We knew this day would come, but we held onto the hope that there would be more time. John Michael "Ozzy" Osbourne—our beloved Prince of Darkness—has taken his final bow, his last encore echoing into eternity. He leaves this world not in shadow, but in light, embarking on his next great journey beyond this life.
My journey as a technology executive living in Silicon Valley and working in IT for 35 years.
Tuesday, July 22, 2025
Today, the world feels a little quieter, a little dimmer.
Tuesday, June 10, 2025
Missing My Friend.
I don’t have many words right now, but I wanted to share with my community that a dear friend, Gayle Noble, has taken her final step beyond this life and - if you believe as I do - begun her next journey among the stars.
Saturday, March 8, 2025
Happy International Women's Day
Let's be honest—this shouldn’t be a one-day celebration. Just as Pride and Black History shouldn’t be confined to a single month, recognizing and uplifting women should be part of our everyday mindset.
Friday, July 8, 2022
IT Recognition & Leadership
A post showed up in my LinkedIn feed recently that stopped me in my tracks. It got me thinking about the health and well-being of IT teams, and more specifically, the people I lead.
I have spent 30 years in IT here in Silicon Valley. In that time, one thing has remained stubbornly consistent: IT teams are taken for granted. We are the glue holding complex processes together, and most of the time, nobody notices until something breaks.
I rose through the ranks the hard way. Front-line support, increasing responsibility, and eventually leading the very teams I once was a part of. That experience gave me something invaluable: a deep appreciation for what these people go through every single day.
Here is what I believe without reservation. The head of any IT department has one non-negotiable responsibility above all others: protect your people. That means managing their workload, shielding them from unnecessary chaos, and creating conditions where they can actually do their best work without burning out.
At my previous company, where I spent 13 years and built what I genuinely consider a world-class support organization, the executives largely took IT for granted. The old saying, "if it is working, we are doing our jobs," sounds harmless enough, but it erases all the effort, planning, and late nights that make continuity of service possible. Recognition rarely came from within.
The moment that sticks with me most happened at a sales kickoff meeting around 2014. A guest speaker from VMware stood in front of 150 people and asked one simple question: Have you thanked your IT team today? It took someone from outside the company to start a conversation that should have been happening all along. The SVP of Sales asked me to stand and be recognized. It felt good, but it also felt like it should not have required a guest speaker to make it happen.
Recognizing people for good work should not need a catalyst. It should be instinctive.
But this is not really about IT getting a moment in the spotlight. It is about something bigger. Every experience I have had, every leader who invested in me, every difficult situation I navigated, helped shape the way I lead today. I did not get into technology for applause. I got into it because I genuinely love what it makes possible for people.
Burnout is real. It is quiet, it is cumulative, and by the time you see it, you are often too late. Flexibility and empathy are not soft skills. They are the foundation of a functional, sustainable team. Nobody on my team should ever feel overlooked or worn down without someone in their corner.
That is the standard I hold myself to. Every day.
Monday, March 21, 2022
Real Leadership comes from Empathy
Here's the rewrite:
Real Leadership Comes from Empathy
I came across an article in INC. magazine today that I could not stop thinking about. It focused on a CEO who summed up his company's remote work decision in ten words. Those ten words say everything about what emotionally intelligent leadership looks like in practice.
Dan Price, CEO of Gravity Payments, surveyed his employees about where they wanted to work. The results came back: 7% wanted to be in the office full time, 31% preferred a hybrid arrangement, and 62% wanted to work fully from home. His response? "Sounds great. Do whatever you want. If you get your work done, that's all that matters."
That is it. No committee. No policy debate. No performative flexibility theater. Just a leader who listened and got out of the way.
This is consistent with who Dan Price has always been. In 2015, he restructured his entire company's compensation model and set a minimum salary of $70,000 for every employee. He ran the numbers, believed in his people, and made the call. It was not about optics. It was about genuinely understanding what his staff needed to live well and do good work.
COVID changed the rules for everyone, whether companies were ready or not. The organizations that responded with empathy and adaptability kept their people. Those that clung to rigid, outdated expectations found themselves on the wrong end of the Great Resignation, watching talented employees walk out the door in search of workplaces that actually respected their lives outside of work.
So what is emotional intelligence, and why does it matter so much right now?
The dictionary defines it as the capacity to be aware of, control, and express one's emotions, and to handle interpersonal relationships with good judgment and empathy. That definition sounds clinical, but the reality is deeply personal.
Think about what the past few years looked like for most families. College students and high schoolers doing classwork from their bedrooms. Parents managing their kids' education while keeping up with their own jobs. Households with four or five people all competing for bandwidth at the same time. My own family was no exception. My wife and I were grocery shopping for her parents and dropping food at their garage, kept at a distance while they disinfected everything we touched. That was our routine for months.
Now multiply that by every single person on your team. Each of them was carrying their own version of that story. As a leader, you are not just managing deliverables. You are managing people who are managing entire lives at the same time. That reality has to be part of how you lead.
Will Rogers once said he never met a man he did not like. When his life was adapted into a Broadway musical in 1991, his character described a practice rooted in his Native American heritage: walking around to the other side of a person to see what they were seeing. To understand what drives someone, what worries them, what they are working toward. That is empathy in its most practical form, and it is how I try to approach every conversation with my team.
When I work with someone, I always come back to three questions:
- What has their experience been?
- What motivates them?
- How can I help them reach their personal and professional goals?
A leader who asks those questions, and actually listens to the answers, builds something different than a leader who just manages tasks.
The INC. article also included a list of leadership practices worth keeping visible:
Show genuine personal interest in your people. Communicate expectations clearly and early. Set reasonable norms around response times for messages and email. Check in regularly, not to monitor, but to support. Coach rather than micromanage. Give people room to take smart risks and explore ideas. Treat mistakes as learning, not failure. Recognize good work loudly and often. When things go sideways, give feedback that helps rather than harms.
I would add one more. Invest in your people's future, not just their current role. The best thing you can do for your team is make sure they are growing, that they have the skills to do their jobs not just today but in the environment that is coming. Workplaces are changing fast. A good leader makes sure their people are ready for what is next.
High emotional intelligence, paired with strong communication and a genuine commitment to your team's growth, is what separates managers from leaders. It is also what keeps good people from leaving.
What is your EQ?
Saturday, December 25, 2021
Company Respect and ME: Black Helmet Apparel
Update: Black Helmet Apparel has since gone out of business. I will leave it at that.
Update 2: Black Helmet is back (2025) and they seem to be back to basics
Wednesday, July 28, 2021
Women and Technology: A Lesson from Blizzard's Failure
Here's #4:
Women and Technology: A Lesson from Blizzard's Failure
I am sad and angry about what continues to come out of the Blizzard/Activision campus. The reports describe years of extreme toxicity, sexual harassment, and outright assault, all protected and perpetuated by a culture that should never have been allowed to take root in the first place.
Let me say that plainly, because it deserves to be said without softening: this was not a rough workplace. This was a sustained, predatory environment that destroyed careers and harmed real people.
I have been a Blizzard supporter since Warcraft 2. I subscribed to World of Warcraft from its launch, with only a brief break in 2005. I attended BlizzCon four times in person and several more times virtually. At one point, working there was genuinely my dream job. I believed in what they built.
Blizzard was at the top of the gaming world for a long time. Then the wheels started coming off. The Activision merger in 2008 began a slow cultural shift. Chris Metzen's departure in 2016 was followed by a broader leadership exodus in 2018. What came after was not a surprise to the people inside, even if it shocked those of us watching from outside.
The California Department of Fair Employment and Housing described the workplace culture as a "pervasive frat boy" environment. That phrase is almost too mild for what the reports actually describe.
Here is what troubles me most beyond the harm done to the victims: the technology industry already struggles deeply to attract and retain women. The pipeline problem is real, the systemic barriers are real, and stories like this make every bit of progress harder to achieve. When news breaks that one of the most celebrated companies in tech fostered this kind of environment for years, why would any woman look at this industry and think she would be safe, valued, or respected?
I have seen what a genuinely inclusive team looks like. At one point in my career, my IT department was split evenly between men and women. It was one of the best teams I have ever led. Not despite that balance, but in part because of it. Different perspectives, different problem-solving approaches, and a culture where everyone felt they belonged made us better at everything we did.
The best manager I ever had was a woman. She gave me an opportunity I might not have gotten elsewhere, genuinely invested in who I was becoming, and mentored me for four years. I would not be the leader I am today without her influence.
I was bullied in high school. I have been treated poorly at jobs. Those experiences did not harden me into someone who passes that treatment along. They made me determined to make sure nobody on my team ever has to feel that way. Every person, regardless of their background, identity, or sex, deserves every opportunity to succeed and a workplace where they feel genuinely safe.
Toxic culture does not survive because of one bad actor. It survives because people around it stay quiet. That ends when leaders decide it ends.
I cancelled my 16-year World of Warcraft subscription until Blizzard addresses the lawsuit and makes real, meaningful changes. Not symbolic ones. Real ones.
We can do better. We have to.
Friday, December 18, 2020
Lessons from the Solarwinds Orion Cyber Attack
On December 13, 2020, SolarWinds CEO Kevin B. Thompson notified customers of a highly sophisticated supply-chain attack affecting Orion Platform software builds from versions 2019.4 through 2020.2.1.
The details were still emerging, but the attack appeared to involve malicious code inserted into software updates distributed to SolarWinds customers. Approximately 18,000 organizations may have installed the affected versions. The incident came to light shortly after cybersecurity firm FireEye disclosed that it had experienced a breach involving the theft of internal security tools.
This was a sobering moment for the cybersecurity community. The scope of the compromise extended beyond private companies, potentially affecting Fortune 500 organizations and government agencies, including entities responsible for national cybersecurity.
Why this attack matters
Most security conversations focus on attacks that come from outside an organization - such as denial-of-service attacks or penetration attempts - or attacks that exploit people and systems from within, such as phishing, ransomware, or malware.
The SolarWinds incident exposed a different and especially concerning risk: the compromise of a trusted software-development and delivery process. By inserting malicious code into legitimate software updates, attackers were able to take advantage of the trust customers placed in a widely used vendor.
The incident underscores an important reality: every organization may have vulnerabilities within its software development lifecycle. Even well-established processes can be compromised if appropriate safeguards, reviews, and monitoring are not in place.
For years, organizations have invested heavily in perimeter protection, intrusion detection and prevention, endpoint security, and network monitoring. Those controls remain essential. But this attack demonstrated that the software development process itself must also be treated as a critical security boundary.
The long-term impact will likely include stronger tools, more rigorous standards, and updated regulations designed to improve software supply-chain security.
What can be done?
Improve communication and information sharing
Effective response depends on timely, useful communication among companies, government agencies, and security professionals. Privacy and data-protection laws remain important, but organizations also need practical ways to share threat intelligence quickly and responsibly.
In a cybersecurity incident, early access to relevant information can help organizations contain an attack before it spreads. Coordination across agencies and industries is especially important when responding to threats with broad public and economic consequences.
Strengthen quality control and code review
Although the full technical details were still under investigation, the incident made clear that malicious code had entered the SolarWinds software delivery process. That should prompt every organization to review how code is developed, approved, tested, built, and released.
Agile development and automation can improve speed and consistency, but they do not eliminate the need for strong controls. Organizations should consider:
- Independent code reviews and approval processes
- Automated integrity checks between releases
- Monitoring for unexpected code changes or behaviors
- Secure, isolated test environments
- Comprehensive audit logs for development and release activities
- Regular reviews of third-party and open-source dependencies
Automation can help identify meaningful differences between code versions and flag suspicious changes for human review. It should support - not replace - clear accountability and sound engineering judgment.
Act now
Organizations should assess their current exposure and avoid assuming that any process is inherently secure. Review systems across the business, from software development and vendor management to finance and operational workflows.
A mature cybersecurity program may identify risks before they become incidents, but no single team or tool can protect everything. Security must be a shared responsibility across IT, engineering, leadership, legal, operations, and other business functions.
Breaking down departmental silos and examining the software development lifecycle honestly - even its weaknesses - is essential. Technology and standards will continue to improve, but organizations also need disciplined processes, open communication, and collective accountability to reduce the likelihood and impact of future attacks.
Sunday, September 27, 2020
COVID and the Great Re-Negotiation Strategy
The Great Three Four?
There are moments in life that change us. They give us a new perspective and divide life into a clear before and after. I have lived through several of those moments, and I think of them as “The Great Three.”
The first was getting married. My spouse and I went on our first date in 1991, and my life has never been the same. She is my best friend, my biggest supporter, and a constant source of joy. Sharing life with her has been good for my soul.
The second was becoming a parent. I used to think of it as the birth of my first child, but each of my three children has changed my life in a different and important way. The line between life before children and life after children is unmistakable. I understood that parents love their children, but I did not fully understand the depth of that bond until my son was born.
The third was losing a parent. I lost my father 16 years ago this December. Not a day goes by that I do not think about him in some way. Losing a parent is painful, but it is also one of those moments that changes how you see life. I am grateful that I still have my mother and my in laws.
What about COVID-19?
So what does this have to do with COVID-19?
Until 2020, I had never seriously considered how much a global pandemic could change everyday life. I now think “The Great Three” has become “The Great Four.” COVID-19 changed all of us, and many things will never return to the way they were.
As an IT executive, I have planned for disasters of all kinds: fires, floods, storms, hurricanes, tornadoes, and earthquakes. A pandemic was always possible in theory, but it felt distant and hard to picture. We had historical examples, including the 1918 flu pandemic, and more recent events such as H1N1. But none of those prepared most of us for the scale of disruption COVID-19 brought.
Businesses had to adapt quickly. Employees began working from home. Schools moved online. Healthcare changed. Companies had to find new ways to serve customers and keep operating. At the same time, many families faced illness, loss, and uncertainty.
The human cost has been heartbreaking.
The need for more empathy in business
The pandemic also made me look differently at the contracts we have with vendors and suppliers.
For much of 2020, I was responsible for corporate facilities in addition to my regular IT leadership role. Before work from home and shelter in place orders, our company operated five main locations along with several smaller offices around the world.
Once offices closed, we were still paying for buildings we could not use. Like many companies, we asked landlords for some relief. They had their own bills and mortgage obligations, of course, but many were unwilling to discuss meaningful options. The response often came down to contract language, late fees, collections, or delayed payments that would eventually still be due.
That experience made one thing clear to me: business contracts often leave little room for empathy when circumstances change dramatically.
The pandemic clause
Over the years, I have reviewed many contracts. Most include language for disasters or acts of God, but few clearly address what happens during a pandemic that prevents a business from using the space, equipment, or services it is paying for.
That needs to change.
Future contracts, especially longer-term leases and equipment agreements, should include clear provisions for a pandemic or government mandated closure. These clauses could define what happens if a business is required to close or cannot use what it is paying for.
For example, a lease could provide temporary rent relief if a shelter in place order prevents employees from occupying the space. An equipment contract could reduce payments if copiers, printers, or other office equipment cannot be used because no one is allowed in the office.
This is not about avoiding obligations because a company chooses to work from home. It is about fairness when a business is required to close through no fault of its own.
A landlord should not be expected to carry the entire burden, and neither should a tenant. The point is to agree in advance on a reasonable way to share the impact of an extraordinary event.
Hindsight is always clear. Still, COVID-19 has taught us to plan for risks that once felt unlikely. Hopefully, we will not see another pandemic of this scale for many years. But if we do, better contracts and more thoughtful business relationships can help everyone weather it with a little more fairness and empathy.
Friday, June 19, 2020
The Human Side of Technology - People Come First
People Come Before the Job
We are living through strange and difficult times. Our county has been under a shelter in place order for months. Some restrictions are beginning to ease, and we have been fortunate that our local healthcare system has been able to manage the case numbers so far.
Still, there is another cost that is becoming harder to ignore. It is not just about the health of our networks, systems, or businesses. It is about the health of the people doing the work, including their mental health and overall well-being.
A lesson I learned early
From 1999 to 2002, I worked for a technology startup called eHealthInsurance. At the time, it was everything I wanted in a job: a fresh approach to health insurance, an energetic leadership team, and a company that seemed excited to have me. I was young, motivated, and eager to contribute.
In 2001, my wife and I were expecting a baby. I spoke with my manager about transferring from the Bay Area to the Sacramento area, where we planned to raise our family. The move was approved.
We sold our home in San Jose, moved in with my in laws temporarily, and bought a home in Roseville. The plan was for me to stay in San Jose until our daughter was born in 2002.
Then life changed quickly.
The September 11 attacks happened. As a former firefighter and EMT, I felt the loss deeply. Soon after, the dot com bubble burst and the economy entered a downturn.
Early in 2002, the vice president of engineering learned about my move and revoked the approval for my transfer. This happened only two months before my daughter was due. We had already sold our house, were living with my in-laws, and were preparing to move into our new home.
It was a shock. We had made major decisions based on an agreement that was suddenly gone.
The meeting that changed my view of leadership
I spent the next several weeks trying to keep the conversation open and find a solution. The company already had a telecommuting policy for employees who lived more than 50 miles from the office. I hoped that some flexibility would be possible.
At our final meeting, I was told that my position would not transfer to Folsom. I would be required to work in Sunnyvale five days a week. Even if I moved to the Roseville area, roughly 120 miles away, I would not be allowed to work from home or from the Folsom office.
I was disappointed, but I also knew the decision had been made. After months of trying to do the right thing and communicate openly, I resigned.
That experience stayed with me.
My point is not to dwell on an old job. It is to highlight a lesson about management. As leaders, we have a responsibility to care about our employees as people, not simply as resources.
That leader saw the situation only as a business problem. There was no room for my family, the difficult economy, the baby we were expecting, or the fact that my manager had approved the move months earlier.
Understanding what people need now
Today, I am a vice president of IT. I manage people, carry responsibilities, and report to leaders above me. But none of that removes my responsibility to lead with compassion and empathy.
Recently, an employee came to me to talk about how the pandemic had affected their mental well-being. They were feeling isolated and struggling with the uncertainty of life during COVID-19.
I listened. I told them they were not alone.
Many of us have felt the strain. The boundaries between work and home have blurred. Workdays stretch into long hours while families share the same space all day. It can feel like we are caught somewhere between a permanent vacation and a constant workday.
Some days, it is hard to find motivation. Some days, it is hard to focus. That does not mean people are failing. It means they are human.
The specifics of what the employee needed were less important than making space for the conversation. They needed to be heard, and I needed to respond with understanding and flexibility.
Their health and well-being mattered more than the immediate task in front of them.
The kind of leader I want to be
After that conversation, I realized something important. I had become the leader I needed when I was in that difficult situation in 2002.
Over my career in IT, I have tried to learn from the best managers I have worked for. I have also learned from the ones who showed me what not to do. My goal has always been to combine those lessons with my passion for technology and become the best leader I can be.
This experience reminded me that leadership is not just about projects, budgets, systems, or results. It is about people.
COVID-19, shelter in place orders, social unrest, and economic uncertainty have taken a real toll on many people. Work life and personal life have blended together in ways few of us expected. Focus can become difficult. Isolation can become overwhelming.
As managers and supervisors, we need to make room for compassion. We need to listen. We need to remember that every employee has a life outside of work, with challenges we may not always see.
Business matters. Results matter. But the people doing the work matter more.
That is how I want to lead, every day.
Monday, April 20, 2020
Supply Chain and Infrastructure Limits
It often starts with congestion: a cough, a blockage, or a restriction in a pathway we depend on to function. I am not talking about COVID-19 in the human body. I am talking about the effect the pandemic had on the systems that keep our communities and businesses running.
In many ways, the same idea applied. As demand increased and normal patterns changed, supply chains and network infrastructure became congested. Things we had always assumed would be available suddenly were not.
The early warning signs
In January 2020, the CDC issued a travel alert related to Wuhan, China. At that point, the United States had only a small number of known cases. By the end of January, the U.S. government had begun issuing travel restrictions related to China.
In February, I moved my home internet service from Comcast Business to Xfinity Residential. At the time, it seemed like a practical decision. The service offered more bandwidth at a lower cost, and it worked well for my family.
Then, in early March, as head of IT and the Facilities, I needed to purchase hand sanitizer and disinfecting wipes for the office - to replenish our stock. I searched through Amazon and other suppliers, only to find that delivery dates were more than 30 days away. Soon, sanitizer, wipes, and toilet paper became difficult to find almost everywhere.
These were ordinary items we had always taken for granted. We still had some supplies, but not in the quantities we wanted. For me, that was the first real warning sign that the supply chain was under strain. It was the first time in many years that a common item had simply disappeared from online retailers and local stores.
A sudden shift to working from home
By mid March, an incident at our San Jose office required us to begin working from home before the Bay Area issued its shelter in place order. Soon after, California followed with statewide restrictions.
My children were also sent home from school. Two attended Leland High School, and one attended De Anza College. Beginning March 16, 2020, they joined millions of other students across the Bay Area in trying to learn and connect from home.
At the same time, Silicon Valley and much of the region moved to remote work. We did not immediately realize how much pressure this would place on our network infrastructure.
Millions of people were suddenly working from home, attending online classes, streaming video, and trying to stay connected. Children who could no longer see friends in person turned to Netflix, YouTube, Hulu, gaming, and social media. Adults relied on Zoom, GoToMeeting, Webex, and other platforms to keep their jobs moving.
All of it created a massive and unplanned stress test for the internet.
When home internet became a business problem
My move to residential internet had seemed like a good decision in February. But once nearly every household in the area was relying on home connections throughout the day, the service became slow and unreliable.
I had to rethink the setup quickly.
I brought Xfinity Business back into the house because I could no longer depend on a connection that slowed down during the middle of the workday. The contract was not perfect, but it gave me a dedicated 100 Mbps connection, an LTE backup modem, and battery backup for about $120 per month during the first year. The installation and configuration took about two weeks.
In the meantime, my wife and I relied on mobile hotspots to keep working. Sometimes they worked well. Other times, they did not.
The experience made it clear how dependent we had become on systems that were never designed for everyone to rely on them at once.
The growth and growing pains of video meetings
As people adjusted to working and learning from home, platforms such as Zoom became essential. They gave families, schools, and businesses a way to stay connected when in person meetings were not possible.
But the rapid growth also exposed weaknesses. Zoom had been designed for ease of use, and some meetings lacked basic security settings. This made it easier for disruptive people to enter public meetings, sometimes sharing offensive sounds or graphic images.
The platform improved over time, adding stronger security options and better guidance for meeting hosts. Still, the early days were a reminder that rapid growth can reveal gaps in security, capacity, and planning.
Planning for the next disruption
Things are more stable now. Zoom is more secure, and my home internet is generally reliable, even though outages still happen from time to time.
The larger lesson is that we need to look more closely at the capacity of the systems we depend on. Businesses, service providers, schools, and governments all have a responsibility to consider what happens when demand reaches unexpected levels.
Few people imagined that tens of millions of students would need to learn online at the same time, often through video calls. Few expected entire workforces to depend on home internet connections overnight. Yet that is exactly what happened.
One positive outcome of 2020 was that it forced us to rethink what is acceptable and what we need to build for the future. We may not know exactly when a crisis will end, but we can prepare better for what comes next.
That means protecting our supply chains, strengthening our infrastructure, and planning for capacity before we need it.
Wednesday, April 8, 2020
Cloud Strategies and Authentication Methodologies
Making the Cloud Work for IT
Like most forward thinking IT teams, we are always looking for better ways to connect people with the data, tools, and services they need.
“Do more with less” is a phrase no IT leader loves to hear, but it is a reality in many organizations. After more than 25 years working in startups, I have learned that efficiency is not simply about reducing headcount or spending less. It is about using automation to handle repetitive work while protecting the reliability, security, and integrity of the systems the business depends on.
Moving toward the cloud
Many organizations have adopted cloud services for systems that once had to be managed on site. Ten years ago, I was hesitant about that idea.
Why hand over control of a system to someone else? Hosting a service internally meant control over the hardware, software, configuration, management, and customization. Giving that up felt risky.
My first real experience with cloud services was hosted Exchange, before Office 365 became widely available. As a systems administrator, the idea of no longer managing an email platform myself was uncomfortable at first. I worried that my skills would become less relevant.
Instead, it gave me room to focus on more important work.
Exchange is a complex system to operate well. By using a hosted service, I no longer had to spend as much time on day to day maintenance, disaster recovery planning, and troubleshooting every technical issue. When a problem occurred, the provider became the first level of support.
That freed me and my team to focus more on the company’s needs, rather than spending all of our time maintaining the underlying tools.
The value of cloud services
Today, cloud strategy is common across many organizations. Cloud services can take critical systems that might otherwise require several administrators and make them easier to manage at scale.
For example, our Exchange environment supports roughly 375 active email accounts and uses more than 3.3 TB of storage. It serves a global community of sales, services, and support employees, with availability close to 99.99 percent.
Running that same environment on site would require substantial hardware, dedicated storage, replication to a secondary location, backup and recovery systems, and likely one or more full time administrators.
Cloud services do not eliminate responsibility, but they can reduce the operational burden and allow IT teams to focus their time where it matters most.
Too many passwords
The move to cloud services also creates a challenge. Each platform often comes with its own login, password, and user management process.
As companies adopt more applications, this quickly becomes difficult for employees and IT teams alike. People have more passwords to remember. New hires need accounts in multiple systems. When someone leaves, IT needs to make sure access is removed everywhere.
Single sign on platforms such as Okta and OneLogin help solve this problem. They allow companies to use one identity system across multiple services, including Atlassian, Microsoft 365, Salesforce, NetSuite, Dynamics 365, and many others.
At Virtana, we use Okta to support authentication, multi factor authentication, and automated user provisioning and deprovisioning. This reduces the likelihood of manual errors and makes it easier to manage access consistently.
We have deployed this approach across more than 20 services used by the company. When we evaluate a new platform, such as SurveyMonkey or Monday.com, one of our first questions is whether it supports SAML and can integrate with our single sign on environment.
The goal is simple: make access easier for employees while keeping company systems secure.
Monitoring the cloud
As cloud environments grow, visibility becomes just as important as access management.
Virtana’s acquisition of Metricly added cloud monitoring capabilities for services such as AWS. The platform became part of our broader CloudWisdom offering and helps organizations understand how their cloud infrastructure is performing.
One of the most valuable capabilities is cost optimization. It is one thing to know that AWS cost $50,000 in a given month. It is much more useful to understand what drove that cost and where changes could reduce spending without affecting performance.
Those savings can be reinvested in innovation, infrastructure, or people.
Cloud services are not a replacement for thoughtful IT leadership. They are a way to spend less time maintaining routine systems and more time helping the business move forward.
Monday, February 4, 2019
Nest and Your Peace of Mind
Here's #10:
Nest and Your Peace of Mind
Nest has been taking a lot of heat lately over reports of their camera systems being hacked. Before we accept that framing at face value, it is worth understanding what actually happened and where the real problem lies.
Here are the facts. Yes, unauthorized people gained access to accounts belonging to two families, and the results were frightening. One family received a false nuclear alert through their home system. Another had a stranger speaking through the camera in their child's room. Nobody should ever experience either of those things. As a parent, the thought of hearing an unknown voice coming from my child's bedroom triggers every protective instinct I have.
But here is the part that tends to get lost in the headlines: Nest was not breached. The accounts were compromised because the owners were reusing passwords that had already been exposed in breaches at other websites. The attackers did not break into Nest. They walked in through a door the users had left unlocked, using credentials that were already floating around on the dark web.
That distinction matters, and it is important to say it clearly without blaming the victims. We have all become far too comfortable in our digital lives. Most people have credentials on dozens of websites and apps, accessed across phones, tablets, computers, and smart devices. Keeping track of unique, strong passwords for all of them feels impossible, and so people fall back on the same email and password combination across multiple sites. That is an understandable habit. It is also a genuinely dangerous one.
Here is the reality: over a three to four year period, there is a very good chance that at least one site you use has been compromised and your credentials exposed. Once that happens, those credentials get tested against other services automatically. If you use the same password on Nest that you used on a site that was breached two years ago, someone will eventually find their way in.
So what can you actually do?
First, stop reusing passwords. Every account should have a unique password. I know that sounds overwhelming, but a good password manager makes it manageable. You only need to remember one strong master password, and the manager handles the rest.
Second, turn on two-factor authentication everywhere it is available, and especially on anything connected to your home. Nest supports it. Use it. Even if someone has your password, they cannot get in without the second verification step.
Third, check whether your credentials have already been exposed. The website haveibeenpwned.com lets you enter your email address and see which known breaches included your information. It is free, it is reputable, and the results are often sobering.
Companies like Nest share some responsibility here too. Making security features more prominent and strongly encouraging two-factor authentication during setup would go a long way. Balancing ease of use with genuine security is not easy, but when the product involves cameras inside someone's home, that balance needs to lean harder toward protection.
Your home should be a place where you feel safe. A few simple habits can go a long way toward making sure it stays that way.
Tuesday, January 29, 2019
Responsible Corporations: My Privacy Does Matter
Yesterday was a big day in the Apple world, and not in a good way.
Around 4 PM on January 28th, MacRumors, my go-to source for Apple news, began reporting on a serious flaw discovered in the Group FaceTime feature of the latest iOS update. The bug was straightforward and alarming: if you initiated a FaceTime call with someone and then added yourself back into the call as a third participant, an audio bridge would open on the other end, whether or not the person you called ever accepted. In plain terms, you could listen in on someone without their knowledge or consent.
By 11 PM, local television news was running the story. That same night, Apple disabled Group FaceTime on their servers entirely, shutting down the vulnerability before it could spread further.
I went to bed feeling reasonably reassured. Apple has spent years positioning itself as a company that genuinely champions user privacy. It is woven into their marketing, their product announcements, and their public messaging. I had just upgraded a Mac, and one of the first things Mojave presented me with was a notice about privacy and Apple's commitment to protecting it. Their entire privacy page exists as a public declaration of values. I believed them. I still want to.
Then I woke up the next morning.
MacRumors had posted a thread showing that a teenager had discovered this exact bug and reported it to Apple on January 21st, a full seven days before it became public. The timestamps on those posts cannot be faked. Apple had been made aware of a significant privacy vulnerability affecting millions of users, and nothing changed until mainstream media picked up the story.
That is the part that concerns me most.
I am not suggesting Apple acted maliciously. What I am suggesting is that somewhere in the chain between a teenager's bug report and a company-wide response, something failed. Either the report did not reach the right people, or it did and the urgency was not recognized, or, in the worst case scenario, someone knew and was quietly working toward a backend fix before the story got out. Any of those outcomes points to a process problem that a company of Apple's size and stated values should not have.
Technology companies, especially those that have built their brand on privacy and trust, have a responsibility that goes beyond good marketing. When a flaw is reported, the response cannot depend on whether a journalist picks up the story first. Users deserve to know when their security is at risk. Transparency, even when it is uncomfortable, is what actually builds trust over time.
Apple has done remarkable things. I remain a believer in a lot of what they stand for. But this was a stumble, and it deserves to be called one clearly.
Put people above the bottom line. Always.
Monday, November 19, 2018
Windows 10 Fall 2018 Update: A LTSC Usability Problem Microsoft Missed
Let me be clear upfront: the Windows 10 Fall 2018 update, version 1809, did not delete my user files and did not touch my activation keys. Those horror stories made the rounds and understandably scared a lot of IT administrators. That is not what this post is about.
This is about a quieter, more frustrating problem. A usability issue that suggests Microsoft's engineers lost track of which version of Windows they were actually building for.
At work, we run the Long Term Servicing Channel build of Windows 10, now called LTSC, previously called LTSB. The Long Term Servicing Channel exists specifically for environments that need maximum stability and minimal disruption. It is the right choice for a lot of businesses, and we made that choice deliberately. The tradeoff has always been clear: you give up Microsoft Edge and the Microsoft Store in exchange for a leaner, more predictable operating system.
Losing Edge was never a hardship. Losing the Store created some friction. A few users wanted access to the Windows Subsystem for Linux, which inexplicably requires the Microsoft Store to download and install. Others ran into printer driver issues, specifically with HP hardware, that also required the Store to resolve. Those are legitimate complaints worth a separate conversation with Microsoft.
But the 1809 update introduced something new and genuinely irritating. The updated interface now includes a Themes section, which has never appeared in an LTSC build before. Scattered throughout the updated UI are hooks and prompts pointing directly to the Microsoft Store, a component that is not installed and was never meant to be part of this build.
Click on certain interface elements and you are told you need a Store package to proceed. Try to use the updated Snipping Tool, which now prompts you to upgrade to Snip and Sketch, and you are directed to download an app that only exists in the Store. The Store that is not there. The Store that was intentionally left out.
This is what makes it frustrating. These are not edge cases or obscure settings. These are visible, everyday parts of the interface. In the previous 2016 LTSB build, none of these prompts existed. Someone made a decision during the 1809 development cycle to update the interface without accounting for the fact that LTSC users would be staring at buttons and options that lead nowhere, for the next three years.
The ask here is simple. Microsoft, when you build for LTSC, please take the time to remove or hide the elements that depend on components your LTSC users deliberately do not have. Do not leave people staring at a prompt they can never fulfill. That is not a small thing when you are managing a fleet of business machines and your users are asking why something that looks like it should work simply does not.
Do better with the details, Microsoft. Your enterprise customers are counting on it.
Friday, October 12, 2018
Proper Documentation REQUIRED!
I have been in IT since 1989. Twenty-nine years in the field, twenty-five of them as paid professional engagements. My first computer was a Macintosh SE with dual floppy drives, no hard drive, and 1MB of RAM. I say that not to date myself, but to establish that I have seen a lot of what works and a lot of what does not.
Recently, I took over full responsibility for the IT organization at Virtual Instruments. My background has always been rooted in infrastructure: servers, routers, switches, endpoints. Taking on the application side of the business was a new challenge, and what I found when I got there was instructive in the worst possible way.
From Order to Chaos, and Back Again
I joined Virtual Instruments in 2009. On paper, I am employee number 76, and I am one of a small handful of people who have been with the company from its earliest days to now. During that time, the applications division was always a separate world from infrastructure.
For a while, it was run well. A Director of Applications named Anne was exceptional at her job. She had the skills, the discipline, and the professionalism to run a tight operation. You always knew where things stood. When she left in 2015, that position was not backfilled, and the vacuum it created had consequences that lasted years.
From late 2015 through early 2018, the applications team existed largely in firefighting mode. Too many tasks, not enough oversight, and no consistent framework to work within. A lot changed during that period. Almost none of it was documented.
When I took over in 2018, my first priority was to bring stability and industry best practices to a department that had been operating in the dark. That meant a significant amount of reverse engineering.
We use an ERP system that has no native integration with our CRM or warehouse platform. To bridge that gap, we rely on middleware, specifically Dell Boomi, to move orders between systems. What I found when I started digging into the existing Boomi workflows ranged from straightforward and logical to genuinely difficult to interpret. Some processes had multiple forked paths that seemed to meander without clear purpose. Staring at someone else's undocumented code and asking yourself what they were trying to accomplish is a frustrating and time-consuming way to run an IT operation.
It does not have to be this way.
Documentation Is Not Bureaucracy. It Is Respect for the Next Person.
I have lived by one principle throughout my career: there is no acceptable reason for an IT professional to skip proper documentation. None. Not timeline pressure, not team size, not the assumption that you will always be there to explain it yourself.
The framework I keep coming back to is ITIL. If you are not familiar with it, here is the short version. ITIL 3.0 is an industry standard framework that structures IT service management into five stages:
- Service Strategy
- Service Design
- Service Transition
- Service Operations
- Continual Service Improvement
Service Strategy aligns IT activities with the core needs of the business. Service Design creates and adapts services to support those needs. Service Transition moves systems through change management, testing, and knowledge transfer. Service Operation manages day-to-day events and incidents. Continual Service Improvement identifies opportunities to do things better over time.
Working within a framework like ITIL or COBIT makes undocumented work structurally difficult. The discipline is built in. When my predecessor operated without any framework, critical context was lost the moment a project closed. No notes. No decision rationale. No institutional knowledge. Just systems running on logic nobody could fully explain anymore.
Good documentation paired with sound architectural decisions creates systems that are manageable. The absence of both creates systems that are fragile and expensive to maintain.
The Tools That Made a Difference
Choosing the right framework is only part of the answer. You also need tools that support the work without getting in the way. Here is what we put in place:
Atlassian Confluence became our documentation hub. Of all the wiki-style platforms I have evaluated, Confluence is the most intuitive and flexible. The tool has to disappear into the work. If people are fighting the interface, they are not documenting.
A proper helpdesk and ticketing system is non-negotiable. Every IT team, regardless of size, needs a way to track incidents and requests. Metrics depend on it. Accountability depends on it.
GitHub gave our application team a place to store and version their code. Infrastructure teams may not use it daily, but for any team writing or managing scripts and integrations, it is indispensable.
Monday.com helped bring visibility to complex, multi-phase projects with a lot of moving parts and stakeholders who needed to stay informed without being in every meeting.
Slack improved day-to-day communication and collaboration across the team in ways that email simply cannot match.
Where We Are Now
Today, the applications team is visible, accessible, and effective. We are doing more with a lean, skilled group, supplementing with contractors when we have genuine technical gaps to fill. We are methodically working through systems that were previously black boxes, exposing what is inside, documenting what we find, and building a foundation that the next person can actually work from.
The lesson is simple. No IT team is too small to operate with discipline and documentation. A team of two people benefits from a framework. A team of five people needs one. The investment in doing it right the first time pays back every single time someone has to touch that system after you.
Document your work. Every time. No exceptions.
Wednesday, September 12, 2018
Apple Announcement Day - Fall 2018
I am not going to run through predictions or spec leaks. There are plenty of sites better positioned for that. What I do want to talk about is something that deserves more direct attention: the death of the sub-$1,000 smartphone.
The iPhone has been around for just over ten years. In that time, the price has climbed steadily while the subsidized carrier model that once softened that climb has quietly disappeared. Today you essentially have two realistic options: buy the phone outright, or spread the same full retail cost across 12 or 24 monthly installments. Either way, you are paying the same amount. The installment plan just makes it easier not to notice.
I bought an iPhone X outright last year. $1,200 for the 256GB model, before tax, plus whatever time I spent waiting in line. Apple's cost to manufacture that phone was approximately $400. That is a $600 margin on a single device.
Here is how the numbers have looked across every base iPhone model over the years:
Model Date Build Cost Retail Price iPhone Jun 2007 $220 $499 iPhone 3G Jul 2008 $174 $199 iPhone 3GS Jun 2009 $179 $199 iPhone 4 Jun 2010 $187 $199 iPhone 4S Oct 2011 $188 $199 iPhone 5 Sep 2012 $194 $199 iPhone 5C Sep 2013 $173 $99 iPhone 5S Sep 2013 $198 $199 iPhone 6 Sep 2014 $211 $199 iPhone 6S Sep 2015 $211 $649 iPhone 6S+ Sep 2015 $236 $749 iPhone SE Mar 2016 $160 $399 iPhone 7 Sep 2016 $224 $649 iPhone 7+ Sep 2016 $277 $769 iPhone 8 Sep 2017 $247 $699 iPhone 8+ Sep 2017 $295 $799 iPhone X Sep 2017 $370 $999 iPhone XS Sep 2018 — $999 iPhone XS Max Sep 2018 $370 $1,099 iPhone XR Sep 2018 — $749
The pattern is clear. Carrier subsidies began disappearing around the iPhone 6 era, a transition that started in 2013 and was essentially complete by the time the iPhone 7 launched. Retail prices jumped immediately and have not looked back.
The XS, XS Max, and XR were all announced today. The era of the sub-$1,000 iPhone is over.
There are alternatives worth considering. OnePlus continues to produce excellent Android hardware at prices that make Apple's lineup look difficult to justify on value alone. But if you are deeply embedded in the Apple ecosystem and have no interest in leaving it, you are going to keep paying. The ecosystem lock-in is real, and Apple knows it.
The Apple Watch tells a similar story. I bought a Series 3 with cellular last September for $429. Today Apple announced the Series 4, and the base model without cellular starts at $429. Add cellular and you are at $529. That is a $100 increase for the same feature I was already paying for.
To refresh both my phone and my watch in 2018 would cost me somewhere around $1,800.
Here is where I landed. The Series 4 watch is worth the upgrade. The EKG capability alone justifies it for me. The phone is a different calculation. The XS is an "S" year, which historically means refinement rather than reinvention. I am going to wait for the reviews, specifically around camera performance and the practical value of the upgrades, before I decide whether the cost is worth it this cycle.
Apple makes extraordinary products. But at some point the value conversation has to happen honestly, and that point is now.
Tuesday, July 7, 2015
Find My Mac: Good Idea, Incomplete Execution
In IT, stolen hardware is a fact of life. Laptops walk out the door. It happens in offices, coffee shops, airports, and cars. So when Apple extended its Find My iPhone feature to the Mac platform through iCloud, it should have been a meaningful step forward. The problem is that on the Mac side, it falls well short of what it could and should be.
Here is why this matters. The Activation Lock feature Apple introduced for iPhones has produced measurable results. A New York City Police Department report from October 2014 showed that iPhone thefts dropped 19% and grand larcenies involving Apple devices dropped 29% after Activation Lock launched. CNET reported shortly after that stolen iPhone volumes dropped 25% in New York, 40% in San Francisco, and 50% in London in the twelve months following the feature's introduction. Those are not small numbers. The feature works.
So why does the Mac version not work the same way?
Find My Mac exists, but it has a fundamental weakness: wiping the machine defeats it entirely. A thief who knows what they are doing can erase the drive, reinstall the operating system, and the device has no memory of who it belonged to. The serial number to iCloud account association disappears. The machine becomes anonymous.
That does not have to be the case, and fixing it does not require a dramatic rethinking of how Macs work.
Every Mac periodically checks for software updates. That is already built in. Why could that check-in process not also include a reference back to iCloud to verify whether the device's serial number is associated with an account? If it is, and the machine has been wiped and a new iCloud account is being added, the system could simply respond: this Mac is already registered to another account. Just like an iPhone. Just like an iPad.
The responsibility chain would mirror what already exists in the iOS world. If you are selling a Mac, you remove the activation lock before handing it over. If you are buying one, you verify the lock is clear before completing the purchase. Simple, familiar, and already proven to reduce theft.
The serial number is permanent. The iCloud association does not have to disappear just because someone reformatted the drive. Keeping that link intact across a wipe is technically achievable, and the real-world impact on theft rates would likely mirror what we have already seen on iOS.
Apple has built the foundation. The logic for how this should work is straightforward. The data showing it would make a difference is already there.
Apple, if you are hiring, I am available.
Tuesday, February 18, 2014
Old Poems I Dredged Up from the Internet
I stumbled across these recently while wandering through the older corners of the web. They are mine, written back in 2001 when I apparently had a lot of feelings about computers and a lot of time to put them into verse. I am sharing them here partly for the sake of preservation, and partly because they still make me smile.
Tuesday, December 3, 2013
macOS 10.9.1 Mavericks Beta and World of Warcraft
I have been running the Mavericks 10.9.1 beta for about a week, and overall it addresses a solid number of the usability issues that shipped with 10.9. So far so good, with one very specific and very annoying exception.
The system is kernel panicking and rebooting spontaneously, and I cannot pin it to anything except World of Warcraft. Ripping CDs, streaming music, general use — all fine. The moment I sit down to play, it is only a matter of time before the OS halts and restarts with no useful detail about what caused it. Every single time, it is during gameplay. Nothing else triggers it.
I am choosing to believe the operating system has developed opinions about how I spend my free time.
To verify the issue is actually tied to the 10.9.1 beta and not something deeper, I am rolling back to 10.9.0. If the problem disappears, that confirms it. If it does not, I may have to drag my dual Xeon tower in from the garage to keep the WoW habit alive and the Mac out of trouble.
More to follow once I have results.
Today, the world feels a little quieter, a little dimmer.
We knew this day would come, but we held onto the hope that there would be more time. John Michael "Ozzy" Osbourne—our beloved Pri...
-
We knew this day would come, but we held onto the hope that there would be more time. John Michael "Ozzy" Osbourne—our beloved Pri...
-
Update: Black Helmet Apparel has since gone out of business. I will leave it at that. Update 2: Black Helmet is back (2025) and they seem to...
-
Here's #4: Women and Technology: A Lesson from Blizzard's Failure I am sad and angry about what continues to come out of the Bli...


