20 September 2007

A Defensible Standard of Care: Six Million Reasons...

There are 6,000,000 reasons why Operational Risk at TD Ameritrade is in the Red Zone this week as a result of what seems to be a case of malicious code discovered last week, or over a year ago.

This author received a recent letter from TD Ameritrade regarding their so called pseudo "breach". And we quote:

"While investigating client reports about the industry-wide issue of investment-related SPAM, we recently discovered and eliminated unauthorized code from our systems. This code allowed certain information stored in one of our databases, including email addresses, to be retrieved by an external source."


What is absolutely amazing is the request to visit www.amtd.com for more information and a list of Frequently Asked Questions (FAQs) and an additional message from me, (The CEO Joe Moglia). The link to this message requires you to run Windows Media Player for what must be a sincere apology. However, the PR department must not know how many malicious code exploits are associated with .wmv files. Nor, how many people still do not have broadband connections as a consumer.

But that is not even the most fascinating aspect of this whole incident. The story gets even more disturbing if it is indeed true:

Scott Kamber of Kamber & Associates, a New York law firm that sued Sony BMG last year for its use of a rootkit, told InformationWeek on Monday that the lawsuit initially claimed that Ameritrade knew about the data breach last November. However, he says he now has information that the company knew about the ongoing breach a full year ago.

Kamber, who filed the suit this past May, had recently filed a preliminary injunction asking the court to compel Ameritrade to disclose the data breach and the compromised information to current and prospective customers. The company was given a two-week adjournment and made the public announcement during that recess.

"I am glad customers finally know of the compromise of their personal information," said Kamber. "I'm not pleased it took the company so long to do that."

Hillyer said she could not comment on ongoing litigation but said, "As soon as we discovered it, we stopped it. And as soon as we had gathered enough information, we notified our clients."

Ameritrade notified the FBI and the U.S. Securities and Exchange Commission last week, according to the spokeswoman.

It's apparent that the nexus of Information Security, Digital Forensics, eDiscovery, Legal Risk and Reputation Management have imploded in Bellevue, NE yet this will not be the last place we hear about this kind of incident. If a Rootkit is on a server there, you can be sure that there are others at a another broker or investment management firm near you.

Being vigilant about protecting privacy and doing the right thing with customers in the event of a breach has significant legal ramifications, that is for certain. What is less known at this point are the processes and corporate behavior that could be even more of a source of liability for TD Ameritrade. Who what how and why is now under investigation and will play out in a court room again soon.

The degree that any firm in the industry is "Litigation Ready" or has adequately prepared for this particular nexus between the elements of Information Security and the Law will determine the amount of Operational Risk they are potentially exposed to in incidents like this one. How can any firm prepare for an event similar to this?

1. Conduct a Litigation Readiness Audit of the firm.

2. Develop a strategic plan for achieving a "Defensible Standard of Care."

3. Train the stakeholders on Crisis, Command and Control.

4. Implement an early warning data analytics system to preempt potential threats.

Number four on this list pertains to something that is also in the authors letter. "As part of our effort to protect privacy, we have hired ID Analytics, which specializes in identity risk, to investigate and monitor potential identity theft." Let's just hope these guys didn't load up a CD at their shop handed over to them by TD Ameritrade with 6,000,000 records of personal identifiable information on it.

14 September 2007

Privileged Information: The Decision to Cooperate...

True or false: A large corporate private sector company hires an outside counsel to investigate an employee suspected of fraud. The outside counsel hires a fraud examiner to look into the facts. The fraud examiners report to the outside counsel will assist in determining whether a crime has been committed. The report and the communications with the outside counsel are protected confidential work product and is privileged. If you don't know the answer, read on.

Organizations who realize that internal investigations can pose a tremendous risk of litigation are ahead of the Operational Risk Management curve. Being proactive about prudent strategy on how to address the potential internal employee fraud is imperative, especially if you plan to pursue litigation to try and recover the stolen assets.

The two primary areas of emphasis here for the purpose of what information is discoverable is the attorney-client privilege and the work product doctrine: This Texas case from the Texas Bar Journal article by Derek Lisk illustrates the point:

In yet another case in which one party sought to protect documents from an investigation on privilege grounds, the U.S. District Court for the Eastern District of Texas took a more expansive view of the privilege. In-house counsel for Electronic Data Systems (EDS) hired outside attorneys, who in turn hired a consulting firm, to independently analyze and report on alleged misuse and misappropriation of assets by an EDS employee, Mr. Steingraber. In the ensuing litigation, EDS objected to producing documents from the investigation.

Steingraber, like Seibu Corp., argued that the documents were not privileged “because they were made to facilitate a business decision rather than the rendition of professional legal services.” This court, however, sided with the party seeking to protect the documents, finding Steingraber’s interpretation of the privilege “unduly narrow” and disagreeing with Seibu Corporation to the extent it held otherwise. Among other things, the court said, “The fact that the attorneys may have been hired to facilitate a business decision does not mean that such a decision was devoid of legal consequences.” Because EDS hired the outside lawyers to contribute legal expertise, including contract interpretation, risk evaluation, witness interviews, and evidence evaluation, the communications between them were “for the rendition of legal services.”

The status of H.R. 3013 in the US House of Representatives is unknown as it goes to be debated in committees:
7/12/2007--Introduced.
Attorney-Client Privilege Protection Act of 2007 - Amends the federal criminal code to prohibit any U.S. agent or attorney, in any federal investigation or criminal or civil enforcement matter, from demanding, requesting, or conditioning treatment on the disclosure by an organization (or affiliated person) of any communication protected by the attorney-client privilege or any attorney work product.
Prohibits a U.S. agent or attorney from conditioning a civil or criminal charging decision relating to an organization (or affiliated person) on one or more specified actions, or from using one or more such actions as a factor in determining whether an organization or affiliated person is cooperating with the government.
The question on the table here is how much as a corporation do you want to cooperate to prosecute the employee? It may make sense as a corporation to waive some rights to help recover your losses. How you architect a process for engaging outside counsel, independent investigators and fraud examiners in order to mitigate Legal Risk is crucial. The information exchanged, obtained in the process and communicated between parties must be done correctly. Not only to protect the information under the new Federal Rules of Civil Procedure but to insure the integrity and trust of the information itself.

A Board of Directors that oversees the governance of hundreds or thousands of employees is going to be continuously subjected to corporate malfeasance and white collar crime matters. The rule of law within the halls of the organization must be clear and precise. The mechanisms for the company to cooperate with investigators may mean the difference between an employee that creates irreversible economic damage to the enterprise or even worse. Our national security.

07 September 2007

BMPE: Internal Audit Awareness...

Risk in the supply chain may not always come from that vendor who provides your power, water or telecommunications. Black Market Peso Exchange (BMPE) is an Operational Risk that is starting to gain more awareness with Internal Auditors. This has been around since the 1980's yet even today some of our most sophisticated financial services institutions are being subjected to this system of fraud. The BMPE has been another way for money laundering from illicit criminal drug proceeds to impact our risk management controls:
American Express Bank International's anti-money laundering program was deficient in three of the four core elements. Namely, the Bank failed to implement adequate internal controls, failed to conduct adequate independent testing, and failed to designate compliance personnel to ensure compliance with the Bank Secrecy Act. American Express Bank International's high-risk customer base, product lines, and international jurisdiction of operations required elevated measures to manage the risk of money laundering and other financial crimes.

Nevertheless, the Bank conducted business without adequate systems and controls reasonably designed to manage the risk of money laundering, including the potential for Black Market Peso Exchange transactions that may be used by Colombian drug cartels to launder the proceeds of narcotics sales. American Express Bank International's failure to comply with the Bank Secrecy Act and the regulations issued pursuant to that Act were serious, repeated and systemic.

This method of money laundering is effective for the drug traffickers and requires more awareness on the behalf of fraud examiners and independent auditors. The IRS form 8300 requiring companies and financial entities to disclose receipts in excess of $10K in cash or equivalents doesn't work very well as wire transfers are not considered cash or cash equivalents.

Javier Sarmiento with GlassRatner has a substantive article on the subject in the last issue of the ACFE Fraud Magazine.

A point is made that needs to be emphasized here. "Don't rely on banks and financial institutions to conduct anti-money laundering (BSA/AML) procedures on behalf of the company." Is it possible that your organization has purchased inventory with funds that have been utilized as part of the BMPE scheme? What about resellers and distributors that are part of your own revenue supply chain.

In terms of Independent testing, make sure that your Internal Audit department is educated and aware of this particular mechanism for use by money launderers:

American Express Bank International's independent testing of its Bank Secrecy Act program was ineffective. Internal Audit Staff lacked sufficient training and knowledge to facilitate compliance with the Bank Secrecy Act. Audit scopes were not always tailored or designed to capture and test for compliance with certain requirements of the Bank Secrecy Act.

Internal Audit staff also failed to conduct sufficient customer transaction testing to adequately evaluate the overall sufficiency of the anti-money laundering program at the Bank. Furthermore, Internal Audit failed to assist management with tracking and following-up on previously identified regulatory examination deficiencies. In addition, Internal Audit failed to conduct adequate testing of the suspicious activity monitoring system or identify the numerous data integrity concerns associated with this system for an extended period of time. The ineffectiveness of the Internal Audit function at American Express Bank International contributed to the failure to identify significant deficiencies in this system before 2007.

03 September 2007

A-Space: Intel 2.0...

A week or so from now around 8:30AM on the East Coast of the United States there will be many people remembering where they were six years ago. On September 11, 2001 we will stop and observe a minute of silence and reflect on all that has changed and been accomplished and what has stayed the same. It may seem like a distant memory for some, yet a bad dream from last night for so many others.

Sharing intelligence or the valuable aspects of relevance, to you, or your enterprise requires the proper tools and mechanisms. This is a given. However, all the operational risk tools and systems will never be the entire answer to finding the "needle in the haystack" or "connecting the dots". The DNI has been implementing the right kinds of methods and applications to help solve the equation for preventing catastrophic incidents of the magnitude of 9/11 in search of the correct answers:

It's hard to imagine spies logging on and exchanging "whuddups" with strangers, though. They are just not wired that way. If networking is lifeblood to the teenager, it is viewed with deep suspicion by the spy.

The intelligence agencies have something like networking in mind, though, as they scramble to adopt Web technologies that young people have mastered in the millions. The idea is to try to solve the information-sharing problems inherent in the spy world - and blamed, most spectacularly, for the failure to prevent the Sept. 11, 2001, attacks.

In December, officials say, the agencies will introduce A-Space, a top-secret variant of the social networking Web sites MySpace and Facebook. The "A" stands for "analyst," and where Facebook users swap snapshots, homework tips and gossip, intelligence analysts will be able to compare notes on satellite photos of North Korean nuclear sites, Iraqi insurgents and Chinese missiles.

Sharing information is not the hard part. Analyzing it with the "grey matter" necessary to put 2 + 2 together beyond the capability of the algorithms of the software requires training and extreme context. Corporate Enterprises have been utilizing similar systems and tools on their secure Intranet's for years and the agencies are now taking the lessons learned and applying these to the social networking community of their analysts. Smart strategy as many of these "Outsourced" entities are operating from the private sector NOC or SOC and have been delivering intelligence products long before they were hired to do so for the government.

Observing the lessons from the Financial Services Industry on what works and what is treading on thin ice can be a helpful example. Sharing intelligence across organizations, platforms and between competitors has been the norm at SWIFT:

SWIFT is the industry-owned co-operative supplying secure, standardised messaging services and interface software to over 8,100 financial institutions in 208 countries and territories. SWIFT members include banks, broker-dealers and investment managers. The broader SWIFT community also encompasses corporates as well as market infrastructures in payments, securities, treasury and trade. Over the past ten years, SWIFT message prices have been reduced over 80%, and system availability approaches 5x9 reliability — 99.999% of uptime.
Swift is considered the nerve center of the global banking industry, routing trillions of dollars each day between banks, brokerages and other financial institutions. The group's partnership with the U.S. government, first revealed in media reports in June 2006, gave officials at the CIA access to millions of records on international banking transactions in an effort to trace money that investigators believed might be linked to terrorist financing. Swift agreed to turn over large chunks of its database in response to a series of unusually broad subpoenas issued by the Treasury Department beginning months after the attacks of Sept. 11, 2001.

At 8:30AM on 9/11 2007 during our moment of silence we can only pray that our Intel sharing continues and doesn't get strangled by those who have forgotten this day of remembrance.

30 August 2007

BSA/ AML: Testing the Channel...

Legal compliance with the Bank Secrecy Act (BSA) and Anti-Money Laundering (AML) is a complex and growing concern by regulators, enforcement and Operational Risk Executives. In the United States, the FFIEC (Federal Financial Institutions Examination Council) has published the latest Examination Manual to provide guidance:

Enterprise-Wide BSA/AML Risk Assessment

Holding companies or lead financial institutions that implement an enterprise-wide BSA/AML compliance program should assess risk both individually within business lines and on a consolidated basis across all activities and legal entities. Aggregating risks on an enterprise-wide basis for larger or more complex organizations may enable an organization to better identify risks and risk exposures within and across specific lines of business or product categories. Consolidated information also assists senior management and the board of directors in understanding and appropriately mitigating risks across the organization. To avoid having an outdated understanding of the BSA/AML risk exposures, the holding company or lead financial institution should continually reassess the organization’s BSA/AML risks and communicate with business units, functions, and legal entities. The identification of a BSA/AML risk or deficiency in one area of business may indicate concerns elsewhere in the organization, which management should identify and control.

When a financial institution utilizes a strategy for it's channel or broker network the goal is to build controls into the consumer application process. These controls help the parent financial institution with compliance issues and give the independent broker or registered investment advisor with the tools and mechanisms for risk mitigation. However, to what degree do these independent brokers who interface with the consumer actually understand, implement and comply 100% with BSA/AML laws?

This question may haunt the minds of many OPS Risk professionals as they try to manage the mountain of data and documentation requirements at the home office or processing center. When there are dozens or hundreds of independent brokers in the client acquisition process your risk exposure increases dramatically. When and how often do you need to audit these important entities in your member or client supply chain?

Independent testing (audit) should be conducted by the internal audit department, outside auditors, consultants, or other qualified independent parties. While the frequency of audit is not specifically defined in any statute, a sound practice is for the bank to conduct independent testing generally every 12 to 18 months, commensurate with the BSA/AML risk profile of the bank. Banks that do not employ outside auditors or consultants or have internal audit departments may comply with this requirement by using qualified persons who are not involved in the function being tested. The persons conducting the BSA/AML testing should report directly to the board of directors or to a designated board committee comprised primarily or completely of outside directors.

Those persons responsible for conducting an objective independent evaluation of the written BSA/AML compliance program should perform testing for specific compliance with the BSA, and evaluate pertinent management information systems (MIS).

This is not any surprise to large banks and securities dealers who have been working diligently on these compliance management problems for decades. Whenever an organization is deploying a distributed and indirect model for acquiring new consumers, high net worth individuals and other business entities for financial-based products and services; BSA/AML programs should be robust. The individuals who are planning to launder money that has been obtained illegally or are part of a fraud scheme will prey on those unsuspecting and naive institutions first. In some cases, it could be an independent broker or business who is the target of a sophisticated and influential individual. They want to find a weak link in the institutions sales channel to gain access to a well known brand to leverage their scheme with new victims.

The criminal trial of ex-Refco Inc. Chief Executive Phillip R. Bennett and two other former executives has been postponed until March 2008, according to court transcripts.

During a telephone conference last month, U.S. District Judge Naomi Reice Buchwald delayed the trial of Bennett; Robert C. Trosten, Refco's ex-chief financial officer; and Tone N. Grant, the commodities broker's former president, until March 17. A transcript of the call was released publicly earlier this week.

The case was originally scheduled to go to trial in October.

The men are facing a variety of charges including conspiracy, securities fraud, bank fraud, wire fraud and money laundering.

Late Wednesday, the litigation trusts representing Refco's creditors announced they had sued Thomas H. Lee Partners LP in federal court in Manhattan, alleging the buyout firm uncovered red flags about Refco and its executives before the buyout firm's 2004 purchase of a controlling stake in Refco, but failed to follow up in hopes of profiting from Refco's initial public offering the next year. Lee has denied the claims.


13 August 2007

ESI: Authenticity of Evidence...

Legal opinions on the admissibility of evidence and electronically stored information (ESI) are becoming more prevalent and increasingly relevant to Operational Risk Management:

In Lorraine v. Markel, authentication of information is a key issue in the ruling. Maryland Courts Watcher caught this ruling and our eye recently. "In its 101 page opinion, the court dedicated at least 90 pages to providing extensive and detailed analysis and guidance on the interrelated evidentiary issues governing the admissibility of electronically stored evidence (ESI), including: analysis under Rule 104, relevance under Rule 401, authentication as required by Rule 901(a), effect of hearsay as defined by Rule 801 and any applicable exceptions, consideration of the form of the ESI being offered under the original writing rule and the admissibility of any secondary evidence to prove its content, and the probative value of the ESI considering potential unfair prejudice or one of the other factors identified by Rule 403."

Whether ESI is admissible into evidence is determined by a collection of evidence rules that present themselves like a series of hurdles to be cleared by the proponent of the evidence. Failure to clear any of these evidentiary hurdles means that the evidence will not be admissible. Whenever ESI is offered as evidence, either at trial or in summary judgment, the following evidence rules must be considered: (1) is the ESI relevant as determined by Rule 401 (does it have any tendency to make some fact that is of consequence to the litigation more or less probable than it otherwise would be); (2) if relevant under 401, is it authentic as required by Rule 901(a) (can the proponent show that the ESI is what it purports to be); (3) if the ESI is offered for its substantive truth, is it hearsay as defined by Rule 801, and if so, is it covered by an applicable exception (Rules 803, 804 and 807); (4) is the form of the ESI that is being offered as evidence an original or duplicate under the original writing rule, of if not, is there admissible secondary evidence to prove the content of the ESI (Rules 1001-1008); and (5) is the probative value of the ESI substantially outweighed by the danger of unfair prejudice or one of the other factors identified by Rule 403, such that it should be excluded despite its relevance.

Authenticity and the chain of custody of ESI will continue to be a major challenge for the general counsels of major corporations in the years ahead. Creating and maintaining trusted information through out the enterprise intersects policy, processes, people and technology. The legal risk associated with non-compliance and missed opportunities is a growing concern in executive management and Board of Directors meetings.

The explosion of information as early as 2001 started a process of discussions on the nexus of information security regarding data integrity and authenticity:

With the explosive growth of data exchange and the availability of access to services over the Web, the Trusted Information requirement is more and more an issue to providers and users of these services. Addressing this security issue, this volume is divided into eleven parts covering the essentials of information security technologies, including application-related topics, and issues relating to application development and deployment:

  • Security Protocols;
  • Smart Card;
  • Network Security and Intrusion Detection;
  • Trusted Platforms;
  • eSociety;
  • TTP Management and PKI;
  • Secure Workflow Environment;
  • Secure Group Communications;
  • Risk Management;
  • Security Policies;
  • Trusted System Design and Management.

Companies like IBM have been talking to clients about trusting their information for decades. However, when the discussions turn to litigation and admitting information stored on hard disks, dvd's, USB Thumb Drives and the data on your VOIP phone system it all starts to become more complex than one could ever imagine. That complexity and the speed that courts are asking for responsive answers puts your legal risk in the center of the discussion.

Achieving a Defensible Standard of Care requires more than a savvy outside counsel. It demands an effective CIO, CSO and Records Manager working in combination with the hundreds of law firms you may have retained to address your ongoing litigation.

22 July 2007

Show Me The Money: Complacency Risk...

The last time we checked, CFO's were still doing battle with CxO's about their budget and the growing magnitude of Operational Risks as a result of too little funding. Learning how to count differently is a consistent conversation within the ranks of corporate enterprises today. How do I address the needs of the employee, the regulators and management for software systems and safety solutions that require continuous change with this budget?
"Champions for new investments in Enterprise Content Management (ECM) solutions must make convincing arguments for change. Among many hurdles, the champion must express a business case for an ECM solution. That business case must present an economic analysis of the "before" and "after" financial impact. It must deliver measurable financial return on investment (ROI). The bottom line that is always asked is "show me the money".

Enterprise Content Management is the technologies used to Capture, Manage, Store, Preserve, and Deliver content and documents related to organizational processes.

The business case for any new investment requires an analysis of what the existing business issue or problem is and what the benefits are, making this new investment. Counting differently than in the past may require looking beyond the typical methods for creating this so called "Show me the money" step for executive management. Can ECM provide the solution to more than one of the problems in the enterprise with managing information and getting answers faster and more accurately than ever before? If it can, then this could be a path to designing a risk management architecture that provides a myriad of capabilities across a spectrum of potential vulnerabilities.

The most important job is to keep in-house information under control. The questions add up: where to put the thousands and thousands of e-mails, what to do with the electronically signed business correspondence, where to put taxation-relevant data, how to transfer information from the disorganized file system, how to consolidate information in a repository that everybody can use, how to get a single login for all the systems, how to create a uniform in-basket for all incoming information, how to make sure that no information is lost or ignored, etc. etc. Document technologies play an important role in all these questions. ECM solutions are necessary basic components for many applications. Every potential user will naturally consider his own individual needs before deciding on a system. However, putting off decisions does not make them less necessary. Every year something supposedly better and easier to use will come along, but waiting will just mean never installing anything. Every time the decision is put off, the mountain of uncontrolled and unused information gets bigger, and known problems get larger. A sensible long-term migration strategy removes the fear of fast technology change.

Complacency is a threat that many do not think about. What is the cost of complacency in delaying decisions to invest? Whether it be that latest hot stock, buying new enterprise software or the maintenance on the critical infrastructure supporting your operations, timing is everything. At some point, a decision has to be made and you are never going to have enough data to totally justify an investment one way or another. You must find the courage to do something, before complacency makes the decision for you:

One person has been killed and at least 20 others injured when a steam pipe exploded underneath a street in central New York during the evening rush hour.

The explosion in midtown Manhattan sent clouds of steam, mud and rocks into the air and forced the evacuation of nearby streets and Grand Central Station.

The New York Police Department said the incident was not terrorism-related.

Millions of pounds of steam are pumped beneath the streets of New York to help heat and cool thousands of buildings.

The 83-year-old pipe exploded just before 1800 (2200 GMT), sending people running from the scene as steam billowed up from the ground.

New York Mayor Michael Bloomberg later ruled out the possibility of a terrorist attack.

"There is no reason to believe whatsoever that this is anything other than a failure of our infrastructure," he told a news conference.

"The big fear that we have is whether there may or may not have been asbestos released."

Maintaining, upgrading and investing in your IT software systems is no different than looking after your power generation pipelines or critical infrastructure conduits along right of ways. Lack of robust Software Quality Assurance and the complacency for justification of new systems may not result in human fatalities such as the explosion in NYC. Unless of course the information you desire can't be found or can't be accessed when you need it.

Connecting the Dots and Show Me The Money are what complacency risk is all about.

17 July 2007

4GW: Trusted Information Class Actions...

The SEC is in the middle of a Supreme Court battle and they have called in the "A" team to assist. Former SEC officials William H. Donaldson, Arthur Levitt and Harvey J. Goldschmid want to expand investors' abilities to sue in frauds:

The big-money issue has mobilized lawyers who bring class-action lawsuits and the companies and executives they target in one of the most important securities-law issues to reach the Supreme Court in years.

In cases in which fraud-ridden corporations have filed for Chapter 11 bankruptcy protection, investors may not be able to wrest money from the company itself. Lawsuits against business partners and advisers such as accountants and lawyers may present the only rich and viable option for shareholders and plaintiff lawyers, experts said.

What have we learned since Enron? Do we not have a more ethics based atmosphere at the professional services firms? In the long run, will investors be better off with the ability to sue the advisors of the companies as accomplices to wrong doing? You can bet that if the US Chamber of Commerce has it's way, the SEC is in for a real fight on this one.

Some people are behind bars. Some companies are out of business. And the Dow is again at an all time high nearing the 14,000 threshold. All of the legislation, class actions and fraud allegations are all about one thing. Information. Trusted Information.

A number of trends focused on corporate data continue to distract today's IT departments. Shareholders are clamoring for more transparency as a result of the financial scandals that have shaken confidence in corporate governance around the world. Compliance legislation such as the U.S. Sarbanes-Oxley Act (whose impact is reaching far beyond the U.S.) can result in jail sentences for executives who - even unintentionally - report erroneous information. New privacy laws around the world restrict the use of customer information. Increasing global competition has put pressure on organizations to use their expensive information assets more strategically.

All these issues can be summed up in a single concept: trusted information. Simply accessing data is no longer enough. Today's CEOs, CFOs and knowledge-workers must be able to reliably track the information they use for decisions back to the original source systems in order to ensure its timeliness, accuracy and credibility.

Over the last decade, organizations have invested millions of dollars in systems to collect, store and distribute information more effectively. Despite this, information users at all levels of the organization are often uncomfortable with the quality, reliability and transparency of the information they receive.

Today's organizations rarely have a "single view of the truth." Executives waste time in meetings debating whose figures are correct, rather than what to do about the company's issues. Additionally, they worry about the consequences of making strategic decisions using the wrong information, directly impacting the long-term survival of the organization.

This brief essay by Jeffrey Ritter discusses the compelling forces converging at the beginning of the 21st century that are shaping the need to consider trusted information as a vital asset that should be the priority of any organization:

As the 21st century accelerates, digital devices connected to the Net will continue to be indispensable to modern life. But those devices, and the services provided through them, remain vulnerable to human judgment—the 21st century winners will be those who earn and sustain the trust of those using the devices and the services—whether those are consumers, employees, shareholders, lenders or service providers.

When the law intersects with the validity of information the corporate battle lines are drawn. Think about how much time and dollars are spent proving or disproving the integrity of information in a court of law. Those organizations who know that they are in the "4th Generation Warfare" (4GW) era will survive only if they can grasp this concept. Fourth Generation Warfare removes the front entirely. Attackers rely on a barrage of information salvos and coordinated incidents to paralyze or erode the adversaries political will, rather than seeking decisive hand-to-hand combat. Does this sound familiar to your General Counsel?

We are not talking about Al Qaeda now. We are talking about the class action "Army" that is forming the strategy and the means to wage unconventional battles against your, trusted information. Or is it?

22 June 2007

Private Equity: Nexus of Risk...

In recent comments in the main stream security media we have heard that convergence is over. It means that the arguments are over on whether convergence is a highly debated topic, not that it is still occuring. In fact, it is speeding up with M & A activity and the private equity surge to buy and sell large global enterprises.

Why would a company like Blackstone Group do an MBO with a company like Intelenet Global Services? Convergence in information technology is still happening under the umbrella of Business Process Outsourcing (BPO) at a rapid pace. More layoffs and elimination of redundant data centers, call centers and customer service centers is a tremendous business. Especially when you are trying to gain control, slice up and sell companies like Sungard, Nielson and other significant investments in critical infrastructure. It's going to be a deja vu moment anytime soon. When you are operating a private equity firm with so many facets you require special people with power and to give you advice. That is why Paul O'Neil is only a phone call away from the Senior Managing Directors at BX.

What kind of Operational Risks are happening within the portfolio of private equity firms like Blackstone as they try to achieve economies of scale and convergence? The same kind that exist within any organization that is focused on convergence and divergence of information simultaneously. Centralize telecom and decentralize risk management to the business units. Centralize information processing and decentralize access through mobile devices. The list goes on.

Execution, Delivery & Process Management

Losses from failed transaction processing or process management, from relations with trade suppliers and vendors. This includes Transaction Capture, Execution & Maintenance Miscommunication, Data entry, maintenance or loading error Missed deadline or responsibility, Model / system misoperation Accounting error, entity attribution error, Delivery failure, Collateral management failure Reference data maintenance, Monitoring & Reporting Failed mandatory reporting obligation, Inaccurate external report (loss incurred), Customer Intake & Documentation Client permissions / disclaimers missed Legal documents missing / incomplete, Customer / Client Account Management Unapproved access given to accounts, Incorrect client records (loss incurred), Negligent loss or damage of client assets, Trade partners, non-client vendor misperformance and vendor disputes.

Business Process Outsourcing (BPO) and Business Process Management (BPM) are being hailed as the answer to mitigating much of the operational risk exposures. It is also about creating new found synergies and elimination of redundant systems in order to drive greater return on investment. Yet all of the enterprise architecture, IT reengineering and Six Sigma / Lean will not change the current and impending threat to our interdependent Internet Protocol (IP) linked economy.

John Schwarz from the New York Times highlights the reality of the possibility of an Internet Armageddon. "ANYONE who follows technology or military affairs has heard the predictions for more than a decade. Cyberwar is coming. Although the long-announced, long-awaited computer-based conflict has yet to occur, the forecast grows more ominous with every telling: an onslaught is brought by a warring nation, backed by its brains and computing resources; banks and other businesses in the enemy states are destroyed; governments grind to a halt; telephones disconnect; the microchip-controlled Tickle Me Elmos will be transformed into unstoppable killing machines."

Private sector companies that are owned or controlled by large private equity and alternative investment hedge funds may be even more at risk and the target of both nation state (China) and non-state actors (Al-Qaeda in Europe). Getting access to the information on the future plans, strategy and architecture of protecting critical infrastructure companies is a priority by those who wish to wage a simultaneous salvo of both digital and physical attacks.

A major hurdle that nations face in defending their critical infrastructures is working with the entities that actually own their countries' telecommunications networks, electrical grids, and transportation systems. This is a major issue in the United States, given that the private sector owns more than 85% of the critical infrastructure and doesn't take kindly to government demands that shareholder money be invested in protection rather than expansion.

Cooperation between government and private-sector critical infrastructure owners is essential. "When it comes to information warfare, corporations in general are no match for a trained [enemy] intelligence officer," David Drab, a 27-year veteran of the FBI who retired in 2002 and is now principal for information content security with Xerox Global Services, said in an interview. These officers have an objective, they have resources, and often they have the element of surprise on their side, he added.

Acceleration of private equity investments puts control of managing the vital lifeblood of information into the hands of Senior Managing Directors, CIO's and Project Managers at the BPO third parties. The nexus of thinking from these participants is to do what ever it takes to converge operations and eliminate redundancy. One can only hope that they are becoming together to discuss the same topics as other large financial institutions. The East Coast Buildings Plot is just one example of why this is imperative.

In publicly released statements, bin Laden has also stressed his “policy” of “bleeding America to the point of bankruptcy.” And an excerpt from the Al Qaeda publication Sawt al-Jihad states:

“If the enemy has used his economy to rule the world and hire collaborators, then we need to strike this economy with harsh attacks to bring it down on the heads of its owners. If the enemy has built his economy on the basis of open markets and free trade by getting the monies of investors, then we have to prove to these investors that the enemy's land is not safe for them, that his economy is not capable of guarding their monies, so they would abandon him to suffer alone the fall of his economy.”


19 June 2007

FACTA: The Writing is on the Wall...

Now that the financial community is wiping their brow with a sigh of relief on this latest Supreme Court ruling, what can a General Counsel or Chief Risk Officer expect? Will the adversarial train of plaintiff suits slow down and come to a halt. Not likely.

The U.S. Supreme Court's ruling that blocks investors from suing Wall Street investment banks under antitrust laws could save Wall Street firms a bundle by limiting investors to smaller recoveries.

In a case dating back to the dot-com bubble, the high court ruled Monday that antitrust suits would pose a "substantial risk" to the securities market. Damages in antitrust cases are tripled, in contrast to penalties under the securities laws.

The ruling struck down a lower court decision that would have allowed investors to go after Wall Street firms that they say engaged in anticompetitive practices by conspiring to drive up prices on about 900 newly issued stocks in the late 1990s.

Because the well-documented implosion of names like Enron Corp. swallowed any serious money that investors might hope to recover from that and other flame-outs, some investors have turned to the banks and other Wall Street regulars such as accounting firms that did work for such companies.

Wall Street institutions in the case before the Supreme Court were Credit Suisse Securities (USA) LLC, formerly Credit Suisse First Boston LLC; Bear, Stearns & Co. Inc.; Citigroup Global Markets Inc.; Comerica Inc.; Deutsche Bank Securities Inc.; Fidelity Distributors Corp.; Fidelity Brokerage Services LLC; Fidelity Investments Institutional Services Co. Inc.; Goldman, Sachs & Co.; The Goldman Sachs Group Inc.; Janus Capital Management LLC; Lehman Brothers Inc.; Merrill Lynch, Pierce, Fenner & Smith Inc.; Morgan Stanley & Co. Inc.; Robertson Stephens Inc.; Van Wagoner Capital Management Inc.; and Van Wagoner Funds, Inc.

These institutions may not have "Anti-Trust" anxiety from the Supreme Court any longer yet there are plenty of other Operational Risks on their minds. Namely International Fraud.

In an era of data warehousing, metadata management, business process management and the looming BASEL II Accord there are plenty of conversations about what to do about fraud and other regulatory compliance. Multi-factor authentication for online banking systems is not a trivial matter when it comes to Enterprise Risk Management. Is the customer service organization ready for the upgrade? Is the consumer going to be confused on what questions they are being asked to get access to their latest online credit card statement? What is my customer "churn" factor? In other words, how many of my customers are jumping ship as a result of the operational risks that have turned their loyalty into consumer driven class action fraud litigation?

An International Banking Fusion Center is on the horizon and it's not too far from the same justification that addresses Know Your Customer (KYC) and the financing of terrorism.

According to one study respondent, "Organizations are secretive of fraud losses and that inhibits our ability to work together."

"The sharing of intelligence is key to being able to take advantage of the predictability of fraud," First Data's Barwell continues. "Banks are sitting on valuable data that, if analyzed innovatively, could provide fraud intelligence worth sharing. One major bank has shown that if their internal client databases across business lines and geographies are analyzed using sophisticated link analysis tools, spurious networks of accounts can be uncovered and, when fully investigated, could uncover organized networks of first-party fraud accounts."

Barwell adds that several U.S. banks have expressed interest in taking the "quantum leap" to true data sharing.

The International Language of Fraud

"In the last eight to 10 years, fraud has really gone international," says Steve Baker, director of the Midwest region of the Federal Trade Commission (FTC). The FTC maintains a Consumer Sentinel database that includes more than 3.5 million consumer fraud complaints and is accessible to more than 3,000 law enforcement agencies internationally. In 2006, 22 percent of the reported fraud was cross border.

So What? What does information sharing have in common with:

International fraud, Identity Theft and the risk of litigation within the banking or credit card industry. Now the bankers want to sue the retailers and recover losses for the lack of privacy and security controls at the retailers. Since December 2006, plaintiffs’ class action firms in California and elsewhere have filed over 200 nationwide class actions in federal court against a broad spectrum of retailers and restaurants alleging violations of the Fair and Accurate Credit Transactions Act ("FACTA"). In addition to California federal courts, FACTA cases have been filed recently in federal courts in Pennsylvania, Illinois, New Jersey, Nevada, Maryland and Kansas.

13 June 2007

ID Theft: The Innocent Insider...

If you were a betting person you might think that the threat of 1 Million Botnets is a greater Operational Risk than a "lone wolf insider". What is the likelihood that one person will impact your business and disrupt your operations vs. the power of thousands of rogue computers unleashing a salvo of malicious code or denial of service attacks on your institution?

A botnet is a collection of compromised computers under the remote command and control of a criminal “botherder.” Most owners of the compromised computers are unknowing and unwitting victims. They have unintentionally allowed unauthorized access and use of their computers as a vehicle to facilitate other crimes, such as identity theft, denial of service attacks, phishing, click fraud, and the mass distribution of spam and spyware. Because of their widely distributed capabilities, botnets are a growing threat to national security, the national information infrastructure, and the economy.

“The majority of victims are not even aware that their computer has been compromised or their personal information exploited,” said FBI Assistant Director for the Cyber Division James Finch. “An attacker gains control by infecting the computer with a virus or other malicious code and the computer continues to operate normally. Citizens can protect themselves from botnets and the associated schemes by practicing strong computer security habits to reduce the risk that your computer will be compromised.”

Yet there are individuals within your own organization who lie in wait, innocently. For the right timing and the right vulnerability to be exploited. They have been unknowingly planning and operating under cover for years and are masters at evading detection. In the Executive Suite, the "Bot" may operate in the background or under the radar of management audits and risk management control mechanisms. So how do you catch them or at least detect their presence? Send everyone on vacation.

When was the last time you had the fraud investigators training the internal auditors? When did you last utilize a "True" Independent outside advisor, investigator or consultant to assist your CISO in early detection. If you have 10,000 employees, 99.x% of these employees are hard working and honest people without any hidden agenda to bring harm to the organization or individuals inside the company. However, not all who would bring harm to you are stealing money or other physical assets from the warehouse. We aren't talking about a few items from the office supplies closet or a case of beer from the 7-11.

We are talking about the one employee who is operating a "Botnet" from behind the walls of your Fortune 50 company. Do you have anyone sharing pictures or music in the executive suite? Without you detecting it.

We define peer-to-peer, bot, and botnet below.

  • peer-to-peer - A peer-to-peer network is a network in which any node in the network can act as both a client and a server.
  • bot - A bot is a program that performs user centric tasks automatically without any interaction from a user.
  • botnet - A botnet is a network of malicious bots that illegally control computing resources.

Some definitions of peer-to-peer networks require no form of centralized coordination. Our definition is more relaxed because the attacker may be interested in hybrid architectures. Our definition of a bot is not inherently malicious. However, the malicious nature of a bot is implicit under some contexts. Finally, we do define a botnet to be malicious in nature.

The case study of the Trojan.Peacomm bot demonstrates one implementation of peer-to-peer functionality used by a botnet. That "Lone Wolf" in your organization could be your innocent administrative secretary and they don't even know it.

10 June 2007

The New New Math: Corporate Responsibility...

The "New New Math" (N2M) is the evolution of economics and return on investment in the modern day organization. Is it a hybrid equation of a previously published and patented algorithm? An upside down or inside out way of justification for new resources or or just new emphasis on the latest shareholder suit. The N2M is something all too often found in the most successful corporations across the globe and it's starting to see the light of day as a result of increasing Operational Risks.

Another way of looking at and understanding the "New New Math" for investment can be found in the roots of what some would say is just good old fashioned Corporate Social Responsibility (CSR):

Corporate Social Responsibility (CSR) is a concept that organizations, especially (but not only) corporations, have an obligation to consider the interests of customers, employees, shareholders, communities, and ecological considerations in all aspects of their operations. This obligation is seen to extend beyond their statutory obligation to comply with legislation.

CSR is closely linked with the principles of Sustainable Development, which argues that enterprises should make decisions based not only on financial factors such as profits or dividends, but also based on the immediate and long-term social and environmental consequences of their activities.


So the N2M on Return on Investment is now being considered across the enterprise and the Board of Directors meetings. ROI discussions are shifting away from the typical GAAP dialogue and more directed at whether new strategic initiatives are "The Right Thing To Do." When you have executives nodding their heads in the meeting about making positive decisions to invest millions of dollars in corporate initiatives based upon it's "The Right Thing To Do" justification, you are experiencing the "New New Math" (N2M)

Making strategic decisions on CSR and N2M is quickly becoming the emotional reasoning and rationale for many corporate enterprise investments. Measuring the ROI doesn't always come in a percentage of dollars invested or a normal way of thinking about getting a return. Many times the executives who champion these initiatives have an underlying reason for doing so that reaches into their personal lives. So when you invest in more robust security for the company or significant programs to increase the protection for key employees, that ultimate driver could be as simple as losing a fellow colleague to kidnapping or the latest law suit.

How your organization is perceived internationally may dictate the degree of risk for your traveling executives. The attack on an employee may be an attack on your "Brand" and what the general public believes that you stand for, in the "minds eye" of the media blur.

Why us?
Where businesses are the target of terrorism, it is usually because of what they represent, rather than anything they do or don’t do themselves. Global brands can assume symbolic significance for terrorists. The US National Counterterrorism Center’s list of significant terrorist events describes 24 attacks on McDonald’s restaurants between 1993 and 2005 worldwide.

Of the minority where responsibility was claimed, motivation for the attacks included nationalism, anti-globalisation, religion and Marxism – but in each case the perpetrators objected to the restaurant as a symbol of America, not a purveyor of products. Mr Jenkins notes that, before 9/11, the two best correlated predictors of whether a US firm would suffer an attack were size and familiarity to the public – corporate behaviour, even philanthropy, was inconsequential. Added to this is the very real possibility of risk displacement: business targets are often easier to hit than government facilities or sites.

Attacks on your organziation or employees don't always have to take a violent twist. Many times these are orchestrated under the cloak of a "personal scandal" or even the filing of a civil Intellectual Property litigation. Legal Risk is a consistent threat to the enterprise and is far often the most effective way of bringing down the house in terms of putting a cloud of uncertainty and speculation about a company that may be in, a competitors "cross hairs."

A week after the public learned of Qualcomm Inc.'s bombshell admission that it withheld potentially thousands of important documents in a high-stakes patent trial against Broadcom Corp., many in the intellectual property community are still buzzing about the gaffe.

The case is even more striking because the attorney who has publicly apologized for Qualcomm's error has a strong reputation in his field, as does his firm. Yet several attorneys say it's still too early to assign blame for the error.

"Whenever there are accusations of concealment of evidence and they prove to be true, there definitely is going to be harm to the lawyers and the parties," said Anup Tikku, an IP associate with Kirkpatrick & Lockhart Preston Gates Ellis, who has followed the case closely. "What I find difficult to understand is how Qualcomm interviewed witnesses, put them on the stand and did not realize these documents existed."

Corporate Social Responsibility extends to Enterprise Litigation Governance and goes well beyond just understanding electronically stored information (ESI). The "New New Math" on doing the right thing in preparation for legal risk are taking on new dimensions as the implications of judgements in favor of the plaintiff set new legal precedence and case law. The Board of Directors and executive management are getting the message that protecting their employees from violence and politically motivated terrorism is just as imperative as preparation for adversarial law suits.

When you hire a defense firm and they get blindsided about eDiscovery or Enterprise Content Management (ECM) and your own Records Management and IT personnel are scratching their heads, your "Brand" is going to take hit. The operational risks associated with a lack of preparedness and a limited strategy for preemptive action calls for the "New New Math." It's coming to a board room near you and when it does, don't be surprised that the investment decisions are based more on emotion than on your controllers 27 pages of hard numbers.

28 May 2007

Memorial Day: The Courage to Serve...

Today is Memorial Day in the United States and Spencer is on his way to Airborne "Jump School" in Ft. Benning, GA as a proud member of the US Army. He gave up going to a nice University of California campus and a few years of fraternity fun to serve his country and took a risk by joining a life long fraternity of men and women who have defended our country. Simultaneously Keith is risking his life serving the US again for the "nth" time in Afghanistan as US Army Lt. Col. (Ret) on another important and vital mission. He gave up a hunting, fishing and teaching lifestyle to help secure certain important real estate utilizing his diplomatic and training skills learned from decades of real-time experience in South East Asia with the Central Intelligence Agency.

Having spent some time with both of these brave and courageous men makes you wonder what they both have in common. What are the attributes of a person who makes a selfless sacrifice to protect and to serve? Whether it's in the military or in public safety, there is something that is in their DNA and not yours. It's something that many of us think about and end up not doing anything about it. When you fill up your gas tank this week or stroll down the outdoor mall you might ask yourself who made all of this possible? The answer is those who have served and those who are serving right now.

Millions across the country will pause Monday afternoon to honor the sacrifices of the American military in observance of the National Moment of Remembrance.

Crowds at Major League baseball stadiums, NASCAR tracks, train stations, malls, stores and even the astronauts aboard the International Space Station will participate in the “National Moment of Remembrance,” which is observed at 3 p.m. every Memorial Day.

"The national Moment of Remembrance is a time for Americans to contemplate those things that bind us together by remembering the legacy of those who died to better our country," Carmella LaSpada, executive director of the White House Commission on Remembrance, said.

"We encourage all Americans, no matter where they are and what they are doing, at 3 p.m. local time on Memorial Day, to stop and give thanks."

The observance is an initiative of the White House Commission on Remembrance, which Congress established in 2000.

The commission encourages Americans to remember the sacrifices of fallen troops and the families they left behind.

So when you return to work tomorrow after your Memorial Day holiday, hopefully you will have had a chance to say a prayer or to at least acknowledge those brave individuals. And it's also a time to evaluate your own work ethic or duty serving as leader of your organization. Are you putting your employees in harms way? What steps or measures are you taking to make sure that they are training and preparing to mitigate operational risks on a daily basis. To have the courage to do the right thing and to keep the organization out of jeopardy. Beware of the cowboy.

From Leadership Lessons of the Navy SEALS


The Cowboy

Neither of us knows if such a thing has ever been tolerated in modern commando teams. Yes, sometimes you need to charge forward. But, there are simply too many potential casualties and too much political currency resting on commando missions to entrust one to a cowboy. Authorization for an operation depends on the accurate calculation of operational risk. This requires an assessment of proven forces ability to perform a task. All this is contrary to the cowboy philosophy of depending on experimentation, pluck, and luck in order to succeed.

"The problem with being a cowboy is that your bosses won't employ you if they can't trust you, and they can't trust you if they don't know what you'll do. And then you're stuck with the reputation." --LT. CMDR. Jon Cannon


Believe it when he says that people who try to be cowboys in your organization are operating without regard to risk. Now multiply the number of cowboys by the number of people that they surround on their team who think that this is the way to operate. It doesn't take long to find out that these are the root causes of many of the operational risks in your organization. And it starts out with the basics:

> Revenue is not booked according to the rules. Products sit in the warehouse yet revenue ends up on the sales reps commission report because (s)he had a signed order.

> Assets are not valued correctly. Bank accounts are not validated to make sure they actually exist and accounts receivables are inflated.
These are just two of the many facets of fraud that starts with a few cowboys who have little regard for managing risk and all the incentives to line their pockets with new found cash or bonuses.

You might think that the reason is greed. However, the real motive may not be so clear. More than likely, the motive is fear. And that fear is something that grows until it gets to the point of creating harm, loss and destruction. You have to find the cowboys in your organization and you have to follow the mantra of quality gurus from years past, "Drive out Fear".

24 May 2007

Hedge Funds: Crystal Ball on Regulation...

Looking into the crystal ball for the future regulation of hedge funds is a cloudy subject and the feds are making statements that would alarm any high net worth investor. So what are the issues with asking for some additional transparency and reporting mechanisms for the 1% who choose to diversify their portfolios?

Why is regulation inevitable? There are a number of factors, including:

  • Industry growth and the increasing influence of hedge funds in the capital markets.
  • The absence of genuine regulatory oversight.
  • The changed political landscape.
  • Increased participation by public pension funds and corporate pension plans.
  • Continuing instances of fraud and blow-ups.
  • The lack of transparency.
  • Increasing complexity and concerns of systemic risk.

All of these factors, taken together, have created an environment that is ripe for regulatory oversight. Of course, this does not mean that hedge funds should be regulated. Indeed, there are good arguments that hedge fund regulation is not necessary, and may even be imprudent. Opponents of regulation have argued persuasively that, among other things, hedge funds provide benefits, such as market liquidity, and that regulation will simply drive hedge funds offshore.

As the financial wizards of the global markets figure out ways to keep regulators from asking too many questions the leadership of the companies operating in the hedge fund environment are getting prepared. They are strategically implementing the mechanisms and the controls that any prudent investment management company have in place to deal with the operational risks associated with other main stream institutions in the sector.

So what is on the mind of the SEC and others who oversee the implications of hedge funds that are not being so proactive:

The hedge fund industry, long a Wall Street innovator, has frequently created exotic money-making strategies that have then ballooned in popularity.

But as Neil Brown, director of AIMA and managing director of New York-based Citigroup Alternative Investments, noted, when a profitable arbitrage trade is uncovered, managers then pile onto the trade, and the opportunity to make money gets "arbed away."

This summer's meltdown in convertible bond hedge funds proved a wrenching case in point. Convertible arbitrage managers buy convertible bonds, which are bonds that can be exchanged for a certain amount of a company's common stock, and short the underlying stock of the issuing company to profit from the difference in price between the two securities.

Long considered a safe haven, the strategy posted big losses this year, which forced three big convertible bond hedge funds to close: San Francisco-based Marin Capital Partners, which had $2.2 billion in assets at its peak; Alta Partners, run by San Francisco-based Creedon Keller & Partners, which had about $1.2 billion at its peak; and Minnesota-based EBF & Associates' $669 million Lakeshore International Fund.

Now, hedge funds are coming up with new, more exotic strategies as traditional strategies, such as certain kinds of arbitrage, get overcrowded.

So what? The fact that the markets will regulate itself is a valid point being made around many dinner tables in London, New York City and Shanghai as hedge funds managers can feel the trend of fraud driven regulators breathing down their necks:

Shanghai is setting up a financial task force to counter a rise in cases of fraud and other abuses linked to soaring stock prices, state media reported Tuesday.

The task force, including staff from the securities and banking watchdogs, police and other government agencies, will focus both on combatting illegal share dealings in companies not listed on the bourse and also on the practice of diverting public funds into high-risk investments, the state-run newspaper Shanghai Daily reported.

"Risks are accumulating and we should be well aware of illegal financial activities and make it a priority of our work to clamp down on them," it quoted Feng Guoqin, a Shanghai vice mayor in charge of the task force, as saying.

So why are hedge funds any different than any other alternative investment? The myths are there and they need to be addressed:

MYTH #14: HEDGE FUNDS ARE NOT REGULATED
Hedge funds often are said to be unregulated or lightly regulated. The perception is that hedge funds are cowboys taking advantage of the wild-west financial markets without a sheriff in town.

EVIDENCE:
Hedge funds are required to comply with every rule, regulation, and law that affects virtually all investors in the public and private financial markets. Further, hedge funds are subjected to a variety of investor-related laws and regulations that impact who can qualify to invest with hedge funds. Additionally, there are a variety of state and federal laws that can require some managers to register as investment advisors—thereby invoking a series of additional regulations and requirements, including periodic regulatory examinations and filings. When the topic of regulation arises in the hedge fund industry, managers are far from being cavalier about the existing and continually proposed regulatory requirements.

19 May 2007

Cyber Terrorism: Attack on a Nations State...

The attack on the Critical Infrastructure of the nation state of Estonia over the past few weeks should be a wake-up call to governments across the globe. The facts are coming out in the mainstream media this week about the origins of the attack and the magnitude of the event. Yet the real lesson to be learned here goes deep into the chasm of having "Cried Wolf" too many times and the resulting ignorance of a major threat in the making.

Young men paying cash to learn how to fly large Boeing airliners and not worried about landings. Does this ring a bell?

Peter Finn of the Washington Post Foreign News Service has identified much of the real issue at stake here:

This small Baltic country, one of the most wired societies in Europe, has been subject in recent weeks to massive and coordinated cyber attacks on Web sites of the government, banks, telecommunications companies, Internet service providers and news organizations, according to Estonian and foreign officials here.

Computer security specialists here call it an unprecedented assault on the public and private electronic infrastructure of a state. They say it is originating in Russia, which is angry over Estonia's recent relocation of a Soviet war memorial. Russian officials deny any government involvement.


How many more of these "Botnet" attacks will be necessary for the public, the media and the government to realize that this is the beginning of a new generation of warfare that will be fought using "Zeros and Ones" as increasing effective ammunition against your enemy. Whether it be a nation state or your business competitor, large Distributed Denial of Service (DDOS) attacks can be rented on the Internet by the hour. So how big a network of "Bots" is necessary to disrupt a nation state like Estonia?

Roughly 1 million unwitting computers worldwide were employed, said Jaak Aaviksoo, Estonia's minister of defense. Officials said they traced bots to the United States, China, Vietnam, Egypt and Peru. By May 1, Estonian Internet service providers were forced to disconnect all customers for 20 seconds to reboot their networks.

Disruptions of all kinds are giving Chief Security Officers (CSO) head aches and heart attacks as the economic impact of spoof e-mail and DDOS attacks wreak havoc beyond the network to the financial markets. The attacks could be the work of competitors or more likely the coordinated, well planned and funded mission of a worthy criminal or terrorist adversary:

Apple (Quote) shares dropped 3 percent to $104.63 in afternoon trading as ultimately false rumors of iPhone and Mac OS X Leopard delays spread across the Internet.

The plummet started when technology news blog Engadget.com reported Apple pushed iPhone's launch from June to October and Mac OS X Leopard from October to January. Ryan Block, the post's author, cited an "authority" for a source.

It turns out that "authority" was a forged e-mail sent to thousands of Apple employees at 9:09 a.m. this morning. It was eventually leaked to Block who posted at 11:49.


What impact does the media and information leaks have on the market value of your company? How do you as a CSO, CEO or Chief Risk Officer mitigate the risk of this kind of "Social Engineering" ploy to manipulate your stock price? The answer is not more software or some kind of fancy new device for analyzing network traffic.

The answer is education and enhanced monitoring of information. It's also making sure that your institution has prepared for and tested the resiliency of the organization for such a scenario. The Department of Homeland Security has been exercising for major incidents of the magnitude described against Estonia for years. The next event is scheduled for the spring of 2008 and is know as CyberStorm II. In this exercise the scenario will involve both physical disruption and the digital origin of vulnerability exploits. The lessons learned will be a public and private partnership discussion for years to come.

The Case Studies of the Estonia attack and the Apple spoof are being written as we speak and the output is what any CSO should be seeking. Increased awareness and education of it's employees, customers and suppliers. Without effective learning, the resiliency of the enterprise is in jeopardy.


16 May 2007

Defensible Standard of Care: Legal Risk...

A "Defensible Standard of Care" is a hot topic these days around the Board of Directors Audit Committee conference table. Information Security standards are consistently being discussed by the CIO and CSO in the context of compliance. So where is the nexus? Why is it so critical to enabling the enterprise business resilience of a global institution?

The answers lie in the fundamental understanding that the Board of Directors and the "C" Suite are both working towards the same focal point. Their motive is almost identical. To be able to provide the evidence and the testimony that keeps their integrity and reputation intact. To understand this nexus, first we must provide the definitions:


What is ISO/IEC 27001:2005?

ISO/IEC 27001:2005 is a standard setting out the requirements for an Information Security Management System. It helps identify, manage and minimize the range of threats to which information is regularly subjected.

ISO/IEC 27001:2005 covers the following topics:

  • Security policy - This provides management direction and support for information security
  • Organization of assets and resources - To help you manage information security within the organization
  • Asset classification and control - To help you identify your assets and appropriately protect them
  • Personnel security - To reduce the risks of human error, theft, fraud or misuse of facilities
  • Physical and environmental security - To prevent unauthorized access, damage and interference to business premises and information
  • Communications and operations management - To ensure the correct and secure operation of information processing facilities
  • Access control - To control access to information
  • Systems development and maintenance - To ensure that security is built into information systems
  • Business continuity management - To counteract interruptions to business activities and to protect critical business processes from the effects of major failures or disasters
  • Compliance - To avoid breaches of any criminal and civil law, statutory, regulatory or contractual obligations, and any security requirement

ISO/IEC 27001:2005 is the updated version of the world renowned British Standard for Information Security Management Systems, BS 7799-2:2002.

This Information Security Management System (ISMS) is simply that, a published set of guidelines and controls. Useless without the support of the correct tools, methodologies and people to make it come alive and incorporated into the culture of the organization. This requires an adaptive and resilient framework for managing change.

A "Defensible Standard of Care" comes alive within this ISO 27001 standard:

Clause A.15.1 Compliance with legal requirements

Objective: To avoid breaches of any law, statutory, regulatory or contractual obligations, and of any security requirements.

Clause A.15.1.3 Protection of organizational records

Control
Important records shall be protected from loss, destruction and falsification, in accordance with statutory, regulatory, contractual, and business requirements.

In the United States, as well as many other countries, a party involved in civil litigation is responsible for preserving any potentially relevant evidence, including materials that may lead to the discovery and production of other relevant evidence, beginning when the party knew a lawsuit had been filed, or had a reasonable basis to believe that litigation would occur.

Effective December 1, 2006, the United States Federal courts adopted revised Rules of Civil Procedure that confirm the importance and admissibility of Electronically Stored Information (ESI) as evidence in civil litigation. As lawyers and the courts begin to operate under the new Rules, company officers responsible for demonstrating the reliability of their corporate electronic records are rapidly moving into the “firing zone”.

The reason is entirely adversarial: if a hostile lawyer can discover uncontrolled risks that compromise the reliability or integrity of a company’s electronic records, then the value of those records as evidence declines and the potential for how the case will be resolved, whether in the courtroom or through settlement, is altered. In response, a company must be prepared to demonstrate their ESI has been managed pursuant to a defensible standard of care.

As a result, adherence to Clause A.15.1.3 includes protecting records that become important to litigation and assuring their continued integrity and availability. For these purposes, information security practices are indispensable, and the failure to apply and extend those practices to relevant evidential materials can create a material risk for many companies.

And this risk extends well beyond the inner sanctum of the legal department, internal audit and information technology. This risk reaches into the outside counsel the company has retained for defense litigation. How many law firms are under retainer at your institution? Do they have an effective set of standards, methodologies and programs to handle your next ESI request? In the game of litigation only the most agile and preemptive strategies will prevail.

So how do you understand and determine how adept your outside counsel is when it comes to ESI and eDiscovery? Now it's time for your own investigation, audit and request for information. You have to develop the same kind of process for evaluation of outside legal counsel as you do for the next set of financial auditors or outsourced disaster recovery vendor. It's imperative that you look at enterprise content management and the records administration controls within your Information Security and Operational Risk Management framework to see how it supports a Defensible Standard of Care. The Nexus of Information Security and The Law. Here are 8 Survival Strategies courtesy of Jeffrey Ritter at Waters Edge Consulting:

  • Start a Dialogue.
  • Be Prepared to Bear Witness.
  • Be Prepared to Preserve.
  • Define "Not Reasonably Accessible".
  • Demonstrate "Routine Good Faith Operation".
  • Prepare to Deal with eDiscovery vendors.
  • Prepare your lawyers "In and Out".
  • Protect your records at the Law Firms.
Institutions wishing to achieve a defensible standard of care for protecting business sensitive data such as intellectual property, financial records, customer data and business records will find the Waters Edge Protocol a welcome advantage in streamlining the effort required to tailor requirements, policy, processes, and implementation plans to meet their business needs.

10 May 2007

IT Audit: Communicating with the CEO...

In the latest issue of ITAudit, Jackie Bassett is right on target. She has clearly identified the items necessary to close the gap of communicating to top management before, during and after an Information Technology Audit. A key component of any prudent Operational Risk Management Program:

At its most basic level, an IT security audit is a systematic evaluation of a company's IT security infrastructure that measures how well security policies, procedures, and controls conform to a set of established criteria. Today's internal auditors know that the true value of an IT security audit to an organization goes beyond compliance. By successfully communicating their IT security audit recommendations, auditors can have a major influence on corporate strategy. Unfortunately, many auditors find there is little guidance to help them communicate audit results and recommendations to senior-level managers when preparing for the IT security audit. Consequently, conveying IT security recommendations can be one of the most challenging parts of an internal auditor's job. However, with a little preparation and knowledge, auditors can enhance the way they communicate IT security audit results as well as provide recommendations senior managers can relate to, understand, and implement.

What can the board of directors do to make sure that their CEO has moved to a place focused on mitigating operational risks to enhance opportunities and long term strategy?

Fundamentally, the first task is to make sure that the CEO has a management system in place for operational risk. What is needed is a process approach for establishing, implementing, operating, monitoring, maintaining and improving the effectiveness of an organisation’s operational risk enterprise architecture (OREA).

Let’s break OREA down this a little further to get a better view of some of the specific operational attributes:

People
Employee fraud, misdeed, unauthorised activity, loss/lack of personnel and employment law.

Process
Payment/settlement, delivery/selling, documentation/contract, valuation/pricing, internal/external reporting and compliance.

Systems
Technology investment, development, access, capacity, failures and security breach.

External
Legal liability, criminal activities, outsourcing, suppliers / insourcing, disasters / infrastructure, regulatory/political.

The attributes of operational risk are the same key areas that need to have metrics created for measurement and auditing. Performance management, Balanced Scorecard and other methodologies for managing, monitoring and continuous improvement need to be implemented so the boards of directors have a way to get timely alerts, updates and reporting.

The operational risk enterprise architecture (OREA) is a management framework that requires a process approach embedded with the legacy of our quality initiatives of the past several decades. The reason is because of the threat of change itself. The P-D-C-A model (plan – do – check – act) is appropriate for application to this process approach and threat of a constantly changing corporate environment:

Plan
Establish policy, objectives, targets, processes and procedures for managing operational risks to deliver results in accordance with the organisations business objectives.

Do
Implement and operate the policy, controls, processes and procedures.

Check
Assess and measure in applicable areas while reporting results to management for review.

Act
Take corrective and preventive actions based on results to continually improve the OREA framework.

Operational risk management is getting the attention of organizations outside of the major banks at a rapid pace. Board of directors in any industry will soon realize that the successful CEO of the future will be a master of building a culture with effective operational risk management systems at its core.

Furthermore, interpreting how enforcement of IT security controls and policies can strengthen connections with customers and suppliers, how authorization processes can preserve intellectual property, or how separation of duties can drive innovative new business processes demonstrates to senior managers that internal auditors are an invaluable company resource and asset.