I recently attended the most interesting cyber-related event in several years. What made this so interesting was the fact that all three major stakeholder groups were represented, not equally mind you, but they were all there. The three stakeholder groups were academia, business/commercial, and government/defense/intelligence. During the event, all three stakeholder groups had the opportunity to express their views and opinions and that is what made this event so different.
As each stakeholder group presented, questions were posed to the speakers as is typical at nearly every conference. During the breaks, I was able to listen to the individual interactions between the stakeholder groups. Those side interactions created the opportunity for a fairly private, but substantially open dialogue. After listening to this, iIt became evident that each stakeholder group differed to a fair degree with the other two. It was also clear that the other two stakeholder groups had difficulty understanding how the other group or groups could have the wrong view/opinion. Watching this and thinking about this, Then I had the ah-ha moment.
It appeared the view/opinion of each stakeholder group was shaped to a great extent by the way that particular stakeholder group was measured and how they themselves defined and measured success. I decided to test this and crafted an interaction with those presenting with a multifaceted statement. The statement had two parts. One part was supported of the presenter’s position and suggested an extension to that research. The second part was crafted based on a different stakeholder’s view based on their measure and definition of success. Each time I did this, the presenter acknowledged the supportive portion of my statement and objected to the portion that was aligned with the other stakeholder.
A respect for the opinions of the other two stakeholder groups was minimal at best. Stepping back, one would estimate that 10 percent (or less) commonality existed between the views of these three groups. Each group is being measured and work to enhance that measure. Those measures are substantially different between these groups. That has to be addressed if a substantive improvement in national cybersecurity is to achieved in the short or near term.




