Showing posts with label Insider Threat. Show all posts
Showing posts with label Insider Threat. Show all posts

22 August 2026

Innovation: Truth in Data Provenance...

For years mathematicians and computer scientists have written about the trustworthiness of “Data Provenance”.


Relying on the integrity of data collection, transport and of course the source of data is a real science.  Our modern day zeros and ones span all aspects of our lives and Operational Risk Management (ORM) professionals have encountered the questions surrounding trust and the process of decision making long before the invention of computing machines.


At the root of decision making with integrity the source of data is questioned.  The reliability and history of previous data from the source.  As the data was transported from Point A to Point B was there any possibility that the data was altered, modified or corrupted.


Couriers and the use of a "Hawala" type system have been used by traders and terrorists for hundreds of years.


"Truth in Data Provenance" is the question mark that enables trust decisions.  This is why modern day cryptography is at the center of so many arguments and debates, when it comes to the topic of trusted information.  Yet hundreds of years ago, long before telecom and ICT was invented, the trustworthiness of data provenance was a vital factor.  The use of transposition ciphers were in use by the ancient Greeks.


So what?  In 2026 what does the truth in data provenance have to do with our business commerce, our transportation, our banking, even our abilities as governments to maintain our defense against attack?


The topic is vast and deep and worth exploration at the top level of human decision-making.  Yes, it is vital that our computing machines have high-assurance data integrity, in order for our global systems to operate day-to-day.


Yet what impact does trusted information have with humans in an environment of work and daily collaboration?  How does truth in data provenance, affect our decision making and the environments we work in?


In a report by LRN, the subject of trust in the work environment as a motivator has become more apparent:


Another fascinating result of the study had to do with two squishy-sounding characteristics of a company: character and trust. Companies deemed by employees to have both strong character and inspired trust performed almost four times better, using the metrics mentioned earlier, than those that had other positive cultural attributes, such as collaboration and celebrating others. (This applied to all three types of companies, though, naturally, culture and trust were much more prevalent in the self-governing ones) What’s more, “high trust” organizations were 11 times as likely to be called more innovative than their competitors. Trust, the How Report suggests, is more important than virtually any other characteristic.

How organizations address the trustworthiness of data provenance is still a new frontier in this day and age.  The use of new sensors, sophisticated analysis of "Big Data" by computer algorithms (AI) and the pace at which new data is generated by the "Internet of Things" (IOT) makes this a significant area of focus for our current executives and enlightened organizational leadership.


Why?


But what does that really mean? How does one measure the absence or presence of something as abstract as trust? The How survey defines it as “a catalyst that enhances performance, binds people together, and shapes the way people relate to each other.” High trust groups encourage risk-taking, which in turn is what is necessary for true innovation to occur. When innovation fails, it’s because companies don’t put enough faith in employees to let them take risks. The industries with the highest amount of trust were “computers/electronics,” followed by “software/Internet.” Coming in last? Government.

At the most fundamental level, the culture you are operating in has all to do with the trust that exists or is absent.


It has all to do with the trustworthiness of data provenance.  Leadership in any organization, must see the relevance between trust and innovation.  Between innovation and risk-taking. 


Your future and your culture depends on it...

02 May 2026

Critical Infrastructure Protection: Resolve to be Ready...

Terrorism Risk includes the risk from attackers both “Internal and External” to our organizations.


These attackers are still using conventional (incendiary explosive devices IED) or Active Shooters and unconventional (Digital Advanced Persistent Threat (APT) methods to disrupt the operations and economic well being of corporate organizations, the real estate finance industry and most of our Critical Infrastructures.


The process and systems for managing Terrorism Risk are rapidly changing as the commercial real estate finance and building owners strive to establish new standards.


Critical Infrastructure Protection (CIP) is now again a national priority. 


The key catalysts for change could further motivate infrastructure owners to implement new risk reduction programs and measures. 


Some of the key catalysts that remain for change are:

·Insurance – those institutions that are sharing risks that a building owner faces.

·Finance – banks, REIT’s (Real Estate Investment Trusts), and others such as pension funds that provide the capital for investments in commercial infrastructure.

·Regulation – Federal, State and Local jurisdictions that regulate building design, construction and operations.

Overall Terrorism Risk reduction begins with these key catalysts in concert with owners of critical infrastructure, whether that is a corporate office building, a hospital, a mall, a school, religious facility, subway, or a hotel.


These soft targets are where the risk management decision-making is again already taking new directions.


In order to introduce new changes in process or design that impacts the physical or operational aspects of critical infrastructures (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners and operators.


Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety.


Consistently the conversations are not about “if” something is going to happen, it is about “where” or “when” it is going to happen.


Therefore, it is imperative we initiate a proactive hedge against the inevitability of a loss event occurring in the future.


First however, we must understand the character of terrorism risk in critical infrastructure and some of the anti-terrorism tools currently available to help manage that risk.


The recognition by insurers that owners will continue to invest in terrorism risk reduction and building safety with the proper incentives is vital to overall risk management of critical infrastructures.


The assessment of terrorism vulnerability in key structures identified as soft targets can be a key component of the rating of risk for a specific structure.


"In order for owners to benefit from the potential of reduced premiums from direct insurers they must be able to demonstrate a combination of risk mitigation measures and programs to help improve the survivability of the infrastructure or to reduce it’s vulnerability to certain threat profiles."


These need to be exercised on a continuous timetable with extensive documentation, training and reporting.


In order for insurance brokers to accurately represent their buyers mitigation programs and measures to the direct insurers they must have a foundation of knowledge about the structures physical vulnerabilities.


However, even more essential is the understanding of the operational and human attributes of the building that are contributing to the proactive tactics to prevent losses and further exposures to potential terrorism risk.


If this step takes place, the insurers can better evaluate these operational and human elements to determine the value and effectiveness of these tactics so that they can be considered for premium reductions.


The building itself, two miles from The White House, 10 Downing Street or the Eiffel Tower, has little chance of moving outside the high-risk zone for terrorist events. 


The only methods for reducing risk exposures are to dramatically impact the operational and human elements of the building to mitigate hazards and increase the survivability of the people and systems that are resident.


As landlords and other interested real estate finance industry partners move towards updated standards to mitigate terrorism risk and protect critical infrastructure, the necessity for state-of-the-art tools and systems to mitigate those risks is paramount.


CxO’s in corporate enterprises are ever more concerned about emergency preparedness and the continuity of their enterprises.


Now that threats to government and business operations are becoming ever more prevalent, organizations must plan for every type of business disruption from hardware and communications failures, to natural disasters, to internal or external acts of terrorism...

28 March 2026

CRMS: Mechanisms for Continuous Risk Monitoring...

Stryker, Lloyds Bank, European Commission, Fortinet and others have yet to announce their settlement with recent hacker and/or data breach law suits.


One of the systemic resilience problems at large institutions including large and global organizations like Stryker is keeping your finger on the pulse of "Risk Indicators”.


Unfortunately for SVP's and other CxO executives in the corporate hierarchy, your middle managers are creating the layer that impedes the best Early Warning System you have at your disposal.


When problems surface on the front line or in the "Cube City" down in Information Systems, the normal agenda is for the employee to go to their direct supervisor to raise the "Red Flag" or disclose the incident.


And the first behavioral response by the Middle Manager is to keep it quiet. Fix it before anyone else finds out. Keep it under wraps until damage control can be implemented.


When you are the head of Enterprise Risk Management, you need mechanisms to bypass and eradicate the barrier holding your intelligence, incidents and overall hunches for ransom.


There is no magic system or process that will solve it all. The only way to attempt at breaking through this layer of social and organizational dysfunction is to circumvent it.


A continuous risk monitoring system has to be implemented and operating anonymously 24/7 if the upper echelons of executive management are ever going to "Feel the Pulse" of true risk hotspots in the company.


These hotspots translate into human "Risk Indicators" from the sources themselves, people who know what's going wrong and know the truth.


A Continuous Risk Monitoring System (CRMS) is an automated human feedback and problem identification mechanism for detecting risks. It allows leaders of large organizations to quickly identify problems and incidents of all kinds in their company.


Call it a sophisticated whistle-blower system or suggestion box but that is exactly what it is, on steroids.


The ideal system would emulate communication patterns in small groups which is often a major ingredient in successful teams. It would also run on the existing computers and networks of the organization or from home by logging in via a trusted VPN.


The soldiers on the front line know what is going on far sooner than the commanders in the “Joint Operations Center” just as the employee or 3rd party supplier does and they need a way to communicate the issue, concern or threat in a rapid and efficient manner.


The system provides the executives with instant or trend based Intel that is actionable. It provides the "Insight" as well as the pertinent facts that you need to make quick effective decisions.


Think about how long it takes for data and relevant information to percolate and bubble up from the places in your organization that are considered "Current Risk Hot Spots”.


The point is that for far too long we have been playing the old telephone game. You know, the one that you played as a kid sitting around the kitchen table or on the floor in a circle.


One person starts and whispers into the ear of the person to their right. Just a sentence or two. By the time the message gets around to the 3rd or 4th person, now the data is dramatically different than the original. It's been interpreted, edited and sanitized.


Walk down the hall or pick up the phone and contact the person in person who is in charge of the corporate “Emergency Operations Plan (EOP)”, electronic suggestion box or corporate whistle-blower program at your institution.


Ask them for the most recent activity log.  Ask yourself how you could get this mechanism to perform better and then work with your front line to develop something that middle management can't filter, change or delete.


That is when you will be on your way to getting the real story, in more recent real time…


08 March 2026

ID Risk Management: Corporate Intelligence Unit (CIU)…

What is your name? Where do you live? What is your phone number? Where were you born? What is your social security number? What is your passport number? Where was it issued? What evidence do you have that this is all true? Your identity is at stake and Operational Risk Management is on the line.

These questions and more are asked of us on a regular basis to establish our true identity. The entity asking these questions is considering you to be granted access, access to what?

It could be to establish an account at a banking institution, get a drivers license or become a member of a trusted community of people. Or it could be a country deciding whether to grant you a visa to visit or work for a period of time.

Whether you are in the UK, admitting people into your country or a Global 500 company allowing someone access to your corporate facilities, digital assets or place of business; you must have ways to effectively validate who people say they are, and who they really are.

Even if you asked all of the questions above in the early stages of the company hiring process, would you really have the entire picture? This changes over time and events in a persons life. Identity Management and the use of both "known to many" and "known to few" attributes about who you are and who you know, is a reality in today's blur of global commerce.

When a country has a breach of security admitting people, who are not who they purport to be, is it any different in the context of a Defense Industrial Base company headquartered in Chicago, IL or an Investment Banking firm in Geneva, Suisse? What are different are the motives and the outcomes from the fraudulent acts.

What are the current arguments and the leading reasons why our policies, methods and tools associated with Identity Management are in a state of chaos in the United States?

"What is interesting is that the same people who are coming to work every day with their TWIC or CAC cards are also victims of ID Theft as consumers."

The same individuals who walk into the SCIF or the bank vault may very well be people who have active investigations going on regarding their identity being used to perpetrate crimes or other fraudulent motivations. So what are some of the most important issues on the Identity Management horizon?

In all of the breaches, all of the incidents there is a root cause for the failure in the people, process, systems or external factor that opened up the vulnerability for the attacker to exploit and obtain their objective.

It's called Continuous Monitoring. This issue is found in all places in Appendix G of the US NIST sp800-37 that illustrates the reason why “Continuous Monitoring” is critical especially in information systems:

Private Sector companies have a duty to invest in resources, policy refinement and new methods or tools to keep continuous monitoring as vigilant as possible:

"Conducting a thorough point-in-time assessment of the deployed security controls is a necessary but not sufficient condition to demonstrate security due diligence. A well designed and well-managed continuous monitoring program can effectively transform an otherwise static security control assessment and risk determination process into a dynamic process that provides essential, near real-time security status-related information to organizational officials in order to take appropriate risk mitigation actions and make cost-effective, risk-based decisions regarding the operation”

Much of what we know about our employees is found in their HR files, background reports (if ever done) and what co-workers say about their behaviors in the workplace.

Corporate Security, Risk Management, General Counsel, Information Technology, Public Relations and even the EAP (Employee Assistance Program) executive managers shall create, maintain and continuously operate a Corporate Intelligence Unit (CIU) and “Threat Assessment Team”.

Without it, the consequences of not knowing a persons true identity or current state of mind could cost you more than the loss of life.

It could cost you or the organizations global reputation…

24 January 2026

Leadership in Crisis: Building Trust with Continuous Training...

How often have you ever heard the leadership management philosophy that you must "Train Like You Fight"?  Here is another way to look at it:

"The more you sweat in peace, the less you bleed in war." Norman Schwarzkopf

The theme is all too familiar with Operational Risk Management (ORM) teams that operate on the front lines of asymmetric threats, internal corruption, natural disasters and continuous adversaries in achieving a "Defensible Standard of Care."

As the senior leader in your unit, department or subsidiary the responsibility remains high for preparedness, readiness and contingency planning.  Your personnel and company assets are at stake and so what have you done this month or quarter to train, sweat and prepare?  How much of your annual budget do you devote to the improvement of key skills for your people in a moment of crisis or chaos?

What will the crisis environment look like?  Will it develop with clouds, water and wind or the significant shift in tectonic plates?  Will it begin with the insider employee copying the most sensitive merger and acquisition strategy to sell to the highest bidder?  Will it start with a single IT server displaying a warning to pay a ransom or lose all possibility of retrieving it's data and operational capacity to serve your business?  Will it end up being another example of domestic terrorism or workplace violence like San Bernadino, Paris or Ft. Hood?

Leaders across our globe understand the waves of risk and the possible issues that they may encounter each year.  Many travel to Davos to the World Economic Forum where the world tackles these disruptive events, with the best minds and exchange of information.  Why? They understand that vulnerability is what they fear the most.

Yet what can you do in your own community, at your own branch office to address the Operational Risks you face?  How can you wake up each day with the confidence as a leader, that you have trained and prepared for the future events that will surprise you?  It begins with leadership and a will to lead your team into the places no one really likes to talk about.  The scenarios that people fear to train for, because they think they will never happen.

Achieving any level of trust with your employees, your customers and your supply chain revolves around your leadership.  The discipline of "Operational Risk Management" is focused on looking at all of the interdependent pieces of your business mosaic.  The environment you operate in, even the building that houses your most precious assets.  All of these factors are considered in developing and executing your specific plan for training and readiness.

So what?  The question is

"Why Don't Employees Trust Their Bosses"?

Why this lack of trust?

As a leader your roles are multi-faceted and there is never enough time or money in the budget.  The leaders who excel in the next decade, will find a way.  They will invest in their teams training and the systems to increase trust, by addressing Operational Risk Management (ORM) as a key component of the interdependent enterprise.

The "TrustDecisions" you require and the understanding developed to insure effective "Trust Decisions" by all of your stakeholders will remain your most lofty goal as a leader.

How you train to fight and how you sweat now will make all the difference in your next war.  From the boardroom to the battlefield your leadership is all that is needed.  Your leadership will make a difference...