Thursday, April 10, 2008

Fire and Motion

If you had to reduce your business strategy to three words, what would they be?

For Joel Spolsky, the co-founder of Fog Creek Software and author of blog Joel on Software, the three words would be "Fire and Motion."

"Fire and Motion" is a military phrase that refers to firing your weapon (and causing your enemy to cower), while running forward (thereby gaining territory and through your promixity to your enemy, improving your aim).

Spolsky explains how everyone from small businesses to large companies like Starbucks can use "fire and motion" to drive their businesses forward.

Spolsky's article appears in the April edition of Inc. Magazine. You can find an online copy here.

As a metaphor, "fire and motion" does a good job of conveying the relentless activity that successful businesses engage in. But I find the idea of "firing" a little vague.

Spolsky cites the example of Starbucks throwing McDonalds off their game. Starbucks educated a lot of America about what coffee could be (at least compared to the watery stuff served in most restaurants) and offered customers a superior sipping and dining experience—purple armchairs and wood paneling beat hard plastic chairs every time.

But it's hard to derive this strategic approach simply from the idea of "firing." Firing is attacking the enemy. Undoubtedly Starbucks is attacking McDonalds by marketing good coffee and giving their customers a more comfortable environment for consuming fast food. But Starbucks could have interpreted "firing" with some other strategy for attacking McDonalds: cheaper burgers, more burgers, aggressive advertising, etc. And these other approaches would not necessarily work as well as the strategy Starbucks has chosen.

To fire with maximum effect, it's important to pay attention to Spolsky's comment about successful companies setting the agenda for their markets.

If you look at a competitive market, the successful company is always the one setting the agenda and forcing competitors to match it. For example, JetBlue's version of fire and motion came in the form of a superior customer experience.

This is the key: To fire effectively, you've got to be more than busy. You've got to set the agenda.

That's where a blue ocean strategy comes in. A blue ocean strategy creates new products and services that redefine the costs and benefits of a solution, enabling a company to move from an intensively competitive "red ocean" market to a new "blue ocean" market, free from competitors.

A blue ocean strategy sets the agenda for a market:

  • JetBlue redefined the US airline market
  • Starbucks redefined the fast food market
  • Yellow Tail redefined the US wine market (it's now the top selling wine in the US)
  • Salesforce.com redefined the sales force automation market

To gain sufficient fire-power, you've got act on a blue ocean strategy. Simply keeping busy with traditional tactics (promotions, store openings, etc.) doesn't cut it.

This is why I recommend that management teams develop value curves for their products and markets, then use those curves to develop a blue ocean strategy designed to deliver dramatic growth. (Value curves are described by Kim and Mauborgne in their book Blue Ocean Strategy. I help start-ups with this type of planning.)

By comparing value curves, I can understand how Starbucks is firing at McDonalds. I can see what Starbucks is adding and subtracting from the traditional fast food experience. I can get a sense of how Starbuck's choices relate to its costs and prices. And I can better understand how Starbuck's new fast-food agenda creates trouble for McDonalds, and why McDonalds is now responding the way it is (i.e., with better coffee and more stylish decors) to align itself with the market as Starbucks has redefined it.

So, be relentless. Use "fire and motion." But to figure out how you're going to fire and what ammo you're going to load, develop a blue ocean strategy.

Sunday, March 30, 2008

Is Someone in Your Company Publishing All Your Confidential Files? How Do You Know?

I've written about IT security, in one form or another, for almost a decade now, so I've seen more than my fair share of stories about virus and worm attacks, employees stealing confidential information, malware being used to extort money from large companies, and other nefarious acts of theft and sabotage. But I have to say that a pair of articles—one by John Foley and another by Avi Baumstein—in a recent issue of InformationWeek managed to rattle even me.

The topic is data leakage caused by peer-to-peer (P2P) file-sharing applications. P2P applications enable users to share and transmit files over a vast network of computers all running the same P2P software. In some P2P networks, a node simply makes files available for other nodes to discover and download. For example, I might put a bunch of documents in a sharing folder. You might use the P2P application to search for these documents, discover them, and copy them from my system to yours.

Another model of P2P network is specially designed for handling large media files, such as software distribution packages and movies. These networks use a "swarming" protocol such as BitTorrent to disassemble very large files, transmit them as hordes of little files, and then reassemble them into a copy of the original on the other end. Because there are hundreds, thousands, or even millions of computers functioning as nodes in the network, this type of P2P network offers a convenient solution for efficiently distributing large files, such as 150 MB software packages, without putting excessive load on any one CPU or segment in the network.

Sounds clever and convenient, right? But P2P file-sharing applications can also be dangerous, because many of them allow anonymous remote users to browse and transfer a lot more content that the computer owner may realize. Here's a typical example: Joe comes home from a long day's work at a large accounting firm. He wants to download a song he heard on the radio. He uses a P2P network to find a bootleg copy of the song. He downloads the song. What he doesn't realize is that when he's installing the P2P application and clicking Next, Next, Next, to get through the installation, he's making the entire contents of his laptop accessible to the P2P network. Other users of the network can now browse his laptop and download whatever they find.

His company's firewall? Bypassed. His company's security policies? Moot. Joe is not intending to do harm (well, other than perhaps grabbing a pirated version of a song), but by using P2P software, he's effectively negating the millions of dollars of security controls his IT has developed and implemented to keep their business data confidential and in compliance with regulations such as SOX and Gramm-Leach-Bliley. He's publishing all the confidential materials he has on his laptop. Chances are, he's got quite a few.

When InformationWeek reporters investigated P2P networks to find out just how much confidential data was being accidentally leaked by P2P networks, they were shocked at what they found. Users were inadvertently publishing "spreadsheets, billing data, health records, RFPs, internal audits, product specs, and meeting notes . . . files with the home and cell phone numbers of senators, confidential meeting notes, and fund-raising plans [for a state political party] . . . spreadsheets listing patients' names along with their HIV and hepatitis status . . . [and] a slew of court documents regarding a sticky divorce."

Limewire, the most popular client of a P2P solution called Gnutella, is supposedly installed on over 18% of all computers.

Three suggestions, then:

  1. Read the full InformationWeek articles (here
    and here) and encourage your managers and employees to do the same.
  2. Forbid or tightly control the use of P2P programs such Limewire on your business computers.
  3. Have an IT engineer use one of these programs immediately to discover if your business is already exposed.

Tuesday, March 18, 2008

Tracking the Recession

The economy is all over the headlines, but if you'd like to see a lot of telltale graphs collected in one place, check out the DismalScientist's Recession Watch.

Monday, March 17, 2008

Happy St. Patrick's Day

Skip the bad jokes about beer and leprechauns today. Here's a better taste of things Irish: two and a half minutes of sheer magic as Tommy Peoples plays a strathspey called the Laird of Drumblair.

Enjoy.

Wednesday, March 12, 2008

Time for a Check-up

We're just about halfway through March, which means that Q1 is just about over. If you spent Fall 2007 or the first weeks of January putting together a strategic plan or business plan for 2008, it's time for a check-up.

A well-designed strategic plan includes measurable milestones supporting each objective. It's time to call a meeting with stake-holders and see how much progress you're making against your objectives and milestones.

Given the turmoil the financial markets are going through, it's probably also a good time to sanity-check your plans for the year. Adjustments to goals and changes of course may be in order.

And if you've made general plans that lack specific milestones and measurable objectives, it's time to sit down and define those specifics, too, so that you're able to gauge the progress you're making in each area. Judging activity against measurable outcomes is the best way to distinguish work that's truly productive from work that merely keeps everyone busy.

Sunday, March 9, 2008

Casting a Critical Eye on Expenses of All Kinds

Jason Calacanis, the CEO of a Web search start-up called Mahalo, has posted a list of recommendations of saving money when running a start-up.

What I like about the list is its thoroughness: Calacanis has really thought about where to invest (comfortable chairs so his employees will be able to work long hours comfortably) and where not to (he buys cheap tables, because all a table needs to be able to do is hold stuff). His recommendation to eschew phone lines in favor of IM, Skype, and cell phones reflects a reality I see in other Silicon Valley start-ups. The company phone list and traditional phone lines an anachronism, once everyone's on Skype. I even know one CEO who never answers his direct dial number, because the only people who call him on that line are vendors pitching him services. (How long before tradeshow vendors, printers, and PR firms realize that trolling Skype is probably going to be more productive than looking up phone numbers on Web sites? How long, after that, before executives begin guarding their privacy more closely on Skype and Twitter?)

Calacanis's recommendation to buy employees a second monitor reminded me of some research conducted by Jacob Nielsen, Sun's Web usability expert. Nielsen found:

Big monitors are the easiest way to increase white-collar productivity, and anyone who makes at least $50,000 per year ought to have at least 1600x1200 screen resolution. A flat-panel display with this resolution currently costs less than $500. So, as long as the bigger display increases productivity by at least 0.5%, you'll recover the investment in less than a year.

The examples of cost savings that Calacanis cites probably resonate most strongly with those in software companies. But managers in other industries could do well to think as critically about what employees really need in order to be productive.

Longstanding industry habits and daily routines can lead us to take too much about our work environments for granted. As a result, we might overlook simple changes we can make to increase worker productivity, minimize distractions, and perhaps even increase employee morale. (I'll bet the folks at Mahalo appreciate those monitors and iPhones.) As Calacanis's list shows, it's useful to critique everything from furniture to communication infrastructure, and put as much thought into what you're leaving out as what you're keeping in.

Friday, February 15, 2008

Beware of Vista

For the second time in about a month, my Vista machine has automatically downloaded upgrades from Microsoft that have broken Word.

I have to say, don't go near this operating system unless you really have to.

Update:

Here's a Network World Community blog posting, describing the same problem:

http://www.networkworld.com/community/node/23685

And here's a link to a Microsoft Support page telling users how to edit the registry and delete a registry key to fix the problem:

http://support.microsoft.com/default.aspx?scid=kb;EN-US;940791

Second Update:

More problems with Vista, discovered by Microsoft executives no less, are detailed in this New York Times story.