22 December 2005

Financial Services Marketers: Get Ready for Your Audit...

The FDIC Small-Entity Compliance Guide is now available. The guide summarizes the obligations of financial institutions to protect customer information and illustrates how certain provisions of the Security Guidelines apply to specific situations.

Distinction between the Security Guidelines and the Privacy Rule

The requirements of the Security Guidelines and the interagency regulations regarding financial privacy (Privacy Rule)8 both relate to the confidentiality of customer information. However, they differ in the following key respects:

- The Security Guidelines address safeguarding the confidentiality and security of customer information and ensuring the proper disposal of customer information. They are directed toward preventing or responding to foreseeable threats to, or unauthorized access or use of, that information. The Security Guidelines provide that financial institutions must contractually require their affiliated and non-affiliated third party service providers that have access to the financial institution's customer information to protect that information.

- The Privacy Rule limits a financial institution's disclosure of nonpublic personal information to unaffiliated third parties, such as by selling the information to unaffiliated third parties. Subject to certain exceptions, the Privacy Rule prohibits disclosure of a consumer's nonpublic personal information to a nonaffiliated third party unless certain notice requirements are met and the consumer does not elect to prevent, or "opt out of," the disclosure. The Privacy Rule requires that privacy notices provided to customers and consumers describe the financial institution's policies and practices to protect the confidentiality and security of that information. It does not impose any other obligations with respect to safeguarding customers' or consumers' information.


3rd Party marketers of financial institutions are preparing for new audits of the their information securtiy controls and processes. Slicing and dicing customer information utilizing pscyhograpics and demographics is a normal task. Mailing millions of pieces annually with new offers from collaborating internal companies and external partners creates significant challenges in managing sensitive customer information. This increased exposure to potential data loss and other threats warrants additional scrutiny with supply chain companies that interface with the marketing department.

One way to find out how ready your partners would be for a formal audit is to ask them when was the last time they had an independent audit of their information security controls. Many organizations today serve multiple financial institutions in the same region and therefore are consistently being asked for evidence of a SAS 70 audit opinion. SAS 70 is not a predetermined set of standards that an organization must satisfy in order to “pass” the audit. In a SAS 70 audit, the service organization is responsible for describing its control objectives and control activities that might be of interest to auditors in user organizations. SAS 70 objectives can be non-specific for an audit and may have large gaps in real-time day to day operations.

20 December 2005

Resilience Masks the Real Problem: Training...

The UK financial services sector has completed the first phase of it's Resilience Benchmarking Project. More than 60 key firms and financial infrastructure providers from the UK volunteered to take part in the Resilience Benchmarking Project, the results of which were mixed and highlighted a number of significant operational risk issues relating to business continuity. Here is the summary of FSA discussion points:

1 Although the financial system appears to be technologically resilient, are there vulnerabilities in other areas that could put it at risk?

2 What action could the Tripartite Authorities take to help bring together the component parts of the system?

3 How can firms strengthen their collective resilience?

4 Would it be helpful to publish recovery-time targets for wholesale payments, trade clearing and settlement? If so, would 60-80% of normal values and volumes within four hours, rising to 80-100% by the next working day, be reasonable recovery targets?

5 If we decide to publish targets, should these apply to core firms and financial infrastructure providers only, or should they apply more widely?

6 Should we consider publishing targets for other functions such as resumption of trading and retail payments?

7 If we were to publish targets, should these be informal in nature or should they be embedded into rules and guidance?

8 What more can be done to encourage joined-up planning and testing to reflect better the likely impact of a major operational disruption and how this could be facilitated?

9 Could the weaknesses in business continuity and crisis management arrangements undermine recovery time capabilities?

10 Would it be helpful to set a minimum distance criteria between primary and recovery sites? If so, what should that distance be?

11 Should we actively encourage firms to diversify their back-up arrangements, in particular core firms and financial infrastructure providers?

12 Do you agree with our conclusions and proposed actions in relation to recovery service provision? Is there more that the Tripartite Authorities should do in this area – for example including a specific survey on recovery service provision in future benchmarking studies?

13 We invite feedback on the measures we propose to take to mitigate concentration risk: encouraging end-to-end testing; sharing information on resilience and recovery arrangements the financial infrastructure providers have in place; and encouraging wider geographical diversification.

14 Should FSA maintain its non-prescriptive approach to business continuity management?

15 We would welcome comments on the estimated cost of reaching the targets we propose to publish for core firms and financial infrastructure providers:
– from those organisations to which these targets would apply; and
– from other organisations for which these targets might be considered aspirational goals.

16 We would welcome views on the estimated cost of lost business arising from the delayed recovery of a vital counterparty (i.e. a core firm or financial infrastructure provider).


The word "Resilience" occurs 70 times in this 52 page document. The word "Security" occurs only 12 times. The word "Continuity" occurs 63 times. The word "Risk" occurs 52 times. Resilience seems to be the overall theme these days.

The definition of Resilience is an interesting one:

Main Entry: re·sil·ience
Pronunciation: ri-'zil-y&n(t)s
Function: noun
1 : the capability of a strained body to recover its size and shape after deformation caused especially by compressive stress

2 : an ability to recover from or adjust easily to misfortune or change


The definition has a reactive flavor to it with the thought that something is going to happen and when it does, you must be able to recover quickly. With all the synomyms and word games being used today it all comes back to effective training. And this is where the benchmarking study has revealed the corporate business enterprises greatest weakness:

Training is another potential area for improvement. Only 42 firms include business continuity planning in induction programmes for new staff, and ten respondents had provided training to less than 5% of their staff. Fewer than a third of participants have provided training to staff that might be called upon to deal with sensitive issues, such as working on a casualty helpline. The responses to these and a number of other questions indicate a lack of appropriate training needs analysis and a need for greater consideration of the effects of a crisis on those who might be asked to undertake some of the most harrowing and disturbing roles.


16 December 2005

High Quality or Low Price: Pick One...

Have you ever heard that old saying, "You can have high quality or you can have a low price, pick one." Now apply this to Operational Risk Managment in your domain.

It seems that the U.S. Senate has mixed priorities right now on the U.S. Patriot Act debate. Wyoming is a low risk area in terms of critical infrastructure yet it will receive the same funding as states with more shoreline, ports and vulnerabilities to the security of the United States. James Jay Carafano has identified what the key issue really is:

What’s Missing?

There was one important provision that did not make out of conference. The original Patriot Act established the requirement that a significant percentage of all homeland security grants be distributed automatically to each state, big or small, regardless of national priorities or risks. Current funding formulas guarantee each state .75 percent of the funds available. As a result, 40 percent of these funds are immediately tied up, leaving only 60 percent for discretionary allocations. As the 9/11 Commission’s report rightly stated, the current system is in danger of turning homeland security funding into “pork-barrel” spending, making spending on security just another state entitlement program. In conference, an initiative to restructure the system and allocate money according to risk and needs rather than an archaic formula was rejected by Senate conferees. This is the third time the Senate has turned back House legislation to reform the grant system. And it is just wrong.


Prudent risk management policies and strategy point to investing to improve resilience in the areas that are identified as being most vulnerable and that the consequences of a loss would be unacceptable. What part of the risk management methodology is missing in the presentations or education of our law makers?

The part that is missing is the part that no one can present in fear of it becoming public information and for it to get into the hands of those who may use it to harm the homeland. Those single-points-of-failure exist in every country or city that has a significant capitalist marketplace. The resilience of the respective economies depends on the infrastructure that fuels it and every dollar and resource needs to be focused on those highest risk areas.

Mr. Carafano makes another observation worth consideration, regarding the The September 11 Commission Report Card: The Good, the Bad, and the Ugly:

At the top of the list is the failure of the Congress to put together a comprehensive package of border security and immigration reforms that enhance security, promote economic growth, and protect civil liberties. Also missing from the list is the tragic underfunding of the Coast Guard. The same service that saved 33,000 lives during and following Hurricane Katrina faces cuts to its modernization budget in the House.


The private sector can change all of this in a heart beat. The safety and security of our economic livelihood is in the hands of the telecom/high tech, banking and finance, health care and energy sectors. In the long run, the executives in these industry sectors have the power to change our law makers points of view. Let's just hope that they all realize that it is their own corporate assets that are at a greater risk now, than they were over four years ago.

15 December 2005

CIP Risk Management: NIPP & Tuck...

As part of the new National Infrastructure Protection Plan NIPP v1.0 the years old RAMCAP (Risk Analysis and Management for Critical Assets Protection) methodology of the American Society of Mechanical Engineers makes it's way into the mainstream:

RAMCAP is an overall methodology and provides a common framework for homeland security risk analysis decision-making that includes:

–Common terminology
–Common metrics for comparing risks across sectors
–Common basis for reporting results
–Basis for informing resource allocation decisions

•Countermeasures
•Consequence mitigation actions


ASME was awarded a grant by the Department of Homeland Security to develop uniform risk-based guidance in September 2003. The methodology's sequential steps include:

•Vulnerability analysis
•Consequence analysis
•Risk analysis
•Countermeasures and mitigation
•Decision analysis
•Multiple assets and sectors


The NIPP is a "draft" today and the comment period has already expired December 5, 2005. We expect that we will see sector specific plans soon after the national plan is finalized. It will be interesting to see how the private sector reacts. Industry critics say the draft lacks specificity at this point. However, maybe this is a good thing for the owners and operators of 85% of the nations critical infrastructure.

12 December 2005

Reducing Operational Risk Through CAP & IPv6...

After attending the United States IPv6 Summit last week it was apparent that Emergency Preparedness and National Security is a top priority. This is increasingly true as we see the grades on our progress by the 9/11 commission and others with regard to data communications and interoperability issues. One facet of all of this has to do with the important work already underway by the technical committees at OASIS:

The mission of the EM TC is to create incident and emergency-related standards for data interoperability. The TC welcomes participation from members of the emergency management community, developers and implementers, and members of the public concerned with disaster management and response.

Standards currently under review by the committee:

The Common Alerting Protocol (CAP), a data interchange standard for alerting and event notification applications, currently in version 1.1. CAP functions both as a standalone protocol and as a payload for EDXL messages.

The Emergency Data Exchange Language (EDXL), a broad initiative to create an integrated framework for a wide range of emergency data exchange standards to support operations, logistics, planning and finance.


Why is IPv6 and CAP a big issue in operational risk management? It will save lives and property as it is deployed in numerous communications devices and services in the future. Currently, the big drive for IPv6 is new uses, such as mobility, quality of service, privacy extension and so on. The U.S. Government has also specified that all federal agencies must deploy IPv6 by 2008.

Karen Evans and the OMB are preparing the federal CIO's for the transition:

The CIO Council will develop additional transition guidance as necessary covering the following actions. To the extent agencies can address these actions now, they should do so. Beginning February 2006, agencies’ transition activity will be evaluated using OMB’s Enterprise Architecture Assessment Framework:

• Conduct a requirements analysis to identify current scope of IPv6 within an agency, current challenges using IPv4, and target requirements.
• Develop a sequencing plan for IPv6 implementation, integrated with your agency Enterprise Architecture.
• Develop IPv6-related policies and enforcement mechanisms.
• Develop training material for stakeholders.
• Develop and implement a test plan for IPv6 compatibility/interoperability.
• Deploy IPv6 using a phased approach.
• Maintain and monitor networks.
• Update IPv6 requirements and target architecture on an ongoing basis.


Much of what IPv6 is all about has to do with capacity of our current standard IPv4. However, as more emphasis is put on interoperability and the use of millions of new data capture and reporting sensors both CAP and IPv6 will both be essential building blocks to the future. One example illustrated the other day is the changes being made in London and other global metro areas to capitalize on the fact that most citizens are carrying mobile phones with picture and video taking capabilities. These video images are increasingly being utilized to assist both law enforcement and emergency responders with new insight into the real situation as it unfolds. In some cases while voice circuits are jammed the data communications can get through.

Sometimes, a picture is worth a thousand words.

06 December 2005

Mitigating Operational Risks Around the Globe...

In this month's CSO Online, Todd Datz has an article worth exploring. How to Manage Security Halfway Around the World talks about several key components of global operational risk mitigation:

Different cultures. Unstable political environments. Language barriers. CSOs in global companies face many a challenge as they try to manage security in far-flung locations. One of the biggest challenges? A good number of your security managers reside in functions other than corporate security, so security is often a part-time gig managed by people with part-time security training. There’s no ironclad set of rules or policies that all those employees can follow.


If you are like most organizations doing business on a global basis, you don't have a security department in every office. This is why it is imperative for your local employees to establish local relationships with other businesses or entities who will help protect your vital corporate assets.

Educate Your Global Security Staff
Training is a critical component of any global security program, especially given that many security managers in foreign locations come from nonsecurity functions—such as HR or engineering—and thus wear multiple hats.


It's critical to have a local presence along with a centralized global policy and audit function know as Enterprise Security Risk Management. Together the partnership keeps a great degree of relevance to the issues and cultures in a particular country while simultaneously keeping a consistent and correlated set of standards for legal compliance. International laws for exchange of information, transmitting funds and selling products and services to Specially Designated Nationals (SDN)'s are all important business risks to be managed.

With a growing focus on risk management, The Yankee Group predicts that by 2008, the $165 million Enterprise Security Risk Management market will grow to $650 million as more organizations move to strengthen their global security posture. According to The Yankee Group, most organizations today utilize informal security risk management processes using professional services and homegrown databases that are often time-consuming and ineffective.

01 December 2005

Board of Directors: Corporate Responsibilities...

The primary responsibilities of the Board of Directors are getting more scrutiny than ever before. Especially in the light of the fact that statements executives make about quarterly earnings are a focus for class-action shareholder lawsuits.

Many public institutions are no longer bowing to Wall Street and publishing or promising quarterly numbers. In fact, many are following the lead of people like Warren Buffet of Berkshire Hathaway. He doesn't believe in the short sighted behavior that occurs around quarterly conference calls with analysts. Look to the The Washington Post as one example.

The Board is ultimately responsible for ensuring the performance and survivability of the corporation. The shareholders want the Board to do the following:

1. To ensure legal and ethical conduct.

2. To insist on strategic and operational planning.

2. To develop in collaboration with management a real-time risk assessment.

4. To establish a Corporate Governance culture based on best practices.

5. To exercise the Director's fiduciary duty of care on behalf of the shareholders.

An ever more important responsibility is to apply the use of technology and it's purpose in the survival and longevity of the organization. At the Washington Post, which does not offer quarterly guidance, they have adopted technology to help satisfy the analysts needs for information.

WASHINGTON, Nov. 30 -- The Washington Post Company (NYSE: WPO) will audio webcast its presentation at the Credit Suisse First Boston (CSFB) Global Media Week Conference next week. The Company's presentation will take place on December 6 at 4 p.m.

The live webcast will be accessible from a link on The Washington Post Company's website, http://www.washpostco.com, and at http://www.csfb.com. A transcript will be posted on http://www.washpostco.com following the presentation.


Maybe someday the SEC will reconsider Regulation FD:

"The Reg FD rule reads as follows: "Whenever an issuer, or any person acting on its behalf, discloses any material nonpublic information regarding that issuer or its securities to [certain enumerated persons], the issuer shall make public disclosure of that information... simultaneously, in the case of an intentional disclosure; and... promptly, in the case of a non-intentional disclosure."


In light of this, most Directors and Executive management are counseled to say very little about what is happening in the company.

24 November 2005

Avian Flu: What are the Risks?

Avian influenza, or bird flu, is a contagious viral disease caused by certain types of influenza viruses that occur naturally among birds. Usually, these viruses do not infect humans, but several cases of human infection with bird flu viruses have been reported recently.

Why could this become an Operational Risk for your organization? Currently, these viruses are circulating in bird populations in Asia, and have resulted in severe illness and death in humans. Since the recent outbreaks of this strain began in 2004, more than 120 people have been confirmed as infected and more than 60 have died. Most human cases are thought to have occurred through contact with infected poultry or contaminated surfaces. However, some scientists worry that if the virus were able to mutate and be able both to infect people and then to spread easily from person to person in a sustained fashion, a global "influenza pandemic" (worldwide outbreak of the disease) could begin.

This WHO Avian Flu Fact Sheet can provide some of the answers on the disease.

21 November 2005

Simulation & Analysis: COOP on Steroids...

All of the planning tools that have automated the process of developing BCCM and COOP documentation have addressed only a small piece of the total mosaic for operational risk management. There is however a new "kid" on the block that is worth keeping your eye on. This is because they have created the tools for doing critical simulation and analysis of the impact of significant business disruptions to our critical infrastructures.

FortiusOne’s target market encompasses both the public and private sector. The former includes federal, state, local and international segments, with primary emphasis on Homeland Security, National Defense, Intelligence and Emergency Management for critical infrastructure vulnerability assessments and consequence management. FortiusOne’s private sector market addresses risk analysis for the Banking/Financial Services, Transportation, Energy, Telecommunications, Insurance and general Supply Chain segments with primary emphasis on business continuity planning, business optimization and disaster recovery. Market size exceeds $40B and is upward trending in both public and private sectors. Recent events and consequences related to hurricane Katrina, terrorist threats and attacks, and corporate management/mis-management events have created intense interest in FortiusOnes’s products and services. The Company’s revenue model for both public and private sectors includes fixed price product pricing for basic assessments with additional high valued consultation for detailed analysis of specific client defined scenarios.


While we have all the confidence that there is a market for tools like these, the largest challenge still remains. Human Factors.

All of the scenario planning and simulation is important to create new contingency procedures or the application of new methods for mitigating the impact of such scenarios. However, the human factors are and will remain unknown until you actually exercise and effectively test that scenario. Only testing will tell you what people did or didn't do or why they reacted the way they did. The psychological and physiological unknowns are what throw the planners and simulation operators for a loop every time.

We hope that FortiusOne also gives their clients the insight they require to create the most realistic and optimal tests to determine what the real outcomes will look like before and after a natural disaster or terrorist event.


17 November 2005

ISO 27001 : Information Security Management...

What Is ISO 27001?

ISO 27001, titled "Information Security Management - Specification With Guidance for Use", is the replacement for BS7799-2. It is intended to provide the foundation for third party audit, and is 'harmonized' with other management standards, such as ISO 9001 and ISO 14001.

The basic objective of the standard is to help establish and maintain an effective information management system, using a continual improvement approach. It implements OECD (Organization for Economic Cooperation and Development) principles, governing security of information and network systems.


This particular standard defines and specifies an 'Information Security Management System', known as an ISMS. It compliments the existing ISO 17799 security standard, and specifies a general framework for the creation and maintenance of the security process within an organization.

These two standards (ISO 17799 and ISO 27001) are closely related, and although their scope is wide, they have very distinct roles.

ISO 27001 defines the overall requirements for the security management system itself, the focus being on management. It is this standard, rather than ISO 17799, against which certification is offered. It was based upon an earlier standard, known as BS7799-2, but has been more closely aligned with other quality management standards.

09 November 2005

The Risk of 4GW: It's Here to Stay...

In today's OSAC 20th Annual Briefing at the U.S. State Department Bureau of Diplomatic Security we witnessed some excellent briefs from corporate CSO's and keynotes from Sandy Weill, COB of Citigroup and Dr. Condoleeza Rice, U.S. Secretary of State.

All had the theme of the day, the valuable and lasting public private partnership established twenty years ago by former U.S. Secretary of State George P. Shultz. There was much talk of the current risk of Fourth Generation Warfare (4GW), the same method of guerilla warfare described in The Sling and the Stone. In the middle of the presentations, many of our PDA's and phones began their vibrations and buzzing. Within a few minutes, the podium was announcing the latest attack on our own corporate assets in the capital of Jordan.

At least 57 people were killed and more than 100 injured when suicide bombers blew themselves up at three hotels in Amman, the capital of Jordan.

The hotels were popular with foreigners and many of the guests were involved in work in Iraq. The attacks destroyed the fragile calm that Jordan has enjoyed despite its proximity to Iraq and the support of its ruler, King Abdullah, for American and British policy in Iraq.

Major Bashir al-Da'aja, a police spokesman, said: "There were three terrorist attacks on the Grand Hyatt, Radisson SAS and Days Inn hotels and it is believed that the blasts were suicide bombings." Said Darwazeh, the health minister, said there were more than 50 dead but the toll could rise.


The Overseas Security Advisory Council (OSAC) now claims over 3,000 U.S. companies, educational institutions, religious groups, and non-governmental organizations as members known as constituents. Although OSAC is rarely in the limelight, the ways in which it helps American businesses fight terrorism abroad is unparalleled.

Is that a "Predator" taking off?

Mission

The MQ-1 Predator is a medium-altitude, long-endurance, remotely piloted aircraft. The MQ-1's primary mission is interdiction and conducting armed reconnaissance against critical, perishable targets. The MQ-1 Predator carries the Multi-spectral Targeting System with inherent AGM-114 Hellfire missile targeting capability and integrates electro-optical, infrared, laser designator and laser illuminator into a single sensor package. The aircraft can employ two laser-guided Hellfire anti-tank missiles with the MTS ball.


Tomorrow, in our second day of the OSAC briefing the room will be missing many of the constituent members as they begin the investigations and deploy new resources in the pursuit of justice.

01 November 2005

Online Pharmaceutical Counterfeiting: The Digital Threat...

Pharma healthcare companies all over the globe are working hard to identify counterfeit drugs and to put these criminals out of business. This operational risk strategy saves countless lives each year. The first article in a series on counterfeiting at CSO Online misses a key focus on the Internet Channel of Distribution. In order to pursue this growing threat, organizations must consider the use of real professionals to deter, detect, defend and document effectively in order to have a comprehensive anti-counterfeiting program.

The continuing growth of the Internet provides counterfeiters with ready access to unsuspecting consumers. Since goods purchased via the Internet are normally delivered through the conventional mail system, they frequently by-pass national regulations for the distribution of controlled goods.

The use of intelligent Internet surveillance with proprietary software, enables the detection of illicit distribution, trademark abuse, objectionable association and counterfeit activities, which can then be countered in a highly focused manner.

Authentix identifies client products on sale from suspect counterfeit sources, retrieves them anonymously and tests them for authenticity. In cases of minor misdemeanors they issue Cease & Desist letters for clients and monitor compliance. Where counterfeit or diverted product is retrieved, they support our clients through legal remediation by maintaining a documented chain of evidence.


All of the forensic markers and post testing due diligence will not stem the tide of bogus pharma web sites selling counterfeit drugs. An effective corporate risk intelligence process combines both the low tech (HUMINT) sources and the high tech methods (DIGITAL SURVEILLANCE) from a single entity. Only then will the data fusion and correlation of information allow for a legal, competent and rapid interdiction of this lethal threat.

Counterfeit medicines are a global scourge. The World Health Organization (WHO) estimates that as much as 10 percent of the half-trillion-dollar pharmaceutical market is counterfeit. In some developing countries, more than half of the drug supply may be fake. Every year, thousands die from ingesting fake medicines, many of which have been produced in squalid conditions using ingredients such as boric acid and highway paint.


28 October 2005

Zombies Being Hunted: Trick or Treat?

The FTC and Microsoft are going Zombie Hunting just in time for Halloween.

"The widespread use of zombie computers to commit crimes over the Internet presents a very real danger to law-abiding computer users," said Tim Cranton, the director of Microsoft's Internet Safety division.

Earlier this year, Cranton said, Microsoft set up a "clean" PC, then infected it with malicious code commonly used by attackers to turn a computer into a zombie. Researchers then monitored the PC's use of the Internet for 20 days, and tallied the number of messages sent through it.

"In those 20 days, this one computer received 5 million connection requests from spammers, and sent 18 million spam messages," said Cranton.

That amount of data was impossible to analyze, so Microsoft focused on the three most-active spamming days, when 470,00 connection requests were made of the PC, and about 1.8 million messages were sent through it.


OnGuard Online has been launched to help consumers and business become more aware and educated on digital threats. This site is in collaboration with private industry and:

U.S. Department of Homeland Security
U.S. Federal Trade Commission
U.S. Postal Inspection Service
U.S. Department of Commerce

There is a whole of common sense here yet it is encouraging to see that the Fed's are now acknowledging that ID Theft is out of control. The financial services industry is certainly at risk as long as consumers are banking online and using their PC's to pay their bills.

If haven't already, you should consider signing up for alerts from US-CERT.

25 October 2005

The Risk of A Blueprint For Action...

Now that Tom Barnett has released his newest book, Blueprint For Action: A Future Worth Creating it will be interesting to see the outcome.

However, before we make any comments or offer our own analysis, we are going to finish the entire book. Page 33 of 362. Stay tuned.

In the mean time, you can visit his web site and blog to find out more about his journey.

24 October 2005

Hurricane Risk: Floridians Take On Another Cat. 3...

The residents of Florida have learned some lessons over the past 14 months about preparedness. They have just been blasted by another Category 3 storm with over a month left to the end of the season. The estimates are now coming in that Wilma will have a significant impact with over $5B. in insured damages.

Hurrican Wilma came ashore with winds of 125 mph near Cape Romano, about 20 miles south of Naples, at about 6:30 a.m. local time. The coastal parts of Collier County, which includes Naples and nearby beach resort Marco Island, haven't been hit by a hurricane since 1960.

The state was hit by a record four hurricanes last year, causing a combined $22.9 billion in insured damages. Charley accounted for $7.5 billion, Ivan caused $7.1 billion, Frances resulted in $4.6 billion and Jeanne left $3.7 billion in insured damages.

Hurricane Katrina, which struck the U.S. Gulf Coast in August, is expected to be the most costly U.S. disaster for insurers. Storm modeler Risk Management Solutions Inc. estimated $40 billion to $60 billion in claims, as much as three times the $20.8 billion produced by Hurricane Andrew, which hit Florida in 1992.


In the wake of Hurricanes Katrina and Rita, hospitals across the United States of America are re-evaluating their disaster recovery plans. VHA, the national health care alliance, surveyed member hospitals across the country, and nearly half of those who responded are planning to modify their disaster plans - changing their evacuation plans, seeking alternative communication systems and preparing for extended periods of self-sufficiency.

More than 350 hospital leaders and managers, ranging from chief executive officers and chief nursing officers to materials managers, pharmacists and emergency department coordinators, responded to the VHA survey. According to respondents, nearly half (48.2 percent) are planning to change their disaster recovery plans.

Here are a few reminders for getting your Business Ready:

1. If you rent, lease or share office space, coordinate and practice evacuation and other emergency plans with other businesses in your building or facility.

2. Conduct regularly scheduled education and training seminars to provide co-workers with information, identify needs and develop preparedness skills.

3. Include preparedness training in new employee orientation programs.

4. Do tabletop exercises with members of the emergency management team. Meet in a conference room setting to discuss individual responsibilities and how each would react to emergency scenarios.

5. Schedule walk-through drills where the emergency management team and response teams actually perform their designated emergency functions. This activity generally involves more people and is more thorough than a tabletop exercise.

6. Practice evacuating and sheltering. Have all personnel walk the evacuation route to a designated area where procedures for accounting for all personnel are tested. Practice your “shelter-in-place” plan.

7. Evaluate and revise processes and procedures based on lessons learned in training and exercise.

8. Keep training records.

21 October 2005

Phishing: The Takedown...

Why Phishing Incident Response Plans May Not Be Optional.

The Treasury Department’s Office of the Comptroller of the Currency issued a bulletin in July that outlines the steps banks should take to mitigate the risks of phishing. Among other things, national banks were told they must file suspicious activity reports, or SARs, if they are the target of a spoofing incident.

Last December, the Federal Deposit Insurance Corp. issued guidelines for how financial institutions can mitigate phishing risks. The document warns that “the financial service industry’s current reliance on passwords for remote access to banking applications offers an insufficient level of security” and describes better options, such as two-factor authentication.

Phishing as a operational risk to an institution requires effective deterence as well as detection. These comments from a recent article at CSO Online paint the picture about why a takedown is a necessary response to a phishing incident.

The Takedown
The window of opportunity for a phisher is the time between when a phishing e-mail goes out and when the fraudulent website collecting information is taken down. Left unchecked, a phishing site may stay up for days or even weeks, as information trickles in from dawdling customers who've fallen for the scam. A good takedown process can slam that window shut within hours.


Nowadays, the attempt to do a takedown is standard fare—so standard, in fact, that the Treasury Department's Office of the Comptroller of the Currency has issued guidelines about the steps banks should take to disable spoofed websites. (Takedown, which essentially just relocates the problem, may be the only defense that the targeted company has. Prosecutions of phishers have been next to nonexistent, due to the difficulty of tracing how personal information has been captured, sold and exploited.)


As this article mentions, their are several very reputable firms who can assist you with the takedown. It may be even more important to have a 24 X 7 detection service monitoring the Internet for new web sites popping up and to get you ready for the barrage of spam e-mail onto the net to spoof your unsuspecting consumers. For more information on this, see Cyveillance.

Another important note is the PR and communications crisis management that is necessary to keep customers informed, the public aware of your Anti-Phishing strategy and more. You see, at the end of the day 99% of online banking customers won't leave you because you had an incident. They will leave you if you don't handle the response correctly.

17 October 2005

Corporate Governance: Deja Vu...

This is another sad story of Operational Risks far from being managed or in this case even considered when so many "Red" flags were waving in the wind.

NEW YORK, Oct 17 (Reuters) - Financial services companies beware: The fast meltdown of futures and commodities broker Refco Inc. (RFX.N: Quote, Profile, Research) may cause investors to think twice before making bets on similar types of ventures.

The crisis at Refco in the past week has happened even as new U.S. financial reporting rules and increased auditor oversight -- the result of a wave of scandals at companies such as Enron and WorldCom in 2001-2002 -- were supposed to have better protected shareholders from such debacles.

There have also been plenty of hard looks at the behavior of executives throughout corporate America in recent years, as witnessed by the high-profile criminal trials of one-time highflyers like WorldCom's Bernard Ebbers and Dennis Kozlowski of Tyco International Ltd. (TYC.N: Quote, Profile, Research)

Still, New York-based Refco's former chief, 57-year-old Briton Phillip Bennett, managed to escape heavy scrutiny while building up Refco and even during its initial public offering of shares.

He was charged with securities fraud last week over allegations he hid about $430 million in company debt. Bennett's lawyer has said there is "no justification" for his client's arrest.


This one has lot's of people sick to their stomach and more are going to be checking in to the local clinic before this one is over. Everyone will be pointing fingers and wondering why SOX didn't save the day. The truth of the matter is Mr. Bennett is a true master at "Social Engineering" and was able to use his power to do the same thing that others in a position like his have done in the past. The finance industry is built on trust and this will be another lesson on why due diligence on a 24 x 7 basis is a harsh neccesity.

11 October 2005

The Impact of Katrina: A Look Into The OPS Risk Crystal Ball...

The impact of hurricane Katrina is only beginning and it's easy to see how many institutions may be starting the battle with their insurance companies.

These "Expected" external events the likes of Katrina and Rita have impacted about 280 financial institutions in the Gulf Coast of the U.S.. These institutions represented around $270B. in assets and many are now looking to the insurance industry for payouts on those policies that transfered some of their risks.

Looking into the crystal ball, let's consider the public testimony of Steven G. Elliott, Senior Vice Chairman Mellon Financial Corporation before the Subcommittee on Financial Institutions and Consumer Credit Committee on Financial Services - U.S. House of Representatives in 2004:

"Banks should view risk mitigation tools as complementary to, rather than a replacement for, thorough internal operational risk control. Having mechanisms in place to quickly recognize and rectify legitimate operational risk errors can greatly reduce exposures. Careful consideration also needs to be given to the extent to which risk mitigation tools such as insurance truly reduce risk, or transfer the risk to another business sector or area, or even create a new risk (e.g. legal or counterparty risk)."

"Investments in appropriate processing technology and information technology security are also important for risk mitigation. However, banks should be aware that increased automation could transform high-frequency, low-severity losses into low-frequency, high-severity losses. The latter may be associated with loss or extended disruption of services caused by internal factors or by factors beyond the bank’s immediate control (e.g., external events). Such problems may cause serious difficulties for banks and could jeopardize an institution’s ability to conduct key business activities."


While overall the Fed and the institutions resilience is to be commended compared with other major critical infrastructures such as the Energy sector, we still have a long way to go with contingency planning. The regulators and insurance industry is looking at Business Crisis and Continuity Management with a new found diligence especially with the institutions outsourcing and supply chain partners.

Outsourcing of activities can reduce the institution’s risk profile by transferring activities to others with greater expertise and scale to manage the risks associated with specialized business activities. However, a bank’s use of third parties does not diminish the responsibility of management to ensure that the third-party activity is conducted in a safe and sound manner and in compliance with applicable laws. Outsourcing arrangements should be based on robust contracts and/or service level agreements that ensure a clear allocation of responsibilities between external service providers and the outsourcing bank. Furthermore, banks need to manage residual risks associated with outsourcing arrangements, including disruption of services.


Beyond the impact of Katrina, talking and listening to the OCC, FDIC and the Federal Reserve this week at the Risk Management Association (RMA) Annual Conference in Washington, DC produced some additional views and questions in the operational risk crystal ball:

1. Regulators are reinforcing the need for a comprehensive risk framework.

2. Does the amount of capital that I hold support the risks that we are engaged in?

3. Does our institution have excess capital?

4. How do I differentiate our risks by industry or geography to address concentrations and impact from cycles?

5. How do I integrate risk management into the Strategic Planning Process to make sure the methodology is understood and objectives are being communicated from the Board?

There must be the development of new risk management models that allow for the addition of new risk events and the elimination of those factors that may no longer be relevant.

07 October 2005

The Risk of Pandemic: A Global Threat...

Pandemic: A Worldwide Outbreak of Influenza is now getting attention on many global fronts including a plea by U.S. President George Bush to vaccine manufacturers to step up their production and R & D. In recent weeks, senior officials here have embarked on a public information campaign, warning of the possibility of a lethal pandemic which could claim millions of lives.

Mr Bush has even suggested that the US military would be used to quarantine affected areas of the United States in the event of an outbreak. What exactly is a pandemic?

An influenza pandemic is a global outbreak of disease that occurs when a new influenza A virus appears or “emerges” in the human population, causes serious illness, and then spreads easily from person to person worldwide. Pandemics are different from seasonal outbreaks or “epidemics” of influenza. Seasonal outbreaks are caused by subtypes of influenza viruses that are already in existence among people, whereas pandemic outbreaks are caused by new subtypes or by subtypes that have never circulated among people or that have not circulated among people for a long time. Past influenza pandemics have led to high levels of illness, death, social disruption, and economic loss.


And where there is a threat like this, the criminal minds begin to see opportunity for unsuspecting prey. Roche is now on alert and you should be also.

Swiss drug maker Roche urged consumers on Friday not to buy its flu drug Tamiflu over the Internet to avoid the risk of purchasing potentially counterfeit pills as they build stockpiles in case of a bird flu pandemic.

With experts predicting that millions could die if the bird flu strain H5N1 mutates into a human flu virus, some consumers appear to be building up their own reserves of the drug, doubling up on governments' efforts to prepare for a pandemic.

05 October 2005

CyberCrime: What is the Real Truth?

The CSI/FBI Computer Crime and Security Survey is now published and some of the results are enlightening to say the least.

Since this is not a research paper, we can't publish the statistics of our main interest in the survey. Please see Table 1 on Page 14 for the next comment to have any relevance regarding the percent of respondents who "Don't Know" how many incidents they have encountered.

If one quarter don't know the number of security incidents, then that is around 175 companies who are flying blind or don't care about measuring the frequency, nature or cost of breaches. This is why we don't buy the general trend in Figure 14 that attacks or misuse detected are declining over the past 12 months.

27 September 2005

Rita and The Suicide Bomber...

Now that the U.S. is dealing with the aftermath of a Category 3 hurricane "Rita" and the U.K. is analyzing it's response to the 7/7 "Suicide Bombers", what operational risks do they have in common?

The answer is plain and the truth hurts. There is no stopping either threat and they will always find a way to inflict significant losses to our property and human lives. These threats are at opposite ends of the spectrum however when it comes to the event itself.

One attacker is tracked and shown on national television as it grows and bears down on it's next target. We know when and where. The other attacker is hard to detect in advance and operates in stealth. Now the question again is, what do they have in common? In both cases, we know they are coming again.

Our preparation and planning for the next incident itself, using a myriad of scenario-based exercises or tests can assist those who deter and detect these threats as well as those who will be tasked to alert or defend and help recover from the next one. These are both risks that you can help mitigate the consequences and the impact although one could argue the likelihood is inevitable and increasing.

What is less predictable is human behavior. The emotions, actions and attitudes of dozens, thousands or millions of people can't be predicted. One can only learn from these events and over the course of history, establish a baseline of knowledge. The next incident will be different and it will have some of the same characteristics.

Human behavior is the key to our greatest risk management challenges. Both the U.K. and the U.S. have seen the pictures of bomb and hurricane casualties in the past three months. Human behavior in one case has the attributes of a well-trained and coordinated response. The other case is rapidly becoming a "Case Study" for those public servants who are learning what went wrong. While it's unfair to compare the scope of the two scenarios, it's obvious that we still don't have a firm grasp on human behavior.

23 September 2005

Survive: A Strategy for Every Business...

Well over two years ago upon our founding, 1SecureAudit joined a global organization of people who really "Get it". Who understand and demonstrate the necessity and true philosophy of Business Crisis and Continuity Management. Is your U.S. institution a member? Do you have top executives who are contributing strategic resources and knowledge to the survival of your business? Ignoring the multitude of significant threats and business disruptions to your enterprise is nothing less than a lack of corporate strategy for long term survival.

Launched in 1989, Survive has since grown throughout the world to become the leading forum for expertise and information exchange among business continuity management practitioners and professionals, and all managers and directors with responsibility for ensuring the resilience and ultimate survival of their companies.

Originally focused largely on the back-up and recovery of IT and communications systems, Survive is now the only organisation of its kind in the world addressing the continuity needs of the entire organisation.

Our members are concerned about everything from protecting the company data and staff safety, to safeguarding the reputation and value of the whole enterprise.

The demands are growing on public and private sector organisations to prove they have processes in place to maintain continuous impressive performance 365 days a year, regardless of unusual internal or external circumstances. Such demands can be almost impossible to meet. But through understanding how organisations of different shapes and sizes tackle the difficult issues, members learn how to build resilience into their businesses and how to make business continuity a core part of the their company culture.

Business continuity management is about not making excuses. It's about being wise before the event. It is a state of mind that understands great organisations never moan they didn't do well because of the state of the economy, a fire at the warehouse, an internal fraud, or a strike by a group of key workers. Great organisations do well anyway.


As another Category 4 hurricane bears down on the U.S. for the second time in a month, we can only hope that the business community in Texas is ready. Gods speed to the people of Houston and beyond.

21 September 2005

Adaptation + Visible OPS = Managed Change

Managing Complextiy and change in any enterprise is an Information Technology nightmare. Adaptive can assist you in managing change.

A picture is worth a thousand words.

A model is worth a thousand pictures.

An Adaptation is worth a thousand models.

The Zachman Framework™ is often mistaken by some to be a 6 x 6 matrix. We believe that it is not. We see it as a structured, multidimensional management framework that helps organizations plan, design and implement complex, adaptable information systems. Our view of the framework is shown in this Adaptive rotating hexagon.

We believe that the Zachman Framework guides an organization to define its own unique business and technology "language". This language answers the questions about Why, What, How, Who, When and Where related to an enterprise's strategies, business processes and a number of more concrete levels of an information technology architecture.

The Framework is designed so that people with different perspectives can communicate. The different user perspectives are analagous to those with any complex engineering scenario - "Planner", "Owner", "Designer", "Builder", "Sub-contractor" and the final result - "Operating Enterprise".


In this article from George Spafford he articulates the essence of change management in the IT worldview.

"Change is pervasive through the organization and has huge impacts on the operations of the business. People at all levels in IT must understand and value the fact that as the level of complexity increases in a system, the value of effective change management processes increases.

Studies have shown that 80 percent of the fires that IT fights and 80 percent of security breaches are caused by human error. The vast majority of the problems in IT, and thus for the overall organization, will arise from human limitations in the face of escalating systemic complexity."


For those of us who use and advocate "Visible Ops", here are 4 reminder steps to running more effective ITIL operations in your enterprise:

1. Stabilize the Patient

2. Catch & Release and Find Fragile Artifacts

3. Establish Repeatable Build Library

4. Enable Continuous Improvement

Visit ITPI for more.

19 September 2005

Reputation Risk: Is Murphy to Blame?

Any board member or executive today is well aware of the direct impact an adverse event or significant business disruption can have on shareholder value and customer confidence. When it does happen, how many people just throw up their hands and shout, Murphy's Law!

Murphy's Law ("If anything can go wrong, it will") was born at Edwards Air Force Base in 1949 at North Base.

It was named after Capt. Edward A. Murphy, an engineer working on Air Force Project MX981, (a project) designed to see how much sudden deceleration a person can stand in a crash.


Murphy is all about managing the "What if's" and planning for their possibility. Here is an example. Are you moving your business sometime soon? What is the possibility that when you do, you will be able to use your e-mail the day you open your new doors? More than one business has been subjected to the Law's of Murphy whenever a complex and logistical project or program is underway. If you are one of those corporate executives who has been unable to use your e-mail or web services the Monday after the big office move, you are not alone. The question is not that it could happen, it's what impact will it have on both customer and employee satisfaction the day it happens, and beyond.

This Corporate Board Member article sums up the impact of Reputation Risk on your organization.

While every Board member knows the importance of managing Enterprise Reputation Risk, the task seems overwhelming. Some Boards are not even trying to proactively manage the risk: their companies will be forced to rely on “reactive” measures after the Reputation Risk event has occurred. These after-the-fact public relations initiatives are expensive and often ineffective. And, since they are event-directed, they don’t provide an ongoing risk structure for the company to identify and control other issues which can cause Reputation Risk. Considering the enormous loss of both financial and franchise value which accompany Reputation Risk, is a Board which only reacts to risk events really doing its job?


In your future planning to mitigate the Operational Risks associated with Murphy and your reputation, we are reminded of a few of our favorite Murphy's Laws:

1. Computer systems are unreliable, but humans are even more unreliable. Any system which depends on human reliability is unreliable.

2. If there is a possibility of several things going wrong the one that will cause the most damage will be the one to go wrong.

3. A difficult task will be halted near completion by one tiny, previously insignificant detail.

4. High speed chases will always proceed from an area of light traffic to an area of extremely heavy traffic.

5. Every emergency has three phases: PANIC... FEAR... REMORSE.

Do you think you're spending too much time with your team planning? You haven't. Success in your organization doesn't happen because everything goes according to the plan. It happens because you were prepared when things go wrong. The organizations whose team has planned for every possible scenario and trained together in live simulations will become the most successful. Their missions will be accomplished on time and within budget.

Incidents of different severity and frequency are happening around you and your organization every day. Would your employees know what an incident looks like let alone know what to do next to mitigate the risk to them and the organization?

15 September 2005

The Global State of Information Security: Still Risky Business...

Operational Risks are rising and executives are more interested in preparing their employees for the next crisis.

In a recent worldwide study by CIO Magazine and PWC concerning their risks, thousands of security leaders are fanning the flames over so many breaches and so little insight.

The survey asked about next year's 2006 top priorities or To-Do List:

1. Business Crisis and Continuity Management

2. Employee Training and Awareness programs

3. Data Backup

4. Overall Information Security Strategy

5. Network Firewalls


The good news is that the budgets are finally rising in light of increased theft of intellectual property and identities along with other major information crimes. Budgets in 2005 are now 13% of the IT budget. Consolidation and compliance are issues to be managed however these have bogged down strategic initiatives for the future.

Even after spending in the billions, incidents are still rising and these are the sources of the attacks:

59% - Malicious code

26% - Unknown

25% - Unauthorized entry

21% - Denial-of-service


And what is the most enlightening or discouraging statistic from this group is the answer to the question: When an incident does occur as a result of an attack, who do you tell?

No One - 55%

Customers - 16%

Partners/suppliers - 14%


Is there some correlation between the 26% unknown sources of attacks and the 55% of the incidents where no one is told about it.

12 September 2005

The Paradox of Privacy...

The banking industry has much to do to overcome the flat curve for new online customers. If this latest Ipsos Insight Research is correct, then privacy remains a significant issue in the consumers mind.

The proliferation of "phishing" and highly publicized hacker tactics have thwarted industry efforts to convince customers that online banking is safe. Results of the survey include:

83 percent of survey respondents who conduct their personal banking online reported concerns over protecting their personal information from theft.

73 percent of people said personal information theft is a deterrent for them to use online banking survey respondents were equally concerned about banks selling their personal information to a third party, with 72 percent of respondents citing the issue as "extremely" or "very important."


Promising not to sell your information to third parties is only part of the problem. The financial institutions are still using direct marketers and other data mining companies to make sure their latest loan offer goes to the most qualified and relevant customer. In some cases, the banks are doing much of the analysis in-house and only sending the "Bulk Mailers" the correctly correlated data records.

This New York Times article, Europe Zips Lips; U.S. Sells ZIPs, by Eric Dash sums it up quite nicely:

One thing that both privacy cultures have in common is that it is becoming harder for either to control what is and isn't kept private. Information is increasingly the lifeblood of the global economy, not to mention the global fight against terrorism and the quarry of hackers.

As this year's data breaches and compromises have shown, no one really knows how safe the world's vast pool of confidential data is, and therefore how protected anyone is against an invasion of data privacy.

Mr. Reidenberg, the law professor, compares the current situation to the stock market meltdown after the 1929 crash. America responded then by creating the Securities and Exchange Commission and a host of financial disclosure and accounting reforms. The need to safeguard sensitive data, Mr. Reidenberg said, "will necessitate the United States focusing on the legal way we structure information processing, just like we needed to do in the 1930's to put the economy back on stable footing."


With Identity Theft and Money Laundering as the two top issues with almost every banking institution, you would think that these 3rd party mailers would be consistently monitored and audited just as the banks are. Nothing could be farther from reality.

08 September 2005

Corporate Social Responsibility...

Corporate Social Responsibility (CSR) is getting a real work out since our planet's latest natural catastrophe, Hurricane Katrina. Organizations and companies many of us have never heard of are contributing supplies, manpower and aid to the recovery of this key economic region of the U.S..

Social responsibility is a matter more companies are paying close attention to these days and the potential risk that a blind eye may have on the future performance of the institution. What is most interesting are the stories of corporate heroism coming out of the news reports that validates this thinking. And the reports of those organizations who have failed to answer the call to act in the best interest of their employees and customers.

The risk of failed processes and programs pertaining to social issues is a real threat to the faith people have in your company and your brand, even if they are not a customer today. Contingency planners understand the impact that adverse business disruptions can have on the performance of the company. Less known is the impact that a lack of social responsibility can have on the damage to the brand and reputation of the organization. Many will soon find out as the truth is told.


As the political lines are drawn in the sand, one can only wonder who the real heroes are going to be after this historical event is documented. The mothers, fathers, brothers and sisters. The grand parents and the aunts and uncles. Those who weathered the storm or evacuated in time to keep their loved ones out of harms way. Hundreds of thousands of their stories will never make it to the six o'clock news.

Corporate Social Responsibility spans the spectrum from the local Wal-Mart, Marriott and Bank of America to the corner grocery and gas station. Yet the real winners are those who continue to utilize their own talents and resources to contribute in some meaningful way.

01 September 2005

Begin the Lessons Learned...Again

In the aftermath of Hurricane Katrina, one can only wonder what will happen next. We are already questioning our abilities to respond. One thing is certain, this will not be the last hurricane of this season or the last crisis event facing the Homeland. In order to make sure that organizations and businesses are even more prepared for the near future and beyond, you must have the correct systems to support your worst case scenario and contingency plans.

EMAware is an emergency management system for agencies, jurisdictions and companies that need to control the flow of information before, during, and after emergencies. Using EMAware, organizations can manage inbound and outbound emergency messages and create workflow rules that automate the process of activating emergencies and notifying key staff and peer organizations.

EMAware allows you to:

* Automate maintenance of Emergency Action Plans
* Originate, receive and manage CAP and EDXL alerts
* Support staff training and testing
* Integrate siloed monitoring systems
* Manage geographically dispersed offices and mobile workforces


Total organizational awareness is critical in emergency situations. And behind the awful images of CNN live on location, are thousands of people and computers behind the scenes making the recovery even more effective. Our intelligence branches are using geo-spatial imaging to help coordinate search and rescue operations using satellite pictures. FEMA, the Red Cross and DHS are communicating over secure networks for voice, email and text messaging.

No country has the means to recover faster from a disaster of this magnitude than the United States of America. 9/11 is now in our thoughts again this week. Always remember.

31 August 2005

Corporate Emergency Response Teams...

1SecureAudit Joins Nationwide Coalition In Collaboration With The U.S. Department Of Homeland Security's National Preparedness Month

The company will join a wide variety of national, state and local organizations, including the U.S. Department of Homeland Security and the American Red Cross, in educating the public about preparing for emergencies.


For Immediate Release

MCLEAN, Va./EWORLDWIRE/Aug. 31, 2005 --- 1SecureAudit, an emerging leader in Operational Risk Management Solutions for the Financial and Healthcare Services Sectors, and its partners in a national coalition, today announced a free event that will describe the simple steps an organization can take to prepare for an emergency.

As part of a special effort during September, which is National Preparedness Month 2005, 1SecureAudit will join national, state and local organizations, including the U.S. Department of Homeland Security and the American Red Cross, in raising public awareness about the role of preparedness in protecting lives and property. Making an emergency plan, assembling an emergency supply kit and identifying community emergency-response resources greatly improve people's ability to survive a natural or man-made crisis.

"We're taking important steps to help organizations become even more educated, trained and better prepared, and we urge you to take time this month to do the same in your business," said Peter L. Higgins, managing director of 1SecureAudit.

On September 28, 2005, join 1SecureAudit at 1:00 p.m. EDT for a free online webinar to learn how to create corporate emergency response teams (CERT).
Produced in cooperation with Long Branch Systems, Inc. of Rockville, Maryland, and ABD Insurance and Financial Services of Redwood City, California, the web-based presentation will highlight tasks that a business can perform now, and issues that it must consider in the future as it develops a comprehensive all-hazards risk program.

Download Details

29 August 2005

Katrina: Category 4 Storm Blasts U.S....

Now that Hurricane Katrina has made landfall for the second time in the U.S., we are reminded of several important operational risk management topics.

If a third party service provider is being considered for the provision of critical information processing services, the organization requires outsourcing service providers to develop and establish a disaster recovery framework, which defines its role and responsibilities for documenting, maintaining and testing its contingency plans and recovery procedures. The vendor must review, update and test its business continuity plans regularly in accordance with changing technologies, conditions and operation requirements.

The organization must also be prepared for worst-case scenarios for service interruptions when a service provider is unable to continue operations or render the services required. The organization's business continuity plans must include additional vendors or in-house recovery procedures to resume information processing. Arrangements must be made to ensure continued availability of the information service in the event the third party service provider is unable to perform under their contract obligations.

Katrina's fury also was felt at the Louisiana Superdome, normally home of professional football's Saints, which became the shelter of last resort for about 9,000 of the area's poor, homeless and frail.

Electrical power at the Superdome failed at 5:02 a.m., triggering groans from the crowd. Emergency generators kicked in, but the backup power runs only reduced lighting and cannot run the air conditioning.

About 370,000 customers in southeast Louisiana were estimated to be without power, said Chenel Lagarde, spokesman for Entergy Corp., the main energy power company in the region.


Hibernia Bank, who is merging with Capital One and is in the path of Katrina has this to say about their BCCM operations:

Elevated back-up generators are in place to support the company's central processing operations in New Orleans in the event of a power outage in the city. Hibernia's operations centers in Houston and Shreveport are ready to serve as data back-up sites. In addition to providing contingency-planning support for the New Orleans center, the Houston center supports Hibernia's Texas operations.

"We constantly monitor the hurricane's track and communicate with emergency officials," said Herb Boydstun, president and CEO. "We have mobilized our people across Louisiana and in Texas to respond to storm-related issues."

Boydstun pointed out that Hibernia has comprehensive contingency plans designed to minimize disruption of service to its customers and to resume operations as soon as possible.

Employees are trained to transfer and recover systems, data and other vital components quickly. In Shreveport, the company has computers with redundant systems that can be activated in case of a New Orleans power outage. Hibernia maintains additional space in the Shreveport area that can quickly be converted to a technology center to support operations routed from New Orleans.


We wish them and all others in the New Orleans, LA and Biloxi areas Gods speed during these difficult days ahead.

26 August 2005

Safety & Security: Wi-Fi to the Rescue...

Have you ever wondered where high value assets are located in your facility or on your campus? Especially those that are mobile assets. Have you ever wondered who and where visitors to your offices are located at any given time? Now Ekahau is making the answers to these and other questions much easier and at a more rapid response. Safety, production costs, and time-to-market are vital points of consideration for industries such as oil refineries, chemical factories and other process-industry facilities. By being able to easily track people, vehicles, and assets, these factors can be made substantially more efficient.

Founded in 2000, Ekahau is the recognized leader in location-enabling enterprise Wi-Fi networks. Ekahau's mission is to provide the easiest, most cost effective and accurate positioning solutions for locating people, assets, inventory and other objects using wireless enterprise networks. The Ekahau solution tracks wireless laptops, PDAs, VOIP phones, Wi-Fi tags and other 802.11 enabled devices.

Ekahau’s solution allows businesses to keep track of valuable assets and equipment, improve the overall workflow, and improve the levels of corporate security and customer service. With Ekahau, the critical corporate resources, people and assets, will be always available at the right place and at the right time. As Ekahau's location tracking solution does not require installation of proprietary wireless infrastructure, but can be done individually over the private Wi-Fi network, the deployment cost is kept in minimum, and the overall system payback time is the fastest possible.


Safety and security applications are numerous especially in healthcare:

• Emergency management - more efficient and faster emergency response
• Patient monitoring - better patient safety and increased throughput
• Workflow management - better staff utilization and increased patient throughput
• Equipment management - reduced need for inventory
• Information delivery - improved workflow, reduced errors
• Billing support & verification - improved revenue capture

We can think of other homeland security and first responder applications using the Ekahau capabilities especially in post event incident management and key personnel tracking inside a closed perimeter. As WiMax and other 802.11 networks are deployed in major metro locations, the applications become wide spread.

22 August 2005

HIPAA: Outsourcing Protected Health Information...

At least in the U.S., the Department of Health and Human Services (HHS) is quite clear about Protected Health Information (PHI). What is personal or protected health information and under what circumstances as a business must you keep this information private?

Now let's introduce the offshoring or outsourcing component of running a data intensive and information centric business model. Healthcare is all about the collection, analysis and historical trending of data about our vital signs, symptoms, habits and test results. Where is all of that data being processed and stored from transcribed audio and visual media?

Most patients who visit the hospital probably do not spend too much time thinking what happens to information in their medical records after they leave, but in the age of outsourcing, the path of a patient's medical record can be a long and precarious one. Medical Data Theft is a growing concern.

Consider a recent case at a university hospital in California, where the doctor's notes from a patient visit were first sent to a transcription service company in Florida, which decided to subcontract to another firm in Texas. The Texas firm subcontracted the work yet again, ending up with a woman in Pakistan. This Pakistani woman became upset because her payments for her services were late, so she decided to send an e-mail to the university hospital, threatening to post the medical records on the Internet if she was not paid immediately. It might sound like a nightmare, but it is the reality of outsourcing today.

Medical records are secured under HIPAA standards, but when they leave the United States, these rules may not necessarily apply.


QUESTION: To what extent does the HIPAA Privacy Rule (the "Privacy Rule") govern contracts with foreign contractors and subcontractors?

Do you know that soon your PHI may be located in a Medical Information Bureau (MIB)? And in this case, it could be a real problem or as this scenario describes, it could kill you:

Here's the scenario. A bad guy steals your identity. He ends up in the hospital and pretends to be you. His medical history becomes a part of your "MIB identity, or Medical Information Bureau identity." You could end up being denied insurance -- or much, much worse. If you show up on the medical bureau as having heart disease or diabetes and then show up at the hospital unconscious, they might kill you trying to save you.

18 August 2005

Big Blue Gets Serious About ORM...

Big Blue is getting ever more serious about Operational Risk Management. Recently unveiled solutions for biometrics, enterprise risk management frameworks, and customer relationship management cater to their financial customers.

When IBM says listen, most finance sector CIO's stop in their tracks.

IBM demonstrated a "cancelable" biometrics system, in which a prearranged transformation algorithm intentionally distorts a person's biometric data, such as a fingerprint, rendering the original biometrics useless for identification purposes. The biometrics project was conceived out of a need "to make replacing biometrics as easy as replacing credit cards," said IBM researcher Nalini Ratha during a presentation at IBM's Industry Solutions Lab in Hawthorne, N.Y.

IBM detailed an enterprise risk-management framework intended to help financial institutions cope with a stream of regulations such as Basel II and the Sarbanes-Oxley Act. The central themes of the IBM approach are that risk and compliance need to be managed centrally, and that operational risk, such as the likelihood of losses due to unpredictable events such as natural disasters, needs to be modeled using probabilistic means. IBM tested the risk framework during its own Sarbanes-Oxley compliance process, which involved almost 10,000 financial-control points.


As a public company, they are the perfect lab for testing their own systems and solutions, especially when it comes to regulatory compliance issues. The question remains whether the SOX process at IBM will produce positive outcomes. Time will tell. Even more interesting is their approach to "cancelable biometrics". The financial industry is under new pressure to solve some of the operational loss events due to unauthorized access. Authentication using more than a User ID and password is gaining momentum as a result of new focus by the banks to stem the millions of dollars they are losing each month. This solution tries to address the privacy issue for consumers feeling their data is safe and to thwart the value to hackers gaining access and utilizing your personal biometric for fraudulent purposes.

IBM's system wouldn't entirely solve the replaceability problem of biometrics: If a hacker got hold of a user's fingerprint and made a passable model, he could still wreak havoc with it. What IBM's technology could do, however, is significantly narrow hackers' opportunities to gain access to such data. If a user's fingerprints (or facial photographs, iris scans or any other biological marker) aren't stored in any of the systems she uses them to access, cracking those systems won't give the hacker keys to the victim's biometric kingdom. If a hacker did get in - and the frequency with which companies sheepishly confess to database hacks and inadvertently exposed personal information illustrates the reality of that risk - IBM's system would let a user quickly cancel the compromised biometric profile and generate a new one, akin to replacing a lost or stolen credit card.


The cryptographers think they have found irreversible algorithms to make this commercially feasible. We wish this becomes a reality.

15 August 2005

ISO 17799: Culture Sensitive Best Practices...

“Unlike ISO 17799, however, the SAS 70 is not a "best practices" standard. Instead, it documents the controls in place that satisfy the company's internal control objectives.” This CSO's worldly insights could not be more true.

Implementation of 7799 standards and a comprehensive ISMS provides your organization with a security & privacy governance framework… a one-stop best practices solution for cultural security and privacy issues across the globe. Measuring documented controls across Lines of Business and International Business Units requires a single benchmark. Without a pervasive global information security standard within the organization, employees and management can’t determine if they are improving, or where they are most vulnerable to new threats. Auditors can’t certify if controls are working without a published and well-established set of processes and procedures for checking the validity and evidence of information security.

CSO’s facing a myriad of new Operational Risks are quickly adopting the use of thoroughly tested or proven controls and best practices that span countries and cultures. More importantly, they have also discovered that supply-chain risk extends the reach of their management systems well beyond their own boardroom.

11 August 2005

OREA: Operational Risk Enterprise Architecture

What impact does change have on Operational Risk? As Boards of Directors and Executives try to cope with increased market competition, organizational restructuring and mergers or acquisitions; complexity becomes exponential. Change has a monumental impact on risk exposures and consequences.

Adaptive continues to be a leader in the creation of effective Enterprise Architectures to manage risk on a global scale.

Many organizations have difficulty effectively tracing how their strategies are implemented and how resources are used across the organization. Every year, millions or even billions of currency is lost on mismatches between strategies, processes, performance targets, roles and responsibilities, human resources, IT applications and projects to improve all these.

Top executives recognize that effectively managing an organization requires a clear understanding and alignment of several key factors. However, they typically lack the tools they need to manage the complexity involved. This is where Adaptive's Top Slice Architecture comes in.

To continuously adapt to their changing environments, executives must know about, keep in balance, and communicate several things:

What exactly are the strategies of the organization and how should they be implemented? (Strategy Development and Organizational Change)

What are the processes the organization executes, how are they integrated, and how do they contribute to the strategy of the organization? (Business Process Management)

How are human resources being utilized and whether there is optimum use of skills and resources available across processes and functions? (Human Resource Management)

To what extent is the organization chart a proper reflection of appropriate roles and responsibilities, in order to effectively and efficiently carry out all work?(Organization Management)

What IT applications are available in the organization, how do they interface and what processes and functions do they support? (IT Portfolio Management)

How does the performance of each process, each function and each individual add up to the organizationÂ’s performance? (Performance Management)

What projects are currently underway, how do they effect and impact change, what processes and IT applications do they change and how does this contribute to the strategy of the organization? (Project & Program Management)


Companies who are in highly regulated industry sectors are perfect examples of organizations who must rapidly adapt to new laws, government mandates and must remain proactively compliant. How can you effectively keep pace in managing risk without an Enterprise Architecture? Simply stated: It's literally impossible.

Can you visualize how information flows through your organization? In order to report new information to regulators you first have to know what applications and databases are impacted by the new law or a request for additional data. Without a repository of metamodels to start with, you won't know where to begin.

In the context of Operational Risk Management, Enterprise Architecture enables the construction of end-to-end visualization of the information flows from any point (e.g. origin, final report, any intermediate point), in a form suitable for both business and technical users: and also allows the linkage of the technical definitions to business term descriptions.

If your Operational Risk professionals are not working side by side your Enterprise Architects, maybe it's time you booked that conference room for a few weeks.

09 August 2005

US National Security: Critical Infrastructure Protection...

Now that InfraGard has a Memorandum of Understanding with DHS, only time will tell what impact the new formalized relationship will have on national preparedness.

WASHINGTON--(BUSINESS WIRE)--Aug. 8, 2005--InfraGard National Members Alliance (INMA) today announced it has struck an official Memorandum of Understanding (MOU) with the Department of Homeland Security (DHS) Private Sector Office (PSO) regarding a Strategic Partnership. The announcement was made at the 2005 "InfraGard Congress," InfraGard's annual business meeting, which is taking place today at the JW Marriott in Washington D.C.

The purpose of the MOU between InfraGard and DHS is to outline the objectives of a Strategic Partnership between the two parties, as well as their related roles and responsibilities. A Strategic Partnership between InfraGard and DHS will provide both organizations with the opportunity to develop and cultivate existing relationships between the government and the private sector in an effort to engage private sector subject matter experts for the protection of our nation's critical infrastructure.

"InfraGard highly values its MOU with DHS, and is looking forward to engaging our local members with DHS leadership to identify issues and develop programs to address them," said Dr. Phyllis Schneck, chairman of the Board of Directors, InfraGard National Members Alliance. "DHS has expressed interest in InfraGard's success in engaging subject matter experts in all 50 states across all 14 critical infrastructure sectors to build trusted relationships with Federal, state and local law enforcement and government agencies. Additionally, the relationship between DHS and InfraGard is critical as our membership grows to serve as the primary liaison between private sector and all areas of government and law enforcement."

The joining of forces between InfraGard and DHS will enable both organizations to raise security awareness more effectively in communities across the country. Through National and local events coordinated by InfraGard across its 84 chapters, DHS leadership will have a forum to better inform the business community about homeland security programs and initiatives. In turn, the private sector will have a channel via InfraGard to communicate its issues to DHS, and also provide direct feedback about DHS initiatives.


FBI Director Mueller's keynote is another indicator that public / private cooperation is essential to the government in order to protect our vital national assets.

"Director Mueller's participation in the InfraGard 2005 National Conference is proof positive of the significant role InfraGard has played in National security. Furthermore, thanks in large part to InfraGard's vision and dedication, law enforcement agencies across local, state and Federal levels actively are and will continue to work together to secure the United States from threats to its critical infrastructure."

In addition to Mueller's keynote at the InfraGard 2005 National Conference there also will be tracks and technical sessions dedicated to the following topics: Drinking Water Security; Maritime and Port Vulnerabilities and Security; Computer Forensics; Cyber Security; First Responders; Financial Institution Security; Regulatory Compliance; and Supervisory Control and Data Acquisition (SCADA) Systems.

08 August 2005

Healthcare Risk: Counterfeiting & Online Pharmacies...

Pharmaceutical companies are on the offensive along with the FDA to rid the Internet from bogus Online Pharmacies.

The continuing growth of online pharmacies provides dealers and counterfeiters with ready access to unsuspecting consumers. Since goods sold online are typically sent through the conventional mail system, they frequently by-pass national regulations for the distribution of controlled goods.

Jim Kouri's thoughts on this subject are correct:

Those Americans demanding the US government to allow citizen's access to foreign prescription drugs should heed the concerns of the world's foremost health organization. According to the World Health Organization's definition a counterfeit medicine "is one which is deliberately and fraudulently mislabelled with respect to identity and/or source. Counterfeiting can apply to both branded and generic products and counterfeit products may include products with the correct ingredients or with the wrong ingredients, without active ingredients, with insufficient active ingredients or with fake packaging."

It is estimated that one in 20 pharmaceutical products on the market is counterfeit, with the number rising to one in three in some developing countries.

Counterfeit pharmaceuticals are manufactured and distributed by criminals, companies or individuals who have the desire to make money unlawfully. They may contain too much, too little or no active ingredient, the wrong ingredients or high levels of impurities, contaminants and even toxic substances. They could be reject or out-of-date formulations withdrawn from the market which are obtained by counterfeiters, relabelled as bona fide product and introduced back into circulation. They have killed and injured thousands around the world.


The use of effective operational risk mitigation strategies for Pharma and Healthcare companies, enables the detection of illicit distribution, trademark abuse, objectionable association and counterfeit activities, that can then be countered in a highly focused manner. The outcomes can save lives and millions of dollars per year.

For a list of Certified Online Pharmacies see:
VIPPS Program

For more information on this health care risk see:
Safe Medicines

05 August 2005

ORM for Board Directors: 4D Risk Strategy...

Savvy Operational Risk Management Executives and Audit Committee Directors should ask themselves the following questions:

Do we have the management systems we require to audit compliance, risk, and claims data?

Are the corporate data collection systems automated?

Are we in compliance with state and federal regulations affecting my industry?

How do we merge data from internal and external sources so it provides me with a holistic view of risk?

How do we easily compare data across Lines of Business?

How do we chart risk exposures in real-time for the company as a whole?

How do we access our audit information in the organization?

In our current threat environment, interested parties inside and outside of an organization are demanding more accountability from Board Directors to handle all facets of Operational Risk Management (ORM). This cannot happen until there is a clear understanding of the different types of risk that could impact the company as well as the consequences and frequency.

In order to survive, corporations need a "4D Risk Strategy". Only then, can any of these questions begin to be answered with any certainty.

02 August 2005

National Preparedness Month 2005 Coalition Members...

NATIONAL PREPAREDNESS MONTH 2005 COALITION MEMBERS
AS OF August 1, 2005

The U.S. Department of Homeland Security and the American Red Cross are working with a wide variety of public and private sector organizations to educate the public about the importance of emergency preparedness. Throughout September, these organizations will provide information, host events and sponsor activities that disseminate emergency preparedness messages to and encourage action in their customers, members, employees, stakeholders and communities across the nation. Below is a listing of the 166 members of the 2005 National Preparedness Month Coalition as of August 1, 2005.

Click Here to Join the National Preparedness Month Coalition Members

1SecureAudit is hosting a Webinar in collaboration with Long Branch Systems and ABD Insurance, Inc. on September 28th, 2005. We hope you will join us!