The Macrosite for News, Analysis and Opinion about the Future of the Internet

Gary Kern, CIO, MutualBank

Internet Evolution's instant message board - join the crowd...
You must login to participate in this chat.

... and we are out.

Thinkernetter

Great Event...  Thanks everyone!

 

Rank: Cave Painter

good day to all

Rank: Cyborg

Thank you for joining us Gary. Thanks Mary for hosting. Thanks all for joining!

IQ Crew

Thank you Gary

Rank: Cave Painter

Phew - it's been interesting!   Thanx to all!

Thinkernetter

Thanks for the very clear and full responses.

Thinkernetter

Thanks for your time and insight, Gary!

Thinkernetter

Gary, it's been a pleasure to hear from you. Thank you for your time.

Thinkernetter

Part of the user acknowledgement is they agree to keep up with security patches - but it would end up being more a reactionary tool if they didn't...

Thinkernetter

Any final questions for Gary?

IQ Crew

@Victor - that is one of the worries   we are actively looking into tools that will help us increase our visibility into remote devices.  Wish to say we were "there" but we aren't

Thinkernetter

Security is certainly up there on concerns list.  But again, it's part of something that increases every year with the needs, along with compliance, yet my budget and staffing don't

Thinkernetter

Ah good question, victor.

IQ Crew

Gary,
@Nicole "Gary, what's your policy for employees using Droids?"
Saw response to this, and was trying to add to it.
Especially if I have a rooted Droid???

And the bigger question is do you monitor that the these devices are patched and up to date, like IT does for the PCs?

Rank: Cave Painter

Re: compliance issues - I certainly think Financial Services & Health Care are the 2 industries hit hardest with compliance.   Makes it harder to "make a profit" that's for sure!

Thinkernetter

@Gary -- In this case it was after-hours so blcoking wasn't really an issue.  Makes me wonder if it's a suitable application of gamification for learning?

Thinkernetter

@Kim - I think a lot of compliance things are somewhat mandatory annually, but not sure about information security (yet) - but I think it soon will be.

Thinkernetter

@smkinoshita - I'm one that likes an environment where people can "play" with technology - it gets people more comfortable with it.  That's why I hate blocking things that I don't absolutely have to.

Thinkernetter

Is security your highest concern in your position, or are there other concerns that trump it?

Thinkernetter

Gary, I wonder how common mandatory security courses are for staff in a banking environment.  Are you ahead of the curve here?

Thinkernetter

Gary, are any specific regulations for financial firms harder to comply with than others? Do the regulations vary in complexity and "issues" caused for IT?

Thinkernetter

All bank compliance, including info security, is taken online annually by all employees.  Different courses for different roles, but Info Sec is required for everyone.

Thinkernetter

@Gary -- OK, this is a off topic, but I once introduced a manager friend of mine to Real Time Strategy games.  He was fascinated by its resource management and its "Fog of War" game play mechanics, probably due to work parallels.

Thinkernetter

Gary, regarding the mandatory info security classes at your organization, do employees have to take them just once? Periodically?

IQ Crew

ALL employees sign an annual "Acceptable Technology Usage" document.  Wireless/remote users have a separate one that depending on level of access may require additional approval.

Thinkernetter

@Kim - we have, but rarely (please don't make me jinx us).  Never for a MAJOR incident.  We have had some phishing, and thankfully got servers taken down rather quickly (even when in Europe) so as much 'lucky' as a good plan - but regardless, we at least knew what we wanted to do without thinking through the "fog of war"

Thinkernetter

@Nicole "Gary, what's your policy for employees using Droids?"

Especially if I have a rooted Droid???

Rank: Cave Painter

Droids - they need to Administrative Officer approval and to sign an Personal device wireless agreement.  Also need to allow us to enforce lockup interval and potentially wipe device if lost or employee terminated.

Thinkernetter

@Gary: do employees have to sign your policy documents regarding IT device use and/or social networking?

Thinkernetter

You've never had to use your security incident plan? 

Thinkernetter

Thanx @Joanne - sleep well!

Thinkernetter

Gary, what's your policy for employees using Droids? 

IQ Crew

PHISHING attack or Data Breach -- now that I know it keeps you up (and most likely your peers), I can get a better night's sleep!  Thank you!

Thinkernetter

I think those fears would keep me up at night too.

IQ Crew

Have I missed any Q's?  Repost if I didn't get to you...  or you want further embellishment

Thinkernetter

Online Banking - covered by our CORE provider (FISERV), and they help us with 2nd tier support.  Our 8-5 call center at the bank is pretty good with basic issues.

Thinkernetter

Keeps me up - wondering if we are the specific target of a PHISHING attack or Data Breach.  You can never be 100% secure, so we try to have a good incident response plan in place - but hope we never have to use it!

Thinkernetter

RE: Open Networks - we are probably more liberal in what we allow (probably driven by me) as I feel the more you see and interact with, the more ideas and opportunities arise.  We try to use "abuse" as a Management or Performance issue as opposed to overt blocking for all.  we do block the basics (porn, gambling,etc.)   Did that cover your point?

Thinkernetter

Gary, what topic "keeps you up at night" the most when it comes to security, if at all?

Thinkernetter

Gary, do you outsource support for online banking?

Thinkernetter

Mandatory info security classes -- very smart! ALL organizations should do that.

IQ Crew

RE: Basic IT education - that is one of our targets as well.  For the last few years we've been adding mandatory "Info Security" classes and details to our "End User Acknowledgement" to cover those thngs.  Education is tough as we also feel compelled to educate our CUSTOMERS who are using online banking or mobile - as the bank typically gets hit even if it's user caused.

Thinkernetter

@Joanne Goldman -- again, good point. 

Thinkernetter

@Gary: Are employees required to sign off on documents of policy, such as about device use and/or social media use?

Thinkernetter

Gary, any policies about using open networks?

Thinkernetter

iPhone owners need to install the TRACKER app and inform us immediately if lost.  We then make an assessment on "wipe" procedures

Thinkernetter

@smkinoshita, I think those topics would need to be covered in an orientation class so a company doesn't assume people know about them and regret not training people later.

Thinkernetter

That doesn't include applications, but I think that gets a little more customized based on the company.

Thinkernetter

Do you have mandatory tracking of iPhones in case they're lost or stolen?

Thinkernetter

RE: Devices - may depend on level of access needed as well.  For example, for VPN access we ONLY allow company owned devices to do that.

Thinkernetter

OK, let me rephrase then:  when I say "Basic I.T.", I think at a bare minimum all business people need to be aware of phishing, strong passwords, social media policies & the fact that anything published online is there and public forever, the importance of respecting and protecting the privacy of company and clients.

Thinkernetter

DEVICES:  we suggest iPhone or Droids only.   

Thinkernetter

Haha, good answer, Gary. Thanks.

IQ Crew

@nicole - I came from shops where the IT organization was as big as the entire bank, and the stress was much higher... that's one of the things that drove me to the community bank, a bit better "quality of life".  So actually the days got better just by being here!

Thinkernetter

@Gary: Can you name any devices you actually recommend to new hires?

Thinkernetter

And welcome to all Internet Evolutionaries here!

Thinkernetter

Gary: I read the other day that the new federal CIO said the first 40 days he was in office were his worst days on the job ever. Did you have a "worst ever" period when you first assumed the role?

IQ Crew

Saw an earlier post about recommending devices - we try to do that, and then a little bit of "other devices will be by best effort"

Thinkernetter

Welcome, Gary! Thank you for joining us today.

Thinkernetter

Thanx Kim- a bit nerve wracking to "try to be interesting"  

Thinkernetter

@Joanne Goldman -- good point.

Thinkernetter

@Kim, Agreed, but it's really important for people to have a holistic view of the business both for decision making and respectful interaction with other departments.

Thinkernetter

All: Gary (gckern) is already on the board here with us, so please ask him your questions!

IQ Crew

Hey Gary, great presentation.

Thinkernetter

Please repost or ask your questions - have a long queue I may not catch up with!

Thinkernetter

@smkinoshita, Basic IT can mean different things at different companies. There should be onboarding classes for proprietary software or other classes to help people succeed.

Thinkernetter

Signing in!

Thinkernetter

Awareness of the entire business environment is very demanding.

Thinkernetter

On that note, basic I.T. is a required course for all business studies at Fanshawe College.

Thinkernetter

I think basic I.T. skills should be mandatory for business.

Thinkernetter

CFWalters, I thought I read that the federal government made the transition from BlackBerry to iPhone.

IQ Crew

Government uses Blackberries, but someone told me that they may be going to a different smartphone.  Still those who have Blackberries are few and far between, and only the higher ranking gov personnel.

Rank: Cave Painter

Joanne, if Mary doesn't ask him on air please feel free to ask Gary when he joins us on the chat.

IQ Crew

Do they offer suggested devices to new hires? 

Thinkernetter

That's impossible to manage (re: what employees are doing w/devices despite the security settings).

IQ Crew

Genie's out of the bottle on BYOD.  Quite right.  We're not all going back to locked down Blackberries.

Thinkernetter

Awilliams: the check deposit feature.

IQ Crew

Anyone else have questions for Gary while we're still on air?

IQ Crew

what's your favorate?

Thinkernetter

It's a useful feature right now... it's my favorite thing on the Chase app.

IQ Crew

Refresh will work, Joanne.

IQ Crew

No problem here.

Rank: Cave Painter

Audio a little choppy.  I'm sure the March Madness tourney is taxing all networks today.

Rank: Cave Painter

Can't hear anything.

Thinkernetter

smk, just hit refresh.

IQ Crew

Die but now working for me!

Rank: Cave Painter

Freshing fixed it.

Thinkernetter

@CFWalters, Outsourcing can be anything not done inhouse.  It can be hiring an advertising agency rather than having an inhouse staff, or IT consultants to do a software implementation.

Thinkernetter

No, my audio suddenly died.

Thinkernetter

After refresh audio is fine

Thinkernetter

Everyone hearing the audio OK?

IQ Crew

Refresh your pages.

Thinkernetter

Hang tight, I think we had a technical glitch.

IQ Crew

@CFWalters I'm not sure if outsourcing is really the same as off shoring...

Thinkernetter

There's your question, smk.

IQ Crew

Typically outsourcing consists of going overseas?  How does that benefit the US?

Rank: Cave Painter

Ah, like Nigel F. wrote for us, this is where marketing and IT have to join forces.

IQ Crew

Outsourcing can be a great solution for small businesses to scale.

Thinkernetter

It occurs to me that this is something we've seen with enterprise legal services for years: a small inhouse team primarily concerned with engaging and running outside contractors (law firms).

Thinkernetter

@Kim:  Do nothing, or hire experts.  It also comes down to trust.

Thinkernetter

Continuing to refine the process is better than waiting until something bad happens to ask important questions.

IQ Crew

@Joanne: I guess it's more secure than not doing it at all (if you can't afford to do it inhouse).

Thinkernetter

@Kim, which poses the question:  How secure is outsourcing your security?

Thinkernetter

Great: paper and pencil!

Thinkernetter

Good one, smk. I have sent it to Gary through mind signal. Let's see what happens.

IQ Crew

I've heard (via All Analtyics, a sister site of IE) that fraud detection can be done using social network analytics.  Gary, do you have any thoughts on that?

Thinkernetter

Interesting that security would be outsourced.

Thinkernetter

Howdy, victor, welcome.

IQ Crew

Great to have you, batye.

IQ Crew

Hello, Internet Evolutioners :)

 

Rank: Cave Painter

If anyone has questions for Gary, share 'em here. We will send him a mind signal with the question and see if he receives it.

IQ Crew

Awilliams. We welcome you.

IQ Crew

Hello radioland!

Thinkernetter

Too true, Joanne! Welcome!

IQ Crew

If you're just joining us, say hello!

IQ Crew

@Nicole, Good to be here -- and alive!

Thinkernetter

Hello, hello.  Hello.

Thinkernetter

Great, we'll definitely get to that then.

IQ Crew

Curious as to what it's like from the company's point of view.

Thinkernetter

Are you looking to ask Gary about outsourcing, smk?

IQ Crew

In contrast, my wife works for a California-based company -- she's a heck of a lot more than 2-3 hours away.

Thinkernetter

I'm actually interested in using the Internet to outsource.  I've heard of several people around me locally who work for companies 2-3 hours away remotely.

Thinkernetter

hello to all :)

Rank: Cyborg

Thank you in advance for your time and response.

My question is in firewall administration and security.  Can you describe what MutualBank does to ensure servers are scanned and remediated to satisfy Payment Card Industry standards?  What triggers remediation?

Rank: Cave Painter

How many listeners/followers do you anticipate?

Thinkernetter

Test typing

Thinkernetter

Here is where we will be chatting with CIO Gary Kern tomorrow, Thursday, March 15, at 2 PM ET.

Thinkernetter

Here is where we will chat with Gary Kern on Thursday, March 15, at 2 PM ET. Looking forward to it!

Thinkernetter
IBM information resources
IETV: the thinkerNet on film
5
of
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   3 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   No comments


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
Brian Baron
How Edmunds.com Uses Analytics to Customize Site

3|14|13   |   0:47   |   No comments


The automotive website uses propensity modeling to target ads and customer registration forms, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
an IBM information resource
sponsored content
big blue blog
Alison Diana
Alison Diana   5/21/2013   1 comment
Ushering in a new era of cognitive computing systems, IBM announced today the IBM Watson Engagement Advisor, a technology breakthrough that allows brands to crunch big data in record time to transform the way they engage clients in key functions such as customer service, marketing, and sales.
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Keep Critical Data With a Knowledge Management System
Taimoor Zubair
Fortune 500 companies lose at least
$31.5 billion a year by failing to share knowledge. A Knowledge Management System (KMS) can help companies significantly reduce these costs.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
Yahoo Needs to Break Tumblr in Order to Fix It
Joe Stanganelli
As
Mitch Wagner discussed today, Yahoo is acquiring Tumblr. The big Internet debate at the moment is whether Tumblr will be good or bad for Yahoo. Regardless of their stances on the future of Yahoo itself, many claim that Yahoo will somehow ruin Tumblr.

CLICK FOR MORE