13 April 2007

In Search of Answers: OPS Risk Intel...

When it comes to Operational Risk, what is on your mind? These are just a few recent inquiries from around the globe:

  • operational risk consultant
  • plausible deniability risk mitigation
  • operational risk and causes for information technology department
  • digital forensics plus ediscovery software
  • operational risk management in bank
  • hedge risk asian tsunami
  • bbc programmes advice on insurance companies covering anti terrorist cover
  • hsac navy seals
  • metrobank and trust company philippines risk managment practice
  • passmark passes fdic audit
  • gsk italy germany executive's supply chain quality assurance manufacturing
  • define issues and action plans orm
  • ethical prior the implemention of disaster response
  • operational risk management dulles airport
  • Business Crisis and Continuity Management (BCCM)
  • invision, deloitte, risk, root cause analyses
  • bs 25999 part1
  • system malfunction hurricane katrina critical infrastructure
  • fraud risk management vs. compliance investigation
  • "opinion letter" "disaster recovery"
  • the newest trends in operational risk for public sector
  • north carolina department of revenue real estate investment trust voluntary disclosure
  • parmalat crisis management
  • public sector operational risk management
  • bank of america sas 70
  • example document retention policy homebuilder
  • fbi justice report sedona mortgage fraud
  • operation risk management test answers
  • suibin zhang
  • authenticol systems boulder
  • helicopter detecting grow ops
  • using ipsonar opinion
  • pneumonia, operational risk
  • reasons for enterprise risk management assessment

If you are like us, we see some real "nuggets" of intel in these searches. One observation is that Operational Risk is diverse and it's facets are complex. The interdependencies of people, processes, systems and external events combined with the legal implications makes this discipline ever more sought after in the ranks of enlightened institutions.

So why would somebody be looking for information on
plausible deniability risk mitigation?

Over a year ago Bruce Schneier had this to say:

Deniable File System

Some years ago I did some design work on something I called a Deniable File System. The basic idea was the fact that the existence of ciphertext can in itself be incriminating, regardless of whether or not anyone can decrypt it. I wanted to create a file system that was deniable: where encrypted files looked like random noise, and where it was impossible to prove either the existence or non-existence of encrypted files.

This turns out to be a very hard problem for a whole lot of reasons, and I never pursued the project. But I just discovered a file system that seems to meet all of my design criteria -- Rubberhose:

Rubberhose transparently and deniably encrypts disk data, minimising the effectiveness of warrants, coersive interrogations and other compulsive mechanims, such as U.K RIP legislation. Rubberhose differs from conventional disk encryption systems in that it has an advanced modular architecture, self-test suite, is more secure, portable, utilises information hiding (steganography / deniable cryptography), works with any file system and has source freely available.

The devil really is in the details with something like this, and I would hesitate to use this in places where it really matters without some extensive review. But I'm pleased to see that someone is working on this problem.

Next request: A deniable file system that fits on a USB token, and leaves no trace on the machine it's plugged into.

So what? Why would an Operational Risk Professional be concerned about a USB token that leaves no trace on the machine it's plugged into? We think you get the big picture here. So are there any other nuggets of intel worth exploring in this latest list of searches?


What about Business Crisis and Continuity Management (BCCM)? When it comes to a crisis, there are numerous sources that impact your Operational Risk Strategy:

The many sources of significant loss events are changing as we speak. Here are a few that should not be overlooked:

· Public perception

· Unethical dealings

· Regulatory or civil action

· Failure to respond to market changes

· Failure to control industrial espionage

· Failure to take account of widespread disease or illness among the workforce

· Fraud

· Exploitation of the 3rd party suppliers

· Failure to establish a positive culture

· Failure in post employment process to quarantine information assets upon termination of employees

So what? Boards of Directors have the responsibility to insure the resiliency of the organization. The people, processes, systems and external events that are constantly changing the operational risk landscape become the greatest threat to an enterprise. It’s the shareholders duty to scrutinize which organizations are most adept at “Continuous Continuity” before they invest in their future. Hopefully you understand that the operational risk spectrum is wide as it is deep. Keeping your fingers on the pulse of what people are concerned about could be as simple as this quick exercise in "search terms analysis."

06 April 2007

Ethics: The Tone at the Top...

Have you had your annual check-up? Is the health of your organization improving or on the way to a potential loss of reputation?

The Board of Director's are consistently talking about how they can create the correct "Tone at the Top" when it comes to ethics and compliance. Global corporations realize the importance of these issues in order to create a focus on competitive advantage and other new "Carrots" rather than the old motivators of fear, uncertainty and doubt (FUD Factor). Employees who are "Beaten with a Stick" in order to comply with federal laws and state rules of conduct are looking for new vision and new methods to improve the health of organizational ethics. An interview with Perry Minnis, Alcoa's Director of Ethics and Compliance highlights this point:

Organizations have always confronted ethics problems, but it seems that only in the last 25 years or so that ethics has grown from an academic discipline into a mandatory department at most corporations. How has this happened?

I believe the heightened awareness can be attributed to several factors: the defense contracting scandals during the Reagan Administration; the issuance, in the early 1990s, of the Federal Sentencing Guidelines, which established criteria for assessing the completeness of ethics and compliance programs; the emergence of high profile scandals - Enron, Tyco, WorldCom, etc.; and the passage of the U.S. Sarbanes-Oxley Act and the associated provisions of the New York Stock Exchange and SEC requirements. Plus companies now have a general sense that a reputation for ethical behavior is a competitive advantage. It engenders customer loyalty and employee allegiance.

Mr. Minnis and other officers like him who are charged with creating the right "Tone at the Top" must cooperate with a multitude of players within the enterprise to address this cultural awareness. Part of this strategy should include the check-up for fraud and the signs that it may be present in certain business units or processes within the organization.

In this Fraud Prevention Check-up tool we are especially pleased to see question number 7:

To what extent has the entity established a process to detect, investigate and resolve potentially significant fraud? Such a process should typically include proactive fraud detection tests that are specifically designed to detect the significant potential frauds identified in the entity’s fraud risk assessment. Other measures can include audit “hooks” embedded in the entity’s transaction processing systems that can flag suspicious transactions for investigation and/or approval prior to completion of processing. Leading edge fraud detection methods include computerized e-mail monitoring (where legally permitted) to identify use of certain phrases that might indicate planned or ongoing wrongdoing.

The use of automated tools to help prevent fraud from occuring will continue to be just that, a tool. It's imperative that anyone utilizing such mechanisms for early warning remember the taxonomy for an "Incident:"

"Attackers use tools to exploit vulnerabilities to create an action on a target that produces an unauthorized result to obtain their objective."

While the ethics and compliance department teams up with the IT and Security departments to create the policies and implement the tools to deter, detect and defend against fraud, the opposing force is also gaining ground. Hackers, spies, terrorists, corporate raiders, professional criminals, vandals and voyeurs are using their own tools to test and to exploit your vulnerabilities.

The three areas that you need to focus on continue to be:

  • Design
  • Implementation
  • Configuration
Whether it is through physical attack, information exchange, user commands, scripts, programs, autonomous agents, toolkits or data taps you can be assured that these tools are being utilized to exploit you. They are being directed at the design, implementation or configuration of your "Controls" in order to achieve the action they desire:

  • Probe
  • Scan
  • Flood
  • Authenticate
  • Bypass
  • Spoof
  • Read
  • Copy
  • Steal
  • Modify
  • Delete
All of these actions are directed at their target. Accounts, people, processes, data, components, computers, networks or internetworks. They are looking for and unauthorized result:

  • Increased Access
  • Disclosure of Information
  • Corruption of Information
  • Denial of Service
  • Theft of Resources
And sadly, when you boil it down to the reasons or objectives they seek to achieve; it usually falls into one of four categories:

  • Challenge, Status, Thrill
  • Political Gain
  • Financial Gain
  • Damage
Once you understand the entire taxonomy of an "Incident" you are far better equipped to prevent and preempt attacks on your valuable corporate assets. Equally as important is the "Tone at the Top" to set the foundation for an environment that employees embrace and will protect at all costs.

29 March 2007

DRP: Document Retention Policy...

Corporate Fraud is nothing new and seems to be going in cycles. Now we are back to the days of the real estate financing and mortgage lending wrong doing but this time it might be a larger issue than the past. When this issue gets on the docket over at the Daily Caveat, you can bet this is not going to be a trivial matter.

Atlanta-based Beazer Homes USA is facing scrutiny from the FBI over allegedly fraudulent practices in the company's mortgage lending business. Beazer, a public company, operates as a home builder in 21 states.

The bureau's report said mortgage fraud comes in two broad varieties: "fraud for profit," which is largely committed by industry insiders and involves practices such as falsely inflating property values, and "fraud for housing," which is committed by borrowers and involves actions such as acquiring a house under false pretenses.

The bureau said it is cooperating with trade associations representing mortgage bankers and the government-sponsored companies that purchase mortgages, Fannie Mae and Freddie Mac, to raise awareness of mortgage fraud.

Whenever you have boom times, you can bet that the opportunities and the malfeasance will be higher and that the investigations won't gear up until well after the peak. Even if the situation has equalized and the market place is doing all the right things to adjust, you still need to put a light on those who are prone to bad behavior.

Operational Risk is all about internal and external fraud mitigation. The tools, cues and clues that an OPS Risk professional utilizes are all after the truth and for the future good of all impacted by these serious loss events.

Fraud

A risk difficult to model is fraud. Booms tend to induce fraud, misrepresentation and scandals. To quote Bagehot again:

"The good times of too high price almost always engender much fraud."

Or the great economic historian, Charles Kindleberger:

"The propensity to swindle grows parallel with the propensity to speculate during a boom. The implosion of an asset price bubble always leads to the discovery of fraud and swindles."

And now the search begins for evidence. The evaluation of the Document Retention Policy (DRP) at Beazer Homes will no doubt be a subject of discussion today and for weeks to come. If they are like most prudent organizations who have completed their DRP and have employees educated on day one of their employment, it should be crystal clear:

Here is some sample language from a standard DRP:
Our records include virtually all of the records you produce as an ABC Corporation employee. Such records can be in electronic or paper form. Thus, items that you may not consider important, such as interoffice emails, desktop calendars and printed memoranda are records that are considered important under this policy. If you are ever uncertain as to any procedures set forth in this policy (e.g., what records to retain or destroy, when to do so, or how) it is your responsibility to seek answers from ABC Corporation’s DRP Manager.

The goals of this DRP are to:

  • Retain important documents for reference and future use;
  • Delete documents that are no longer necessary for the proper functioning of ABC Corporation;
  • Organize important documents for efficient retrieval; and
  • Ensure that you, as an ABC Corporation employee, know what documents should be retained, the length of their retention, means of storage, and when and how they should be destroyed.
Yes, a policy about destruction of documents. This is where many organizations fail to mitigate the risk of data theft or even eDiscovery of data that could become relevant in a future investigation. However, these days, everybody is saving everything and for what looks like could be a very long time.

"If a lawsuit is filed or imminent, or a legal document request has been made upon ABC Corporation, ALL RECORD DESTRUCTION MUST CEASE IMMEDIATELY.

"ABC Corporation’s DRP Manager may suspend this DRP to require that documents relating to the lawsuit or potential legal issue(s) be retained and organized. A critical understanding of this section is imperative. Should you fail to follow this protocol, you and/or ABC Corporation may be subject to fines and penalties, among other sanctions."

The phone has just got to be ringing off the hook over at Stratify!

23 March 2007

Global Risk: Resilience & Interdependencies...

It's no surprise that spending will be up in 2007 on Operational Risk Management. In a recent AMR Research study, OPS Risk will increase dramatically:

The study reveals 46% of firms surveyed plan to implement or evaluate technologies for risk management in the next one to two years.

The emergence of risk management as a critical practice is based on the business need for global sourcing strategies, increasingly complex contract manufacturing relationships, and the greater number of natural and political events that can disrupt the supply chain, according to AMR.

Supplier failure and continuity of supply is the Number 1 risk factor for 28% of firms, the survey says. Events such as the Enron scandal, 9/11, health scares such as SARS and avian flu threats, the Asian tsunami and Hurricanes Katrina and Rita have forced companies to re-evaluate their preparations for catastrophes and unplanned events.

Other survey results include:

* 33% of firms have dedicated budget line items for supply chain risk management activities.

* 54% of firms plan to increase their budgets for risk management over the next 12 months.

* The top areas of application spending to support supply chain risk management are sales and operations planning, inventory optimization, business intelligence and supply chain visibility and event management applications.

After all, risk managers have figured out that a holistic Enterprise Risk Management approach with a firm discipline in Operational Risk is paying off. The strict focus on just compliance with SOX or Basel II is myopic.

Cristiana Báez-Safa, Managing Director in Marsh's FINPRO (Financial and Professional Services) Practice, noted: "Many large European financial institutions have changed the direction of their operational risk projects as often as two or three times since starting their compliance efforts."

"From simply taking a narrow view, 'what can I do to comply with Sarbanes-Oxley and Basel II?', for example, risk managers in the financial services sector are now asking themselves how they can help improve business process efficiency, reduce operating costs and mitigate the risks that concern the Board most."

She also indicated that "the longer-term trends in operational risk management are greater penetration and coordination of risk management across all facets of the business; more detailed scenario planning in key areas of potential exposure; and tailored risk transfer solutions for operational risk."

Local risks can become global risks depending on the severity and connectedness to other interdependencies. We have already witnessed the impact of such events as hurricanes on gas refining operations in the US Gulf Coast Region and the impact on transportation costs. Under regulation of sub-prime mortgages by the federal agencies may have a long-term effect on capital liquidity accross the globe.

And there are many others according to the World Economic Forum 2007 Global Risks Report, :
Economic
• Oil price shock/energy supply interruptions
• US current account deficit/fall in US$
• Chinese economic hard landing
• Fiscal crises caused by demographic shift
• Blow up in asset prices/excessive indebtedness

Environmental
• Climate change
• Loss of freshwater services
• Natural catastrophe: Tropical storms
• Natural catastrophe: Earthquakes
• Natural catastrophe: Inland flooding

Geopolitical
• International terrorism
• Proliferation of weapons of mass destruction (WMD)
• Interstate and civil wars
• Failed and failing states
• Transnational crime and corruption
• Retrenchment from globalization
• Middle East instability

Societal
• Pandemics
• Infectious diseases in the developing world
• Chronic disease in the developed world
• Liability regimes

Technological
• Breakdown of critical information infrastructure (CII)
• Emergence of risks associated with nanotechnology

These risks over the next ten years are the global in nature and have significant interdependencies. The breakdown of CII and Transnational Crime and Corruption are far more likely to occur than a Pandemic however not quite as costly in US loss exposure.

With all the talk about prioritization and upstream mitigation, how do you know that you spending your resources in the right place? When will the next incident occur? Finally, what interdependencies will come into play?

One approach is to improve resilience, allowing the system to cope with a range of unexpected manifestations. Such “downstream mitigation” recognizes that not all events can be predicted and prevented.

Enabling Global Business Resilience is the name of the game and those organizations who understand it and can implement effectively will be our next generations survivors.

18 March 2007

Corporate Fraud: Revenue vs. Risk...

It's been over five years now since the "Black Monday" at Enron. Volatility in the markets over the sub-prime mortgage industry has investors a little nervous. Operational Risk Executives are hoping that this is not a deja vu moment.

Though the main Enron characters have received their prison sentences, there's no closure for corporate fraud. Sherron Watkins, Enron's sentinel, describes the debacle's details and warns that it could happen again.

Dec. 3, 2001. Black Monday. The day that Enron declared bankruptcy. CEO Ken Lay had left a voice mail on the phones of all Enron employees asking they come into the office regardless. Nearly 5,000 were called to a massive meeting and told that the paychecks that they had recently received would be their last. Three weeks before Christmas.

In August of that year, Sherron Watkins, an Enron vice president, had sent an anonymous memo to Lay that read, "I am incredibly nervous that we will implode in a wave of accounting scandals."

Of course, that's exactly what happened. After the company's demise, the investigating U.S. Congress discovered Watkins' memos to Lay and other top executives. (After sending the memos, she had met with Lay with no results.) Watkins was soon lauded as an "internal whistle-blower," brought before Congressional and Senate hearings to testify against her former bosses, and heralded by TIME magazine as a "Person of the Year," with WorldCom's Cynthia Cooper and the FBI's Coleen Rowley.

With the chaos going on in sub-prime lending in the United States, the concern is that suddenly the liquidity that fueled this past boom is about to "Go South". Will there be any issues that surface about the fraud imposed upon consumers over the terms and conditions of the loans they signed to become part of the American Dream? Are there any "Sherron Watkins" sitting there in their offices today wondering how they can become the next "Whistleblower" to make it to the cover of Time Magazine?

Only time will tell whether any of the volatility in these companies has a ripple effect in markets for the long term. Yet the culture that exists today inside those organizations must be tense and certainly there are a handful who wish there was a way they could make it all go away. So what advice would Sherron have for anyone feeling this way at their institution in a role of Operational Risk Management?

If you ever were to go back to a corporate executive position, what kinds of things would you ensure would be set in place before you took the job?

In addition to the zero tolerance policy I've already mentioned for ethically challenged employees, I'd be sure that the company had a mechanism for bad news to get to the top and had effective policies and procedures for dealing with that bad news. I would also verify that the company's control and risk personnel had autonomy and equal power with top revenue executives. I would want to see that top management values the control and risk management function. I would want to make sure they recognize that control and risk personnel will not be the most popular and that the problems the company avoids as a result of the work of these groups will never be quantified.

Think about what she is saying here. Control and risk personnel need to have equal power with the executives who are bringing in the revenue. This means that the powerbase of the sales and marketing team would need to be on par with the Internal Audit and Risk Management executives. This culture shift is harder to achieve than one would think. The ego's aside, the people who make it their job to worry about losses and to mitigate risks day in and day out are just not used to waving the big black flag of doom. Everybody loves to hear that the business has been won, the competition defeated and the company just closed the biggest "Deal" in it's history. Let the spin doctors in Marcom get the Press Releases flying!

It has been said before, the tone starts at the top. The CEO and Board of Directors who are cognizant of the neccesity for effective risk management objectives must also create a balanced powerbase at the top to balance the "revenue generators" with the "loss mitigators." So who are some of these people who deserve a greater exposure to this new born culture shift:

  • Director of Information Security promoted to CISO. (Chief Information Security Officer)
  • Director of Corporate Facilities to CSO. (Chief Security Officer)
  • Director of Regulatory Affairs to CCO. (Chief Compliance Officer)
  • Director of Privacy to CPO. (Chief Privacy Officer)
  • Director of Human Resources to CHO. (Chief Humanity Officer)
If the CEO thinks that this is too many chiefs in the "C" Suite, then what about the idea of creating the Executive Office of Operational Risk Management (ORM). This would be on par with the Chief Financial Officer and might even include the Chief Information Officer. The top ORM officer would be on par with the EVP of Sales or Marketing and unlike the Chief Operations Officer (COO) would be focused on the effectiveness of risk controls and not so much on the efficiency or uptime of corporate processes. What does Sherron think the moral is?

You've been asked this one numerous times, I'm sure, but what's the moral of the story?

Being an ethical person is more than knowing right from wrong. It is having the fortitude to do right even when there is much at stake.

14 March 2007

OSINT 2: When is it time?

In our last post we were exploring the "Open Source Intelligence" discussion. We said that we were going to continue the arguments. We wonder why some companies don't have a more proactive OSINT operation in their own institution looking at potential threat intel. While there are very expensive services that can package up exactly what you are looking for, sometimes it just takes a little more time and the right "Sources." Take Michael Sutton's Blog for instance:
Phree Phishing
I recently blogged about the phishing pages that I found during a Tour of the Google Blacklist . In that posting I noted how I was surprised to find that Yahoo! was actually hosting phishing sites designed to phish Yahoo! credentials. Not surprisingly, Read More...

Filed under

A Tour of the Google Blacklist
[Update 01.10.07: In response to some of the queries that I've been receiving, I've published a follow up blog to discuss the structure/decryption algorithm of Google's Encoded/Hashed Blacklist .] I recently decided to devote a day to walking Read More...
Posted 04 January 07 12:48 by msutton

Filed under , ,

You could get a service from Michael's X-Lab, at iDefense or even a more wide range of collection capabilities from the likes of Cyveillance to assist the in-house OSINT operation. Throw in some Stratfor, OSAC and one or two variations of Symantec or Qualys and you have it mostly covered. Except for one thing. Plenty of "Gray Matter."

We might agree that there is more information out there than anyone could possibly imagine accessible with a few clicks and keystrokes. Yet the easy part is the collection and the filtering or storage. Making any sense of it all with the relevance you seek is the "Holy Grail" for you, today. But that might change tomorrow.

It's the consistent development of a new hypothesis and testing it that determines who will get the next new piece of information ready for OSINT. And still the question remains. Will this be better kept secret, or out in the "Wild"? The argument usually isn't whether the results of the test should be published, it's more about when.

Open Source Intelligence is going to be around for some time to come. The tools are getting even better to find and process information. The only real impediment will continue to be those who want to wait and hold on to it a little longer. And remember this:

OSINT: If Intelligence were a baseball game...

06 March 2007

A Glitch: NYSE Minor Malfunction...

AS SHAREMARKETS plunged around the world, anxious investors, big and small, sat glued to their computer screens. But the lesson learned from yesterday's market correction was that computer systems just aren't up to scratch when investor panic sets in.

The first malfunction came in New York, where a glitch triggered a sudden plunge in the Dow Jones Industrial Average. Brokers, already spooked by morning falls, could do little but watch on as, at 2pm local time, the Dow fell 200 points in seconds.

Dow Jones said its computer system couldn't handle the vast volume of trades — about 4.5 billion, double the daily average — at the New York Stock Exchange.

If you have been reading Richard A. Clarke's new "Fiction" novel, Breakpoint, the so called "Glitch" had some of us wondering:

The global village--an intricately intertwined network of technology that binds together the world's economies, governments, and communication systems. So large, so vital--and so fragile. Now a sophisticated group is seeking to "disconnect the globe"--destroying computer grids, communications satellites, Internet cable centers, biotech firms. Hard to do? If only that were so.

What is a glitch anyway? Didn't we hear that as an excuse from Virgil Gus Grissom in the "The Right Stuff".? He was pilot of Mercury-Redstone 4 ("Liberty Bell 7"), the second American (suborbital) spaceflight. Following the splashdown of "Liberty Bell 7", the hatch, which had explosive bolts, blew off prematurely, letting water into the capsule and into Grissom's suit. Grissom nearly drowned but was rescued by helicopter, while the spacecraft sank in deep water. Grissom maintained he did nothing to set off the explosives to blow the hatch. "It was a glitch!" Later evidence proved him right.

Whenever you hear the word "Glitch", what are you thinking? Human error. Or Computer error.
n.
  1. A minor malfunction, mishap, or technical problem; a snag: a computer glitch; a navigational glitch; a glitch in the negotiations.
  2. A false or spurious electronic signal caused by a brief, unwanted surge of electric power.
  3. Astronomy A sudden change in the period of rotation of a neutron star.
In the case of the New York Stock Exchange and Liberty Bell 7 we are talking about something that could not be predicted. Maybe not something that had ever been seen before during testing or simulations. Therefore, the only answer could be a glitch. If you are a computer programmer you know exactly what happened. You know where the orders were piling up in the database ready to be tabulated when the systems processes started up again. Being down for an hour with those kind of trading volumes can pile up a few orders in the queue.

Operational Risk Management is about anticipating those occasional "Glitches" and preparing for them in advance. While you may not see the exact variant everytime you create and exercise a scenario, you recognize something similar. You get a feeling that you have seen this before, even if it was in a bad dream. As a Quiet Professional, working to mitigate risks, create a safe haven and achieve your mission, you expect that you will see a glitch today. And if you do, then you will act with confidence and speed to remedy the situation as it unfolds before you.

So you want a look into the crystal ball? As Richard Clarke says, "Sometimes you can tell more truth through fiction." Or is it?

02 March 2007

Insider Threat: Reputation is #1 Concern...

A recent EIU Survey on Business Resilience has some reinforcing stats, yet nothing so shocking.

Forty-seven percent of the risk managers questioned for a new Economist Intelligence Unit survey into business resilience said that unplanned downtime of information technology systems lasting 24 hours or more could jeopardise the survival of their entire business.

The severity of the threat from disruption to IT systems is one of several factors prompting companies to increase the attention they devote to risks associated with their operations.

75 percent say that operational risk management is an increased focus as their reputation remains their highest concern overall. And today, UBS, Bear Stearns, Morgan Stanley and others are cooperating on an SEC investigation into insider trading:

Employees of some of Wall Street's top banks were among more than a dozen people charged on Thursday in what authorities called one of the most pervasive insider trading rings since the 1980s, accused of using leaked information and even blackmail to make millions of dollars.

U.S. prosecutors filed criminal charges against 13 people and the Securities and Exchange Commission filed civil charges against 11 in an investigation that has spanned more than a year and is ongoing. One person named in the SEC's complaint does not face criminal charges.

Authorities said some of those of those accused in the cases used clandestine meetings, disposable cell phones, secret codes and cash kickbacks to elude detection and avoid suspicion.

It was "one of the most pervasive Wall Street insider trading rings since the days of Ivan Boesky and Dennis Levine," Linda Thomsen, director of enforcement with the SEC, said at a joint news conference with the U.S. Attorney and the FBI.


Electronic Discovery strategy today focuses on providing the least amount of data required to satisfy legal requirements. Litigators are careful asking for data as they will no doubt be required to reciprocate with the same amount of actionable data. However, amendments to the Federal Rules of Civil Procedure (FRCP) that went into effect on December 1 require that organizations be prepared to locate and produce information in electronic format- including emails, files, and database data-during legal litigation.

The eDiscovery war has started and these firms will be delivering Terabytes of electronic information to satisfy the ongoing process for criminal and civil litigation. These operational and reputational challenges would stress any organization who is not prepared for such demanding and extensive requests for electronic records. Expensive too, at an average of $1,800. per gigabyte.

27 February 2007

Whistleblower: The FCPA & Voluntary Disclosure...

Operational Risks involving people are happening everyday in your organization. It may be going on for a day, a week and sometimes years. But at some point someone has to tell someone before it gets violent or the company loses any more corporate assets.

What is the anonymous phone number at your organization to phone in the "Whistleblower" information? Who is responsible for the follow through on investigations? How can you insure against employee confidentiality and any possible reprisals?

In most cases the call is by phone and not by some other method. It is rarely a hoax and the hotline is keeping tabs on the subordinate / management battle over half of the time.
What's the best way for an employee to blow the whistle on fraud or related infractions? The most popular way seems to be via hotlines or similar reporting tools. According to a joint report from the CSO Executive Council, an organization of corporate and government security executives, and The Network (a hotline provider), almost two-thirds of the nearly 200,000 reports it studied were made via hotlines without first alerting anyone in management.

Few of those alerts prove to be false alarms. The study, which tracked incidents at 500 organizations over the past four years, found that 65 percent of the reports were serious enough to warrant investigation, while 46 percent led to some type of action being taken. Corruption and fraud accounted for 10 percent of the incidents, well behind personnel-management situations (51 percent). Company and professional-code violations accounted for 16 percent and employment-law violations 11 percent.

Compliance with an effective Whistleblower program is just the beginning of developing a culture that has a zero tolerance for the kinds of risks that make an HR manager or General Counsel have constant nightmares. This is certainly the case on the front lines where business is being transacted and deals are being cut on a global basis. Is there sufficient due diligence to determine whether any party in the transaction is not in violation of the Foreign Corrupt Practices Act (FCPA)?
By definition, FCPA crimes generally occur thousands of miles outside of the United States. Why would counsel advise a corporate client to bring such activities to the attention of the SEC or the DOJ? Is it necessary to self-report when, as a good corporate citizen, the client has investigated thoroughly, corrected the problem, and taken substantive remedial measures including firing the wrongdoers and correcting the financials?

Having the possibility of a deferred prosecution agreement is the strategy utilized more often than you would think these days. In any case, SOX requires a Whistleblower program, and the next phone call may have to do with that last big deal that closed last quarter. Why Voluntary Disclosure?
The DOJ's "Principles of Federal Prosecution of Business Organizations," commonly known as the "Thompson memorandum" and published in 2003 on the heels of SOX, also played a significant role in the surge of voluntary disclosures. The Thompson memorandum placed an "increased emphasis" on a company's cooperation with the government when considering whether to prosecute. Voluntary disclosures were an important part of that cooperation.

At the end of the day all of the auditing will never catch the people that know the system. That is why the anonymous phone number can make all the difference in mitigation of significant risks to your enterprise.

23 February 2007

The Board Room: IT Strategy Focus...

A new survey or 400 directors published in the March/April issue of Corporate Board Member Magazine by Deloitte Consulting has some interesting insights. In regard to the use of Information Technology as important or very important to insure success in various areas of the business:

  • 69% say implementing the right IT strategy is "very important" in compliance.
  • 66% in learning about and retaining customers.
  • 57% in managing risk.
  • 50% in competitive positioning.

So how come only 14% say they are "completely and actively involved" in IT strategy?
Boards of Director's are in the dark and this won't be changing very dramatically unless you are the result of a significant incident such as T.J. Maxx:

According to The Boston Globe today, TJX Companies has stated that a data breach it revealed last month may have occurred a year earlier than investigators initially thought. The company operates the retail outlets T.J. Maxx, Marshalls and HomeGoods (2,500 stores in the United States), so the earlier date of the hacking may mean millions more customers were exposed. The company declined to give numbers, however.

TJX discovered the breach in December 2006, and it made news on Jan. 18, 2007. At that time the company reported that hackers may have made off with credit and debit information from transactions in the United States, Canada and Puerto Rico from some months in 2003 as well as transactions between May and December 2006.

Yesterday, according to the Globe, TJX said a systems review revealed that intrusions had occurred as early as July 2005, not May 2006.

This trickle of data breaches spread over time led some experts to judge the corporation’s computer systems outdated, weak and not up to card-company security standards.

Information Technology strategy and the amount of effort or time a Board of Directors spends on it is most likely determined by the CEO. If they trust the Chief Information Officer and what they are doing, then they leave it alone. This is becoming an area under greater scrutiny by Directors as these kinds of incidents occur on a more regular basis in the news. However, just because it's not in the news, doesn't mean that it's not happening today at your institution.

There is another war brewing between the banks, retailers and the credit card issuers about who is the guilty one. At the end of the day, consumers will lose. Even pressure by VISA and others to make sure merchants are in compliance with the laws around encrypting data and the storage of the data may not be enough. The retailers have already started their lobbying efforts:

As information security has become a major focus of consumers, governments and businesses alike, the care with which companies protect credit card data has become increasingly important. In many instances, the Achilles heel of data security is a lack of application controls.

Encryption alone is not the answer. With most of the encryption techniques, the same key is used to lock and unlock the data. The problem is: How do you secure these keys in the POS application? Once these keys are compromised, the "secured" data is no longer secure.

The best way to secure data is to not store data. A technology knows as “tokenization” offers a greater level of security by substituting a unique identifier (a token) for a card number, so the card data is never in the system. This token is a random unique value and has no way to be deciphered to gain knowledge of the associated card information. With tokenization, the merchant swipes the card data and sends the information through a gateway to a processor and receives back an approval. But instead of sending the card data itself back to the merchant and the POS system, it is converted to a token: a globally unique, randomized representation of credit card data that is 16 characters long. Only the token is stored in the system.

The token spans the lifetime of the transaction so it provides full support for tips, tabs and incremental authorizations. The merchant does not need the card number or data past the initial request, so storing this information is unnecessary. The entire liability to protect the card data is now on the gateway, where it should be. The primary objective of tokenization is to enable businesses to operate normally while not storing the sensitive data that is the target of data thieves. This technology also eases the burden of compliance for merchants. If no data is stored on site, the merchant has a significantly reduced PCI compliance burden.

The Board of Directors who discuss IT strategy on a regular basis perform better financially and those who don't may be paying the price.

18 February 2007

Economic Intelligence: Wake-up Call...

Chris Cooper plays a traitor in the movie based on the true story of Robert Hanssen. "Breach" is a wake up call for the United States to continue its counterintelligence initiatives with vigor. However, this story is written not from the perspective of Hanssen, but that of another FBI employee who assisted in his capture and prosecution.

Based on the true story, FBI upstart Eric O'Neill enters into an operational risk power game with his boss, Robert Hanssen, an agent who was ultimately convicted of selling secrets to the Soviet Union. Eric now lives in Washington, DC and is an attorney, he never became an FBI agent. His role played by Ryan Phillippe, shows the audience how even Eric was skeptical that someone like Hanssen could be a traitor.

Critical to the agency’s ability to arrest and convict Hanssen was the placement of 26-year-old special surveillance operative Eric O’Neill in Hanssen’s office. Working directly under Hanssen, O’Neill was able to provide the team of investigators with information needed to take down one of the worst spies in the history of the United States.

Shortly after being intimately involved in the Hanssen investigation, O’Neill left the FBI to study law. O’Neill also took time to work on a book based on his experiences, which ultimately led to Breach, a film about his involvement in the Hanssen case.

Counterintelligence is the number 2 priority behind Counterterrorism at the FBI.

The Cold War is not over, it has merely moved into a new arena: the global marketplace. The FBI estimates that every year billions of U.S. dollars are lost to foreign competitors who deliberately target economic intelligence in flourishing U.S. industries and technologies, and who cull intelligence out of shelved technologies by exploiting open source and classified information known as trade secrets. Foreign competitors who criminally seek economic intelligence generally operate in three ways to create their spy networks:

1. They aggressively target and recruit susceptible people (often from the same national background) working for U.S. companies and research institutions;

2. They recruit people to locate economic intelligence through operations like bribery, discreet theft, dumpster diving (in search of discarded trade secrets), and wiretapping; and,

3. They establish seemingly innocent business relationships between foreign companies and U.S. industries to gather economic intelligence including classified information.

In an effort to safeguard our nation's economic secrets, the Economic Espionage Act (EEA) was signed into law on October 11, 1996.

How to Protect Your Business from Espionage: 6 steps
1. Recognize there is a real threat.
2. Identify and valuate trade secrets.
3. Implement a definable plan for safeguarding trade secrets.
4. Secure physical trade secrets and limit access to trade secrets.
5. Confine intellectual knowledge.
6. Provide ongoing security training to employees.



14 February 2007

OPS Risk: The Bishop vs. A Stolen Laptop...

Now that the news is in the mainstream media about the recent threats to financial institutions, one can only wonder how soon this case will be solved. The Bishop is being compared to the "Unabomber". Profilers believe that he is white male, a loner with dangerous beliefs that he can manipulate stocks.

The U.S. Postal Inspection Service is alerting financial firms of potential danger from a would-be letter bomber after companies in Kansas City and Denver were targeted with explosive devices and threatening notes, an agency spokeswoman said on Monday.

Working with the Securities and Exchange Commission, the Postal Inspection service is trying to obtain contact information for thousands of financial companies to warn them of the threats, said spokeswoman Wanda Shipp.

"The events may be linked, and the recipients were probably not selected at random," the postal advisory reads.

The action comes after Stratfor, a global intelligence firm, last week issued a warning that pipe bombs addressed to American Century Investment Management Inc. in Kansas City and Janus Capital Group in Denver appeared linked to someone known as "the Bishop," who has threatened at least six financial firms since 2005.

The Chief Security Officer's at these institutions have a primary duty of care to insure the safety of employees whenever threats of this magnitude take place. There is no "Radar" that can alert you to when the next incident will occur. This is why many institutions have taken a new "Operational Risk" perspective when it comes to the hazards and events that may impact the business.

A true Operational Risk perspective has it's roots in understanding exposure to risk and the likelihood of an event occuring. Yet how could one ever predict the rise of another so called Unabomber? The fact is that you don't. This is why you must have an "All Hazards" worldview operating within the culture of your organization. The threat could be an innocent looking priorty mail package with a pipe bomb or a thick brown envelope containing the latest class action law suit. You have to be operating in a complete state of preparedness for whatever the next incident brings.

What ORM Is Not . . .

  • About avoiding risk
  • A safety only program
  • Limited to complex-high risk evolutions
  • A program -- but a process
  • Only for on-duty
  • Just for your boss
  • Just a planning tool
  • Automatic
  • Static
  • Difficult
  • Someone else’s job
  • A well kept secret
  • A fail-safe process
  • A bunch of checklists
  • Just a bullet in a briefing guide
  • “TQL”
  • Going away
While this incident entering the mail room has slowed down a few institutions, there is another battle going on in a different part of each business that is a whole different type of risk. This has to do with the frequency and the pervasive spectrum of new risks across the enterprise:

The U.K.’s financial services regulator has levied a heavy fine against the nation’s largest building society over a stolen laptop containing confidential customer information.

The Financial Services Authority (FSA) fined Nationwide Building Society 980,000 (US$1.9 million [m]) for "failing to have effective systems and controls to manage its information security risks," the regulator said.

Nationwide, which has about 11 million customers, did not realize the laptop contained customer information and waited three weeks before starting an investigation, the FSA said.

The speed of change in the connected economy...

08 February 2007

eDiscovery: The New Digital Age...

What does Operational Risk have to do with legal liability? Digital Forensics is a growing discipline across the landscape of corporate, legal and academic institutions. The volumes of electronic information involved in new litigation and investigations calls for expert practitioners and witnesses to make sure that evidence is uncovered, preserved and presented without spoilation. The era of eDiscovery is upon us.

Analyzing the data and making sense of all of it by the investigator is getting easier yet we have a long way to go. This area of event reconstruction or forensic timeline editor is now becoming a reality:

The area of event reconstruction in computer forensics deals with analyzing and evaluating data obtained from a system and use it to determine what happened. The data recovery process is a well-covered area within computer forensics, but little work has been done on how to actually analyze and evaluate the data. Only very crude tools, such as mactimes or individual log analyzers, exist. A comprehensive event reconstruction on a system that takes into account data from various sources, such as file MAC times, system logs, firewall logs, and application data, is mostly done manually by the investigator. With storage capacities growing rapidly and systems permanently being connected to global networks more and more, it is not uncommon that the number of events recorded by a system easily goes into the hundreds of thousands.

This remains only a small facet of the real problem when it comes to finding what is relevant for litigation. In the context of legal discovery, the days of making copies and filing them in boxes is being dwarfed by the newest Federal Rules of Civil Procedure (FRCP) and the preservation of metadata. The best of breed answers to the digital discovery revolution can be found at Stratify, an emerging player in the automated eDiscovery spectrum of software solutions.

Optimize Litigation Readiness

General counsel together with their outside counsel need an effective means to manage documents and emails from key custodians and/or on specific topics in advance of litigation or regulatory discovery requests. When they receive a discovery request they need to be able to easily and quickly select sets of documents for review and analysis in their eDiscovery application.

The Stratify Legal Discovery™ service was designed to fulfill these requirements as the most easy-to-use, efficient eDiscovery solution available to law firms and corporate counsel.

Electronic Document Retention and Production has been a subject of great importance for many years inside law firms and the legal departments of the Fortune 500. The Sedona Conference has forged the way in providing guideance and some best practices to consider when embarking on this challenging mission. The question is, who is looking out for the Russell 2000 small cap company or mid-sized enterprise business? A single person may even represent the legal team, as the sole General Counsel.

Operational Risk includes legal risk, which is the risk of loss resulting from failure to comply with laws as well as prudent ethical standards and contractual obligations. It also includes exposure to litigation from all aspects of an institutions activities.

It's just a matter of time if you are in a highly regulated business sector that the time will come for your day in court. Make sure you are ready long before the phone rings or the papers are served. What is the source of the personal identifiable information that has caused this wave of consumer based fraud?

The FTC has released it's study on the methods, origins, victims and costs today of ID Theft. The odds are that the data breach may not be what puts you on the hot seat.

The US futures regulator, the Commodity Futures Trading Commission, has filed a complaint in the District Court for the Northern District of Georgia against New York-based hedge fund manager Cornerstone Capital Management and its chief executive, Joseph Profit of Atlanta.

The complaint alleges that Cornerstone and Profit violated the anti-fraud provisions of the Commodity Exchange Act and a CFTC regulation. On January 31, US district judge Richard Story issued a restraining order freezing the defendants' assets and prohibiting them from destroying documents or denying CFTC staff access to books and records.


06 February 2007

Self-Regulation: NERC Get's Proactive...

Now that the power sector and electrical utilities are going public with their acceptance of converged standards, other sectors may not be far behind. Some of the regulated critical infrastructure sectors have been working towards an industry wide set of controls that must be implemented and audited. Who will be next?

The North American Electric Reliability Council's new cybersecurity standards for critical infrastructure protection have eight categories, which apply utility risk management analyses to networked systems. A thumbnail description of the main areas:

  • Critical cyberassets
  • Security Management Controls
  • Personnel and training
  • Electronic security
  • Physical security
  • Systems Security Management
  • Incident Reporting and Response Planning
  • Recovery plan
You can bet that the drafting team has pulled their language from many of the standards that have already been in practice for years. In fact, most of the launch point for this effort came from work done soon after 9/11. How soon other industry sectors decide to adopt this framework will likely be decided by the lobby shops. Politics aside, the electric utility sector has moved into a phase of self-regulation and for good reason.

The huge blackout of Aug. 14, 2003, in which a software glitch at a single electrical provider in Ohio cascaded into an event in which 50 million people in North America lost power, underscored the importance of the reliability standards discussion. But Miserendino says that the group's biggest motivator was the threat that FERC might come in and do the regulating for it. In part, he says, that's because the 2005 Energy Act made FERC responsible for electrical transmission reliability and gave the federal agency the ability to fine utilities for noncompliance.

We can only hope that other Critical Infrastructure sectors take the same initiative sooner than later. As private enterprises, you can do it your way now or face the governments perspective later.

01 February 2007

Future Jihad: Financing Systemic Ideology...

One only has to listen to a few stories from experts in Counterterrorism to realize that vigilance is still the mantra. Yesterday the facts and observations from Walid Phares made us ever so more aware and even more focused on the mission. Funding of the war of ideas.

His point is clear that the funding of education and systemic transfer of ideology across the globe is why we are still so vulnerable. "The class room. The news room. To the War room."
For the United States, winning the War on Terror depends on two battlefields. The first is overseas, where Washington must confront jihadi forces and help allies to win their own struggles with terrorism. This will require the United States to support democratic change abroad, both as a counterweight to jihadist lobbies and as a means of assisting Arab and Muslim democrats to win the conflict within their own societies.

The second, however, is closer to home. Homeland security planners must be thinking seriously about a duo of unsettling questions. First, are jihadists already in possession of unconventional weapons on American soil, and how can the U.S. government deter them? This crucial issue tops all other challenges, for a terrorist nuclear strike on the U.S. has the potential to transform international relations as we know them. Second, how deeply have jihadist elements infiltrated the U.S. government and federal agencies, including the Federal Bureau of Investigation, the Department of Homeland Security, the Department of Defense, and various military commands, either through sympathizers or via actual operatives?

In a recent Economist Intelligence Unit survey on Operational Risk Management the question is asked:

Which of the following types of threats receive the most attention in your organisation's consideration of Operational Risk?

  • 42% - Loss of Data
  • 36% - Systems Failure
  • 28% - Supply Chain Disruption
  • 27% - Worm or Other Malicious code attack
Unplanned downtime of systems was tied with malicious code, next was human error at 26%, human malfeasance such as theft or fraud at 20% followed by a tie for:
  • 15% - Terrorism
  • 15% - Application Failure
Why is terrorism tied for 8th on this list? Maybe it is because institutions have more confidence in our Homeland Security and the FBI than they do in their own IT department. Or could it be the frequency of the threat that puts these items so high or low on the list of concerns. One thing is certain, the financing of "Future Jihad" is not going away.

In fact, the funding mechanisms are morphing and adapting as new Anti-Money Laundering initiatives and Regulator oversight creates even more difficult avenues for terrorist financing to occur. The private sector still remains the Deputy Sheriff as new transactions take place outside the traditional banking controls of Citi, B of A and HSBC. Hedge funds, insurance companies and other broker / dealers still provide the weak link in the chain for tracking the movement of zeros and ones across a global financial grid.

This multi-dimensional problem is not something to ignore. When you really think about Terrorism, what is your definition? What is a terrorist?

The day will come when you finally realize that a terrorist is and could be increasingly responsible for the top 4 items on the EIU list. It's all a matter of your own worldview.

30 January 2007

Shareholder Value: Through Integrated Risk Management...

Supply chain risk management is getting more attention these days. As institutions get their own house in order with operational risk losses they are moving outside and auditing their suppliers. The complexity of the supply chain is increasing as organizations become leaner. A recent AMR Research Study results reveal that supplier failure and continuity of supply is the number one risk factor for 28% of firms.

The Enron scandal and the emergence of Sarbanes-Oxley compliance, the 9/11 terrorist attack, SARS and avian flu threats, the Asian tsunami and Hurricanes Katrina and Rita, and high-profile business failures have forced companies to evaluate how well-prepared their organizations are to handle catastrophe and unplanned events. For other firms, strategic and execution risks are front of mind, such as hitting a launch window for a short lifecycle product.

Additional survey results include:

  • 33% of firms say they have dedicated budget line items for supply chain risk management activities.
  • 54% of firms plan to increase their budgets for risk management over the next 12 months. Of those firms, the average spending increase will be 17% year over year.
  • The top areas of application spending to support supply chain risk management are sales and operations planning, inventory optimization, business intelligence and supply chain analytics, and supply chain visibility and event management applications.
And while much of these manufacturing and distribution organizations are focused on the supply chain, in the financial sector, two international laws will affect how organizations retain, recover and report on data. BASEL II, which took effect Jan. 1, requires the worldwide banking community to uniformly capture data to allow operational risk factors to be identified and analyzed. This is just the beginning of additional financial sector scrutiny as the hedge funds exposure becomes a regulators new target zone.

Concern that booming lending to hedge funds may have led to a relaxation in credit standards has prompted US and European regulators to start the first joint investigation into whether banks and brokers are managing such risks appropriately.

The move is a sign that regulators are stepping up transatlantic co-ordination. It comes after a call by Angela Merkel, the German chancellor, for closer US-European Union co-ordination on financial regulation.

Officials from the Securities and Exchange Commission, the UK’s Financial Services Authority, the New York Federal Reserve and other European regulators met last month to discuss credit issues, according to David Cliffe, an FSA spokesman.

They want to know if the collateral required of hedge funds from their lenders is enough to cover losses, and whether margins are set at appropriate levels to help avoid systemic risk in the event of trading losses.

Operational Risks span the enterprise from the front office to the back office. From the servers room to the trading room. It's no wonder that Boards of Directors and corporate management have now realized that Enterprise Risk Management is the name of the game:

"The creation of shareholder value through the integrated management of risk."

New rules on the evidentiary discovery of clients' electronically stored information, international banking rules and more detailed interpretations of the Health Insurance Portability and Accounting Act will spur customers to put mechanisms in place to more quickly discover and retrieve archived data.

2007 is going to be another year of growth and opportunity. How you manage risk is going to be a deciding factor.

23 January 2007

ORM: Automation Revolution...

There are many organizations out there evaluating the now more mature Operational Risk platforms for their institutions. Just as the dawn of Enterprise Resource Management (ERM) such as Peoplesoft, SAP and others; there will be a fight for maket share and end users will look to their trusted advisors for expert resources. How do you know what application is right for your organization?

The question remains, are you ready? Is your department and staff up to speed on what this means for the process changes necessary in your enterprise for an ORM application to succeed?

OpenPages ORM automates the process of identifying, measuring and monitoring operational risk, integrating all risk data – risk and control self assessments, loss events and key risk indicators – in a single solution. OpenPages ORM combines powerful document and process management with a monitoring and decision support system that enables organizations to analyze, manage and mitigate risk in a simple and efficient manner.

Risk self-assessment capabilities enable organizations to document and evaluate their risk frameworks, including processes, risks, events, key risk indicators and controls. Executive-level dashboard and reports provide visibility into key risk metrics and policy compliance, while business process automation capabilities provide for real-time event escalation; automated risk processes, such as loss event root-cause analysis; and, streamlined remediation of issues and action items.

With loss event tracking, risk managers can track loss incidents and near misses, recording amounts, determine root causes and ownership. OpenPages ORM provides statistical and trend analysis capabilities and enables end-users to track remedies and action plans. Key risk indicators provide capabilities for tracking risk metrics and thresholds, with automated notification when thresholds are breached. OpenPages ORM provides facilities for both manual and automatic data inputs from internal and external data sources.

With OpenPages ORM, organizations can embed operational risk management and governance into the corporate culture, making procedures more effective and efficient while providing management with peace-of-mind that the corporate brand is protected.

How do you make a decision on OpenPages, SunGard or SAS? Like the implemention of ERM platforms you end up with new challenges, both technical and human oriented. Making a choice requires at some point a consensus of the end user, the departments impacted by the decision and the costs of customization or configuration. The total project will also require:

  • Choosing the correct technology solutions with your specific business challenges.
  • Rapidly integrating new technology with the remainder of your IT infrastructure.
  • Effectively fine-tuning business processes to address your organization.
  • Continuously re-evaluating the deployment to ensure maximum ROI.
As with most large IT projects it's important to have Program Management Office (PMO) functions up and running prior to making a final purchase. And if you are a true Operational Risk Management professional, you have already performed your analysis of the threats and hazards to the successful implementation, training and launch of your new ORM system.

19 January 2007

Investigations: Rules of Engagement...

Sarah Scalet at CSO has asked the question: What are the 10 commandments of responsible investigations?

The topic is a result of the HP scandal. What are the prudent rules of engagement to answer the original question? Who is leaking information from this Board Room to the media?

Sarah says, "I did a lot of thinking and had a lot of conversations about how to run corporate investigations in a responsible way.

By responsible, I mean not only done in a legal and ethical way (although those things, too), but also done in an effective and appropriate way. There are a lot of gray areas in investigations, and there are complicated and expensive ends to which you can take things. If we've learned anything from the mainstream media coverage of the HP debacle, it's the importance of making sure that an investigation meets the suspected crime."

In any investigation of fact finding and to find the truth there will be data leaving a trail of answers, the key is to make sure you have the correct hypothesis. If you haven't first created a sound and cohesive test plan, the results will not answer the question, hunch or theory. And that is where investigations go down a path of emotional intent as opposed to a process of factual discovery. The data collection didn't answer the emotional question so go find some information that does. This is where the real flaw lies in most investigations.

Let's take a quick quiz to make a point:

Business crime losses are typically the result of:

a. Non-violent acts committed by insiders.
b. Non-violent acts committed by outsiders.
c. Violent acts committed by insiders.
d. Violent acts committed by outsiders.

If you answered "B" then you are incorrect. The answer is "A". Insiders are the first place you begin to look when accounts are missing money, the system has been hacked or vital corporate information has fallen into the wrong hands.

From the behavioral sciences perspective it is axiomatic
that a protection program will not succeed unless it:

a. Meets the personal needs of the vast majority of the workforce.
b. Cultivates the willing cooperation of those affected by it.
c. Incorporates sufficient disciplinary sanctions to convince the workforce to follow
prescribed procedures.
d. Provides for termination of employment in the case of repeated violations of mandatory procedures.

If you answered "C" then you are wrong. The answer is "B". The willing work force, employees and society in general follow and obey the laws that they can identify with the most. In the Board Room the normal procedure is to have people sign a non-disclosure agreement. By having people submit to the act of promising not to talk about what happens behind closed doors, you are creating a forum for trouble.

The Ten Commandments of Responsible Investigations would not be necessary if transparency and policy governance was imbedded in the culture. If this was in place, people would not have as much of a motivation to break the rules. At the root of the issue, you have to go back to one of our earlier blogs on Trust.

12 January 2007

Policy Governance: The Road to Change...

The Board of Director's at your company are talking again about Policy Governance. The reason is that change is necessary and when it's time for a new worldview, there are only a few real choices anymore. The old way hasn't worked and now it's time to start with a blank sheet of paper.

So what is Policy Governance?

Policy Governance�, an integrated board leadership paradigm created by Dr. John Carver, is a groundbreaking model of governance designed to empower boards of directors to fulfill their obligation of accountability for the organizations they govern. As a generic system, it is applicable to the governing body of any enterprise. The model enables the board to focus on the larger issues, to delegate with clarity, to control management's job without meddling, to rigorously evaluate the accomplishment of the organization; to truly lead its organization.

In contrast to the approaches typically used by boards, Policy Governance separates issues of organizational purpose (ENDS) from all other organizational issues (MEANS), placing primary importance on those Ends. Policy Governance boards demand accomplishment of purpose, and only limit the staff's available means to those which do not violate the board's pre-stated standards of prudence and ethics.

Is management clear on the mission? Is the CEO out of synch with what the Board of Directors "Ends" are and what direction they are heading in? Policy Governance may be the answer. Yet a new mindset shift or a new methodology will not get you to where you want to be without effective Governance Strategy Execution.

Reinventing your board isn't easy and putting a fence around the CEO perimeter may be even harder. The goal is to make sure that your policies are resilient and endure beyond the potential longevity of a CEO. If you can accomplish this, then it takes the personal human to human potential for conflicting personalities or styles out of the equation. You have to start high enough and in the most broad context:

The CEO shall not cause or allow any organizational practice, activity, decision or circumstance that is in violation of commonly accepted business and professional ethics and practices...

Now that you have the outer perimeter set, you can start to narrow it down and provide greater scrutiny in places you are really concerned about.

As an example, and this is not a one way street:

  1. The Board will not provide orders to people who report directly or indirectly to the CEO.
  2. The Board will not review or evaluate staff other than the CEO.
At the end of the day or the fiscal year for that matter, being on the Board of Directors requires courage and the ability to make hard decisions. Policy Governance is one way to take the change process and to make it happen like you never have in the past. And remember, John Carver and the Policy Governance model are one in the same. He is the inventor and steward for this mechanism of change in the global corporate enterprise.

14 December 2006

Litigation Risk: Thirsty for Justice...

The big four or five or six firms have had a big run in the post-Enron era. Micro-cap companies with $75M. in assets are still not subjected to SOX. What does the crystal ball say about post-Spitzer investigations as he takes on his new role as governor? Did SOX clarify the CFO's internal controls and give investors a better view into their risk portfolio?

On the eve of a highly anticipated Securities and Exchange Commission meeting that could bring about looser regulations for small businesses that have yet to comply with the Sarbanes-Oxley Act, a new study credits the 2002 law with cleaning up larger companies' internal controls and reducing the number of errors in financial statements.

In fact, the Glass Lewis & Co. report — released on Tuesday — says the number of restatements by larger companies fell 26 percent during the first nine months of 2006. The report's authors attribute this decline to the most contentious provision of Sarbox, Section 404, which requires management to attest that their company has adequate internal controls.


In parallel, the Department of Justice has issued the McNulty Memorandum that will provide more clear guidance on the rules for a federal prosecutor should they want to bring charges against a company. The Principles of Federal Prosecution of Business Organizations was created as a result of intense lobby efforts by business advocates in Washington, DC.

The new guidelines, which the department has dubbed the "McNulty memo," say that "prosecutors generally should not take into account whether a corporation is advancing attorneys' fees to employees or agents under investigation and indictment." The only exception, according to a footnote in the memo, is in "extremely rare" cases where the "totality of circumstances" show advancing fees to culpable employees was done with the intention to "impede a criminal investigation."

With respect to obtaining privileged information, federal prosecutors will have to go through a more rigorous approval process, similar to the process required of prosecutors seeking electronic wiretaps or subpoenas for reporters. For certain types of sensitive attorney-client information, such as the advice a defense attorney gave to the management of a corporation facing a fraud investigation, prosecutors are now required to obtain the approval of the Justice Department's No. 2 official in Washington -- currently McNulty.

For privileged factual material a company has obtained through an internal investigation into an alleged fraud, such as transcripts of interviews with culpable employees, prosecutors will need to obtain the approval of the local U.S. Attorney in their district, who can only sign off on such a request with the approval of the head of the DOJ's Criminal Division in Washington, currently Alice Fisher.


And just when KPMG thought they were being vindicated they have been served with a law suit from Fannie Mae. When the auditors start fighting against corporate management or vice-versa, the lawyers get in the middle and you can bet that hundreds of millions of dollars are at stake. In the end, there is only one winner; and it's not the investor.

11 December 2006

Privacy: Phone Records Protection Act...

Last week, HP agreed to a $14.5 million settlement in the California civil lawsuit related to the company’s spying scandal. And this week we only have President Bush to sign the "Pretexting" bill:

The U.S. Congress has wrapped up its work for the year by passing a bill that would make it illegal to obtain a person’s phone records without permission.

The Senate late Friday passed the Consumer Telephone Records Protection Act of 2006 , spurred in part by revelations in September that Hewlett-Packard (HP) investigators had used deceptive means to gain access to phone records of reporters and company board members.

The bill, sponsored by Representative Lamar Smith, a Texas Republican, would make illegal the act of pretexting — tricking phone companies into giving up private records by pretending to be a customer. The bill, which passed by voice vote in the Senate, allows prison sentences of up to 10 years and fines of up to $500,000 for deceiving phone companies into handing over records such as phone logs.


As Jon Doak, the new Chief Ethics and Compliance Officer continues in his new role at HP it should be interesting to see how the criminal case proceeds. Corporate monitoring of it's employees and suppliers will get new oversight and the IT organization will soon be storing all e-mail meta data if it isn't already. Organizations like HP have a duty to protect their intellectual assets and trade secrets. Exactly how you implement those policies, tools and strategies calls for an effective risk assurance program that includes far more than just new awareness training.

The Private Investigation industry and Online Data Brokers who have collaborated in the past will be scrutinizing any upcoming enforcement actions to determine if the bill actually has any "teeth". Can you hear the US Attorney on the phone right now? "Set up a task force"...

07 December 2006

Basel II: Hedge Funds Risk...

Hedge Funds Managing Partners have been looking in the rear view mirror as they see the regulators following their every move. Oversight is not just a phenomenon here in the U.S. with the SEC and our own legislators. There is another international wave of change on the horizon:

Japanese banks may be forced to cut back their investments in hedge funds to comply with a global risk regulation.

Banks, pension funds, and insurers are among the largest Japanese investors in hedge funds. Japanese investors have quadrupled their hedge fund holdings during the past five years, to $35 billion.

The March 2007 deadline for Japanese banks to comply with Basel II, a regulation that will alter the capital reserve requirements for financial institutions, is what is causing the concern. The regulation could be especially problematic for smaller Japanese institutions, which manage more than one third of the country's $6.7 trillion of assets. Those institutions may be "incapable" of managing the associated risk under the new rules, one banking executive told Bloomberg News at a conference this week.

In some cases, banks will have to hold $1 in reserve for every $1 invested. Japanese regulators have yet to announce any guidance for complying with Basel II.


Here in the United States the pressure is building to develop more systematic compliance for hedge funds to address the growing corruption and fraud schemes.

Senate Judiciary Committee Chairman Arlen Specter, a Pennsylvania Republican, is circulating draft legislation that would require hedge funds accepting pension money to register with federal regulators. Hedge funds would also be forced to set up ethics codes and compliance programs, and allow the U.S. attorney general to reward private citizens for helping in insider trading cases.


Why all of the talk about regulation and oversight? With over 8000 hedge funds now controlling over $1 Trillion in assets it won't be long before the marketing gets pushed down to just the "high net worth" individuals. Having a place for pension fund managers to get some portfolio exposure on the other end of a risk spectrum is one thing. To move the access to these investment vehicles closer to the average consumer is now the concern.

The hedge fund industry has shown few signs of major fraud, but cases of wrongdoing may rise if more of these investment vehicles are sold to mass-market savers, international financial regulators said on Monday.

The sector does not appear to have high levels of dishonesty, but some national watchdogs fear risks of fraud could rise if these funds were to become more available to retail investors, the International Organisation of Securities Commissions (IOSCO) said in a report.

Hedge funds, traditionally a secretive industry domiciled in offshore tax havens such as the Cayman Islands, have come under growing scrutiny from central banks and regulators concerned about the sector's potential impact on financial stability.

Traditionally, hedge funds have been used only by wealthy individuals or institutions such as pension funds.

"The extent of fraud relating to hedge funds varies in the member jurisdictions ... the absolute number of fraud complaints is presently not high, although some regulators perceive a risk of greater fraud in the future as further retailisation occurs," the report said.