Read Software Trends

Showing posts with label Data. Show all posts
Showing posts with label Data. Show all posts

Wednesday, October 30, 2019

Mid-State Lumber Improves Real-time Data With DMSi

Mid-State Lumber is a family-owned business in Branchburg, NJ that has grown significantly since its founding in 1976, adding multiple locations and expanding into new territories.

DMSi's Agility has proven to be a good fit for Mid-State Lumber. The industry-specific functionality is an asset for the company. “I have worked in every department in the company, and I find that Agility is helpful in every area,” said Maria Hall, Mid-State Lumber’s primary system manager. “Anything that you want to do from quoting, to automated processing, to reporting, to viewers…you name it. Agility does it all. I love the system.”

Agility allows Mid-State Lumber’s departments to coordinate effectively. Because Agility provides real-time data, everyone sees current information. There’s no need for departments to update each other over the phone or email. Real-time data makes it easier for the Mid-State Lumber team to provide excellent service. Employees in every area of operation know information in Agility is current and accurate. There’s no need to double-check that a product is available before placing an order or scheduling a delivery.

Agility also allows Mid-State Lumber to be extremely responsive to customers’ needs. Credit manager Anita Toupin appreciates that results are instant: “I love the way it’s real-time. As soon as a guy enters an order, I have receivables change. If a customer is past due and on credit hold, as soon as we get checks and apply them, it frees up their account.” Agility has also helped Anita reduce the paper trail common in many offices. Agility’s reports and queries pull up all the data she needs in one screen. For instance, she can run a report to find all invoices past due by a certain number of days. Or she can use the A/R Credit Details screen to view an account’s credit information across all branches.

The DMSi team has worked closely with Mid-State Lumber and developed solid relationships with their counterparts. As a veteran employee of a service-based company, Anita is keenly aware of the impact those relationships can have: “DMSi is like a family. It really is. They treat their customers the same way, and that’s a really positive thing.”

Learn more at the DMSi newsroom

New Software Research Guides Available
Finding that you cannot keep up with all the changes in the latest software? Want to know how the software's features and functions can assist you? Please contact sjay@bswllc.com for more information about these latest editions.

For 2019 Distribution and Manufacturing Software Guide:

Visit our website to learn more about the Brown Smith Wallace Advisory Services at http://www.software4distributors.com and to use our Software Features Comparison Wizard, visit http://www.software4distributors.com/compare/default.aspx.
Also, read our 2018 Mid-Year Supplements at http://www.software4distributors.com/downloads/2018_Mid_Year_Supplement_Blog.pdf?utm_source=DownloadPDF&utm_medium=Blog&utm_campaign=2018Supp.

Developed through a partnership with Industrial Distribution, Industrial Supply, Contractor Supply Magazine and Brown Smith Wallace Advisory Services, these 12 page Supplement Guides provide valuable, independently researched information. Each Guide details software company information, identifies vertical markets, highlights functions and technology features, new developments to the software package, shows graphs of the user range, basic entry price point, sales channel (how and where the software is sold), along with company contact information. The Supplement Guides provide everything you need to know when beginning your software selection and evaluation process.

 
Follow Us on Twitter
Follow Us on Twitter

Wednesday, March 13, 2019

Wagner Machine Co. Grows Business With ECi's M1

Wagner Machine Company in Champaign, Illinois, was founded in 1982 as a precision machine shop. Today, Wagner operates out of a 30,000 square foot plant that houses more than 20 CNC mills and 20 CNC lathes. Over the past 30-plus years, it has seen steady growth, but sometimes, growth can also bring problems. As the company grew, management found the largely home-grown systems that were being used to run the business simply unable to keep up.


“Before we brought in ECi's M1, we were using six different software programs to run the company,” Wagner recalls. “None of them actually spoke to each other and one of our key programs was crashing frequently because the database could not handle the volume and complexity of the business we were processing.”


Fast forward to today—with the company now using M1 to steer the ship—and those six different programs have been replaced by a single system that seamlessly integrates all the company’s critical management and data functions, providing the kind of efficiency and productivity the Wagner team needs to maintain its solid growth pattern.


Wagner points to several features that made M1 the right choice for the company. “I really like the way M1 gives you the ability to have multiple modules open at the same time,” she says. “Switching back and forth from Estimating and Quoting to Purchasing, for example, is seamless with M1. You don’t need to close out one window before switching to another and you certainly don’t need to open up a second instance of the program and use up a second license,” she points out.


M1’s ability to provide quick and easy access to critical business information also earns high marks. “M1’s search functionality is incredibly robust,” says Wagner. “I can modify M1’s search grids however I want and then save my preferences in the system so they’re there when I need them again—that’s a huge plus for just about any aspect of our operations.”


But even with all that growth, the basic philosophy the Wagners put in place continues to drive the company, due, in no small part, to the power and flexibility M1 has provided. That’s good news by any measure. And what’s even better is that regardless of where future growth may take the company, M1 will be more than able to help keep it healthy and profitable.


To learn more, visit the ECi Newsroom.


New Software Research Guides Available
Finding that you cannot keep up with all the changes in the latest software? Want to know how the software's features and functions can assist you? Please contact sjay@bswllc.com for more information about these latest editions.


For 2018 Distribution Software Guide: http://www.software4distributors.com/downloads/2018_Distribution_Software_Guide.pdf?utm_source=DownloadElectronic&utm_medium=Blog&utm_campaign=2018DSG


For 2018 Manufacturing Software Guide:
http://www.software4distributors.com/downloads/2018_Manufacturing_Software_Guide.pdf?utm_source=DownloadElectronic&utm_medium=Blog&utm_campaign=2018MFG


Visit our website to learn more about the Brown Smith Wallace Advisory Services and to use our Software Features Comparison Wizard.

Also, read our 2018 Mid-Year Supplements http://www.software4distributors.com/downloads/2018_Mid_Year_Supplement_Blog.pdf?utm_source=DownloadPDF&utm_medium=Blog&utm_campaign=2018Supp
Developed through a partnership with Industrial Distribution, Industrial Supply, Contractor Supply Magazine and Brown Smith Wallace Advisory Services, these 12 page Supplement Guides provide valuable, independently researched information. Each Guide details software company information, identifies vertical markets, highlights functions and technology features, new developments to the software package, shows graphs of the user range, basic entry price point, sales channel (how and where the software is sold), along with company contact information. The Supplement Guides provide everything you need to know when beginning your software selection and evaluation process.





Follow Us on Twitter


Follow Us on Twitter

Monday, November 19, 2012

3 Questions Every Distributor Should Ask About Analytics

Data doesn’t speak, it only responds.

Turning data into usable information is the responsibility of the user. It’s up to you to analyze your mountains of data to seek out the answers you’re looking for.

Whether you’re a multimillion-dollar company or a small start-up, distributors must answer three analytics questions:

1) Is my business doing OK? Or more specifically, how is your industry doing?

2) Which KPIs should I be focusing on? Distributors should ask: How are sales doing? Margin? Inventory turnover? Receivable collections? Personnel productivity? These things really make the difference.

3) What do my customers need? It’s not enough to focus your efforts on the 10 biggest customers because those 10 customers aren’t necessarily the most profitable customers. They may, in fact, be a resource drain.

Read more on the Advanced Distribution Today blog.

The Brown Smith Wallace 2012 Mid-Year Supplements are available. Visit our website to download your copy!


Friend Us on Facebook Follow Us on Facebook


Follow Us on Twitter Follow Us on Twitter

Wednesday, October 17, 2012

Are You Using Your ERP To Create Better Pricing?

When your salesperson goes in for a pitch, where does the pricing model come from? Instincts — or hard data?

Unfortunately, most companies rely on the former, letting sales reps’ knowledge of the market dictate the organization’s pricing. It’s a bad idea, according to an article on the Modern Distribution Management website. Companies should use their ERP systems to analyze the previous 12 months of transactions to segment customers, products and pricing sensitivity. Using big data analysis, management can determine how much a customer would be willing to pay for an item. That pricing information can be unlocked right from a distributor’s data — and turned into valuable, actionable knowledge the sales team and management can use.

Read more on the Advanced Distribution Today blog.

The Brown Smith Wallace 2012 Mid-Year Supplements are available. Visit our website to download your copy!


Friend Us on Facebook Follow Us on Facebook


Follow Us on Twitter Follow Us on Twitter

Monday, October 1, 2012

3 Technology Trends Distributors Must Adopt

Being tech-savvy is important for distributors. As the economy improves, interest rates drop and businesses look into improving their lines of trade, more executives are replacing or updating their outdated ERP software. How can wholesale distributors tap into the latest technology trends? There are three developments they can take-on: cloud, big data, and adoption rates.

Read more on the Advanced Distribution Today blog.

The Brown Smith Wallace 2012 Mid-Year Supplements are available. Visit our website to download your copy!


Friend Us on Facebook Follow Us on Facebook


Follow Us on Twitter Follow Us on Twitter

Wednesday, June 16, 2010

How to Adhere to Payment Card Industry Data Security Standards by Ron Schmittling

To learn more about PCI Compliance Review:
http://www.software4distributors.com/resource/default.aspx

To learn more about IT Security and Privacy:
http://www.software4distributors.com/evaluation/registration.aspx

PCI Compliance Primer
As consumers rely more on debit and credit cards as opposed to cash, merchants are facing increased risk exposures if they don’t have proper security measures in place. Cyberthieves troll for information on merchant networks, which has resulted in significant security breaches that have made headlines.

In 2004, a consortium of credit card companies, including Visa, MasterCard, Discover and American Express, banded together to set Payment Card Industry (PCI) Data Security Standards. These standards direct merchants that process, store or transmit credit card information to maintain a secure environment. And if your business accepts credit or debit cards, the standards apply to you.

Business owners have to comply with those security standards and implement safeguards to protect customer information. This article will discuss how your company can meet PCI standards and protect against security breaches.

What is PCI compliance, and who must comply?
The three keywords for PCI compliance are process, store and transmit. If your organization processes, stores or transmits credit card information, you must maintain a secure environment as laid out by the PCI standards. So, if customers or vendors use debit or credit cards to make purchases from your business, you must be compliant. This includes meeting 12 standards, which can be broken down into six key areas: building and maintaining a secure network; implementing safeguards to protect cardholder data; maintaining a vulnerability management program; applying strong access control measures; regularly monitoring and testing network security; and enforcing an information security policy.

Your policy will ultimately drive the compliance process, so the first step is to take a security inventory of your business to determine how compliant it is, what security measures are in place and what weak spots must be addressed. An outside adviser with experience in security and privacy can provide feedback on how to structure a plan. This framework will set the tone for your internal compliance strategy and help protect your business.

PCI security standards are not laws; they are a method of self-imposed regulation by the consortium of credit card companies. There are no federal mandates in place, but there is a move in that direction since some states have started to pass laws or require organizations to comply with PCI Data Security Standards. This trend is expected to continue in association with the Data Breach Notification Laws movement.

What are the consequences of failing to comply with the standards?
At their discretion, payment brands such as Visa or MasterCard can fine acquiring banks $5,000 to $10,000 a month for PCI compliance violations. Banks are likely to pass these fees on to noncompliant merchants. Many banks have begun notifying noncompliant merchants of their need to comply or face fines.

You should review your merchant agreement and note any penalties and fees for noncompliance, which can include prohibiting merchants from processing credit card transactions, higher processing fees and other restrictions. Any fraud loss associated with a compromise in security may be borne by the merchant starting on the date of the security breach. Depending on the level of security negligence, the FTC could become involved and impose significant federal fines, up to $250,000 and/or up to five years in prison.

Not knowing is not a viable excuse for noncompliance and could cost you and your organization. It is your responsibility to understand your merchant agreement and what the PCI standards mean to your organization.

What steps can a company take to become PCI compliant?
Compliance responsibility depends on your merchant level, and there are four levels as defined by PCI Data Security Standards. Level 1 merchants are those that process more than 6 million transactions a year. It is important to note the annual transactions are measured in volume, not dollars. Level 2 includes merchants that process 1 to 6 million transactions per year. Level 3 covers merchants with 20,000 to 1 million eCommerce transactions per year. Level 4 includes any merchant with fewer than 20,000 eCommerce transactions per year, and all other merchants with fewer than 1 million transactions annually.

Companies in Levels 2, 3 and 4 follow the same compliance process that includes completion of an annual self-assessment questionnaire and having quarterly network scans performed by a PCI Approved Scanning Vendor (ASV). The results are submitted to the merchant’s bank. Level 1 merchants follow similar procedures, but also are required to have an annual on-site review completed by a Qualified Security Assessor (QSA), a PCI-certified provider and have an annual network penetration test performed. The QSA will submit the merchant’s Report on Compliance to its merchant bank. The PCI Council lists ASVs and QSAs at
http://www.pcisecuritystandards.org/.

Where should an organization start on its PCI compliance initiative?
The most important step is to set an internal policy of how you’ll address PCI compliance and information security. Too many times, organizations rush into identifying a new product they think will fix PCI compliance or information security problems instead of organizing their efforts around the organization’s overarching policies and processes.

Once that policy has been defined and implemented, an organization can begin to enforce it and truly drive its compliance initiatives. But compliance starts with your information security policy and security controls. Many organizations struggle with where to start, as PCI compliance can be a daunting and complex task. Reaching out to a QSA to kick-start your PCI compliance efforts is a great first step.

What are the PCI DSS main areas?
The actual PCI Data Security Standards include 12 major requirements for validation and certification under six main auditing areas or "control objectives". All of the compliance areas include basic security rules that most merchants and service providers should already have in place, or have a familiarity with them when audited.

The six main control objectives for PCI DSS compliance and validation are as follows:

  • Build and Maintain a Secure Network

  • Protect Cardholder Data

  • Maintain a Vulnerability Management Program

  • Implement Strong Access Control Measures

  • Regularly Monitor and Test Networks

  • Maintain an Information Security Policy

What is a QSA?
QSA stands for Qualified Security Assessor. It is a certification obtained by experienced security consultants that enable them to conduct the on-site data security assessments for PCI DSS Compliance. QSA's are required to recertify every year by attending training provided by the PCI Council and passing a rigorous exam. A recertifying QSA must also obtain annual professional education credits from training and other experiences in order to retain certification. May QSA's also maintain other certifications through their work as security practitioners such as CISSP, CISA, CISM, etc.

What are the requirements for becoming a QSA?
The PCI Council requires all QSA’s to be full time employees of a Validated QSA company. The security professional must complete a thorough application process with the PCI Council and undergo and pass its three-day QSA training course. A closed-book exam is administered which must also be passed to receive the official QSA certification.

In addition, the QSA must meet the following minimum requirements, submit a current resume with the PCI Council, and complete a background check from the QSA company:

  • CISSP, CISA or CISM Certificate

  • 5 Years of IT Security experience

Why are QSAs important?
PCI QSAs are trained by the PCI Standards Council to understand the intent and rigor required to meet the PCI requirements. Only a QSA can certify PCI compliance and working with a QSA is the best way to ensure your implemented controls will meet the PCI compliance requirements. And of course, getting it right the first time saves time and money.

QSAs are required to strictly adhere to the DSS audit procedures document and complete the mandatory Report on Compliance required for PCI certification and validation on behalf of the merchant or service provider.

Many QSA’s help companies perform their annual PCI self-assessments also. Self-assessments are much easier said than done, as most merchants and service providers simply lack the knowledge and understanding of PCI to self-assess with no help. A QSA can help bridge the knowledge gap and quickly assist with completing your self-assessment.

Further, a QSA can also assist in recommending various hardware and software solutions for PCI compliance along with giving a company excellent guidance on how to meet the rigorous demands of PCI Compliance. When it comes to compliance and certification for PCI, you need to use a QSA.

What types of services do QSA’s typically provide?
QSA’s typically provide the following types of services:

  • On-Site Data Security Assessments (PCI "Audits"),

  • PCI Gap Analysis or Readiness Assessments,

  • Remediation Services for areas of PCI deficiency,

  • Project Management,

  • General PCI consulting and advice.

Depending on the size of the company, its complexity, and the number of distinct credit card processes, most engagements will last anywhere from 1 - 6 months.

Level-1 Merchants and Level 1-2 Service Providers are required to have a QSA to conduct their annual on-site data security assessment. Level 1-2 qualifiers are that they have more than 6 million transactions. Level 2-4 Merchants and Level-3 Service Providers do not have required QSA audits and may use the PCI Self-Assessment Questionnaire to self-certify.

What are the pros and cons of hiring a QSA versus doing it yourself?
There are pros and cons for both ways of performing PCI compliance, but the pros outweigh the cons in selecting a QSA to assist with your PCI compliance initiatives. QSAs provide third-party validation which proves 'due diligence', in addition, they know the data security standard and how it is to be applied to different types of organizations. The cons are the usually the cost of hiring a QSA. Yet, the costs to the organization when considering ‘doing it yourself’ should also be considered - that is, resources needed to assist with PCI compliance plus resources from other strategic, profit-generating initiatives. Another con to consider is that it can be difficult to get up to speed on all PCI requirements, which could provide an unfortunate opportunity for merchants to miss key areas, controls, and dates. In the long run, it may be far more economical to hire a QSA.

What are the benefits of using a QSA and becoming PCI compliant?
In the past few years as cybercrime has sky-rocketed it's necessary to do more to protect companies and customers alike. The PCI requirements might seem difficult to get a grasp on; however, they are beneficial for customers, merchants, and the credit card industry. Merchant and service providers have to meet a number of measures from QSAs and ASVs in order to be PCI Compliant.

There are a number of significant benefits to becoming PCI Compliant and utilizing a QSA to assist, including:

  • 'Trust'. Consumers greatly benefit from doing business with PCI Compliant companies because it means all of their sensitive information is kept both safe and secure.

  • Means that your business has been checked for security weaknesses by a qualified, information security professional.

  • It provides an incredibly solid structure for greatly improving security, operation and audit performance by a having an independent assessment performed.

  • It sets any business up to be more stable and to avoid infections or security disasters.

  • Without it you can't process credit card information and a merchant cannot get by without processing credit cards nowadays.

  • Merchants who are PCI compliant are offered some level of protection from the fines if you should happen to be breached. If you are compliant at the time you suffer an attack, you may have a ‘safe harbor’, along with connections to a QSA that can assist in shepherding the process to minimize the breach effect on both your customers and business.

About The Author
Ron Schmittling, CPA/CITP, QSA, CISA, CIA, Security and Privacy Practice Leader at Brown Smith Wallace, LLC
Ron’s 18+ years of experience include more than five years in senior-level technical leadership roles at a major financial services firm, as well as, positions in information security and technology consulting for several international organizations. Ron is a thought leader, frequent speaker and author on topics in the information security and PCI compliance arena. Ron is a member of the American Institute of Certified Public Accountants (AICPA), the Illinois CPA Society (ICPAS), the Missouri Society of CPAs (MSCPA), ISACA, Institute of Internal Auditors (IIA), InfraGard, International High Technology Crime Investigation Association (HTCIA), Information Systems Security Association (ISSA), and the Institute of Computer Forensic Professionals (ICFP).
Schmittling can be reached at 314-983-1398 or
schmittling@bswllc.com.

About The Brown Smith Wallace Security and Privacy Practice
The Brown Smith Wallace Security and Privacy Practice is a market leader in helping businesses, government, financial institutions, retailers, educational institutions, and healthcare groups and other organizations define the true risks in their environment and deploy the right solutions and technologies to ensure the continued success of day-to-day operations and objectives. Our services include attack and penetration testing, internal vulnerability assessments, security risk assessments, security training, social engineering tests, PCI compliance reviews, PCI readiness assessments, PCI ASV vulnerability scanning, privacy risk assessments, computer forensics, and many others.

Add to Technorati Favorites