Welcome to Your Operations Solved, for Tuesday, April 6th, 2021
I'm your host, Channing Norton, of PC Solutions, and this is the Seventh episode of our show,
Listen to us Tuesday, Wednesday, Thursday, or on our Saturday compilations. If you find the show helpful or informative, please do give it a like on your platform of choice, or share it to someone else who might also like it.
First, an update to Thursdays story on the Ubiqiti data breach. Ubiqiti has made a statement in regards to the whistleblower's allegations, reaffirming that they have no evidence that customer data was accessed. The whistleblower has ALSO responded to Ubiqiti, by asserting that to be accurate, but not in a good way. Namely, the whistleblower has now expanded to say that Ubiqiti has no such evidence because they do not keep logs of customer data access. This is equivalent to an airline saying that they have no record of any safety incidents on their planes, and that being true, not because there are none, but because they don't keep such information to know, and just like the airline, this is neither reassuring, nor a good thing by any stretch of the imagination. While an effective way to ensure you can make public statements of "no evidence that data has been accessed," this is a HUGE security issue on Ubiqiti's end, in addition to being simply deceptive in communicating to their customers. I'd say this moves Ubiqiti solidly into the list of vendors to never do business with, if they weren't there already.
With that, let's get onto the headline for the day.
A massive facebook data breach could be used to compromise security at your business.
So, over the weekend, a database of information belonging to facebooks users was leaked. This information has actually been for sale on the darkweb for a few months now, but someone leaked all of it to whoever wants to downloaded. This includes data on over 500 million global users, and is up to date as of 2019. Compromised were mostly profile information, real name, and Cell phone number pairings, but a few hundred million email addresses were also compromised. This information can be crossreferenced with someone's live profile to build a pretty thorough personal profile to target Phishing, that already has up to date contact information, which you wouldn't get by just viewing facebook without this data. The end result is that this is being used to build attacks against businesses using social engineering. Effectively, people are getting emails with the name of their boss in the "From" line, asking them to please send over this years W2's ASAP. Or the information is being used to guess passwords. Or in a million and five other ways to move money from your business to an attacker
While obviously such phishing attacks have always been a risk, but now they can be made even more convincing. The sheer size of the dataset also potentially allows "lateral motion" in other attacks, where an attacker compromises one element of a system and uses that access to gain further access. For instance someone could hijack a phone number, and, knowing that it's used for 2 factor authentication for the owners facebook account thanks to this breach, use that access to gain access to their facebook, and impersonate them on that platform to achieve their goals, such as spreading a bad link around.
For your business, it means that you need to be making sure that your employees know how to identify these scams, which can be achieved with a Phishing Simulation, where you run a fake attack, and see who falls for it. Now is also a good time to be looking at upping your spam protection to ensure that less of this gets through. If you don't secure yourself, you're running the risk of being victim to one of these attacks, which can put companies out of business. I'm not trying to scaremonger here, but small businesses are victims to these attacks hundreds of times every day, and it never spells good things for the victims, so protecting yourself is worth the low cost to do so.
Today on the show, for the solution, I'd like to talk about the implementation of SOPs, or Standard Operating Proceedures, and how they can help you deliver more consistent products and services to your customers, with less rework, while making it easier to train new people and grow your business. For starters, who benefits the most from SOPs? Largely speaking, you'll want to implement sops in organizations as early as it makes sense to do so, after the initial sales crunch, when what you are selling and how you deliver that product is largely set. This is because when you change these elements of your business, the SOP has to change too.
So, what is a SOP?
A SOP is a documented proceedure that clearly and unambigiously explains how to perform a task in your business. This way, by following a SOP, an employee can ensure that they perform said task to the same standard that their supervisors would want them to. It alleviates mental load on your employees, and inconsistency in the quality of work performed by employees by making the tasks more repeatable. It can take the form of a Wiki article, checklist, set of rules, or whatever other format makes sense, with the end goal being that, with a well written SOP, anyone can perform the tasks listed, with little variation in end result. As a practical exercise to get the hang of things, try writing a SOP for making a sandwich of choice after the show today. Determine the order and amount of ingredients, if the sandwich should be toasted, and, if so, for how long, is it sliced? What way? Do you trim the crust? Make that sandwich using the SOP, then hand the proceedure to someone else, and see if they can make an identical sandwich, without looking at the sandwich you made. Now compare the result to asking a third person to make a sandwich of that type without any further instruction. In addition to showing how a good SOP can make your product more consistent to your customers, I've also just handled your next meal for you. You can thank me later.
As hinted at above, a good SOP is like a recipe, it should be complete and unambigious. There should be no questions after reading a SOP by someone with the basic initial knowledge in the relevant field in how to perform the task. For instance, provided you know what "Chop" and "Dice" and "Fry" and "Boil" mean, you shouldn't have any issues following just about any recipe in a cookbook. For those field specific knowledge pieces like "Boil," you'd then want to consider if writing a SOP to describe their processes is necessary. For instance, writing a SOP on how to turn a computer on is likely not helpful, but writing a SOP on how to add a new item to your inventory software would likely be necessary if your inventory changes with any significant frequency.
So, we are beginning to see the value of SOPs we can start talking about implementation in your business. I'd schedule out some time to start thinking about "How can I document X job." Task yourself with writing One SOP a day, and revising one a week. These should be living documents that update as your business changes, and are continually improved. For instance, think of how you would describe handling your Sales process to a new employee, from start to finish. Then describe your fulfillment process. Look at each step of these processes, each one is themselves a process, or perhaps several. Each one of these need a SOP. You can do this for each department, and each employee role, until you have a library of SOPs. In doing so, you have done several things,
With all that said, SOPs are a big topic, and one we will cover more tomorrow, specifically, join us on the show for a discussion of how to distribute them, so that they don't just end up forgotten in a binder somewhere.
If this show was helpful, entertaining and informative for you, please do give us a like, and share it to someone else who you think might like it, that's our show for today, join us tomorrow!