19 October 2010

OPS Risk: Diversifying Systems Portfolio...

What kind of testing, experiments and operational risk projects are your organization running simultaneously right now? As an example, do you have an OPS Risk project where a business unit has moved entirely to using "Google Apps" for their entire computing utility platform? Migrated the e-mail system to Gmail, eliminated the use of Microsoft Office Suite and Outlook for the purpose of increasing your understanding of the benefits, vulnerabilities or other metrics. If you have not, the question is why not?

We recommend you do this now. Move an entire business unit, such as the crisis management team or operational risk management department to jump off the "Microsoft Mother Ship" and develop several metrics categories. Buy everyone a Blackberry or Android based smart phone and couple this with an Android-based Tablet PC or soon to the market the Blackberry Playbook. Enable a domain for use by the team for all participants to get on Google Apps and keep the team dedicated to being enterprise connected, yet possibly more resilient to any major internal business disruption.

You must establish metrics beyond the technology and app compatibility and focus in on productivity, accessibility and any failures in the systems themselves. Once you have untethered your team from the Microsoft-centric platforms in the enterprise and now are living in the virtual cloud or outsourced world of using Google Apps or other SaaS or IaaS-based solutions, the testing is only beginning.

The behaviors that your employees now take upon themselves to work within this new set of tools, devices and services may very well pave the way for the organization to be more resistant to several corporate plagues. Besides the normal scourge of Microsoft related exploits by Malware and Trojan horses it would be interesting to measure how people actually feel. Do they feel or have an attitude of being more productive or less? Are the new behaviors that they are experimenting with doing their work giving them more insight, increased speed to answers or greater reach into the information they need to make important decisions?

And even if this team was finding that there were missing capabilities from their Microsoft Exchange and Outlook apps, you could still migrate them to a hosted solution outside your own enterprise. This outsourced yet hosted somewhere else Microsoft-based platform could be the answer where you have teams that must be using a Microsoft-based OS desktop, tethered to a Microsoft-based enterprise app. There are even now governments making the case for the exodus to Google Apps:

The debate continues about whether cloud computing and hosted services put sensitive data at risk or actually realize the cost savings that are promised. Some local governments have determined that the return on investment for moving to cloud-based services isn’t sufficient yet to justify moving in that direction. But the concern isn’t universal. Orlando, Fla.; Washington, D.C.; and some departments in New Mexico and Colorado have already migrated to Google Apps.

This year, Google even launched a version of its productivity suite tailored for government customers that meets federal IT security benchmarks. According to the company, Apps for Government is the first cloud computing suite to receive Federal Information Security Management Act-moderate accreditation, designed to standardize IT security across the government and relieve concerns about perceived security risks.

“By the end of the migration, most customers are convinced that data would be safer in Google data centers,” Cohn said.

Not all governments believe in cloud computing as the smart solution. Some local governments don’t see the cost benefits in migrating unless it’s a last resort. Some observers believe that was the case in L.A.

Last year, the city decided to implement Gmail on more than 30,000 desktops and adopt the suite. The five-year deal made L.A. the first government of its scale to choose Gmail for the enterprise.

Whether you are the City of Los Angeles, Washington, D.C. or other smaller jurisdictions, you can start to see that the momentum is starting to take effect. So the Operational Risk Management team at your organization might be on to something as they break away from the corporate Mother Ship, to test and try the resiliency and the productivity of another platform outside the Microsoft Suite.

As you begin to explore the number of new apps that are working on the integration with Google you start to see other places that maybe, you can eliminate Microsoft Excel, Word and Project Management:

The Google Apps Marketplace offers products and services designed for Google users, including installable apps that integrate directly with Google Apps. Installable apps are easy to use because they include single sign-on, Google's universal navigation, and some even include features that integrate with your domain's data.

Operational Risk Management is about testing and experimenting to find the vulnerabilities in your current environment. It's about establishing teams with new and different ways to running their day to day business in order to increase the resilience of certain core capabilities within the enterprise. Have you ever had a financial planner say, "You need to diversify your portfolio."? Let's just hope you listened to this piece of wise advice these past two years...

04 October 2010

Stuxnet: Digital Sabotage of Critical Infrastructure...

The Chief Information Security Officer's (CISO) are getting significant new understanding of the new threat emerging in the digital domains. The Energy, Chemical, Water, Transportation and other Critical Infrastructure sectors are on high alert. The Operational Risks associated with their Programmable Logic Controller (PLC) systems using Siemens technologies are being attacked. Stuxnet is a new worm that has emerged over the past few months and is being analyzed from several vectors. One analysis that is forthcoming is who developed this new sophisticated industrial sabotage cyber weapon? Let's consider this logic from Ralph Langner:

Many aspects of Stuxnet are so completely different from malware as we know it that it's only natural that so many hard-working experts at some point in the analysis ended in frustration. The best way to approach Stuxnet is not to think of it as a piece of malware like Sasser or Zotob, but to think of it as part of an operation -- operation myrtus. Operation myrtus can be broken down into three major stages: Preparation, infiltration, and execution.
Stage 1, preparation:
- Assemble team, consisting of multiple units (intel, covert ops, exploit writers, process engineers, control system engineers, product specialists, military liaison)
- Assemble development & test lab, including process model
- Do intel on target specifics, including identification of key people for initial infiltration
- Steal digital certificates

Stage 2, infiltration:
- Initial infiltration using USB sticks, perhaps using contractor's comprised web presence
- Weapon spreads locally via USB stick sharing, shared folders, printer spoolers
- Contact to command & control servers for updates, and for evidence of compromise
- Update local peers by using embedded peer-to-peer networking
- shut down CC servers

Stage 3, execution:
- Check controller configuration
- Identify individual target controllers
- Load rogue ladder logic
- Hide rogue ladder logic from control system engineers
- Check PROCESS condition
- Activate attack sequence

For the CISO and executives who are sitting around the latest emergency CISCO Telepresence call at companies such as Entergy, American Electric Power, Dominion Resources and dozens of others in the power grid industry; the reliability factor is uncertain.

If this new malware had an initial project budget cost of seven figures $,$$$,$$$.00 to achieve the three stages described previously, preparation, infiltration, and execution then the price will soon be more affordable. A price for a malware exploit kit such as this one as it is reengineered for other purposes or types of targets will decrease dramatically as it propagates across the Internet.

The significance of the decrease in price is that now it will be more affordable for the transnational economic crime syndicates. How they will utilize the new Stuxnet capability in their toolkit for cyber extortion, digital sabotage and other schemes remains to be seen. What is certain is that it will not be long before this becomes a reality. Gary McGraw comments further:

Stuxnet is a fascinating study in the future of malware. Not only did it reveal at least 4 0days (which are still being patched by Microsoft), it clearly demonstrated that physical process control systems of the sort that control power plants and safety-critical industrial processes are ripe for compromise.

Now that the genie is out of the bottle, it is hardly possible to stuff it back in. Expect the techniques and concepts seen in Stuxnet to be copied. Attacks on process control systems are no longer the fantasies of paranoids in tinfoil hats — they are here.


The next Operational Risk that will be on the horizon are the plaintiff law suits, each time we have an event like this one:


Pacific Gas and Electric Co. on Monday announced it would put as much as $100 million towards rebuilding areas of the Crestmoor neighborhood destroyed in the flames. PG&E president Chris Johns maintained that money in that relief fund would be spent on reconstructing the San Bruno neighborhood, not paying off potential legal claims. Nonetheless, the utility company reportedly already cut the city a $3 million check to cover expenses associated with responding to the disaster. PG&E is also expected to pay victims whose homes were destroyed up to $50,000 to help pay for their everyday necessities. “I realize money can’t return lives. It can’t heal scars, it can’t replace memories… But there does come a time for healing and for rebuilding, and we are committed to helping that happen,” Johns added.

A full probe would be required to determine what might have caused the 30-inch high-pressure gas pipeline to burst at Earl Avenue and Glenview Drive around 6:15 p.m. that Thursday evening. Thirty-seven homes were apparently leveled in the blast. A 30-foot-wide crater could also be seen in the aftermath of the explosion. Authorities evacuated over 100 people in the area immediately after the blast. Now the California Public Utilities Commission has ordered PG&E to check all high-pressure gas lines located in densely populated areas. The National Transportation Safety Board (NTSB) is leading the investigation into the fatal San Bruno natural gas explosion.


It is too early to determine the exact nature of the cause of the San Bruno, CA disaster yet the corporate general counsel's of major utilities are preparing for their defense. The legal risks could go well beyond the exact scene of the explosion. Why? As the plaintiffs examine the number of PLC and SCADA controllers involved in the area of the incident, you can be certain they will be looking at the software systems associated with them. They will be requesting the Information Technology organization at PG&E to produce evidence of their policies, procedures, and best practices as it pertains to SCADA exploits such as the Stuxnet worm.

Managing the Operational Risks associated with the Energy and Chemical "Critical Infrastructure" sectors goes well beyond the norm of security and safety. Even BP has established a new Operational Risk initiative in the aftermath of their Gulf of Mexico catastrophe.

BP is to create a new safety division with sweeping powers to oversee and audit the company’s operations around the world.

The Safety & Operational Risk function will have authority to intervene in all aspects of BP’s technical activities.

It will have its own expert staff embedded in BP’s operating units, including exploration projects and refineries. It will be responsible for ensuring that all operations are carried out to common standards, and for auditing compliance with those standards.

The powerful new organisation is designed to strengthen safety and risk management across the BP group. It will be headed by Mark Bly and report directly to incoming chief executive Bob Dudley.

The company said the decision to establish the new function follows the Deepwater Horizon accident in the Gulf of Mexico and BP’s investigation into the disaster. It is one of a number of major changes announced by Dudley as he prepares to take over his new role on October 1.

Who will be in charge of the "Stuxnet Task Force" ?

18 September 2010

China Syndrome: FCPA & Rating Agencies...

A modern day "Operational Risk China Syndrome" is making the Board of Directors nervous these days. The new syndrome otherwise called the Foreign Corrupt Practices Act (FCPA) has been the buzz at rating agencies for months. Are you sure about your ability to withstand the scrutiny of a FCPA litmus test? Board Member Magazine explains:

On June 2nd, Fitch Ratings agency announced that Foreign Corrupt Practices Act violations could result in ratings downgrades. That’s one more reason boards should educate themselves on FCPA and how their companies are monitoring FCPA-related risks. It appears, though, that many boards do not feel comfortable with their companies’ compliance programs. In a soon-to-be released survey from KPMG’s Audit Committee Institute, only 27 percent of U.S. audit committee members said they were satisfied that their company had an effective process to manage Foreign Corrupt Practices Act risks, and other risks associated with doing business in Brazil, Russia, India, China and other emerging markets. 35 percent of respondents were only somewhat satisfied, and 9 percent said process improvements were needed in conducting such business, which may include sourcing, outsourcing, manufacturing, or sales and distribution channels.

As your Business Development teams fan out across the globe to satisfy the appetite of the Chinese economy for critical infrastructure, establish a sound and effective awareness, training and audit program. What are the ramifications of putting unprepared personnel on the ground to do business in the Chinese Markets?

American companies or individuals who enter joint ventures with foreign partners, as well as those who hire foreign agents or distributors in China, must be extremely cautious of the vicarious liability that they may face as a result of a third party's violation of the principles set forth in the FCPA. According to the Justice Department, an American company will be subject to liability under the FCPA if it makes payments to an intermediary third party with the knowledge that such payments will go to a foreign official for corrupt purposes. Conscious disregard is enough to satisfy the requirement; if the American company is aware of a "high probability" that such payments will occur, the knowledge requirement will be satisfied. More importantly, a joint venture partner, agent, or distributor will be considered an intermediary third party for purposes of the FCPA. Therefore, any violation of FCPA standards by one of those parties could result in the American company being vicariously liable under the FCPA.

In order for the Board of Directors to have peace of mind on the emerging markets business opportunities first a substantial compliance framework needs to be established. Next, the implementation of predictive analytics software to manage the complexity of companies, people and relationships as you do business in any of these countries. This includes the subscription to several databases that include the constantly changing landscape of specially designated nationals (SDN) and politically exposed persons (PEP). World check explains:

During the period 2005 to 2007 alone, more than 310 elections and by-elections took place around the world – that’s an average of nearly 10 elections per month. (Source: ElectionGuide.org). This means that your existing clients may be elected to public office, and hence become PEPs, without your business knowing it. It may be that you only apply your due diligence processes to new customers and so miss a whole category of individuals that do not meet your corporate risk appetite. As such, routine and ongoing PEP risk screening is not only considered best practice, but is also a legal requirement.
In practice, full compliance with PEP legislation has not come without major operational challenges. In the post-9/11 era, the proliferation of regulatory compliance laws, combined with the need to screen hundreds of thousands of users and accounts on a routine basis, has created a substantial administrative burden for businesses subject to PEP legislation.

The sheer magnitude of the due diligence challenge has subsequently led to the adoption of a risk-based approach to regulatory compliance, but nevertheless Enhanced Due Diligence and ongoing risk management is still required for PEPs. Broadly speaking, the risk-based approach entails the identification of risks that exceed your business’ stated risk appetite (including the need for regulatory compliance), and then matching individuals and entities against these heightened risks during the preliminary stages of due diligence. Should a person fall into one or more of the specified heightened risk categories, additional due diligence is then required.

As your company establishes it new China-based strategy for partnerships, joint ventures or actually putting employees in country the operational risks become exponential. Remember, a sound and prudent risk framework includes a 4D approach:

  • Deter
  • Detect
  • Defend
  • Document

With these established and operating on a global basis the Board of Directors will be sleeping more soundly. Or perhaps not...learn more.

11 September 2010

Remembering 9/11: Teaching the Children...

Where were you on September 11th, 2001? Everyone seems to remember...

On a cool sky blue morning, 9 years ago in Northern Virginia, sitting in a hotel restaurant having breakfast around 8:00AM with a business colleague. A little over 40 minutes into our discussion, we heard some people talking quite loud in the bar next to us as they tuned into CNN. As cell phones rang around us, they were all loved ones checking in and urging us to hurry home.


8:46:40: Flight 11 crashes at roughly 490 mph (790km/h or 219m/s or 425 knots) into the north face of the North Tower (1 WTC) of the World Trade Center, between floors 93 and 99. (Many early accounts gave times between 8:45 and 8:50). The aircraft enters the tower mostly intact. It plows to the building core, severing all three gypsum-encased stairwells, dragging combustibles with it. A massive shock wave travels down to the ground and up again. The combustibles and the remnants of the aircraft are ignited by the burning fuel. As the building lacks a traditional full cage frame and depends almost entirely on the strength of a narrow structural core running up the center, fire at the center of the impact zone is in a position to compromise the integrity of all internal columns. People below the severed stairwells start to evacuate—no one above the impact zone is able to do so.

8:49:34: The first network television and radio reports of an explosion or incident at the World Trade Center. CNN breaks into a Ditech commercial at 8:49. The CNN screen subtitle first reads "World Trade Center disaster." Carol Lin, the first TV network anchor to break the news of the attacks, says:

"This just in. You are looking at obviously a very disturbing live shot there. That is the World Trade Center, and we have unconfirmed reports this morning that a plane has crashed into one of the towers of the World Trade Center. CNN Center right now is just beginning to work on this story, obviously calling our sources and trying to figure out exactly what happened, but clearly something relatively devastating happening this morning there on the south end of the island of Manhattan. That is once again, a picture of one of the towers of the World Trade Center."


Walking to the parking lot, the proximity of the kids high school and middle school to the CIA created a feeling of great internal anxiety and it soon turned to fear.

9:37:46: Flight 77 crashes into the western side of the Pentagon and starts a violent fire. The section of the Pentagon hit consists mainly of newly renovated, unoccupied offices. All 64 people on board are killed, as are 125 Pentagon personnel.

Looking around the crowd this evening at our 9/11 Memorial Ceremony in our little village, some of the kids were not old enough to remember that day. We said prayers and recited the names of the six men and women who were from our little town. "Friends of the Freedom Memorial" formed in 2002 to build the site and dedicated to the residents who have given their lives for our freedom.

The Boy Scouts handed out programs and lead us in the Pledge of Allegiance. We sang the National Anthem. "America the Beautiful". We starred at the six candles lit in their honor.

What this day is about every year beyond these memories, is the renewed vow of vigilance. A time to revisit all the reasons why you have made the decisions you have since that Tuesday morning nine years ago. Never forget that day. Never forget why you wake each morning.

9/11 vigilance is about being adaptive. It is about resilience. For those of us who have never paid the same price as those who have served, supported and are the mothers, fathers, brothers, sisters or relatives of those who have, we can never know or really feel what they have. We can only pledge our vigilance in continuing our respective missions.

Most of all. The mission is not America's alone and the entire planet understands this. As they teach the history of 9/11 in the schools of New York City, Haiti, Chile, Pakistan, India and even Saudi Arabia, what do you think the lesson is about? If it is not about vigilance and resilience, then we are doing our children a disservice. We must be preparing them for the future threats that this globe will be facing in the years and decades before us.

Whether it is the wrath of "Mother Nature" or the evil planning of ordinary people does not matter. We can never predict exactly the day the hour or when and where the next attack will occur. Whether it will impact our buildings, bridges, rivers, schools or the Internet is unknown. If all of us on this 3rd rock from the sun, have done our job teaching our kids about vigilance and resilience, then we should all be able to have a peaceful nights sleep. Devoid of nightmares.

Remember that Tuesday in September across the globe for the lessons we have all learned since that infamous day in New York City, Washington, DC and Shanksville, Pennsylvania. For the children, teach them the truth.

06 September 2010

Protective Security: Discovery Lessons Learned...

Operational Risks at Discovery Communications are on the agenda for the next Board of Directors Meeting. The lessons learned are being discussed and there are many legal considerations after a gun man strapped with explosive devices held hostages in the lobby of the Silver Spring, Maryland company on September 1, 2010.

A security guard who called 911 after a gunman entered Discovery Channel's headquarters calmly told the operator: "You're probably going to need a sniper."

The call, released Friday, was one of several placed minutes after a gunman entered the lobby and took three hostages. Other callers described the propane tanks strapped to the gunman's body, and a blinking device in his left hand.

After hours of negotiating with James Lee, 43, police shot him to death as the hostages were preparing to make a break for it, police said.

Even in the first minutes after the siege began, Discovery security had an idea of who they were dealing with. A security employee told a 911 operator that they believed the man was in the lobby was Lee. He told the operator Lee appeared disoriented, had propane tanks strapped to his chest and at least one person on the ground.

"It looks like he's got an IED. He looks like he's setting up an explosive device in the lobby, you're probably going to need a sniper," he tells the operator. "You gotta move fast."

In police radio transmissions, an officer described the suspect as an "Asian male following the do-not-admit sign Discovery has."

Since the attack on the Holocaust Museum in Washington, DC where another lone gun man walked into the lobby with a rifle there has been hours and hours of debriefing. There has been presentations on the protective security measures that worked. There are lessons learned on those measures and policies that failed. Yet one thing is certain in both of these incidents. The protective security strategy for an active shooter scenario is still up for debate.

The Holocaust Museum and Discovery Communications have differing philosophies about the design of a layered defense as it pertains to this type of threat. Discovery did not have protective security that was able to disarm and prevent Mr. Lee from entering their facility and taking hostages.

This blog has discussed the vulnerability that exists in every facility or digital network in terms of how attackers will exploit the vulnerability of Design, Implementation or Configuration. It is obvious in the case of Discovery that the attacker had done his homework and knew in advance that they do not have "Armed Guards" in the lobby. The larger lesson to both Discovery and to others is not so much about the decision of "Armed" vs. "Unarmed", as much as it might be on how and where visitors are allowed to access the building itself. The design of the Discovery Protective Security Process and design of the facility is a major Operational Risk.

Perhaps this message also needs to be sent to the commercial architects and the developers of buildings about why it is important to design protective security measures into the physical engineering of the facility to begin with. Making decisions about whether to arm your guard force with weapons however may not even need to be discussed, if the process and design of your building security is done correctly.

  • First, the visitors entrance and lobby area shall not be the same for employees. Ideally, the employees enter the building from the parking garage directly, that is also secured. Or even a secure side entrance if they commute to work. It is never good design to have employees entering in the same space with visitors.
  • Second, design the building so that the visitors entrance is set back a minimum of 75 yards from the main facility, detached or connected only through a covered walkway or enclosed hallway. Ideally, the visitor screening and registration all occurs in this detached building with the first layer of the protective security team.
  • Third, once visitors are screened and given the green light, they may proceed to the secondary waiting lobby in the main facility. This again, is a holding area until the visitor is greeted and escorted into the building with the company employee.

As good as the Discovery guards were at describing the situation unfolding before them, the fact remains that the attacker should never had the opportunity to take any hostages. The Board of Directors may be taking into consideration many new ideas and digesting the lessons learned from Corporate Security. One can only wonder if they will increase the budget to be commensurate with the threat before them. The legal teams will be gearing up for a number of attempts to use this event as a platform for adversarial plaintiff suits.

Domestic Extremism is not just about a lone wolf who has a history of psychological issues. Violent activist groups who are active in the international movement to use animals, "The Earth" or other religious causes to fuel their justification are a growing threat, here and abroad.

Until last month, the small market town of Langnau in the rolling Swiss hills had two claims to fame: it was a centre for the production of Emmental cheese and one of the sunniest places in Switzerland.

Now, thanks to a routine police traffic inquiry, it has the dubious honour of being the location where one of Europe's biggest alleged acts of eco-terrorism was foiled.

On the night of April 15, 2010, local officers pulled over a car on one of the town's quiet streets.

Inside the vehicle they found a large cache of explosives, primed and ready to detonate.

The three people in the car are alleged to have been members of the murky Italian anarchist group Il Silvestre, who were reportedly on a mission to blow up the unfinished £55 million ($118 million) IBM nanotechnology facility.

The apparent attack is believed to be part of a new co-ordinated wave of eco-terror on the continent.

The IBM site is due to be opened next year and will be the most advanced centre for nanotech and biological scientific research in Europe. The group, formed in Tuscany, is considered by some to be one of the rising "eco-terror" groups in Europe, with a rigid cell structure, access to explosives, and a membership that supposedly has no qualms about killing to achieve its goals.


Protective Security measures to mitigate Operational Risks such as these require a comprehensive yet adaptive strategy. What may be most disturbing on the Discovery Channel incident is that the attacker all but announced his attentions on his website in advance. If you don't currently monitor the digital domains for your organizations benefit, then start this soon. You may be amazed at the "Open Source Intelligence" (OSINT) that exists on what Domestic Extremists are saying and planning for your company.

Even after the Twin Towers fell, environmental extremism was seen as a severe threat and, in 2006, Congress passed legislation - the Animal Enterprise Terrorism Act - which classified certain acts of civil disobedience, such as blockades, trespassing, property damage and the freeing of animals, as acts of terrorism.

An FBI assessment continued to reinforce fear of environmental radicals when it stated "together eco-terrorists and animal rights extremists are one of the most serious domestic terrorist threats in the US".

It warned that tactics were "becoming increasingly violent, with threats to life, not just to property".

23 August 2010

Critical Infrastructure Resilience: Put On a "Black Hat"...

Why is a data-centric network like AboveNet, Inc. with their high bandwith solutions connecting with Terremark's NAP in the Washington, DC region? Operational Risk and Cloud Computing is the answer. Clients and customers are requesting more secure infrastructure to house and store their growing inventory of cloud-based apps and other data requirements for "Business Continuity", Disaster Recovery and Continuity of Operations.

Built to accommodate five 50,000-square-foot independent data centers and one 72,000-square-foot office building, Terremark's NAP of the Capital Region exceeds Federal standards for a carrier grade data communications and hosting facility. Customers in the Terremark NAP of the Capital Region now have access to AboveNet's high bandwidth connectivity solutions for all business data communications needs. AboveNet currently serves Terremark customers at the NAP of the Capital Region, and also connects to Terremark data centers in Miami, FL, Dallas, TX, and Santa Clara, CA.

AboveNet has the expertise and high bandwidth connectivity solutions to meet your specific business needs. Customers use high bandwidth solutions to enable their mission critical applications

  • Major Broadcasters use AboveNet’s high bandwidth connectivity solutions to facilitate broadcasting of their live shows and to store historical video content to remote datacenters
  • Pre and Post Film Production Houses are using fiber optic connectivity solutions to provide on lot virtualized post production capabilities for all new films
  • Online Gaming and Social Networking customers use AboveNet services to support content delivery for their end users
  • Online Communication, Content and Product providers use fiber networks to provide content for their on-line products such as MSN, Hot Mail, etc
  • Major Financial Institutions use WDM fiber optic connectivity to achieve their Financial Transaction Processing and Business Continuity needs
  • Hedge Funds use Ethernet networks to connect to the likes of NASDAQ and AMEX and move trading data between their offices
  • Oil and Energy customers use WDM networks to support their Geo Thermal Mapping Disaster Recovery needs
  • Internet Sales customers use high bandwidth network solutions to boast the efficiency of their sales and service

Critical Infrastructure solutions in the global economy require a robust combination of bandwith and data centers. The Virtual Corporation and the Blur of change in the connected enterprise requires that the servers that are the "life blood" of the business be available, fast and assured. Business agreements that improve the capabilities of vital critical infrastructure organizations is a vital facet of prudent Operational Risk Management. Why?

These servers are often underutilized, tying up capital in unneeded software licenses, half-empty drives and idle processing capacity. Long deployment times limit your ability to respond rapidly in an on-demand world. And dedicated servers are expensive to replace, leaving you tied to older models while new advances pass you by.

A true utility computing solution should solve both the economic and capacity-on-demand shortcomings of traditional infrastructure, allowing you to pay only for the resources you need while enabling the rapid deployment of new capacity. And it should do all of this without any performance compromise, in a secure, highly available enterprise-class environment.


The Operational Risks of owning, operating and maintaining your own computing infrastructure are growing. The risks of new threats to embedded systems is also increasing in the transportation industry. The safety and security of the traveling public is being compromised by computers that control braking on a Metro train and the proper position for the wing flaps on a departing commercial airliner:

Authorities investigating the 2008 crash of Spanair flight 5022 have discovered a central computer system used to monitor technical problems in the aircraft was infected with malware.

An internal report issued by the airline revealed the infected computer failed to detect three technical problems with the aircraft, which if detected, may have prevented the plane from taking off, according to reports in the Spanish newspaper, El Pais.

Flight 5022 crashed just after takeoff from Madrid-Barajas International Airport two years ago today, killing 154 and leaving only 18 survivors.

The U.S. National Transportation Safety Board reported in a preliminary investigation that the plane had taken off with its flaps and slats retracted — and that no audible alarm had been heard to warn of this because the systems delivering power to the take-off warning system failed. Two earlier events had not been reported by the automated system.

The malware on the Spanair computer has been identified as a type of Trojan horse.

Are you investing as much in the safety and security of your computing infrastructure as you are in the preventative maintenance of your vehicles, rail cars or aircraft? When was the last time you took them offline and audited these systems for the possibility of infections or just incorrect or outdated updates to the software?

The facts are that you don't have the proper manpower or resources to keep up with the "Blur of the Connected Economy" in the transportation or information technology sectors. Your Operational Risks are increasing by the day, minute and second as a result of your ignorance to the Single-Points-of-Failure in the design, implementation or configuration of your systems.

So what is on the minds of those interested in your own self-defense? See Blackhat Briefings from last month and see what might impact you and your organization.

13 August 2010

Risk Appetite: In Search of the Perfect...

Operational Risk in the corporate enterprise is on the rise and savvy CxO's recognize it. The continuous and advanced schemes, attacks, reputation crises and regulatory compliance changes has the executive suite on full alert.

The global news cycle, financial markets in turmoil and a seemingly upset weather pattern on "Planet Earth" has OPS Risk professionals on ready standby. It's 24 x 7 x 365 responding to new threats and a growing set of domino effects as incidents are more interconnected and have substantial new interdependent relationships.

Operational risk is a serious concern not only to traditional and alternative investment managers, but also to their clients and the organizations that regulate buy-side firms. In worst-case scenarios, an investment firm’s failure to identify and mitigate operational risk can result in significant direct costs and a devastating loss of reputation. It may take years to reassure investors, regulators, and trading partners that the firm is well-managed. So what exactly is operational risk? Castle Hall Alternatives calls it “risk without reward.” The Basel Committee on Banking Supervision (Basel II) defines operational risk as “the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events,” and states that the definition is intended to include legal risk but exclude reputational risk, and lists as examples events ranging from data entry errors to earthquakes.¹ But operational risk is not something that can be easily identified by a generic checklist, nor is there a single, universally applicable approach to mitigating the operational risks to which a given firm is exposed.

A generic check list is by all means not the way to approach most Operational Risks yet starting with a standard framework of controls and optimizing from there is a good start. Certainly the natural catastrophe risk mitigation exercise whether the tornado or earthquake has a foundation in the kinds of preparedness that can assist those caught in the vortex or the fault line of destruction. Yet how could a check list really help with a threat that is adapting to your environment on the fly and creating new obstacles to mitigate the risk before you?

Kerry Dewey was a finance officer for a small nonprofit in the Pacific Northwest. She was having a bad day, but it got worse when her local bank called her to inquire about the validity of a recent funds transfer for just under $10,000 from the nonprofit’s account to an account at an Alabama bank. Moments before, the Alabama bank had contacted Kerry’s bank because its policy is to investigate any transfer that’s close to, but less than, $10,000 – an amount that fraudsters commonly use to avoid currency transaction reporting.

Kerry’s bank stopped the transfer after she assured them that no one in her organization initiated the funds transfer. The episode prompted Kerry to review the nonprofit’s banking transactions in the past few days. She uncovered five other illegitimate transfers that totaled close to $50,000, and each transfer went to a different payee. Fortunately, her bank was able to contact the banks where the funds were transferred, and those banks were able to stop the transferred monies from being withdrawn by the fraudsters. Kerry had opened a very dangerous e-mail.
This case is fictional, but it’s representative of a relatively new “spear-phishing” e-mail scam that has recently emerged as a significant source of revenue for cyber criminals.

As you can see the Small-to-Medium-Enterprise (SME) and other businesses that might have a single person responsible for payroll, accounting and acting as corporate controller are just as vulnerable to the Operational Risks as the large hedge funds, Global Money Center institutions and Corporate Enterprises of the Fortune 500.

The pervasive and constantly evolving components of Operational Risk now require a substantial blend of people, software and management systems. Those savvy CxO's now realize that Operational Risk Management is something that is not being dealt with solely by the CFO, CRO, CIO or CSO in it's entirety. Therefore, the silo's of risk management within the organization are themselves a "substantial risk" to the overall enterprise risk management aspiration. The "Insider" who watches these silos manage their domains and fiefdoms with the goal of keeping it all within the unit or department or section realize that their scheme or attack will have little chance of detection for months, even years.

This is why the Office of Inspector General in government is so necessary and is so feared. This is why the outside auditors or independent investigators are so feared. This is why these two mechanisms for mitigating risks are typically too late and discover something that in the end, most people had a hunch was going on anyway. It's a perpetual cycle that won't end anytime soon and will keep our organizations searching for that eternal balance of a "Perfect Risk Appetite".

29 July 2010

Employee Misconduct: Mitigating Insider Risks...

The new Verizon Cyber Report is a valuable read for OPS Risk professionals that focus on data breach and incident response. The full breach report can be found at this link at Verizon Business.

We have to agree with the observations made by Brian Krebs on the following topic in the report:

A key finding in this year’s report is that most companies suffering breaches missed obvious signs of employee misconduct – breaches that were either initiated or aided by employees. Sartin said in almost every case where a breach investigation zeroed in on an employee as the culprit, investigators found ample evidence that the employee had long been flouting the company’s computer security and acceptable use policies that prohibit certain behaviors, such as surfing porn or gambling Web sites on company time and/or on corporate-issued laptops.

The study found a strong correlation between ‘minor’ policy violations and more serious abuse. From the report: “Based on case data, the presence of illegal content, such as pornography, on user systems (or other inappropriate behavior) is a reasonable indicator of a future breach. Actively searching for such violations rather than just handling them as they pop up may prove even more effective.”


The "Insider Threat" continues to be under estimated and all of the monitoring tools will not be able to stop it completely. Ever. So what are some of the solutions to address the issues at hand? Here are a few ideas worth exploring if not for the Fortune 500 Enterprise but the small-to-medium enterprise (SME) who doesn't have the budget or the internal staff to engineer a robust and resilient infrastructure. They have their unique place in a layered approach to cyber defense:

Idea #1: ScanSafe

Cisco recently acquired the pioneering SWG SecaaS company ScanSafe. ScanSafe continues to execute well and has the largest market share in the SecaaS market including several organizations with well more than 100,000 seats. ScanSafe is expected to form the basis of an increasing array of Cisco SecaaS offerings, starting with the addition of e-mail. Cisco's credibility with the network operations team, the progressive development and market growth of the S-Series and the acquisition of the leading SecaaS provider moved Cisco into the Leaders quadrant this year.

Idea #2: IronKey

IronKey was chosen by the Reader Trust Voting Panel, comprised of security and technology experts from large, medium and small enterprises from all major vertical markets, representing the wide distribution of SC Magazine readers. With an unprecedented number of entries submitted the 2010 SC Magazine readers selected IronKey over competing solutions from Check Point, CREDANT, PGP and Symantec.

IronKey brings unprecedented mobile data security to enterprise and government organizations by combining the IronKey multifunction security devices with the ability to remotely manage the devices and strictly enforce security policies from a centralized administrative console. IronKey enables organizations to securely deliver complete desktop environments on ultra-secure, remotely managed devices with integrated two-factor authentication and fraud protection capabilities.


Idea #3: OpenDNS

OpenDNS has solutions that are perfect for organizations of all sizes, from small businesses to Fortune 500 enterprises. With no equipment to install, no upgrades and no maintenance, OpenDNS will reduce your costs, give you more control and make navigating the Internet on your network a safer, more secure experience.

OpenDNS provides comprehensive security for your organization's network through botnet and malware site protection. OpenDNS delivers network security services through the DNS layer, blocking known malicious or infected sites from resolving on your network. Since infected sites are prevented from resolving, malicious content is blocked from reaching your network, and thereby OpenDNS provides the most efficient protection available.

Built-in botnet protection stops trojans, key loggers and other persistent malware and viruses on machines in your network from sending out confidential data and personal information to hackers outside the firewall.


These are just three examples that we have found to be reliable, cost effective and easy for the small-to-medium size company to hedge against some of the infrastructure risks and bad behavior by employees. So what else could the savvy VP of Operational Risk inject into the organization to address some of the other types of "Insider Threat"?

Provided as a resource by the Association of Certified Fraud Examiners (ACFE), EthicsLine serves as an internal control tool through which companies can detect and deter fraud. Powered by Global Compliance, EthicsLine includes hotline, case management and analytics to empower organizations to prevent, detect and investigate instances of organizational fraud and abuse.

EthicsLine provides expertise and experience. As the power behind EthicsLine, Global Compliance introduced the original ethics and compliance hotline and is the largest provider of hotline, case management, and analytic solutions worldwide – supporting over 25 million client employees in almost 200 countries. Global Compliance also provides additional products and services that integrate with EthicsLine and protect an organization from fraud and abuse.


The employee who knows how to circumvent the "Rule Sets" as it pertains to the Acceptable Use Policy for the corporate digital assets may also be the same person who is stealing from the company. Whether they are stealing actual cash from the register, using vendor billing schemes or other occupational fraud tactics they understand how to get around the control objectives. Operational Risk Managers need to look at the employee population as an ecosystem of risk and that a certain percentage of those employees will be trying to surf Internet gambling sites and simultaneously misappropriating assets.

As you spend more time in OPS Risk, the more you understand the intersections with human behavior. The tools will assist you along the way yet it is the day to day interaction with people that will help you predict where and how someone may be increasing the risk to your enterprise.

23 July 2010

Top Secret America: Analysis of Competing Hypotheses...

Operational Risk Management Executives are still digesting the latest Washington Post investigative reporting from Dana Priest and William M. Arkin, "Top Secret America". The U.S. Intelligence Community (IC) and the Defense Industrial Base (DIB) employees in the suburbs of Virginia, Maryland and DC will be debating the impact over whispered dialogue around the weekend BBQ or over a candle light dinner in their favorite Georgetown restaurant.

The aftermath of the disclosure, increased transparency and ongoing investigation will continue for months and most likely years. New questions, new facts and new ideas will be put on the table for consideration inside the board rooms of private sector companies, law firm lobby shops and the government program management offices. Risk Management and the topics of risk exposure and the likelihood of incident categories will be the center of the conversation.

Since the Safety and Security of the United States is the foundation for the article, it makes the nexus of all the newspaper writing, blogposts, TV interviews and Internet "Tweets" relevant to Operational Risk Management.

As professionals in the IC and DIB continue to evolve their solutions on the ever changing threat to US citizens, you only have to look to the requirements placed in front of them. What risk are we trying to mitigate? What exposure do we have now? What is the likelihood that this will happen to us and how soon?

The requirements dictate the solution. The understanding of the threat dictates the requirements. The solution is not going to be implemented one time, one place and then it's over. It's going to be adaptive and it's going to evolve at the speed of the threat. The question that is always being asked by everyone is, how fast can we adapt?

Dana Priest and Bill Arkin may have done our country a great service at this point in time. The "Analysis of Competing Hypotheses" (ACH) may be utilized to ultimately prove the correct course and to make even more sound analytical judgments about our national security evolution. By actually using the data facts uncovered by their current research the process of eliminating errors in the data can begin. And once the data has been normalized and cleansed so that all agree that it is the true baseline, then the ACH can begin.

As the DNI provides the leadership and works through the governance cycles with all of the IC Director's and Secretary's, then the use of a vetted methodology such as ACH combined with the entire risk management exercise, may indeed reveal some operational risk vulnerabilities. It would be through the analytic process, risk matrix and the future enterprise architecture work that a more robust, resilient and economic model is developed and implemented.

Now about the question on whether our national security has been compromised or the risk to our private sector assets has increased as a result of the Washington Post article. Only time will tell as the possibility of future VBIED incidents, take out the facades of previously unknown or unnoticed IC or DoD facilities identified and validated in the newspaper's research.

Even now however, the vulnerability of our vital national security assets are most likely to be copied, stolen, corrupted or deleted by the logic bombs lying in wait, before major kinetic disruptions. It will no doubt be a 4GW blended attack on our homeland that combines the effects of both that experts predict is our greatest threat.

This brings us back to the quote at the top of this blog:

"The Only Thing Necessary For Evil To Triumph Is For Good Men To Do Nothing." --E. Burke

God's Speed to the United States of America...

06 July 2010

Black Swan: Consumer Financial Protection Bureau...

The Consumer Financial Protection Bureau has been born out of the 2,300 pages of the final US Federal Financial regulation of 2010. The tone on what and how the CFPB operates is spelled out in the legislation and Operational Risk Managers are actively scouring the fine print to determine the compliance and legal ramifications. Yet the new Director's leadership may spell out the impact more than any of the new rules. The WSJ enlightens us:

The legislation says the bureau's purpose is to "regulate the offering and provision of consumer financial products or services." Details are left largely up to the new director, who would serve a five-year term. The law creates offices for research, tracking consumer complaints, consumer financial literacy and fair lending, among others.

Among the director's first tasks will be refining the agency's mission. Critics and supporters, though agreeing on the importance of the new agency, differ on what will constitute success.


Institutions will be adjusting their behavior to the new rules and it will be adjusting to how it continues to do proprietary trading. It's hedge fund ownership is now limited to 3% and the "Volcker Rule" is the same percentage for trading Tier 1 capital. The entire financial services industry is essentially gearing up for more of the same with minor adjustments on how it implements it's various risk management strategies. So what has changed and what will change?

Large banks and their supply chains will be looking for new ways to leverage their ability to improve margins. And when you look for ways to improve margins, you raise rates add more fees and incrementally gain a tremendous avenue for increased cash flows. Enterprise Risk Management will try to find a way to hedge against the "Black Swan" event from ever happening again. Even today, the business is still in the dark on the mathematical equations that caused the last implosion of world markets and the unraveling of the financial trust that is the foundation for the system to operate with efficiency and market speed.

Going forward the risk management professionals will be dissecting the final law to determine how it will impact their business, institution or agency for the next few years. As business owners and corporate institutions begin to see what direction the new Consumer Financial Protection Bureau (CFPB) chief will be taking, they will be devoting resources and budgets to adjust to these market changes.

And while all of this is evolving in the open and transparent world of finance you can bet that the next "Black Swan" event is on the horizon. As "Operational Risk Managers" who witness the speed and the complexity everyday in the trading pits, software development units and on the white boards of countless conference rooms will tell you; the next one is out there:

"A Black Swan is a highly improbable event with three principal characteristics: It is unpredictable; it carries a massive impact; and, after the fact, we concoct an explanation that makes it appear less random, and more predictable, than it was." Nassim Nicholas Taleb, from his book The Black Swan - The Impact of the Highly Improbable

Sens. Chris Dodd (D., Conn.) and Blanche Lincoln (D., Ark.) are trying to calm the fury among bankers and business groups over a last-minute change to the financial overhaul bill that critics now say could upend the way companies hedge against risk.

In the early hours of Friday June 25, Democrats altered a key provision to the derivatives section of the financial overhaul bill. It has a completely different meaning depending on who you ask. Some believe the language would require all people engaging in derivatives contracts to post “margin,” or more costs to engage in a deal. Others believe it would apply only to big banks and major derivatives dealers. The difference could swing billions of dollars one direction or another.

The confusion stems from a part of the section, tucked into the 2,300-page financial overhaul bill, that says margin requirements “shall” be set against “all” uncleared swaps. Some companies believe they should be exempted because they aren’t risky derivatives speculators, and fear it will drive up their costs. Several companies and business groups have said the language is such a glaring mistake that it could undermine the entire derivatives market, particularly for companies using these products simply to hedge risk.

But the language is in sections of the bill setting rules for “swap dealers,” which are essentially banks or large derivatives traders regulators plan to place tougher restrictions on. Depending on how it is interpreted, the language could apply only to those “swap dealers.”

Regardless, the confusion has led to an uproar…


01 July 2010

Fraud Terrorism Nexus: Public-Private Partnerships...

The ACFE "Report To The Nations on Occupational Fraud and Abuse has been published in the July/August mailing of Fraud Magazine. There are some tell tale signs that Operational Risk Management is working and yet we have so far to go on this journey towards a more transparent, ethical and safe workplace environment.

Here are some of the highlights and findings from this annual survey:

  • 5% of annual revenues are lost to fraud
  • 25% of the fraud incidents involved losses of $1,000,000.00 or more
  • Frauds lasted a median of 18 months before being detected
  • Small organizations are much more likely to be victims
  • Fraud perpetrators often display warning signs they are engaging in illicit activities

While these are consistent with previous years results the article in this latest issue that caught our eye is worth further investigation and analysis. "The Fraud-Terror Link: Terrorists are Committing Fraud to Fund Their Activities."

The threat of terrorism has become the principal security concern in the United States since 9/11. Some might perceive that fraud isn’t linked to terrorism because white-collar crime issues are more the province of organized crime, but that perception is misguided. Terrorists derive funding from a variety of criminal activities ranging in scale and sophistication – from low-level crime to organized narcotics smuggling and fraud. CFEs need to know the latest links between fraud and terror.

Credit card fraud, wire fraud, mortgage fraud, charitable donation fraud, insurance fraud, identity theft, money laundering, immigration fraud, and tax evasion are just some of the types of fraud commonly used to fund terrorist cells. Such groups will also use shell companies to receive and distribute illicit funds. On the surface, these companies might engage in legitimate activities to establish a positive reputation in the business community.

Financing is required not just to fund specific terrorist operations but to meet the broader organizational costs of developing and maintaining a terrorist organization and to create an enabling environment necessary to sustain their activities. The direct costs of mounting individual attacks have been relatively low considering the damage they can yield.

The nexus between those who wish to attack our physical or digital infrastructure assets are after the same outcomes. High number of victims and media exposure. The threshold for financing overt attacks is coming down and the face of terrorism is changing. It has morphed into a pattern of behavior that requires the OPS Risk professionals to see the link and to study the reasons why the Fraud-Terror convergence is happening now.

Small groups of people who are doing pre-operational surveillance on targets in both physical locations and online Internet points of presence are in need of funding. Yet it doesn't take much. The London Bombings of 2005 were financed with a budget of around $15K. Now let's go back to the stats from the latest survey for a minute.

"Internal controls alone are insufficient to fully prevent occupational fraud. Though it is important for organizations to have strategic and effective anti-fraud controls in place, internal controls will not prevent all fraud from occurring, nor will they detect most fraud once it begins."

So where is this wave of fraud schemes coming from and attacking the average person on the street. Actually it's in cyberspace. This is where a tremendous amount of non-profit, charitable and other mechanisms for generating revenue and funding for terrorism occurs. Identity Fraud, Mortgage Fraud, Insurance Fraud and Immigration Fraud all are the precursors to the collection and potential dissemination of funds to those who are planning to harm people and our economic way of life.

We have found in that the best approach to this threat is education, awareness and sharing of best practices. To jump start the conversation in your metro area of the United States you only have to look to your local InfraGard chapter. This is a good first step in opening up the dialogue on topics such as transnational economic crime and who is behind these operations. Here is a good example of what's happening in the Washington, DC area:

Topic:

"The Communication Infrastructure and Organization of Transnational Cyber Criminal Syndicates"

This Intelligence Briefing will address the tradecraft employed by cyber criminals who participate in private, organized transnational criminal operations using self-created and self-maintained infrastructures rather than the tradecraft of those in traditional underground forums that exist on the Internet. Included in the briefing will be discussion of technical infrastructures, communication methods and division of labor of cyber criminal organizations.


Once the Certified Fraud Examiner, IT cybersecurity professional and the intelligence analysts finish their brown bag lunch, you can see the collaboration wheels turning. In the grand scheme of millions and billions of dollars that are spent on sensors, anti-terrorism technologies for homeland security or the dollars wasted on procurement, the simple public-private partnership wins every time. Again, reflecting on the latest Occupational Fraud survey:

Occupational frauds are much more likely to be detected by tip than by any other means. This finding has been consistent since 2002 when the ACFE began tracking data on fraud detection methods.

22 June 2010

Workplace Privacy: Ontario Prevails on Data Audit...

Operational Risk Management professionals in corporate America have been following the Quon vs. City of Ontario case for five plus years. Now the Supreme Court of the United States has ruled 9-0 to increase the clarity on the new age of electronic privacy in the workplace. The LA Times explains:

Washington…In its first ruling on the rights of employees who send messages on the job, the Supreme Court rejected a broad right of privacy for workers Thursday and said supervisors may read through an employee's text messages if they suspect the work rules are being violated.

In a 9-0 ruling, the justices said a police chief in southern California did not violate the constitutional rights of an officer when he read the transcripts of sexually explicit text messages sent from the officer's pager.

In this case, the high court said the police chief's reading of the officer's text messages was a search, but it was also reasonable.

Police Sgt. Jeff Quon had sued the chief and the city of Ontario, California after he learned the chief had read through thousands of text messages he had sent to his wife and a girl friend. Quon won in the 9th Circuit Court of Appeals, but lost in the Supreme Court Thursday.


The scope of the investigation by the employer was not unreasonable and within the scope of determining whether the large amount of text messages was work related. What kind of corporate risk initiatives will be impacted by this ruling?

As corporations continue to battle the "Insider" risk associated with occupational fraud, workplace violence related stalking or sexting, industrial espionage, corruption and violations of acceptable use policies this case will become an example. What will continue to be the challenge for OPS Risk professionals who are responsible for internal monitoring, digital asset audits and insider investigations of potential malfeasance is the scope and reasonable nature of the case.

Get ready for a rush to the local Verizon Wireless or AT&T store for your own personal PDA or iPhone due to Justice Kennedy's ruling:

What’s more, Kennedy suggested that privacy in the modern age has more than one meaning.

“Cell phone and text message communications are so pervasive that some persons may consider them to be essential means or necessary instruments for self-expression, even self identification. That might strengthen the case for an expectation of privacy. On the other hand, the ubiquity of those devices has made them generally affordable, so one could counter that employees who need cell phones or similar devices for personal matters can purchase and pay for their own. And employer policies concerning communications will of course shape the reasonable expectations of their employees, especially to the extent that such policies are clearly communicated. “


If you are the CxO responsible for the auditing of digital assets within the enterprise, or the responsible party for insuring privacy in the workplace it's time to convene a two day workshop to review. Take a few days to bring the legal, privacy, IT and business unit deal makers to the same hotel resort country club to converge on this vital issue. The Operational Risks associated with executive communications that were previously thought to be private may be monitored and audited anytime when company assets are being utilized.

The opportunity to work through different workplace related scenarios, highlight the legal rulings and discuss the "What if's" could mean the difference between adversarial litigation and "Achieving a Defensible Standard of Care."

This is also a good time to establish the foundation for the "Corporate Intelligence Unit" within the enterprise:

Beyond the utilization of threat assessment or management teams, enterprises are going to the next level in creating a "Corporate Intelligence Unit" (CIU). The CIU is providing the "Strategic Insight" framework and assisting the organization in "Achieving a Defensible Standard of Care."

The framework elements that encompass policy, legal, privacy, governance, litigation, security, incidents and safety surround the CIU with effective processes and procedures that provides a push / pull of information flow. Application of the correct tools, software systems and controls adds to the overall milestone of what many corporate risk managers already understand.

The best way in most cases to defend against an insider attack and prevent an insider incident is to continuously help identify the source of the incident, the person(s) responsible and to correlate information on other peers that may have been impacted by the same incident or modus operandi of the subject.

07 June 2010

FCPA Readiness: Training Corporate Aviators...

Operational Risk Management is a topic that rarely comes up at a social event, unless you happen to be talking with a "Naval Aviator". In just a few minutes of explaining the focus of this writers subject matter expertise, the dialogue took on a whole new level. Mike M. immediately began to talk about the many facets of Operational Risk in the context of flying his missions across the globe. He sipped his drink in the back yard under flaming torches as the backyard BBQ buzz was in high gear.

As we continued the conversation on the OPS Risk "All Hazards" point of view and the vulnerability of false or failed information he was clear about one thing. When all fails in the face of pre-planning, contingency exercises and the dawn of a new twist in your mission objectives becomes apparent, your training instinct is what takes over. This may be a true statement when it comes to the military worldview and their obsession with continuous training exercises yet it remains a lofty and sometimes elusive goal in the ranks of the private sector and Fortune 1000 companies.

The private sector company is still eons away from the level of readiness and the ability to call their employees in top shape as it pertains to corporate fundamentals. The Corporate 101 of ethics, compliance and legal risk is typically an hour orientation on the first week of the job. The training associated with protecting company assets and personnel is left to a few people in the Facilities Security Office. Providing the awareness of online threats, phishing and data leakage or privacy is often an online web "Flash" based learning module you must answer to correctly if you want access to the corporate e-mail server.

The serious nature of Operational Risk on the deck of the aircraft carrier operating in the Arabian Sea is light years away from the mind set of the Board of Directors at the latest Quarterly Meeting after a round of golf. You have to ask yourself why there is a difference?

The topic of Risk Management in the context of the corporate enterprise in many cases comes down to lawyers and insurance companies. The perception is that these two devices for risk management will be able to solve any problem that arises or any incident that could eventually occur. This mindset by corporate management is in many cases what causes their eventual downfall.

Investing in the education, training and awareness building of your company employees will in the long run provide tremendous business resilience and longevity. Exercising special diligence in the implementation of the proactive controls for early warning and effective detection will at some point pay off. Just ask companies such as HP or Avon:

Fitch Ratings says there could be rating implications to U.S. corporate issuers with modest free-cash flow or liquidity for violating the Foreign Corrupt Practices Act (FCPA). This is in addition to management distraction, reputational risk and added compliance costs according to a new special report issued today.

In April 2010 alone, three corporations rated by Fitch were the subject of news stories related to the FCPA, including Avon Products Inc. (Avon), Hewlett-Packard Co., and BHP Billiton, Plc. Violation of the FCPA is a criminal offense and average fines have started to increase. Mere indictment can trigger onerous reporting requirements, civil lawsuits and business losses. More important, enforcement activity is set to increase with a primary focus on the pharmaceutical industry.

In the U.S., proposed financial reform legislation in the House and Senate includes rewards for whistleblowers which provide added impetus for corporations to self-report violations. The cost of investigating violations on a worldwide basis can be relatively high, as noted in Avon's recent disclosure that the cost of its current FCPA investigation is expected to be in the $85 million to $95 million range during 2010 after being $35 million in 2009. The $85 million would represent approximately 55% of Avon's 2009 free cash flow. However, Avon maintains substantial cash balances which can easily fund these FCPA investigatory costs.


The Operational Risk associated with corruption on the front-line of business operations is growing. The reason is because of the continued pressure that is being put on the deal-makers and the "Rain Makers" to increase revenue. Companies that must fill the product pipeline with new inventory and the best pricing will continue to operate in risky waters, especially if they are selling their goods and services on a global scale.

As we finished our smoked beef BBQ, corn bread and baked beans "Naval Aviator Mike" came to the bottom line. "When the mission plan goes haywire or the equipment begins to fail, there is only one thing you have left. Your instinct. That instinct is directly hard wired to your training."

We agree and will continue our advocacy of the direct link between an organizations dedication and investment in Business Resilience, Training and Exercises and their ability to survive in today's hostile corporate environment.

28 May 2010

Memorial Day: Vigilance Reminder...

What does Memorial Day mean this weekend in the United States? A time to reflect on all those who have served and sacrificed their lives for our freedom and continued way of life. At the same time it is an opportunity to look into the minds of those who will determine the future course for our security strategy. The U.S. National Security Strategy articulates this future vision. How does Secretary of State Clinton see the new strategy?

The strategy calls on the United States to build its economy “and to shape the global system so that it is more conducive to meeting our overriding objectives: security, prosperity, the explanation and spread of our values, and a just and sustainable international order,” Clinton said.

The threats are diverse, the secretary of state continued, and include terrorism, proliferation of weapons of mass destruction and the means to deliver them, climate change, cybersecurity, energy security and many others. Responding to these threats, she said, also produces opportunities, new modes of cooperation, new capacities to improve lives and tangible efforts to bridge great gaps in understanding.

“We are in a race between the forces of integration and the forces of disintegration, and we see that every day,” Clinton said. “And part of our challenge is to define American leadership in relevant terms to the world of today and tomorrow, and not merely looking in the rearview mirror, which makes it very hard to drive forward.”



If you are sitting in a "Mud Hut" in Kandahar right now or standing on the grave of a loved one in "Section 60" at Arlington National you could be asking yourself, what does this all mean to me?

The thoughts and words of world leaders may change about what is the proper way to go about the "Global Housekeeping" this year or decade yet it will never change the threat that continues to be our greatest Operational Risk. The human beings on the planet that get up every morning to fight on the battlefield, find food and water for their family, commute to a chaotic and quiet room in a major city to read, analyze and think about new information or even pray to their god, have the same vulnerability.

A complacent point of view. A lack of vigilance to help defeat the evil behavior of other humans, prepare for the hazards thrown at us by mother nature and the will to utilize civility in our approach to solving all of the problems before us. Complacency is the greatest operational risk before us.

com·pla·cen·cy

–noun, plural -cies.

1.
a feeling of quiet pleasure or security, often while unaware of some potential danger, defect, or the like; self-satisfaction or smug satisfaction with an existing situation, condition, etc.

It is the reason there are so many people still scratching their heads on such topics as:

  • AIG
  • Bernie Madoff
  • SEC
  • Freddie Mac
  • Fannie Mae
  • Conficker
  • Umar Farouk Abdulmutallab
  • Qods Force (IRGC-QF)
  • Zeus
  • Faisal Shahzad
  • ‘Volume Algo’
  • Deep Water Horizon
And the list goes on. Memorial Day each year is a dedication to those who have served our country and still are serving our country. The operational risks are many and they are not slowing down. This Memorial Day 2010 requires that we all make the pledge to purge ourselves of any complacent attitudes. Our vigilance is the last opportunity we all have to make a difference on this planet.