Curious how MBB's cybercapabilities are viewed within the cyber world. Experiences, thoughts?

like
Posting as :
works at
You are currently posting as works at

I am a McK vet and a cyber partner at PwC. All the MBBs struggle here as they do not have staff with years of cyber experience so even assessments and strategy can be seen as uninformed and easily contested by the CISO (who carries a lot of weight due to the scarcity of good ones and the premium a quality CISO can command).

This hurts their credibility even in areas such as Cyber Org, Operating Models, Ops Improvement, etc. all of which are key strength of theirs outside of cyber.

Their fee structure can also be challenging for them. This is especially true in more hands on keyboard areas such as controls implementation, testing and such. Incident Response is something they really won’t be able to do with their present approach and this limits an attractive entry point to larger remedial work.

All the MBBs should focus their cyber efforts as adjuncts to their strong Digitial Tranformation business.

That said, I’m confident the MBBs will sooner or later figure it out as they are smart, well funded, think longer term and know they need relevancy in this area. It will just be painful, success will be decidedly non-linear and will require them to step out of their comfort zone.

They will all need to bite the bullet and bring in senior people (Director/Senior Partner) with credibility and the ability to pull quality people people from other firms. This will definitely be a cultural challenge for them. In the 1990s McK bought a firm that became the BTO and gave them credibility in IT. It was a multi-decade effort to truly integrate them due to the unique culture of MBBs. They may have to do this again for cyber.

like

Thank you! Why do you think they need relevancy in cyber? In my opinion cyberstrategy is a nascent market with strong competition and there is a risk of diminishing their brand because of lower quality work

Most individuals at cyber firms don't know who the MBB are and most hate consultants.

like

I’ve seen MBB do some cyber related work but I think it’s more of a management oriented cyber work

like

McK is the only group I've seen in MBB do pentesting, and that's exclusively internal.

In the arena of implementation and hands-on maturity development work, Big 4 firms tend to get a lot of work in addition to specific vendors (e.g. CyberArk, FireEye) or boutiques (e.g. Trimarc).

For strategy, I see a lot of competition between Big 4 and MBB.

For proactive services, I see a lot of work going to boutiques (CrowdStrike, Mandiant, SpecterOps etc).

Tl;Dr depending on the area you're looking at, MBB has a relatively small breadth of coverage, but are high performers in their fields. Most people I talk to have no idea what MBB even means.

like

Agreed PwC 1. I'm a Senior Consultant at Mandiant and I do many protective services, IRs and strategy. For almost every engagement, I'm touching a keyboard.

In my firm, MBB services aren't really taken on until the Director level or higher.

I don’t think they are viewed highly by the cybersecurity organizations of companies. Cybersecurity is a specialized field and companies with a cyber background (like my employer) or a tech background (like Accenture or IBM) are seen as the best

like

BCG/Mck doesn't do technical work like pen tests or IR. Our cyber people are management consultants more likely to engage with WEF than def con.

My impression is that Bain's "cyber" people are mostly PE with industry exposure.

Impression-wise, D1/D2 are about right.

Great, great PowerPoint with amazing access to data on things like spend metrics. Otherwise, absolutely forgettable based on the McK work I had to deal with at a client briefly...

Thanks for the replys. I'm looking for a place which has a strong cyber strategy practice. Since mbb does mainly strategy work I was wondering if they also did cyber.
Seems that Deloitte and Accenture are better choices for this.

^ on top of this, the pricing models really do have an affect on the work. As PwC 2 mentioned, MBB is extremely expensive. Why should I hire them to implement a solution when Accenture can charge a similar cost for several more months of hand-holding and assurance that everything is done properly?

Accenture has a lot of highly technical people, and I see a lot higher percentage of hands-on work there. Unfortunately I don't have a lot of proposal experience so I haven't seen the strategy side of the competition

Related Posts

Anyone here with experience as a Product Manager? I’ve close to decade of consumer lending experience including Sales/Advisory, Supervisor and Underwriting. I have have been looking to pivot into a more impactful role this year. I am due for an interview for a Product Manager next week. The company ticks all my boxes but the job description a bit vague. I will be grateful if anybody willing to share what the day role looks like and what I need to look out for in an interview. Thanks. Cheers.

Where in Healthcare Consulting can a registered nurse succeed? I read about healthcare consulting companies and the services they offer and they appear heavy IT/comp-sci based. What are healthcare consulting specialties where an RN can leverage their clinical background?

like

Interested in UX but have no experience or much knowledge about it. What kind of roles were you in before you got into UX, how did you get there, did you have to get a certification, and what does your day to day work consist of? Is it more technical, psychological or design based?

like

Is it more worth it to go into FDD at a regional firm now, or hope that my current big 4 will transfer me come spring 2021?

I'm kind of in the mindset of only doing FDD at big 4, otherwise I'll go straight to industry. Am I being too down on mid-market FDD experience and the related exit ops?

Also, I can't go the route of doing FDD at a different big 4. Already got rejected by all of them cause I'm not in audit (but have CPA).

like

Does anyone have recommendations for thought leaders/influencers in the M&A space? Looking for blogs, books, YouTube videos? Not currently in the space, trying to learn more as I’m thinking about a pivot after a few years in consulting/startups

likehelpful

I've recently went to a restaurant and saw a robot waiter, I thought that was the coolest thing. What do you all feel about this shift in the restaurant industry?

like

What is the value in professional certifications? ACCA, CFA, CIPD, etc.

like

Is MBB serious about DEI? How is the environment for minorities (both at the bottom and top, including for East/South Asians)

like

It's my first month in a new job as Product Owner. I went from a company that digital product development was their secondary focus along with consultancy services, to a company that their only focus is the product. The difference in scale as well as the different domain, certainly feeds into my imposter syndrome. What are the things I should focus to achieve within my first few months at the new job?

Anyone here broken into real estate private equity from big 4 consulting? What steps did you take to jump into RE PE? What gaps in knowledge did you have and how did you fill them? Outside of the knowledge gaps what other things do you think you needed in order to get into RE PE?

like

CFP & ChFC looking to change firms. Currently in a bank program, but not a large portable book to bring over to the next firm. Over a decade experience and about to finish up my MBA. Currently nowhere near the income level I want to be. Any suggestions for a good program to go to for my next move?

like

Anyone ever considered contractor gig in Meta/Facebook or any other big players in tech? I'm full-time in a smaller company and it's pretty stable. Wondering if the move could be worthwhile. Mostly want to explore other areas. Other things to consider: planning for babies in the next 3-5 years; maternity leave in current position is basically what's legally required.

like

I haven't been reading recently but I want to start again! Any good book recs?

Past likes include:
Dune (1&2 - series got a little weird later on)
Enders Game
Michael Crichton's Sphere & Prey
Gates of Fire
Loved the hobbit but that's probably all I could do with that genre as I'm not super into fantasy/magic really.

I like sci-fi but I could get into a good adventure if consensus is its worthwhile. Not really into nonfiction. Thanks!

like

What is the value add of doing a residency if you’re an MD vs. going straight into consulting with the end goal of pharma or buy side work and starting your business career earlier?

like

McKinsey & Company Hi all! Any fishes at BCG and/or McK have time to chat sometime within the next few days/weeks?

I’m a consulting analyst at Accenture, really interested in strategy work (mainly tech/software clients but open to all backgrounds) hoping to make the jump some time next year. I’d very much appreciate connecting to understand your journey with the firms and the work you do.

Thanks in advance, and happy holidays!
Boston Consulting Group McKinsey & Company

like

How do I get a job as a Mechanical Engineer if I dont have experience?

I couldn’t get an internship while in school. I have a BS in ME and projects from school under my belt. I’ve also passed the FE exam. I’ve been mostly just doing CAD for a company for the last year by creating minimally dimensioned drawings and moving parts around in assemblies. I want to evolve in my career and be doing more. I worked so hard to earn my degree and I feel like I’m not even using it. But who will hire me?

like

I am a QA lead looking to break into google Spotify or meta as a program manager or project manager . Can someone please guide me on what does it entail to be a PM at these companies?

like
like

Seeking advice as a junior level employee in strategy land — what are your thoughts on where the agency landscape is headed now? Should I stick with it in the coming years? Should I jump ship and seek comms/brand work elsewhere?

Any and all thoughts appreciated!

like

I am a 2nd year associate at a plaintiff’s firm specializing in toxic tort cases (individual). I’ve had the opportunity to be third chair on a trial, and will likely be second chair in an upcoming trial. However, given the track record of the firm and the amount of money at stake in each case, I am afraid I won’t get any first chair experience, if any, for at least another 5-7 years. I am considering staying at the firm but trying to get trial experience through side Pro Bono work. Thoughts?

like

More Posts

Anyone work at Instrument’s PDX office? Just applied for the Senior Strategist position. Have both UX and Brand experience. What’s it like to work there? Looking to move back to the PNW!

I’m a private immigration attorney whose interested into transitioning into a high level federal government attorney position in the future (not in this administration). Ideally, I’d love to work in the solicitor general’s office.

I’m only a year or two into practice and am wondering if there are any tips to best position myself for this type of position? I don’t anticipate making any moves that way for at least 5 more years. No clerking experience or law review, so that’s -2 points for me

like

Can anyone please refer me in LTI.

I have 2.8 yrs exp. Skillet - Azure Cloud, Devops. Open to any new latest technology as well.

I am serving notice period.

Thanks for your help

Hi Guys, currently being considered for a security developer role at Siemens Bangalore. What would be a fair compensation for my profile - BE, MSc, 1 YOE at Siemens (intern)?
Any advice is appreciated, thanks.

like

I finished my internship at EY LLP (Feb-Jul) after nearly 6 months. I've been promoted to Senior Analyst. Is there a set time of month that I must be in this position in order to be considered for the next promotion?


Otherwise, is there a mid-year promotion?

like

Hi! Can anyone provide insight into how I can increase my chances of getting a position at Microsoft? It's in the Financial Services Group and I think I'd be a good fit. Any help is appreciated!

Fellow 🐟 any thoughts? Received an offer from Deloitte -> Role Manager, Base 180K HCOL, YOE 8, Current Base -> 150K and may get close to 160K in 3 Months. Is it worth the jump? Pros in current role -> High Visibility due to small practice, 45 to 50 Hr work week. Will be SM in next 2 to 3 Years, Cons - TC, Brand Value, Mid Tier Clients. Any opinions?

like

Bhagwan ka dia hua kafi kuch hai, 5.5 saal ka experience hai, 18 LPA ka package hai, 3 saal ka Selenium, TestNG, BDD, Java mei experience hai. Bass kami hai toh ek lambe 35-40-50 LPA ke package ki.

Hence I need help, I will be looking for a switch in the next 2-3 months, but this time I want to make it big. I am ready to work hard, just need guidance from you, as to how to improve myself and gain a good package along with great work culture. Madad kro yar, gareeb ki dua milegi😁 TIA 🙂✌️

likesmart

Hi Guys, I am 5.5 years Java Developer and I have offer from JPMorgan Chase and Walmart .

Jpmc: 50% on current fixed + jpmc benefits Walmrat: 50% on current fixed + yearly bonus + stocks.

Please help me choose which will be better, mainly looking for brand value, work life balance and yearly hikes.

like

For people who work at Wells Fargo or have knowledge of Wells salary, expecting an offer for Senior Vice President in Dallas, TX. What salary should I expect/ask for? Any advise would be appreciated!

Hi. I have 6.4 years experience. I have offers from Randstad offshore services (direct) and mindtree. Both are offering good packages. Which company is good?

like

What’s the thought that keeps you from giving up?

like

Hey - anyone at Deloitte Nashville who would be willing to refer my application?

Is it true for Assoc 602 level who hasn't completed one year, can't have S. My managers(functional and local) gave this reason for my OOO?

My functional manager personally messaged me later and said his recommendation is SOS but they cannot work past through the rules of less than 1year

like

Should I put $20K towards my student loan balance of $230K before the no-interest period ends or max out my 401k, which I have contributed nothing to this year. I’m 25. Employee matches 4%.

like

Will I be overpaying, if I get a 2017 Lexus RX350 AWD with 49.5 K miles on it for 32K out of door from a dealership near me? This is my first time buying a used car and also anything outside of a Honda. All insights are appreciated.

like

Would you take a freelance gig that would be a promotion (with potential to join full time) with a smaller company whose values you really agree with, OR a full-time offer for a lateral move with a larger company with teammates you know and trust? Of course factoring in all the nuances of covid. TIA!

like

Saw some people from EY TAS change their titles to Strategy and Transactions on LinkedIn. Is this just a fancy name change the group did or are EY TAS folks now doing strategy work in addition to the typical FDD work ?

like

Anyone have tips on culturally relevant (read Black) parent podcasts or parent preparation programs?

I’m looking for something similar to New Mom Boss but for us

Trying to transition from my full time job now to freelance. Anyone hiring? Good recruiters you know? 8yrs exp, background in tech/strategy/creative, worked in both small and large agencies.

like

Additional Posts in Cyber Security Bowl

What’s a good taxonomy for defining requirements for logging & monitoring? (i.e., apps, db, infra, etc.)

likefunny

What are exit ops for Big 4 Cybersecurity Consultants that are non technical (Strategy/Risk)?

like
like

Anyone here do post-breach data mining? Being pursued to start a practice line doing this and trying to understand market value.

like

Has anyone made the move from cyber security at the Big4 to cyber security for media companies? For example Disney or Warner Bros.

How did you manage it?

like

Privacy fish - Anyone taken the CIPM and can share what the exam is like?

Content outline seems like application of standard consulting approach, so how do they test it on an exam?

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

Anyone else at CyberArk Impact this week? Anything exciting going on?

Deloitte Cyber, how long did it take you to receive an offer after final interview?

like

Tell me it’s not true.

Post Photo
funnylike

AWS Cloud question- what the difference between an SCP and IAM? Thanks in advance

like

Any BCG Platinion Cyber folks here?
What kinna work do you guys do? Planning to make the switch after 5 years with Uncle D. Wanna hear from you guys about culture, projects and areas of expertise.

like

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

Any recommended study material for CIPP and/or CIPM (still debating the two)?

I have a nontechnical undergrad degree and 4 years of experience in the cyber industry. Should I invest my time in getting my CISSP / other certs OR getting a technical Masters degree like CS or MIS?

like

Always bragging about how awesome they are. Awesome people dont brag. They just are

like

Cissp cert is as much hard as it seems? Much more than cisa?

like

Today I passed CIPP/US, and earned Security+ in early August. Interviewing for a cybersecurity role at Deloitte tomorrow! Super excited! Interested to connect with fish at Deloitte, especially Deloitte Global. Thanks!

like

I’m a woman in my mid 20s and constantly face situations where people outside of cyber (still within the company) that I’m dealing with (older men in particular) who always push back against my cyber/technical recommendations even with managers cc’d. I studied, earned certs, and worked hard to get to where I am. Is it bc of my gender and age? In all honesty, I’ve written recommendations that male counterparts voiced in the past that had ZERO pushbacks.

like

New to the U.S., is the Healthcare Industry (via HIPAA), the only industry in the U.S. that legally mandates having a designated Privacy Officer? So for example, although GLBA has obvious privacy requirements, unlike with healthcare, financial institutions in the U.S. are not mandated by law to have a designated Privacy Officer?

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal