Monday, March 9, 2015

Is It Time to Revive Knowledge Management?

This blog post has been originally posted on the Big Men on Content blog:
Back in the 90s, Knowledge Management was being heralded as one of the best use cases for content management. The goal of Knowledge Management was to effectively capture and reuse an organization’s knowledge. That’s a lofty goal and it’s not a surprise that most Knowledge Management failed miserably.
There were many cultural, organizational, and process reasons for the failures of Knowledge Management but one of the main reasons was the technology.  Back in the 90s, the technology to capture, manipulate, share, and reuse content was still in its infancy. In fact, most vendors indirectly admitted as much when they stopped marketing Knowledge Management as one of their offerings.
But the customers haven’t given up on it.
In fact, I keep running into customers and prospects with “Knowledge Management” on their business cards. And, rightfully so! There are some major demographic related issues that drive the demand for Knowledge Management.
Many customers I meet face the problem of an aging workforce. According to the Bureau of Labor Statics, there are numerous industries with a median workforce age over 50. I’ve seen organizations with an average workforce age over 55. In fact, the Stanford Center on Longevity predicts that by the year 2020, the 55+ years old workers will represent 25% of the workforce!
This is a workforce that is not Internet natives. They are not millennials. They didn’t grow up digital. A lot of their knowledge and expertise is not in a corporate repository. It is in the decades of notes stored on paper and in their heads. In a few years, those employees will retire and their knowledge will leave the organization. Often, this knowledge is mission critical and it has to be captured, processed, shared, and reused.
Does that sound familiar?
Yes, that’s exactly what Knowledge Management is supposed to be all about. Knowledge Management is needed more than ever before and, finally, the technology has advanced mightily since the 90s. Today, our ability to capture information in the form of paper, voice, images, drawings, video, and other content is very powerful. So is our ability to ingest, index, and manipulate the content. We have structured and unstructured data analytics which help to make sense of all that information. Finally, we have compelling responsive experience, mobile devices, and cloud environments that help us share and consume the information effectively.
Knowledge Management is needed and increasingly, Knowledge Management is possible. Maybe, it’s time to start promoting Knowledge Management again. Because this time, it might actually work.

Friday, February 6, 2015

Could ECM Have Prevented the Sony Hack?

This blog post has been originally posted on the Big Men on Content blog:
There were hundreds of data breaches last year but Sony Pictures won the prize for the most publicity received by a hack. Mostly that publicity came about because Dennis Rodman’s friends got to watch The Interview before any of us. Like the President of the United States said, we can’t tolerate that. We must prevent such cyber-attacks.
But how?
According to the media coverage, most of the stolen data was in the form of structured data such as employee salaries and social security numbers but also emails, documents, movie scripts, and video files – even entire full-feature movies. Over 100 terabytes of data have been allegedly stolen and a lot of it was unstructured data, content. From the little information we have about the hack, no ECM system was in place and the content was stolen from servers and employees computers running Windows. ECM has always been claiming to have the ability to ‘secure’ content, right?
So, would ECM have prevented the Sony hack?
Let’s assume that it really was a hack – a malicious data breach by external actors rather than an internal security leak. An Edward Snowden scenario would have been a whole different ball of wax. But if the bad guys came from the outside, could ECM have prevented the Sony hack?
ECM could have certainly helped by securely archiving the content files and email messages, keeping them off the user drives, and expunging them as their retention period expired. Culling the email volume would have reduced the number of sensitive and sometimes embarrassing emails that were hacked and exposed. It wouldn’t solve the problem entirely but it would have helped. Getting rid of unneeded and potentially compromising data is one of the best practices of information governance solutions based on ECM. Well organized ECM repository and processes would have kept at least some of the sensitive content off employees’ hard drives.
Next, let’s consider permissions. Many of the stolen files were allegedly swept off file servers, which likely had little or no permission control. An admin level access gives a hacker the master key to the vault. Permissions provided by an ECM system would make things much more difficult for the hackers. Sophisticated permissions often allow administrators or even curators to do their job without having the rights to access the content itself – no master key. That would have helped a lot.
How about security features? I’ll skip over the authentication, SSL, VPNs, and other perimeter security that is not specific to ECM – most ECM systems do this but so do other applications. I’m skipping over virus checker and malware detection for the same reason – those were clearly not in place or ineffective in the hack but they are outside the scope of ECM. By the way, a two-factor authentication and a good firewall would have helped too – chances are they had some of it and it was hacked.
The ECM specific security would include repository level encryption and possibly also file level encryption. The repository level encryption is big – many customers use it, it doesn’t burden the users, and it does represent another layer of security, which could have prevented some of the data theft.
File level encryption provided by a rights management system is also a capability that some ECM vendors provide. But let’s be honest, most customers don’t use it as it imposes a significant burden on users and impacts their productivity. That said, having to break the encryption of every file would provide as much security as one can get these days.
I should also mention the audit trail, which by itself doesn’t prevent any data theft but it does help the forensics after the fact. Tracing back the hack helps to assess the damage and more importantly, to prevent it from happening ever again. The Sony hack apparently occurred over several months. A good audit would have discovered the breach earlier and prevented some of the data loss. ECM systems are well known for their sophisticated audit trails and I bet Sony now wishes they had it.
So, to sum things up, an ECM system could not have entirely prevented a data breach like the Sony Pictures hack. No system can. But it would have provided several additional layers of security to protect the intellectual property better and the result of the hack would have compromised less data. Every security layer makes things more difficult for the bad guys and it slows them down. That’s what security is all about – both in the physical and in the digital world.

Wednesday, January 7, 2015

The Need for Content Curation

This blog post has been originally published on the Big Men on Content blog. 
Most content libraries start great. You pick a repository, populate it with some initial content, include decent metadata, establish ways for people to add more content, set some expiration policies, and voilĂ  – you have your sales library, your marketing assets library, or your library of product information.
The library is easy to use and navigate. It was built by a small group of people who had a clear, shared concept of how to organize it. The users can find what they need and everybody is happy. We have another content management success story under our belt!
Now, let’s fast-forward a few months. People are regularly contributing additional artifacts to the library and the library’s growing. The team that has built the library has moved on to build something else. But that’s OK; they have done their work. The library is still well organized and everyone can find what they need, when they need it. This is content management at its best. Everybody is still happy.
A couple of years later, the library has grown substantially. Nobody really remembers the original structure or how content was to be stored, tagged, and classified. People are saving artifacts based on their view of the structure and everyone has a different view. Nobody has time to add proper metadata to content assets – most content is stored without metadata or with “lazy” metadata. The original project team has had the foresight to set default expiration rules for content but when content assets come up for review, there is no time for it and everything is being kept without ever deleting anything.
The library is no longer well organized. Nobody can easily navigate it and every search yields pages and pages of results. Hardly anyone is happy with the library. The library is now seen as this dreaded place where content goes to die. The users need something better to be productive. They need something simple, easy to navigate, not this bloated repository full of junk. The business blames IT and IT blames the vendor.
Eventually, they decide to build a new library…
What has gone wrong? Well, it wasn’t the content management system, no matter which vendor you chose. It was the process. More precisely, it was the lack of process. The library was built without a content curation process in place. Curation would ensure that somebody decides what to keep in the library and what not. Curation would also ensure that every new artifact is added the right way – in the right location and with the right metadata. Curation would also ensure that the structure, rules, metadata, and policies are evolving to keep up with the changing requirements of the organization.
Some of the curation processes can be automated and some of them may require manual work. But without curation, a successful content management deployment can quickly become a digital landfill.

Wednesday, December 31, 2014

My 2014 Predictions Scorecard

Just like every year, I review my predictions from last January and publicly score how well I did. After all, predicting the future without accountability is something only a futurist would do. Futurist is a cool job if you can get it. It’s fun just like a historian, except you can’t be confronted with any actual facts. Well, I’m not a futurist and so this is how I did:

1.     Big Data shifts to Big Content
I predicted that the industry would get tired of talking about ‘big data’ and that we would start looking for insights coming from ‘big content’, large volumes of unstructured data. Well, this has really happened, even if the term itself isn’t used much. The media got tired of ‘big data’ and replaced it pretty early on in 2014 with new buzzwords such as the Internet of Things (IoT) and – yes! – Analytics. Analytics refer to the ability to get insight from unstructured data, in contrast to Business Intelligence (BI), which is primarily focused on structured data. Ever heard of IBM Watson? Well, that’s all about analyzing large volumes of content.
Score: 1 out of 1

2.     ECM stays
I predicted that the term Enterprise Content Management (ECM) will survive another year unscathed, even though many voices will keep calling for its demise. Not only has ECM survived, I find that it’s stronger than in the last couple of years. Many of the vendors from adjacent industries such as Enterprise File Sync and Share (EFSS) and Capture are reinventing themselves as ECM wannabes. As the market is consolidating, the term ECM seems to be one of the constants.
Score: 2 out of 2

3.     BPM market looking for direction
I predicted that the BPM market would continue looking for a something new. It still is. I was at the Gartner BPM Summit just a couple of weeks ago and among the 20-30 sponsors, hardly anyone stood out with their ability to differentiate. I have further predicted that BPM will become a feature of other solutions. That hasn’t exactly happened yet, even though I have not seen many BPM deployments lately that didn’t involve a repository and one or more core applications. Yet the BPM market remains solidly an independent market for now and I can only give myself half of a point here.
Score: 2.5 out of 3

4.     Digital marketing meets compliance
I have predicted that amid the consumer security and privacy pressures, marketers will start paying more attention to information governance and data security. I was completely wrong on this one. While there has been a security breach story every week through 2014, still nobody cares about consumer privacy and data security. The last of all who will ever care are apparently the marketing departments. #Fail.
Score: 2.5 out of 4

5.     Mobile market
I’ve predicted that not much will happen in the mobile market with iOS and Android keeping their massive share while Blackberry remains stagnant. I have also predicted, though, that Microsoft will enjoy a substantial adoption of their Surface tablets, reaching 10% share of the tablet market. Why did I ever make a quantifiable and verifiable prediction? The market stayed about the same, with Apple and Google far ahead of anyone else. The Surface gained a lot of adoption and I see a whole bunch of them now when I travel. Yet, its market share according to Statista was only 5.7% in Q3/2014 - not quite enough for 10%. Still, I think that I deserve half of a point here!
Score: 3 out of 5

6.     Spying will continue
I predicted that we wouldn’t see any material changes in legislation or any proof that the NSA would change any of their data collection practices as a result of the Snowden leaks. Indeed, nothing changed. We have moved on, accepting the spying the same way as we have accepted security controls at airports. Life sucks a little more but not enough to take it to the streets.
Score: 4 out of 6

7.     Data privacy will become the new code of business conduct
Yes, yes, yes. This has happened. As I have predicted, many companies started putting their employees through mandatory security and data privacy training classes. Just like in the case of the code of business conduct training, the primary goal is to reduce corporate liability rather than to address the actual problem - which may or may not be even possible. Anyway, I call it progress towards security awareness and get a point here.
Score: 5 out 7

8.     The end of corporate social software
I’ve predicted that most companies will give up on building a generic social water cooler and that they will simply replace social software with file sync and share. This happened – since sharing files is apparently the highest level of collaboration most employees are willing to endure. I’m not sure anyone even mentioned enterprise social software at all in 2014. Pure play vendors continue disappearing with some of the once-leaders going through major shake-ups including CEO replacements (i.e. Jive) and company re-branding (i.e. Newsgator – now Sitrion).  Just like I have predicted, social software became a feature. What’s even more interesting is that the traditional collaboration software and – gasp – e-mail are going through a renaissance with a new breed of solutions such as Google Inbox and IBM Verse.
Score: 6 out of 8

9.     Cloud will go through a reality check
2014 has become a year of reality check for cloud software vendors. The big event that I predicted would come was Box when they filed their now fabled S1 document with the SEC. The filing exposed an alarming and widely unexpected disregard for profitability. The market gasped in unison and Box was forced to postpone their IPO indefinitely and we haven’t seen any other cloud vendors rushing to disclose their numbers. As a result, things have certainly cooled off a bit on the venture-funding front and people are all of the sudden asking those pesky questions about monetization, cash flow, and (oh dear!) profits. That said, we haven’t seen an actual failure of a cloud vendor and nobody is worried about viability of any of the cloud vendors who are now safe-guarding our corporate data. So in all fairness, I don’t deserve a full point on this one.
Score: 6.5 out of 9

10. Cars will beat wearable devices
I’ve predicted that wearable devices would not be a big hit in 2014. That has happened – Google has effectively killed its once-hyped Glass, Apple failed to ship the Apple Watch (though I still want one), Nike did something stupid with the FuelBand and not much new happened otherwise. That said, I have also predicted that more attention would be paid to the user experience in our cars, which didn’t happen at all. While everyone continues drooling about the Tesla, nothing new happened in the auto sector, not even at Tesla. That’s too bad because most car manufacturers still believe that better user experience means dark wood interior trim… I will have to stretch the rules to give myself half of a point here. But then again, I’m doing the scoring so why not, right?
Score: 7 out of 10

With 7 out of 10 points, my predictions weren’t particularly good. Some of them were obvious, some didn’t happen. The greatest disappointment in 2014, albeit one that I predicted, was the lack of advances in data security. The problem is becoming dire and yet nobody cares. This has to be the greatest problem to be solved right now – and I am not sure it will be solved anytime soon. The one prediction that I have missed completely was the Internet of Things (IoT), which is where most of the innovation occurred. With the IoT, home automation is becoming reality at a reasonable price, which is very exciting. Other than the IoT and the re-invigoration of email, 2014 was kind of a slow year.

We’ll see what happens in 2015!


Tuesday, November 25, 2014

Security and the Internet of Things

I am a big fan of the Internet of Things - all the smart devices that are changing our lives by being connected to the Internet. I consider myself a pioneer and early adopter of these gadgets. What worries me though, are the security and privacy issues involved with using such devices. So, what are the concerns?

Well, I am not too worried about my IrrigationCaddy sprinkler controller. Even if someone was to hack into it, the most damage they could do is to make my lawn look greener. After all, we’ve been conserving water heavily in California and the lawn looks pretty dry. Similarly, I am not too worried about all the Belkin WeMo switches and outlets that control the lights in my house. A possible hacking could lead to some pranks or annoyance but it would probably not represent a significant security concern.

But I am a bit more worried about my Nest thermostat. The concern is not so much the temperature in my house but rather the fact that the device knows when we are home and when we are away. After all, we set it on “away” mode when we leave town to conserve energy. Knowing we are away could be some very useful information for a potential perpetrator planning a break-in.

Similarly, the wearable devices represent a privacy concern. Jawbone recently published a fascinating blog post about the effect of the Napa earthquake on the sleep of Bay Area residents. While the data is fascinating, it also conveys a disturbing fact – the device knows when you are asleep! What’s the worry with that? Well, if someone were to break into your house, knowing that you are asleep would be pretty useful information, wouldn’t it?

The concern with cloud-based cameras such as the Dropcam – which is now owned by Nest, a Google company – is also pretty obvious. The camera feed is available and often also stored in the cloud, which begs another obvious privacy concern. The fact that Google owns both Dropcam and Nest is only adding to the concerns. After all, Google has been pretty open about their disregard of consumer privacy.

What concerns me even more is the trend towards smart cars. Sure, the Tesla is pretty awesome and the factory’s ability to upload and deploy patches and updates over-the-air is amazing. But what vital systems of the vehicle can be controlled remotely? Could a possible hacker make my car stall while driving on the on the freeway? Could they lock or switch off my breaks? That could become a life-and-death scenario.

I was recently at a conference where I saw a panel about the future of smart cars.  It was scary to see how the insurance companies are chomping at the bit to get the car manufacturers to implement smart devices that would monitor our driving behavior. They claim it is only to our benefit – the good drivers would pay lower premiums than the bad drivers. In fact, the Progressive Snapshot already does that, albeit on a voluntary basis. But it is a small step from Snapshot to the Fitbit activity tracker and if your health insurance company starts accessing your daily activity data to adjust your premiums, you may get worried about the Internet of Things. And rightfully so.


The Internet of Things, the world of smart devices connected to the Internet, will make our lives better. In fact, it will make our lives amazing. But if the data falls into the wrong hands, which is not an unreasonable concern, the smart devices could represent a major privacy and security concern for all of us.

Tuesday, November 4, 2014

File System in the Cloud

Today, Microsoft and Dropbox surprised us all by announcing a partnership. According to the announcement, Microsoft Office applications on mobile devices will be integrated with Dropbox to allow direct access to documents from within the Dropbox folders. This is a big deal.

With this announcement, Dropbox has the chance to effectively become the file system for mobile devices – the file system in the cloud. This is something that Apple didn’t include in all the ingenious plans for its iOS operating system. Apple has always claimed that applications and their data need to be compartmentalized. But people wanted a file system – perhaps that’s what 30 years of DOS and Windows dominance have taught us. Dropbox came up with an alternative and it became hugely popular.

Apple eventually relented and started introducing iCloud as a way to share data in the cloud, primarily for music and video content that is. Yet Apple didn’t pay much attention to documents, which opened up the window of opportunity to the likes of Dropbox, OneCloud, and Google Drive. Not to mention that only a few users have figured out how Apple iCloud actually works.

Since then, Dropbox has been a run-away success, attracting well over 300 million users. Google, Microsoft, Apple, and dozens of other vendors attempted to follow in their footsteps. Now, it would appear that Microsoft is conceding the race to Dropbox. That alone is huge. Microsoft OneDrive struggled from the beginning to gain any meaningful market share and now, its future is uncertain.

The greater deal yet, is the fact that by way of closely integrating with Microsoft Office, Dropbox really has the opportunity to become the default file system for mobile devices; a cloud based file system – something that Apple failed to deliver.

The announcement begs another question. Giving up on OneDrive in favor of Dropbox is a massive concession. Microsoft doesn’t concede anything often. Dropbox got itself a sweet deal and Microsoft didn’t do it just because it gives the users a choice of storage. Sure, Microsoft gets more money from selling Office than they ever would get from OneDrive, but I suspect that Microsoft is likely getting something more in return. Today, we can only speculate what it is. If I were to place my bet, I’d be putting my chips on Microsoft Azure right now, at the cost of Amazon EC2. I suspect that Dropbox may be leaning closer to Azure now. But that’s of course just speculation.

Today, the world may have changed a bit. Or, maybe it changed a lot. Dropbox has been given the opportunity to become a major force in the cloud-a mobile game of thrones. It doesn’t change much for the enterprise customers who will still need to ask whether the consumer-focused Dropbox is an adequate solution for sensitive corporate data. But in the consumer space, Dropbox has been handed the keys to the kingdom.

Accessing files in Dropbox from within Office on iPad. Cool!