Target CIO resigns amid breach investigations
startribune.com
startribune.com
Walmart has zero career paths for technical expertise. There are low-level technical positions (rarely entry-level) and they peak at "Technical Expert", and to get past that you have to switch to pure people management.
The IT division, internally called ISD, is so completely inept that the majority of the company still runs on Windows XP despite the fact that support will expire in about a month. They had a Windows 7 team at one point, but that team was dissolved and the rollout "suspended indefinitely".
ISD is so universally recognized as terrible that they were actually the only reason I had a job there. Individual departments and divisions have been forming their own "IT Teams" for years, because it's a hell of a lot cheaper to pay somebody $70,000/year to create a half a dozen new applications yearly than it is to pay ISD $2.8 million to do one of those applications poorly over the course of two years. And then completely dissolve the development team responsible and offer little to no ongoing support for the application.
Despite those exorbitant costs ISD is hemorrhaging money just trying desperately to keep the lights on, mostly because they're still running decades-old legacy applications and hardware. They only recently started drawing up plans to start sunsetting some of the hundreds of legacy systems over the course of the next decade or so.
This is really just scratching the surface of how terrible retail IT can be, and how little they value real technical expertise. Given what I've seen I wasn't so much surprised that the Target et al breach happened, only that it didn't also include Walmart or happen much sooner.
I have a good deal of confidence in Walmart Labs' technical abilities, but they do not have responsibility for the majority of the IT areas that pain the company as a whole.
Well actually the first step was scapegoating the CIO rather than those responsible for putting someone without an IT background in the position. This was the failure of institutional culture, not an individual who accepted an offered promotion to a level but not a position for which they were qualified.
Target's hiring of a consultant specializing in risk management and regulatory compliance says it all. The culture hasn't changed and Target's board still doesn't see technological expertise as a core skill.
Yes, whoever promoted Jacob to CIO should also resign.
Judging by her youthful looks, I'd say she was clearly on one of these "fast tracks" and landed in the CIO position exactly as you pointed out.
If it's "her turn to be promoted" I find that they just invent an appropriate title.
This is how big business operates. They dont care about real security of data, all they care is compliance.
Not so sure about that either:
http://arstechnica.com/uncategorized/2008/08/target-to-pay-6...
"Target has settled a class action lawsuit with the National Federation of the Blind over accessibility complaints with Target.com. Despite the law being unclear as to whether the Americans with Disabilities Act (ADA) applies to websites, the company will pay a substantial fee and update its web site to make it accessible to the blind."
This was after repeated appeals by the NFB to have them correct the site. It took a class action lawsuit for them to actually to do something. Even then Target sought to have the case dismissed:
http://en.wikipedia.org/wiki/National_Federation_of_the_Blin...
"Target moved to dismiss the case, claiming its brick and mortar stores are accessible to the blind, and that civil rights laws apply to the accessibility of its stores."
Just look at the retardation UW is teaching:
https://www.coursera.org/course/inforiskman
https://www.coursera.org/course/inforisk
https://www.coursera.org/course/infosec
Those "people", they call themselves teachers/professionals in the field, will tell you that Information Security is ALL about covering your ass and shifting blame to a third party. All three courses are about getting a slip of paper that says you delegated responsibility clearing your company from any lawful obligations in case of a breach. Not a single peep about technical aspects or real security of data/infrastructure. Its all about getting that "we paid company X to do it for us" waiver.
There was (deleted now) a huge thread on Coursera forum titled Disappointment covering this topic and demonstrating total lack of professionalism or any real world knowledge. Whole UW program is a government funds skimming scheme. Just look at this garbage:
"Center of Information Assurance and Cybersecurity at the University of Washington, designated by the NSA/DHS as a Center for Academic Excellence in Information Assurance Education and Research"
I highly encourage you to check out those courses (I think there is preview available for old lectures) if you are in need of a laugh, or reality check concerning state of CIO education.
http://www.theawl.com/2010/08/real-america-the-ceo-of-target...
Not so much affinity, as ideology?
Actually, no. That is one of the biggest problems with properly functioning IT systems, they become invisible - nobody notices until something screws up...
CISO sort of exists to get thrown under the bus, but in a regulated industry, has a huge compliance role.
The whole point of policy is to resource the whole thing adequately so individual mistakes get prevented, or caught and corrected, before they turn into a Target-scale problem. But that usually requires doing more than just bare compliance minimums, and is only possible with board level support for that kind of thing. Probably exists at Target now. Probably didn't before.