Showing posts with label Intellectual Property. Show all posts
Showing posts with label Intellectual Property. Show all posts

08 June 2024

Organizational Integrity: Trusted Relationships...

Before 9/11, almost all of our countries and organizations current day vulnerabilities were in existence.

Whether you focused on increasing protection from other nations states, the growing regional terrorist sects or the online dark net criminal syndicates, their growing presence and actions were all visible.

What has changed in the past two decades in the continuous and pervasive strategies to provide greater Critical Infrastructure Protection and security and safety to our United States and our citizens?

If there was a simple bullet list of items to address the answer to this question, it would seem:

  • Incomplete.
  • Short sighted.

Today, our adversaries have substantial new speed and stealth due to technology innovation, such as encryption, 5G and various levels of Aerial/SAT imaging or video.

They have new highly-trained human assets who are continuously recruited online and in-person to travel and impersonate roles in the private sector to attend our key events and meetings.

To get more perspective, one only has to watch the entertaining and educational movie “Duplicity” to learn and remember how our organizations intellectual property and new inventions are under constant assault.

Yet the “Infinite Game” continues across old and new frontiers of our globe, in some of the most unexpected places for the average U.S. citizen, who might not even know the answer to some of our standardized U.S. History 101 questions.

In our Farm lands. In our Schools. In our Private Equity firms. In our Financial institutions. In our Healthcare organizations. In our Utility companies. In our Defense Industrial Base (DIB). In our Global Fortune 100.

How might we improve our abilities to increase our resilience?

We must step up our learning from what has worked more than two decades ago.

Many have forgotten integrity or never experienced what can be accomplished with even more trusted relationships.

You see, it might take your valuable time to make a phone call on that little rectangular camera box in your pocket.

It might take your time to get on a plane or in your car to drive across miles of a freeway to meet someone in person at a coffee shop or for a club sandwich.

The trusted old "One-to-One", "Face-to-Face" ability to build a relationship from a personal introduction to a lasting intellectual and learning experience is our only future hope.

It remains the chance to see and feel another persons true ambition, real emotion or innovative intellectual excellence.

You might think that our world has changed tremendously over the past two decades.

In reality, "Building Trusted Relationships" has a formula that has lasted over centuries…

26 April 2024

Navigating Wisdom: Partners in True Innovation...

Before you were wise, you were prone to be testing, wondering what would happen next.

The more you found yourself exploring, testing and better understanding the results, the more wisdom you created.

Creating the opportunities for gaining new knowledge and learning, requires first an attitude of curiosity.

What is on the other side of that hill? Who lives around the corner? How does a bird fly? Why does the sun shine during the day and the moon at night?

Are you creating curiosity with the purpose of learning more and asking new questions?

After the process has been repeated enough times with the same results, you begin to craft your own hypothesis.

True Innovation begins here.

Beyond your curiosity stage and past your due diligence, now you have arrived at your new hypothesis:

1 a: an assumption or concession made for the sake of argument

b : an interpretation of a practical situation or condition taken as the ground for action

2 : a tentative assumption made in order to draw out and test its logical or empirical consequences

3 : the antecedent clause of a conditional statement

Now your testing begins and you experience the outcomes and results. The evidence of your work will provide you the path for your future navigation.

Too fast, too slow. Too hot, too cold. Too high, too low. Keep testing.

So what kind of “Innovation Navigator” will you become?

Time will tell and much of what happens in your life is going to be a factor of the people you meet.

Who else has the same curiosity as you do? What questions do they ask that you never thought about?

You see, you need a Team Mate. A Wing Man. A Buddy. Together you will discover far more about your growing curiosity and your new tested hypotheses.

You will leverage each others strengths together and you will cover each others vulnerabilities.

How wise will you both become as “Innovation Navigators”…

04 December 2022

TrustDecisions: Quality of Innovation...

When you approach a new problem-set in your start-up or emerging business there are several methods for your teams approach to solving it.

The methodology that you and your team use to solve your particular problem, will make all the difference in how fast the business grows and accelerates towards ultimate success.

Our team continues to utilize a SPRINT-based approach and a lean launchpad mindset to find the correct solutions to deliver with quality.

Over the course of many years of growth, the patience and the focus on staying true to the system, to the proven steps in the sequence has always provided results.

In so many cases, the results are not what we could have imagined at the beginning of our journey.

The original hypothesis we thought was going to lead us to a successful outcome turned 90 or 180 degrees.

The answers to our problem-set changed as we interviewed more people, dozens of others in the same industry with a similar set of issues in the past.

The story continues as we designed the new prototype solution. It would change after several more iterations navigating us towards true innovation.

“Innovation Navigators” don’t give up easily. We test, we try and we make changes. The pursuit of information assurance is vital.

The quality of the solution that is designed and tested to solve the problem is a direct result of the number of times you test and the information captured for analysis.

How might you hold off the business needs just a little more longer, to truly improve the quality of your deliverable?

The speed of business in many cases calls for new designs and solutions to be delivered long before the “Quality Assurance” process is fully complete.

We have witnessed too many times a solution implemented long before it was ready for production, for the playing field or for the customers roll out.

When was the last time you encountered someone who states: “Our servers have been overwhelmed by the response to our new “X” and we apologize for any delays.”

You see, problem-sets will be encountered on a more frequent basis and will take much longer to solve if “Quality Assurance” testing is not completed or compromised.

How trustworthy will you become with your clients or customers?

Consider these principles from “Achieving Digital Trust” by Jeffrey Ritter on page 35 and 36:

  • Every transaction creating wealth first requires an affirmative decision to trust. 
  • Building trust creates new wealth. Sustaining trust creates recurring wealth. 
  • Achieving trust superior to your competition achieves market dominance. 
  • Leadership rises (or falls) based on trust (or the absence of trust).

“Innovation Navigators” in 2023 and beyond shall study each one of these principles in their own organization.

They will utilize a proven methodology, that is centered on the science of “TrustDecisions”…

29 February 2020

Workplace Violence: Maximize Dialogue and Anonymity...

Proactive vs. Reactive. The argument goes on in many organizational departments when it comes to budgeting for preparedness vs. response. How do you detect the next employee "Gone Rogue" as they say?

What is the early warning indicator that tells you that you need to train employees on the detection of "abnormal behavior" or out of context business transactions?

If we are to continue the path of handling disruptions in business and emergencies with personnel with the idea of mitigating the risk post incident, then increase the number in the budget for the line items under outside counsel, litigation and insurance.

However, the idea that a corresponding increase in the line items in the budget under the heading compliance, security and training will decrease risks prior to an incident, is prudent thinking.

In the battle for finite dollars to be spent across the enterprise in all categories that have significant risks, there will always be an argument on where the investment of resources will have the biggest payoff or return on investment.

"Yet, how will you ever know whether this is the year of the earthquake, the cyclone or the employee who becomes hostile or potentially lethal?"

The point is, you will never know, for certain...

This is why an investment in enterprise risk management dialogue requires that every department and each process, factor in additional costs for mitigating risks.

Each person who is closest to the work being done knows where the greatest potential is for a loss event. The place that is most vulnerable.

Just ask the HR specialist what employee they have hired over the past year or two that represents the most lethal threat to the company. Just ask the IT Security Engineer what system or application is on the verge of a melt down and they can tell you.

Or just ask the executive who they think the middle manager is, that is getting ready to move to the competition, with all the latest Intellectual Property (IP) secrets. Most likely, they can tell you.

Being proactive in managing operational risks sometimes means that you have to ask your employees risk related questions on a continuous basis. You have to document and collect the answers and feedback so that you can detect trends in behavior or potential eruptions in behavior.

Finally, you need to figure out how to do all of this using new tools and processes, to protect privacy and anonymity. Get started!

22 February 2020

Analytical Decisions: Navigating to a Trusted Future...

"For those of us who are decision makers, these are huge problems. With growing velocity, we are losing our ability to trust digital information to be factual, accurate, reliable, and authentic. But we also are losing something far more important—trust in the quality of our own decisions and our confidence in those we trust to make good decisions"  Jeffrey Ritter-Achieving Digital Trust

Think about all the Trust Decisions that you made this morning.  This week.  This month.

Countless decisions to act upon your experience, your current information or the live scenario unfolding almost instantly in front of you.  "Trust Decisions".

Is this a discipline or process that you can truly learn and improve upon?  The question is, do you think it is important enough to learn more and to devote precious time to making this a priority in your life?
Where are you in your particular "Life Cycle" right now?  At the beginning, near the end or somewhere in between?  Yet it is never to early, to study and learn more about the science of Trust.

SpaceX is looking to raise around $250 million in new funding according to a new report from CNBC’s Michael Sheetz. The additional cash would bring SpaceX’s total valuation to around $36 billion, according to CNBC’s sources — an increase of more than $2.5 billion versus its most recently reported valuation.

The rocket launch company founded and run by Elon Musk is no stranger to raising large sums of money — it added $1.33 billion during 2019 (from three separate rounds). In total, the company has raised more than $3 billion in funding to date — but the scale of its ambitions provides a clear explanation of why the company has sought so much capital.
Building trust with a new person, new organization, new project, new government or new ecosystem requires a sound and thoughtful strategy.  A strategic approach to reaching your vision, completing the transaction and achieving your outcome.
Trust is the affirmative output of a disciplined, analytical decision process that measures and scores the suitability of the next actions taken by you, your team, your business, or your community. Page 49 - Achieving Digital Trust - Jeffrey Ritter
Godspeed on your particular TrustDecisions ahead.  Onward!

13 July 2019

Red Zone: Behavioral Analysis Interviews...

Industrial Espionage and the theft of trade secrets is continuously on every Operational Risk Management (ORM) executives mind these days.  The names Chelsea Manning and Julian Assange have been headline news for years.

In addition, the 2009 conviction under the Economic Espionage Act of 1996 in the United States, is a stark reminder of the accelerated requirements for an "Insider Threat Program" (InTP), by the counter intelligence and OPSEC units of major public and private organizations.  Flashback to a decade ago:

"A former Rockwell and Boeing engineer from Orange County, CA was remanded into custody this morning after a federal judge convicted him of charges of economic espionage and acting as an agent of the People’s Republic of China, for whom he stole restricted technology and Boeing trade secrets, including information related to the Space Shuttle program and Delta IV rocket."

How 250,000 pages of classified, proprietary and otherwise sensitive information was found under this employees house is a good question? What might be an even more interesting question is pertaining to the controls for OPSEC and INFOSEC at Boeing in Orange County, CA a decade ago.

Information Operations (IO) or Information Security controls are only as good as the creativity and the will of the individual human being, that exploits the vulnerabilities in the design, configuration or implementation of your layers of defense.

This is why the counter intelligence and OPSEC capabilities within the enterprise must be ever vigilant and continuously adapting to the changing personnel within the organization.

In collaboratin with the Information Technology organization, the Digital Operational Risks that the OPSEC team is focused on these days, has to do with Data Loss Prevention (DLP)  software platforms and proactive data exfiltration detection capabilities.

As companies such as Boeing and other Defense Industrial Base (DIB) institutions utilize the latest software, hardware and other technology to assist in the "insider" detection and prevention of stealing, changing or deleting sensitive information, there still remains the risk of human factors and social engineering.

Sometimes the low tech or human designed detection systems that work on behavioral sciences, can be just as effective as the newest software running on the fastest computer box.

One example is "The Reid Technique" in the context of doing routine interviews and investigations with a set of "Red Zone" employees. Who are the red zone employees?

Those individuals who have certain access to systems or information, leave the organization for involuntary reasons or people that may be 3rd party suppliers to the key people in the red zone. So how does the Reid Technique help?

"The Reid Technique is a method of meeting, conferring with, and evaluating, the subjects of an investigation. It involves three different components — factual analysis, interviewing, and interrogation. While each of these are separate and distinct procedures, they are interrelated in the sense that each serves to help eliminate innocent suspects during an investigation."

The "Integrity Interview" is a highly structured interview with a job applicant. The purpose for the interview is to develop factual information about the applicant's past behavioral patterns.

The philosophy behind the interview is very straightforward. The most accurate indicator of an individual's future behavior, is their recent past behavior.

The same technique can be used on a departing employee with the emphasis on adherence to all "Acceptable Use" policies, regarding digital assets and cyberspace access to organizational data repositories.

Individuals who have the characteristics associated with deception, could be the target of a further investigation to determine whether any unauthorized information has been sent to an encrypted webmail account or if a 2 TB Thumb Drive happened to be plugged into a corporate laptop, the night before the last day on the job.

This low tech method may still be one of the most effective means for industrial espionage. Old school methods with 21st century technologies. All of the detection hardware and software, CCTV cameras, tagged files or RFID countermeasure, will not be able to thwart a diligent, patient and trusted insider.

Utilizing "Behavioral Interview Analysis" can make the difference between early detection or late reaction.

And while the OPSEC group is working on the "Lone Wolf" insider, there are swarms of non-state attackers initiating their asymmetric information operations strategy on the corporations and governments worldwide.

Economic espionage and attacks on nations states critical infrastructures, requires a substantial shift in policy and taxonomy, if we are ever going to be effective in protecting our IP and trade secrets.

While the CEO's and the General's are being briefed on the latest facets of "Weaponizing Malware," we can only hope that OPSEC is still conducting the behavioral analysis exit interview.

A face to face encounter, with someone who may just be that one person, who has your most valuable intellectual property or trade secrets in the purse or backpack at their feet...

06 July 2019

Business Resilience: Supply Chain Risk to National Security...

The Operational Risks associated with a major disruption is now again at the top of the Board of Directors agenda. Economic discussions inside the corporate risk management executives conference rooms, have been focused on the WEF Global Risks Report these past six months.
"The Global Risks Report 2019 is published against a backdrop of worrying geopolitical and geo-economic tensions. If unresolved, these tensions will hinder the world’s ability to deal with a growing range of collective challenges, from the mounting evidence of environmental degradation to the increasing disruptions of the Fourth Industrial Revolution."
The art of Risk Assessment and Vulnerability Management, extends far beyond the guards, gates and fire walls defending your global institutions. The risk of suppliers' "Supply Chain" disruption has grown significantly in the past few years as a result of just-in-time (JIT) inventory management.

This is further inflamed by the outsourcing momentum, as some economies continue their struggle with semiconductor trade wars or escalating natural disasters.

The implications and outcomes of a lack of effective supply chain resilience planning, can provide exposure beyond just a loss of sales. This myopic approach to effective Operational Risk Management (ORM) strategy, can extend to market share erosion and a tarnished brand image.

The risk assessment of suppliers' "Supply Chains" will not be overlooked any longer from the Board Room. More prudent audits of current supply chain exposures will take place and the corporate operations management will feel the pain for some time to come.

The independent and thorough review of the exposures to the institution are going to make some in procurement and accounting uncomfortable. The risk mitigation strategy going forward will invoke a third party review, of most supply chain strategy planning, to encompass the use of "Black Swan" scenarios and alternative thinking on the risk of volatility.

Even a survey of resilience professionals conducted by The Business Continuity Institute found that almost three quarters of supply chains had experienced significant disruption in the 12 months prior to the study.

With 28 per cent of those occurrences attributed to supplier insolvency and 20 per cent due to failure of outsource service provision, almost half of these supply chain disruptions were down to supplier or service provider failure - in other words, circumstances outside one’s own immediate control.

So how resilient is your supplier's "Supply Chain?" The security and safety of your private sector organizations supply chain is now back on the Board of Directors agenda, so how proactive is your organization?

Now think about this. What if the security and safety of your country depended upon a specialized semiconductor for an electronic component that was destined for Broadcom, Boeing, Raytheon or Cisco?

The risk of your supplier's "Supply Chain," may have significant consequences far beyond the bottom line, at the next shareholders meeting.

It could mean the difference between having a resilient economy, or even a devastating asymmetric attack on our Homeland.

08 June 2019

New Vision: Security Operations Center and CIU...

Flashback over 8 years ago when there was a convergence of thinking about the topic of a "Defensible Standard of Care" going on in the industry.

The key Operational Risk Management news from the 2011 RSA Conference was coming in, yet there were inside sources who still needed to be interviewed. What did they think was the most brilliant presentation or idea(s) presented?

This particular release caught some eyes as it addressed much of the thinking on the latest evolution of the Security Operations Center (SOC).  How much of this is still relevant today:

New Vision for Security Operations: Six Core Elements
The vision includes six core elements and prescriptive guidance for how to incorporate these elements into existing security operations. These elements include:
  • Risk planning: The new SOC will take a more information-centric approach to security risk planning and invest in understanding which organizational assets are highly valuable and essential to protect. With priorities based on GRC policies, security teams need to conduct risk assessments that focus on the “crown jewels” of the enterprise.
  • Attack modeling: Understanding attack modeling in a complex environment requires determining which systems, people and processes have access to valuable information. Once the threat surface is modeled, organizations can then determine potential attack vectors and examine defense steps to isolate compromised access points efficiently and quickly. RSA® Laboratories has developed theoretical models based on known APT techniques and employed game theory principles to identify the most efficient means of severing an attack path and optimize defense costs.
  • Virtualized environments: Virtualization will be a core capability of tomorrow's SOC – delivering a range of security benefits. For example, organizations can "sandbox" e-mail, attachments and URLs suspected of harboring malware. Anything suspicious can be launched in an isolated hypervisor and the virtual machine can be cut off from the rest of the system.
  • Self- learning, predictive analysis: To remain relevant in tomorrow's IT environment, a SOC will need to truly integrate compliance monitoring and risk management. The system should continually monitor the environment to identify typical states which can then be applied to identify problematic patterns early. Statistic-based predictive modeling will be able to help correlate various alerts. Developing such a system will require real-time behavior analysis innovations, although some of these elements are available today.
  • Automated, risk-based decision systems: A key differentiator of a more intelligent SOC will be its ability to assess risks instantly and vary responses accordingly. Similar to risk-based authentication, the SOC will employ predictive analytics to find high-risk events and then automatically initiate remediation activities. The prospect of dynamic typography is one of the most exciting areas of this type of systems automation for the cloud. To implement an APT, an attacker must understand network mapping and be able to model it. In response to this, organizations can remap their entire network infrastructure to disrupt an attacker’s reconnaissance efforts. This is akin to physically rearranging a city at frequent intervals – and the entire process can be automated so that links between systems stay intact and dependencies are handled without human intervention.
  • Continual improvement through forensic analyses and community learning: Although forensic analysis can be resource-intensive, it is an imperative element of a SOC and key to mitigating the impact of subsequent attacks. Virtualized environments can provide snapshots of the IT environment at the time of the security event providing useful information if detection of the attack was delayed. Having a way to share information about attack patterns will be the future of the SOC. This concept should be embraced in order to exchange threat information within respective industries and better predict the path of the APT and thereby determine countermeasures.
The evolution of the SOC in your enterprise may start in some unconventional places. Who is it in your organization that is responsible for the loss of corporate assets?

Who in your company is the one who determines what items are counted as losses to the bottom line?

Who does the enterprise look to when the crisis hits and people are looking for answers in minutes, not hours, or days?

Who picks up the phone to answer the call from the local FBI Field Office?

These may not be the people you think of in the CIO's office or IT department. These people however need to be part of the combined Security Operations Center solution in the company.

The Advanced Persistent Threat (APT) now requires the intersection of prudent strategy from the business leadership, the accounting or finance leadership and the risk management leadership.

If the CIO is looked upon as the key executive running a "Utility" inside the enterprise, think again.

This blog has discussed the "Corporate Intelligence Unit" in years past :

Beyond the utilization of threat assessment or management teams, enterprises are going to the next level in creating a "Corporate Intelligence Unit" (CIU). The CIU is providing the "Strategic Insight" framework and assisting the organization in "Achieving a Defensible Standard of Care."

The framework elements that encompass policy, legal, privacy, governance, litigation, security, incidents and safety surround the CIU. It includes with effective processes and procedures that provides a push / pull of information flow. Application of the correct tools, software systems and controls adds to the overall milestone of what many corporate risk managers already understand.

The best way in most cases to defend against an insider attack and prevent an insider incident is to continuously help identify the source of the incident, the person(s) responsible and to correlate information on other peers that may have been impacted by the same incident or modus operandi of the subject. "Connecting The Dots" with others in the same company or with industry sector partners, increases the overall resilience factor and hardens the vulnerabilities that are all too often being exploited for months if not years.

In retrospect, you can be more effective investigating and collecting evidence in your company to gain a "DecisionAdvantage". To pursue civil or criminal recovery of losses from these insider incidents, you may not go to law enforcement, but it's likely they will come to you once they get a whistle blower report, catch the attacker and/or they have the evidence that you were a victim.
How your organization pulls together the right people to staff and operate your "CIU" is going to depend on your culture, funding and current state of the threat.
BALTIMORE— -
It has been a month since the City of Baltimore's networks were brought to a standstill by ransomware. On Tuesday, Mayor Bernard "Jack" Young and his cabinet briefed press on the status of the cleanup, which the city's director of finance has estimated will cost Baltimore $10 million—not including $8 million lost because of deferred or lost revenue while the city was unable to process payments. The recovery remains in its early stages, with less than a third of city employees issued new log-in credentials thus far and many city business functions restricted to paper-based workarounds.
Here is another thought. A thorough review of the current funding, staffing and strategy of a SOC or CIU in the enterprise, may even become a priority at the next "Board of Directors" meeting.

07 April 2019

Preemption: An Operational Risk Perspective...

"The global regulation of cybersecurity is one of the most contentious topics on the international legal plane. States, the actors primarily responsible for arranging most other international regulatory regimes, have so far been incapable of reaching a consensus on how to govern international cyberspace. For example, in 2017, the United Nations Group of Governmental Experts, arguably the most promising effort to create international norms for cyberspace, collapsed. In this vacuum, private tech companies are seizing the opportunity to create norms and rules for cyber operations, essentially creating a privatized version of cybersecurity law."  LawfareBlog Ido Ikilovaty

Preemption - A Knife That Cuts Both Ways by Alan M. Dershowitz should be considered for the professional Operational Risk Managers reference library:

Decisions to act preemptively generally require a complex and dynamic assessment of multiple factors. These factors include at least the following:
  1. The nature of the harm feared.
  2. The likelihood that the harm will occur in the absence of preemption.
  3. The source of the harm--deliberate conduct or natural occurrence?
  4. The possibility that the contemplated preemption will fail.
  5. The costs of a successful preemption.
  6. The cost of a failed preemption.
  7. The nature and quality of the information on which these decisions are based.
  8. The ratio of successful preemptions to unsuccessful ones.
  9. The legality, morality, and potential political consequences of the preemptive steps.
  10. The incentivizing of others to act preemptively.
  11. The revocability or irrevocability of the harms caused by the feared event.
  12. The revocability or irrevocability of the harms caused by contemplated preemption.
  13. Many other factors, including the inevitability of unanticipated outcomes (the law of unintended consequences).
Regardless of the agreement or bias of the reader, this book makes you think upside down and sideways about decisions you have made, and will make.

While Mr. Dershowitz takes time to make his own opinions known, his mastery of building the foundation for transformation is unequaled on such a topic; controlling dangerous and destructive human behavior and how to confront terrorism, crime and warfare.

During the course of a single day in the life of the Operational Risk Manager there are dozens if not hundreds of preemptive or preventive decisions to be made.

Private Sector vs. Public Sector is not so much the issue here. Whether you are the Chief Operational Risk Officer at a major banking institution or the Commander in the local Emergency Operations Center, you both have the same dilemma.

A decision must be made quickly and you must be able to live with the implications of either decision.

19 January 2019

International Risk: Cyberwarfare Rules of Engagement...

When the financial private sector views the actions of government, in terms of regulation and compliance, it is often considered another risk to its operations. Why? More rules and the need to report on oversight, creates new obstacles to other more valuable revenue producing activities.

CDOs were a focus in the movie "The Big Short" and is an example of a financial product that explains why the government regulation mechanisms continue to exist. Yet the implementation of internal controls, to thwart the embezzlement of funds or the theft of proprietary intellectual secrets, is something that is encouraged and welcomed in the banking community. This paradox is something that continues to occur in the cyber risk management domain.

The dawn of Internet banking, spawned many of the Operational Risks associated with using public networks for our various banking transactions. The oversight of cyber risk management in the financial institution, is still a major challenge yet becoming more mature by the day.

Government is more effectively learning how to apply the right oversight with private sector institutions, through the use of International Standards such as ISO 27001 and NIST best practices to protect Critical Infrastructure.

The newest strategies for cyber risk management have been a robust topic of global conversation. New reports on the origin of state sponsored hacking and cyber crime data breach incidents, has produced some new theories on how to address these international Operational Risks:

"Deadly force against organized hackers could be justified under international law, according to a document created by a panel of legal and cyber warfare experts. Use of lethal force on those behind a cyberattack on a nation would be legal if the virtual attack meets criteria similar to those currently accepted for real-world warfare, said Michael N. Schmitt, chairman of the International Law Department at the U.S. Naval War College in Newport, R.I. Schmitt is the editor of the Tallinn Manual on the International Law Applicable to Cyber Warfare, a 300-page book put together by a score of experts at the request of NATO and published by Cambridge University Press."

Even the most knowledgeable cyber experts, are at odds over the topic of "Active Defense" and the use of asymmetric cyber force, to retaliate against a so called attack or denial of service. A kinetic response is much more clear, based upon the source or attribution evidence of the attack. In the cyber domain, the word "Attribute" has some very interesting ramifications.

The State-of-Play will remain the same and for good reason. The governments of the world do not have issue with each other performing reciprocal cyber espionage. This practice is just a new version of intelligence collection and the next manifestation of Tinker Tailor Soldier Spy. However, if there should be any visible or kinetic damage to infrastructure, then the Tallinn Manual will be a vital resource for all. The question remains, what is a cyberattack? Jim Lewis said over five years ago:
“Cyberattack” is one of the most misused terms in the discussion of Chinese hackers. With very few exceptions, China has not used force against the United States in cyberspace. What it has been doing is spying. And spying, cyber or otherwise, is not an attack or grounds for war, even if military units are the spies. Spying isn’t even a crime under international law, and it wouldn’t be in Washington’s interest to make it so."
  Cyberwarfare Rules of Engagement remains a significant international Operational Risk...

18 November 2018

Risk Parity: Ideal Organizational Design...

Organizations across the globe are operating each day with Operational Risks. As a result, management is doing their best to implement a combination of Operational Risk Management (ORM) capabilities.

The strategy is to manage risk to the enterprise through a series of controls and modification of human behavior. Is it possible to create the most ideal organization from the start? Could you design it with the lowest possible Operational Risk exposure at every physical, process, virtual and human component?

What do we mean by this? Lets play a game. Or more importantly, lets imagine a workplace exercise to design the ideal professional services organization in one hour:

This organization will be in the private sector. The fictitious name for the organization is "Improvise, Inc." All of the legal entities have been created and it is registered as a U.S. Delaware company. It will have the following characteristics, capabilities, assets and purpose:

200 humans with advanced education between 25 and 65 years old. 50% Men & 50% Women
Global reach of professional services. (It sells intellectual capital and information)
Office hubs are physically located across four locations: Denver, Zurich, Abu Dhabi, and Singapore.
Language expertise includes English, German, French, Italian, Arabic and Mandarin.

Subject Matter Expertise of the Improvise associates is diversified. The core staff devoted to operational administrative processes is also diversified by physical location, 4 people each. Therefore, less than 10% core overhead.

Improvise, Inc. generates revenues by selling information, advisory services and subject matter expertise. The diversity of it's 200 humans and their Intellectual Capital provides professional services to Fortune Global 500 companies.

Now, to start the exercise you will have one hour to design the ideal mosaic of people, processes, systems and external factors to operate Improvise, Inc. on a daily basis. Begin.

How would you begin designing the ideal organization? Will you have a headquarters location? Will the offices have four leased corporate offices or utilize a virtual / shared space model? What will the facilities layout be with single offices, cubicles, conference rooms? Would you start with human resources and the hiring and selection process? What kind of systems and tools would you procure to issue to your new associates? How would you communicate and what vendor/providers will Improvise use outside its core? What organizational "Rule-sets" will be established?

Who will govern and what roles of power and influence will these employee-owners (Associates) have to make decisions for the good of Improvise? What countries across the globe will you dispatch your associates to do their work? How will you keep them safe and secure where and how they travel? What vendors and service providers will you contract with to provide digital communications and store your valuable intellectual property?

Will you locate your Associates across the four locations equally? Since you have 200 split into 100 men and 100 women, will you have 25 of each or 50 people in each office? Will they all be citizens of that native country only? Again, we are designing the ideal organization with Operational Risk Management (ORM), as our highest priority in the design. Is this even a valid consideration?

What about the use of digital assets? Will your associates at Improvise use PC or Mac, both? Microsoft or Linux-based? Android or iOS? Anti-virus scans daily or monthly. VPN, yes or no. Public or Private cloud? Encrypt data to remote sites? Retention and privacy policy? What happens when an associate goes home? When they leave the organization? Is there an "Acceptable Use" policy in place? And the list goes on.

Will Improvise standardize on a single travel agency, airline or hotel chain? What kind of training will occur with your associates on international customs, cultures, threats and vulnerabilities. Who will be accompanied by a buddy system or personal protection specialist when they travel? Will travelers receive intelligence briefings or reports in advance of their departure? Commercial or private carrier?

What processes are to be put in place for Improvise to follow, in the way it sells and delivers it's professional services? What autonomy does each associate have to make their own decisions on the price, scope and deliverable to a client? How do you interact, treat and question yourselves? Are your associates subject to any laws from the U.S. or the country they are operating in with regard to selling your professional services? Why are we doing all of this?

So when you are done with this first phase of the exercise after one hour, how could you improve Improvise, Inc. over your lifetime? Hopefully, this illustrates the breadth and depth of Operational Risk Management (ORM) and some of the key considerations. Your single points of potential failure. Your risk exposures and places to focus your design. Your decisions and how this shapes your culture and principles. Your trust and transparency.

One last thought. How would you currently judge your risk parity? In other words, how have you allocated risk effectively across the organization. Not in terms of assets, but in terms of volatility. Think about it. What kind of social contract do you have in place to operate together?

Is it true, that you are now on your way to achieving true "Business Resilience"...

19 August 2018

Information Threat: Battle for Superiority...

What continues to be the greatest economic threat to your organization? Is it "Internal" or "External" to your institution? Could it be both?

Insiders rarely work alone and therefore the nexus with some outside influence, whether it be a person, life factors or some other entity are typically in play.

Is an engineer in R&D copying precious intellectual property information from within the enterprise company, that could be worth hundreds of thousands or even millions to the highest competitive global bidder? Could your small business have an accounting supervisor that has been diverting funds to a private bank account for the past two years?

Would it be possible that a supplier or 3rd party partner is capable of inflating the number of billable hours on a project?

Whether it's IP Theft, Fraud or other white collar corporate malfeasance, these Operational Risks are real and growing at a double-digit percentage rate annually. The greatest economic threat to your organization could be complacency or an apathetic staff, who works without adequate resources and little communication with the Executive "Powerbase".

The compliance and oversight mechanism's are in full swing from the federal governments around the world as highly regulated critical infrastructure organizations are implicated in a myriad of corruption, scandal, ethics and criminal matters.

Litigation is an Operational Risk that many organizations have realized the necessity for more robust internal teams to address the continuous requests for information from the government.

There is one common denominator across all of the insider threats, external forces and other vectors that seem to be attacking our institutions night and day. That common denominator is "Information".

And underlying this is the data and meta data that all to often ends up being the key or clue to finding the "Smoking Gun" and the source or person(s) associated with the scheme or attack on the organization.

Managing information in a mobile and interconnected planet is a major issue in any global company. Providing the tools and the right information faster and more accurately than the competition can be the difference in your own survival on the corporate battlefield.

So how does the CxO suite even begin to address the risks, opportunities and resilience in our demanding "Information-centric" environment?

They believe in having a strong culture of ethics, training and continuous monitoring of employees, systems and their supply chain. They understand the importance of providing the vital resources to the people on the front line of risk management and to make sure that their early warning systems and methods are not compromised.

This breed of CxO's are the new breed of organizational management, that are leveraging information to their most significant advantage:
Whether you are trading in a marketplace, analyzing assets on a map or manufacturing widgets and selling them to qualified buyers, operational risk management begins and ends with information. Managing that information effectively and more accurately than your competition is the name of the game. What have you done today to insure your survivability in the face of the next crisis?

17 September 2017

DEF: Defense Entrepreneurs Forum Increases National Security Velocity...

There is a tremendous amount of buzz and focus on innovation these days, especially around the .gov and .mil ecosystems.  The Defense and Intelligence domains are in a race and competition for increased velocity in procurement, adoption of new or updated systems, talented people and the implementation of state-of-the-art Commercial-Off-The-Shelf (COTS) solutions.

Every so often you come across some thought leaders like the Defense Entrepreneurs Forum (DEF), that know what true innovation means.  They get it.  The membership understands that innovation does not always = technology alone.  The process of innovation and the people who surround it will tell you, that many prototypes of new innovation do not always include semiconductors, transistors or gigahertz.

When you combine the nodes of an ecosystem of smart people, devoted to increasing velocity in the defense and intelligence communities, there will be inspiration, connection and empowerment.  Each one of these nodes is vital, yet they grow and sustain themselves independently.  Working together however, they will provide our national security institutions additional resources, insight and outside the agency expertise.

At the latest Annual Forum at University of Texas - Austin this past week, it was in full force in conjunction with "Clements Center for National Security".  Keynotes and talks from Adm. William McRaven (ret.), Ori Brafman, Col. Mark Berglund, Brigadier-General Hans Damen, Admiral Bobby Inman (ret.), Todd Stiefler, Warren Katz, Clare O'Neill, Lauren Fish, Kaly McKenna, Eric Burleson, Brendan Mullen, Steve Slick, Kristen Wheeler, Kristen Hajduk and others were just the top line.

The bottom line up front is that as a participant, you witnessed first hand, that people with outstanding ideas with a similar mission and the genuine enthusiasm for improving United States National Security is increasing velocity.  In greater numbers, momentum and thought leadership.  The Defense Entrepreneurs Forum (DEF) is now in it's 5th year and is a best kept secret no longer.

So what?  What is DEF’s goal?

"We believe that the complexity of national security necessitates Defense professionals with innovative solutions. We believe that great ideas do not depend on rank and that creative problem solving cannot be developed rapidly. Today’s junior and mid-grade Defense professionals will be the future military leadership of this country.
  • Inspire: By attracting diverse, passionate, and innovative individuals, DEF inspires individuals through a community of like-minded national security innovators.
  • Connect: In person and virtually, DEF is a network that connects innovative thinkers who seek to improve on the status quo and educates them on how to do this.
  • Empower: Through a variety of methods--from idea generation to senior-leader engagement--DEF empowers junior leaders to be change agents in national security."
The innovation mindset is only part of the equation.  You need people with the context, experience and ambition to make a real difference.  Those who are seeking new ideas, new talent and new methodologies for increasing velocity.  People who want to contribute time, resources and intellectual thought leadership.

As the wheels went up on the dawn of a new day over Austin, TX our plane headed North East.  The future is bright for U.S. National Security.  Trust is in the wind and the Defense Entrepreneurs Forum is accelerating...

05 August 2017

LIGHTest: An Open Global Ecosystem of Trust...

On the dusk of another day in Southern California, there are new TrustDecisions being made, that will impact how our IoT and Critical Infrastructure evolves in the decades ahead.  Operational Risk Management (ORM), will continuously adapt to our global future of "Achieving Digital Trust."

Yet, this innovative catalyst and consortium has been forming over the past year, from the European Union.  It is called LIGHTest.
"Lightweight Infrastructure for Global Heterogeneous Trust management in support of an open Ecosystem of Stakeholders and Trust scheme"
"This is achieved by reusing existing governance, organization, infrastructure, standards, software, community, and know-how of the existing Domain Name System, combined with new innovative building blocks. This approach allows an efficient global rollout of a solution that assists decision makers in their trust decisions. By integrating mobile identities into the scheme, LIGHTest also enables domain-specific assessments on Levels of Assurance for these identities."

Trustworthy computing is not new and it has been evolving since the beginning of the Internet with PKI.  What is encouraging and worth pursuing now, is a better understanding of the problem-set.

What is the real problem, that LIGHTest will address and try to solve?
"The DNS translates domain names that humans can remember into the numbers used by computers to look up destination on the Internet. It does it incrementally. Vulnerabilities in the DNS combined with technological advances have given attackers methods to hijack steps of the DNS lookup process.
They want to take control and direct users to their own deceptive Web sites for account and password collection to perpetuate their Internet disruption attacks and crime schemes. The only long-term solution to this vulnerability, is the end-to-end-deployment of a security protocol called DNS Security Extensions – or DNSSEC."
So what?

The Domain Name System (DNS) relies on these foundational entities for our Global Internet. Designated by letter, they are the operators of the root servers:

A) VeriSign Global Registry Services;
B) Information Sciences Institute at USC;
C) Cogent Communications;
D) University of Maryland;
E) NASA Ames Research Center;
F) Internet Systems Consortium Inc.;
G) U.S. DOD Network Information Center;
H) U.S. Army Research Lab;
I) Autonomica/NORDUnet, Sweden;
J) VeriSign Global Registry Services;
K) RIPE NCC, Netherlands;
L) ICANN;
M) WIDE Project, Japan.

Ref: http://www.root-servers.org

Now when you are just starting to understand the complexity of the problem that LIGHTest is attempting to solve, you add "Mobile Identities" to the dialogue.

It is one step towards trust to get machines to complete a transaction with integrity and consistent trustworthiness.  When you add the challenge of validating reputation and identities of people, the scale of the entire problem-set soars.  The geopolitical and organization boundaries that are now the state-of-play are tremendous.  The United States Department of Commerce is at the table.

Think about how far we have come in our technological history and enterprise architecture, with the pervasive use of communications satellites and 30 billion mobile devices by 2020, now imagine how far we still have to travel, to attain true "Digital Trust."  The infrastructure is global and the complexity is far greater than most humans can truly understand.  To trust one another, to trust transactions, to trust our machines and digital inventions implicitly.  That is our lofty aspiration.

LIGHTest is heading in an innovative direction, in the pursuit of greater trustworthiness and we have to keep reminding ourselves why:

Instilling fear in peoples minds about monetary losses, stolen intellectual property, hackers, cyber criminals and rogue web sites is important.  Buyer beware!  Stranger danger!  See something Say something.  WannaCry.  AlphaBay.  No different than wanted posters for bank robbers, fraudsters, or terrorists.
Companies, people, products or services that continue to serve up messages of digital fear, uncertainty and doubt, are in need of even more clarity and education.  The real problem-set to be solved is about trust and making more highly effective trust decisions, at increasing velocity...

19 March 2017

Startup Strategy: Opportunity of Digital Trust in a New Era...

The startup ecosystem of new ideas for SaaS platforms or mission based digital solutions are becoming evermore robust, in our growing economy.  As a result, Operational Risk professionals are more in demand to help new co-founders adapt to the legal, compliance and consumer transparency requirements, that will soon descend upon them.

It makes sense, that when you are starting a new company you first are focused on the product/mission and who the intended market or user will be.  Yet soon after this is defined and the "Go-to-Market" strategy is in place, there is a tremendous amount of Operational Risk design and implementation of internal capabilities, that will be required.  In just Social Media, here is just one example:
"As social networks continue to mature, they increasingly take on roles they may not have anticipated. Moderating graphic imagery and hate speech, working to address trolling and harassment, and dealing with dissemination of fake news puts companies like Facebook and Twitter in powerful societal positions. Now, Facebook has acknowledged yet another challenge: Keeping your data safe from surveillance. That’s harder than it may sound. When you post something publicly on a social network, anyone can view it—including law enforcement or federal agencies."
Since the dawn of the Internet, new startup companies have been developing algorithms and bots to scour the vast landscape of "data oceans" for relevant content.  As public Internet tools, databases and consumer-oriented web sites were developed for even Blogs (Blogger.com) such as this one, other companies were figuring out how to capture the data content in their searchable systems.

Years later, startups developed ways to develop the API as a new product-set, so that other companies could embed and utilize a set of data or capability and have it more integrated with a new set of functionality or service mission.  What is one company in this category focused on Twitter?  Gnip.com:
"PowerTrack provides customers with the ability to filter a data source’s full firehose, and only receive the data that they or their customers are interested in. This is accomplished by applying Gnip’s PowerTrack filtering language to match Tweets based on a wide variety of attributes, including user attributes, geo-location, language, and many others. Using PowerTrack rules to filter a data source ensures that customers receive all of the data, and only the data they need for your app."
So what?

If you are a startup company that is planning on a pledge to your customers to "Keeping your data safe from surveillance," just as the juggernaut Facebook is also currently doing, you have a tremendous amount of work and new processes/systems to get in place.  You are embarking not only on the steep growth curve of adding new customers and revenue; you are simultaneously under the mandate to help achieve a higher level of "Digital Trust" with those same customers.

Developing the policy alone is only the start.  Here is how Twitter is addressing it:

"To be clear: We prohibit developers using the Public APIs and Gnip data products from allowing law enforcement — or any other entity — to use Twitter data for surveillance purposes. Period. The fact that our Public APIs and Gnip data products provide information that people choose to share publicly does not change our policies in this area. And if developers violate our policies, we will take appropriate action, which can include suspension and termination of access to Twitter’s Public APIs and data products."

How Facebook and Twitter and Snapchat or LinkedIn and all of the hundreds of Social Media companies will scale up enforcement, is now the big question.  Maybe they have the deep pockets and resources to build and operate their "Digital Trust" business unit.  What about the new startup with only 6 or 7 figures in the bank from a seed or even "A" round of funding?

The policy implications and new federal laws being drafted in the United States and the European Union may be good indicators of where the future requirements will be defined for a new startup.  In the EU this week, the G20 finance ministers are converging on the topic of "Cyber Crime" soon after a recent indictment:
"Two intelligence agents from Russia, another G20 member, with masterminding the 2014 theft of 500 million Yahoo accounts. The indictment was the first time U.S. authorities have criminally charged Russian spies for cyber offences including for computer fraud, economic espionage, theft of trade secrets, and wire fraud."
How will the new startup who is focused on addressing transparency, privacy, and surveillance now "Enable Digital Trust of  Global Enterprises."  Here is a glimpse from the latest PwC CEO Survey:

"Yet, if forfeiting people’s trust is a sure-fire route to failure, earning their trust is the single biggest enabler of success. As an example, the progression from assisted to augmented to autonomous intelligence depends on how much consumers and regulators trust machines to operate on their own. That, in turn, depends on whether those who create the machines have the right risk and governance structures, the means to verify and validate their claims independently and the mechanisms to engage effectively with stakeholders."

"In short, trust is an opportunity, not just a risk. Many CEOs recognise as much: 64% think the way their firm manages data will be a differentiating factor in future. These CEOs know that prioritising the human experience in a virtual world entails treating customers with integrity."


Welcome to the new era of achieving Digital Trust...

12 March 2017

Vault 7: Adapt to Live Another Day...

When you spend enough time in any austere environment, you begin to respect it's abilities to change rapidly.  You begin to respect the changing natural forces and how these new potential threats could become a new Operational Risk in just minutes.  The decisions that you make in the next few seconds, could mean a positive outcome or a significant catastrophe.

Will you turn right or go left?  Will you accelerate or slow down?  Will you ascend or descend?  These decisions that you make in your quest to adapt to your changing austere environment will forever be remembered.  Whether they are stored in the synapses of the brain or the log files of an autonomous system executing code, the trust decision is evident.

How long has it been since you really took a deep look at your decisions the past minute, hour or day?  This analysis of the evident decisions made and the environment that you are operating in will forever allow for growth or death.

Systems thinking and the continuous learning of a changing environment can happen at 12,000 feet above sea level at minus 10 degrees, or within the climate-controlled data centers or corporate offices of your global enterprise.  What are you doing today to help achieve new levels of trust, in order to survive another day?

Why is it that so many individuals are surprised when they get a call from their CxO or even corporate counsel that sounds like this?  "It looks like our Intellectual Property or Trade Secrets, are now in the hands of our competition".  "Our enterprise is encountering significant new risks to our ongoing operations and we must adapt immediately'.
Introduction
Just as American and European critical infrastructure executives were beginning to wrap their minds around the devastation of the Office of Personnel Management, ransomware erupted onto the scene. We then experienced concentrated DDoS attacks such as the Mirai botnet attack on Dyn, which enabled a quantum leap for cyber criminals of even the most novice of technical aptitude to wreak havoc on targeted organizations at the click of a button or for less than one bitcoin. Unfortunately, adversaries continue to evolve, and cyber defense remains a reactionary culture. Numerous, persistent and adaptive, cyber-adversaries can more easily, remotely and locally besiege critical infrastructure systems, than information security personnel can repel the incessant barrage of multi-vector attacks. Now, all techno-forensic indicators suggest that an under-discussed cyber-kinetic attack vector will ubiquitously permeate all critical infrastructure sectors due to a dearth of layered bleeding-edge military grade cyber security solutions. Unless organizations act immediately, in 2017 The Insider Threat Epidemic Begins.
Some people are surprised.  Yet it is the small team of "Operational Risk Professionals" in your enterprise, that have been continuously training, operating in clandestine and unknown environments and learning each day, for this moment.  They are not surprised.  They are the people who have designed their operations and systems to be resilient, to endure austere environments and to adapt to live another day.

Seek out these people in your organization.  Find the expert individuals in each of the departments or business units, that also interface with your external environment and supply chain.  Now look inside and in the mirror.  Where are the vulnerabilities inside?  How can you adapt your operations to create trust with employees and simultaneously make your organization more resilient?
Take the “Vault 7” CIA data Wikileaks released this week. Assuming it is legitimate, it originated from a network that presumably has a very small attack surface. Wikileaks expressly claims that the data is from “an isolated, high-security network situated inside the CIA’s Center for Cyber Intelligence in Langley, Virgina,” and experts agree that seems likely. And knowing that CIA networks are probably secure and defended supports the notion that the the data was either leaked by someone with inside access, or stolen by a well-resourced hacking group. It’s far less likely that a random low-level spammer could have just casually happened upon a way in.
 Build digital trust in your organization by better understanding the entire surface for potential attacks.  Analyze the rules that are in place now and how they might need to be changed according to the continuously changing environment you operate in.

Finally, adapt to live another day...

27 August 2016

Human Capital Risk: Know Your Company...

Operational Risk Management (ORM) is about continuous innovation.  It requires a steadfast momentum towards a future spectrum of dynamic resilience.  The shift in thinking is that your ability to survive the impact of any adverse incident to your people, process, systems or other external factor is commensurate with your current-state of resiliency.

You must establish and cultivate the creative and innovating environment in your organization at the core.  Then wrapped around this ecosystem of core human potential, the culture evolves into a ripe entity of new possibility.  New hope.

Simultaneously the visions of what contributes to a healthy environment and the attributes of what creates a deterioration, starts to become more clear to you.

You see, when most people think about risk management they are immediately drawn to threats and vulnerabilities external to the organization.  Protect against known external threats and remediate known vulnerabilities.

How much time is devoted to understanding the maturity and the resilience of your core internal ecosystem of human capital.  From the inside out.  The same human capital that will either achieve survival after any known or unknown incident, could also contribute to it's inevitable demise.

So what are we talking about it?  How well do you know your company?  Jason Fried, CEO of 37signals.com explains:
  • As CEO, maintaining a healthy culture isn’t someone else’s job — it’s my job. I had to take responsibility for knowing my people and knowing my company. That buck starts and stops with me.
  • Answers only come when you ask questions, so the tool had to be built around questions. People generally don’t volunteer information re: morale, mood, motivation unless they’re directly asked about it.
  • The entire system had to be optional. No one at the company should be forced to use it. Forcing people to give you feedback is ineffective and builds resentment.
  • This couldn't be a burden on my employees. Employees would never have to sign up for something or log into anything.
  • Information had to come in frequently and regularly. Huge information dumps once or twice a year are paralyzing and lead to inaction.
  • I had to follow-through. If someone (or a group of people) suggested an important change, and it made sense, I had to do everything I could to make it happen. I wasn't creating this system to gather information and do nothing about it.
  • It had to be automated, super easy (for me and my employees), non-irritating, and regular like clockwork. This had to eventually become habit for everyone involved. If it ever felt like something that was in the way or annoying, it wouldn’t work. It had to be something people looked forward to every week.
  • Feedback had to be attached to real people - it couldn’t be anonymous. You need to know your people individually, not ambiguously. If someone has a problem, you need to know who it is so you can talk to them about it. This requires trust on everyone’s part.
  • Success depended on a combination of automated, and face-to-face, back-and-forth with my team. The unique combination of automated and face-to-face communication play off each other in really positive ways.
Quantity vs. Quality.  If you have read any of Jason's books such as "Rework" you know what we are talking about.  37 Signals has been in business now about 16 years and has just surpassed xx people. Congratulations Jason.

Managing Operational Risks with an organization begins with the clairvoyance and the insight gained from knowing your human capital.  Knowing your people when they come on board and knowing how they change over time.

Do you think that the person you hired two years ago is still the same person? What about ten years ago or 20?  People change for a myriad of reasons impacted by the environment on the home front and certainly their work place environment.

The resilience of your organization begins and ends with knowing your company, or government agency.  In order to know your enterprise, you need to know your people.  Your ecosystem of innovation possibility and the longevity of your organization depends on it.   As a recent agency example,  commentary by George Bamford:
In the summer of 1972, state-of-the-art campaign spying consisted of amateur burglars, armed with duct tape and microphones, penetrating the headquarters of the Democratic National Committee. Today, amateur burglars have been replaced by cyberspies, who penetrated the DNC armed with computers and sophisticated hacking tools.
Where the Watergate burglars came away empty-handed and in handcuffs, the modern- day cyber thieves walked away with tens of thousands of sensitive political documents and are still unidentified.
Now, in the latest twist, hacking tools themselves, likely stolen from the National Security Agency, are on the digital auction block. Once again, the usual suspects start with Russia – though there seems little evidence backing up the accusation.

09 April 2016

Trade Secrets: Gearing up for DTSA...

The Fortune Global 500 and the smallest research and development organizations in the U.S. have another ruleset to keep their eye on this week.  It is named DTSA or S.1890 - Defend Trade Secrets Act of 2016 has passed the Senate.  Operational Risk Management (ORM) is preparing for the next addition to national laws.

The attribution of cyberespionage adversaries has been gearing up since the Sony Pictures hack.  The private sector has been hunting and identifying those shadow individuals and nation state special units for years.  Now the lawyers can get more aggressive with civil actions.

The question remains, will another law deter the actions by global organized crime and the intelligence community of some significant nations?  How will attribution and more aggressive civil actions in foreign jurisdictions make a difference?

As a global organization, can you access your database of confidential trade secrets?  No different than the task of the identification of information assets that you are going to protect, you need an inventory.  What are they and where are they?  Everyone knows the formula for "Coca-cola" is written on a single piece of paper that is locked up in a vault in Atlanta, GA right?  Or is it?

There are trade secrets across America that have been stolen by operatives working inside organizations.  They may be preparing to leave the U.S. for another country outside the reach of law enforcement and the legal process for seizing the stolen property.  That is going to change soon.
The EX-Parte Seizure Order is part of the Trade Secrets bill that allows a trade secret owner to obtain an order from a judge for U.S. marshals to seize back the trade secret from the alleged bad actor without prior warning. This is to protect the trade secret owner from having the alleged bad actor skip the country or destroy the evidence before it is recaptured.
Now that Trade Secrets are in the same legal and enforcement category with patents and trademarks, you can predict that your legal budgets will need to be adjusted, upwards.  In general, what is a Trade Secret?
The subject matter of trade secrets is usually defined in broad terms and includes sales methods, distribution methods, consumer profiles, advertising strategies, lists of suppliers and clients, and manufacturing processes. While a final determination of what information constitutes a trade secret will depend on the circumstances of each individual case, clearly unfair practices in respect of secret information include industrial or commercial espionage, breach of contract and breach of confidence.
The effort to make intellectual property a "Trade Secret" is another strategy in itself. The determinations to designate something a trade secret is going to depend on the invention or the data itself. We understand. So what?
A Chinese businessman pleaded guilty Wednesday (March 23) in federal court in Los Angeles to helping two Chinese military hackers carry out a damaging series of thefts of sensitive military secrets from U.S. contractors.

The plea by Su Bin, a Chinese citizen who ran a company in Canada, marks the first time the U.S. government has won a guilty plea from someone involved with a Chinese government campaign of economic cyberespionage.

The resolution of the case comes as the Justice Department seeks the extradition from Germany of a Syrian hacker — a member of the group calling itself the Syrian Electronic Army — on charges of conspiracy to hack U.S. government agencies and U.S. media outlets.
Our adversaries are determined. They are already here. It has been documented for years. Let the next wave of legal indictments and seizures begin. One thing is certain. The "Insider Threat" is still present and your organization can do better. The ability to effectively utilize the correct combination of controls, monitoring, technology and internal corporate culture shifts will make all the difference. What are you waiting for?

05 March 2016

Zeros and Ones: Context & Proportionality Don't Translate...

"Context and Proportionality do not translate to Zeros and Ones."  This was a key take away from the 2016 RSA Conference last week in San Francisco.  Thousands of Operational Risk Management (ORM) professionals attended to listen to speakers with titles such as Attorney General, Secretary of Defense and Chief Technology Officer.

Perhaps more important however, were the actual practitioners in the legal system and those "Quiet Professionals" responsible for our national security, who were clearly outlining the digital landscape and our significant challenges ahead.  For our nation and the future of our social and economic destiny.

The software engineers and companies who are writing millions of lines of software code are at risk.  Here is why.  Context and Proportionality do not translate to Zeros and Ones because lawyers are writing words with "Semantically Intentionally Ambiguous Meaning" (SIAM), in the pursuit of achieving digital trust.  Privacy and security intent in the translation from lawyers to software engineers, has been lost for a long time.

How can we summarize the entirety of what just took place this past week at RSA:
  • Visibility
  • Threat Protection
  • Compliance
  • Data Security
These four pillars are where the industry is still categorized in the majority, yet we came across some very interesting companies and products that are creating a new buzz.  Walking the halls and observing the presentations, the mobile computing generation was in full force.  As everyone shuffled between sessions like the overcrowded high school hallways, the only safe location was on an escalator where you could stare at your iPhone for 20 seconds with a little peace.  Can you imagine the amount of intellectual property intelligence being collected by competitors and adversaries using digital sensors and good old fashioned trade craft during the week?

So what?  In the spirit of all the talk and debate, the sales and marketing, the presentations and powerpoint slides, what have we learned?

"Context and Proportionality do not translate to Zeros and Ones."

Why is this so important to grasp?

At a certain point in the accelerating evolution of technology innovation there are disruptive bifurcations.  It means that the rise of a particular system achieves a point in time when instead of rising and growing on the "S" curve, the system begins its descent and erosion, until it is outdated or no longer trusted as a standard.

We are soon to reach a new bifurcation in the digital systems that run our businesses, markets and governments.  The organizations who rely on the Internet in their daily operations need to adapt.  Quickly.  Those that are able to accomplish rapid reengineering will survive.  And those who wait or miss the signals to adapt, will perish or become absorbed by the digital environment surrounding them.

19 December 2015

Cyber Domain: International Law of Asymmetric Warfare...

The international laws and human understanding of what crosses a "Red Line" are being defined in cyberspace in real-time.  The operations of the Chief Security Officer (CSO) and Chief Information Security Officer (CISO) are now becoming more adaptive.  The Operational Risk Management (ORM) enterprise architecture, will soon call for three standard mission functions:
  • Computer Network Attack (CNA): Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves.
  • Computer Network Defense (CND): Includes actions taken via computer networks to protect, monitor, analyze, detect, and respond to network attacks, intrusions, disruptions, or other unauthorized actions that would compromise or cripple defense information systems and networks.
  • Computer Network Exploitation (CNE): Includes enabling actions and intelligence collection via computer networks that exploit data gathered from target or enemy information systems or networks.
 Computer Network Defense (CND) has been the norm for many organizations and now, that is no longer enough.  Yet before we can determine why we must  add CNA and CNE, we better understand the breadth and depth of the cyber realm.  The "Over-the-Horizon" view, of the reality of that domain, is rapidly developing into a proactive risk management imperative, for Global 500 organizations.  Why?

The non-state actors are organizing and evolving into what could be coined for the laymen, as a modern day "Cyber al-Qaida."  A "Cyber  Taliban."  Or even a "Cyber 1st Amendment or 4th Amendment cadre of affiliated entities.  These digital non-state actors following a set of ideologies, as opposed to a set of true investigative journalists or independent non-partisan watch dogs, are metastasizing at an exponential rate.

This ideology fueled by cyber activism and directed at a particular organization or country, is on a digital battlefield that spans the globe.  It has long been said that the Internet is nothing more than a mirror, of the good and evil in our physical world.  The existence of cyber warriors who are interested in going beyond the goal of financial crimes to kinetic destruction of critical infrastructure, is a well known fact.

Who are these cyber warriors that identify with a movement or cause, that attack the well being of other humans or destroys the property or economic assets of another organization.  They are the same ideologues that have existed long before the Internet.  The difference is that the reach, speed and ubiquitous nature of the digital medium accelerates the threat and the requirement for an effective counter balance.  Putting actual skill sets aside for a moment, the real differentiator has been on a "White Hat" or ethical warrior focus:
Regarding whether there were different rules of armed conflict for cyberwarfare in dealing with states like Iran, versus terror entities like Hamas or al­-Qaida, he first noted that while there is “no consensus,” the “US, Israel, England and others” argue that “self ­defense” principles justify attacks against terror groups, even if they are not states.  --IDF Col. Sharon Afek-- Article by Yonah Jeremy Bob
The CNA, CND and CNE operations in the digital Global 500, will now employ those individuals who have an ideology that is more directly opposed to the worldview of a "Cyber al-Qaida."  In the long war, the cyber "White Hats" will endure.  The asymmetric warfare of the next decade, will encompass operational risk professionals behind the network, who have a different context.  Why? Because they believe in a ideology far more patriotic than their predecessors.  They are the "Quiet Professionals" who have retired from SOCOM active duty and now span the ranks of the corporate private sector.

The international laws of the cyber domain are in play for our prosperity or our peril.