<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Paul Matthews &#8211; iStart keeping business informed on technology</title>
	<atom:link href="https://istart.com.au/istart-author/paul-matthews/feed/" rel="self" type="application/rss+xml" />
	<link>https://istart.com.au</link>
	<description>iStart keeping business informed on technology</description>
	<lastBuildDate>
	Thu, 13 Aug 2026 09:07:53 +0000	</lastBuildDate>
	<language>en-us</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>What you need to know about GDPR</title>
		<link>https://istart.com.au/opinion-article/what-need-know-gdpr-anz/</link>
				<comments>https://istart.com.au/opinion-article/what-need-know-gdpr-anz/#respond</comments>
				<pubDate>Mon, 28 May 2018 23:27:59 +0000</pubDate>
		<dc:creator><![CDATA[Jennene Kelly]]></dc:creator>
		
		<guid isPermaLink="false">https://istart.com.au/?post_type=opinion-article&#038;p=28482</guid>
				<description><![CDATA[<p>GDPR went live on 25 May - but how does it affects you?...</p>
<p>The post <a rel="nofollow" href="https://istart.com.au/opinion-article/what-need-know-gdpr-anz/">What you need to know about GDPR</a> appeared first on <a rel="nofollow" href="https://istart.com.au">iStart keeping business informed on technology</a>.</p>
]]></description>
								<content:encoded><![CDATA[<section class="vc_section_wrapper"><div class="wpb_row row-fluid">
	<div class="span12 wpb_column column_container">
		<div class="wpb_wrapper">
			
	<div class="wpb_text_column wpb_content_element ">
		<div class="wpb_wrapper">
			<p>So what&#8217;s all the fuss about? It&#8217;s actually a really significant change to the rules around personal data, and <strong>it really does affect you</strong>.</p>
<p><strong>Here&#8217;s a quick summary:</strong></p>
<ul>
<li>The EU says the changes attempt to &#8220;harmonize data privacy laws across Europe, protect and empower all EU citizens data privacy and reshape the way organisations across the region approach data privacy.&#8221;</li>
</ul>
<ul>
<li>One of the more controversial impacts of the new rules, and the reason it has such a world-wide impact, is what they call the &#8220;<strong>extra-territorial applicability</strong>&#8220;.  This means that it applies to all companies worldwide who are <strong>dealing with information about people residing in the EU</strong>, even those simply offering goods or services to EU citizens. It hits everyone and it&#8217;s huge.</li>
</ul>
<ul>
<li>One of the key changes is around <strong>consent</strong>. Basically if a company is going to store or process personal data such as names, email addresses and the like, it needs to have explicit consent. The small print in the middle of a <strong>10-page &#8220;terms and conditions&#8221;</strong> aren&#8217;t enough &#8211; it has to be in complete <strong>plain English</strong>.</li>
</ul>
<ul>
<li>The method of consent has to be recorded as well and proper records kept. This is significant &#8211; for example, if you have a mailing list you need to be able to show when people opted in and how.</li>
</ul>
<ul>
<li><strong>The fines are huge too</strong>. Companies can be fined up to <strong>4 percent of their annual global turnover</strong> for breaches, with big fines for even seemingly minor issues.</li>
</ul>
<ul>
<li>Companies must now also tell people if they&#8217;ve had a <strong>breach</strong>. We&#8217;ve seen a heap of this lately &#8211; people&#8217;s information being stolen and companies keeping it quiet to try to avoid reputation damage. Do that now and it could cost <strong>2 percent of global revenue</strong>.</li>
</ul>
<ul>
<li>Other changes are familiar to Australian&#8217;s, such as the right to obtain any information that is <strong>being held about them</strong>.</li>
</ul>
<ul>
<li>There&#8217;s heaps more as well, such as the controversial &#8220;<strong>right to be forgotten</strong>&#8221; This basically gives EU citizens the right to have Google, for example, remove references to them on searches. And again, the rules apply globally &#8211; not just to EU companies.</li>
</ul>
<ul>
<li>The new rules also put into law the concept of &#8220;<strong>Privacy by design</strong>&#8221; for software developers. Basically software developers have to show they&#8217;ve built privacy into software from the ground up, not just tagged it on in the end. This has been a long time coming.</li>
</ul>
<p>So some really important things to think about from a IT Professional perspective as well, even if you&#8217;re not based in the EU.</p>
<p><span style="color: #ff9900;"><a style="color: #ff9900;" href="https://gdpr-info.eu/" target="_blank" rel="noopener noreferrer">View the full regulations here</a></span></p>
<p><strong><br />
<a href="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg"><img class="alignright size-medium wp-image-10147" src="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews-148x200.jpg" alt="Paul Matthews" width="148" height="200" srcset="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews-148x200.jpg 148w, https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg 150w" sizes="(max-width: 148px) 100vw, 148px" /></a>ABOUT PAUL MATTHEWS//</strong></p>
<p><span style="color: #ff9900;"><a style="color: #ff9900;" href="https://www.linkedin.com/in/nzpaulm" target="_blank" rel="noopener noreferrer">Paul Matthews</a></span> is chief executive of the Institute of IT</p>

		</div> 
	</div> 
		</div> 
	</div> 
</div></section>
<p>The post <a rel="nofollow" href="https://istart.com.au/opinion-article/what-need-know-gdpr-anz/">What you need to know about GDPR</a> appeared first on <a rel="nofollow" href="https://istart.com.au">iStart keeping business informed on technology</a>.</p>
]]></content:encoded>
							<wfw:commentRss>https://istart.com.au/opinion-article/what-need-know-gdpr-anz/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
							</item>
		<item>
		<title>Time to call in the pros</title>
		<link>https://istart.com.au/opinion-article/time-to-call-in-the-pros/</link>
				<comments>https://istart.com.au/opinion-article/time-to-call-in-the-pros/#respond</comments>
				<pubDate>Sun, 29 Mar 2015 22:27:44 +0000</pubDate>
		<dc:creator><![CDATA[Jennene Kelly]]></dc:creator>
		
		<guid isPermaLink="false">https://istart.co.nz/?post_type=opinion-article&#038;p=10146</guid>
				<description><![CDATA[<p>The Institute of IT Professionals NZ (IITP) CEO <strong>Paul Matthews</strong> explains what the Chartered IT Professional accreditation is and why we need it…</p>
<p>The post <a rel="nofollow" href="https://istart.com.au/opinion-article/time-to-call-in-the-pros/">Time to call in the pros</a> appeared first on <a rel="nofollow" href="https://istart.com.au">iStart keeping business informed on technology</a>.</p>
]]></description>
								<content:encoded><![CDATA[<section class="vc_section_wrapper"><div class="wpb_row row-fluid">
	<div class="span12 wpb_column column_container">
		<div class="wpb_wrapper">
			
	<div class="wpb_text_column wpb_content_element ">
		<div class="wpb_wrapper">
			<p>In 1907 a group of engineers and bridge builders in Quebec, Canada, embarked on an ambitious project to build the longest bridge in the world. But before the bridge was completed it was to cost almost 100 human lives.</p>
<p>On August 29th the partially built bridge collapsed, killing 75 workers and injuring another 11. A Royal Commission of Enquiry found a lack of experience of the type and size of bridge and clear mistakes had caused the disaster and held the designer and consulting engineers responsible. Construction began on the bridge once more in 1916, but disaster struck again, when the central span was being raised into position, and fell into the river killing 13 workers.</p>
<p>The managers had been made aware of the problem that caused this second collapse a full six weeks prior by the engineer responsible for the construction of the centre section, but hadn’t taken any action. All in all, 88 people lost their lives to predictable failures.</p>
<p>So what does all of this have to do with IT and technology today?</p>
<p>It was after this double tragedy that the concept of the Professional Engineer was born. Engineers realised that they couldn’t continue to have such devastating failures caused by inexperience or not following reasonable standards of practice. And they could no longer tolerate decision-makers ignoring their professional advice.</p>
<p>A similar sentiment has been growing in the international IT community since 2008, when the national tech professional bodies from Canada, the UK, Australia, South Africa, Japan and elsewhere came together to discuss whether it was time for the IT profession to also put in place minimum competency standards. Since then, all of these countries, and many others have done just that.</p>
<p>In New Zealand’s case, the road towards the Chartered IT Professional accreditation that was officially released in February began when the IITP (then called the NZ Computer Society) released a 2008 discussion document outlining a range of problems in the industry and calling for the profession to form independent competency standards to address them.</p>
<p>As well as continual significant failures in major IT projects in both the public and private sectors, some of the issues highlighted included the global IT skills shortage; significant reduction in technology undergraduates and in the percentage graduating; negative perception of IT as a career amongst youth; and lack of retention of skilled individuals in New Zealand.</p>
<p>In other words, our bridges were falling down and we needed to do something about it. New Zealand’s response, run by the Institute and named IT Certified Professional (ITCP), was released in late 2009 to great success.</p>
<p>Up until that point, IT was almost the only vocation or profession remaining without a set of independent benchmarks outlining the minimum expected standards of skills, knowledge, ethics and professionalism for people operating the field. And we’re not just talking about the established professions such as accountants and lawyers here. Almost every area you can think of, from plumbers to librarians and architects, has minimum standards in the form of an overarching professional certification. The reason for such accreditations is that there is a real difference between someone who knows what they’re doing and someone who doesn’t. Professionals have the right to differentiate themselves and a responsibility to come together within professional bodies and define minimum standards.</p>
<p>In February the IITP converted the ITCP to the Chartered IT Professional NZ, issued under license from the UK-based BCS, the Chartered Institute for IT. It also introduced a new Certified Technologist accreditation for those in the first few years of their career. The reason for the change is to increase the recognition of Kiwi IT professionals both in New Zealand and around the world, and to provide credentials that are immediately recognisable by the public.</p>
<p>Those accredited have committed to adhering to standards of professional conduct and ethics and have agreed to be professionally accountable if they don’t. In return, they have the weight of the entire profession behind them when they say that a project can’t proceed because if it does, the bridge will fall down.</p>
<p><strong>ABOUT PAUL MATTHEWS//</strong><br />
<a href="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg"><img class="alignright size-full wp-image-10147" src="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg" alt="Paul Matthews" width="150" height="202" srcset="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg 150w, https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews-148x200.jpg 148w" sizes="(max-width: 150px) 100vw, 150px" /></a><span style="color: #ff9900;"><a href="https://www.linkedin.com/in/nzpaulm" target="_blank" rel="noopener noreferrer"><span style="color: #ff9900;">Paul Matthews</span></a> </span>is chief executive of the Institute of IT</p>

		</div> 
	</div> 
		</div> 
	</div> 
</div></section>
<p>The post <a rel="nofollow" href="https://istart.com.au/opinion-article/time-to-call-in-the-pros/">Time to call in the pros</a> appeared first on <a rel="nofollow" href="https://istart.com.au">iStart keeping business informed on technology</a>.</p>
]]></content:encoded>
							<wfw:commentRss>https://istart.com.au/opinion-article/time-to-call-in-the-pros/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
							</item>
		<item>
		<title>How to avoid the IT hall of shame</title>
		<link>https://istart.com.au/opinion-article/how-to-avoid-the-it-hall-of-shame/</link>
				<comments>https://istart.com.au/opinion-article/how-to-avoid-the-it-hall-of-shame/#respond</comments>
				<pubDate>Thu, 04 Apr 2013 21:41:23 +0000</pubDate>
		<dc:creator><![CDATA[Jennene Kelly]]></dc:creator>
		
		<guid isPermaLink="false">http://testbed.istart2.com.au/?post_type=opinion-article&#038;p=3706</guid>
				<description><![CDATA[<p>IT security and project stuff-ups are certainly nothing new in our field. But things seem to be getting worse and sadly, most of these issues are preventable...</p>
<p>The post <a rel="nofollow" href="https://istart.com.au/opinion-article/how-to-avoid-the-it-hall-of-shame/">How to avoid the IT hall of shame</a> appeared first on <a rel="nofollow" href="https://istart.com.au">iStart keeping business informed on technology</a>.</p>
]]></description>
								<content:encoded><![CDATA[<p>Two thousand and twelve certainly saw its share of high-profile IT gaffs. The year seemed to lurch from scandal to scandal, with the two most prominent security stuff-ups being the calamitous launch of TradeMe competitor Wheedle, taken down after just a few days amidst what had become a fever pitch of complaints about gaping security holes; and the revelation that up to 736 publicly-accessible kiosks in WINZ offices throughout New Zealand weren&#8217;t properly locked down, allowing access to sensitive documents including details of abused children.</p>
<p>Add to that the long-running and far from resolved Novopay fiasco and 2012 certainly wasn’t a good year for the reputation of our profession.</p>
<p>In fact New Zealand&#8217;s Privacy Commissioner Marie Shroff has gone as far as labeling it the &#8220;year of the data breach&#8221; and, given the above issues and others such as the ACC Pullar affair, it would certainly be difficult to argue that she&#8217;s wrong.</p>
<p>So what really happened and what do the issues of the past year have in common? Wheedle was a well-intentioned and, by all accounts, well-resourced company that promised to finally take on incumbent behemoth TradeMe in the online auction game. Backed by the founder of Mainfreight, its battle cry included claims of good technology, 40 servers on standby and millions in advertising.</p>
<p>But despite all of this, the founders seriously let themselves down on the IT front. For example, they allegedly didn&#8217;t even bother encrypting passwords sufficiently and left gaps in their website that allowed members to change other members&#8217; auction details (including reserve and buy-now prices) leaving the site open to serious abuse. In fact they made a litany of fairly entry-level coding errors and simply got the basics wrong.</p>
<p>It was later revealed that the website development had been outsourced to developers in India, presumably to save costs.</p>
<p>The WINZ kiosk situation should never have happened either. In this case, the Ministry of Social Development built hundreds of self-help kiosks to enable the unemployed to edit their CVs and search for jobs. A great idea, and for the most part they did everything right. However there were two fundamental – and basic – flaws to their execution.</p>
<p>The first was technical; the kiosks were connected smack-bang in the middle of the Ministry&#8217;s network with no separation, physical or logical. This meant that a somewhat minor oversight when locking the kiosks down (the ability to access network locations through Microsoft Word&#8217;s ‘Open’ dialog box) became a major issue, especially when it was combined with access to sensitive files such as phone logs, invoices and other information, including that of abused children.</p>
<p>While somewhat unforgivable, this wasn&#8217;t even the biggest oversight. It emerged later that the Ministry had been made aware of these issues. In fact they&#8217;d hired an external security company to audit the kiosks, then simply ignored four out of the six security issues identified, including the major lack-of-separation issue that caused the breach.</p>
<p>Interestingly, a request for funds to do the separation properly had been made. It was apparently ignored and the project pushed ahead without it, probably to save costs. It&#8217;s worth noting that the cost of the two recent Deloitte reports into what went wrong is an astonishingly high $450,000 so far – and that&#8217;s before the fix has even started.</p>
<p>So again, ignoring the basics caused potentially catastrophic results.</p>
<p>Then there&#8217;s Novopay, the New Zealand Ministry of Education&#8217;s payroll solution built on Australia&#8217;s Talent2 system. Those that have worked in IT for any length of time will know there are often teething problems in the implementation of any new system, especially one as complex as a payroll system for upwards of 90,000 people in hundreds of schools across a country. Teething problems are more or less a given, which is why they are factored into the rollout plans for major new systems.</p>
<p>Already two years overdue and undoubtedly millions over budget, did the powers that be push ahead with the Novopay launch knowing there were still issues, amidst political and financial pressure to get it done? It appears the pre-launch testing showed the system wasn&#8217;t ready; only 37 percent of trial users thought it was ready to go. Yet on 20 August 2012 they kicked it off anyway, flicking the switch on all schools and all teachers in one fell swoop.</p>
<p>The promised ministerial inquiry into the resulting mess will hopefully shed light on why they didn&#8217;t roll it out to a small group of schools first to identify and resolve most issues before they became totally overloaded by a backlog of thousands of problems. Kicking things off in 50 schools would have identified most of the problems that have subsequently appeared, but in a way that meant they could actually deal to them quickly and without affecting too many people. Not only is that best practice, it&#8217;s also common sense.</p>
<p>As you can probably see, a pattern is emerging here, one that we see constantly repeated in IT. It is a pattern of standard good practice being ignored, budgets being cut and cost or political pressure leading to cutting corners with disastrous effect.</p>
<p>In short, it demonstrates a naively held view that cutting costs in the implementation of IT projects won&#8217;t have the dire consequences that we see time and time again.</p>
<p>Isn&#8217;t it about time we stopped being so foolish? So, how do you prevent your company being the next 6 o&#8217;clock news item on privacy, security or IT failing? It&#8217;s simple really: just resource and do the job properly. Play by the rules, don&#8217;t cut corners, follow established good practice and don&#8217;t be fooled into false economy and believing that saving a few bucks now won&#8217;t cost you a bunch down the line.</p>
<p>The price of doing it right is seldom more than the cost of cutting corners when all is said and done. And as Wheedle, MSD, Novopay and many others have discovered, getting it wrong in IT can come at huge expense to your wallet&#8230; and your reputation.</p>
<p><strong><a href="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg"><img class="alignright size-full wp-image-10147" src="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg" alt="Paul Matthews" width="150" height="202" srcset="https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews.jpg 150w, https://istart.com.au/wp-content/uploads/2015/03/writer_Paul-Matthews-148x200.jpg 148w" sizes="(max-width: 150px) 100vw, 150px" /></a>ABOUT PAUL MATTHEWS//</strong></p>
<p>Paul Matthews is chief executive of the Institute of IT Professionals New Zealand<br style="color: #727272;" /><br style="color: #727272;" /><a style="color: #ff9905;" href="http://www.iitp.org.nz">www.iitp.org.nz</a></p>
<p>The post <a rel="nofollow" href="https://istart.com.au/opinion-article/how-to-avoid-the-it-hall-of-shame/">How to avoid the IT hall of shame</a> appeared first on <a rel="nofollow" href="https://istart.com.au">iStart keeping business informed on technology</a>.</p>
]]></content:encoded>
							<wfw:commentRss>https://istart.com.au/opinion-article/how-to-avoid-the-it-hall-of-shame/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
							</item>
	</channel>
</rss>
