It’s that time of year again. The organization’s training and travel budgets need to get spent or else they’ll be reduced for next year. So, it’s time to hurry up and pick out conferences to attend which are scheduled in the last three months of the year.
I was lucky and got to go to two this year-one in London and one in Berlin. The one in London was also attended by lots of fellow yanks; the one in Berlin entirely by Europeans (sauf moi, bien sur). What a difference in the lunchtime conversations between the two.
For example, in London I sat at a lunch table with a group of mostly American CISOs and vendors. The conversation started innocently enough with discussions about the difference in the work environments and the approach to information security between the States and Europe. Now, at this point the conversation could have gone in a variety of different directions-discussions of cultural differences, national stereotypes, differences in laws, et cetera. Instead, the Americans at the table mostly wanted to know how existing security products could be tailored to meet European needs or how Americans might be able to ‘break into’ the European market. They wanted to know what security companies were doing well in Europe.
From there the conversation went on to a favorite American pastime which is how to get rich quick. It seemed like every American at the table (myself included) had an idea about a business or a product that everyone would want to use.
The conversation was peppered with references to famous American tycoons like Buffet, Gates and Walton. Invoking their advice and experience was treated with a reverence usually reserved for Bible readings at religious revivals. And the analogy is not too far off the mark as the entity being paid homage in this case was none other than the god of free market capitalism. The Americans at my table had kept the faith in spite of the horrible economic meltdown that was occurring daily in the global financial markets. They were the true believers.
Six weeks later I found myself in a similar situation at a different security conference in Berlin. Even though it might sound like the start of a joke, I really was at a table with 5 Europeans (a Swiss, a Brit, a Frenchman, a Belge and a German). Bratwurst and sauerkraut had replaced fish ‘n chips and mushy peas on the menu, but the nature of the conversation had a similarly abrupt change. What did you do last night? Went to the Opera. Oh really? Which one? At present we have three Operas going on here in Berlin. Mozart? Yes, he’s my favorite too. The performances at the Staatsoper are among the best in the world. What? That’s nothing compared to what we have in Vienna. Austria has the best opera, Germany the best classical concerts. No way! You’re ignoring Italy completely. That’s true. What about west end theatre in London? Oh, much better than Broadway. Really, you think? Did anyone see the documentary on BBC World last night? And so on and so on.
If the conversation wasn’t about culture it was about an abstract idea, or world politics or current events. There was no consideration about vertical markets or penetration strategies or get-rich-quick schemes. Any daydreaming was reserved for planning the next vacation which, on average; Europeans have 5-6 weeks whereas Americans have 2-3 weeks per year. Work in general and security in particular was never discussed, which I found odd, this being a security conference. It’s never been said to me explicitly, but I get the definite sense that Europeans look down on such work discussions during free time as beneath them or at the very least topics that should be reserved for the workplace and not the lunch table.
Now, I already know that after this column gets published that there will be a few humorless PC police in the reading audience who will dash off a nastygram accompanied with pearl-clutching sobs about how could I be so base as to perpetuate such stereotypes of Europeans and Americans and what does this have to do with security and (fill in the blank here with your favorite pet peeve).
To those people I say this is what I experience and I write it the way I see it.
Not only that, but this cultural difference also affects the way you manage security in Europe as opposed to in the States. In the States you’re always be called on to justify security in financial terms whether it be return on investment, dollars saved or cost avoided. That isn’t to say that you don’t have those same considerations in Europe, it’s just that they are much more muted than in the States.
In Europe my experience has been that you want to do something in security primarily because it is best practice. I find Americans to be more willing to be on the bleeding edge with trying new security products, whereas Europeans tend to be more circumspect until such time as the technology has been proven and-you guessed it-thought to become part of best practice. For example, when I came to my present organization 3 years ago, employees still didn’t have Internet availability from their desktop. It was my first action as the CISO to begin promoting this initiative. Not to belabor the point, but the primary questions from management about the project were not its cost justification but rather was the proposal following best security practices for international organizations.
I can’t think of any Star Trek episodes that focused on how Ferengis and Vulcans got along, so I can’t offer a lot of advice in this area. I do know that any European managing security in the States had better bring a calculator and any American managing security in Europe had better read up on ISO standards if they want to fit in with the culture.
Paul Raines is an American CISO working in Europe.




