tour through a nuclear plant, and there was a big red valve with a sign on it that said “Do not touch,” how many of you would turn it? None, I would guess. But in a phishing test conducted at a major financial-services firm, one of the test emails actually said: “This is a Phishing Test. Clicking the link below will cause harm to your computer.” At least one executive clicked it! When asked why, he said, “I was curious to see what it would do.”

That executive should have been fired, for cause, on the spot.  It’s too bad the author of the article didn’t identify the company; if that executive still works there, that would be a financial services firm that shouldn’t get anyone’s business; the company will have demonstrated that it won’t take seriously its obligation protect its customers’ personal financial data—or the monies customers might actually place with it.

An Argument

…for leaving the European Union altogether.

By openly invoking the role of investors, financial markets and the defense of the eurozone in his speech on Sunday, the president [Italian President Sergio Mattarella] lends credence to the populist argument that Italy has become the battleground in a war between the international establishment and national democracies. Even if populists win the elections, their supporters believe, they will never be allowed to hold power for fear that they would oppose the dogma that dominates the eurozone.

That speech was his rationalization for his decision to block the coalition of the two parties who one the last national elections from forming a government.  With that speech, he demonstrated the fact of the Italian peoples’ belief.

And this from European Commissioner for Budget and Human Resources Günther Oettinger:

…markets will teach Italians how to vote….

And German Chancellor Angela Merkel’s

comparison between Italy and Greece is an unveiled threat: Italians had better toe the line, or they will not be spared what the Greeks have been going through.

The Wall Street Journal‘s editors have this one right.

[W]hat is happening in Rome is not only about the future of the euro. It has also to do with the state of democracy, in Italy and in Europe. Discussing and questioning the governance of the eurozone, as the Italian right-left populist coalition wished to do, should not be a taboo in mature democracies.

But national sovereignty be damned, and to hell with democracy and what petty voters want.  That’s the elitist EU attitude.  The worthies of EU governance Know Better.

This is what the Italian people need to think very seriously about in the coming national elections.