Showing posts with label caesars. Show all posts
Showing posts with label caesars. Show all posts

Monday, September 25, 2023

NEW INC. MAGAZINE COLUMN FROM HOWARD TULLMAN

 

Don't Gamble with Your Tech Security

This week's cyberattacks in Las Vegas are yet another reminder that you can't be passive about protecting your network and other digital assets. You need to relentlessly remind all team members that they each have a role, every day, in protecting the company--and their jobs. 

 

BY HOWARD TULLMAN, GENERAL MANAGING PARTNER, G2T3V AND CHICAGO HIGH TECH INVESTORS@HOWARDTULLMAN1

 

Watching the hapless victims of a cyberattack as portrayed on The Morning Show -- running around like headless chickens while clueless executives demand instant protection from the just-arrived outside team of white-hat hackers -- I was painfully reminded of just how interconnected we all are by our devices. And how exposed and vulnerable every business is to network intrusions by criminals, along with the extortionate ransom demands that typically accompany them.

When people returned to the office, they brought with them all the shortcuts, compromises, simplistic passwords and other bad habits they've adopted working remotely, along with all the crap and viruses their kids have inadvertently loaded on their laptops and home networks. Now's the time for companies to refocus and redouble their efforts to protect themselves, their people, their customers, their networks, and their digital assets from the risks and increasing likelihood that they are cyberattack targets. Remember, it wasn't raining when Noah built the ark.

The trouble is that until they've been the victim of identity theft or had a check ripped off from the mail, everyone and every business of whatever size thinks that it won't happen to them. You can explain the risks, the economic and reputational costs, the relatively inexpensive preventative steps, and everything else to smart and otherwise prudent and rational entrepreneurs and corporate executives.  But you can't understand for them. 

An excellent case in point: two of the largest casinos in Las Vegas just got hit by cyberattacks with Caesars paying millions in ransom (without sharing any of that information on the Strip) shortly before MGM got hit with a similar attack.  We've been led to believe by Hollywood heist movies that it's incredibly tough to take on a casino because of massive security and surveillance technology. Guess not. You can't really stop what you can't see and keeping ahead of the hackers is more difficult every day. You either pay up front for the protection that is available and keep your fingers crossed or you pay after the fact for the failure and hope it doesn't happen again.

In the recent Morning Show episode, the head honchos at the UBA network were ultimately unwilling to pay a $50 million ransom although it appeared that the network could come up with the cash.  Obviously, this is far from the case for most companies and institutions. And, in the typical circumstances of any startup or relatively new business, a substantial and unpayable demand would very likely mean the death of the firm.

Startups are rarely sitting on piles of cash; investors never want to see their funds going out the door to pay ransoms; and new business builders almost never spend scarce dollars on insurance.  Apart from the D&O insurance which their investors demand, it's a one-in-a-million prospect that they've purchased sufficient business interruption protection to cover cyberattacks. Entrepreneurs believe in passion and promotion, but rarely commit appropriately to downside protection. One of the clearest COVID-19 lessons was just how strapped and skinny millions of startups are and how little thought and money they had committed to resilience and backing up their businesses and their data securely offsite.

To me, the show actually had a far more important message, especially for executives and senior managers charged with cybersecurity responsibilities. The episode tracked the responses and reactions of the various junior and senior staff members to the crisis. Whether through stupidity, selfishness, or inadvertent subversion, several main characters completely ignore the experts' very specific directions to surrender their mobile phones to contain the spread of the virus. Worse yet, despite being told that the corrupted phones represented further risks of damage, they stealthily snuck off to make personal calls. Which reminded me of an old truism: men are not against you; they are merely for themselves.

The point is that no one has the luxury of acting alone because there’s really no digital environment that’s absolutely isolated, insulated, or secure. Every system is subject to human intervention, frailty, ignorance, and self-interest. If your team doesn’t seriously commit to help secure your systems, it’s just a matter of time before you suffer. A little inconvenience and some simple precautions can avoid a ton of disruption. And, as a recent Deloitte survey shows, the risk isn’t where you expect it. Gen Z is, in fact, many times more likely to fall for these schemes as older employees. Turns out, they only think they’re a lot smarter and computer-savvy than you.

There are three major messages that senior management needs to carefully and consistently deliver, and also demonstrate and validate through their own actions. An example or two of conscientious compliance by the boss is worth a million words.

First, make it absolutely clear that the concerns expressed about system security aren't nags or nuisances, they're necessities. They represent existential risks to the business, and the safeguards that have been implemented aren't casual or suggested, they're mandatory and will be strictly enforced with zero tolerance. But just saying it doesn't make it so. Your whole organization needs to live it.

Second, it's far too easy for people to assume that these matters are someone else's responsibilities and especially to hand it off to the IT guys and let them worry about it.  That's misdirected: the vast majority of breaches aren't super-sophisticated or driven by complex technical intrusions. They're the result of simple sloppiness, stupid reuse of the same passwords, laziness in terms of updating software, and, of course, social engineering, which rarely has anything to do with the technical aspects of your systems. You want your people to be helpful when asked, but, in these precarious times, a fair amount of caution, suspicion, and confirmation makes a lot of sense. Keep in mind that 91% of all known cyberattacks start with email phishing.

Third, one ongoing problem is that the fraud phishers and the hungry hackers have increasingly adopted two strategies: (1) they constantly use fake Microsoft logos and language to misleadingly alert users to the falsehood that their passwords need to be changed before they expire or are turned off by Microsoft; and (2) as the year ends, they will again be sending millions of fake emails with titles relating to year-end comp changes, salary adjustments, and bonuses, which appear to be coming from internal HR departments.  They're not, but they are close to irresistible in terms of the temptation to open them. Now is a very good time -- since October is National Cybersecurity Awareness month - to remind your team about these two schemes in particular and also to consider how best to distinguish your legitimate communications from the noisy and cluttered mess.

None of this is easy to pull off, but all of this is critical right now to get out ahead of the problem, to the extent that's possible. Sharing stories from other companies and articles about attacks and breaches that have been hit is somewhat helpful, but sadly, most people still won't believe that these things can happen to them.  Until they do.

SEP 26, 2023

Monday, January 23, 2023

NEW INC. MAGAZINE COLUMN BY HOWARD TULLMAN

 

Do You Have the Right Influencers?

Companies such as Cameo have shown the value of making genuine connections with people through its platform. But now that everyone wants to sell via social media, you've got to up your game.  

BY HOWARD TULLMAN, GENERAL MANAGING PARTNER, G2T3V AND CHICAGO HIGH TECH INVESTORS@TULLMAN


When Cameo was started at the 1871 tech incubator in Chicago, the two founders had to overcome a staggering amount of skepticism about the whole premise -- that anyone would pay any amount of money for short, customized, video messages, wishes and greetings created for their friends and family by C- and D-level celebrities and other has-beens and "never wases." It didn't happen overnight, but eventually, and with a huge boost from the pandemic lockdowns, Cameo killed it. Cameo's 2020 gross revenues were about $100 million -- four times the 2019 results -- and the company soon grew to be one of Chicago's brightest unicorns.

As with so many firms which raced to bulk up in order to meet the Covid-19 craziness, Cameo overbuilt its team and the 2021-2022 season was spent dealing with slower growth and right-sizing the business's headcount. More importantly, management was able to apply the product-market fit lessons learned to build a stronger set of offerings for the future.

As you might expect, there are many explanations of what ultimately helped Cameo turn the corner early on, and plenty of their "creators" are happy to take credit. Yet it's pretty clear that the real hook wasn't the celebrity, skill or talent of the various amateur or professional participants that the customers connected with; it was something much more basic and too often overlooked.  Interestingly enough, the fact that the first few thousand cameos were fairly crappy, done on iPhones on the fly in bad locations and circumstances and, as often as not, with only a rough approximation of the actual "script" that the customer was seeking, turned out to be not a flaw, but a compelling feature. These weren't slick Hollywood shorts (dare I say Quibies) or painstakingly produced IG user-generated fantasy flicks; they were down-to-earth, simple videos which felt like they were made by friends.

The key to these critical connections with the customers was that, even though everyone knew these weren't technically authentic, everyone was also in on the game.  Above all, what came through was the fact that the creators were sincere. The videos may have been clumsy or hokey, the performers might have stumbled along the way but what was obvious was that they were trying their best and actually putting themselves into the moment. Strangely enough, you might say that, even as they were using a cellphone to create the end product, they weren't phoning it in. Sincerity reads on the little screen just as effectively as does on the big screen at the theater. The immediacy, the simplicity, the directness, and the informality of the process combined to create a touching and convincing result that no one really anticipated.

Now, as we see the shift from the attention economy, where clicks counted most, to the influencer economy, which started as looks, but is increasingly about lucre, Cameo and others in the game are shifting their offerings from entertainment to information and economics. Cameo's "partners" are now happy to make brand and product endorsement videos for all kinds of companies.  

In the past, social didn't need to sell stuff to make ends meet - selling slices of your mindshare and attention to advertisers was enough.  Today, the business is all about ROI and every player needs to pay their own way. Social is no longer simply about seeing, it's all about shopping. Context trumps content. The central context now is less about community and far more about commerce. Novelty, notoriety, and noise are no longer enough. And not every influencer is a smart choice.

Cameo's initial experience provides some important lessons for brands and advertisers who want to use the omnipresent influencers effectively. The issue now is whether Cameo's latest attempts to translate and transfer their creators' credibility and connection to the commercial world will work or whether it will undermine the very reasons these people were accepted and appreciated in the first place. Too often, the medium gets in the way of actual communication.

There are three important ideas to keep in mind as you decide whether the risks and costs associated with employing influencers make sense and will provide a real return on your investment - not simply in terms of buzz, but in terms of bottom-line bucks. Brands and businesses need to build trust, authenticity, and benefit into their stories and the right influencers can help them do that.

(1)  Make Sure Your Influencers Know What They're Talking About

You need to take great care to ensure that the particular talent talking the talk is actually someone who consumers believe walks the walk as well. Snoop Dogg can sell Corona by the case and cannabis products all day long, but I wouldn't ask him (or Matt Damon) about crypto. Cred is extensible, just as brands can expand their coverage, but the capacity and qualifications of the endorser need to be known not simply to the industry or insiders but to the target consuming population as well. They don't have to be in the business - Snoop doesn't make the beer - but they need to know the business they're talking about. The Manning family may look silly hawking gambling apps for Caesars, but everybody truly believes that they love Lays potato chips.

(2)  Talk to Me about Me or Have a Friend Do It

Don't waste the time I don't have talking to me about you and your products or services; tell me simply and succinctly what you can do for me. How will you save me time, money, increase my productivity, or help me make better, smarter decisions about the things that matter in my life? People listen mainly to other people these days, most often at work, and the best paths are always the byways. These are lateral conversations in proper contexts from close and trusted sources -- not blasts or blatant attempts to beat me into submission. Subtle sharing sells. To be effective, influencers need to connect their own experiences to those circumstances and situations that the customers would empathize with and understand.

(3)  Make Sure the Influencers are Properly Positioned

The only content that really reaches the right audiences and effectively communicates your pitch is content that is authentically shared and passed on from trusted peers, friends, and families at the right time and place. If I'm not listening, it doesn't matter who is speaking or what you're selling. If the time's not right, even the most effective communicator will not get the job done. It's all about sharing, not selling. Given the growing swamp of competing and commoditized product offerings and the glut of ads about them, no one is looking for more choices. We want simple answers from people we trust. A finite and carefully cultivated number of credible influencers can provide those responses and directions if they're presented properly and in the right context.

Reverse mortgages may be sketchy -- and there are known scams associated with them -- but there's no better man to sell them to senior citizens than Tom Selleck. He's the right guy, right age, right persona, and a simple story. Trust me, I'm a TV Police Commissioner, a family man, and here to help.

Total Pageviews

GOOGLE ANALYTICS

Blog Archive