Manufacturers have traditionally been positioned as a link in the long chain of supply. Somewhere between raw materials and finished products is where the manufacturer exists, transforming the materials into products that can be resold via distributors and wholesalers.
The supply chain was linear and relatively predictable, but that is all changing. With the introduction of broad internet connectivity, web-based services, large e-commerce platforms and increasingly innovative and competitive new logistics players, the supply chain is becoming a spiderweb of connectivity and communication, with linear approaches out the window and, to some extent, predictability along with it.
The economy we have today is an environment where customers demand more direct and personal approaches, and producers are being forced to find ways to accommodate. With the huge e-commerce platforms like Amazon and Alibaba, along with more direct-to-consumer channels, manufacturers are being turned into direct-to-consumer suppliers. Acting as drop shippers for the seller, the manufacturer isn’t shipping bulk or volume to distributors or wholesalers but smaller shipments direct to the consumer.
Many retail stores have now become more fulfillment locations than the place where the customer buys. This is causing tremendous change in logistics tools and approaches because the size of shipments is becoming smaller while the number of deliveries – and delivery locations – is only increasing.
Customers can go right to the brand’s website and buy direct, driving increased focus on building brand value and improving the overall customer experience. With the demand from consumers for flexibility in how and where they buy, retailers have shifted their approaches to bring e-commerce into the brick-and-mortar stores. This is where online and offline sales channels come together, creating pressure in ordering and fulfillment systems to offer the flexibility and experience consumers want.
While this converged channel model requires businesses to make new and continued investments in e-commerce and digital solutions to enable the flow of orders and information, it also delivers several potential benefits to the business, including the ability to better manage growing customer expectations, better compete in the digital marketplace, and address disruptions in the supply chain by having alternative options.
Delivering the goods has always been an operational challenge, with success often measured in performance and cost. Today’s marketplace requires more agility and flexibility, which means the role of supply chain managers is more strategic than ever. Simple logistics now has a direct impact on the customer’s decision to buy now, as well as buying again later.
The world of cybersecurity constantly changes, making ongoing education the key to understanding the threats businesses face and how to possibly deal with them.
Cybersecurity is often defined as a set of techniques for protecting an organization’s digital infrastructure – the networks, systems, and applications – from being compromised by attackers and other threat actors. Cybersecurity is comprised of the efforts to design, implement, and maintain security for any organization network which is connected to the Internet.
Cybersecurity is made up of the technology, people, and processes which create strategies to protect sensitive data, ensure business continuity, and safeguard against financial loss.
To understand what cybersecurity entails, it is important to have a basic understanding of the relevant terminology.
Starting with a few that are frequently misused, here are some cybersecurity terms to add to your business vocabulary.
Data are the bits and bytes. When multiple bits and bytes are combined, they make up information. Knowledge is required to turn information into action.
A threat is the possibility that something bad that might happen, while a risk includes the probability of the bad thing happening and the possible result.
Risk Management is the process of responding to the possibility that something bad might happen. Traditionally, there are four options for managing risk in the business: accept it, transfer it to someone else, avoid it altogether, or mitigate it (reduce the severity). To manage cybersecurity risk, many businesses establish requirements or controls to identify activities, processes, practices, or capabilities an organization may have. Controls may or may not be mandatory, but requirements generally are.
Information Security, or Information Assurance, is the protection of facts, news, knowledge, or data in any form. Information Assurance is an important aspect of preserving business resources and is often combined with cybersecurity, although it isn’t squarely in that area. Where cyber addresses digital, information security must also address non-digital such as paper, human knowledge or memorized, stone tablets, pictures, and signals or whatever.
Authentication is the process of proving an individual is who they say they are (claiming an identity and then proving it), whereas authorization is the use of access controls to determines and enforces what authenticated users are permitted to do within a computer system. Access Controls are the means and mechanisms of managing access to and use of resources by users.
Audits, in cybersecurity, are usually performed after a security incident. In general, an audit is an official inspection of some type. An assessment is often more like a health check for gauging capability or status. Audits may be performed internally or by outside entities. Compliance is meeting a requirement, whether internal or external. Sometimes these are regulatory requirements where a certification or attestation of some type is shown. Both audits and assessments may be required to be compliant with certain standards or designations.
A cyberattack is any attempt to violate the security perimeter of a logical environment. This could be a single computer system, a local or wide-area network, a cloud server, etc. – whatever is within your “perimeter” and is interconnected with your systems, regardless of location in the physical world. Cyberespionage, on the other hand, is the unlawful and unethical act of violating the privacy and security of an organization for the purposes of leaking data or disclosing internal, confidential, or private information.
And then there’s malware (malicious software), which includes any code that is written for the specific purpose of causing harm, disclosing information or in some other way violating the security or stability of a system. The malware category includes lots of different types of terrible and potentially damaging programs including virus, worm, Trojan horse, logic bomb, backdoor, Remote Access Trojan (RAT), rootkit, ransomware, and spyware/adware and more.
To better-secure your systems, multi-factor or two-factorauthentication is suggested. Multi-(multiple) factor and two-factor authentication are a means of verifying a “claimed” identity using two or more types of proof (authentication factors). The password is typically the initial proof provided, and the other factor/method might be SMS to your phone or possibly an authenticator app.
For example: You claim that the email address is your identity, and you verify that by entering your password. That is one “factor” that proves your identity. But if your password gets hacked or revealed, it would be good to have another layer of protection on that login. Two is better than one in this case; MFA (multi-factor) and 2FA (two-factor) authentication is considered stronger than any single factor authentication and requires another method (factor) of identification to prove your identity.
Finally, there are zombies. Yes, Zombies. This is a term that relates to the concept of a malicious network of “bots” (a botnet). Botnets are made up of poor, innocent computers that are compromised by malicious code so that they can run remote control or other agents. The agents give the attackers the ability to use the system’s resources to do nefarious things, like perform illicit or criminal actions. The zombie can be the system that hosts the malware agent of the botnet, or it could be the malware agent itself. Either way, zombies are bad.
Security is an essential consideration for every business, and the Internet and the interconnected design of today’s technology has made things so much more complicated. The most important thing is to be aware of the threat and how that landscape is changing, and to educate team members so that everyone in the company participates in keeping the system, and the business, protected.
When the pandemic forced many business users to move to remote work, it also forced the network security “boundary” to expand greatly and with great speed. Companies quickly adapted their tools and work so that it could be done somewhat effectively even as the employee working environment changed. But new security models to match with new working models have not as quickly been adopted.
Business cloud workloads grew, by some estimates, as much as 20% just in the first 6 months of 2020. Yet many of those businesses electing to bring cloud working models to their business also made of the mistake of not expanding their security as they expanded the cloud network. This leaves systems and information vulnerable. Phishing, ransomware, credential theft and web app attacks have increased, catching businesses in their vulnerable states.
“In April to June of 2020 alone, security incidents increased by 188%.”
Even more than on-premises systems, it was the external cloud-based data and applications that were under attack because so many companies expanded their use of cloud services without enhanced security as part of the plan. Any expansion to include the cloud as network also significantly increases security risks. One report found that 35% of businesses made their cloud storage openly accessible to the public, allowing anyone to access it via the internet.
Don’t let your critical information be exposed or put at risk. When you begin using a cloud service, make sure to also address security for the new working mode or it could lead to lost or leaked information or a system breach.
Mendelson Consulting and NOOBEH cloud services take security very seriously. We help our clients keep their applications and data working properly and have a focus on methods to keep information safe regardless of what cloud you work on.
The cybersecurity threat landscape has changed dramatically in the last few years. No longer primarily a big-business concern, cybersecurity has become a key focus of businesses small and large. Attacks on SMBs are on the rise, perhaps because they represent a plentiful and often easy target. And the cost of damage and disruption to business just keeps going up.
Cybersecurity is not a problem you can simply throw a bunch of money and tools at to fix.
No matter how much great software or fancy systems you implement, the people will always be a big part of the equation. The root cause of over half the data breaches reported is a result of negligent employees or contractors.
That means that nearly half of all attacks are being executed through phishing or social engineering. The only tool you can apply to this problem is education. Efforts should be focused on security awareness and training workers to be more cautious to the point of almost being paranoid. Better to be safe than sorry in this case.
Training workers to be more careful as they work with emails, documents and websites is part of it, but there is much more to making sure the business is addressing the entire cybersecurity issue. NIST (National Institute of Standards and Technology) offers a wide variety of information and guides that businesses can use to learn more about and implement cybersecurity practices. Among these resources is the Cybersecurity Framework.
According to NIST, “the Framework focuses on using business drivers to guide cybersecurity activities and considering cybersecurity risks as part of the organization’s risk management processes.” It is a highly useful tool in helping the business align and prioritize activities with business requirements, risk tolerances and resources. The standard framework includes elements that are consistent and common across sectors and critical infrastructure, so it can be oriented to any business.
Even if the business is not prepared to delve into the details of a comprehensive cybersecurity policy and guideline, a basic outline and approach cannot be avoided without asking for disaster.
Putting this squarely into the Risk Management category, there is an ongoing process of identifying, assessing, and responding to risk situations or conditions. To manage the risk, businesses need to consider the likelihood that an event will occur and what the potential impact is as a result.
Knowing the acceptable level of risk for reaching the business objective is the risk tolerance. If a business understands its risk tolerance, the company can prioritize cybersecurity activities and make informed decisions about cybersecurity expenditures.
There are five key functions to consider as it relates to cybersecurity risk: Identification, Protection, Detection, Response and Recovery. How the business addresses each of these in the context of the systems and activities is essentially the business’s cybersecurity posture, a high-level and somewhat strategic view of the organization’s management of cybersecurity risk.
The key to building a solid foundation for business cybersecurity practice is to establish a platform where all the business applications and data can be identified and access secured.
User desktops, productivity applications, operational software and business data can be hosted on private cloud servers, allowing the business to fully-manage data and application access. The server-based model reduces or eliminates the need to sync data to devices, and remote desktops keep user environments secure, patched and up-to-date.
Our consultants can’t write your cybersecurity policies or determine your risk tolerance, but we can help implement a solution that improves fault tolerance, resilience, and recovery.
Accounting professionals have an opportunity right now to help their business clients through the difficulties presented by the COVID-19 pandemic. With work-from-home mandates and increasingly fluid reporting requirements to support grants, loans and loan forgiveness, business owners need all the support and good advice they can get.
The global pandemic is changing the landscape of business worldwide. Many small businesses in the US have either closed or are on the brink, looking for ways to keep the doors open and employees paid. Supply chains are strained, distribution has slowed, and workers are being asked to work from home if possible.
These are challenging times, but the guidance and support you can provide to your business clients can be just what they need to help keep the doors open and workers producing. Remote access, cloud hosted applications and data, and real-time accounting support and management reporting are the weapons you and your clients will use to fight the conditions that are currently working against you both.
Help your clients deploy cloud hosting services for their entire business.
Running applications and storing data on an in-house network increases the cost and complexity of supporting a remote or mobile workforce, for you and for your clients.
Remote access and supporting work from home requires that users have the means to communicate with each other and to collaborate on the work. Tools to support communication and collaboration are critical when the workforce is distributed, operating from a variety of locations and with whatever device is available. Yet business owners, operators and managers may find that collaboration apps and other online tools don’t provide access to the applications and data required to do all their work.
To address the problem of working on client data, some accountants may install the client software and copy the data to their own in-house networks. This creates a situation where the accountant is paying for computing resources, space and management of client applications and data in addition to their own. This increases the cost of internal operations for the accounting firm and can impact internal system performance while also reducing overall productivity.
More to the point, this model only supports doing after-the-fact work for the client, which results in the data and reporting being outdated and far less useful to the client in supporting daily decision-making. This model also does nothing to help the firm with their own possible work-from-home needs even as IT support and on-site service becomes more limited.
Accounting professionals wanting to provide services to clients proactively rather than reactively must have real time access to the same applications and data that the client uses. The old fallback to remote control solutions is one approach, yet it is not really an optimum solution to the problem.
Remote control, like PCAnywhere, GoToMyPC or LogMeIn expose the professional to more of the client computing environment than is necessary, introducing risk and the potential for blame if something goes wrong. And remote-control solutions are single user, reducing productivity because the client can’t use their system while the accountant controls the computer. RC solutions also rely on the availability and function of the on-premises systems. If the on-prem systems aren’t turned on, up and running and accessible, then the remote user can’t connect.
It may be that online or web-based applications are an option, but for many businesses they aren’t really a viable solution. QuickBooks Online is simplified software and is not appropriate or usable for many businesses. The QBO subscription model is per-company, limiting options and reducing cost-efficiency for businesses with multiple entities. And QBO doesn’t address other business needs, such as working with documents and reports, and it can’t provide any access or support for other business applications. Even the ability to backup and preserve data is very limited without specialized services and tools.
Shared hosting service might be closer to the right answer, yet shared hosting is generally only useful for very small organizations and supports only core QuickBooks functions, so it can be as restrictive QBO. Shared infrastructure used by the shared hosting platforms can also introduce significant risk to every business on the platform because ransomware and malware can easily move through connected file systems and servers.
Compare shared services to a public pool where it is very easy to transmit from one person to another; in these networks an intrusion can end up spreading malware to the entire network and platform, resulting in days or even weeks of outages. Unfortunately, disaster recovery is often limited to recovery of the provider hosting platform and does not always include recovery of all customer data.
The best solution for business is private, managed cloud hosting service delivered on a trusted and proven platform like Microsoft Azure.
Hosting service that takes advantage of the Microsoft Azure cloud platform allows the business to centralize access to all their important applications and data, making it possible to provide complete application functionality for all users no matter where they are located.
Using the Azure platforms means that security, fault tolerance, scalability and agility are designed into the solution rather than being extras from the hosting provider. Microsoft-managed datacenters and Microsoft-managed hardware means the experts in systems and security are handling the big stuff while the service provider focuses on what the client needs.
The virtualization technology enables the agility to meet changing business needs, scaling systems up or down if necessary. Massively scalable platform allows services to be right sized now without concern for future resource requirements (no buying ahead based on possible future needs). There are no arbitrary limitations placed on the applications or services the business needs to run on the cloud platform, and no fees for running more apps.
Making all the applications and data available to workers, when and where they need them, is the key to promoting higher levels of productivity while delivering the data management needs to support daily decision-making.
Now that you have access, provide pro-active support and help business owners and managers make the right decisions.
Better data and reporting to support business and finance management is more important than ever, especially when having the right information can mean the difference between keeping the doors open and closing shop for good. Whether the goal is to shore up finances to keep employees on staff or to create a cushion to help weather supply chain disruptions, businesses owners need quality financial and performance data in order to make the right decisions for the company.
Once the accounting professional has real-time access to client systems, they can work cooperatively in the data to ensure that the right information is available when it is needed. As business owners seek to take advantage of grants and loan programs available due to the pandemic, the financial and other performance data becomes even more essential in terms of developing qualification and eventually forgivability of the loan.
With timely access, proper reporting tools and regular support and oversight, business owners benefit from a closer working relationship with their accounting professionals. The additional support and proactive service is more necessary now than ever. For the accounting pro, an elevated relationship with client is being developed, where the services provided become more meaningful and the value of those services more evident.
When discussing how a business operates – how folks in the company go about the business of getting work done – the conversation almost always boils down to a discussion of the problems, conditions and challenges to consistently getting the work right and on time.
No mud. No flow. We got to go. (Deepwater Horizon, 2016)
Sometimes the focus is on people and other times it is on resources or processes, but the underlying context is that there are kinks in the line which interrupt the flow. When the flow is interrupted, bad things can happen.
The flow in business is the workflow: those strung-together processes which make up the work and form the operation.
The workflow guides workers in the performance of their jobs, informing them about who is supposed to do what when, and sometimes even why.
Structured and managed workflow drives the 3 E’s in business: Efficiency, Effectiveness and Evolution.
In almost every discussion about structuring work and documenting processes and procedures, the terms “efficient” and “effective” come up. In fact, it is hard to have a conversation on these subjects without running into those terms. Most organizations recognize that worker efficiency and process effectiveness are guided and informed by structured workflows, so desk reference guides and operations manuals become the norm. What may be somewhat less obvious is the evolutionary aspect of modeling business workflows, where improvements small and large may be uncovered or identified at any level of work while it is being described and modeled. A solid workflow management system serves to remove any memory impairment in a business, memorializing not just the process but its result as part of the historic record of the business. This data assists in supporting ongoing process evolution, ensuring continued alignment with changing business conditions and goals.
Modeling the operation and applying conditional elements like timing and resource availability can make the difference between useful guidance and a semi-useful handbook of procedures.
As business conditions change so does the workflow. Unlike with printed manuals, the software system that is used to structure workflows and provide worker guidance can also supply data necessary to support change. Using a software solution to manage workflow creates an agility in the business that is necessary to make meaningful adjustments when it matters –prior to or with change, rather than far after.
This article is the 3rd in series, and focuses on how business workflows are supported and informed by the right software solution. Even more, that activity tracking and process controls should be part of the structure and foundation for worker activities, where workers perform their job functions while the systems that guide them capture meaningful information regarding those activities and transactions.
The thesis is that creating structured workflows not only informs workers what is expected of them and when, but the act of creating and updating the workflows helps identify disconnected processes, finds missing process data, smooths cross-functional transitions, and identifies missing or ineffectual policies. There are numerous conversations and interactions that wrap around or influence every activity and transaction. The goal is modeling the business and workflows in a way that not only defines worker activities but also connects those activities (transactions) to the related documents, contacts, policies and other data involved or impacted.
Whether there are a few or many individuals involved in the business, there are tasks and activities which must be performed in particular order and manner.
For a few people to efficiently and effectively manage the work, it is essential that there be clarity in what should happen and when and by whom it is to be done. It may seem that crafting workflow systems to guide these activities could be overkill, where a few people could communicate directly and let each other know what and when. Really, it only seems that way and typically only when things are going just right. Change a factor or condition or make an individual unavailable to perform the work and things can change dramatically. What was once a seemingly straightforward operation becomes mysteriously ineffective when critical players or information are no longer available.
Without structure to guide and support the entire organization, any part may fail to perform when the essential elements holding the process together are removed. The result is dis-satisfaction with the work as well as the result. In the end, it means reduced performance reflected as lower productivity, lower work quality, lower customer satisfaction levels, and lower profits. As with any legend or lore, details in the “tribal knowledge” are lost over time and what was once trusted and workable ultimately fails in the face of progress.
These truths became the focus of a conversation with Jerie Harrell of Small Business Solutions LLC (SBS) based in Huntsville, Alabama. Jerie works with Bob Crook, also known as “QB Bob,” and his team of certified consultants offering on-site and remote setup, training, instruction, and ongoing maintenance of QuickBooks financial solutions for small to mid-sized businesses. SBS prides themselves on forming long-term relationships with their clients. According to Jerie, the team “is always there after the sale; we don’t walk away after a customer buys from us”.
“I often tell clients we are like an Oreo cookie, with the accountant on one side and the client business on the other” Jerie says. ”We’re the creamy center that holds everybody together and makes things work together. The client’s business is more efficient and gets things done faster with our support, and the accountant gets better data”.
Keeping things coordinated with the consultants, supporting clients and managing ordering and other activities keeps Jerie very busy most days. Layer into those responsibilities the added requirement to plan for expansion and train new personnel and the workload gets even bigger. There is a lot of information to manage, lots of procedures to work through, and the regular work needs to be done completely, accurately and in a timely manner or the machine breaks down and customers don’t get the products or services they need when they need them. Just thinking about taking a vacation or maybe even retiring causes chills to run up and down her spine because Jerie knows she has more work to do before that could really happen. This is where the discussion about workflow and process support really started.
Jerie knows that you have to “keep things simple and keep the flow simple” in order to get everyone to participate. Her background in process analysis and improvement is really helpful to the business, because it enforces the understanding that things need to be fully documented and communicated clearly. “If you get things written down.. the processes and procedures, then the staff can be more efficient and effective. They get more work done, production goes up, sales go up, and then you can hire more people. “
Speaking of hiring new people, this is another area that Jerie knows she needs to address and is among the reasons for looking at a structured workflow system. Also, while the idea of retirement sounds increasingly attractive on some days, the challenge is that Jerie’s job has been developed over many years and there isn’t a comprehensive guide to how she does it all. She has created a way of working and a flow that meets the needs of the business, and transitioning all that knowledge is no small endeavor. “Having things structured and documented is the key. I always have procedure manuals on every desk, but that doesn’t cover everything. The workflow, time management, and the underlying processes should be visible to others because even if a key person isn’t available, business still has to go on”.
Synergy Enterprise is a business management solution from the Dutch software company Exact (www.exact.com).
Looking at CRM and workflow solutions, and specifically at the Synergy Enterprise system from Exact Software, is the next big step in solving the workflow problem and setting up the business to learn more from its activities.
“Transparency in the workflows and processes allows you to analyze them, identify bottlenecks and where improvements can be made” says Jerie.
“It’s like TQM (Total Quality Management) embedded in the CRM: you manage from the bottom up. When I look at CRM, I really see workflow. It’s everything in the business: everyone is a customer… even your boss is a customer, and the goal is to provide great customer support throughout the organization. I try to help inform management about work performance, but there are a lot of issues that are intertwined. How do you measure that without a good system?”
Summing things up, Jerie suggests that implementing Synergy in a business might be similar to using something like Google Analytics to analyze and understand website activity. She asks “why not track the activities performed in everyday business? Why did the customer not buy from you and what needs to happen to change that outcome? You need to know more!”
All three E’s are there, and I couldn’t have said it better myself.
Make Sense?
J
Series Introduction: Fringe to Foundation: Aligning Business Goals and Lifting Business Performance through Digital Workflows
Article 1: Every Business Deserves a Chance to be Better