Mood swings

I’ve already mentioned that one of the Chamber’s security team’s responsibilities was taking care of the firewall infrastructure. That included not only maintaining and configuring the existing equipment but also planning the evolution of that infrastructure, including capacity planning and defining the network topology.

At that time, the Chamber had plans to deploy a wireless network in every building and significantly increase network capacity. The network team planned to use 40 Mbps trunks as the backbone. With that increase, the firewalls would become a bottleneck because they didn’t have the capacity to process traffic at that scale. That forced us to re-evaluate the whole firewall infrastructure to make sure it was sized according to the new plans.

At that point, finding firewalls that could handle that level of throughput wasn’t easy. The Chamber used CheckPoint, which was supplied mainly as software. There were appliances from other manufacturers that promised greater capacity, but with proprietary solutions. Even though we thought the network project was oversized, we couldn’t simply ignore those requirements and undersize the security infrastructure.

The process ended up being pretty complex because it was heavily based on rough estimates. We didn’t have enough real data for precise capacity planning. In the end, financial constraints weighed significantly on the decision. To reduce costs, we ended up accepting a maximum capacity lower than the one planned in the network project. In short, it was a project based more on assumptions than on concrete data, and budget ended up being the main factor.

When a Brazilian public agency buys software, systems, or hardware, it’s common to also include training for the employees. That ensures the availability of funds to train the teams that will operate those solutions. At the Chamber, we tried to include this kind of training whenever possible. Since the procurement process doesn’t specify the supplier ahead of time, it makes sense to include training provisions, as any solution meeting the requirements could win the bid, even one that the internal teams don’t know how to operate. In one of those purchases for the security team, we included hands-on training, which would be held in Brasília, at the office of a partner of the manufacturer. For those who know the city, it was in one of the office buildings above Brasília Shopping. The training would last a week, Monday to Friday.

For a personal reason, I ended up missing Monday morning, but it had already been arranged that I’d join the course starting in the afternoon. At lunchtime, I met my colleagues at the shopping mall’s food court and we went up together to continue the training. That’s when I discovered the course had barely started: there had been a problem with the instructor’s arrival from São Paulo, and on top of that, the computers prepared for the hands-on part weren’t working properly. That afternoon, the instructor was only able to cover the theoretical part. Before the end of the day, we were told that the training would be moved to another location with adequate infrastructure. From the next day on, it would be held at the convention center of a hotel in the Setor de Hotéis e Turismo Norte (SHTN), which ended up being more convenient for me because of the easier commute.

From then on, the course started working better. We even tried to include the instructor socially, taking him to lunch at some restaurants in Vila Planalto. But by the end of the week, I made a mistake I regret to this day. During a coffee break, while chatting with a close colleague, I told the story of the gringo who had missed a presentation because he had spent the night partying. It wasn’t my intention to make any association with the instructor, but he overheard the conversation and understood it that way. He was visibly annoyed.

From that moment on, the mood changed completely. Despite our efforts to welcome him throughout the week, he began to conduct the course in a strictly technical and distant way. At one point, he commented that the problems on the first day weren’t his fault: he had had difficulties with the flight, the partner company hadn’t been able to prepare the equipment, and that had nothing to do with him going out the night before. It became clear he had overheard the conversation. I hadn’t even been present on Monday morning and had no concrete information about what had happened. Still, he felt offended. I thought about clarifying, but didn’t.

A story told as a joke ended up causing a misunderstanding. Looking back, it’s possible the stress caused by the problems with the training contributed to his reaction. But either way, I was the trigger.

The main lesson I took from that is that context is everything. The intention behind what is said doesn’t matter as much as the impact it may have in another context. In the instructor’s context, everything was already going wrong, and any comment along those lines could sound like direct criticism. In my case, what I lacked was context: I hadn’t followed the events of the first day and didn’t know exactly what had happened. Since then, I’ve become more careful with this kind of situation, always trying to consider the listener’s context. Even so, it’s hard to know exactly how much context the other person has — or thinks they have — about what we’re saying.