Showing posts with label policy governance. Show all posts
Showing posts with label policy governance. Show all posts

22 August 2026

Innovation: Truth in Data Provenance...

For years mathematicians and computer scientists have written about the trustworthiness of “Data Provenance”.


Relying on the integrity of data collection, transport and of course the source of data is a real science.  Our modern day zeros and ones span all aspects of our lives and Operational Risk Management (ORM) professionals have encountered the questions surrounding trust and the process of decision making long before the invention of computing machines.


At the root of decision making with integrity the source of data is questioned.  The reliability and history of previous data from the source.  As the data was transported from Point A to Point B was there any possibility that the data was altered, modified or corrupted.


Couriers and the use of a "Hawala" type system have been used by traders and terrorists for hundreds of years.


"Truth in Data Provenance" is the question mark that enables trust decisions.  This is why modern day cryptography is at the center of so many arguments and debates, when it comes to the topic of trusted information.  Yet hundreds of years ago, long before telecom and ICT was invented, the trustworthiness of data provenance was a vital factor.  The use of transposition ciphers were in use by the ancient Greeks.


So what?  In 2026 what does the truth in data provenance have to do with our business commerce, our transportation, our banking, even our abilities as governments to maintain our defense against attack?


The topic is vast and deep and worth exploration at the top level of human decision-making.  Yes, it is vital that our computing machines have high-assurance data integrity, in order for our global systems to operate day-to-day.


Yet what impact does trusted information have with humans in an environment of work and daily collaboration?  How does truth in data provenance, affect our decision making and the environments we work in?


In a report by LRN, the subject of trust in the work environment as a motivator has become more apparent:


Another fascinating result of the study had to do with two squishy-sounding characteristics of a company: character and trust. Companies deemed by employees to have both strong character and inspired trust performed almost four times better, using the metrics mentioned earlier, than those that had other positive cultural attributes, such as collaboration and celebrating others. (This applied to all three types of companies, though, naturally, culture and trust were much more prevalent in the self-governing ones) What’s more, “high trust” organizations were 11 times as likely to be called more innovative than their competitors. Trust, the How Report suggests, is more important than virtually any other characteristic.

How organizations address the trustworthiness of data provenance is still a new frontier in this day and age.  The use of new sensors, sophisticated analysis of "Big Data" by computer algorithms (AI) and the pace at which new data is generated by the "Internet of Things" (IOT) makes this a significant area of focus for our current executives and enlightened organizational leadership.


Why?


But what does that really mean? How does one measure the absence or presence of something as abstract as trust? The How survey defines it as “a catalyst that enhances performance, binds people together, and shapes the way people relate to each other.” High trust groups encourage risk-taking, which in turn is what is necessary for true innovation to occur. When innovation fails, it’s because companies don’t put enough faith in employees to let them take risks. The industries with the highest amount of trust were “computers/electronics,” followed by “software/Internet.” Coming in last? Government.

At the most fundamental level, the culture you are operating in has all to do with the trust that exists or is absent.


It has all to do with the trustworthiness of data provenance.  Leadership in any organization, must see the relevance between trust and innovation.  Between innovation and risk-taking. 


Your future and your culture depends on it...

16 May 2026

Liaison Mission: When Will You Introduce Them?

As a current Chief Executive Officer or Commander across some branch or agency, who have you named as a key "Liaison?"  Who is this vital person that you have asked to be your voice, your thinking and your representative to a partner, collaborator or strategic ally?

In Chris Fussell's book One Mission:  How Leaders Build A Team of Teams, the Task Force Liaison is described as follows:
"We clearly share a determined adversary--one that, unlike our organizations, is networked and thus moves with incredible speed. In the Task Force, we are now trying to forge a new type of model based on relationships among individuals and organizations like yours--and we'd like to be more closely connected with your organization. Winning will come from leveraging our mutual strengths, sharing insights and nuanced understanding of the problems and respecting one another's positions.

To help our partnership, we would like to give you one of our best people as a liaison. I expect our liaison to be an asset to you, sharing anything we're doing, providing our most timely intelligence, and seeking out ways that we can help your organization accomplish its goals."
This idea is not a new strategy per se.  Similar derivations of the concept have been utilized for hundreds if not thousands of years.  So why is this so important now, to the current state of global and corporate affairs?

The first reason is that operating at the speed of "iMessaging" social media, will create chasms of misunderstanding.  The simple fact is that information being collected, interpreted and disseminated in your digital-based platforms will most likely have gaps.  The messaging and communications will be hard to decipher by others, who don't know all of the acronyms as just one example.

This is where an embedded "Liaison Officer" or representative can bridge the cultures and the lines of direct messaging.  This is how the speed of the combined network is increased in it's ability to pivot, to adapt and to solve problems, faster and with higher quality than the competition.

The second reason is that a key mission of the nominated Liaison is to establish, maintain and perpetuate trusted relationships.  Otherwise, how can the leaders of your two organizations gain any momentum, in the quality and the speed of the partnership that is desired as a relevant outcome?

Now think about your own organization.  Where do you have a blind spot?  What other entity, team, business unit or agency is now seen as a barrier or competitor?  Are you both after the same customer, the same target or the same outcome?  Is a partnership in place now, to even embed or exchange Liaison personnel?

Believe us when we say that your adversary has already done the same.  They are working together across boundaries to share intelligence, to exchange vital data and to work in tandem to perpetuate their cause, their ideology or their campaign.  They have their own trusted Liaison's working each day, to move faster than you are and to achieve new gains in their mission, while you are worried about the unknowns.

Who is it in your organization that you feel that you can't live without?  The one or two leaders that you rely on each day.  The personality that exhibits the way that "Adam Grant" describes a "Giver" or "Matcher," in the way they operate across the team and within the company.  This may be the best person for you to let go of and to be your next "Liaison" to that vital partner, agency or even country.

Looking across the landscape of America, you will find examples of this idea and methodology that is working.  You will find places across the globe where it is in total failure.  Yet how can you raise the odds, that the likelihood of the person you choose to be embedded with another organization, will indeed succeed?

As a current Team Leader, CEO or Commander, it means you will have to go a step farther.  It means that you will have to take this person side-by-side in many cases, into the same office, SCIF, SOC, NOC or conference room to explain it face-to-face.  Sitting across the table from this partnered organizations top executive, you say it:

"I have carefully selected "Jill or Jack" to be our Liaison with your unit or department.  It is something we know to be of great value to the ongoing mission we both face, to address the (problem-set).

 Please know that she/he knows me very well and how I think and what our organizations real capabilities are.  We will miss them, yet want her/him to work alongside your leaders to learn as fast as possible about your greatest hurdles and problems.  It is only then, that we envision a chance for our respective teams to move faster with the most effective joint solutions, to obtain and synchronize our advantage." 

This few minutes face-to-face may make all the difference on the potential for a successful and trusted relationship.  As you stand up and leave your Liaison with their new assigned organization, remember this.

Your Liaison's ability to succeed, will only be as good as the job you have done in preparing them for the assignment.  Think about all the months or years you have worked to shape their character, to instill the ethics and integrity into their daily decisions.  How many problems did you let them solve on their own?

We look forward to hearing the stories about your "Liaison's" and their respective missions to achieve decision advantage and to reach those lofty outcomes you seek...

17 January 2026

Intelligence Sharing: Responsibility to Provide...

Back in the summer of 2008, the "Need to Know" was now finally becoming extinct. Intelligence Communities around the globe began ever so slightly changing their behavior.

The Office of the Director of National Intelligence (ODNI) had released it's Information Sharing Strategy:

The Office of the Director of National Intelligence was announcing the first-ever strategy to improve the ability of intelligence professionals to share information, ultimately strengthening national security.

The "Responsibility to Provide" attitude combined with a "Rule-set" reset could get the entities moving the right direction. Risk Managers in institutions in the private sector have been grappling with this business issue for multiple decades.

The reality that the FBI, NSA, CIA and DHS are sharing more effectively will only be evident in actual behaviors, not technology.

The new mantra "Responsibility to Provide" would be repeated over and over but where is the evidence?  

The culture shift was predicated on the ability to manage risks associated with mission effectiveness and disclosure of sensitive information. A Trusted Environment.

This new information sharing model is not revolutionary and requires the same care with privacy, information security and civil liberties that we all expect when it comes to personal identifiable information.

Adding new incentives to share information or rewards for doing so will soon be the norm and the behavior changes will be evident. Great care will be given to the ability to protect sources and methods of collection.

Creating a "Single Information Environment" (SIE) will improve the ability for analysts and investigators to get access earlier and to discover what exists. Enhancing collaboration across the IC community would be a strategic goal and has been a dream for over twenty years.

So let's go back to the "Trust Model" for a minute:

  • Governance: The environment influencing sharing.
  • Policy: The "rules" for sharing.
  • Technology: The "capability" to enable sharing.
  • Culture: The "will" to share.
  • Economics: The "value" of sharing.

A 500 day plan was then in place. The integration has now been reemphasized even today. Let's make sure that our vigilance continues and on this Martin Luther King Jr. weekend, our spirits are reenergized...

18 March 2023

Reliable: Who Do You Have Faith In?

When you think of the person you would recommend for a particular task or to perform defined professional services, who comes to mind?

There are many ways and words to describe a person or the business, yet if you had only one word to choose from, what would it be?

Reliable  adjective

1: suitable or fit to be relied on: DEPENDABLE

2: giving the same result on successive trials

Reliable noun

1: one that is reliable

In many cases, this is the word people really mean to use, as the basis for their recommendation.

Whether a business or a person is reliable, makes all the difference in your world, especially if you must rely on the outcomes of their service or duty.

When someone or something you pay for, does not meet a series of positive results, you begin to question your decision to utilize the service or receive the product for use.

Unfortunately for many people and businesses, this word “Reliable” is not considered or even measured on a consistent or measurable basis.

"Over the course of time in your life, think of one person or business you could say was truly reliable."

Think of this one person or business you have utilized for more than ten years that is reliable.

In any professional capacity, becoming reliable takes many years of practice and substantial learning. It requires the development of people, processes, systems and real innovation.

Now, think about someone or an entity (business, product, government agency) that you have lost faith in.

The people or businesses that you have stopped interaction with, have become “Unreliable” for your particular requirements or expectations of quality of service.

How would our world change for the better if there was more learning and focus on being “Reliable”?

How can you as a person or business become top of mind, when someone is asked “Who would you recommend” to: _________________?

You too, can become truly reliable…

05 January 2020

ORM: Pervasive Risk Across Disciplines...

What is the origin of the "Operational Risk Management" (ORM) discipline? Was it derived from the work within the financial services industry from the Basel II initiatives?

The definitions and the actual work towards creating standards of conduct and rule-based design has been evolving for the past few decades.

Operational Risk and the approach to risk that is not otherwise considered to be market or credit risk, is one mind set. The other mind set considers the hazards associated with the threat to our valuable assets.

Either point of view depends on the environment that you operate in and the risks associated with that environment.

To give a quick example, here are a few views into Operational Risk in the United States:

"It didn’t take long—the first attack on a U.S. government website hit on Saturday, a day after the killing of Qassem Suleimani in Baghdad. The fact there was an attack is not a surprise—speculation has been rife. And the style of the attack is consistent with the nature of the primary cyber threat we now face. Hackers claiming to be linked to Iran targeted a low-level domain—the website of the Federal Depository Library Program—defacing its home page, echoing Teheran’s threats of vengeance alongside imagery of President Trump, Ayatollah Khamenei and the Iranian flag" Forbes

"Boeing will still burn more than $1 billion a month even after halting 737 Max production, according to J.P. Morgan.  Boeing’s decision to stop suspend production of the troubled aircraft was made in light of months of cash-draining groundings worldwide, but the company’s internal overhead and labor expenses will remain and will increase cash burn, analyst Seth Seifman wrote to clients."  CNBC

These examples encompass a U.S. government agency and a private sector U.S.-based global aerospace company.  Both are operational risk scenarios that could contribute to losses that will also impact the reputation of the entity involved.

That aspect alone, could be the major factor in why Operational Risk Management is such a growing discipline in our 2020 global landscape.

Some of the earliest origins of the Operational Risk concerns come from the military. The U.S. Navy is one of the branches who has embraced it fully:
  • Purpose. To establish policy, guidelines, procedures, and responsibilities per reference (a), standardize the operational risk management (ORM) process across the Navy, and establish the ORM training continuum.
  • Scope. This instruction applies to all Navy activities, commands, personnel, and contractors under the direct supervision of government personnel.
  • Discussion. Risk is inherent in all tasks, training, missions, operations, and in personal activities no matter how routine. The most common cause of task degradation or mission failure is human error, specifically the inability to consistently manage risk. ORM reduces or offsets risks by systematically identifying hazards and assessing and controlling the associated risks allowing decisions to be made that weigh risks against mission or task benefits. As professionals, Navy personnel are responsible for managing risk in all tasks while leaders at all levels are responsible for ensuring proper procedures are in place and that appropriate resources are available for their personnel to perform assigned tasks. The Navy vision is to develop an environment in which every officer, enlisted, or civilian person is trained and motivated to personally manage risk in everything they do.
If only our major business entities would would fully encompass the following steps with all employees and processes then more lives would be saved, corporate assets would be protected and the enterprise would be ever more resilient:

(1) Identify the hazards;

(2) Assess the hazards;

(3) Make risk decisions;

(4) Implement controls; and

(5) Supervise.
Yet the losses and the potential for loss continues across the organizations who are well equipped to make Operational Risk Management a part of every person and operating divisions daily mind set:

The places change, the numbers change, but the choice of weapon remains the same. In the United States, people who want to kill a lot of other people most often do it with guns.


Public mass shootings account for a tiny fraction of the country’s gun deaths, but they are uniquely terrifying because they occur without warning in the most mundane places. Most of the victims are chosen not for what they have done but simply for where they happen to be.


There is no universally accepted definition of a public mass shooting, and this piece defines it narrowly. It looks at the 172 shootings in which four or more people were killed by a lone shooter (two shooters in a few cases). It does not include shootings tied to robberies that went awry, and it does not include domestic shootings that took place exclusively in private homes. A broader definition would yield much higher numbers.

Whether it is on the deck of an aircraft carrier or within any organizations business facility, operational risk is pervasive. It is up to you and your organization to begin to make a difference...

13 October 2019

Organizational Culture: Four Steps to Wisdom...

Data->>Information->>Knowledge->>Wisdom
"Each step up in learning requires a new technology platform. The technology platform that will make possible the leap from Information to Knowledge is the blending of computers and telecommunications with human actions. By the time the knowledge phase matures, around a decade from now, billions of people will use computers with no training at all. Can we imagine the technology platform that will enable us to take the final step to wisdom?" --Four Steps to Wisdom - From "The Monster Under The Bed" by Stan Davis and Jim Botkin

Stan and Jim wrote this book and it was published in 1994. Getting to wisdom is surely now upon us in 2019.  Or is it?

Maturing from step-to-step is not as easy as it may seem.  Think about that learning phase where your organization was taking on the chasm between "Information" to "Knowledge".  What kinds of challenges did you encounter and then conquer in your cultural transformation?
wisdom noun (1)

wis·​dom | \ ˈwiz-dÉ™m
Definition of wisdom

1a : ability to discern inner qualities and relationships : insight
b : good sense : judgment
c : generally accepted belief

The transformation in your organizations from "Knowledge" to "Wisdom" may take much longer to accomplish than the "Information" to "Knowledge" phase.  This is because your culture has not matured enough to even consider the technology platform necessary to make the leap to "Wisdom."

Davis and Botkin talk further about this:  "Business-driven learning will be organized according to the values of today's information age:  service, productivity, customization, networking, and the need to be fast, flexible, and global." Page 18

Does this sound familiar?  Maybe you have heard the words Scrum or DevOps being thrown around in your particular organization.  Or perhaps you have started to focus on agility or innovation as the latest phase of transformation awareness in your business, agency or enterprise.

How can you and your organization take the next step, if you have not achieved the previous level of maturity in your technology adoption?  The speed and comprehension to utilize technology to effectively learn, is a combination of factors beyond just the hardware and software.  It is also a maturity of your learning culture.

As your enterprise makes the leap from "Knowledge" to "Wisdom" the speed of change in your organizational culture must also be commensurate with the speed of change in our technology platforms.

Is your organization still maintaining your own servers and hosting your E-mail internally?  There must be a really good reason why.  Yet have your techies been throwing around that new solution named "Kubernetes."

So as you and your organization tries to innovate into 2020, ask yourself.  Is our learning culture ready for the next generation of technology adoption?

22 June 2019

Cyber Risk: Human Factors vs. Automation...

Operational Risk Management (ORM) is a growing multi-faceted mosaic comprised of people, processes, systems and external events. The risks to the enterprise are increasing at a dynamic speed and trajectory that requires the use of automated tools.

This is where risk to the enterprise may actually expand as executives and operational management rely on software to provide information assurance. The design and architecture of software needs a human-based fail-safe. It requires a human interface that allows and simultaneously requires human intervention. Has too much automation contributed to our increased levels of vulnerability?

Fortunately, the software designs have allowed for these opportunities and for a human-factor to ask "What if" questions. Those questions that may arise after an automated alert from the system tells us that something is outside the baseline parameters set for the system, the sensor or the alarm.

Now we go back to Operational Risk and the nature of thinking from a security and safety perspective. What is the continued reliance on automated systems doing to the human capital who have been charged with the over all "Standard of Care" for the enterprise?

We believe that they may have lost the ability to ask the right questions, at the right moment and with the correct contextual understanding.

What is the truth? Is it true? What evidence do we have that this is true? How do you know that the evidence is not spoiled or compromised? If we know the truth, then what do we do next? Is the software really telling us the truth?

The security and the safety of the enterprise is counting on you. And more importantly, the enterprise is asking you to question the software. The "rule-sets" that you have chosen as a result of the programmers and architects decisions can no longer be trusted.

Is our system learning? In what capacity is the system learning in context with the human interaction for judgement, intuition and ethical emotions? Are you with us? The next generation of "Cyber Security" Innovators are now at the edge of significant new breakthroughs and solutions.

"Active Defense" has been and is a controversial topic du jour, yet the next few years will be a new age of understanding, cultural bifurcations and significant global collaboration.

Our entire platform of digital trust is at stake and the conversation has finally made its way to the nation state policy levels.

Operational Risk Management (ORM) will remain a key factor in decision points for the enterprise, the consumer and the operators of critical infrastructure across the globe.

Lets work on keeping the human factor in the loop as automation continues to give us a false sense of security and safety...

05 January 2019

Quantum Governance: The Rules of Trust...

People are learning to trust an AI, to make decisions on their behalf.  This will change our world exponentially in the next 10 years.

Now that we have reached connectivity to the Net with 50% of the human connected population, the AI of the IoT will be a growing trust factor in our daily lives.

We are accelerating beyond the simple tools of trusting that the answers to our questions are correct from "Siri" or "Alexa."  Accepting the trusted route from Google Maps on the most ideal navigation to our destination is already a given.

Beyond the consumer, the "Algo Bots" and Algorithmic Trading have already replaced the previous years of approximately 600 Goldman Sachs traders with 2 people, to oversee daily operations on the floor.  There are others who have already predicted the replacement of other human operators in various public and private decision-making bodies.

So what?

Trust Decisions in the next decade will be augmented by "Artificial Intelligence" on a more frequent basis.  That is already a given for many groups of decision makers across the globe.  The question is, how will governments begin to regulate AI?

Who will be in charge of making sure that the code and the algorithmic activity is correct?  That the rules behind the Trust Decisions are correct?

You see, as the software becomes more invasive in an individuals daily life and we rely on it for the truth, governments will be involved.  They already are.

The "rules for composing the rules, that lead to millions of peoples trusted decisions is at stake.  Maybe even more so, the evolution of "Quantum Law."  For those thought leaders such as Jeffrey Ritter who have for years been so keen to articulate the emergence of the thought of governance of unstructured data, there is this:
"We are moving from a time in which we presume that all electronic information is true to a time in which we can affirmatively calculate what it is and know the rules by which it is governed on the fly," Ritter said. "That's quantum governance."
You realize that the words will live on for eternity and for others to always contemplate.  That is a given, that all of us shall be considering for our future, sooner than later.

So how might decision making bodies such as the U.S. National Security Council (NSC) utilize AI?  Greg Lindsay and August Cole have already addressed this years ago with METIS:

"The result is a national security apparatus capable of operating at, as you like to say, “at the speed of thought”—which is still barely fast enough to keep up with today’s AI-enhanced threats. It required a wrenching shift from deliberative policymaking to massively predictive analysis by machines, with ultimate responsibility concentrated in your hands at the very top."

In 2019, begin thinking deeper and longer about your TrustDecisions...

18 November 2018

Risk Parity: Ideal Organizational Design...

Organizations across the globe are operating each day with Operational Risks. As a result, management is doing their best to implement a combination of Operational Risk Management (ORM) capabilities.

The strategy is to manage risk to the enterprise through a series of controls and modification of human behavior. Is it possible to create the most ideal organization from the start? Could you design it with the lowest possible Operational Risk exposure at every physical, process, virtual and human component?

What do we mean by this? Lets play a game. Or more importantly, lets imagine a workplace exercise to design the ideal professional services organization in one hour:

This organization will be in the private sector. The fictitious name for the organization is "Improvise, Inc." All of the legal entities have been created and it is registered as a U.S. Delaware company. It will have the following characteristics, capabilities, assets and purpose:

200 humans with advanced education between 25 and 65 years old. 50% Men & 50% Women
Global reach of professional services. (It sells intellectual capital and information)
Office hubs are physically located across four locations: Denver, Zurich, Abu Dhabi, and Singapore.
Language expertise includes English, German, French, Italian, Arabic and Mandarin.

Subject Matter Expertise of the Improvise associates is diversified. The core staff devoted to operational administrative processes is also diversified by physical location, 4 people each. Therefore, less than 10% core overhead.

Improvise, Inc. generates revenues by selling information, advisory services and subject matter expertise. The diversity of it's 200 humans and their Intellectual Capital provides professional services to Fortune Global 500 companies.

Now, to start the exercise you will have one hour to design the ideal mosaic of people, processes, systems and external factors to operate Improvise, Inc. on a daily basis. Begin.

How would you begin designing the ideal organization? Will you have a headquarters location? Will the offices have four leased corporate offices or utilize a virtual / shared space model? What will the facilities layout be with single offices, cubicles, conference rooms? Would you start with human resources and the hiring and selection process? What kind of systems and tools would you procure to issue to your new associates? How would you communicate and what vendor/providers will Improvise use outside its core? What organizational "Rule-sets" will be established?

Who will govern and what roles of power and influence will these employee-owners (Associates) have to make decisions for the good of Improvise? What countries across the globe will you dispatch your associates to do their work? How will you keep them safe and secure where and how they travel? What vendors and service providers will you contract with to provide digital communications and store your valuable intellectual property?

Will you locate your Associates across the four locations equally? Since you have 200 split into 100 men and 100 women, will you have 25 of each or 50 people in each office? Will they all be citizens of that native country only? Again, we are designing the ideal organization with Operational Risk Management (ORM), as our highest priority in the design. Is this even a valid consideration?

What about the use of digital assets? Will your associates at Improvise use PC or Mac, both? Microsoft or Linux-based? Android or iOS? Anti-virus scans daily or monthly. VPN, yes or no. Public or Private cloud? Encrypt data to remote sites? Retention and privacy policy? What happens when an associate goes home? When they leave the organization? Is there an "Acceptable Use" policy in place? And the list goes on.

Will Improvise standardize on a single travel agency, airline or hotel chain? What kind of training will occur with your associates on international customs, cultures, threats and vulnerabilities. Who will be accompanied by a buddy system or personal protection specialist when they travel? Will travelers receive intelligence briefings or reports in advance of their departure? Commercial or private carrier?

What processes are to be put in place for Improvise to follow, in the way it sells and delivers it's professional services? What autonomy does each associate have to make their own decisions on the price, scope and deliverable to a client? How do you interact, treat and question yourselves? Are your associates subject to any laws from the U.S. or the country they are operating in with regard to selling your professional services? Why are we doing all of this?

So when you are done with this first phase of the exercise after one hour, how could you improve Improvise, Inc. over your lifetime? Hopefully, this illustrates the breadth and depth of Operational Risk Management (ORM) and some of the key considerations. Your single points of potential failure. Your risk exposures and places to focus your design. Your decisions and how this shapes your culture and principles. Your trust and transparency.

One last thought. How would you currently judge your risk parity? In other words, how have you allocated risk effectively across the organization. Not in terms of assets, but in terms of volatility. Think about it. What kind of social contract do you have in place to operate together?

Is it true, that you are now on your way to achieving true "Business Resilience"...

13 October 2018

Cognitive Diversity: A Mile High...

On the eve of an early winter storm in Denver, CO USA, there is change in the air and the anticipation of a new blanket of fresh snow.  Hundreds of like-minded individuals with a common mission, steadfast purpose and glowing enthusiasm for innovation are gathered here.  This is the "Virtuous Insurgency."

The Defense Entrepreneurs Forum (DEF) is gaining momentum on so many fronts.  The crisp dialogue and the challenges for change are so distinct and even heart felt.  When you put this much "Cognitive Diversity" in one place over the course of 3 days, there is bound to be multiple examples of critical moments of brilliance and also social intelligence.

Maybe it's time you changed your "Chief Operations Officer" (COO) title to:  "Chief Outlaw Officer."

When was the last time you heard such intellect, witnessed such courage of ideas and even caught your eyes gathering a tear listening to people tell their vivid stories.  This is evidence of the organizational and cultural hurdles that we face each day to achieve our purpose, within a tremendous system designed for an era of arms races and so many decades past.

The United States Department of Defense (DoD) and the incorporated Intelligence Community (IC) are rapidly accelerating the pace of change and even celebrating their failures.  The question on many people's minds is this.  Are we too late?

When was the last time you as a CxO in your commercial enterprise, made the decision to assist our men and women serving our country, to better learn more about the daily business strategies of the private sector?  It's processes, the entrepreneurial factors and the continuous race for market share.

Have you created a strategic initiative within your commercial company, that invites outstanding fellows from our military and intelligence domains, for a Tour of Duty within your organization?

Why not?

You see, it is a 360 degree opportunity for the individuals in your firm to learn from these military and intelligence fellows, to gain new insights as they have become so skilled in their respective specialties and roles.

This learning works both ways and would provide those serving our country with vital experience and understanding of the idiosyncrasies of your industry sector and unique commercial enterprise.

There are current forms of this kind of work exchange fellowship going on across America now, yet it is now being optimized.  It is far from perfect for both stakeholders.

What is the right amount of time and at what level of seniority is the fellow brought in to the organization?  Six months, a year?  Who is the sponsoring department?  Engineering, Information Technology.  Business Development.  Accounting, Customer Service, Procurement, maybe it is even more than one.

You see, organizations today are asking for Veterans to consider their commercial company for employment and have specific recruiting events being marketed to those who have transitioned out of one of our military services.  Why are these companies waiting for someone with a DD Form 214?

Our organizations large and small should be creating the most ideal roles and experiences for these fellows now, so that they ultimately would like to return, once they have finalized their tour of duty with the military.

What is brought back to the inner core of the current state of our military industrial system are new ideas, new processes to be tested and the experiences of working in the private sector.

So how might we lead the commercial race to attract new found experts in asymmetric warfare to work along side those inside your Information Security department?  Who will lead the commercial race to attract new found experts in Geo-Spatial Intelligence to work with your Logistics, Disaster Recovery Planning (DRP) or even your Marketing department?  The possibilities are too numerous to imagine.
"Our U.S. nation state adversaries have optimized their defense and intelligence systems already.  The blur between commercial and military operations is hard to discern sometimes.  The speed to market and the "Cognitive Diversity" of those working on Quantum Computing and Artificial Intelligence is already well known."
One only has to peruse this recent report to ascertain why we are now behind the curve.  Yet our "Virtuous Insurgency" is on the correct trajectory.  Almost straight up...

01 July 2018

4th of July: Risk of Complacency...

This new nation state is turning 242 years old on July 4th, 2018. The United States of America will be celebrating another birthday and the Republic, will reflect on what we have learned, so far.

"Rule of Law" is an ever so powerful component of a democratic way of life and is the envy of so many nations who still seek its most true form. Operational Risk Management permeates the essence of the laws and rights of U.S. citizens in the work place, companies and organizations in global commerce and the government who provides oversight on all of it.

The balance of power between individual citizens and the government responsible for the protection of life, liberty and the pursuit of happiness is always in flux. Yet in the end, "The Union" has endured some of the most significant "Operational Risks" and disruptions one can imagine.

It is the analysis of "The Union" and the incredible resilience of all the moving parts that make the United States what it is today. Weathering the storms of mother nature by hurricanes, tornados, earthquakes and droughts to the economic threats of depression, mortgage or Wall Street implosion has not put a dent in "The Union's" ability to bounce back.

Withstanding the challenges to our Constitution and the rights proclaimed to each and every citizen, has only made us stronger. What cases to the Supreme Court have changed our future?

When you look at your own organization and examine the components of your people, processes, systems and potential external events, does it have what it takes to endure 242 years? Certainly there are risks that exist today that are prevalent in the eyes of shareholders, Board Members and even executive management.

The question really is "What are you doing about it?" This in itself, could be the biggest threat to the United States and your own organization. Complacency.

complacency

[kuh m-pley-suh n-see]
  1. a feeling of quiet pleasure or security, often while unaware of some potential danger, defect, or the like; self-satisfaction or smug satisfaction with an existing situation, condition.
It is the perception of the quiet pleasure or security of your organization or your own country, that may very well be the greatest threat to it's existence. Ignoring the cues and clues to the deterioration of the balance of power, the rule of law and the economic engine necessary to sustain the necessities of life, such as food, water and cash flow may be the reason for your demise.

Your own business resilience will continue to be a factor of the correct mixture of the ingredients that sustain and organically grow the enterprise. Those who try to grow to quickly without regard to quality will in many cases fail.

Those who let the power base become significantly imbalanced, so too will find the ability to endure a tremendous hardship. Those who ignore the constant requirement for monitoring and governance will suffer the realities of human factors. Motivations that are often defined as greed, jealousy and hate, soon will emerge.
"Relationships remain vital to our family unit, the neighborhood we live in and the cities, counties and states that oversee our way of life."
It is those same relationships within our business and government ecosystems, that will determine whether they perpetuate your healthy growth, or its inevitable deterioration.
 
Those same family units, neighborhoods, and government jurisdictions have the power and the ability to avoid complacency and mitigate the Operational Risks that will be present in each. Look around the country of the United States or the nations of the world and you will see who has been complacent, and who has been the most effective in OPS Risk Management.

"I pledge allegiance to the flag of the United States of America, and to the republic for which it stands, one nation under God, indivisible, with liberty and justice for all."

The flag consists of 13 alternating red and white stripes that represent the 13 original colonies, and 50 white stars on a blue field, with each star representing a state. The colors on the flag represent:
  • Red: valor and bravery
  • White: purity and innocence
  • Blue: vigilance, perseverance, and justice
Happy Birthday Uncle Sam!

06 May 2018

IO Convergence: Cyber Warfare Unified Taxonomy...

Information Operations (IO) is an Operational Risk Management priority in both the public and private sector these days. Is it lawful for a U.S. company and U.S. citizens to train and perform cyber warfare activities on behalf of a foreign country?

Flashback to 2012, The Washington Post reports:

By Ellen Nakashima, Published: November 22
"In the spring of 2010, a sheik in the government of Qatar began talks with the U.S. consulting company Booz Allen Hamilton about developing a plan to build a cyber-operations center. He feared Iran’s growing ability to attack its regional foes in cyberspace and wanted Qatar to have the means to respond.

Several months later, officials from Booz Allen and partner firms met at the company’s sprawling Tysons Corner campus to review the proposed plan. They were scheduled to take it to Doha, the capital of the wealthy Persian Gulf state.

That was when J. Michael McConnell, then a Senior Vice-President at Booz Allen and former Director of National Intelligence in the George W. Bush administration, learned that Qatar wanted U.S. personnel at the keyboards of its proposed cyber-center, potentially to carry out attacks on regional adversaries.

“Are we talking about actually conducting these operations?” McConnell asked, according to several people at the meeting. When someone said that was the idea, McConnell uttered two words: “Hold it.”
A common taxonomy was developed years ago for the cyber terms of the computer and network incident domain. Now we need to make sure we all understand what we mean when we say Information Operations policy as it pertains to the digital world.

As an example, in the context of the digital attacker we have Sandia Labs Taxonomy:
  • Hacker
  • Spies
  • Terrorists
  • Corporate Raiders
  • Professional Criminals
  • Vandals
  • Voyeurs
Each is unique and has its own domain or category. We are sure that the same could be used for the context of attackers in the non-digital world, possibly with the exception of Hacker. However, the definition of corporate raider in the off line domains may not be synonymous with the on line domain of cyber incidents.

If we look at the categories that make up the entire "Incident" that Sandia Labs has utilized, we see the following:
  • Attackers
  • Tool
  • Vulnerability
  • Action
  • Target
  • Unauthorized Results
  • Objectives
Without combining the context under each category, we lose the impact of what we are trying to make contextual with regard to an "Incident". We need to make sure that the anti-terrorism taxonomies of the off line and on line domains can be utilized together to describe the attributes of an "Incident". We need to break down the sub-categories as well. For instance, in the Sandia Labs Taxonomy for the Objectives category we have:
  • Challenge, Status, Thrill
  • Political Gain
  • Financial Gain
  • Damage
When we move to the off line domain and are doing risk mitigation and preparedness exercises for anti-terrorism we utilize another set of words to describe and evaluate infrastructure threats and hazards.  Here are Five factors:
  • Existence addresses the question of who is hostile to the assets of concern?
  • Capability addresses the question of what weapons have been used in carrying out past attacks?
  • History addresses the question of what has the potential threat element (aggressor) done in the past and how many times?
  • Intention addresses the question of what does the potential threat element hope to achieve?
  • Targeting addresses the question of do we know if an aggressor is performing surveillance on our assets?
Two years later, the Washington Post reports:

By Ellen Nakashima, Published: November 14
President Obama has signed a secret directive that effectively enables the military to act more aggressively to thwart cyber­attacks on the nation’s web of government and private computer networks.
Presidential Policy Directive 20 establishes a broad and strict set of standards to guide the operations of federal agencies in confronting threats in cyberspace, according to several U.S. officials who have seen the classified document and are not authorized to speak on the record. The president signed it in mid-October. The new directive is the most extensive White House effort to date to wrestle with what constitutes an “offensive” and a “defensive” action in the rapidly evolving world of cyberwar and cyberterrorism, where an attack can be launched in milliseconds by unknown assailants utilizing a circuitous route. For the first time, the directive explicitly makes a distinction between network defense and cyber-operations to guide officials charged with making often-rapid decisions when confronted with threats.
The policy also lays out a process to vet any operations outside government and defense networks and ensure that U.S. citizens’ and foreign allies’ data and privacy are protected and international laws of war are followed.

“What it does, really for the first time, is it explicitly talks about how we will use cyber-operations,” a senior administration official said. “Network defense is what you’re doing inside your own networks. . . . Cyber-operations is stuff outside that space, and recognizing that you could be doing that for what might be called defensive purposes.”
We believe that as our cultures, countries, agencies and professionals work together on Information Operations (IO) and online counter-terrorism initiatives, we are going to have to develop a solid taxonomy. It will provide the foundation for our clear and accurate risk management methodologies and incident management systems, being developed by relevant organizations in mutual collaboration.

Once we have accomplished this fundamental understanding, then true Critical Infrastructure Protection (CIP) cooperation and coordination will occur.

10 March 2018

Security Governance: Rededication...

Security Governance is a discipline that all of us need to revisit and rededicate ourselves to. The policies and codes we stand by to protect our critical assets should not be compromised for any reasons. More importantly, security governance frameworks, must make sure that the management of a business or government entity, be held accountable for their respective performance.

The stakeholders must be able to intervene in the operations of management, when these security ethics or policies are violated. Security Governance, is the way that corporations or governments are directed and controlled. A new element that has only recently been discovered, is the role of risk management in "Security Governance."

Security Governance, like Corporate Governance requires the oversight of key individuals on the board of directors. In the public sector, the board of directors may come from a coalition of people from the executive, judicial and legislative branches.

The basic responsibility of management, whether in government or the corporate enterprise is to protect the assets of the organization or entity. Risk and the enterprise are inseparable. Therefore, you need a robust management system approach to Security Governance.
If a corporation is to continue to survive and prosper, it must take security risks. A nation is no different. However, when the management systems do not have the correct controls in place to monitor and audit enterprise security risk management, then we are exposing precious assets to the threats that seek to undermine, damage or destroy our livelihood.
An organization’s top management must identify, assess, decide, implement, audit and supervise their strategic risks. There should be a strategic policy at the board level to focus on managing risk for security governance.

The security governance policy should mirror the deeply felt emotions of the organization or nation, to its shareholders and citizens. It should be a positive and trusting culture capable of making certain that strategic adverse risks are identified, removed, minimized, controlled or transferred.

An enterprise is subject to a category of risk that can’t be foreseen with any degree of certainty. These risks are based upon events that “Might Happen”, but haven’t been considered by the organization. Stakeholders can’t be expected to be told about these risks because there is not enough information to validate or invalidate them.

However, what the stakeholders can demand, is a management system for Security Governance that is comprehensive, proactive and relevant. The management system includes organizational structure, policies, planning activities, responsibilities, practices, procedures, processes, and resources.

It is this Security Governance management system that which we all should be concerned and which we seek from our executives, board members and oversight committees to provide. There should be a top management strategic policy to focus on managing risk for security governance.

This risk management system should establish the foundation for ensuring that all strategic risks are identified and effectively managed. The policy should reflect the characteristics of the organization, enterprise or entity; it’s location, assets and purpose. The policy should:

1. Include a framework for governance and objectives
2. Take into account the legal, regulatory and contractual obligations
3. Establish the context for maintenance of the management system
4. Establish the criteria against what risk will be evaluated and risk assessment will be defined

A process should be established for risk assessment that takes into consideration:
  • Impact, should the risk event be realized
  • Exposure to the risk on a spectrum from rare to continuous
  • Probability based upon the current state of management controls in place
The strategic security risks that the organization encounters will be dynamic. The management system is the mechanism by which the executives identify and assess these risks and the strategy for dealing with them.

It is this system which we are concerned about and which we seek to provide in order to achieve our Security Governance.

10 February 2018

Cluetrain: Manifesto Revisited...

When was the last time you revisited the 95 theses of the Cluetrain Manifesto? There are some nuggets here that remain timeless, even though they were written over 16 years ago. Here are some of the classics:
  • Markets are conversations.
  • Markets consist of human beings, not demographic sectors.
  • People in networked markets have figured out that they get far better information and support from one another than from vendors. So much for corporate rhetoric about adding value to commoditized products.
  • There are no secrets. The networked market knows more than companies do about their own products. And whether the news is good or bad, they tell everyone.
  • Networked markets can change suppliers overnight. Networked knowledge workers can change employers over lunch.
  • Your own "downsizing initiatives" taught us to ask the question: "Loyalty? What's that?" Smart markets will find suppliers who speak their own language.
  • Companies make a religion of security, but this is largely a red herring. Most are protecting less against competitors than against their own market and workforce.
  • To traditional corporations, networked conversations may appear confused, may sound confusing. But we are organizing faster than they are. We have better tools, more new ideas, no rules to slow us down.
  • We are waking up and linking to each other. We are watching. But we are not waiting.
In a hyperlinked, social networked, iPhone rich society the authors and founders of the Cluetrain Manifesto must have had a crystal ball. The "end of business as usual" has been accelerating and the exponential explosion of zero's and one's has produced a global economy.

Just look at the saturation of IP connections across the planet Earth and you will see where the capital is flowing and the societal impact is obvious.
"A powerful global conversation has begun. Through the Internet, people are discovering and inventing new ways to share relevant knowledge with blinding speed. As a direct result, markets are getting smarter—and getting smarter faster than most companies."
So what? So what does all of this have to do with Operational Risk Management?

It has to do with the pervasive vulnerability that an organization perpetuates, without the correct attitude and policies about managing risks. Theft of trade secrets, corporate espionage, competitive intelligence and loss of intellectual capital as the head hunters feast on your key employees to name a few.

Global enterprises with deep hierarchy in the organizational chart, continue to wonder how their best people have left and who leaked the information on the next big idea.

How would you ever put enough policies, tools, systems, training or behavior modification in place to stop the flow of new hyperlinks through your own corporate IntraNet or the public bulletin boards and social networking web sites? The fact is that you can't.

Here’s one example of how things work in a hyperlinked organization:

You’re a sales rep in the Southwest who has a customer with a product problem. You know that the Southwest tech-support person happens not to know anything about this problem. In fact, (s)he’s a flat-out bozo. So, to do what’s right for your customer you go outside the prescribed channels and pull together the support person from the Northeast, a product manager you respect, and a senior engineer who’s been responsive in the past (no good deed goes unpunished!). Via e-mail or by building a mini-Web site on an intranet, you initiate a discussion, research numbers, check out competitive solutions, and quickly solve the customer’s problem -- all without ever notifying the "appropriate authorities" of what you’re doing because all they’ll do is try to force you back into the official channels.

Game. Set. Match. Managing Operational Risks in the 21st century requires a whole new perspective. A brand new definition of the new "Normal."