12 April 2006

CRO Strategy: Balancing Risk Across Functions...


RiskCenter (04/04/06) ; Kloman, H. Felix
At a recent Global Association of Risk Professionals (GARP) conference in New York, risk managers highlighted the importance of accurate data being provided to the appropriate decision makers in order to make the best decisions for a given situation, and risk managers also noted that they needed to be independent and objective at all times. Risk management tasks should not be absorbed by finance, accounting, or compliance functions, according to experts, because balance is needed between those functions and the risk managers' function as an educated "fortune-teller."

Chief risk officers (CRO), for instance, should be familiar enough with operational functions, while still remaining outside the internal politics of those functions, allowing them to make educated and objective decisions. Panelists at the conference touched upon the learning experiences they had from risk management mistakes and how they turned those mistakes into opportunities for their firms. For risk managers in the banking sector, Basel II is the latest challenge, especially when it comes to allying risks with capital holdings and the disclosure of how those calculations and decisions were made.


CRO's today are coming from more diverse backgrounds than from years past where they may have lived most of their careers in Finance or Internal Audit. Educated fortune tellers are a thing of the past as new tools, systems and sensors provide the modern CRO with new insight. As new tools are introduced to financial institutions to assist them with creating and mining loss event data, the regulators will be watching. What methodology and frameworks are acceptable? What process was utilized for critical calculations?

Lenders that are not banks or owned by banks--and therefore not subject to FDIC rules--are regulated by states. With the growth of these aggressive and potentially deceptive lending practices, state regulators have come under pressure to issue new rules or guidance to ensure that these "exotic loans" do not continue unchecked.


A Chief Risk Officer needs to be active with both state and national associations to keep in touch with the guidance that may be forthcoming.

10 April 2006

Coaching to Mitigate Risks on the Front Line...

HR Troubles are growing in the corporate ranks.

New and various studies reveal that unethical activity continues to occur in the private sector, even while SOX watch dogs are in place and whistle blowers are amoung us. Studies also suggest that large investments in compliance programs have had little impact. Indeed, 16 percent of HR professionals say they have quit their jobs for ethical reasons, according to a 2005 survey by SHRM, the top five ethical lapses given for resigning are:

Lying by management

Title VII violations

The falsification of reports and records

Employee privacy violations

Employees committing fraud


It's not surprising that these compliance programs may be having trouble getting the human behaviors to change. Coaching employees on a regular and consistent basis is far more effective than a one-time class upon hire. Management behavior is the litmus test on whether the culture of an organization could have the potential to become more ethical.

The enforcement of ethical and legal issues is often left up to corporate human resources (HR) departments, when it should be handled daily by front line managers. This is where the behavior or incident is observed in real-time and has the most credibility for making a coaching or serious discussion successful.

06 April 2006

Phishing: Why it Works and What is Next...

If you have ever wondered Why Phishing Works, you need to read this article by Rachna Dhamija at Harvard University, J. D. Tygar, and Marti Hearst from UC Berkeley.

What makes a web site credible? This question has been addressed extensively by researchers in computer-human interaction. This paper examines a twist on this question:

What makes a bogus website credible?
In the last two years, Internet users have seen the rapid expansion of a scourge on the Internet: phishing, the practice of directing users to fraudulent web sites. This question raises fascinating questions for user interface designers, because both phishers and anti-phishers do battle in user interface space. Successful phishers must not only present a high credibility web presence to their victims; they must create a presence that is so impressive that it causes the victim to fail to recognize security measures installed in web browsers.


The phishers are very good and spoofing financial services web sites to the tune of more than 2 million users being fooled last year alone. The web site designers are doing their best to create a site that is so sophisticated in it's look that it is more difficult to replicate on a fraudulent site and URL. The point is, we as consumers are always being asked for information only we would know, or information that we have to authenticate ourselves.

Why can't we turn this problem upside down? Why can't I authenticate the banks web site by asking the bank for a piece of information that only they have or would know the answer to? Some tools and technologies already exist to help with this upside down thinking. Bank of America is using SiteKey, that retrieves a graphical image from it's database, one that I have personally picked and no one else "should" be able to replicate. The answers are on the way.

Chris Young
Senior Vice President and General Manager, Consumer Solutions Division
RSA Security

As senior vice president of the Consumer Division at RSA Security, Christopher Young is responsible for driving the company’s consumer identity protection strategy, including the delivery of RSA® Authentication Service to provide simple and secure layered and two-factor authentication to all online users.

Cyota FraudAction Service is just one example of some new and exciting anti-fraud solutions on the way.


31 March 2006

OPS Risk Refresher...

What are Operational Risks? Here is a refresher for the Financial Services Sector:

Key People Risks

Employee fraud or malice Including collusion, embezzlement, sabotage of bank reputation, money laundering, theft of physical and intellectual property, programming fraud including virus introduction

Unauthorized activity
Including misuse of privileged information, churning, market manipulation, activity leading to deliberate mis-pricing or with unauthorized counterpart or unauthorized product, limit breach, intentionally incorrect models such as deliberate changes to parameters, activity outside exchange rules, illegal/aggressive selling tactics, Ignoring/short-circuiting procedures deliberately

Employment law Including wrongful termination of employment, discrimination/equal opportunity, harassment, non-adherence to other employment law, non-adherence to Health and Safety regulations Workforce disruption Industrial action and other forms of disruption

Loss or lack of key personnel Lack of suitable employees and loss of key personnel



Key Systems Risks


Technology risk
Inappropriate architecture

Investment risk Including strategic platform or supplier risk, inappropriate definition of business requirements, incompatibility with existing systems, obsolescence of software

Systems development and implementation Including inadequate project management, cost/time overruns, programming errors (internal/external), failure to integrate and/or migrate from existing systems, failure of system to meet business requirements

Systems capacity
Including lack of adequate capacity planning, inadequate software Systems failuresIncluding network failure, interdependency risk, interface failure, hardware failure, software failure, internal telecommunication failure

Systems security breaches
Including external security breaches, internal security breaches, programming fraud, computer viruses


Key External Risks

Legal/public liabilities Including breach of fiduciary duty, etc. Criminal activitiesIncluding money laundering, terrorism, robberies, etc.

Outsourcing/supplier risk Including breach of service level agreement, supplier failure, etc.

Insourcing risk Including failure of firm as supplier of services to third-party

Disasters and infrastructural utilities failures Including fire, flood, and failure of critical supplies etc.

Regulatory risk
Including change of regulatory rules etc.

Political/government risk
Including expropriation of assets, changes in tax regime, law and industry regime, etc.

Remember, this does not even cover the largest category of Operational Risk, Processes. The process associated with our different procedures, protocols and mechanisms for doing business are one of the greatest areas to incur loss events. Errors, ommissions and lack of training are just a few of the areas that need to have consistent monitoring and continuous auditing.

24 March 2006

Availability Bias: The Risk of Low Probabilities...

Should corporate America be concerned about weapons of mass destruction? How do you prepare for risks beyond your own workplace? Rad Jones from the School of Criminal Justice, Michigan State University, recently talked about a critical incident exercise he has prepared exclusively for CSO Magazine.

Rad Jones, formerly with the Secret Service and later on security projects with Ford Motor Company, emphasizes that you don't have a plan unless it has been exercised. This is especially true if you have not involved the local first responders in the local area. Role playing in exercises on scenarios that are real world and done on premises is a key component of the preparedness equation. What is left out in many instances during the exercise with the local police, fire or EMS is the Incident Command with the top brass or executives who may be in other locations across the country or the globe. This was witnessed in the Hurricane Katrina catastrophe.

Every metro area in harms way has the ability to do these exercises even on a micro basis. The single 15 story building, the business park surrounding the suburban mall or hotels and even a square block in a downtown city location is a good start. This coordination, planning and continuity builds a new level of resilience into the fabric of the community. This effort has been going on since 2003 with a consortium in Chicago, IL called ChicagoFIRST. This particular effort was spearheaded by the large financial institutions in the city who wanted to get a say and a seat inside the JOC (Joint Operations Center).

The spirit of ChicagoFIRST is spreading with the launch of WashingtonDCFIRST, a consortium based in the Wasington DC metro area. This project will be focused on the critical infrastructure private sector and the relevant interfaces to the local first responder jurisdictions. Collaboration with the Council of Governments (COG) will add the planning already underway for the past few years on issues such as interoperability and credentialing. As an example, the FCC has adopted a plan to establish a Public Safety and Homeland Security Bureau. The new Bureau is designed to provide a more efficient, effective, and responsive organizational structure to address public safety, homeland security, national security, emergency management and preparedness, disaster management, and other related issues.

Unlike other private sector initiatives, WashingtonDCFIRST will involve all the critical infrastructure sectors and the private companies who represent the largest employers around the beltway
including: Pepco, Verizon, Washington Gas, Exxon Mobil, AOL, and the Water Utilities. Much of the focus will be on availability bias.

Availability bias is why the U.S. has spent the past four years focusing on scenarios involving terrorism, after the so-called failure of imagination that preceded 9/11. What have politicians and citizens done for the past four years if not imagine terrorism?

And it's why many observers are now questioning whether the country should have spent that time planning not for terrorism but instead for other potential catastrophes. Like a deadly pandemic. Or major earthquake. Or hurricanes.

"One of the key dangers is that people are always focusing on the last catastrophe," says Robert Muir-Wood, the London-based chief research officer for Risk Management Solutions, which does economic risk modeling for the insurance industry. "It's a big challenge to keep everything in perspective and not be biased by what has last happened."

A true risk-based approach means that, when all else is equal, one must override the availability bias and focus on the most likely future scenarios. Unfortunately, figuring out the probability of any given scenario raises its own set of complexities.


The most probable risks that you train and exercise for, will be the incidents that you will be most prepared to handle. Suffice it to say, that the risks that you don't plan for because they are too low probability, will be the incidents or catastrophes that catch you off guard. Think about it. Not preparing and training for the low probability scenarios could cost you millions or billions and maybe your life.

22 March 2006

Pandemic Flu: Financial Institutions Contingency Strategies...

The Board of Governors of the U.S. Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and Office of Thrift Supervision are issuing an interagency advisory to financial institutions and their technology service providers.

This advisory is intended to raise awareness regarding the threat of a pandemic influenza outbreak and its potential impact on the delivery of critical financial services. It further advises financial institutions and their service providers to consider this and similar threats in their event response and contingency strategies. This issuance discusses the National Strategy for Pandemic Influenza (National Strategy) and the roles and responsibilities it outlines for financial institutions.

Critical infrastructure entities also must be engaged in planning for a pandemic because of our society’s dependence upon their services. Both the private sector and critical infrastructure entities represent essential underpinnings for the functioning of American society. Responsibilities of the U.S. private sector and critical infrastructure entities include the following:

• Establishing an ethic of infection control in the workplace that is reinforced during the annual influenza season, to include, if possible, options for working offsite while ill, systems to reduce infection transmission, and worker education.

• Establishing contingency systems to maintain delivery of essential goods and services during times of significant and sustained worker absenteeism.

• Where possible, establishing mechanisms to allow workers to provide services from home if public health officials advise against non-essential travel outside the home.

• Establishing partnerships with other members of the sector to provide mutual support and maintenance of essential services during a pandemic.


For more information see the official U.S. Pandemic Flu site.

16 March 2006

Whistleblowers: The Risk of Unethical Corporate Behavior...

To some people, Sherron Watkins is a hero. To others, she is an Enron Whistleblower that has capitalized on her now famous memo.

Ms Watkins had previously sent Mr Lay an anonymous memo questioning the use of off-balance sheet financial partnerships which were then running up huge losses.

In the memo, which she read out in court, she had expressed concerns that Enron could "implode in a wave of accounting scandals".

She added: "This was not just aggressive accounting, it was fraudulent accounting. I couldn't believe we had done it."


Implementing an effective ethics and compliance program in corporations requires a robust educational and legal strategy. Awareness development, effective policy design and administration is imperative if the organization is going to have any chance of achieving high marks in Corporate Governance.

David Gebler makes some valid points in this article:
Moving in the Right Direction

How do compliance leaders move their organizations to these new directions?

1. The criteria for success of your ethics program must be outcomes-based. Merely checking off program elements, even from the seven steps of the Federal Sentencing Guidelines, is not enough to change behavior.

2. Each organization must identify its own key indicators of its culture. Only by assessing its own ethical culture can a company know what behaviors are the most influential in effecting change.

3. The organization must gauge how all levels of employees perceive adherence to values by others within the company. One of the surprising findings of the (2005 National Business Ethics Survey) (NBES) was that managers, especially senior managers, were out of touch with how non-management employees perceived their adherence to ethical behaviors. Non-managers are 27 percentage points less likely than senior managers to indicate that executives engage in all of the ethics-related actions outlined in the survey.

4. Formal programs are guides to shape the culture, and not vice-versa. People who are inclined to follow the rules appreciate the rules as a guide to behavior. Formal program elements need to reflect the culture in which they are deployed if they are going to be most effective in driving the company to the desired outcomes.


While there may be some who say that a whistleblower is just a discouraged or passed over employee, it may be the origin of a corporate environment that is ready to implode. Fraud and other unethical corporate behavior is a combination of poor operational risk management controls and the people who perpetuate the culture of dishonesty. In a recent survey by Protiviti, companies continue to admit to poor risk management practices.

Other findings of the survey:

* 43 percent of executives consider financial reporting and Sarbanes-Oxley Section 404 compliance to be very significant risks.

* 49 percent tie business success to client satisfaction, believing potential weaknesses in this area pose a very significant risk. Executives said the following risks affect their company's ability to sustain customer satisfaction: operating performance; materials procurement; business continuity; and fraud matters.

* 45 percent of executives cited information systems and IT security as potential areas of vulnerability.


03 March 2006

Keeping Your Business Clean...Revisited

This two year old article is still so true. Worth revisiting in a more risk management conscious corporate environment.

Keeping Your Business Clean - CSO Magazine - June 2004

Take this quiz to test the ethical health and well-being of your business.


BY ANONYMOUS

A COLLEGE PAL OF MINE—a corporate lawyer at a major, publicly traded company—has been watching all of the corporate-integrity meltdowns from his not-so-distant vantage point. Just for fun, he helped me devise a quiz of sorts to check out the "uprightness" of my own situation at my company. I was shocked and disturbed enough with my results to share them here (under the protection of anonymity, of course).

Maybe I'm a good Samaritan, but I care about America's corporations, and I hope our times offer an opportunity to change some thinking. Take this little corporate hygiene quiz with a few of your trusted business pals over a latte or two. And since catharsis is good for the soul, I'll share my answers with you here. I used a scale of one (not so much) to five (absolutely) to get a numerical sense of where I stood.

To start, does your business depend on a complex technical environment with significant uptime reliability?


Aren't we all increasingly reliant on a networked environment with nodes, access points and critical intersections in places that we can't see or control? Uptime reliability is important for everybody these days, but it's an expected cornerstone of businesses that feel they need to hire a CISO. I give myself a four on this one.

Does your company have operations in any country below the equator?


Many U.S. companies have core business processes located in countries below the earth's beltline. Security risks exist there that make knowledgeable security professionals twitch every time their phone rings: kidnappings, corruption, incompetent and criminal law enforcement, Internet crime, organized crime, drugs, money laundering, an overall unsafe environment with too many Foreign Corrupt Practices Act temptations. But what are you going to do? The labor is cheap and we have to be competitive. My company is moving in that direction but not there whole hog yet. So I'll give us a three on this one.

Would you characterize the velocity of your company's business as high-speed?


How about warp speed? How else can we continue to satisfy Wall Street and our fickle shareholders? We're all being pushed to do more with less. And there's so much going on in the back draft of this fast pace, I wonder what the hell else I'm missing. I'll take a five on this one. I'd take a six if it were allowed.

Do you forgo a criticality rating to identify shortcomings in business controls and security measures?


With all the open books and disclosure emphasis these days, the lawyers are really nervous about recording any risk information that could come back to haunt us. As a security professional, I've always lived with criticality ratings—it's all about the likelihood of problems we need to be prepared to address. But I know for a fact that we have no organized process for doing this across the business. In the aftermath of Sarbanes-Oxley, our auditors now rank their findings; but that's ex post facto and, besides, an audit is cyclical and periodic. This is all about what keeps knowledgeable risk managers awake at night and what we are missing. I'd better take a four (and hope for the best).

Does your corporate risk-management model discourage individual managers from seeking out vulnerabilities in the system of controls?

My company doesn't have a risk-management model, per se—and then blame is typically parceled out to the lowest common denominator. I'll take a four on this one, too. (This isn't shaping up well is it?)

Are managers ill-informed about what to look for on control deficiencies or cues on risky behavior?


There's not a lot of sharing here, especially concerning errors or incidents. After all, who wants to shoot themselves in the foot? We have an active infosecurity awareness program, but it hasn't been integrated into any of the training and employee development programs we run on a continuous basis. HR owns management training, but it doesn't recognize that the manager's job has a core risk-management component. And what's the first question out of the CEO's mouth when it hits the fan? "Who's the manager of this disaster?" I can't vouch for manager awareness across the board. So let's score a three here.

Are there unaddressed vulnerabilities in your company's safeguards or other such exposures that could be exploited?

The fact that this question has to be included speaks volumes about the maturity of risk management. Of course there are known gaps! And it's the people who work here who know where to find the holes. The guy who is empowered to do you the most damage already works for you. The developers leave open doors in our applications, and our LAN administrators have the keys to the kingdom. There's no one place where all the data comes together to enable those of us on the firing line to see where the interconnections and interdependencies may exist. Besides, I get paid to think about "what if," so scoring anything less than a five would be dishonest.

01 March 2006

The Wild West of the New Millennium...

Rather than engaging in a futile attempt to suppress technology, the music business should try to work with consumers. Murray writes: "The most sustainable solutions include the creation of favorable alternatives to piracy by making legitimate distribution channels more convenient." Bingo! Imagine how much more money the music industry would have made by creating pay-per-song download sites instead of paying lawyers to prosecute downloaders."


These words by Brian H. Murray were the writing on the wall in January 2004 in this article by Jonathan Jackson. Mr. Murray may have predicted the transition by the MPAA and other digital rights advocacy groups to change the industry from one of piracy to one of profits. Introduce Mr. Steve Jobs of Apple, the iPod and iTunes and now you have your 1 billionth download. That's .99 cents X 1,000,000,000.

How could you endorse the use of technology and tools like Weblogs to create new opportunities for your enterprise? Message boards and other chat web sites have been around for a decade making online brand management a necessity for any brand conscious entity. Defending The Brand was the title of Brian Murray's book published in 2004 and it is still a component of any comprehensive risk management strategy.

Managing Intellectual Property Rights and sensitive or proprietary information is a major concern for General Counsel's and Chief Marketing Officers. Making sure that trade secrets and ideas are protected is a priority. And when it comes to employees expressing their opinions about management, the watercooler and local bar has not been enough. When message boards, web sites or blogs post comments on a company or organization they typically are a way for discouraged, disgruntled or maybe even dangerous employees to vent their feelings.

The intersection of Civil Rights, Privacy, Cybercrime and White Collar Crime is creating a buzz. With whistleblowers sending anonymous email, posting to weblogs and a whole new spectrum of enforcement actions, sometimes you have to step back and see the big picture. General Public License, 3.0 and Open Source has created new subjects for debate.

The Operational Risks in your organization are growing at an exponential rate. Cooperation and information sharing is still a road block to progress. The answers are only clear if you can see the beauty in what Mr. Murray's thinking was over two years ago:

"I never cease to be amazed by the bold, clever, and unscrupulous behavior that is so common on the Internet. Through my experience defending brands, I can say with confidence that anything that you thought would never happen online is probably already going on, and anything you think couldn't possibly exist on the Internet is almost certainly there. Though it's an overused cliche, the Internet really is the Wild West of the new millennium."


26 February 2006

eDiscovery: New Threat or Opportunity?

In the midst of the Enron trial there are many CISO's and CEO's scratching their heads while they grab another pack of TUMS off the desk. eDiscovery is a compelling threat and opportunity for the organization. In either case, it will cost millions of dollars.

Conducting effective internal investigations and even thorough incident response requires a robust Governance Strategy. Just ask Morgan Stanley about it's $1.45 billion verdict in a default judgement when the bank failed to respond plaintiff's discovery requests for computer-based information.

An outsourced process for eDiscovery is quickly becoming a real board room issue. Not only because of the financial impact, $7K to $12K per hard drive but also the number of cases that are settled prematurely. Outside counsel handles the eDiscovery process on a per-case basis and is not typically interested in what the company must do internally to create and establish a long-term governance and risk management strategy.

The CISO who directs a system of consistent Information Security Risk Management will have the foundation for an in-house eDiscovery team and who can work side-by-side General Counsel for compliance and incident response.

Paul French is a computer forensics consultant with a few TIPS:

Ensuring Compliance

A good digital document retention policy is, of course, only as good as the method in which it is implemented. Here a few compliance guidelines you should have your clients consider:

* Establish a records compliance task force, so there are easily identifiable “go-to” people regarding retention activities.

* The compliance task force should create detailed logs of record-purging and back-up activities.

* Archiving procedures should be periodically reviewed and tested. More times than your clients would care to admit, electronic record back-ups are not properly performed or aren’t being performed at all. Incompetence is not a sound defense strategy! If back-up tape hardware is updated, be sure that there’s a back up plan for accessing data on old tapes--these likely will not work with newer hardware. Old back-up tapes stored in a seldom visited closet could pose an unpleasant surprise if they appear suddenly in discovery proceedings, particularly if your client is unable to find the hardware needed to review them.

* Make certain that all media are considered and accounted for in the purging policy. This includes not only servers, desktops, and laptops, but also PDAs, BlackBerries, and various removable media devices.

* It’s a good idea to have an objective third party periodically review and validate that policies are being followed. In doing so, the vendor should interview key personnel and review a sampling of data using forensic tools.


CISO's are seeing their budgets and powerbase grow yet the goal remains the same, Enterprise Risk Management. The Board of Directors now recognizes the significance of having a CISO with an established team for eDiscovery, no matter who may be asking for the timely information.

24 February 2006

OPS Risk: From Basel to the Hearing Room...

The Basel Committee on Banking Supervision, an arm of Switzerland-based Bank for International Settlements, has defined the Basel II capital adequacy requirements for global banks. One of the committee's principal goals is to reduce risk in the financial system worldwide by aligning each banks capital requirements to more accurately reflect its credit, market and operational risks.

Archer Technologies (Archer), a leader in enterprise security and compliance solutions, has announced the release of its Vendor Management solution. Vendor Management enables organizations to consolidate disparate vendor information into a single application to optimize resources and reduce risk. Archer also announced its expansion into operational risk management with the introduction of the Sarbanes-Oxley (SOX) Compliance Management solution. This new offering complements Archer's Vendor Management product and enables companies to dramatically decrease the cost and effort associated with SOX compliance.

The significance of the new modules from Archer could be summed up in one or two words.

Convergence

Relevance


Due to the number of financial institutions currently utilizing these solutions for Enterprise Security Management it makes sense to add the modules that intersect with the Enterprise Risk Mission Critical Activities. Operational Risk Management is converging with some of the elements of the traditional CISO job function. Just ask any CISO (Chief Information Security Officer) at a public institution about the number of times the audit teams have been knocking on the door trying to get access.

The relevance of supply chain management and SOX Management modules for the CISO has to do with the real essence of what Operational Risk is all about. Three years ago just managing threats to the desktop PC's, Web Servers and other vital E-Commerce functions was enough. Not anymore.

Now you must add your inteligence feeds from providers such as iJet, OSAC, iDefense, Shavlik, and Stratfor. Then you combine your Real Estate assets including facilities, Gulfstream G5's and create a correlation of real-time enterprise risk to give you a 360-degree view. Combine this with a monitoring system for the ever changing controls in your ERP system and now you have a holistic mechanism for mananging Operational Risk in your enterprise.

That's the easy part. The hard part is yet to be done. The correlated information still requires the grey matter to make faster and more relevant decisions to accept, transfer or mitigate this threat. What are the implications of each? When do I act? How do I execute? All the knowledge from your tools and systems still leaves the most difficult aspect of Enterprise Risk Management.

Just ask all of the people sitting in SOC's, JFO's or any center where a fusion of information is creating the knowledge necessary to make these decisions. They all have the same answer:

You must create a “culture of preparedness” in which all people share responsibility for corporate risk management and homeland security. This includes strong partnerships between federal, state and local governments and especially the private sector. You never know where or when your next incident is going to occur:

The Phoenix hostage incident began about 3:30 p.m. (5:30 p.m. ET) when a man entered the offices of the National Labor Relations Board, grabbed a secretary and took her into a room where a hearing was being held, said Gordon Jorgensen, who retired last month from the board and had spoken with some of the NLRB employees.

"The guy was apparently in our reception area and wanted to talk to someone and ... one of our secretaries walked by. He pulled a gun on her" and escorted her into the room, where a hearing was being held.

One woman escaped early in the evening and a second woman was released about an hour before the man surrendered.

Dozens of police and fire crews were on the scene, and authorities evacuated the building and sealed the area.


10 February 2006

Economic Espionage: Chasing 0's and 1's...

What do corporate executives worry about these days? The same thing Chief Security Officers and General Counsels have nightmares about. They all realize that globalization is truly upon us. Rapid transportation, open borders and the Internet have opened new doors for criminals and terrorists to move information quickly, deploy orders and even post stolen assets for sale in an underground world of ubiquitous trade.

Economic Espionage is the #2 issue at the FBI and for good reason. The recent indictment of Suibin Zhang illustrates just one example of a crime happening all too often and right under the corporate executives nose.

The United States Attorney for the Northern District of California announced that Suibin Zhang, 37, of San Jose, California, was charged late yesterday by a federal grand jury in San Jose in a nine-count indictment alleging computer fraud; theft and unauthorized downloading of trade secrets; and the unauthorized copying, transmission and possession of trade secrets.

The maximum penalties for each of the computer fraud counts is 5 years imprisonment, a $250,000 fine or twice the gross gain or loss and 3 years supervised release. The maximum penalties for each of the trade secret counts is 10 years imprisonment, a $250,000 fine or twice the gross gain or loss and 3 years supervised release.

An indictment simply contains allegations against an individual and, as with all defendants, Mr. Zhang must be presumed innocent unless and until convicted.


The people who work for your organization need to have a greater awareness of what the Economic Espionage Act of 1996 is all about. Whether the information that was presumed to be stolen is Mr. Zhang's property or the property of his employer will be at question here. Corporate Information Security Policy will have covered this yet the motivation and the lack of understanding of what constitutes intellectual capital or trade secrets is what needs the most clarification with employees.

VIII.B. The Economic Espionage Act of 1996, 18 U.S.C. �� 1831- 1839
VIII.B.1. Overview of the statute The Economic Espionage Act of 1996 ("EEA") contains two separate provisions that criminalize the theft or misappropriation of trade secrets. The first provision, codified at 18 U.S.C. � 1831(a), is directed towards foreign economic espionage and requires that the theft of the trade secret be done to benefit a foreign government, instrumentality, or agent. It states: (a) In general. -- Whoever, intending or knowing that the offense will benefit any foreign government, foreign instrumentality, or foreign agent, knowingly - (1) steals, or without authorization appropriates, takes, carries away, or conceals, or by fraud, artifice, or deception obtains a trade secret; (2) without authorization copies, duplicates, sketches, draws, photographs, downloads, uploads, alters, destroys, photocopies, replicates, transmits, delivers, sends, mails, communicates, or conveys a trade secret; (3) receives, buys, or possesses a trade secret, knowing the same to have been stolen or appropriated, obtained, or converted without authorization; (4) attempts to commit any offense described in any of paragraphs (1) through (3); or (5) conspires with one or more other persons to commit any offense described in any of paragraphs (1) through (3), and one or more of such person do any act to effect the object of the conspiracy, shall, except as provided in subsection (b), be fined not more than $500,000 or imprisoned not more than 15 years, or both.


07 February 2006

Grass Roots Risk Management...

When you set your organizational direction and adopt a common language and framework for managing risk you must include the measurable categories associated with credit, market and operational risk. Many choose to adapt the COSO Guidelines to create their unique risk management and control framework.

The question remains, Is that enough? Do you have enough categories to truly address the methodical management of all material risks?

The Board of Directors must be able to understand the framework to begin any meaningful programatic approach to identifying, assessing, managing and mitigating risks. Now what would happen if you added a few more categories to include:

1. Compliance
2. Legal
3. Strategic
4. Reputation

Certainly the Board understands that these are real and important categories to include in the framework. However, these are much more difficult to measure and merge with the new governance culture found in most SOX oriented organizations.

Creating the right environment for employees and supported by the correct processes is not enough these days. Now the front line must also have the right tools to help in performing risk assessments and analysis as change takes place in products and the market place. Creating a risk culture that is effective is a balancing act for employees who are trying to decide if they have a material risk to mitigate or an opportunity that has yet to be realized. Employees need to be able to embed this kind of decision making into the fabric of their daily work routines as opposed to a quarterly or annual exercise.

The largest institutions that have already established the framework, support processes and tools along with the staff are well on their way to meeting the goals of prudent corporate governance. Developing a more comprehensive and pervasive adoption rate across the Tier II and small to medium-sized intitutions is far from reality. We are just beginning this long and difficult journey.

Maybe the biggest question for these evolving risk management cultures is how and where to begin? The answer might be found in your current abilities to deal with "Change" itself. At the end of the day, any Operational Risk Management program is going to be about the ability to address the velocity of change. If you haven't been getting an "A" in this part of your report card then you can be sure that managing your new found material risks will be far from excellent.

A "Loss" is a financial impact from an event that shows up on the companies financial statements. This financial impact shows up as "write-downs" or other entries in the annual report. As you build a Loss Event Database to record losses across the organization you expose the organization to new risks that have never been known before. This is where resources are invested and where management realizes the beauty of having a "Grass Roots Risk Management" initiative.

03 February 2006

Managing Strategic Change for Operational Risk...

There have not been more sweeping changes in business regulation and compliance since the Great Depression. The fall of Enron Corporation provided much of the catalyst for new laws and new corporate governance oversight. The Board of Directors and senior management are now tasked with the continuous risk of “operational volatility” with people, processes, systems and external events. Effective Operational Risk Management begins with an effective strategy to manage change in your organization.

What institutional fraud presents the greatest operational risk to companies? In a recent poll by Oversight Systems of 200+ Certified Fraud Examiners:

63% - Conflict of Interest

57% - Fraudulent Financial Statements

31% - Billing Schemes

29% - Expense and Reimbursement Schemes

25% - Bribery/Economic extortion

20% - Inventory and Non-Cash Asset Misuse


From the conviction of former WorldCom CEO Bernie Ebbers to the acquittal of HealthSouth’s Richard Scrushy, corporate fraud continues to make headlines. Four years after Enron’s collapse, financial integrity remains a key issue for corporate America.

The 2005 Oversight Systems Report on Corporate Fraud surveys certified fraud examiners to report the trends, risks and major concerns that businesses face today.

While most fraud examiners view Sarbanes-Oxley (SOX) as an effective tool in fraud identification, few think it will change the culture of business leaders. Nearly two-thirds of respondents (65 percent) indicate that SOX has been somewhat or very effective in identifying incidences of financial-statement fraud. Only 19 percent of those surveyed found SOX to be ineffective or serve to prevent fraud identification.


·What are the consequences of ignoring need for change related to operational risks?

·What will be a starting point for initiating changes related to operational risk management?

·Is your organization ready for managing changes in order to manage operational risk? If yes, at what readiness level? If no, how can it become ready?

Are you a boardroom director or senior corporate manager? Does your organization have a culture that avoids an examination of organizational processes such as decision-making, planning and communication concerning the risk of change? Are you an executive who would like your organization to accept, adapt and therefore institutionalize and legitimize these processes related to operational risk?

If you said yes to any the questions above and nodded positively to the possibility for a change in your organization, then first you must effectively
"Manage Strategic Change for Operational Risk".


01 February 2006

Internet Crime Pandemic: The Botnet Outbreak...

If you thought that your INFOSEC team was busy last year, they haven't seen anything yet. The rise of Trojans & Botnets is becoming an Internet Crime Pandemic.

"Cyber-crime nowadays takes many forms, and perhaps even more dangerous than botnets are the targeted attacks that we have witnessed recently," explains Luis Corrons, director of PandaLabs. "The biggest problem lies in their secrecy: a large company could be serving the interests of a group of malware creators without realizing it. Many of their computers could be at the disposal of these cyber-crooks, with all the legal implications that this might have for the company itself." Until now it is a risk that companies have not considered sufficiently, but one which is no longer possible to ignore."


Most of the successful attacks exploit the most vulnerable facet of every companies defense. It's people. Targeting executives within a specific industry group such as the savings and loan sector is a good example. The global marketplace for reselling data about people is now showing exponential growth. Once the executive clicks on a link inside what looks like a legitimate email he has opened his network to a potential new "Zombie".

Why do the spammers, pharmers and spear phishers continue to invest in these types of attacks? It's good for their criminal business.

The FBI recently snared a 20-year-old hacker (Jeanson James Ancheta) whom they believe wrote computer code to assemble botnets and sell access rights after he was lured into a trap. Ancheta in his plea accepted responsibility for selling botnets and directing zombie machines to surreptitiously download adware besides intruding into government computers.

Ancheta is understood to have as a result benefited by $3,000 from botnet sales and $60,000 from the clandestine adware downloads. With close to 400,000 machines under his control, Ancheta was doing well enough to gift himself a BMW.


28 January 2006

Travel Threat: Executive Operational Risk...

Operational Risk Management is a vital component for any Board Member or Corporate Manager who travel internationally.

Company executives who travel extensively on commercial airlines are constantly being subjected to a spectrum of new threats. The latest concern is putting executives in potential harms way with the rise in Avian Flu.

Once these highly compensated and important corporate officers reach a cities destination, there is of course the choice of hotel. Where and where not to stay is now a question many corporate travel departments are asking themselves. How do you know what is the most secure and safe place to stay?

Stratfor provides substantive tips and advice from their intelligence and publications. Terrorist attacks in past years against U.S., Israeli and Australian embassies forced Western countries to harden their diplomatic compounds abroad, turning them into veritable fortresses of security. In response, terrorists began focusing on softer symbols of Western influence, such as large hotels and resorts. By attacking a Marriott, a Hyatt, a Moevenpick or another popular Western chain, the perpetrators can cause mass casualties and gain international media attention -- and all without having to penetrate extreme security.


As a saavy travel department and global corporate security chief already know, there are some other choices that should be considered namely, iJet:

iJET was incorporated in 1999 with a mission of protecting international travelers through the use of our proprietary technology and services platform. That mission has evolved and broadened over time as our Worldcue® Risk Management System has been applied to protecting both employees and other assets of multinational corporations. Today, iJET has over 350 corporate clients that rely on iJET to monitor, protect, and respond to operating risks around the world.

The escalation of terrorism, infectious diseases, and unforeseen natural disasters has forced multinational organizations and their employees to re-evaluate their perception of risk. Such events are often beyond a company's control, yet corporate liability and responsibility to employees and assets continues to increase. As a result, corporations need a fresh approach and new set of tools to meet the operational risk management demands in today's business environment.


This part of the equation is an easy one. Get real-time intelligence while on the go and utilize strategic tools and solutions for risk mitigation along the way. Moreover, travel light and without a huge entourage of large NFL size body guards in tow. You might as well paint a bulls eye on your back.

The hard part of the equation is getting your executives and highly valued employee assets trained and ready. Having all of the "What Could Happen" and "Be Careful of" in your head will not be enough unless you train, practice and test. Many global companies are doing just that, training their employees in threat detection and giving them new skills and strategy to save themselves from potential attacks of all kinds. See Threat Detection and Management to learn how.

24 January 2006

Supply Chain Risk: Spending Time with The Right People...

What is the largest obstacle within your organization to address risks such as corporate fraud, natural disasters and disruptions to your supply-chain?

According to top responses in a recent poll of 600 financial executives accross the United States, the UK and Europe:

33% - Insufficient Time

23% - Inadequate Personnel

19% - Insufficient Budget

13% - Not Viewed as a priority


Does this mean that the Board of Directors has transfered risks using vehicles like insurance? The same study asked what percentage of risk management budgets are allocated to "Risk Control" vs. "Risk Transfer":

Risk Control - 56%

Risk Transfer - 44%


While there are new and innovative new insurance policies being marketed these days, these typically can not cover many of the losses from damaged corporate reputation, a drop in market share or lost sales. As Board of Directors raise the priority above a 13% response, this should cascade to impact the insufficient budget. Now the question remains on how to deal with the "Inadequate Personnel" and "Insufficient Time".

You can hire dedicated people, add additional responsibilities to existing personnel or you can even Insource. In every case, you will need to find more time for planning and training to make sure that new risk controls are implementated and monitored. Without a systematic program that is culturally institutionalized, even these new initiatives will fail.

To quote one of the leading global business continuity membership organizations Survive:

Business Continuity Management is about not making excuses. It's about being wise before the event. It is a state of mind that understands great organizations never moan they didn't do well because of the state of the economy, a fire at the warehouse, an internal fraud, or a strike by a key group of workers. Great organizations do well anyway.


20 January 2006

OFAC Compliance: Ensure Your Transactions are Legal...

Archaic and ineffective name searching technology is still in use today across all levels of intelligence agencies and law enforcement. Names remain the single most important means for identifying persona non grata at our borders. Biometrics are only useful the second time you meet someone. Everyone in the world knows how easily security at America’s borders can be circumvented — except Americans.

Language Analysis Systems is the world's recognized leader in providing multi-cultural name recognition software solutions for mission critical applications. We have worked with U.S. Intelligence and Border Protection agencies for nearly two decades, developing a revolutionary and patent-pending approach to name matching and searching, going far beyond simplistic Soundex and key-based approaches. We offer a variety of proven commercial products to government, law enforcement, and commercial organizations that solve a multitude of name related problems.


How else can this technology be used to help our DHS with the war on terror? Are you a U.S. business? If you are, then you must comply with OFAC especially if you are a financial institution, mortgage broker, car dealer, boat dealer, real estate agency or insurance broker.

OFAC administers and enforces economic and trade sanctions against targeted foreign countries, terrorism sponsoring organizations and international narcotics traffickers.

Pay attention. Dutch bank giant ABN Amro Bank , has agreed to pay a total of $80 million in US fines for violating regulations to prevent money-laundering, regulators and the bank said last month.

The Financial Crimes Enforcement Network at the Treasury Department said that ABN's "serious, longstanding and systemic" problems allowed people from Russia and other former Soviet republics to move $3.2 billion to shell companies in the United States from August 2002 to September 2003.

Investigations by state and federal officials also found that the Chicago and New York branches of the bank participated in wire transfers and trade transactions from 1997 to 2004 that violated economic sanctions on Libya and Iran.

ABN AMRO said on Monday that it recognises that serious mistakes were made and accepts the sanctions.


There are now dozens of software solutions and programs available to help with compliance of BSA and AML compliance. The question is, which one is right for your organization? If you do not have a step in your customer or client acquisition process that intersects with compliance then you are at significant risk.

Sales and business development personnel, business development or broker networks must be able to have a high degree of confidence that the business or person they are creating the quotation or proposal for is not an SDN, or Specially Designated National.

Are you an insurance company who uses a network of brokers? What are you doing to implement the policies and programs to comply with this new requirement:

The final rules apply to insurance companies that issue or underwrite certain products that present a high degree of risk for money laundering or the financing of terrorism or other illicit activity. The insurance products subject to these rules include:

• permanent life insurance policies, other than group life insurance policies;

• annuity contracts, other than group annuity contracts;

• any other insurance products with features of cash value or investment features.

At minimum, insurance companies subject to the rule requiring an anti-money laundering program must establish a program that comprises four basic elements:

• A compliance officer who is responsible for ensuring that the program is implemented effectively;

• Written policies, procedures, and internal controls reasonably designed to control the risks of money laundering, terrorist financing, and other financial crime associated with its business;

• Ongoing training of appropriate persons concerning their responsibilities under the program; and

• Independent testing to monitor and maintain an adequate program.


19 January 2006

Scenario Analysis: The Value of the Hypothesis...

In the December 2005 issue of OpRisk and Compliance Magazine Dean Lamble from Hewlett-Packard has this to say in the article on "Planning for Disaster":

Key areas will include security, evolving threats of terrorism, and how to cope with a pandemic outbreak such as bird flu. Companies will be paying far more attention to how the contingency plans perform when tested. Compliance continues to be a key concern, with increasing legislation directing responsibility to the board.

More than 25,000 banks around the world will work to comply with Basel II over the next five years. One of its most controversial aspects is the inclusion of Operational Risk Management. While banks have attempted to manage operational risks for many years, now for the first time they must measure it.


Most money center banks have already achieved high levels of competency with capturing loss events and with risk self-assessments. Scenario analysis and KRI (Key Risk Indicators) is still a distant goal. OPS Risk is still a maturing discipline and regulators are allowing some flexibility here. However, financial institutions are still stuck to some degree on imagining incidents that have not occured to them in the past. Probabilities are not low just because they haven't happen to your institution historically.

A hypothesis is the place to begin.

hy·poth·e·sis ( P ) Pronunciation Key (h-pth-ss) n. pl. hy·poth·e·ses (-sz)

1. A tentative explanation for an observation, phenomenon, or scientific problem that can be tested by further investigation.

2. Something taken to be true for the purpose of argument or investigation; an assumption.

3. The antecedent of a conditional statement.


If an event has happened to another insitution is it so improbable that it could also happen to your own firm? The starting point for effective scenario analysis is the intelligence and the external data that provides the evidence of such an incident. Then the goal is to gain "insight" on how it could happen and what the impact would be in your own environment. Capture of data on extreme events is imperative even if only one $10M. event has occured in the last ten years.

Today, an audio tape from Osama bin Laden has been posted on the Internet along with a transcript of his comments. The authenticity is being validated as he has not been heard from for over one year. Has your scenario analysis included potential events of the magnitude of the 7/7 bombings in London or the 11/9 Amman Jordan suicide attacks on three Western hotels?

"Bruce Newsome, a terrorism researcher at the think tank RAND, said the plot carried out by four men in London is a "likely model for future U.S. attacks." The bombers, all British citizens, had no criminal records, weren't on any watch lists and had no extremist pasts. (A fifth man, believed to be the mastermind of the plot, has been arrested in Egypt.) Tracking such potential perpetrators is nearly impossible because there are no warning signs, Newsome said."


Somewhere in your contingency planning and scenario analysis there must be hypothetical loss events on the magnitude beyond our imagination.

17 January 2006

You've Been Indicted. The Most Feared Words in the Boardroom...

Over two years ago this corporate governance article appeared in Corporate Board Member Magazine.

June 25, 2003
You've Been Indicted. The Most Feared Words in the Boardroom

By Peter L. Higgins


Every Fortune caliber organization from financial services to health care has already implemented a pervasive compliance program to mitigate the risk of ending up with the SEC or US Attorney in the lobby.

The catalyst behind these initiatives is generated from the U.S. Sentencing Commission's Organizational Sentencing Guidelines. They allow for more lenient sentencing if an organization has evidence of an "effective program to prevent and detect violations of law."

The Guidelines contain criteria for establishing an "effective compliance program."

These include oversight by high level officers, effective communication to all employees, and reasonable steps to achieve compliance such as:

* Systems for monitoring and auditing
* Incident response and reporting
* Consistent enforcement including disciplinary actions


Yet the corporate incivility continues. Why is it that we can’t pick up the morning paper or listen to the news on the way to work without hearing about a new indictment of a top ranking officer?

Here lies the question many Board of Directors are scratching their heads about these days. How can we avoid these ethical and legal dilemmas and how can they be addressed without creating a state of fear and panic?

The answer lies in the human factors of what motivates people’s behavior. This requires programs, controls and good old fashioned vocational counseling. However, the real facts are that all of these alone will not be able to stem the tides of corporate malfeasance.

A guest column by Jacob Blass
President, Ethical Advocate
highlights the past few years:

The number of companies around the world that reported incidents of fraud increased 22% in the last two years according to the 2005 biennial survey by PriceWaterhouseCoopers (PWC), which interviewed more than 3,000 corporate officers in 34 countries. In England, a recent Ernst & Young survey of the Times Top 1000, indicated the average cost of each fraud exceeded $200,000.
But fraud is not the only problem. There's also misconduct, unethical behavior, lying, falsification of records, sexual harassment, and drug and alcohol abuse.

PWC found that “accidental” ways of detecting fraud, such as calls to hotlines or tips from whistleblowers, accounted for more than 33% of the cases. Internal audits were responsible for detecting fraud about 26% of the time.


If these latest figures are correct than this means that 59% of the detection was a result of effective operational risk management. Let's just hope that the remainder is the result of corporate managers and leaders doing their job to mitigate new risks on a daily basis.

As indicated, the great manager can impact the lives of tens or hundreds of people in your company. Conversely, the uncivil manager can wreak havoc with a similar numbers of lives. The position of management is ever so powerful to influence those around them.

Your company wide compliance initiative has the elements that provide guidance for creating a program that the government is likely to look favorably upon. The problem is that these same criteria inadvertently communicate the message that implies building a program based on this formula is enough. It isn’t.


Maybe it’s time the Board of Directors looked into who is managing the organization into a future of civil or uncivil destiny. We have a clear choice.

11 January 2006

HSAC: Private Sector Information Sharing Task Force...

At first glance the room full of Homeland Security Advisory Council members looked like any other agency briefing. C-Span setting the stage for people to look good and say the right thing for the public record. Items such as we need to use a systematic risk management approach to funding and we should replace the word "Protection" with the word "Resiliency" were the highlights. And underneath, the audience was disturbed by the presentations because of it's lack of solid recommendations.

What happened later in the closed door session is where the rubber meets the road and serious work gets done. Yet the take away was this. After reading the 80 page report from the Private Sector Information Sharing Task Force there was one recommendation that stood out.

DHS should respond to private sector concerns about liability risks associated with sharing security information with DHS. This is why they recommend that the Critical Infrastructure Information Act (CIIA) should be fully implemented. If this could ever be clarfied and the legal counsels of the private sector gave it a major blessing then we would be well on our way to achieving a greater degree of safety, security and peace of mind.

In fact, Attachment D of the report goes so far as to list the categories of information that the government is seeking from the private sector on the critical infrastructure that they own. The number one item on the list is "Cyber Threats to U.S. Infrastructure". The number two item is "Terrorism".

It's no surprise that these are the two largest threats to the U.S. in the eyes of the task force.

06 January 2006

OPS Risk: An Ocean of Continuous Change...

In the latest issue of OpRisk & Compliance Magazine Eric Holmquist from Advanta makes the case for the Small to Medium sized institution. His brilliance continues and it's one of the reasons why we are an Advanta customer. They understand and practice OPS Risk hands down.

Overseeing an operational risk programme never ceases to fascinate me. There are aspects to op risk that are overwhelmingly unique from any other risk discipline. As I have said previously, it has the most moving parts. It involves every single person in the company, without exception. It is constantly in motion, involving an ever-changing set of assumptions and forces. And it is, ironically, sometimes unfortunately, and perhaps more importantly, the most intuitive.


Eric singles out the large mistake many organizations have made. Certification of controls for SOX 404 misses many of the OP risk factors and is all to focused on the financial control itself. Operational Risk assessments properly look at the potential and the likelihood of failures in the process so far, as well as potential threats to the process in a high moving parts environment.

The hint in his article about evaluation of core processes under the "heat lamp" is most critical. When people and systems are concerned, there are all too many opportunities for a failure and potential losses to occur. And those people are exactly who are the ones to be in the drivers seat to analyze those places that the proper tools in the right hands could exploit a known vulnerability. They may not know all of the ways to mitigate the threat, yet they are where you are going to get your "intuition" on what could happen.

As Eric says, "Operational Risk is constantly in motion", and assumptions change as often as the weather.


As the discipline of OPS Risk matures in the white collar world of Wall Street and the blue collar world of small community banking one thing is certain. No one will ever be able to predict or provide a scenario analysis that prepares exactly for the next incident. Mother Nature may act the same over and over to some degree and that helps us think in terms of magnitudes and categories. What about the person sitting in the next office who makes a random decision to inflate last months expense report? What about that electrical fire in the storage room?

Those who can master the art of change and rapidly adapt as unforeseen events occur will be here tomorrow to take on that next unplanned scenario.

04 January 2006

Security vs. Privacy: A Public Private Paradox...

If your are interested in what is on the minds of some of the PowerBase for information security and privacy you need to look no further. The comments and posts on Bruce Schneier's weblog tell the truth. His post on the Top Ten Privacy concerns from EPIC, (The Electronic Privacy Information Information Center)has created some very interesting points.

And to add to the concerns, comments and controversy is this:

Cyber Security Industry Alliance (CSIA), the only advocacy group dedicated to ensuring the privacy, reliability and integrity of information systems, today called on the federal government to assert greater leadership in the protection of our information infrastructure in 2006. Its release of the "National Agenda for Government Action on Information Security" identifies 13 specific actions required to improve information security for consumers, industry, and governments globally. As part of the Agenda, CSIA also provides a report of the government's limited progress in information security in 2005 and releases a new "Digital Confidence Index" that reflects the public's lack of confidence in our nation's critical infrastructure.


What is the paradox? The feds may need to show more leadership yet the private sector owns a majority of the critical infrastructure. Any lack of confidence should be an indicator that the private sector hasn't invested enough money and resources in information security and protection of our country's vital corporate assets.

24 December 2005

Enterprise Preparedness: Business Process Management (BPM)

Enterprise Preparedness Organizations are experiencing unprecedented pressure from a number of directions to remain competitive in today's changing economy. The challenges of satisfying profit expectations, meeting customer demands, avoiding litigation, and complying with government regulations have created tough conditions for the executives who are managing the business. Besides the pressure to create new markets, manage cost, and generate profits, they must also demonstrate the ability to effectively manage adversity when it occurs. The current stringent regulatory environment coupled with a hypersensitive investment community has made the need to prepare for adverse events a corporate mandate.


Troy Smith's article is correct on many of the fundamentals of Enterprise Preparedness. We would emphasize the need to also have some effective tools for capturing the processes during the important planning phases. One company to consider is Metastorm.

As the first breakaway BPM vendor, Metastorm is a leader in business process management (BPM) software and best practice methodologies for modeling, automating, integrating, and improving both human and system-based processes. Metastorm BPM™ is a complete solution for roundtrip process improvement, designed specifically to address complex processes that are unique to organizations. Metastorm’s 1200+ global client base in manufacturing, retail, financial services, business services, healthcare and government are achieving rapid ROI and Enterprise Process Advantage® in customer service, supply chain operations, risk management, and internal operations.


22 December 2005

Financial Services Marketers: Get Ready for Your Audit...

The FDIC Small-Entity Compliance Guide is now available. The guide summarizes the obligations of financial institutions to protect customer information and illustrates how certain provisions of the Security Guidelines apply to specific situations.

Distinction between the Security Guidelines and the Privacy Rule

The requirements of the Security Guidelines and the interagency regulations regarding financial privacy (Privacy Rule)8 both relate to the confidentiality of customer information. However, they differ in the following key respects:

- The Security Guidelines address safeguarding the confidentiality and security of customer information and ensuring the proper disposal of customer information. They are directed toward preventing or responding to foreseeable threats to, or unauthorized access or use of, that information. The Security Guidelines provide that financial institutions must contractually require their affiliated and non-affiliated third party service providers that have access to the financial institution's customer information to protect that information.

- The Privacy Rule limits a financial institution's disclosure of nonpublic personal information to unaffiliated third parties, such as by selling the information to unaffiliated third parties. Subject to certain exceptions, the Privacy Rule prohibits disclosure of a consumer's nonpublic personal information to a nonaffiliated third party unless certain notice requirements are met and the consumer does not elect to prevent, or "opt out of," the disclosure. The Privacy Rule requires that privacy notices provided to customers and consumers describe the financial institution's policies and practices to protect the confidentiality and security of that information. It does not impose any other obligations with respect to safeguarding customers' or consumers' information.


3rd Party marketers of financial institutions are preparing for new audits of the their information securtiy controls and processes. Slicing and dicing customer information utilizing pscyhograpics and demographics is a normal task. Mailing millions of pieces annually with new offers from collaborating internal companies and external partners creates significant challenges in managing sensitive customer information. This increased exposure to potential data loss and other threats warrants additional scrutiny with supply chain companies that interface with the marketing department.

One way to find out how ready your partners would be for a formal audit is to ask them when was the last time they had an independent audit of their information security controls. Many organizations today serve multiple financial institutions in the same region and therefore are consistently being asked for evidence of a SAS 70 audit opinion. SAS 70 is not a predetermined set of standards that an organization must satisfy in order to “pass” the audit. In a SAS 70 audit, the service organization is responsible for describing its control objectives and control activities that might be of interest to auditors in user organizations. SAS 70 objectives can be non-specific for an audit and may have large gaps in real-time day to day operations.

20 December 2005

Resilience Masks the Real Problem: Training...

The UK financial services sector has completed the first phase of it's Resilience Benchmarking Project. More than 60 key firms and financial infrastructure providers from the UK volunteered to take part in the Resilience Benchmarking Project, the results of which were mixed and highlighted a number of significant operational risk issues relating to business continuity. Here is the summary of FSA discussion points:

1 Although the financial system appears to be technologically resilient, are there vulnerabilities in other areas that could put it at risk?

2 What action could the Tripartite Authorities take to help bring together the component parts of the system?

3 How can firms strengthen their collective resilience?

4 Would it be helpful to publish recovery-time targets for wholesale payments, trade clearing and settlement? If so, would 60-80% of normal values and volumes within four hours, rising to 80-100% by the next working day, be reasonable recovery targets?

5 If we decide to publish targets, should these apply to core firms and financial infrastructure providers only, or should they apply more widely?

6 Should we consider publishing targets for other functions such as resumption of trading and retail payments?

7 If we were to publish targets, should these be informal in nature or should they be embedded into rules and guidance?

8 What more can be done to encourage joined-up planning and testing to reflect better the likely impact of a major operational disruption and how this could be facilitated?

9 Could the weaknesses in business continuity and crisis management arrangements undermine recovery time capabilities?

10 Would it be helpful to set a minimum distance criteria between primary and recovery sites? If so, what should that distance be?

11 Should we actively encourage firms to diversify their back-up arrangements, in particular core firms and financial infrastructure providers?

12 Do you agree with our conclusions and proposed actions in relation to recovery service provision? Is there more that the Tripartite Authorities should do in this area – for example including a specific survey on recovery service provision in future benchmarking studies?

13 We invite feedback on the measures we propose to take to mitigate concentration risk: encouraging end-to-end testing; sharing information on resilience and recovery arrangements the financial infrastructure providers have in place; and encouraging wider geographical diversification.

14 Should FSA maintain its non-prescriptive approach to business continuity management?

15 We would welcome comments on the estimated cost of reaching the targets we propose to publish for core firms and financial infrastructure providers:
– from those organisations to which these targets would apply; and
– from other organisations for which these targets might be considered aspirational goals.

16 We would welcome views on the estimated cost of lost business arising from the delayed recovery of a vital counterparty (i.e. a core firm or financial infrastructure provider).


The word "Resilience" occurs 70 times in this 52 page document. The word "Security" occurs only 12 times. The word "Continuity" occurs 63 times. The word "Risk" occurs 52 times. Resilience seems to be the overall theme these days.

The definition of Resilience is an interesting one:

Main Entry: re·sil·ience
Pronunciation: ri-'zil-y&n(t)s
Function: noun
1 : the capability of a strained body to recover its size and shape after deformation caused especially by compressive stress

2 : an ability to recover from or adjust easily to misfortune or change


The definition has a reactive flavor to it with the thought that something is going to happen and when it does, you must be able to recover quickly. With all the synomyms and word games being used today it all comes back to effective training. And this is where the benchmarking study has revealed the corporate business enterprises greatest weakness:

Training is another potential area for improvement. Only 42 firms include business continuity planning in induction programmes for new staff, and ten respondents had provided training to less than 5% of their staff. Fewer than a third of participants have provided training to staff that might be called upon to deal with sensitive issues, such as working on a casualty helpline. The responses to these and a number of other questions indicate a lack of appropriate training needs analysis and a need for greater consideration of the effects of a crisis on those who might be asked to undertake some of the most harrowing and disturbing roles.


16 December 2005

High Quality or Low Price: Pick One...

Have you ever heard that old saying, "You can have high quality or you can have a low price, pick one." Now apply this to Operational Risk Managment in your domain.

It seems that the U.S. Senate has mixed priorities right now on the U.S. Patriot Act debate. Wyoming is a low risk area in terms of critical infrastructure yet it will receive the same funding as states with more shoreline, ports and vulnerabilities to the security of the United States. James Jay Carafano has identified what the key issue really is:

What’s Missing?

There was one important provision that did not make out of conference. The original Patriot Act established the requirement that a significant percentage of all homeland security grants be distributed automatically to each state, big or small, regardless of national priorities or risks. Current funding formulas guarantee each state .75 percent of the funds available. As a result, 40 percent of these funds are immediately tied up, leaving only 60 percent for discretionary allocations. As the 9/11 Commission’s report rightly stated, the current system is in danger of turning homeland security funding into “pork-barrel” spending, making spending on security just another state entitlement program. In conference, an initiative to restructure the system and allocate money according to risk and needs rather than an archaic formula was rejected by Senate conferees. This is the third time the Senate has turned back House legislation to reform the grant system. And it is just wrong.


Prudent risk management policies and strategy point to investing to improve resilience in the areas that are identified as being most vulnerable and that the consequences of a loss would be unacceptable. What part of the risk management methodology is missing in the presentations or education of our law makers?

The part that is missing is the part that no one can present in fear of it becoming public information and for it to get into the hands of those who may use it to harm the homeland. Those single-points-of-failure exist in every country or city that has a significant capitalist marketplace. The resilience of the respective economies depends on the infrastructure that fuels it and every dollar and resource needs to be focused on those highest risk areas.

Mr. Carafano makes another observation worth consideration, regarding the The September 11 Commission Report Card: The Good, the Bad, and the Ugly:

At the top of the list is the failure of the Congress to put together a comprehensive package of border security and immigration reforms that enhance security, promote economic growth, and protect civil liberties. Also missing from the list is the tragic underfunding of the Coast Guard. The same service that saved 33,000 lives during and following Hurricane Katrina faces cuts to its modernization budget in the House.


The private sector can change all of this in a heart beat. The safety and security of our economic livelihood is in the hands of the telecom/high tech, banking and finance, health care and energy sectors. In the long run, the executives in these industry sectors have the power to change our law makers points of view. Let's just hope that they all realize that it is their own corporate assets that are at a greater risk now, than they were over four years ago.

15 December 2005

CIP Risk Management: NIPP & Tuck...

As part of the new National Infrastructure Protection Plan NIPP v1.0 the years old RAMCAP (Risk Analysis and Management for Critical Assets Protection) methodology of the American Society of Mechanical Engineers makes it's way into the mainstream:

RAMCAP is an overall methodology and provides a common framework for homeland security risk analysis decision-making that includes:

–Common terminology
–Common metrics for comparing risks across sectors
–Common basis for reporting results
–Basis for informing resource allocation decisions

•Countermeasures
•Consequence mitigation actions


ASME was awarded a grant by the Department of Homeland Security to develop uniform risk-based guidance in September 2003. The methodology's sequential steps include:

•Vulnerability analysis
•Consequence analysis
•Risk analysis
•Countermeasures and mitigation
•Decision analysis
•Multiple assets and sectors


The NIPP is a "draft" today and the comment period has already expired December 5, 2005. We expect that we will see sector specific plans soon after the national plan is finalized. It will be interesting to see how the private sector reacts. Industry critics say the draft lacks specificity at this point. However, maybe this is a good thing for the owners and operators of 85% of the nations critical infrastructure.

12 December 2005

Reducing Operational Risk Through CAP & IPv6...

After attending the United States IPv6 Summit last week it was apparent that Emergency Preparedness and National Security is a top priority. This is increasingly true as we see the grades on our progress by the 9/11 commission and others with regard to data communications and interoperability issues. One facet of all of this has to do with the important work already underway by the technical committees at OASIS:

The mission of the EM TC is to create incident and emergency-related standards for data interoperability. The TC welcomes participation from members of the emergency management community, developers and implementers, and members of the public concerned with disaster management and response.

Standards currently under review by the committee:

The Common Alerting Protocol (CAP), a data interchange standard for alerting and event notification applications, currently in version 1.1. CAP functions both as a standalone protocol and as a payload for EDXL messages.

The Emergency Data Exchange Language (EDXL), a broad initiative to create an integrated framework for a wide range of emergency data exchange standards to support operations, logistics, planning and finance.


Why is IPv6 and CAP a big issue in operational risk management? It will save lives and property as it is deployed in numerous communications devices and services in the future. Currently, the big drive for IPv6 is new uses, such as mobility, quality of service, privacy extension and so on. The U.S. Government has also specified that all federal agencies must deploy IPv6 by 2008.

Karen Evans and the OMB are preparing the federal CIO's for the transition:

The CIO Council will develop additional transition guidance as necessary covering the following actions. To the extent agencies can address these actions now, they should do so. Beginning February 2006, agencies’ transition activity will be evaluated using OMB’s Enterprise Architecture Assessment Framework:

• Conduct a requirements analysis to identify current scope of IPv6 within an agency, current challenges using IPv4, and target requirements.
• Develop a sequencing plan for IPv6 implementation, integrated with your agency Enterprise Architecture.
• Develop IPv6-related policies and enforcement mechanisms.
• Develop training material for stakeholders.
• Develop and implement a test plan for IPv6 compatibility/interoperability.
• Deploy IPv6 using a phased approach.
• Maintain and monitor networks.
• Update IPv6 requirements and target architecture on an ongoing basis.


Much of what IPv6 is all about has to do with capacity of our current standard IPv4. However, as more emphasis is put on interoperability and the use of millions of new data capture and reporting sensors both CAP and IPv6 will both be essential building blocks to the future. One example illustrated the other day is the changes being made in London and other global metro areas to capitalize on the fact that most citizens are carrying mobile phones with picture and video taking capabilities. These video images are increasingly being utilized to assist both law enforcement and emergency responders with new insight into the real situation as it unfolds. In some cases while voice circuits are jammed the data communications can get through.

Sometimes, a picture is worth a thousand words.

06 December 2005

Mitigating Operational Risks Around the Globe...

In this month's CSO Online, Todd Datz has an article worth exploring. How to Manage Security Halfway Around the World talks about several key components of global operational risk mitigation:

Different cultures. Unstable political environments. Language barriers. CSOs in global companies face many a challenge as they try to manage security in far-flung locations. One of the biggest challenges? A good number of your security managers reside in functions other than corporate security, so security is often a part-time gig managed by people with part-time security training. There’s no ironclad set of rules or policies that all those employees can follow.


If you are like most organizations doing business on a global basis, you don't have a security department in every office. This is why it is imperative for your local employees to establish local relationships with other businesses or entities who will help protect your vital corporate assets.

Educate Your Global Security Staff
Training is a critical component of any global security program, especially given that many security managers in foreign locations come from nonsecurity functions—such as HR or engineering—and thus wear multiple hats.


It's critical to have a local presence along with a centralized global policy and audit function know as Enterprise Security Risk Management. Together the partnership keeps a great degree of relevance to the issues and cultures in a particular country while simultaneously keeping a consistent and correlated set of standards for legal compliance. International laws for exchange of information, transmitting funds and selling products and services to Specially Designated Nationals (SDN)'s are all important business risks to be managed.

With a growing focus on risk management, The Yankee Group predicts that by 2008, the $165 million Enterprise Security Risk Management market will grow to $650 million as more organizations move to strengthen their global security posture. According to The Yankee Group, most organizations today utilize informal security risk management processes using professional services and homegrown databases that are often time-consuming and ineffective.

01 December 2005

Board of Directors: Corporate Responsibilities...

The primary responsibilities of the Board of Directors are getting more scrutiny than ever before. Especially in the light of the fact that statements executives make about quarterly earnings are a focus for class-action shareholder lawsuits.

Many public institutions are no longer bowing to Wall Street and publishing or promising quarterly numbers. In fact, many are following the lead of people like Warren Buffet of Berkshire Hathaway. He doesn't believe in the short sighted behavior that occurs around quarterly conference calls with analysts. Look to the The Washington Post as one example.

The Board is ultimately responsible for ensuring the performance and survivability of the corporation. The shareholders want the Board to do the following:

1. To ensure legal and ethical conduct.

2. To insist on strategic and operational planning.

2. To develop in collaboration with management a real-time risk assessment.

4. To establish a Corporate Governance culture based on best practices.

5. To exercise the Director's fiduciary duty of care on behalf of the shareholders.

An ever more important responsibility is to apply the use of technology and it's purpose in the survival and longevity of the organization. At the Washington Post, which does not offer quarterly guidance, they have adopted technology to help satisfy the analysts needs for information.

WASHINGTON, Nov. 30 -- The Washington Post Company (NYSE: WPO) will audio webcast its presentation at the Credit Suisse First Boston (CSFB) Global Media Week Conference next week. The Company's presentation will take place on December 6 at 4 p.m.

The live webcast will be accessible from a link on The Washington Post Company's website, http://www.washpostco.com, and at http://www.csfb.com. A transcript will be posted on http://www.washpostco.com following the presentation.


Maybe someday the SEC will reconsider Regulation FD:

"The Reg FD rule reads as follows: "Whenever an issuer, or any person acting on its behalf, discloses any material nonpublic information regarding that issuer or its securities to [certain enumerated persons], the issuer shall make public disclosure of that information... simultaneously, in the case of an intentional disclosure; and... promptly, in the case of a non-intentional disclosure."


In light of this, most Directors and Executive management are counseled to say very little about what is happening in the company.