Comment Re:Be firm.. (Score 1) 902
our IT department decided to implement a much more comprehensive firewall than before
You have the problem basically here. IT should not just decide things on their own, without, at the very least, consulting with the business (essentially the customers of IT services), especially if there is a significant impact to the business operations.
IT should usually also not have the authority to set policy or decide on the actual overall security level / risk acceptance level. Policies are under the authority of Top Management. Of course, they can delegate the actual task of formulating policy, but the ultimate decision and approval lies there.
IMO, often people who run IT have somewhat of a god complex (this is where BOFH comes in), just because of their extensive access rights and a feeling of being absolutely essential for the operations of their organization, when in fact, they are in more of a janitorial role.
Think about it in the context of a house or building: You are responsible for making sure the lights and elevators are working, you are handing out keys, make sure the corridors are clean and free of obstacles, there are no fire hazards in the rooms, etc.
However, you are NOT responsible for deciding on who specifically gets a key to what door, or what doors actually should have a lock. Nor are you the person to decide on installing an elevator. This is within the responsibility and authority of the building owner.
So, to answer the question: How to get respect and not become a BOFH? --> Know your place!