01 February 2006

Internet Crime Pandemic: The Botnet Outbreak...

If you thought that your INFOSEC team was busy last year, they haven't seen anything yet. The rise of Trojans & Botnets is becoming an Internet Crime Pandemic.

"Cyber-crime nowadays takes many forms, and perhaps even more dangerous than botnets are the targeted attacks that we have witnessed recently," explains Luis Corrons, director of PandaLabs. "The biggest problem lies in their secrecy: a large company could be serving the interests of a group of malware creators without realizing it. Many of their computers could be at the disposal of these cyber-crooks, with all the legal implications that this might have for the company itself." Until now it is a risk that companies have not considered sufficiently, but one which is no longer possible to ignore."


Most of the successful attacks exploit the most vulnerable facet of every companies defense. It's people. Targeting executives within a specific industry group such as the savings and loan sector is a good example. The global marketplace for reselling data about people is now showing exponential growth. Once the executive clicks on a link inside what looks like a legitimate email he has opened his network to a potential new "Zombie".

Why do the spammers, pharmers and spear phishers continue to invest in these types of attacks? It's good for their criminal business.

The FBI recently snared a 20-year-old hacker (Jeanson James Ancheta) whom they believe wrote computer code to assemble botnets and sell access rights after he was lured into a trap. Ancheta in his plea accepted responsibility for selling botnets and directing zombie machines to surreptitiously download adware besides intruding into government computers.

Ancheta is understood to have as a result benefited by $3,000 from botnet sales and $60,000 from the clandestine adware downloads. With close to 400,000 machines under his control, Ancheta was doing well enough to gift himself a BMW.


28 January 2006

Travel Threat: Executive Operational Risk...

Operational Risk Management is a vital component for any Board Member or Corporate Manager who travel internationally.

Company executives who travel extensively on commercial airlines are constantly being subjected to a spectrum of new threats. The latest concern is putting executives in potential harms way with the rise in Avian Flu.

Once these highly compensated and important corporate officers reach a cities destination, there is of course the choice of hotel. Where and where not to stay is now a question many corporate travel departments are asking themselves. How do you know what is the most secure and safe place to stay?

Stratfor provides substantive tips and advice from their intelligence and publications. Terrorist attacks in past years against U.S., Israeli and Australian embassies forced Western countries to harden their diplomatic compounds abroad, turning them into veritable fortresses of security. In response, terrorists began focusing on softer symbols of Western influence, such as large hotels and resorts. By attacking a Marriott, a Hyatt, a Moevenpick or another popular Western chain, the perpetrators can cause mass casualties and gain international media attention -- and all without having to penetrate extreme security.


As a saavy travel department and global corporate security chief already know, there are some other choices that should be considered namely, iJet:

iJET was incorporated in 1999 with a mission of protecting international travelers through the use of our proprietary technology and services platform. That mission has evolved and broadened over time as our Worldcue® Risk Management System has been applied to protecting both employees and other assets of multinational corporations. Today, iJET has over 350 corporate clients that rely on iJET to monitor, protect, and respond to operating risks around the world.

The escalation of terrorism, infectious diseases, and unforeseen natural disasters has forced multinational organizations and their employees to re-evaluate their perception of risk. Such events are often beyond a company's control, yet corporate liability and responsibility to employees and assets continues to increase. As a result, corporations need a fresh approach and new set of tools to meet the operational risk management demands in today's business environment.


This part of the equation is an easy one. Get real-time intelligence while on the go and utilize strategic tools and solutions for risk mitigation along the way. Moreover, travel light and without a huge entourage of large NFL size body guards in tow. You might as well paint a bulls eye on your back.

The hard part of the equation is getting your executives and highly valued employee assets trained and ready. Having all of the "What Could Happen" and "Be Careful of" in your head will not be enough unless you train, practice and test. Many global companies are doing just that, training their employees in threat detection and giving them new skills and strategy to save themselves from potential attacks of all kinds. See Threat Detection and Management to learn how.

24 January 2006

Supply Chain Risk: Spending Time with The Right People...

What is the largest obstacle within your organization to address risks such as corporate fraud, natural disasters and disruptions to your supply-chain?

According to top responses in a recent poll of 600 financial executives accross the United States, the UK and Europe:

33% - Insufficient Time

23% - Inadequate Personnel

19% - Insufficient Budget

13% - Not Viewed as a priority


Does this mean that the Board of Directors has transfered risks using vehicles like insurance? The same study asked what percentage of risk management budgets are allocated to "Risk Control" vs. "Risk Transfer":

Risk Control - 56%

Risk Transfer - 44%


While there are new and innovative new insurance policies being marketed these days, these typically can not cover many of the losses from damaged corporate reputation, a drop in market share or lost sales. As Board of Directors raise the priority above a 13% response, this should cascade to impact the insufficient budget. Now the question remains on how to deal with the "Inadequate Personnel" and "Insufficient Time".

You can hire dedicated people, add additional responsibilities to existing personnel or you can even Insource. In every case, you will need to find more time for planning and training to make sure that new risk controls are implementated and monitored. Without a systematic program that is culturally institutionalized, even these new initiatives will fail.

To quote one of the leading global business continuity membership organizations Survive:

Business Continuity Management is about not making excuses. It's about being wise before the event. It is a state of mind that understands great organizations never moan they didn't do well because of the state of the economy, a fire at the warehouse, an internal fraud, or a strike by a key group of workers. Great organizations do well anyway.


20 January 2006

OFAC Compliance: Ensure Your Transactions are Legal...

Archaic and ineffective name searching technology is still in use today across all levels of intelligence agencies and law enforcement. Names remain the single most important means for identifying persona non grata at our borders. Biometrics are only useful the second time you meet someone. Everyone in the world knows how easily security at America’s borders can be circumvented — except Americans.

Language Analysis Systems is the world's recognized leader in providing multi-cultural name recognition software solutions for mission critical applications. We have worked with U.S. Intelligence and Border Protection agencies for nearly two decades, developing a revolutionary and patent-pending approach to name matching and searching, going far beyond simplistic Soundex and key-based approaches. We offer a variety of proven commercial products to government, law enforcement, and commercial organizations that solve a multitude of name related problems.


How else can this technology be used to help our DHS with the war on terror? Are you a U.S. business? If you are, then you must comply with OFAC especially if you are a financial institution, mortgage broker, car dealer, boat dealer, real estate agency or insurance broker.

OFAC administers and enforces economic and trade sanctions against targeted foreign countries, terrorism sponsoring organizations and international narcotics traffickers.

Pay attention. Dutch bank giant ABN Amro Bank , has agreed to pay a total of $80 million in US fines for violating regulations to prevent money-laundering, regulators and the bank said last month.

The Financial Crimes Enforcement Network at the Treasury Department said that ABN's "serious, longstanding and systemic" problems allowed people from Russia and other former Soviet republics to move $3.2 billion to shell companies in the United States from August 2002 to September 2003.

Investigations by state and federal officials also found that the Chicago and New York branches of the bank participated in wire transfers and trade transactions from 1997 to 2004 that violated economic sanctions on Libya and Iran.

ABN AMRO said on Monday that it recognises that serious mistakes were made and accepts the sanctions.


There are now dozens of software solutions and programs available to help with compliance of BSA and AML compliance. The question is, which one is right for your organization? If you do not have a step in your customer or client acquisition process that intersects with compliance then you are at significant risk.

Sales and business development personnel, business development or broker networks must be able to have a high degree of confidence that the business or person they are creating the quotation or proposal for is not an SDN, or Specially Designated National.

Are you an insurance company who uses a network of brokers? What are you doing to implement the policies and programs to comply with this new requirement:

The final rules apply to insurance companies that issue or underwrite certain products that present a high degree of risk for money laundering or the financing of terrorism or other illicit activity. The insurance products subject to these rules include:

• permanent life insurance policies, other than group life insurance policies;

• annuity contracts, other than group annuity contracts;

• any other insurance products with features of cash value or investment features.

At minimum, insurance companies subject to the rule requiring an anti-money laundering program must establish a program that comprises four basic elements:

• A compliance officer who is responsible for ensuring that the program is implemented effectively;

• Written policies, procedures, and internal controls reasonably designed to control the risks of money laundering, terrorist financing, and other financial crime associated with its business;

• Ongoing training of appropriate persons concerning their responsibilities under the program; and

• Independent testing to monitor and maintain an adequate program.


19 January 2006

Scenario Analysis: The Value of the Hypothesis...

In the December 2005 issue of OpRisk and Compliance Magazine Dean Lamble from Hewlett-Packard has this to say in the article on "Planning for Disaster":

Key areas will include security, evolving threats of terrorism, and how to cope with a pandemic outbreak such as bird flu. Companies will be paying far more attention to how the contingency plans perform when tested. Compliance continues to be a key concern, with increasing legislation directing responsibility to the board.

More than 25,000 banks around the world will work to comply with Basel II over the next five years. One of its most controversial aspects is the inclusion of Operational Risk Management. While banks have attempted to manage operational risks for many years, now for the first time they must measure it.


Most money center banks have already achieved high levels of competency with capturing loss events and with risk self-assessments. Scenario analysis and KRI (Key Risk Indicators) is still a distant goal. OPS Risk is still a maturing discipline and regulators are allowing some flexibility here. However, financial institutions are still stuck to some degree on imagining incidents that have not occured to them in the past. Probabilities are not low just because they haven't happen to your institution historically.

A hypothesis is the place to begin.

hy·poth·e·sis ( P ) Pronunciation Key (h-pth-ss) n. pl. hy·poth·e·ses (-sz)

1. A tentative explanation for an observation, phenomenon, or scientific problem that can be tested by further investigation.

2. Something taken to be true for the purpose of argument or investigation; an assumption.

3. The antecedent of a conditional statement.


If an event has happened to another insitution is it so improbable that it could also happen to your own firm? The starting point for effective scenario analysis is the intelligence and the external data that provides the evidence of such an incident. Then the goal is to gain "insight" on how it could happen and what the impact would be in your own environment. Capture of data on extreme events is imperative even if only one $10M. event has occured in the last ten years.

Today, an audio tape from Osama bin Laden has been posted on the Internet along with a transcript of his comments. The authenticity is being validated as he has not been heard from for over one year. Has your scenario analysis included potential events of the magnitude of the 7/7 bombings in London or the 11/9 Amman Jordan suicide attacks on three Western hotels?

"Bruce Newsome, a terrorism researcher at the think tank RAND, said the plot carried out by four men in London is a "likely model for future U.S. attacks." The bombers, all British citizens, had no criminal records, weren't on any watch lists and had no extremist pasts. (A fifth man, believed to be the mastermind of the plot, has been arrested in Egypt.) Tracking such potential perpetrators is nearly impossible because there are no warning signs, Newsome said."


Somewhere in your contingency planning and scenario analysis there must be hypothetical loss events on the magnitude beyond our imagination.

17 January 2006

You've Been Indicted. The Most Feared Words in the Boardroom...

Over two years ago this corporate governance article appeared in Corporate Board Member Magazine.

June 25, 2003
You've Been Indicted. The Most Feared Words in the Boardroom

By Peter L. Higgins


Every Fortune caliber organization from financial services to health care has already implemented a pervasive compliance program to mitigate the risk of ending up with the SEC or US Attorney in the lobby.

The catalyst behind these initiatives is generated from the U.S. Sentencing Commission's Organizational Sentencing Guidelines. They allow for more lenient sentencing if an organization has evidence of an "effective program to prevent and detect violations of law."

The Guidelines contain criteria for establishing an "effective compliance program."

These include oversight by high level officers, effective communication to all employees, and reasonable steps to achieve compliance such as:

* Systems for monitoring and auditing
* Incident response and reporting
* Consistent enforcement including disciplinary actions


Yet the corporate incivility continues. Why is it that we can’t pick up the morning paper or listen to the news on the way to work without hearing about a new indictment of a top ranking officer?

Here lies the question many Board of Directors are scratching their heads about these days. How can we avoid these ethical and legal dilemmas and how can they be addressed without creating a state of fear and panic?

The answer lies in the human factors of what motivates people’s behavior. This requires programs, controls and good old fashioned vocational counseling. However, the real facts are that all of these alone will not be able to stem the tides of corporate malfeasance.

A guest column by Jacob Blass
President, Ethical Advocate
highlights the past few years:

The number of companies around the world that reported incidents of fraud increased 22% in the last two years according to the 2005 biennial survey by PriceWaterhouseCoopers (PWC), which interviewed more than 3,000 corporate officers in 34 countries. In England, a recent Ernst & Young survey of the Times Top 1000, indicated the average cost of each fraud exceeded $200,000.
But fraud is not the only problem. There's also misconduct, unethical behavior, lying, falsification of records, sexual harassment, and drug and alcohol abuse.

PWC found that “accidental” ways of detecting fraud, such as calls to hotlines or tips from whistleblowers, accounted for more than 33% of the cases. Internal audits were responsible for detecting fraud about 26% of the time.


If these latest figures are correct than this means that 59% of the detection was a result of effective operational risk management. Let's just hope that the remainder is the result of corporate managers and leaders doing their job to mitigate new risks on a daily basis.

As indicated, the great manager can impact the lives of tens or hundreds of people in your company. Conversely, the uncivil manager can wreak havoc with a similar numbers of lives. The position of management is ever so powerful to influence those around them.

Your company wide compliance initiative has the elements that provide guidance for creating a program that the government is likely to look favorably upon. The problem is that these same criteria inadvertently communicate the message that implies building a program based on this formula is enough. It isn’t.


Maybe it’s time the Board of Directors looked into who is managing the organization into a future of civil or uncivil destiny. We have a clear choice.

11 January 2006

HSAC: Private Sector Information Sharing Task Force...

At first glance the room full of Homeland Security Advisory Council members looked like any other agency briefing. C-Span setting the stage for people to look good and say the right thing for the public record. Items such as we need to use a systematic risk management approach to funding and we should replace the word "Protection" with the word "Resiliency" were the highlights. And underneath, the audience was disturbed by the presentations because of it's lack of solid recommendations.

What happened later in the closed door session is where the rubber meets the road and serious work gets done. Yet the take away was this. After reading the 80 page report from the Private Sector Information Sharing Task Force there was one recommendation that stood out.

DHS should respond to private sector concerns about liability risks associated with sharing security information with DHS. This is why they recommend that the Critical Infrastructure Information Act (CIIA) should be fully implemented. If this could ever be clarfied and the legal counsels of the private sector gave it a major blessing then we would be well on our way to achieving a greater degree of safety, security and peace of mind.

In fact, Attachment D of the report goes so far as to list the categories of information that the government is seeking from the private sector on the critical infrastructure that they own. The number one item on the list is "Cyber Threats to U.S. Infrastructure". The number two item is "Terrorism".

It's no surprise that these are the two largest threats to the U.S. in the eyes of the task force.

06 January 2006

OPS Risk: An Ocean of Continuous Change...

In the latest issue of OpRisk & Compliance Magazine Eric Holmquist from Advanta makes the case for the Small to Medium sized institution. His brilliance continues and it's one of the reasons why we are an Advanta customer. They understand and practice OPS Risk hands down.

Overseeing an operational risk programme never ceases to fascinate me. There are aspects to op risk that are overwhelmingly unique from any other risk discipline. As I have said previously, it has the most moving parts. It involves every single person in the company, without exception. It is constantly in motion, involving an ever-changing set of assumptions and forces. And it is, ironically, sometimes unfortunately, and perhaps more importantly, the most intuitive.


Eric singles out the large mistake many organizations have made. Certification of controls for SOX 404 misses many of the OP risk factors and is all to focused on the financial control itself. Operational Risk assessments properly look at the potential and the likelihood of failures in the process so far, as well as potential threats to the process in a high moving parts environment.

The hint in his article about evaluation of core processes under the "heat lamp" is most critical. When people and systems are concerned, there are all too many opportunities for a failure and potential losses to occur. And those people are exactly who are the ones to be in the drivers seat to analyze those places that the proper tools in the right hands could exploit a known vulnerability. They may not know all of the ways to mitigate the threat, yet they are where you are going to get your "intuition" on what could happen.

As Eric says, "Operational Risk is constantly in motion", and assumptions change as often as the weather.


As the discipline of OPS Risk matures in the white collar world of Wall Street and the blue collar world of small community banking one thing is certain. No one will ever be able to predict or provide a scenario analysis that prepares exactly for the next incident. Mother Nature may act the same over and over to some degree and that helps us think in terms of magnitudes and categories. What about the person sitting in the next office who makes a random decision to inflate last months expense report? What about that electrical fire in the storage room?

Those who can master the art of change and rapidly adapt as unforeseen events occur will be here tomorrow to take on that next unplanned scenario.

04 January 2006

Security vs. Privacy: A Public Private Paradox...

If your are interested in what is on the minds of some of the PowerBase for information security and privacy you need to look no further. The comments and posts on Bruce Schneier's weblog tell the truth. His post on the Top Ten Privacy concerns from EPIC, (The Electronic Privacy Information Information Center)has created some very interesting points.

And to add to the concerns, comments and controversy is this:

Cyber Security Industry Alliance (CSIA), the only advocacy group dedicated to ensuring the privacy, reliability and integrity of information systems, today called on the federal government to assert greater leadership in the protection of our information infrastructure in 2006. Its release of the "National Agenda for Government Action on Information Security" identifies 13 specific actions required to improve information security for consumers, industry, and governments globally. As part of the Agenda, CSIA also provides a report of the government's limited progress in information security in 2005 and releases a new "Digital Confidence Index" that reflects the public's lack of confidence in our nation's critical infrastructure.


What is the paradox? The feds may need to show more leadership yet the private sector owns a majority of the critical infrastructure. Any lack of confidence should be an indicator that the private sector hasn't invested enough money and resources in information security and protection of our country's vital corporate assets.

24 December 2005

Enterprise Preparedness: Business Process Management (BPM)

Enterprise Preparedness Organizations are experiencing unprecedented pressure from a number of directions to remain competitive in today's changing economy. The challenges of satisfying profit expectations, meeting customer demands, avoiding litigation, and complying with government regulations have created tough conditions for the executives who are managing the business. Besides the pressure to create new markets, manage cost, and generate profits, they must also demonstrate the ability to effectively manage adversity when it occurs. The current stringent regulatory environment coupled with a hypersensitive investment community has made the need to prepare for adverse events a corporate mandate.


Troy Smith's article is correct on many of the fundamentals of Enterprise Preparedness. We would emphasize the need to also have some effective tools for capturing the processes during the important planning phases. One company to consider is Metastorm.

As the first breakaway BPM vendor, Metastorm is a leader in business process management (BPM) software and best practice methodologies for modeling, automating, integrating, and improving both human and system-based processes. Metastorm BPM™ is a complete solution for roundtrip process improvement, designed specifically to address complex processes that are unique to organizations. Metastorm’s 1200+ global client base in manufacturing, retail, financial services, business services, healthcare and government are achieving rapid ROI and Enterprise Process Advantage® in customer service, supply chain operations, risk management, and internal operations.


22 December 2005

Financial Services Marketers: Get Ready for Your Audit...

The FDIC Small-Entity Compliance Guide is now available. The guide summarizes the obligations of financial institutions to protect customer information and illustrates how certain provisions of the Security Guidelines apply to specific situations.

Distinction between the Security Guidelines and the Privacy Rule

The requirements of the Security Guidelines and the interagency regulations regarding financial privacy (Privacy Rule)8 both relate to the confidentiality of customer information. However, they differ in the following key respects:

- The Security Guidelines address safeguarding the confidentiality and security of customer information and ensuring the proper disposal of customer information. They are directed toward preventing or responding to foreseeable threats to, or unauthorized access or use of, that information. The Security Guidelines provide that financial institutions must contractually require their affiliated and non-affiliated third party service providers that have access to the financial institution's customer information to protect that information.

- The Privacy Rule limits a financial institution's disclosure of nonpublic personal information to unaffiliated third parties, such as by selling the information to unaffiliated third parties. Subject to certain exceptions, the Privacy Rule prohibits disclosure of a consumer's nonpublic personal information to a nonaffiliated third party unless certain notice requirements are met and the consumer does not elect to prevent, or "opt out of," the disclosure. The Privacy Rule requires that privacy notices provided to customers and consumers describe the financial institution's policies and practices to protect the confidentiality and security of that information. It does not impose any other obligations with respect to safeguarding customers' or consumers' information.


3rd Party marketers of financial institutions are preparing for new audits of the their information securtiy controls and processes. Slicing and dicing customer information utilizing pscyhograpics and demographics is a normal task. Mailing millions of pieces annually with new offers from collaborating internal companies and external partners creates significant challenges in managing sensitive customer information. This increased exposure to potential data loss and other threats warrants additional scrutiny with supply chain companies that interface with the marketing department.

One way to find out how ready your partners would be for a formal audit is to ask them when was the last time they had an independent audit of their information security controls. Many organizations today serve multiple financial institutions in the same region and therefore are consistently being asked for evidence of a SAS 70 audit opinion. SAS 70 is not a predetermined set of standards that an organization must satisfy in order to “pass” the audit. In a SAS 70 audit, the service organization is responsible for describing its control objectives and control activities that might be of interest to auditors in user organizations. SAS 70 objectives can be non-specific for an audit and may have large gaps in real-time day to day operations.

20 December 2005

Resilience Masks the Real Problem: Training...

The UK financial services sector has completed the first phase of it's Resilience Benchmarking Project. More than 60 key firms and financial infrastructure providers from the UK volunteered to take part in the Resilience Benchmarking Project, the results of which were mixed and highlighted a number of significant operational risk issues relating to business continuity. Here is the summary of FSA discussion points:

1 Although the financial system appears to be technologically resilient, are there vulnerabilities in other areas that could put it at risk?

2 What action could the Tripartite Authorities take to help bring together the component parts of the system?

3 How can firms strengthen their collective resilience?

4 Would it be helpful to publish recovery-time targets for wholesale payments, trade clearing and settlement? If so, would 60-80% of normal values and volumes within four hours, rising to 80-100% by the next working day, be reasonable recovery targets?

5 If we decide to publish targets, should these apply to core firms and financial infrastructure providers only, or should they apply more widely?

6 Should we consider publishing targets for other functions such as resumption of trading and retail payments?

7 If we were to publish targets, should these be informal in nature or should they be embedded into rules and guidance?

8 What more can be done to encourage joined-up planning and testing to reflect better the likely impact of a major operational disruption and how this could be facilitated?

9 Could the weaknesses in business continuity and crisis management arrangements undermine recovery time capabilities?

10 Would it be helpful to set a minimum distance criteria between primary and recovery sites? If so, what should that distance be?

11 Should we actively encourage firms to diversify their back-up arrangements, in particular core firms and financial infrastructure providers?

12 Do you agree with our conclusions and proposed actions in relation to recovery service provision? Is there more that the Tripartite Authorities should do in this area – for example including a specific survey on recovery service provision in future benchmarking studies?

13 We invite feedback on the measures we propose to take to mitigate concentration risk: encouraging end-to-end testing; sharing information on resilience and recovery arrangements the financial infrastructure providers have in place; and encouraging wider geographical diversification.

14 Should FSA maintain its non-prescriptive approach to business continuity management?

15 We would welcome comments on the estimated cost of reaching the targets we propose to publish for core firms and financial infrastructure providers:
– from those organisations to which these targets would apply; and
– from other organisations for which these targets might be considered aspirational goals.

16 We would welcome views on the estimated cost of lost business arising from the delayed recovery of a vital counterparty (i.e. a core firm or financial infrastructure provider).


The word "Resilience" occurs 70 times in this 52 page document. The word "Security" occurs only 12 times. The word "Continuity" occurs 63 times. The word "Risk" occurs 52 times. Resilience seems to be the overall theme these days.

The definition of Resilience is an interesting one:

Main Entry: re·sil·ience
Pronunciation: ri-'zil-y&n(t)s
Function: noun
1 : the capability of a strained body to recover its size and shape after deformation caused especially by compressive stress

2 : an ability to recover from or adjust easily to misfortune or change


The definition has a reactive flavor to it with the thought that something is going to happen and when it does, you must be able to recover quickly. With all the synomyms and word games being used today it all comes back to effective training. And this is where the benchmarking study has revealed the corporate business enterprises greatest weakness:

Training is another potential area for improvement. Only 42 firms include business continuity planning in induction programmes for new staff, and ten respondents had provided training to less than 5% of their staff. Fewer than a third of participants have provided training to staff that might be called upon to deal with sensitive issues, such as working on a casualty helpline. The responses to these and a number of other questions indicate a lack of appropriate training needs analysis and a need for greater consideration of the effects of a crisis on those who might be asked to undertake some of the most harrowing and disturbing roles.


16 December 2005

High Quality or Low Price: Pick One...

Have you ever heard that old saying, "You can have high quality or you can have a low price, pick one." Now apply this to Operational Risk Managment in your domain.

It seems that the U.S. Senate has mixed priorities right now on the U.S. Patriot Act debate. Wyoming is a low risk area in terms of critical infrastructure yet it will receive the same funding as states with more shoreline, ports and vulnerabilities to the security of the United States. James Jay Carafano has identified what the key issue really is:

What’s Missing?

There was one important provision that did not make out of conference. The original Patriot Act established the requirement that a significant percentage of all homeland security grants be distributed automatically to each state, big or small, regardless of national priorities or risks. Current funding formulas guarantee each state .75 percent of the funds available. As a result, 40 percent of these funds are immediately tied up, leaving only 60 percent for discretionary allocations. As the 9/11 Commission’s report rightly stated, the current system is in danger of turning homeland security funding into “pork-barrel” spending, making spending on security just another state entitlement program. In conference, an initiative to restructure the system and allocate money according to risk and needs rather than an archaic formula was rejected by Senate conferees. This is the third time the Senate has turned back House legislation to reform the grant system. And it is just wrong.


Prudent risk management policies and strategy point to investing to improve resilience in the areas that are identified as being most vulnerable and that the consequences of a loss would be unacceptable. What part of the risk management methodology is missing in the presentations or education of our law makers?

The part that is missing is the part that no one can present in fear of it becoming public information and for it to get into the hands of those who may use it to harm the homeland. Those single-points-of-failure exist in every country or city that has a significant capitalist marketplace. The resilience of the respective economies depends on the infrastructure that fuels it and every dollar and resource needs to be focused on those highest risk areas.

Mr. Carafano makes another observation worth consideration, regarding the The September 11 Commission Report Card: The Good, the Bad, and the Ugly:

At the top of the list is the failure of the Congress to put together a comprehensive package of border security and immigration reforms that enhance security, promote economic growth, and protect civil liberties. Also missing from the list is the tragic underfunding of the Coast Guard. The same service that saved 33,000 lives during and following Hurricane Katrina faces cuts to its modernization budget in the House.


The private sector can change all of this in a heart beat. The safety and security of our economic livelihood is in the hands of the telecom/high tech, banking and finance, health care and energy sectors. In the long run, the executives in these industry sectors have the power to change our law makers points of view. Let's just hope that they all realize that it is their own corporate assets that are at a greater risk now, than they were over four years ago.

15 December 2005

CIP Risk Management: NIPP & Tuck...

As part of the new National Infrastructure Protection Plan NIPP v1.0 the years old RAMCAP (Risk Analysis and Management for Critical Assets Protection) methodology of the American Society of Mechanical Engineers makes it's way into the mainstream:

RAMCAP is an overall methodology and provides a common framework for homeland security risk analysis decision-making that includes:

–Common terminology
–Common metrics for comparing risks across sectors
–Common basis for reporting results
–Basis for informing resource allocation decisions

•Countermeasures
•Consequence mitigation actions


ASME was awarded a grant by the Department of Homeland Security to develop uniform risk-based guidance in September 2003. The methodology's sequential steps include:

•Vulnerability analysis
•Consequence analysis
•Risk analysis
•Countermeasures and mitigation
•Decision analysis
•Multiple assets and sectors


The NIPP is a "draft" today and the comment period has already expired December 5, 2005. We expect that we will see sector specific plans soon after the national plan is finalized. It will be interesting to see how the private sector reacts. Industry critics say the draft lacks specificity at this point. However, maybe this is a good thing for the owners and operators of 85% of the nations critical infrastructure.

12 December 2005

Reducing Operational Risk Through CAP & IPv6...

After attending the United States IPv6 Summit last week it was apparent that Emergency Preparedness and National Security is a top priority. This is increasingly true as we see the grades on our progress by the 9/11 commission and others with regard to data communications and interoperability issues. One facet of all of this has to do with the important work already underway by the technical committees at OASIS:

The mission of the EM TC is to create incident and emergency-related standards for data interoperability. The TC welcomes participation from members of the emergency management community, developers and implementers, and members of the public concerned with disaster management and response.

Standards currently under review by the committee:

The Common Alerting Protocol (CAP), a data interchange standard for alerting and event notification applications, currently in version 1.1. CAP functions both as a standalone protocol and as a payload for EDXL messages.

The Emergency Data Exchange Language (EDXL), a broad initiative to create an integrated framework for a wide range of emergency data exchange standards to support operations, logistics, planning and finance.


Why is IPv6 and CAP a big issue in operational risk management? It will save lives and property as it is deployed in numerous communications devices and services in the future. Currently, the big drive for IPv6 is new uses, such as mobility, quality of service, privacy extension and so on. The U.S. Government has also specified that all federal agencies must deploy IPv6 by 2008.

Karen Evans and the OMB are preparing the federal CIO's for the transition:

The CIO Council will develop additional transition guidance as necessary covering the following actions. To the extent agencies can address these actions now, they should do so. Beginning February 2006, agencies’ transition activity will be evaluated using OMB’s Enterprise Architecture Assessment Framework:

• Conduct a requirements analysis to identify current scope of IPv6 within an agency, current challenges using IPv4, and target requirements.
• Develop a sequencing plan for IPv6 implementation, integrated with your agency Enterprise Architecture.
• Develop IPv6-related policies and enforcement mechanisms.
• Develop training material for stakeholders.
• Develop and implement a test plan for IPv6 compatibility/interoperability.
• Deploy IPv6 using a phased approach.
• Maintain and monitor networks.
• Update IPv6 requirements and target architecture on an ongoing basis.


Much of what IPv6 is all about has to do with capacity of our current standard IPv4. However, as more emphasis is put on interoperability and the use of millions of new data capture and reporting sensors both CAP and IPv6 will both be essential building blocks to the future. One example illustrated the other day is the changes being made in London and other global metro areas to capitalize on the fact that most citizens are carrying mobile phones with picture and video taking capabilities. These video images are increasingly being utilized to assist both law enforcement and emergency responders with new insight into the real situation as it unfolds. In some cases while voice circuits are jammed the data communications can get through.

Sometimes, a picture is worth a thousand words.

06 December 2005

Mitigating Operational Risks Around the Globe...

In this month's CSO Online, Todd Datz has an article worth exploring. How to Manage Security Halfway Around the World talks about several key components of global operational risk mitigation:

Different cultures. Unstable political environments. Language barriers. CSOs in global companies face many a challenge as they try to manage security in far-flung locations. One of the biggest challenges? A good number of your security managers reside in functions other than corporate security, so security is often a part-time gig managed by people with part-time security training. There’s no ironclad set of rules or policies that all those employees can follow.


If you are like most organizations doing business on a global basis, you don't have a security department in every office. This is why it is imperative for your local employees to establish local relationships with other businesses or entities who will help protect your vital corporate assets.

Educate Your Global Security Staff
Training is a critical component of any global security program, especially given that many security managers in foreign locations come from nonsecurity functions—such as HR or engineering—and thus wear multiple hats.


It's critical to have a local presence along with a centralized global policy and audit function know as Enterprise Security Risk Management. Together the partnership keeps a great degree of relevance to the issues and cultures in a particular country while simultaneously keeping a consistent and correlated set of standards for legal compliance. International laws for exchange of information, transmitting funds and selling products and services to Specially Designated Nationals (SDN)'s are all important business risks to be managed.

With a growing focus on risk management, The Yankee Group predicts that by 2008, the $165 million Enterprise Security Risk Management market will grow to $650 million as more organizations move to strengthen their global security posture. According to The Yankee Group, most organizations today utilize informal security risk management processes using professional services and homegrown databases that are often time-consuming and ineffective.

01 December 2005

Board of Directors: Corporate Responsibilities...

The primary responsibilities of the Board of Directors are getting more scrutiny than ever before. Especially in the light of the fact that statements executives make about quarterly earnings are a focus for class-action shareholder lawsuits.

Many public institutions are no longer bowing to Wall Street and publishing or promising quarterly numbers. In fact, many are following the lead of people like Warren Buffet of Berkshire Hathaway. He doesn't believe in the short sighted behavior that occurs around quarterly conference calls with analysts. Look to the The Washington Post as one example.

The Board is ultimately responsible for ensuring the performance and survivability of the corporation. The shareholders want the Board to do the following:

1. To ensure legal and ethical conduct.

2. To insist on strategic and operational planning.

2. To develop in collaboration with management a real-time risk assessment.

4. To establish a Corporate Governance culture based on best practices.

5. To exercise the Director's fiduciary duty of care on behalf of the shareholders.

An ever more important responsibility is to apply the use of technology and it's purpose in the survival and longevity of the organization. At the Washington Post, which does not offer quarterly guidance, they have adopted technology to help satisfy the analysts needs for information.

WASHINGTON, Nov. 30 -- The Washington Post Company (NYSE: WPO) will audio webcast its presentation at the Credit Suisse First Boston (CSFB) Global Media Week Conference next week. The Company's presentation will take place on December 6 at 4 p.m.

The live webcast will be accessible from a link on The Washington Post Company's website, http://www.washpostco.com, and at http://www.csfb.com. A transcript will be posted on http://www.washpostco.com following the presentation.


Maybe someday the SEC will reconsider Regulation FD:

"The Reg FD rule reads as follows: "Whenever an issuer, or any person acting on its behalf, discloses any material nonpublic information regarding that issuer or its securities to [certain enumerated persons], the issuer shall make public disclosure of that information... simultaneously, in the case of an intentional disclosure; and... promptly, in the case of a non-intentional disclosure."


In light of this, most Directors and Executive management are counseled to say very little about what is happening in the company.

24 November 2005

Avian Flu: What are the Risks?

Avian influenza, or bird flu, is a contagious viral disease caused by certain types of influenza viruses that occur naturally among birds. Usually, these viruses do not infect humans, but several cases of human infection with bird flu viruses have been reported recently.

Why could this become an Operational Risk for your organization? Currently, these viruses are circulating in bird populations in Asia, and have resulted in severe illness and death in humans. Since the recent outbreaks of this strain began in 2004, more than 120 people have been confirmed as infected and more than 60 have died. Most human cases are thought to have occurred through contact with infected poultry or contaminated surfaces. However, some scientists worry that if the virus were able to mutate and be able both to infect people and then to spread easily from person to person in a sustained fashion, a global "influenza pandemic" (worldwide outbreak of the disease) could begin.

This WHO Avian Flu Fact Sheet can provide some of the answers on the disease.

21 November 2005

Simulation & Analysis: COOP on Steroids...

All of the planning tools that have automated the process of developing BCCM and COOP documentation have addressed only a small piece of the total mosaic for operational risk management. There is however a new "kid" on the block that is worth keeping your eye on. This is because they have created the tools for doing critical simulation and analysis of the impact of significant business disruptions to our critical infrastructures.

FortiusOne’s target market encompasses both the public and private sector. The former includes federal, state, local and international segments, with primary emphasis on Homeland Security, National Defense, Intelligence and Emergency Management for critical infrastructure vulnerability assessments and consequence management. FortiusOne’s private sector market addresses risk analysis for the Banking/Financial Services, Transportation, Energy, Telecommunications, Insurance and general Supply Chain segments with primary emphasis on business continuity planning, business optimization and disaster recovery. Market size exceeds $40B and is upward trending in both public and private sectors. Recent events and consequences related to hurricane Katrina, terrorist threats and attacks, and corporate management/mis-management events have created intense interest in FortiusOnes’s products and services. The Company’s revenue model for both public and private sectors includes fixed price product pricing for basic assessments with additional high valued consultation for detailed analysis of specific client defined scenarios.


While we have all the confidence that there is a market for tools like these, the largest challenge still remains. Human Factors.

All of the scenario planning and simulation is important to create new contingency procedures or the application of new methods for mitigating the impact of such scenarios. However, the human factors are and will remain unknown until you actually exercise and effectively test that scenario. Only testing will tell you what people did or didn't do or why they reacted the way they did. The psychological and physiological unknowns are what throw the planners and simulation operators for a loop every time.

We hope that FortiusOne also gives their clients the insight they require to create the most realistic and optimal tests to determine what the real outcomes will look like before and after a natural disaster or terrorist event.


17 November 2005

ISO 27001 : Information Security Management...

What Is ISO 27001?

ISO 27001, titled "Information Security Management - Specification With Guidance for Use", is the replacement for BS7799-2. It is intended to provide the foundation for third party audit, and is 'harmonized' with other management standards, such as ISO 9001 and ISO 14001.

The basic objective of the standard is to help establish and maintain an effective information management system, using a continual improvement approach. It implements OECD (Organization for Economic Cooperation and Development) principles, governing security of information and network systems.


This particular standard defines and specifies an 'Information Security Management System', known as an ISMS. It compliments the existing ISO 17799 security standard, and specifies a general framework for the creation and maintenance of the security process within an organization.

These two standards (ISO 17799 and ISO 27001) are closely related, and although their scope is wide, they have very distinct roles.

ISO 27001 defines the overall requirements for the security management system itself, the focus being on management. It is this standard, rather than ISO 17799, against which certification is offered. It was based upon an earlier standard, known as BS7799-2, but has been more closely aligned with other quality management standards.

09 November 2005

The Risk of 4GW: It's Here to Stay...

In today's OSAC 20th Annual Briefing at the U.S. State Department Bureau of Diplomatic Security we witnessed some excellent briefs from corporate CSO's and keynotes from Sandy Weill, COB of Citigroup and Dr. Condoleeza Rice, U.S. Secretary of State.

All had the theme of the day, the valuable and lasting public private partnership established twenty years ago by former U.S. Secretary of State George P. Shultz. There was much talk of the current risk of Fourth Generation Warfare (4GW), the same method of guerilla warfare described in The Sling and the Stone. In the middle of the presentations, many of our PDA's and phones began their vibrations and buzzing. Within a few minutes, the podium was announcing the latest attack on our own corporate assets in the capital of Jordan.

At least 57 people were killed and more than 100 injured when suicide bombers blew themselves up at three hotels in Amman, the capital of Jordan.

The hotels were popular with foreigners and many of the guests were involved in work in Iraq. The attacks destroyed the fragile calm that Jordan has enjoyed despite its proximity to Iraq and the support of its ruler, King Abdullah, for American and British policy in Iraq.

Major Bashir al-Da'aja, a police spokesman, said: "There were three terrorist attacks on the Grand Hyatt, Radisson SAS and Days Inn hotels and it is believed that the blasts were suicide bombings." Said Darwazeh, the health minister, said there were more than 50 dead but the toll could rise.


The Overseas Security Advisory Council (OSAC) now claims over 3,000 U.S. companies, educational institutions, religious groups, and non-governmental organizations as members known as constituents. Although OSAC is rarely in the limelight, the ways in which it helps American businesses fight terrorism abroad is unparalleled.

Is that a "Predator" taking off?

Mission

The MQ-1 Predator is a medium-altitude, long-endurance, remotely piloted aircraft. The MQ-1's primary mission is interdiction and conducting armed reconnaissance against critical, perishable targets. The MQ-1 Predator carries the Multi-spectral Targeting System with inherent AGM-114 Hellfire missile targeting capability and integrates electro-optical, infrared, laser designator and laser illuminator into a single sensor package. The aircraft can employ two laser-guided Hellfire anti-tank missiles with the MTS ball.


Tomorrow, in our second day of the OSAC briefing the room will be missing many of the constituent members as they begin the investigations and deploy new resources in the pursuit of justice.

01 November 2005

Online Pharmaceutical Counterfeiting: The Digital Threat...

Pharma healthcare companies all over the globe are working hard to identify counterfeit drugs and to put these criminals out of business. This operational risk strategy saves countless lives each year. The first article in a series on counterfeiting at CSO Online misses a key focus on the Internet Channel of Distribution. In order to pursue this growing threat, organizations must consider the use of real professionals to deter, detect, defend and document effectively in order to have a comprehensive anti-counterfeiting program.

The continuing growth of the Internet provides counterfeiters with ready access to unsuspecting consumers. Since goods purchased via the Internet are normally delivered through the conventional mail system, they frequently by-pass national regulations for the distribution of controlled goods.

The use of intelligent Internet surveillance with proprietary software, enables the detection of illicit distribution, trademark abuse, objectionable association and counterfeit activities, which can then be countered in a highly focused manner.

Authentix identifies client products on sale from suspect counterfeit sources, retrieves them anonymously and tests them for authenticity. In cases of minor misdemeanors they issue Cease & Desist letters for clients and monitor compliance. Where counterfeit or diverted product is retrieved, they support our clients through legal remediation by maintaining a documented chain of evidence.


All of the forensic markers and post testing due diligence will not stem the tide of bogus pharma web sites selling counterfeit drugs. An effective corporate risk intelligence process combines both the low tech (HUMINT) sources and the high tech methods (DIGITAL SURVEILLANCE) from a single entity. Only then will the data fusion and correlation of information allow for a legal, competent and rapid interdiction of this lethal threat.

Counterfeit medicines are a global scourge. The World Health Organization (WHO) estimates that as much as 10 percent of the half-trillion-dollar pharmaceutical market is counterfeit. In some developing countries, more than half of the drug supply may be fake. Every year, thousands die from ingesting fake medicines, many of which have been produced in squalid conditions using ingredients such as boric acid and highway paint.


28 October 2005

Zombies Being Hunted: Trick or Treat?

The FTC and Microsoft are going Zombie Hunting just in time for Halloween.

"The widespread use of zombie computers to commit crimes over the Internet presents a very real danger to law-abiding computer users," said Tim Cranton, the director of Microsoft's Internet Safety division.

Earlier this year, Cranton said, Microsoft set up a "clean" PC, then infected it with malicious code commonly used by attackers to turn a computer into a zombie. Researchers then monitored the PC's use of the Internet for 20 days, and tallied the number of messages sent through it.

"In those 20 days, this one computer received 5 million connection requests from spammers, and sent 18 million spam messages," said Cranton.

That amount of data was impossible to analyze, so Microsoft focused on the three most-active spamming days, when 470,00 connection requests were made of the PC, and about 1.8 million messages were sent through it.


OnGuard Online has been launched to help consumers and business become more aware and educated on digital threats. This site is in collaboration with private industry and:

U.S. Department of Homeland Security
U.S. Federal Trade Commission
U.S. Postal Inspection Service
U.S. Department of Commerce

There is a whole of common sense here yet it is encouraging to see that the Fed's are now acknowledging that ID Theft is out of control. The financial services industry is certainly at risk as long as consumers are banking online and using their PC's to pay their bills.

If haven't already, you should consider signing up for alerts from US-CERT.

25 October 2005

The Risk of A Blueprint For Action...

Now that Tom Barnett has released his newest book, Blueprint For Action: A Future Worth Creating it will be interesting to see the outcome.

However, before we make any comments or offer our own analysis, we are going to finish the entire book. Page 33 of 362. Stay tuned.

In the mean time, you can visit his web site and blog to find out more about his journey.

24 October 2005

Hurricane Risk: Floridians Take On Another Cat. 3...

The residents of Florida have learned some lessons over the past 14 months about preparedness. They have just been blasted by another Category 3 storm with over a month left to the end of the season. The estimates are now coming in that Wilma will have a significant impact with over $5B. in insured damages.

Hurrican Wilma came ashore with winds of 125 mph near Cape Romano, about 20 miles south of Naples, at about 6:30 a.m. local time. The coastal parts of Collier County, which includes Naples and nearby beach resort Marco Island, haven't been hit by a hurricane since 1960.

The state was hit by a record four hurricanes last year, causing a combined $22.9 billion in insured damages. Charley accounted for $7.5 billion, Ivan caused $7.1 billion, Frances resulted in $4.6 billion and Jeanne left $3.7 billion in insured damages.

Hurricane Katrina, which struck the U.S. Gulf Coast in August, is expected to be the most costly U.S. disaster for insurers. Storm modeler Risk Management Solutions Inc. estimated $40 billion to $60 billion in claims, as much as three times the $20.8 billion produced by Hurricane Andrew, which hit Florida in 1992.


In the wake of Hurricanes Katrina and Rita, hospitals across the United States of America are re-evaluating their disaster recovery plans. VHA, the national health care alliance, surveyed member hospitals across the country, and nearly half of those who responded are planning to modify their disaster plans - changing their evacuation plans, seeking alternative communication systems and preparing for extended periods of self-sufficiency.

More than 350 hospital leaders and managers, ranging from chief executive officers and chief nursing officers to materials managers, pharmacists and emergency department coordinators, responded to the VHA survey. According to respondents, nearly half (48.2 percent) are planning to change their disaster recovery plans.

Here are a few reminders for getting your Business Ready:

1. If you rent, lease or share office space, coordinate and practice evacuation and other emergency plans with other businesses in your building or facility.

2. Conduct regularly scheduled education and training seminars to provide co-workers with information, identify needs and develop preparedness skills.

3. Include preparedness training in new employee orientation programs.

4. Do tabletop exercises with members of the emergency management team. Meet in a conference room setting to discuss individual responsibilities and how each would react to emergency scenarios.

5. Schedule walk-through drills where the emergency management team and response teams actually perform their designated emergency functions. This activity generally involves more people and is more thorough than a tabletop exercise.

6. Practice evacuating and sheltering. Have all personnel walk the evacuation route to a designated area where procedures for accounting for all personnel are tested. Practice your “shelter-in-place” plan.

7. Evaluate and revise processes and procedures based on lessons learned in training and exercise.

8. Keep training records.

21 October 2005

Phishing: The Takedown...

Why Phishing Incident Response Plans May Not Be Optional.

The Treasury Department’s Office of the Comptroller of the Currency issued a bulletin in July that outlines the steps banks should take to mitigate the risks of phishing. Among other things, national banks were told they must file suspicious activity reports, or SARs, if they are the target of a spoofing incident.

Last December, the Federal Deposit Insurance Corp. issued guidelines for how financial institutions can mitigate phishing risks. The document warns that “the financial service industry’s current reliance on passwords for remote access to banking applications offers an insufficient level of security” and describes better options, such as two-factor authentication.

Phishing as a operational risk to an institution requires effective deterence as well as detection. These comments from a recent article at CSO Online paint the picture about why a takedown is a necessary response to a phishing incident.

The Takedown
The window of opportunity for a phisher is the time between when a phishing e-mail goes out and when the fraudulent website collecting information is taken down. Left unchecked, a phishing site may stay up for days or even weeks, as information trickles in from dawdling customers who've fallen for the scam. A good takedown process can slam that window shut within hours.


Nowadays, the attempt to do a takedown is standard fare—so standard, in fact, that the Treasury Department's Office of the Comptroller of the Currency has issued guidelines about the steps banks should take to disable spoofed websites. (Takedown, which essentially just relocates the problem, may be the only defense that the targeted company has. Prosecutions of phishers have been next to nonexistent, due to the difficulty of tracing how personal information has been captured, sold and exploited.)


As this article mentions, their are several very reputable firms who can assist you with the takedown. It may be even more important to have a 24 X 7 detection service monitoring the Internet for new web sites popping up and to get you ready for the barrage of spam e-mail onto the net to spoof your unsuspecting consumers. For more information on this, see Cyveillance.

Another important note is the PR and communications crisis management that is necessary to keep customers informed, the public aware of your Anti-Phishing strategy and more. You see, at the end of the day 99% of online banking customers won't leave you because you had an incident. They will leave you if you don't handle the response correctly.

17 October 2005

Corporate Governance: Deja Vu...

This is another sad story of Operational Risks far from being managed or in this case even considered when so many "Red" flags were waving in the wind.

NEW YORK, Oct 17 (Reuters) - Financial services companies beware: The fast meltdown of futures and commodities broker Refco Inc. (RFX.N: Quote, Profile, Research) may cause investors to think twice before making bets on similar types of ventures.

The crisis at Refco in the past week has happened even as new U.S. financial reporting rules and increased auditor oversight -- the result of a wave of scandals at companies such as Enron and WorldCom in 2001-2002 -- were supposed to have better protected shareholders from such debacles.

There have also been plenty of hard looks at the behavior of executives throughout corporate America in recent years, as witnessed by the high-profile criminal trials of one-time highflyers like WorldCom's Bernard Ebbers and Dennis Kozlowski of Tyco International Ltd. (TYC.N: Quote, Profile, Research)

Still, New York-based Refco's former chief, 57-year-old Briton Phillip Bennett, managed to escape heavy scrutiny while building up Refco and even during its initial public offering of shares.

He was charged with securities fraud last week over allegations he hid about $430 million in company debt. Bennett's lawyer has said there is "no justification" for his client's arrest.


This one has lot's of people sick to their stomach and more are going to be checking in to the local clinic before this one is over. Everyone will be pointing fingers and wondering why SOX didn't save the day. The truth of the matter is Mr. Bennett is a true master at "Social Engineering" and was able to use his power to do the same thing that others in a position like his have done in the past. The finance industry is built on trust and this will be another lesson on why due diligence on a 24 x 7 basis is a harsh neccesity.

11 October 2005

The Impact of Katrina: A Look Into The OPS Risk Crystal Ball...

The impact of hurricane Katrina is only beginning and it's easy to see how many institutions may be starting the battle with their insurance companies.

These "Expected" external events the likes of Katrina and Rita have impacted about 280 financial institutions in the Gulf Coast of the U.S.. These institutions represented around $270B. in assets and many are now looking to the insurance industry for payouts on those policies that transfered some of their risks.

Looking into the crystal ball, let's consider the public testimony of Steven G. Elliott, Senior Vice Chairman Mellon Financial Corporation before the Subcommittee on Financial Institutions and Consumer Credit Committee on Financial Services - U.S. House of Representatives in 2004:

"Banks should view risk mitigation tools as complementary to, rather than a replacement for, thorough internal operational risk control. Having mechanisms in place to quickly recognize and rectify legitimate operational risk errors can greatly reduce exposures. Careful consideration also needs to be given to the extent to which risk mitigation tools such as insurance truly reduce risk, or transfer the risk to another business sector or area, or even create a new risk (e.g. legal or counterparty risk)."

"Investments in appropriate processing technology and information technology security are also important for risk mitigation. However, banks should be aware that increased automation could transform high-frequency, low-severity losses into low-frequency, high-severity losses. The latter may be associated with loss or extended disruption of services caused by internal factors or by factors beyond the bank’s immediate control (e.g., external events). Such problems may cause serious difficulties for banks and could jeopardize an institution’s ability to conduct key business activities."


While overall the Fed and the institutions resilience is to be commended compared with other major critical infrastructures such as the Energy sector, we still have a long way to go with contingency planning. The regulators and insurance industry is looking at Business Crisis and Continuity Management with a new found diligence especially with the institutions outsourcing and supply chain partners.

Outsourcing of activities can reduce the institution’s risk profile by transferring activities to others with greater expertise and scale to manage the risks associated with specialized business activities. However, a bank’s use of third parties does not diminish the responsibility of management to ensure that the third-party activity is conducted in a safe and sound manner and in compliance with applicable laws. Outsourcing arrangements should be based on robust contracts and/or service level agreements that ensure a clear allocation of responsibilities between external service providers and the outsourcing bank. Furthermore, banks need to manage residual risks associated with outsourcing arrangements, including disruption of services.


Beyond the impact of Katrina, talking and listening to the OCC, FDIC and the Federal Reserve this week at the Risk Management Association (RMA) Annual Conference in Washington, DC produced some additional views and questions in the operational risk crystal ball:

1. Regulators are reinforcing the need for a comprehensive risk framework.

2. Does the amount of capital that I hold support the risks that we are engaged in?

3. Does our institution have excess capital?

4. How do I differentiate our risks by industry or geography to address concentrations and impact from cycles?

5. How do I integrate risk management into the Strategic Planning Process to make sure the methodology is understood and objectives are being communicated from the Board?

There must be the development of new risk management models that allow for the addition of new risk events and the elimination of those factors that may no longer be relevant.

07 October 2005

The Risk of Pandemic: A Global Threat...

Pandemic: A Worldwide Outbreak of Influenza is now getting attention on many global fronts including a plea by U.S. President George Bush to vaccine manufacturers to step up their production and R & D. In recent weeks, senior officials here have embarked on a public information campaign, warning of the possibility of a lethal pandemic which could claim millions of lives.

Mr Bush has even suggested that the US military would be used to quarantine affected areas of the United States in the event of an outbreak. What exactly is a pandemic?

An influenza pandemic is a global outbreak of disease that occurs when a new influenza A virus appears or “emerges” in the human population, causes serious illness, and then spreads easily from person to person worldwide. Pandemics are different from seasonal outbreaks or “epidemics” of influenza. Seasonal outbreaks are caused by subtypes of influenza viruses that are already in existence among people, whereas pandemic outbreaks are caused by new subtypes or by subtypes that have never circulated among people or that have not circulated among people for a long time. Past influenza pandemics have led to high levels of illness, death, social disruption, and economic loss.


And where there is a threat like this, the criminal minds begin to see opportunity for unsuspecting prey. Roche is now on alert and you should be also.

Swiss drug maker Roche urged consumers on Friday not to buy its flu drug Tamiflu over the Internet to avoid the risk of purchasing potentially counterfeit pills as they build stockpiles in case of a bird flu pandemic.

With experts predicting that millions could die if the bird flu strain H5N1 mutates into a human flu virus, some consumers appear to be building up their own reserves of the drug, doubling up on governments' efforts to prepare for a pandemic.

05 October 2005

CyberCrime: What is the Real Truth?

The CSI/FBI Computer Crime and Security Survey is now published and some of the results are enlightening to say the least.

Since this is not a research paper, we can't publish the statistics of our main interest in the survey. Please see Table 1 on Page 14 for the next comment to have any relevance regarding the percent of respondents who "Don't Know" how many incidents they have encountered.

If one quarter don't know the number of security incidents, then that is around 175 companies who are flying blind or don't care about measuring the frequency, nature or cost of breaches. This is why we don't buy the general trend in Figure 14 that attacks or misuse detected are declining over the past 12 months.

27 September 2005

Rita and The Suicide Bomber...

Now that the U.S. is dealing with the aftermath of a Category 3 hurricane "Rita" and the U.K. is analyzing it's response to the 7/7 "Suicide Bombers", what operational risks do they have in common?

The answer is plain and the truth hurts. There is no stopping either threat and they will always find a way to inflict significant losses to our property and human lives. These threats are at opposite ends of the spectrum however when it comes to the event itself.

One attacker is tracked and shown on national television as it grows and bears down on it's next target. We know when and where. The other attacker is hard to detect in advance and operates in stealth. Now the question again is, what do they have in common? In both cases, we know they are coming again.

Our preparation and planning for the next incident itself, using a myriad of scenario-based exercises or tests can assist those who deter and detect these threats as well as those who will be tasked to alert or defend and help recover from the next one. These are both risks that you can help mitigate the consequences and the impact although one could argue the likelihood is inevitable and increasing.

What is less predictable is human behavior. The emotions, actions and attitudes of dozens, thousands or millions of people can't be predicted. One can only learn from these events and over the course of history, establish a baseline of knowledge. The next incident will be different and it will have some of the same characteristics.

Human behavior is the key to our greatest risk management challenges. Both the U.K. and the U.S. have seen the pictures of bomb and hurricane casualties in the past three months. Human behavior in one case has the attributes of a well-trained and coordinated response. The other case is rapidly becoming a "Case Study" for those public servants who are learning what went wrong. While it's unfair to compare the scope of the two scenarios, it's obvious that we still don't have a firm grasp on human behavior.

23 September 2005

Survive: A Strategy for Every Business...

Well over two years ago upon our founding, 1SecureAudit joined a global organization of people who really "Get it". Who understand and demonstrate the necessity and true philosophy of Business Crisis and Continuity Management. Is your U.S. institution a member? Do you have top executives who are contributing strategic resources and knowledge to the survival of your business? Ignoring the multitude of significant threats and business disruptions to your enterprise is nothing less than a lack of corporate strategy for long term survival.

Launched in 1989, Survive has since grown throughout the world to become the leading forum for expertise and information exchange among business continuity management practitioners and professionals, and all managers and directors with responsibility for ensuring the resilience and ultimate survival of their companies.

Originally focused largely on the back-up and recovery of IT and communications systems, Survive is now the only organisation of its kind in the world addressing the continuity needs of the entire organisation.

Our members are concerned about everything from protecting the company data and staff safety, to safeguarding the reputation and value of the whole enterprise.

The demands are growing on public and private sector organisations to prove they have processes in place to maintain continuous impressive performance 365 days a year, regardless of unusual internal or external circumstances. Such demands can be almost impossible to meet. But through understanding how organisations of different shapes and sizes tackle the difficult issues, members learn how to build resilience into their businesses and how to make business continuity a core part of the their company culture.

Business continuity management is about not making excuses. It's about being wise before the event. It is a state of mind that understands great organisations never moan they didn't do well because of the state of the economy, a fire at the warehouse, an internal fraud, or a strike by a group of key workers. Great organisations do well anyway.


As another Category 4 hurricane bears down on the U.S. for the second time in a month, we can only hope that the business community in Texas is ready. Gods speed to the people of Houston and beyond.

21 September 2005

Adaptation + Visible OPS = Managed Change

Managing Complextiy and change in any enterprise is an Information Technology nightmare. Adaptive can assist you in managing change.

A picture is worth a thousand words.

A model is worth a thousand pictures.

An Adaptation is worth a thousand models.

The Zachman Framework™ is often mistaken by some to be a 6 x 6 matrix. We believe that it is not. We see it as a structured, multidimensional management framework that helps organizations plan, design and implement complex, adaptable information systems. Our view of the framework is shown in this Adaptive rotating hexagon.

We believe that the Zachman Framework guides an organization to define its own unique business and technology "language". This language answers the questions about Why, What, How, Who, When and Where related to an enterprise's strategies, business processes and a number of more concrete levels of an information technology architecture.

The Framework is designed so that people with different perspectives can communicate. The different user perspectives are analagous to those with any complex engineering scenario - "Planner", "Owner", "Designer", "Builder", "Sub-contractor" and the final result - "Operating Enterprise".


In this article from George Spafford he articulates the essence of change management in the IT worldview.

"Change is pervasive through the organization and has huge impacts on the operations of the business. People at all levels in IT must understand and value the fact that as the level of complexity increases in a system, the value of effective change management processes increases.

Studies have shown that 80 percent of the fires that IT fights and 80 percent of security breaches are caused by human error. The vast majority of the problems in IT, and thus for the overall organization, will arise from human limitations in the face of escalating systemic complexity."


For those of us who use and advocate "Visible Ops", here are 4 reminder steps to running more effective ITIL operations in your enterprise:

1. Stabilize the Patient

2. Catch & Release and Find Fragile Artifacts

3. Establish Repeatable Build Library

4. Enable Continuous Improvement

Visit ITPI for more.

19 September 2005

Reputation Risk: Is Murphy to Blame?

Any board member or executive today is well aware of the direct impact an adverse event or significant business disruption can have on shareholder value and customer confidence. When it does happen, how many people just throw up their hands and shout, Murphy's Law!

Murphy's Law ("If anything can go wrong, it will") was born at Edwards Air Force Base in 1949 at North Base.

It was named after Capt. Edward A. Murphy, an engineer working on Air Force Project MX981, (a project) designed to see how much sudden deceleration a person can stand in a crash.


Murphy is all about managing the "What if's" and planning for their possibility. Here is an example. Are you moving your business sometime soon? What is the possibility that when you do, you will be able to use your e-mail the day you open your new doors? More than one business has been subjected to the Law's of Murphy whenever a complex and logistical project or program is underway. If you are one of those corporate executives who has been unable to use your e-mail or web services the Monday after the big office move, you are not alone. The question is not that it could happen, it's what impact will it have on both customer and employee satisfaction the day it happens, and beyond.

This Corporate Board Member article sums up the impact of Reputation Risk on your organization.

While every Board member knows the importance of managing Enterprise Reputation Risk, the task seems overwhelming. Some Boards are not even trying to proactively manage the risk: their companies will be forced to rely on “reactive” measures after the Reputation Risk event has occurred. These after-the-fact public relations initiatives are expensive and often ineffective. And, since they are event-directed, they don’t provide an ongoing risk structure for the company to identify and control other issues which can cause Reputation Risk. Considering the enormous loss of both financial and franchise value which accompany Reputation Risk, is a Board which only reacts to risk events really doing its job?


In your future planning to mitigate the Operational Risks associated with Murphy and your reputation, we are reminded of a few of our favorite Murphy's Laws:

1. Computer systems are unreliable, but humans are even more unreliable. Any system which depends on human reliability is unreliable.

2. If there is a possibility of several things going wrong the one that will cause the most damage will be the one to go wrong.

3. A difficult task will be halted near completion by one tiny, previously insignificant detail.

4. High speed chases will always proceed from an area of light traffic to an area of extremely heavy traffic.

5. Every emergency has three phases: PANIC... FEAR... REMORSE.

Do you think you're spending too much time with your team planning? You haven't. Success in your organization doesn't happen because everything goes according to the plan. It happens because you were prepared when things go wrong. The organizations whose team has planned for every possible scenario and trained together in live simulations will become the most successful. Their missions will be accomplished on time and within budget.

Incidents of different severity and frequency are happening around you and your organization every day. Would your employees know what an incident looks like let alone know what to do next to mitigate the risk to them and the organization?

15 September 2005

The Global State of Information Security: Still Risky Business...

Operational Risks are rising and executives are more interested in preparing their employees for the next crisis.

In a recent worldwide study by CIO Magazine and PWC concerning their risks, thousands of security leaders are fanning the flames over so many breaches and so little insight.

The survey asked about next year's 2006 top priorities or To-Do List:

1. Business Crisis and Continuity Management

2. Employee Training and Awareness programs

3. Data Backup

4. Overall Information Security Strategy

5. Network Firewalls


The good news is that the budgets are finally rising in light of increased theft of intellectual property and identities along with other major information crimes. Budgets in 2005 are now 13% of the IT budget. Consolidation and compliance are issues to be managed however these have bogged down strategic initiatives for the future.

Even after spending in the billions, incidents are still rising and these are the sources of the attacks:

59% - Malicious code

26% - Unknown

25% - Unauthorized entry

21% - Denial-of-service


And what is the most enlightening or discouraging statistic from this group is the answer to the question: When an incident does occur as a result of an attack, who do you tell?

No One - 55%

Customers - 16%

Partners/suppliers - 14%


Is there some correlation between the 26% unknown sources of attacks and the 55% of the incidents where no one is told about it.

12 September 2005

The Paradox of Privacy...

The banking industry has much to do to overcome the flat curve for new online customers. If this latest Ipsos Insight Research is correct, then privacy remains a significant issue in the consumers mind.

The proliferation of "phishing" and highly publicized hacker tactics have thwarted industry efforts to convince customers that online banking is safe. Results of the survey include:

83 percent of survey respondents who conduct their personal banking online reported concerns over protecting their personal information from theft.

73 percent of people said personal information theft is a deterrent for them to use online banking survey respondents were equally concerned about banks selling their personal information to a third party, with 72 percent of respondents citing the issue as "extremely" or "very important."


Promising not to sell your information to third parties is only part of the problem. The financial institutions are still using direct marketers and other data mining companies to make sure their latest loan offer goes to the most qualified and relevant customer. In some cases, the banks are doing much of the analysis in-house and only sending the "Bulk Mailers" the correctly correlated data records.

This New York Times article, Europe Zips Lips; U.S. Sells ZIPs, by Eric Dash sums it up quite nicely:

One thing that both privacy cultures have in common is that it is becoming harder for either to control what is and isn't kept private. Information is increasingly the lifeblood of the global economy, not to mention the global fight against terrorism and the quarry of hackers.

As this year's data breaches and compromises have shown, no one really knows how safe the world's vast pool of confidential data is, and therefore how protected anyone is against an invasion of data privacy.

Mr. Reidenberg, the law professor, compares the current situation to the stock market meltdown after the 1929 crash. America responded then by creating the Securities and Exchange Commission and a host of financial disclosure and accounting reforms. The need to safeguard sensitive data, Mr. Reidenberg said, "will necessitate the United States focusing on the legal way we structure information processing, just like we needed to do in the 1930's to put the economy back on stable footing."


With Identity Theft and Money Laundering as the two top issues with almost every banking institution, you would think that these 3rd party mailers would be consistently monitored and audited just as the banks are. Nothing could be farther from reality.

08 September 2005

Corporate Social Responsibility...

Corporate Social Responsibility (CSR) is getting a real work out since our planet's latest natural catastrophe, Hurricane Katrina. Organizations and companies many of us have never heard of are contributing supplies, manpower and aid to the recovery of this key economic region of the U.S..

Social responsibility is a matter more companies are paying close attention to these days and the potential risk that a blind eye may have on the future performance of the institution. What is most interesting are the stories of corporate heroism coming out of the news reports that validates this thinking. And the reports of those organizations who have failed to answer the call to act in the best interest of their employees and customers.

The risk of failed processes and programs pertaining to social issues is a real threat to the faith people have in your company and your brand, even if they are not a customer today. Contingency planners understand the impact that adverse business disruptions can have on the performance of the company. Less known is the impact that a lack of social responsibility can have on the damage to the brand and reputation of the organization. Many will soon find out as the truth is told.


As the political lines are drawn in the sand, one can only wonder who the real heroes are going to be after this historical event is documented. The mothers, fathers, brothers and sisters. The grand parents and the aunts and uncles. Those who weathered the storm or evacuated in time to keep their loved ones out of harms way. Hundreds of thousands of their stories will never make it to the six o'clock news.

Corporate Social Responsibility spans the spectrum from the local Wal-Mart, Marriott and Bank of America to the corner grocery and gas station. Yet the real winners are those who continue to utilize their own talents and resources to contribute in some meaningful way.

01 September 2005

Begin the Lessons Learned...Again

In the aftermath of Hurricane Katrina, one can only wonder what will happen next. We are already questioning our abilities to respond. One thing is certain, this will not be the last hurricane of this season or the last crisis event facing the Homeland. In order to make sure that organizations and businesses are even more prepared for the near future and beyond, you must have the correct systems to support your worst case scenario and contingency plans.

EMAware is an emergency management system for agencies, jurisdictions and companies that need to control the flow of information before, during, and after emergencies. Using EMAware, organizations can manage inbound and outbound emergency messages and create workflow rules that automate the process of activating emergencies and notifying key staff and peer organizations.

EMAware allows you to:

* Automate maintenance of Emergency Action Plans
* Originate, receive and manage CAP and EDXL alerts
* Support staff training and testing
* Integrate siloed monitoring systems
* Manage geographically dispersed offices and mobile workforces


Total organizational awareness is critical in emergency situations. And behind the awful images of CNN live on location, are thousands of people and computers behind the scenes making the recovery even more effective. Our intelligence branches are using geo-spatial imaging to help coordinate search and rescue operations using satellite pictures. FEMA, the Red Cross and DHS are communicating over secure networks for voice, email and text messaging.

No country has the means to recover faster from a disaster of this magnitude than the United States of America. 9/11 is now in our thoughts again this week. Always remember.