Showing posts with label software audit. Show all posts
Showing posts with label software audit. Show all posts

Wednesday, March 16, 2016

Corporate lay-offs? "Difficult" economy? Get ready for a software audit!



Your chances of being embroiled in a software non compliance—piracy—punitive audit are higher today than at any time in the history of copyright enforcement. Here's how it works: During difficult economic times, or when your company loses personnel, you are opening yourself up to a significantly higher probability of software license enforcement audit scrutiny. In fact, your chances of becoming involved in a software audit could geometrically increase by as much as double for every five employees you let go.

Do you think this perspective is all so much hot air? When you combine the aggressive “Whistle-Blower Reward Programs” fielded by the software publishers and their enforcement industry friends, your level of risk is increasing as the economy becomes ever more unstable. Read on to discover methods for keeping what little corporate money you have – in YOUR enterprise pockets – rather than continuing to pay out more and more to the software and copyright protected products industry players.

Real World – The software industry players have known for a long time that there is an enormous revenue stream to be had in conducting compliance audits – even against enterprises that have a “clean” compliance record. They've been siphoning enormous amounts of cash from their own customers while constantly attempting to ensure that the entire compliance assurance process is as difficult and poorly defined as possible via ever more incomprehensible licensing schemes.
If your enterprises uses any degree of technology, you are an easy audit target. Period. Full stop. Even if you are 100% ethical and careful in your systems controls.

The bottom line is that technology asset management isn't about how much you spend, it's about the value you receive for every single dollar that you invest. When you can very easily enhance the value you gain from your business technologies, while minimizing initial and ongoing costs AND minimizing related risks, these ideas become no-brainers.

The key is this: Every successful asset management initiative begins with the foundation framework established by proactive software asset management. We build on this relatively basic foundation to deliver genuine life cycle value for software, hardware, and related goods, services, and contractual agreements.
At The Institute, our focus is putting that value—that money—back in your pocket...and KEEPING it there. 

Consider the following:
  • If / When you look honestly at the current (sad?) state of your country's economy, nearly every business is looking to cut expenses and increase ROI, you'll recognize that managing the technology portfolio is one the most easily value-added programs available to you,
  • If / When you realize that, in part due to lower employee numbers in the so-called developed countries, local and global software sales are down,
    • Your suppliers are aggressively hunting for additional revenue streams,
    • For these people, compliance audits are VERY significant income opportunities,
  • If / When you recognize that large numbers of people are discovering that with zero warning they're out of a job,
    • And they are NOT happy with you,
    • It's easy to sign into the anti-piracy sites to deliver up you and your company for an audit,
  • If / When we remind you that the software industry players and their so-called software police / copyright cops are loudly publishing whistle-blower rewards of up to $1,000,000...
    • Money for nothing...?
    • One of the enforcement audit campaigns was even entitled “Don't Get Mad, Get Even”!
    • Does this tell you ANYTHING about enforcement tactics?
  • If / Then - In light of these realities, is it any surprise that your audit risk expands by an approximate factor of double for every five employees you upset?
    • Oh, yeah... Did we mention that existing—and ethical—employees are also very willing to report your copyright violations?
    • Did we also mention that small- to medium-sized businesses are the absolute favorite audit targets?
    • Did we mention that American enterprises are carrying the majority of frequency in being audited for licensing issues? (Because American enterprises can “afford” to pay more in fines / penalties. BUT, this locus of focus is changing as other countries expand their use of high risk software products.)
  • And last, but not least, did we mention that The Institute for Technology Asset Management is your portal to establishing and maintaining effective business processes that extract maximum value from your IT spending dollars while minimizing costs and risks?
    • Did we mention that many of our solutions cost you NOTHING?
    • Did we mention that our methodologies meet or exceed ANY existing standards for software portfolio management?
    • Did we mention that our software asset management credential programs are substantially more comprehensive that anything currently on the market because they focus on practitioner competencies?
Fines and Penalties – The average cost of a single software piracy audit can—and frequently does—exceed $100,000—for even the smallest company (10 computers). To put this in more basic terms, think $3,000 to $5,000USD per computing device in typical settlement fines.

Invisible Value – The average company gains less than $1 in business value from every $14 it spends on technologies. Those same technologies expose the enterprise to enormous enforcement audit risks.

Here's why you need to be concerned: First of all, any business owner or manager should be well aware that former employees very frequently have an ax to grind.  According to research published by the software anti piracy enforcement industry, the majority of whistle-blowers are current or former technology workers or management-level personnel. Who, in your company, knows the most about the products loaded on every one of the computing devices you possess? In polite terms, these are the folks you need to manage. They're also NOT the ones who should be fully responsible for direct oversight of your technology assets.

Here's what you can do: The number one entry barrier to optimizing value in your corporate technology portfolio is to become honestly aware of the realities and issues. As long as your enterprise operates on theory and verbal assurances of compliance and effective life cycle management you will not be capable of delivering value. Theory does not contribute to the bottom line – only quantifiable factual evidence of both compliance and life cycle controls.

Enterprise management—at the highest level—must become aware of, and clearly support, close scrutiny of the entire life cycle of ALL technology-related investments. Failure to do so only perpetuates the existing ineffective practices and procedures. Interestingly enough, failure of upper management to actively support the initiative has statistically, and consistently, been the root cause of a majority of ineffective asset management initiatives.

NEXT: If you have any interest in reducing costs and risks, begin a serious technology asset management program right now—today. Your first step should be to stonewall the software enforcement industry auditors. Since audits are the most immediate and costly threat to any enterprise using today’s technologies, merely eliminating high risk software titles from your exposure field is an enormous step to ongoing savings and improved ROI.

The process is simple: Establish a trusted review team and ensure that all copyright protected products loaded on any computer—or electronic media—are fully and correctly licensed. This is all a matter of brain-work. Cost so far? Nothing but a little of your time. No new products or services to buy…

Do you want more? More details? More ideas? Let us know. The Institute for Technology Asset Management staff is ready and willing to help you learn to take back control of your IT investment dollars.

Thursday, March 10, 2016

How Does Your Carefully Negotiated Software License Become a Complete Waste of Time?

This topic is covered in-depth in The Institute's self-paced, online, professional development modules as part of our Competency-Based SAM Credentials. Institute Credentials are open source, with hundreds of Internet learning opportunities. We never limit you to a single training option.

Your negotiated software license is useless when it's been superseded by that shrinkwrap or clickwrap license your employees never read. We constantly warn professional software asset managers and their companies to steer clear of acquiring either shrinkwrap or clickwrap licenses for any purpose. (Let's call them SCLs.) Read on to discover just one more reason to avoid these common software license scams.

Shrinkwrap & Clickwrap are the most costly & onerous licenses your company can possibly buy or use. And the suppliers would dearly love it if you accidentally locked yourself into one—or more.

This brief review covers a little-known risk of SCLs. Below are the methods used to bind you to hidden clauses within the unread license—clauses that can spell disaster for your company. Even worse, the powerful lobbying interests of the software industry have managed to ensure that this SCL binds you to a license you were never able to read and it's 100% legal.

You should be feeling concerned…

Simple Answer to Our Title Question: Either of these licenses could easily void every previous license you own—including those that you invested a great deal of time and money in carefully negotiating beneficial terms and conditions.

Here's How They Get You: When one of your employees, or a contractor, or a consultant, or any other individual with access to your computers, decides to download an unauthorized product, they can immediately bind you—legally—to the unread virtual license. Within the SCL—the licenses that copyright holders are perfectly aware you will never read—is a clause that automatically voids all previous licenses when the SCL becomes active. The next several clauses in the license will further limit your use and rights in relation to the new product—even support & maintenance coverage—as well as all preceding releases or versions of the product.

Real World: For many software applications, every time you update, patch, or fix there is a carefully hidden check-box that installs a new software product. The default for the box is “accept”. Only by consciously denying that check-box can you eliminate the unauthorized download. Failure to do so places a literally invisible software audit threat on the device.

Instant Solutions: From today forward, EVERY license and agreement you make with every technology supplier must contain a clause that very specifically and very clearly states that the agreement will NOT be superseded by any subsequent agreement or license. You can permit future modifications but only upon activating a clearly written agreement that must be mutually approved and signed by both parties.

Next, you absolutely must ensure that anyone with access to any of your systems is well aware that they are not authorized to acquire and or install any products covered by shrinkwrap or clickwrap agreements—period. This includes the necessity of informing (in written form) all suppliers of software-related goods that THESE are your rules of engagement. If they choose not to comply, they should also be choosing not to provide goods and services to your company and will be removed from your vendor list.

Finally? Enforce the rules—now—and ensure that they continue to be enforced. No exceptions. Not you. Not your CIO. Not your mom. Nobody. Sorry folks, but this is business and you are a prime target for sharp practices that could cost you enormous sums of cold hard cash.

But don't listen to us. It's neither our job, nor our intent, to provide either legal or accounting advice. You pay good money to professionals in those fields. Our task is merely to make you aware of some of these costly little minor details so you can check them out.

If you need any additional information, let us know. The Institute for Technology Asset Management is here to help you cut the costs and risks of business technologies—not to ensure that you pay even more.

Thursday, January 2, 2014

SAM Standards & Best Practices - Great for the big guys. Not so great for the SME...

I've seen small- to medium-sized enterprises around the globe spend tens of thousands of completely wasted dollars attempting to conform to software asset management and/or software license compliance standards & best practices that had virtually nothing to do with their unique environment.

Evidently, Dogbert agrees. This quote from a recent Dilbert comic:
Dogbert: "I'll teach you the best practices of companies that have nothing in common with yours. Those practices will fit your company like a foot in a glove."

While best practices are useful as general guidelines, they are more frequently too complex, to costly, & too dependent on highly controlled environments & high level technicians to genuinely work.

Tired of throwing away good money attempting to implement global standards or best practices?

Do this: Determine what your actual goals are for your software license compliance, software asset management or systems asset management initiative. Conduct a GAP analysis to identify where you need to apply your efforts. Prioritize the efforts to minimize risks & deliver rapid value. Then, permit the process to work for a month or so to stabilize. 

Once stable, repeat. Don't forget to allow for your unique enterprise culture when you initiate these types of changes. Human & organizational change management are critical to your license compliance, SAM, & ITAM/TAM success. 

Take a look at your personal SCCA & SAM credential roadmaps HERE.  Keep in mind that The Institute delivers the only competency-based credentials in the world. These are the skills that employers are genuinely searching for. Credentials that deliver the knowledge you need to succeed - only from The Institute!

Monday, December 30, 2013

Washington D.C. is "upset" with China for counterfeiting & piracy issues?

"...counterfeiting and piracy remain at unacceptably high levels and
continue to cause serious harm to U.S. businesses across many sectors of
the economy,” 

Source: The Hill, 26 January, 2013

Does ANYONE is D.C. have a clue? Have they all become completely brainwashed by the so-called copyright enforcement industry "spin" on reality? Do they genuinely believe that the average Chinese on the street gives a %&$# for the financial impact of their actions on multi-billion dollar U.S businesses? 

Is it possible the root of the issue is that the powerful lobbyists for the video, music, & software industries are driving this attitude? Gee... You think?

I think we can all recognize that China has a completely different perspective on many accepted Western business concepts. Expecting the Chinese government (&/or people) to play the game by our rules is completely ego-centric & consistently doomed to failure.


For example: The current "developed countries" generation has been bombarded by the music, video, & software industries with "anti-piracy educational" materials nearly since birth. Industry agenda copyright education programs have been pushed on the young population for approximately 19 years. Bottom line impact? Zero... Scare tactics simply do not work. (But they're really great for generating all that free anti piracy publicity...)


If we want to reduce the breadth & depth of counterfeiting & copyright piracy - around the globe - we will only do so when we can present a viable alternative to "getting toys for free." And the problem isn't merely China. It's the entire structure of intellectual property marketing that is so antiquated. We "want" the world to buy our products, yet.we continue to price the products according to our own narrow profit expectations rather than the ability of the consumer to actually pay.


We, the developed nations of the planet, have completely forgotten how to price for sales. We continue to blindly push pricing for maximum profits instead of local potential. Guess what? If the majority of your prospects or customers cannot afford to legally purchase your products, the end result is rampant counterfeiting & piracy.


If you genuinely want to reduce music/video/software piracy &/or counterfeiting, find ways to demonstrate the business (or personal) value of the genuine products. As long as we continue to shape the message in terms of its impact on massive multinational western corporations, & not on the value driven to the individual, we will not "get through."


Hey, China... Here's a thought: you can download & use OpenOffice for free & it works just like that over-priced so-called world standard business productivity software. THAT will reduce at least one serious piracy issue.

Monday, September 9, 2013

The Corporate Approaches to Software Piracy & Copyright / License Compliance Need to Move to the Next Generation of Leadership.

This post is in response to an article in ComputerWeekly noted HERE.

The original article discusses how the software piracy landscape hasn't changed much in the past few years. Licensors continue to use unnecessarily complicated licensing schemes & licensees continue to fail to understand as well as fail to manage licenses & licensed products. We CAN, however, change this distressing software piracy trend, but we have to wake up & smell the decaying business processes that expose us to punitive software industry players & their predatory compliance enforcement auditing friends.


It's time to move our outdated software asset management mentalities out of the dark ages & into the next generation of software life cycle management, systems life cycle management, & over-all IT life cycle management.

  • As long as business technology consumers permit the software publishers to control the entire licensing process, we will continue to be targeted by predatory compliance enforcement industry players.
  • As long as the enforcement industry publicity teams use “piracy” as a synonym for "non-compliance", or "honest licensing errors", we will continue as targets.
  • As long as the "compliance landscape" is constantly shifting, we'll be easy targets.
  • As long as the enforcement industry-sponsored "studies" & media blitzes represent the smoke & mirrors world of piracy to the public & our legislators, we'll continue to be targeted.
  • As long as we permit nebulous terms & conditions (such as the literally limitless "right to audit" clause) in licenses, we'll continue to be targeted.
  • As long as our software asset managers are not trained, are being trained only to the enforcement industry perspectives, or are being "qualified" as "professionals" in over-night certification classes, we'll continue to be targeted.
  • As long as the enterprise pays only lip service to software & license life cycle management, we'll continue to be very easy - even clueless - targets.
  • As long as the technical "experts" in the enterprise continue to be in the dark about the realities of license compliance, we'll remain targets.
It's time for the next generation in software asset management professional development & awareness. Business technology consumers need to stop being reactive & start being "intelligently proactive" in addressing the root causes of software life cycle management & compliance assurance.

I've spent nearly twenty years studying the enforcement industry players & their games & it has become evident that our training programs are less than optimal in their approach to compliance assurance (& nearly empty in terms of effective life cycle management). Each & every issue listed in this article & my response could have been minimized by intelligent asset management. Unfortunately, our asset managers frequently are not given the knowledge they need, nor the executive support necessary to address the problems up front - where they could have avoided the confrontation.

For an example of what I'm saying, look through the technician comments on the discussion thread noted in my previous post.

What you'll see, if you can make it all the way through the thread, is that these front line IT personnel DO NOT generally have a clue about compliance or license management. If these people do not understand, or if there is no well-trained/empowered software asset manager in their enterprise, their companies are defenseless - & ripe - for punitive compliance audits.

You want answers? I'll be glad to provide them, along with pointers to the next generation of strategies & tactics for compliance assurance & software life cycle management professional development. Feel free to connect with me at any time.

The Institute for Technology Asset Management publishes its Guide to the Technology Asset Management Body of Knowledge - TAMBOK - the planet's only cost-effective guide to the competencies asset management practitioners need to succeed in the front lines of SAM & ITAM.

Thursday, March 28, 2013

The Next Generation of SAM Training & Certification is Here

Comprehensive SAM - Online, On Demand- At Your Convenience, Without Disrupting Your Busy Schedule!

Reduce the cost of your SAM credential by eliminating unnecessary travel costs. Complete the core competencies of Software & Copyright Compliance Assurance (SCCA) & Software Asset Management (SAM) at your own pace without disrupting your busy schedule.

Follow the link included below to check in to the SAM training industry's only competency-based professional development system. Via our free Learning Management System (LMS) you'll build a credible portfolio of successful course & credential progression.

Read the content overviews & review over 38 cutting edge SCCA & SAM offerings. Take one or more cost-effective 20 minute to 90 minute sessions to try it out, or opt for the even more cost-effective bundled series. The programs come with over 600 pages of Workbooks to help you tailor the content to your unique enterprise & culture. These Institute for Technology Asset Management programs significantly exceed the scope & depth of virtually any alternative SAM programs on the market.

Have questions about the SCCA or SAM credentials? Feel free to ask. I'll provide whatever answers you need to succeed.

Wednesday, November 7, 2012

A Software License Is NOT a Software License

I just read an excellent post on the ITAM Review. It's entitled "Oracle Customer Has Licensing Meltdown" and is located HERE.  Please take time to look it over. Both Martin & the original author have excellent points - points about software licensing issues that we continue to encounter yet never effectively address in the real world.
Software License Terms & Conditions Can Be Changed By The Licensor At Any Time & Without Directly Notifying You.
The key problem is this: As business technology consumers, specifically software consumers, we do not effectively negotiate our licenses. If we did, then we'd actually have to read the license. Having read a software license, and actually understood the inherent instability of the agreement, any sane negotiator would - or rather should - dump the product & the supplier right out of the supply chain and move on to their BATNA.

Instead, we either fail to read the license; or we do not understand what we're reading; or we assume that the copyright holder won't actually enforce the terms; or we treat the acquisition the same as a crack junky desperate for their latest fix - purchasing without regard to future problems.

Here's the bottom line: If you see a clause in a license that looks like this -
Modifications To This Agreement
"We reserve the right, at our sole discretion, to change, modify or otherwise alter these terms and conditions at any time. You can find the most recent version of these terms and conditions on the Site, with the date of last modification noted above. Such modifications shall become effective immediately upon the posting thereof. Therefore, we encourage you to check the date of our terms and conditions whenever you visit this Site to check if they have been updated. You must review this agreement on a regular basis to keep yourself apprised of any changes. If you do not agree to the revised terms and conditions, your sole recourse is to immediately stop all use of the Services. Your continued use of the Services following the posting of modifications will constitute your acceptance of the revised terms and conditions."
It means you do not have stability relating to your existing license terms. This basic wording will show up in your original license as well as contract renewals, updates, upgrades, (even patches) so look for it BEFORE installing. Once you have activated the license by installing (or even accessing) the product, you are stuck with the new terms.

Keep in mind that each of these license agreements also includes a "Right to Audit" clause that will be enforced by the licensor. During that audit, you will be responsible for conforming to the CURRENT terms & conditions for each product. If you are not up to speed on those changes, the auditors don't particularly care. You will pay the fines & penalties for being out of compliance.