22 June 2007

Private Equity: Nexus of Risk...

In recent comments in the main stream security media we have heard that convergence is over. It means that the arguments are over on whether convergence is a highly debated topic, not that it is still occuring. In fact, it is speeding up with M & A activity and the private equity surge to buy and sell large global enterprises.

Why would a company like Blackstone Group do an MBO with a company like Intelenet Global Services? Convergence in information technology is still happening under the umbrella of Business Process Outsourcing (BPO) at a rapid pace. More layoffs and elimination of redundant data centers, call centers and customer service centers is a tremendous business. Especially when you are trying to gain control, slice up and sell companies like Sungard, Nielson and other significant investments in critical infrastructure. It's going to be a deja vu moment anytime soon. When you are operating a private equity firm with so many facets you require special people with power and to give you advice. That is why Paul O'Neil is only a phone call away from the Senior Managing Directors at BX.

What kind of Operational Risks are happening within the portfolio of private equity firms like Blackstone as they try to achieve economies of scale and convergence? The same kind that exist within any organization that is focused on convergence and divergence of information simultaneously. Centralize telecom and decentralize risk management to the business units. Centralize information processing and decentralize access through mobile devices. The list goes on.

Execution, Delivery & Process Management

Losses from failed transaction processing or process management, from relations with trade suppliers and vendors. This includes Transaction Capture, Execution & Maintenance Miscommunication, Data entry, maintenance or loading error Missed deadline or responsibility, Model / system misoperation Accounting error, entity attribution error, Delivery failure, Collateral management failure Reference data maintenance, Monitoring & Reporting Failed mandatory reporting obligation, Inaccurate external report (loss incurred), Customer Intake & Documentation Client permissions / disclaimers missed Legal documents missing / incomplete, Customer / Client Account Management Unapproved access given to accounts, Incorrect client records (loss incurred), Negligent loss or damage of client assets, Trade partners, non-client vendor misperformance and vendor disputes.

Business Process Outsourcing (BPO) and Business Process Management (BPM) are being hailed as the answer to mitigating much of the operational risk exposures. It is also about creating new found synergies and elimination of redundant systems in order to drive greater return on investment. Yet all of the enterprise architecture, IT reengineering and Six Sigma / Lean will not change the current and impending threat to our interdependent Internet Protocol (IP) linked economy.

John Schwarz from the New York Times highlights the reality of the possibility of an Internet Armageddon. "ANYONE who follows technology or military affairs has heard the predictions for more than a decade. Cyberwar is coming. Although the long-announced, long-awaited computer-based conflict has yet to occur, the forecast grows more ominous with every telling: an onslaught is brought by a warring nation, backed by its brains and computing resources; banks and other businesses in the enemy states are destroyed; governments grind to a halt; telephones disconnect; the microchip-controlled Tickle Me Elmos will be transformed into unstoppable killing machines."

Private sector companies that are owned or controlled by large private equity and alternative investment hedge funds may be even more at risk and the target of both nation state (China) and non-state actors (Al-Qaeda in Europe). Getting access to the information on the future plans, strategy and architecture of protecting critical infrastructure companies is a priority by those who wish to wage a simultaneous salvo of both digital and physical attacks.

A major hurdle that nations face in defending their critical infrastructures is working with the entities that actually own their countries' telecommunications networks, electrical grids, and transportation systems. This is a major issue in the United States, given that the private sector owns more than 85% of the critical infrastructure and doesn't take kindly to government demands that shareholder money be invested in protection rather than expansion.

Cooperation between government and private-sector critical infrastructure owners is essential. "When it comes to information warfare, corporations in general are no match for a trained [enemy] intelligence officer," David Drab, a 27-year veteran of the FBI who retired in 2002 and is now principal for information content security with Xerox Global Services, said in an interview. These officers have an objective, they have resources, and often they have the element of surprise on their side, he added.

Acceleration of private equity investments puts control of managing the vital lifeblood of information into the hands of Senior Managing Directors, CIO's and Project Managers at the BPO third parties. The nexus of thinking from these participants is to do what ever it takes to converge operations and eliminate redundancy. One can only hope that they are becoming together to discuss the same topics as other large financial institutions. The East Coast Buildings Plot is just one example of why this is imperative.

In publicly released statements, bin Laden has also stressed his “policy” of “bleeding America to the point of bankruptcy.” And an excerpt from the Al Qaeda publication Sawt al-Jihad states:

“If the enemy has used his economy to rule the world and hire collaborators, then we need to strike this economy with harsh attacks to bring it down on the heads of its owners. If the enemy has built his economy on the basis of open markets and free trade by getting the monies of investors, then we have to prove to these investors that the enemy's land is not safe for them, that his economy is not capable of guarding their monies, so they would abandon him to suffer alone the fall of his economy.”


19 June 2007

FACTA: The Writing is on the Wall...

Now that the financial community is wiping their brow with a sigh of relief on this latest Supreme Court ruling, what can a General Counsel or Chief Risk Officer expect? Will the adversarial train of plaintiff suits slow down and come to a halt. Not likely.

The U.S. Supreme Court's ruling that blocks investors from suing Wall Street investment banks under antitrust laws could save Wall Street firms a bundle by limiting investors to smaller recoveries.

In a case dating back to the dot-com bubble, the high court ruled Monday that antitrust suits would pose a "substantial risk" to the securities market. Damages in antitrust cases are tripled, in contrast to penalties under the securities laws.

The ruling struck down a lower court decision that would have allowed investors to go after Wall Street firms that they say engaged in anticompetitive practices by conspiring to drive up prices on about 900 newly issued stocks in the late 1990s.

Because the well-documented implosion of names like Enron Corp. swallowed any serious money that investors might hope to recover from that and other flame-outs, some investors have turned to the banks and other Wall Street regulars such as accounting firms that did work for such companies.

Wall Street institutions in the case before the Supreme Court were Credit Suisse Securities (USA) LLC, formerly Credit Suisse First Boston LLC; Bear, Stearns & Co. Inc.; Citigroup Global Markets Inc.; Comerica Inc.; Deutsche Bank Securities Inc.; Fidelity Distributors Corp.; Fidelity Brokerage Services LLC; Fidelity Investments Institutional Services Co. Inc.; Goldman, Sachs & Co.; The Goldman Sachs Group Inc.; Janus Capital Management LLC; Lehman Brothers Inc.; Merrill Lynch, Pierce, Fenner & Smith Inc.; Morgan Stanley & Co. Inc.; Robertson Stephens Inc.; Van Wagoner Capital Management Inc.; and Van Wagoner Funds, Inc.

These institutions may not have "Anti-Trust" anxiety from the Supreme Court any longer yet there are plenty of other Operational Risks on their minds. Namely International Fraud.

In an era of data warehousing, metadata management, business process management and the looming BASEL II Accord there are plenty of conversations about what to do about fraud and other regulatory compliance. Multi-factor authentication for online banking systems is not a trivial matter when it comes to Enterprise Risk Management. Is the customer service organization ready for the upgrade? Is the consumer going to be confused on what questions they are being asked to get access to their latest online credit card statement? What is my customer "churn" factor? In other words, how many of my customers are jumping ship as a result of the operational risks that have turned their loyalty into consumer driven class action fraud litigation?

An International Banking Fusion Center is on the horizon and it's not too far from the same justification that addresses Know Your Customer (KYC) and the financing of terrorism.

According to one study respondent, "Organizations are secretive of fraud losses and that inhibits our ability to work together."

"The sharing of intelligence is key to being able to take advantage of the predictability of fraud," First Data's Barwell continues. "Banks are sitting on valuable data that, if analyzed innovatively, could provide fraud intelligence worth sharing. One major bank has shown that if their internal client databases across business lines and geographies are analyzed using sophisticated link analysis tools, spurious networks of accounts can be uncovered and, when fully investigated, could uncover organized networks of first-party fraud accounts."

Barwell adds that several U.S. banks have expressed interest in taking the "quantum leap" to true data sharing.

The International Language of Fraud

"In the last eight to 10 years, fraud has really gone international," says Steve Baker, director of the Midwest region of the Federal Trade Commission (FTC). The FTC maintains a Consumer Sentinel database that includes more than 3.5 million consumer fraud complaints and is accessible to more than 3,000 law enforcement agencies internationally. In 2006, 22 percent of the reported fraud was cross border.

So What? What does information sharing have in common with:

International fraud, Identity Theft and the risk of litigation within the banking or credit card industry. Now the bankers want to sue the retailers and recover losses for the lack of privacy and security controls at the retailers. Since December 2006, plaintiffs’ class action firms in California and elsewhere have filed over 200 nationwide class actions in federal court against a broad spectrum of retailers and restaurants alleging violations of the Fair and Accurate Credit Transactions Act ("FACTA"). In addition to California federal courts, FACTA cases have been filed recently in federal courts in Pennsylvania, Illinois, New Jersey, Nevada, Maryland and Kansas.

13 June 2007

ID Theft: The Innocent Insider...

If you were a betting person you might think that the threat of 1 Million Botnets is a greater Operational Risk than a "lone wolf insider". What is the likelihood that one person will impact your business and disrupt your operations vs. the power of thousands of rogue computers unleashing a salvo of malicious code or denial of service attacks on your institution?

A botnet is a collection of compromised computers under the remote command and control of a criminal “botherder.” Most owners of the compromised computers are unknowing and unwitting victims. They have unintentionally allowed unauthorized access and use of their computers as a vehicle to facilitate other crimes, such as identity theft, denial of service attacks, phishing, click fraud, and the mass distribution of spam and spyware. Because of their widely distributed capabilities, botnets are a growing threat to national security, the national information infrastructure, and the economy.

“The majority of victims are not even aware that their computer has been compromised or their personal information exploited,” said FBI Assistant Director for the Cyber Division James Finch. “An attacker gains control by infecting the computer with a virus or other malicious code and the computer continues to operate normally. Citizens can protect themselves from botnets and the associated schemes by practicing strong computer security habits to reduce the risk that your computer will be compromised.”

Yet there are individuals within your own organization who lie in wait, innocently. For the right timing and the right vulnerability to be exploited. They have been unknowingly planning and operating under cover for years and are masters at evading detection. In the Executive Suite, the "Bot" may operate in the background or under the radar of management audits and risk management control mechanisms. So how do you catch them or at least detect their presence? Send everyone on vacation.

When was the last time you had the fraud investigators training the internal auditors? When did you last utilize a "True" Independent outside advisor, investigator or consultant to assist your CISO in early detection. If you have 10,000 employees, 99.x% of these employees are hard working and honest people without any hidden agenda to bring harm to the organization or individuals inside the company. However, not all who would bring harm to you are stealing money or other physical assets from the warehouse. We aren't talking about a few items from the office supplies closet or a case of beer from the 7-11.

We are talking about the one employee who is operating a "Botnet" from behind the walls of your Fortune 50 company. Do you have anyone sharing pictures or music in the executive suite? Without you detecting it.

We define peer-to-peer, bot, and botnet below.

  • peer-to-peer - A peer-to-peer network is a network in which any node in the network can act as both a client and a server.
  • bot - A bot is a program that performs user centric tasks automatically without any interaction from a user.
  • botnet - A botnet is a network of malicious bots that illegally control computing resources.

Some definitions of peer-to-peer networks require no form of centralized coordination. Our definition is more relaxed because the attacker may be interested in hybrid architectures. Our definition of a bot is not inherently malicious. However, the malicious nature of a bot is implicit under some contexts. Finally, we do define a botnet to be malicious in nature.

The case study of the Trojan.Peacomm bot demonstrates one implementation of peer-to-peer functionality used by a botnet. That "Lone Wolf" in your organization could be your innocent administrative secretary and they don't even know it.

10 June 2007

The New New Math: Corporate Responsibility...

The "New New Math" (N2M) is the evolution of economics and return on investment in the modern day organization. Is it a hybrid equation of a previously published and patented algorithm? An upside down or inside out way of justification for new resources or or just new emphasis on the latest shareholder suit. The N2M is something all too often found in the most successful corporations across the globe and it's starting to see the light of day as a result of increasing Operational Risks.

Another way of looking at and understanding the "New New Math" for investment can be found in the roots of what some would say is just good old fashioned Corporate Social Responsibility (CSR):

Corporate Social Responsibility (CSR) is a concept that organizations, especially (but not only) corporations, have an obligation to consider the interests of customers, employees, shareholders, communities, and ecological considerations in all aspects of their operations. This obligation is seen to extend beyond their statutory obligation to comply with legislation.

CSR is closely linked with the principles of Sustainable Development, which argues that enterprises should make decisions based not only on financial factors such as profits or dividends, but also based on the immediate and long-term social and environmental consequences of their activities.


So the N2M on Return on Investment is now being considered across the enterprise and the Board of Directors meetings. ROI discussions are shifting away from the typical GAAP dialogue and more directed at whether new strategic initiatives are "The Right Thing To Do." When you have executives nodding their heads in the meeting about making positive decisions to invest millions of dollars in corporate initiatives based upon it's "The Right Thing To Do" justification, you are experiencing the "New New Math" (N2M)

Making strategic decisions on CSR and N2M is quickly becoming the emotional reasoning and rationale for many corporate enterprise investments. Measuring the ROI doesn't always come in a percentage of dollars invested or a normal way of thinking about getting a return. Many times the executives who champion these initiatives have an underlying reason for doing so that reaches into their personal lives. So when you invest in more robust security for the company or significant programs to increase the protection for key employees, that ultimate driver could be as simple as losing a fellow colleague to kidnapping or the latest law suit.

How your organization is perceived internationally may dictate the degree of risk for your traveling executives. The attack on an employee may be an attack on your "Brand" and what the general public believes that you stand for, in the "minds eye" of the media blur.

Why us?
Where businesses are the target of terrorism, it is usually because of what they represent, rather than anything they do or don’t do themselves. Global brands can assume symbolic significance for terrorists. The US National Counterterrorism Center’s list of significant terrorist events describes 24 attacks on McDonald’s restaurants between 1993 and 2005 worldwide.

Of the minority where responsibility was claimed, motivation for the attacks included nationalism, anti-globalisation, religion and Marxism – but in each case the perpetrators objected to the restaurant as a symbol of America, not a purveyor of products. Mr Jenkins notes that, before 9/11, the two best correlated predictors of whether a US firm would suffer an attack were size and familiarity to the public – corporate behaviour, even philanthropy, was inconsequential. Added to this is the very real possibility of risk displacement: business targets are often easier to hit than government facilities or sites.

Attacks on your organziation or employees don't always have to take a violent twist. Many times these are orchestrated under the cloak of a "personal scandal" or even the filing of a civil Intellectual Property litigation. Legal Risk is a consistent threat to the enterprise and is far often the most effective way of bringing down the house in terms of putting a cloud of uncertainty and speculation about a company that may be in, a competitors "cross hairs."

A week after the public learned of Qualcomm Inc.'s bombshell admission that it withheld potentially thousands of important documents in a high-stakes patent trial against Broadcom Corp., many in the intellectual property community are still buzzing about the gaffe.

The case is even more striking because the attorney who has publicly apologized for Qualcomm's error has a strong reputation in his field, as does his firm. Yet several attorneys say it's still too early to assign blame for the error.

"Whenever there are accusations of concealment of evidence and they prove to be true, there definitely is going to be harm to the lawyers and the parties," said Anup Tikku, an IP associate with Kirkpatrick & Lockhart Preston Gates Ellis, who has followed the case closely. "What I find difficult to understand is how Qualcomm interviewed witnesses, put them on the stand and did not realize these documents existed."

Corporate Social Responsibility extends to Enterprise Litigation Governance and goes well beyond just understanding electronically stored information (ESI). The "New New Math" on doing the right thing in preparation for legal risk are taking on new dimensions as the implications of judgements in favor of the plaintiff set new legal precedence and case law. The Board of Directors and executive management are getting the message that protecting their employees from violence and politically motivated terrorism is just as imperative as preparation for adversarial law suits.

When you hire a defense firm and they get blindsided about eDiscovery or Enterprise Content Management (ECM) and your own Records Management and IT personnel are scratching their heads, your "Brand" is going to take hit. The operational risks associated with a lack of preparedness and a limited strategy for preemptive action calls for the "New New Math." It's coming to a board room near you and when it does, don't be surprised that the investment decisions are based more on emotion than on your controllers 27 pages of hard numbers.

28 May 2007

Memorial Day: The Courage to Serve...

Today is Memorial Day in the United States and Spencer is on his way to Airborne "Jump School" in Ft. Benning, GA as a proud member of the US Army. He gave up going to a nice University of California campus and a few years of fraternity fun to serve his country and took a risk by joining a life long fraternity of men and women who have defended our country. Simultaneously Keith is risking his life serving the US again for the "nth" time in Afghanistan as US Army Lt. Col. (Ret) on another important and vital mission. He gave up a hunting, fishing and teaching lifestyle to help secure certain important real estate utilizing his diplomatic and training skills learned from decades of real-time experience in South East Asia with the Central Intelligence Agency.

Having spent some time with both of these brave and courageous men makes you wonder what they both have in common. What are the attributes of a person who makes a selfless sacrifice to protect and to serve? Whether it's in the military or in public safety, there is something that is in their DNA and not yours. It's something that many of us think about and end up not doing anything about it. When you fill up your gas tank this week or stroll down the outdoor mall you might ask yourself who made all of this possible? The answer is those who have served and those who are serving right now.

Millions across the country will pause Monday afternoon to honor the sacrifices of the American military in observance of the National Moment of Remembrance.

Crowds at Major League baseball stadiums, NASCAR tracks, train stations, malls, stores and even the astronauts aboard the International Space Station will participate in the “National Moment of Remembrance,” which is observed at 3 p.m. every Memorial Day.

"The national Moment of Remembrance is a time for Americans to contemplate those things that bind us together by remembering the legacy of those who died to better our country," Carmella LaSpada, executive director of the White House Commission on Remembrance, said.

"We encourage all Americans, no matter where they are and what they are doing, at 3 p.m. local time on Memorial Day, to stop and give thanks."

The observance is an initiative of the White House Commission on Remembrance, which Congress established in 2000.

The commission encourages Americans to remember the sacrifices of fallen troops and the families they left behind.

So when you return to work tomorrow after your Memorial Day holiday, hopefully you will have had a chance to say a prayer or to at least acknowledge those brave individuals. And it's also a time to evaluate your own work ethic or duty serving as leader of your organization. Are you putting your employees in harms way? What steps or measures are you taking to make sure that they are training and preparing to mitigate operational risks on a daily basis. To have the courage to do the right thing and to keep the organization out of jeopardy. Beware of the cowboy.

From Leadership Lessons of the Navy SEALS


The Cowboy

Neither of us knows if such a thing has ever been tolerated in modern commando teams. Yes, sometimes you need to charge forward. But, there are simply too many potential casualties and too much political currency resting on commando missions to entrust one to a cowboy. Authorization for an operation depends on the accurate calculation of operational risk. This requires an assessment of proven forces ability to perform a task. All this is contrary to the cowboy philosophy of depending on experimentation, pluck, and luck in order to succeed.

"The problem with being a cowboy is that your bosses won't employ you if they can't trust you, and they can't trust you if they don't know what you'll do. And then you're stuck with the reputation." --LT. CMDR. Jon Cannon


Believe it when he says that people who try to be cowboys in your organization are operating without regard to risk. Now multiply the number of cowboys by the number of people that they surround on their team who think that this is the way to operate. It doesn't take long to find out that these are the root causes of many of the operational risks in your organization. And it starts out with the basics:

> Revenue is not booked according to the rules. Products sit in the warehouse yet revenue ends up on the sales reps commission report because (s)he had a signed order.

> Assets are not valued correctly. Bank accounts are not validated to make sure they actually exist and accounts receivables are inflated.
These are just two of the many facets of fraud that starts with a few cowboys who have little regard for managing risk and all the incentives to line their pockets with new found cash or bonuses.

You might think that the reason is greed. However, the real motive may not be so clear. More than likely, the motive is fear. And that fear is something that grows until it gets to the point of creating harm, loss and destruction. You have to find the cowboys in your organization and you have to follow the mantra of quality gurus from years past, "Drive out Fear".

24 May 2007

Hedge Funds: Crystal Ball on Regulation...

Looking into the crystal ball for the future regulation of hedge funds is a cloudy subject and the feds are making statements that would alarm any high net worth investor. So what are the issues with asking for some additional transparency and reporting mechanisms for the 1% who choose to diversify their portfolios?

Why is regulation inevitable? There are a number of factors, including:

  • Industry growth and the increasing influence of hedge funds in the capital markets.
  • The absence of genuine regulatory oversight.
  • The changed political landscape.
  • Increased participation by public pension funds and corporate pension plans.
  • Continuing instances of fraud and blow-ups.
  • The lack of transparency.
  • Increasing complexity and concerns of systemic risk.

All of these factors, taken together, have created an environment that is ripe for regulatory oversight. Of course, this does not mean that hedge funds should be regulated. Indeed, there are good arguments that hedge fund regulation is not necessary, and may even be imprudent. Opponents of regulation have argued persuasively that, among other things, hedge funds provide benefits, such as market liquidity, and that regulation will simply drive hedge funds offshore.

As the financial wizards of the global markets figure out ways to keep regulators from asking too many questions the leadership of the companies operating in the hedge fund environment are getting prepared. They are strategically implementing the mechanisms and the controls that any prudent investment management company have in place to deal with the operational risks associated with other main stream institutions in the sector.

So what is on the mind of the SEC and others who oversee the implications of hedge funds that are not being so proactive:

The hedge fund industry, long a Wall Street innovator, has frequently created exotic money-making strategies that have then ballooned in popularity.

But as Neil Brown, director of AIMA and managing director of New York-based Citigroup Alternative Investments, noted, when a profitable arbitrage trade is uncovered, managers then pile onto the trade, and the opportunity to make money gets "arbed away."

This summer's meltdown in convertible bond hedge funds proved a wrenching case in point. Convertible arbitrage managers buy convertible bonds, which are bonds that can be exchanged for a certain amount of a company's common stock, and short the underlying stock of the issuing company to profit from the difference in price between the two securities.

Long considered a safe haven, the strategy posted big losses this year, which forced three big convertible bond hedge funds to close: San Francisco-based Marin Capital Partners, which had $2.2 billion in assets at its peak; Alta Partners, run by San Francisco-based Creedon Keller & Partners, which had about $1.2 billion at its peak; and Minnesota-based EBF & Associates' $669 million Lakeshore International Fund.

Now, hedge funds are coming up with new, more exotic strategies as traditional strategies, such as certain kinds of arbitrage, get overcrowded.

So what? The fact that the markets will regulate itself is a valid point being made around many dinner tables in London, New York City and Shanghai as hedge funds managers can feel the trend of fraud driven regulators breathing down their necks:

Shanghai is setting up a financial task force to counter a rise in cases of fraud and other abuses linked to soaring stock prices, state media reported Tuesday.

The task force, including staff from the securities and banking watchdogs, police and other government agencies, will focus both on combatting illegal share dealings in companies not listed on the bourse and also on the practice of diverting public funds into high-risk investments, the state-run newspaper Shanghai Daily reported.

"Risks are accumulating and we should be well aware of illegal financial activities and make it a priority of our work to clamp down on them," it quoted Feng Guoqin, a Shanghai vice mayor in charge of the task force, as saying.

So why are hedge funds any different than any other alternative investment? The myths are there and they need to be addressed:

MYTH #14: HEDGE FUNDS ARE NOT REGULATED
Hedge funds often are said to be unregulated or lightly regulated. The perception is that hedge funds are cowboys taking advantage of the wild-west financial markets without a sheriff in town.

EVIDENCE:
Hedge funds are required to comply with every rule, regulation, and law that affects virtually all investors in the public and private financial markets. Further, hedge funds are subjected to a variety of investor-related laws and regulations that impact who can qualify to invest with hedge funds. Additionally, there are a variety of state and federal laws that can require some managers to register as investment advisors—thereby invoking a series of additional regulations and requirements, including periodic regulatory examinations and filings. When the topic of regulation arises in the hedge fund industry, managers are far from being cavalier about the existing and continually proposed regulatory requirements.

19 May 2007

Cyber Terrorism: Attack on a Nations State...

The attack on the Critical Infrastructure of the nation state of Estonia over the past few weeks should be a wake-up call to governments across the globe. The facts are coming out in the mainstream media this week about the origins of the attack and the magnitude of the event. Yet the real lesson to be learned here goes deep into the chasm of having "Cried Wolf" too many times and the resulting ignorance of a major threat in the making.

Young men paying cash to learn how to fly large Boeing airliners and not worried about landings. Does this ring a bell?

Peter Finn of the Washington Post Foreign News Service has identified much of the real issue at stake here:

This small Baltic country, one of the most wired societies in Europe, has been subject in recent weeks to massive and coordinated cyber attacks on Web sites of the government, banks, telecommunications companies, Internet service providers and news organizations, according to Estonian and foreign officials here.

Computer security specialists here call it an unprecedented assault on the public and private electronic infrastructure of a state. They say it is originating in Russia, which is angry over Estonia's recent relocation of a Soviet war memorial. Russian officials deny any government involvement.


How many more of these "Botnet" attacks will be necessary for the public, the media and the government to realize that this is the beginning of a new generation of warfare that will be fought using "Zeros and Ones" as increasing effective ammunition against your enemy. Whether it be a nation state or your business competitor, large Distributed Denial of Service (DDOS) attacks can be rented on the Internet by the hour. So how big a network of "Bots" is necessary to disrupt a nation state like Estonia?

Roughly 1 million unwitting computers worldwide were employed, said Jaak Aaviksoo, Estonia's minister of defense. Officials said they traced bots to the United States, China, Vietnam, Egypt and Peru. By May 1, Estonian Internet service providers were forced to disconnect all customers for 20 seconds to reboot their networks.

Disruptions of all kinds are giving Chief Security Officers (CSO) head aches and heart attacks as the economic impact of spoof e-mail and DDOS attacks wreak havoc beyond the network to the financial markets. The attacks could be the work of competitors or more likely the coordinated, well planned and funded mission of a worthy criminal or terrorist adversary:

Apple (Quote) shares dropped 3 percent to $104.63 in afternoon trading as ultimately false rumors of iPhone and Mac OS X Leopard delays spread across the Internet.

The plummet started when technology news blog Engadget.com reported Apple pushed iPhone's launch from June to October and Mac OS X Leopard from October to January. Ryan Block, the post's author, cited an "authority" for a source.

It turns out that "authority" was a forged e-mail sent to thousands of Apple employees at 9:09 a.m. this morning. It was eventually leaked to Block who posted at 11:49.


What impact does the media and information leaks have on the market value of your company? How do you as a CSO, CEO or Chief Risk Officer mitigate the risk of this kind of "Social Engineering" ploy to manipulate your stock price? The answer is not more software or some kind of fancy new device for analyzing network traffic.

The answer is education and enhanced monitoring of information. It's also making sure that your institution has prepared for and tested the resiliency of the organization for such a scenario. The Department of Homeland Security has been exercising for major incidents of the magnitude described against Estonia for years. The next event is scheduled for the spring of 2008 and is know as CyberStorm II. In this exercise the scenario will involve both physical disruption and the digital origin of vulnerability exploits. The lessons learned will be a public and private partnership discussion for years to come.

The Case Studies of the Estonia attack and the Apple spoof are being written as we speak and the output is what any CSO should be seeking. Increased awareness and education of it's employees, customers and suppliers. Without effective learning, the resiliency of the enterprise is in jeopardy.


16 May 2007

Defensible Standard of Care: Legal Risk...

A "Defensible Standard of Care" is a hot topic these days around the Board of Directors Audit Committee conference table. Information Security standards are consistently being discussed by the CIO and CSO in the context of compliance. So where is the nexus? Why is it so critical to enabling the enterprise business resilience of a global institution?

The answers lie in the fundamental understanding that the Board of Directors and the "C" Suite are both working towards the same focal point. Their motive is almost identical. To be able to provide the evidence and the testimony that keeps their integrity and reputation intact. To understand this nexus, first we must provide the definitions:


What is ISO/IEC 27001:2005?

ISO/IEC 27001:2005 is a standard setting out the requirements for an Information Security Management System. It helps identify, manage and minimize the range of threats to which information is regularly subjected.

ISO/IEC 27001:2005 covers the following topics:

  • Security policy - This provides management direction and support for information security
  • Organization of assets and resources - To help you manage information security within the organization
  • Asset classification and control - To help you identify your assets and appropriately protect them
  • Personnel security - To reduce the risks of human error, theft, fraud or misuse of facilities
  • Physical and environmental security - To prevent unauthorized access, damage and interference to business premises and information
  • Communications and operations management - To ensure the correct and secure operation of information processing facilities
  • Access control - To control access to information
  • Systems development and maintenance - To ensure that security is built into information systems
  • Business continuity management - To counteract interruptions to business activities and to protect critical business processes from the effects of major failures or disasters
  • Compliance - To avoid breaches of any criminal and civil law, statutory, regulatory or contractual obligations, and any security requirement

ISO/IEC 27001:2005 is the updated version of the world renowned British Standard for Information Security Management Systems, BS 7799-2:2002.

This Information Security Management System (ISMS) is simply that, a published set of guidelines and controls. Useless without the support of the correct tools, methodologies and people to make it come alive and incorporated into the culture of the organization. This requires an adaptive and resilient framework for managing change.

A "Defensible Standard of Care" comes alive within this ISO 27001 standard:

Clause A.15.1 Compliance with legal requirements

Objective: To avoid breaches of any law, statutory, regulatory or contractual obligations, and of any security requirements.

Clause A.15.1.3 Protection of organizational records

Control
Important records shall be protected from loss, destruction and falsification, in accordance with statutory, regulatory, contractual, and business requirements.

In the United States, as well as many other countries, a party involved in civil litigation is responsible for preserving any potentially relevant evidence, including materials that may lead to the discovery and production of other relevant evidence, beginning when the party knew a lawsuit had been filed, or had a reasonable basis to believe that litigation would occur.

Effective December 1, 2006, the United States Federal courts adopted revised Rules of Civil Procedure that confirm the importance and admissibility of Electronically Stored Information (ESI) as evidence in civil litigation. As lawyers and the courts begin to operate under the new Rules, company officers responsible for demonstrating the reliability of their corporate electronic records are rapidly moving into the “firing zone”.

The reason is entirely adversarial: if a hostile lawyer can discover uncontrolled risks that compromise the reliability or integrity of a company’s electronic records, then the value of those records as evidence declines and the potential for how the case will be resolved, whether in the courtroom or through settlement, is altered. In response, a company must be prepared to demonstrate their ESI has been managed pursuant to a defensible standard of care.

As a result, adherence to Clause A.15.1.3 includes protecting records that become important to litigation and assuring their continued integrity and availability. For these purposes, information security practices are indispensable, and the failure to apply and extend those practices to relevant evidential materials can create a material risk for many companies.

And this risk extends well beyond the inner sanctum of the legal department, internal audit and information technology. This risk reaches into the outside counsel the company has retained for defense litigation. How many law firms are under retainer at your institution? Do they have an effective set of standards, methodologies and programs to handle your next ESI request? In the game of litigation only the most agile and preemptive strategies will prevail.

So how do you understand and determine how adept your outside counsel is when it comes to ESI and eDiscovery? Now it's time for your own investigation, audit and request for information. You have to develop the same kind of process for evaluation of outside legal counsel as you do for the next set of financial auditors or outsourced disaster recovery vendor. It's imperative that you look at enterprise content management and the records administration controls within your Information Security and Operational Risk Management framework to see how it supports a Defensible Standard of Care. The Nexus of Information Security and The Law. Here are 8 Survival Strategies courtesy of Jeffrey Ritter at Waters Edge Consulting:

  • Start a Dialogue.
  • Be Prepared to Bear Witness.
  • Be Prepared to Preserve.
  • Define "Not Reasonably Accessible".
  • Demonstrate "Routine Good Faith Operation".
  • Prepare to Deal with eDiscovery vendors.
  • Prepare your lawyers "In and Out".
  • Protect your records at the Law Firms.
Institutions wishing to achieve a defensible standard of care for protecting business sensitive data such as intellectual property, financial records, customer data and business records will find the Waters Edge Protocol a welcome advantage in streamlining the effort required to tailor requirements, policy, processes, and implementation plans to meet their business needs.

10 May 2007

IT Audit: Communicating with the CEO...

In the latest issue of ITAudit, Jackie Bassett is right on target. She has clearly identified the items necessary to close the gap of communicating to top management before, during and after an Information Technology Audit. A key component of any prudent Operational Risk Management Program:

At its most basic level, an IT security audit is a systematic evaluation of a company's IT security infrastructure that measures how well security policies, procedures, and controls conform to a set of established criteria. Today's internal auditors know that the true value of an IT security audit to an organization goes beyond compliance. By successfully communicating their IT security audit recommendations, auditors can have a major influence on corporate strategy. Unfortunately, many auditors find there is little guidance to help them communicate audit results and recommendations to senior-level managers when preparing for the IT security audit. Consequently, conveying IT security recommendations can be one of the most challenging parts of an internal auditor's job. However, with a little preparation and knowledge, auditors can enhance the way they communicate IT security audit results as well as provide recommendations senior managers can relate to, understand, and implement.

What can the board of directors do to make sure that their CEO has moved to a place focused on mitigating operational risks to enhance opportunities and long term strategy?

Fundamentally, the first task is to make sure that the CEO has a management system in place for operational risk. What is needed is a process approach for establishing, implementing, operating, monitoring, maintaining and improving the effectiveness of an organisation’s operational risk enterprise architecture (OREA).

Let’s break OREA down this a little further to get a better view of some of the specific operational attributes:

People
Employee fraud, misdeed, unauthorised activity, loss/lack of personnel and employment law.

Process
Payment/settlement, delivery/selling, documentation/contract, valuation/pricing, internal/external reporting and compliance.

Systems
Technology investment, development, access, capacity, failures and security breach.

External
Legal liability, criminal activities, outsourcing, suppliers / insourcing, disasters / infrastructure, regulatory/political.

The attributes of operational risk are the same key areas that need to have metrics created for measurement and auditing. Performance management, Balanced Scorecard and other methodologies for managing, monitoring and continuous improvement need to be implemented so the boards of directors have a way to get timely alerts, updates and reporting.

The operational risk enterprise architecture (OREA) is a management framework that requires a process approach embedded with the legacy of our quality initiatives of the past several decades. The reason is because of the threat of change itself. The P-D-C-A model (plan – do – check – act) is appropriate for application to this process approach and threat of a constantly changing corporate environment:

Plan
Establish policy, objectives, targets, processes and procedures for managing operational risks to deliver results in accordance with the organisations business objectives.

Do
Implement and operate the policy, controls, processes and procedures.

Check
Assess and measure in applicable areas while reporting results to management for review.

Act
Take corrective and preventive actions based on results to continually improve the OREA framework.

Operational risk management is getting the attention of organizations outside of the major banks at a rapid pace. Board of directors in any industry will soon realize that the successful CEO of the future will be a master of building a culture with effective operational risk management systems at its core.

Furthermore, interpreting how enforcement of IT security controls and policies can strengthen connections with customers and suppliers, how authorization processes can preserve intellectual property, or how separation of duties can drive innovative new business processes demonstrates to senior managers that internal auditors are an invaluable company resource and asset.

29 April 2007

Crisis Management: Corporate 4GW...

Crisis Management is getting the increased attention of Board Directors in light of the latest disclosure rules. And Eric Dezenhall's new book is out in collaboration with John Weber and the excerpt is in the latest issue of Board Member. There are 10 crises that are outlined in the article:
  1. Corporate Mission Creep
  2. The Demise of Science
  3. Outspent and Outgunned
  4. Is Junior Covering Your Crisis?
  5. Wall Street War Zone
  6. Everyone's a Pundit
  7. Make 'em Laugh
  8. Your Brand is a Target
  9. Protecting Intellectual Property
  10. The Porous Corporation
Damage Control: Why Everything You Know About Crisis Management Is Wrong. Much of the conventional wisdom about damage control and crisis PR is self-serving, self- congratulatory, self-deceiving—and flat out wrong. And no one knows it better than Eric Dezenhall and John Weber, who have helped countless companies, politicians, and celebrities get out of various kinds of trouble.

If you’re facing a lawsuit, a sex scandal, a defective product, or allegations of insider trading, other PR experts will tell you to stay positive, get your message out, and everything will be just fine. But happy talk doesn’t help much during a real crisis, and it’s easy to lose sight of your real priorities. In a trial, for instance, you might want the whole world to think you’re a wonderful person, but all that matters is whether twelve jurors think you’re guilty.

#10 caught our eye because this discusses the fact that insiders in the organization have a growing powerbase. Fueled with new tools to capture information in real-time and post it to an off site blog or other online location makes the time between the confidential event and the public disclosure become minutes not just hours. Mr. Dezenhall is clear to point out that the new crisis manager is involved in constant monitoring and taking on a more preemptive and preventive mission. Call it "Damage Control" he says.

As the lines begin to blur between corporate roles of crisis management, brand management, public relations, competitive marketing, fraud management and reputation control, so too does the level of Operational Risk. When you have so many individuals responsible for keeping a handle on potential crises as they are uncovered by a tip, a leak or the whistleblower hotline there is an increasing risk of a lack of an effective Incident Management System.

The blogosphere is just another version of the age old online bulletin board on broadband steroids. Skilled journalists who have for years operated in the mainstream media have their own blog on the online site of the offline magazine or newspaper. The power of "Time to Press" is now a matter of the source and the reach of the blog community. Why does Fox Interactive Media own MySpace?

Savvy Board of Directors realize the value of having an open and transparent approach to the governance of the organization. Even as we speak the newest data on executive compensation, perks, bonus or golden parachutes are being published and communicated by online-based data bases. And with all of this transparency and the fact that all of the data is discoverable in an internal investigation or external litigation makes it imperative that management manage this risk proactively. Not after the fact, reactively.

Corporate Risk Intel is nothing new and over the past five years has blossomed into a mandatory high technology business unit within corporate enterprises. The people, processes, systems and tools require a combination of capabilities, expertise and raw instinct. Extensions of Open Source Intel (OSINT) are fueling the internal "Damage Control" department across the globe. The "Porous Corporation" is quickly becoming a modern day forum for survival of the fittest and other Darwinian strategies of "Adaptation".

Over a year ago, this same topic was addressed in adapting to a corporate (4GW) 4th Generation Warfare Paradigm.



25 April 2007

White Collar Crime: Enduring Truth...

In the 19th century a famous sleuth by the name of Al Pinkerton was quoted:

"A professional should possess the qualifications of prudence, secrecy, inventiveness, persistency, personal courage, and above all, honesty."

Inside the walls of global enterprises are the ticking time bombs waiting for the next opportunity to rationalize their malicious acts upon the organization. Individuals with advanced degrees, outstanding performance and continuous community service are operating just like Al Pinkerton has described, with one exception. Honesty.

White collar criminals are taking the corporate beaches by storm. Backdating once a common practice has now more than 100 companies under investigation. Yet, good old fashioned theft of corporate assets is running at an all time high and internal fraud is now with more tips and leaks a much more easy crime to detect, prosecute and punish. Why do so many companies look the other way and just fire an employee when company wrong doing is uncovered? Reputation.

The phrase "white-collar crime" was coined in 1939 during a speech given by Edwin Sutherland to the American Sociological Society. Sutherland defined the term as "crime committed by a person of respectability and high social status in the course of his occupation." Although there has been some debate as to what qualifies as a white-collar crime, the term today generally encompasses a variety of nonviolent crimes usually committed in commercial situations for financial gain. Many white-collar crimes are especially difficult to prosecute because the perpetrators are sophisticated criminals who have attempted to conceal their activities through a series of complex transactions.

The most common white-collar offenses include: antitrust violations, computer and internet fraud, credit card fraud, phone and telemarketing fraud, bankruptcy fraud, healthcare fraud, environmental law violations, insurance fraud, mail fraud, government fraud, tax evasion, financial fraud, securities fraud, insider trading, bribery, kickbacks, counterfeiting, public corruption, money laundering,embezzlement, economic espionage and trade secret theft. According to the federal bureau of investigation, white-collar crime is estimated to cost the United States more than $300 billion annually.

A true Operational Risk Management professional has to operate as Al Pinkerton described and with even more capabilities than in his day. They have competencies and subject matter expertise to address:

  • Identification
  • Assessment
  • Design
  • Implementation
  • Audit
  • Supervision
You have to ID the corporate assets to protect and the threats to those assets. You then have to determine the likelihood of occurrence. What are the impact to organization from a loss? One must also have knowledge and expertise in accounting, auditing, interviewing, investigation, legal elements, digital forensics, reporting, testifying and communicating. Not only does the OPS Risk professional today require honesty, it also requires much more.

Hiring good people is the constant headache of every manager in every industry in every part of the world, and bankers have probably complained about the situation the loudest. But if a bank makes a bad hire, the pain will only be felt years later when it comes out in the newspapers that both the employee and several million dollars have gone missing.

The situation should be avoidable, but the fact is that nobody can really know who it is that they are hiring. Consider the case of one senior banker, who was ready to hire a new personal assistant. Besides being the best candidate for the job, he had once known the applicant when he had worked at her previous company. Through a chance meeting with one of his old co-workers at that bank, he found out that his applicant had been fired for embezzlement, although the information had not been made public.

Actual levels of internal fraud across the industry are a closely guarded secret, although each banker will have a good idea how much it costs his or her own bank. While it is commonly agreed that the cost of internal fraud greatly exceeds that lost on credit card and other fraud, expensive systems required by regulators to manage fraud throw a monkey wrench into the works.

Whether you are in search of the facts or are rendering an opinion, the way you operate and behave within your organization and in front of those individuals you are in pursuit of, remains the same. You are a "Citizen Soldier". This means that you are not influenced by the politics nor the power of those who may try to pursuade you to see it their way. You see it as it is and your mission is to uncover the real truth and only the truth. Reputations are at stake. Lives will be changed forever. But the truth will endure.

18 April 2007

ECM Security: Trusted Information...

When it comes to Enterprise Content Management (ECM), security is an issue that continues to challenge most vendors. John Newton is in search of topics this week at AIIM that address the security needs of the market place:
Content Log

  • Common identity. There needs to be a common way of addressing identity between different services whether those services are in the enterprise or outside.
  • Common Models for Rights Management. The big, looming problem in content is the fact that huge numbers of users are adding, accessing or updating an even larger number of pieces of content.
  • Distributed Directory Services. Identity is not sufficient for determining roles or entitlements.
  • Mashup Frameworks for Security. Mashups, the integration of different systems at the browser level, represent the fastest-growing and easiest mechanism to weld systems together. Almost all mashups have no notion of security and only work on public systems.
  • Search and Security. As search becomes increasingly federated, such as through the OpenSearch API, managing identity and entitlements on content becomes very problematic.
Whether John will find the answers is questionable. And that is exactly the issue when it comes to hosting or managing enterprise information. Almost a year ago before Stellant (Sealed Media) was purchased by Oracle, their survey of 29 CIO's who had invested more than $1M. in ECM had these as their top priorities:
The concerns were ranked on a scale of one to eight, eight being the most important.
  1. Guarantee ISO 17799 compliance: 6.03
  2. Protection of intellectual property during offshoring or outsourcing: 5.52
  3. Protection of high- and executive-level communications: 4.79
  4. Improvement of workflow-process automation: 4.41
So what?

If you are an ECM vendor and you only have so many bucks to spend on development of the next generation of your software, what are you going to add and what are you going to fix? So why is number one and two so important to CIO's who have invested so much money in their platforms?

Some of the answers can be found in the root cause of their concerns. We found some relevant discussion in a position paper entitled:

W3C Workshop on Transparency and Usability of Web Authentication by Jeffrey Ritter & Said Tabet

Statement of Issues: The conflict between the potential of Web Services and the inadequacy of web authentication is potentially best described as “a failure to communicate”. As enterprises extend and evolve into more dynamic, real-time facilities, central operations require the ability to express their security requirements in greater detail than can be currently enabled. Corporations must define and adhere to increasingly large directories of requirements in the management of their internal security controls; requiring compliance with those controls by participants in the extended enterprise is becoming essential.

Corporate operations increasingly distribute their computing and data processing requirements across a network of third party services, some of which are engaged and employed for controlled, finite sessions. But those third parties, for so long as they are processing data and functioning as part of the operating whole of the primary corporation, are being pressured to demonstrate their adherence to the security controls of their customers. This requirement is an expression of a requirement for trustworthiness—to be engaged as a part of the extended enterprise is to be trusted to perform in compliance with the applicable controls.

The enterprise who has exposure to continuous litigation is evaluating new ways to look at 3rd Parties who manage their information and this includes law firms. When you hand over management of critical and legally binding information to a 3rd party, trust is a key component of that decision. So how do you know if your law firm(s) and database marketing companies such as Merkle, Inc. or other outsourced service providers have the trustworthiness to be part of your extended enterprise? The fact is you don't unless you require the new and existing parts of the information supply chain in your organization to operate as one seamless trusted entity.

The greatest economic risk companies face with electronic discovery is choosing the wrong law firm. Under the new Federal Rules of Civil Procedure, the amounts at stake are not just legal fees or settlement costs; searching for and recovering electronic business records causes productivity losses and threatens revenue. Bottom line, selecting a law firm that is ill-prepared to effectively manage electronic discovery can cost enormously - internal records preservation and production costs are considered one of the largest uncontrolled expenses in corporate America.
So how do you select the right firm?

For corporations, Evaluating the Electronic Discovery Capabilities of Outside Law Firms: A Model Request for Information and Analysis provides corporate law departments, records management and IT departments an invaluable tool to ensure that the legal risks of e-discovery are competently addressed by their outside law firms.

Here is a peek at the line up so far this year by just one government regulator, the SEC.

16 April 2007

Workplace Violence: Hokies in Mourning...

As the details of the event unfolds at Virginia Tech, one is reminded that violence of such magnitude is an operational risk in universities and colleges across the globe.
The Virginia Tech shooting occurred on April 16, 2007 at Blacksburg in the U.S. state of Virginia. At least 32 people were killed, including the gunman, with at least 28 injured,[2] making it the deadliest school shooting in United States history.

As the evidence is collected and the investigations determine what could have prevented such a tragic incident there will also be questions about the response. Workplace violence or campus violence is similar in nature from the standpoint that you plan and prepare for such random incidents. The point is that it may never happen but if it does, are you prepared?

Were the three bomb threats in advance of the incident just active surveillance by the shooter? What proactive measures were taken by law enforcement between the first shooting and the second scene where a majority of the deaths occured? The measures taken on that multi-hour timeline will be scrutinized to find out why the buildings on campus were not secured. Was a crisis plan enacted from the point of the first incident and if so, how effective was it?

A few details emerged from the news conference. At 7:15 a.m., an emergency 911 call came in to University police department about a shooting at a campus building, West Ambler Johnston, a dormitory for about 900 freshman students. About three hours later it was followed by a second shooting at a classroom in a science and engineering building on the opposite end of campus, Norris Hall. The shooter died there, the police said.

Suicide bombers and those with a death wish are the ultimate threat. No level of security or proactive measures can defeat this kind of attack. This fact has been proven over the past few decades on and off the battle field. In the aftermath we can only hope that more is done to heighten awareness about "At Risk Behavior" whether it be in school or at work. The cues and clues that bring people to a point of violence are usually noticed by fellow students or co-workers. However, once the event takes place, those individuals who noticed these behavioral warning signs feel the worst about the incident.

The behavior psychologist's will tell you that the signs are there, you just didn't recognize them in time. Besides the obvious drug or alcohol abuse warning signs, some are more subtle.

Other problematic behavior also can include, but is not limited to:
• Increasing belligerence
• Ominous, specific threats
• Hypersensitivity to criticism
• Recent acquisition/fascination with weapons
• Apparent obsession with a supervisor or coworker or employee grievance.
• Preoccupation with violent themes
• Interest in recently publicized violent events
• Outbursts of anger
• Extreme disorganization
• Noticeable changes in behavior
• Homicidal/suicidal comments or threats

Once the determination is made what motivated this individual to carry out this act today, we will use that information. It will become a new or even repeated warning sign that we have become complacent to in our day to day interactions with others on the job or in the class room.

How will the new crisis programs and workplace violence programs be communicated across the nation incorporating these lessons learned? To begin the process of finding out what is in place and what needs to be done, here is a very relevant self-audit from The National Institute for the Prevention of Workplace Violence.


Workplace Violence Prevention Audit Questions:
  1. Has a specific management level person been designated as the person responsible for coordinating the company's workplace violence prevention initiative?
  2. Has an integrated workplace violence prevention team (also known as Threat Management or Threat Assessment Team) effort been established that includes representatives from the following functions: security, occupational safety & health, risk management, legal, public relations/corporate communications, human resources and operations management?
  3. Does the company have a workplace violence prevention policy?
  4. If a written workplace violence policy exist, does it include provisions addressing how to deal with domestic violence in the workplace, mobbing and bullying behaviors?
  5. Does the company have a written plan describing how the workplace violence prevention plan will be implemented?
  6. Has a pre-established emergency protocol been put in place with local law enforcement and a specific individual (and back up) been designated to contact the police during a critical incident?
  7. Have all managers been trained in workplace violence prevention?
  8. Have all employees been trained in workplace violence prevention?
  9. Does the company have a policy prohibiting the possession of weapons on the company's premises and while an employee is performing their job?
  10. Has the company conducted an organizational violence assessment to determine if 'the common factors of violence prone organizations' are present?
  11. Has the company conducted a Facility Risk Assessment of all of it work areas?
  12. Does the company have a process and procedure in place for conducting Individual Threat Assessments?
  13. Has the company pre-identified and pre-qualified an external workplace violence expert and critical incident debriefing team to assist the organization, if needed?
  14. Are their known workplace violence hazards that employees are exposed to, and/or are similar businesses or companies in your industry or geographic area known for having workplace violence hazards?
The questions will remain for years to come as the answers are discovered in conference rooms and court rooms across the country. Was this the wake-up call that we all needed? And for those who are seeking proven solutions to this Operational Risk, consider Defywire.

13 April 2007

In Search of Answers: OPS Risk Intel...

When it comes to Operational Risk, what is on your mind? These are just a few recent inquiries from around the globe:

  • operational risk consultant
  • plausible deniability risk mitigation
  • operational risk and causes for information technology department
  • digital forensics plus ediscovery software
  • operational risk management in bank
  • hedge risk asian tsunami
  • bbc programmes advice on insurance companies covering anti terrorist cover
  • hsac navy seals
  • metrobank and trust company philippines risk managment practice
  • passmark passes fdic audit
  • gsk italy germany executive's supply chain quality assurance manufacturing
  • define issues and action plans orm
  • ethical prior the implemention of disaster response
  • operational risk management dulles airport
  • Business Crisis and Continuity Management (BCCM)
  • invision, deloitte, risk, root cause analyses
  • bs 25999 part1
  • system malfunction hurricane katrina critical infrastructure
  • fraud risk management vs. compliance investigation
  • "opinion letter" "disaster recovery"
  • the newest trends in operational risk for public sector
  • north carolina department of revenue real estate investment trust voluntary disclosure
  • parmalat crisis management
  • public sector operational risk management
  • bank of america sas 70
  • example document retention policy homebuilder
  • fbi justice report sedona mortgage fraud
  • operation risk management test answers
  • suibin zhang
  • authenticol systems boulder
  • helicopter detecting grow ops
  • using ipsonar opinion
  • pneumonia, operational risk
  • reasons for enterprise risk management assessment

If you are like us, we see some real "nuggets" of intel in these searches. One observation is that Operational Risk is diverse and it's facets are complex. The interdependencies of people, processes, systems and external events combined with the legal implications makes this discipline ever more sought after in the ranks of enlightened institutions.

So why would somebody be looking for information on
plausible deniability risk mitigation?

Over a year ago Bruce Schneier had this to say:

Deniable File System

Some years ago I did some design work on something I called a Deniable File System. The basic idea was the fact that the existence of ciphertext can in itself be incriminating, regardless of whether or not anyone can decrypt it. I wanted to create a file system that was deniable: where encrypted files looked like random noise, and where it was impossible to prove either the existence or non-existence of encrypted files.

This turns out to be a very hard problem for a whole lot of reasons, and I never pursued the project. But I just discovered a file system that seems to meet all of my design criteria -- Rubberhose:

Rubberhose transparently and deniably encrypts disk data, minimising the effectiveness of warrants, coersive interrogations and other compulsive mechanims, such as U.K RIP legislation. Rubberhose differs from conventional disk encryption systems in that it has an advanced modular architecture, self-test suite, is more secure, portable, utilises information hiding (steganography / deniable cryptography), works with any file system and has source freely available.

The devil really is in the details with something like this, and I would hesitate to use this in places where it really matters without some extensive review. But I'm pleased to see that someone is working on this problem.

Next request: A deniable file system that fits on a USB token, and leaves no trace on the machine it's plugged into.

So what? Why would an Operational Risk Professional be concerned about a USB token that leaves no trace on the machine it's plugged into? We think you get the big picture here. So are there any other nuggets of intel worth exploring in this latest list of searches?


What about Business Crisis and Continuity Management (BCCM)? When it comes to a crisis, there are numerous sources that impact your Operational Risk Strategy:

The many sources of significant loss events are changing as we speak. Here are a few that should not be overlooked:

· Public perception

· Unethical dealings

· Regulatory or civil action

· Failure to respond to market changes

· Failure to control industrial espionage

· Failure to take account of widespread disease or illness among the workforce

· Fraud

· Exploitation of the 3rd party suppliers

· Failure to establish a positive culture

· Failure in post employment process to quarantine information assets upon termination of employees

So what? Boards of Directors have the responsibility to insure the resiliency of the organization. The people, processes, systems and external events that are constantly changing the operational risk landscape become the greatest threat to an enterprise. It’s the shareholders duty to scrutinize which organizations are most adept at “Continuous Continuity” before they invest in their future. Hopefully you understand that the operational risk spectrum is wide as it is deep. Keeping your fingers on the pulse of what people are concerned about could be as simple as this quick exercise in "search terms analysis."