Anthony King
Thirty years in security and technology leadership, most of it spent explaining risk to people who don’t work in security — boards, owners, physicians, partners. That’s still the job.
CISSP · InfraGard · ACTRA · Manufacturing
Leadership Council
Tucson based, clients nationwide
What I actually think about this work
In December 2018 the Manufacturing Leadership Journal published a piece I wrote called “Are Companies Embracing the Cyber Challenge — or Running for Cover?” The argument was that the biggest obstacle to security in most businesses isn’t the threats. It’s the noise about the threats.
“This deluge of news — or cybersecurity-noise — has created more confusion than actual help for many businesses, and in some cases this constant wall of noise has become unhelpful to the point of paralysis, especially for small and medium-size companies.”
Anthony KingManufacturing Leadership Journal, December 2018
Eight years on, I’d change nothing except the dates in the statistics.
The point I was making then is the one I make in every engagement now: not every threat will affect your business. Risk is the product of three things — a threat, a vulnerability you actually have, and an impact that would actually hurt you. Miss any one of those and you are buying protection against something that was never going to happen to you, usually from somebody who benefits from selling it.
So the work starts by finding out what your crown jewels really are — the intellectual property, the trade secrets, the product, and the relationships with employees, suppliers and partners that the business runs on. Everything else is downstream of that.
The article closed with four words I still believe: cybersecurity is everyone’s job.
Speaking
In June 2016 I gave a keynote at the 12th Annual Manufacturing Leadership Summit in Carlsbad, California — a Frost & Sullivan event, in its twelfth year, on the future of manufacturing.
The talk was called “Are Factories of the Future Sailing into the Cyber Perfect Storm?” It covered six indicators of the coming storm, and what a manufacturing leadership team could practically do about them.
The room is the part worth knowing. The Summit’s attendees come from 3M, Boeing, Ford, General Electric, General Motors, Honeywell, IBM, John Deere, Lockheed Martin, Merck, Procter & Gamble and Xerox, among others. More than half hold vice-president rank or above, and around one in six sits in the C-suite.
I gave that keynote while serving as Chief Information Security Officer at Raytheon Missile Systems.
In 2018 I returned to the same organization to deliver a conference training session, “Cybersecurity in Manufacturing Supply Chains,” for the Manufacturing Leadership Council in partnership with the National Association of Manufacturers — this time as Associated Konsultants.
Its argument was that supply-chain security is not an IT problem or an operational-technology problem. It is a people, processes and knowledge problem, and the evidence for that is uncomfortable: of the world’s largest recorded data breaches since 2004, none was caused by a technology failure.
Credentials, and how to check them
Anything claimed here can be verified. The links go to the issuing body, not to a page on this site.
CISSP
Certified Information Systems Security Professional, issued by (ISC)². Verify on Credly (opens in a new tab)
Better Business Bureau
Accredited business, A+ rating. View the profile (opens in a new tab)
Dun & Bradstreet
Verified company profile. View the profile (opens in a new tab)
Where I stay current
InfraGard
The FBI’s partnership program with private-sector critical infrastructure. Arizona Members Alliance.
ACTRA
Arizona Cyber Threat Response Alliance.
(ISC)²
Tucson chapter — the professional body behind the CISSP.
SANS
Ongoing security training and research.
Manufacturing Leadership Council
Member. The Council is an invitation-only executive organization within the Manufacturing Leadership Community, part of Frost & Sullivan — whose Summit I keynoted in 2016 and returned to as a trainer in 2018.
CITA · Tucson Computer Society · PMI Tucson Chapter
The local technology and project management community.
Membership isn’t a credential on its own. It’s here because the question behind it is fair: how does one person stay current across this much ground? The answer is that the threat intelligence comes from InfraGard and ACTRA, the practice standards come from (ISC)² and SANS, and the industry view comes from the Manufacturing Leadership Council. None of it comes from a vendor’s roadmap presentation.
Where the thirty years went
Associated Konsultants
Founded August 1983, based in Tucson since 1993. Security and risk consulting for small and mid-size businesses across the United States.
Raytheon Missile Systems
IT Security Director and Chief Information Security Officer. Security governance, risk and compliance for one of the world’s largest defense manufacturers.
A global medical diagnostics company
Vice President and Chief Information Officer.
Aerospace
Engineering and software leadership.
Education
BS, Workforce Education and Development, Southern Illinois University. Electronics and Computer Technology, DeVry Institute of Technology.
Thirty years is only useful if it changed what you do. What it changed for me is what I look at first: I have watched enough businesses buy the wrong protection to be more interested in what a company actually has to lose than in what is currently in the news.
Who I bring in
Associated Konsultants is one person by design, with a small group of specialists I have worked alongside for between ten and twenty years.
When an engagement needs expertise I don’t personally hold, I bring in someone who does.
Matt Tank — a retired FBI agent with more than twenty years in physical security. Matt led the physical security portion of a recent client assessment, and has worked alongside Associated Konsultants for years.
A firm with staff assesses what its staff can assess. I bring in whoever the job actually requires — and if your engagement needs a specialist, they join our first video call, so nobody unfamiliar arrives at your door on the day.
Twenty minutes.
Whether or not there’s a fit, you’ll know inside twenty minutes — and if there isn’t, I’ll say so and point you somewhere better.
(520) 585-4746 · ClientServices@akonsultants.com · Tucson-based — clients nationwide