Thursday, 26 April 2012

How tight do you run your projects?

I submitted a project plan, along with costs to the senior management last week and was told, off-the-record, that my timescales were too short and the expense budget was too small.

I have been a PM for a number of years and I am often told that my budgets are either too high or too low.  At the beginning of a project, this often concerns me and I always wonder what I have missed, or what the other person knows... that they have not told me.

I have the disadvantage, in one way, of a being a contractor, but also the clear advantage of being a contractor in another. 

For the disadvantage, I do not know the project history or "norm" within the specific company.  I do not know if projects historically tend to run to time and budget.  I do not know if suppliers are particularly difficult, or is procurement can hold the ordering and payment processing up.  I do speak to the other project managers and build relationships with all parties involved, from procurement, finance, technical teams and testers etc and I do find if there are any lessons learned from previous projects, from either the project managers or the PMO department.

The advantage I have is that I know different companies work in different ways.  To mitigate this, I build the relationships between the key teams and make sure that they can accurately estimate their timescales, costs and highlight any risks and issues for me.  I of-course build in a certain percentage of time and additional cost to enable any overrun.

What are you best tips for dealing with forecasting within an unknown company?

A Project Manager's CV

I had a CV come across my desk this week, which was given to me by a very reliable source.  The CV on first impressions looked quite good, with over 16 years of Project Management experience, all in the Investment Banking industry.

I looked at it in a little more details today and realized there was very little detail within the CV.  It made me wonder what level of detail we should go into on a CV.  My thoughts are that there should be enough information for each work placement to give an outline of what you have been working on, but leaving out enough detail to be a feeder for a discussion in the interview.

As a PM, I would suggest you explain the basics of any project you have managed, along with the timescales, budgets, project team size and any technology used, replaced or removed.  Again, I would suggest this is at a high level as to not give away any confidentiality and to keep enough information back for interview questions.

In addition, I would highlight any particular issues or risks that were dealt with successfully along with any management reporting levels, SLAs, third party vendor communications etc... All of this I would see as secondary to the actual project details listed in the paragraph above.

The CV in question only came with the secondary information.  I understand it was from an investment banking background, but there is still a certain amount of detail you can add to a CV without it breaking any confidentiality agreements... or am I wrong?

Why Contracting?


I wrote on a forum some advice to a permanent member of staff considering the option of contracting.  The question was "How much experience do you need before you go contracting?".

My answer was fairly short, but I thought it was interesting enough to make into an article to share with you, especially in a time when contractors are getting a bad press.

I left university and after 18 months in two jobs, I went contracting.  Not consulting, contracting.  I was simply a developer assigned to a project to work on the Y2K project (remember that folks?).  I knew I was a good developer and had the confidence to leave the full-time security and branch out on my own.

Rule Number One as a contractor is to have the confidence in yourself to be able to step out and say "I can do this".  Confidence.  Simple.

The knowledge comes second.  This may surprise some people, but the reality is there is always an answer on the internet.  I remember my parents not being too happy about leaving the security of a full-time role and not knowing where I would be working, but I knew that I would be OK, I had the confidence.

I feel that knowledge must be backed up by qualifications.  People often undervalue qualifications, but the reality is that you are able to get a rounded education, the more you look into specific qualifications.  An example was while working within the Lotus Notes Arena, I was able to understand more of the theory and have a deeper understanding of the intricacies, over colleagues without the additional education and research.  My Father was a great believer in education and I am committed to this day to make sure I continue in his three-word mantra... "Education education education".  

Along with knowledge, a contractor is expected to make an impact to the team / project very soon after starting.  Often a day or two to show the processes / governance is all you are allowed before you actually start making progress on the task you have been taken on for.

Contractors get quite a bit of negative press and many full time employees often begrudge a contractor working along side them.  Usually the main reason is down to money.  This simple little thing makes many people jealous in all walks of life, but the issue between contractors vs permanent staff can often be very visible and difficult.

My reply for this is often the fact that we are actually paid more money that the usual member of staff, but we are only paid for the time we are working.  The eight standard bank holidays, sick pay and our annual holiday is not paid, neither are the extras such as Training and Qualifications (remember my paragraph above).  We do have other "perks" such as our subsistence and travel are paid before tax, we can pay ourselves in a way to minimise our tax, but we still have all the additional paperwork, research, accountants fees etc to make this happen.

Anyone can be a contractor.  You need to have the confidence, the knowledge, the qualifications and the self motivation to go out there and sell yourself. 

Tuesday, 27 March 2012

Is Android King - or too Risky?

I have both an Android phone and tablet.  I actually have the new ASUS Transformer Prime, which is incredible.  I like widget and the freedom to place anything on my phone.  There are thousands of Apps available in the new Google Play store. 

However, I attended a Bring Your Own Device event last week which discussed the security implications.  One main point that came across was how insecure Android is, for example there was recently an application for a touch (flash light for my friends in the US), which would maliciously send a text message for an extortionate rate.  McAfee were one of the presenters and showed a frightening slide that told us... 

57% of Android users have no security on their phone 
Only 5% have anti virus or anti malware 
19% have some form of encryption 
17% have a password, or keypad lock 
Some of the above is quite frightening, especially as another slide showed that there were almost 400 new malware Apps found in Q4 of 2011, compared to just over 100 in Q3 of the same year. 

Why Android? 

The reason the hackers are targeting Android is due to that it is easy to publish an application on the Google Play site.  Anyone can simply create an application and publish it.  With the rising market share of Android, it seems that this is the easiest way to hit as many people.  This is why Windows is always a target of many viruses and malware.  I read last week that 90% of the smart phone purchased recently are either Android or iOS, with 53.8% of that figure being Android. 

Another reason for the easy access for malware is that people do not keep their phone up to date with various patches from Google.  This is for three main reasons. 

The phone is "Rooted" and therefore the updates have to come from an independent developer. 
The manufacturer does not update their version of the OS. 
The mobile operator does not allow the OS to be updated by Google or the manufacturer and does not update the OS themselves. 

All of these issues above are beyond the control of both the user and the corporation, when considering BYOD.  Try to think of the number of applications that are downloaded each day.  There was a game released 6 weeks ago, which has already been downloaded 35 million times.  Hackers and writers of malware and viruses will target these popular applications in hope that just 1% of users run their malicious code. 

How do you combat the threats? 

The threats can be combated in a number of ways.   

Malware / Viruses - Firstly, the OS could be kept up to date which would remove some of the loopholes that viruses and malware exploit.  In addition to this, many of the virus protection software companies provide a mobile phone version, for example I use AVG at home, as it is free, and they provide a mobile version - also for free. 
Device lock - On top of this we can add a simple screen lock, which would keep the average thief from stealing our data. 
Encryption - In addition we should encrypt our phones, which would mean that without a key, the data would be unreadable.  This means that as a company, you can send a command to delete the encryption key from the device and this in turn would make the data unreadable. 
Firewall - For corporate customers, you can ensure that the web browsing on the device is all filtered through your company firewall, which will include the safe browser and proxy settings you use within the desktop browsers. 

What to protect? 

There are three parts to securing the mobile device. 

Device - First, what would happen if the device was lost or stolen.  A good Mobile Device Management (MDM) policy is required, which would either track the phone, or could even disable it to the point that it could never be used again.  It would be good to add screen locks and password protection. 

Data - The most expensive part of the loss of the device would not be the replacement value, but would be issues around the data loss.  To prevent this the MDM should be able to Lock / Wipe or Delete the data on the device.  The corporate data must remain encrypted on the device and therefore a tool would be able to remove the encryption key, to ensure the data remains secure.  An issue here is 

Applications - Some companies would choose to only allow certain Apps on their devices, but what would happen in a truly BYOD environment?  If I was to use my own device for reading my work email, i would still want the choice to play games and use Apps that i want to use outside of work.  In response to this, McAfee and other suppliers have created their own Application Store, which contain all of the Apps which have been scanned for any virus or malware, which could be used by the device owner.  In addition to the supply of the applications, the Application Store would be able to remove applications from the device immediately, if a threat is detected. 

Conclusion 

The on-line world is a world where many unscrupulous people reside.  They target the vulnerable and the target them in numbers.  The new on-line experience is growing rapidly via the mobile browser and the number of Apps downloaded from various Application Stores is incredible, for example a new drawing game has had 35 million downloads within 6 weeks.  With the combination of both the application downloads and the web browsing, the sample is large for people to exploit.   

I only have a simple screen pattern lock on my phone, but will be adding the AVG free version of the anti virus / malware to my collection of applications today ! 

Wednesday, 22 February 2012

What is a PID

A PID is a Project Initiation Document and is created once the authorisation to initiate a project has been given.  The PID is the final result of the initiation phase of the project and describes the "what, why, who, how, where, when and how much" of the project.  This document is fairly extensive within the Prince2 Project Management Model and will incorporate many documents, such as the project brief, project scope, project definition and project plan as well as the strategy for the project in terms of communication, quality, configuration management, risk and issues.  More information on these individual topics can be found in the Prince2 book, so I will not go into detail here. 

It is the project managers role to produce the PID and pass it on to the project board for authorisation.  In reality the stakeholders, users and business analysts will need to be involved in producing much of the documentation. 

The PID is a constantly evolving document and remains important throughout the project life cycle.  The PID contains many documents/sections including the project plan, exception plans, risks/issues and therefore is updated throughout the project.  It remains a reference point to who is doing "what, when, how, why". 

Spend time keeping the PID updated and authorised. 

Tuesday, 21 February 2012

Excel: Date to DOTW

Here is a quick tip / reference to how to calculate the day of the week from a date.

=CHOOSE(WEEKDAY(A1),"Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday")

A handy tip !

Monday, 20 February 2012

Define the Stakeholders

A stakeholder is a person, group, organisation, member or system who affects or can be affected by an organisation's actions.   

In terms of Prince2, the definition of a project refers to a temporary organisation and therefore the Project Stakeholders are the people, groups, systems that are directly affected by the delivery of the business products of the project.  From the early stages of a project, the Project Manager must identify the key stakeholders and understand the influence they will have on the product delivery. 

Stakeholders may be internal or external, such as Trade Unions, or external support.  The stakeholders may benefit from the project, however, to some the project may deliver a negative effect, such as reducing team sizes.   

Identifying and working with the stakeholders is a key task in the early stages of your projects.  As I am from a Prince2 background, i follow the standard 6 step approach to stakeholder engagement and interaction.   

1. Who - Identify the key stakeholders 
2.  What - Understand what the project will mean to the stakeholders.  They may gain or loose as products are delivered and therefore their commitment and influence will need to be managed. 
3.  How - This is the defining of the method of communication to the stakeholder.  This will set out the frequency and content of the information that needs to be communicated. 
4.  When - This will define when the communications and the engagement of the different stakeholders will be required. 
5.  Do - This is a simple reminder - You must engage with the stakeholders.  Make sure you do.  You cannot deliver a product without their help, as it may not be fit for purpose. 
6.  Results - Check that the engagement and communication has been successful.  Learn from feedback. 

I actually think the 6 step process is a little over the top and will tailor the steps to suite my requirements.  The key point is to make sure your stakeholders are engaged early within the project.  Be careful, the stakeholder may influence the business in a positive or negative way, so choose your stakeholders wisely.  Stakeholders generally include people from the Project Team, Senior Management, the Customer, Resource Managers, User groups, Trade Unions. 

Define the stakeholder, Engage the stakeholder and Deliver a successful project !