13 August 2010

Risk Appetite: In Search of the Perfect...

Operational Risk in the corporate enterprise is on the rise and savvy CxO's recognize it. The continuous and advanced schemes, attacks, reputation crises and regulatory compliance changes has the executive suite on full alert.

The global news cycle, financial markets in turmoil and a seemingly upset weather pattern on "Planet Earth" has OPS Risk professionals on ready standby. It's 24 x 7 x 365 responding to new threats and a growing set of domino effects as incidents are more interconnected and have substantial new interdependent relationships.

Operational risk is a serious concern not only to traditional and alternative investment managers, but also to their clients and the organizations that regulate buy-side firms. In worst-case scenarios, an investment firm’s failure to identify and mitigate operational risk can result in significant direct costs and a devastating loss of reputation. It may take years to reassure investors, regulators, and trading partners that the firm is well-managed. So what exactly is operational risk? Castle Hall Alternatives calls it “risk without reward.” The Basel Committee on Banking Supervision (Basel II) defines operational risk as “the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events,” and states that the definition is intended to include legal risk but exclude reputational risk, and lists as examples events ranging from data entry errors to earthquakes.¹ But operational risk is not something that can be easily identified by a generic checklist, nor is there a single, universally applicable approach to mitigating the operational risks to which a given firm is exposed.

A generic check list is by all means not the way to approach most Operational Risks yet starting with a standard framework of controls and optimizing from there is a good start. Certainly the natural catastrophe risk mitigation exercise whether the tornado or earthquake has a foundation in the kinds of preparedness that can assist those caught in the vortex or the fault line of destruction. Yet how could a check list really help with a threat that is adapting to your environment on the fly and creating new obstacles to mitigate the risk before you?

Kerry Dewey was a finance officer for a small nonprofit in the Pacific Northwest. She was having a bad day, but it got worse when her local bank called her to inquire about the validity of a recent funds transfer for just under $10,000 from the nonprofit’s account to an account at an Alabama bank. Moments before, the Alabama bank had contacted Kerry’s bank because its policy is to investigate any transfer that’s close to, but less than, $10,000 – an amount that fraudsters commonly use to avoid currency transaction reporting.

Kerry’s bank stopped the transfer after she assured them that no one in her organization initiated the funds transfer. The episode prompted Kerry to review the nonprofit’s banking transactions in the past few days. She uncovered five other illegitimate transfers that totaled close to $50,000, and each transfer went to a different payee. Fortunately, her bank was able to contact the banks where the funds were transferred, and those banks were able to stop the transferred monies from being withdrawn by the fraudsters. Kerry had opened a very dangerous e-mail.
This case is fictional, but it’s representative of a relatively new “spear-phishing” e-mail scam that has recently emerged as a significant source of revenue for cyber criminals.

As you can see the Small-to-Medium-Enterprise (SME) and other businesses that might have a single person responsible for payroll, accounting and acting as corporate controller are just as vulnerable to the Operational Risks as the large hedge funds, Global Money Center institutions and Corporate Enterprises of the Fortune 500.

The pervasive and constantly evolving components of Operational Risk now require a substantial blend of people, software and management systems. Those savvy CxO's now realize that Operational Risk Management is something that is not being dealt with solely by the CFO, CRO, CIO or CSO in it's entirety. Therefore, the silo's of risk management within the organization are themselves a "substantial risk" to the overall enterprise risk management aspiration. The "Insider" who watches these silos manage their domains and fiefdoms with the goal of keeping it all within the unit or department or section realize that their scheme or attack will have little chance of detection for months, even years.

This is why the Office of Inspector General in government is so necessary and is so feared. This is why the outside auditors or independent investigators are so feared. This is why these two mechanisms for mitigating risks are typically too late and discover something that in the end, most people had a hunch was going on anyway. It's a perpetual cycle that won't end anytime soon and will keep our organizations searching for that eternal balance of a "Perfect Risk Appetite".

29 July 2010

Employee Misconduct: Mitigating Insider Risks...

The new Verizon Cyber Report is a valuable read for OPS Risk professionals that focus on data breach and incident response. The full breach report can be found at this link at Verizon Business.

We have to agree with the observations made by Brian Krebs on the following topic in the report:

A key finding in this year’s report is that most companies suffering breaches missed obvious signs of employee misconduct – breaches that were either initiated or aided by employees. Sartin said in almost every case where a breach investigation zeroed in on an employee as the culprit, investigators found ample evidence that the employee had long been flouting the company’s computer security and acceptable use policies that prohibit certain behaviors, such as surfing porn or gambling Web sites on company time and/or on corporate-issued laptops.

The study found a strong correlation between ‘minor’ policy violations and more serious abuse. From the report: “Based on case data, the presence of illegal content, such as pornography, on user systems (or other inappropriate behavior) is a reasonable indicator of a future breach. Actively searching for such violations rather than just handling them as they pop up may prove even more effective.”


The "Insider Threat" continues to be under estimated and all of the monitoring tools will not be able to stop it completely. Ever. So what are some of the solutions to address the issues at hand? Here are a few ideas worth exploring if not for the Fortune 500 Enterprise but the small-to-medium enterprise (SME) who doesn't have the budget or the internal staff to engineer a robust and resilient infrastructure. They have their unique place in a layered approach to cyber defense:

Idea #1: ScanSafe

Cisco recently acquired the pioneering SWG SecaaS company ScanSafe. ScanSafe continues to execute well and has the largest market share in the SecaaS market including several organizations with well more than 100,000 seats. ScanSafe is expected to form the basis of an increasing array of Cisco SecaaS offerings, starting with the addition of e-mail. Cisco's credibility with the network operations team, the progressive development and market growth of the S-Series and the acquisition of the leading SecaaS provider moved Cisco into the Leaders quadrant this year.

Idea #2: IronKey

IronKey was chosen by the Reader Trust Voting Panel, comprised of security and technology experts from large, medium and small enterprises from all major vertical markets, representing the wide distribution of SC Magazine readers. With an unprecedented number of entries submitted the 2010 SC Magazine readers selected IronKey over competing solutions from Check Point, CREDANT, PGP and Symantec.

IronKey brings unprecedented mobile data security to enterprise and government organizations by combining the IronKey multifunction security devices with the ability to remotely manage the devices and strictly enforce security policies from a centralized administrative console. IronKey enables organizations to securely deliver complete desktop environments on ultra-secure, remotely managed devices with integrated two-factor authentication and fraud protection capabilities.


Idea #3: OpenDNS

OpenDNS has solutions that are perfect for organizations of all sizes, from small businesses to Fortune 500 enterprises. With no equipment to install, no upgrades and no maintenance, OpenDNS will reduce your costs, give you more control and make navigating the Internet on your network a safer, more secure experience.

OpenDNS provides comprehensive security for your organization's network through botnet and malware site protection. OpenDNS delivers network security services through the DNS layer, blocking known malicious or infected sites from resolving on your network. Since infected sites are prevented from resolving, malicious content is blocked from reaching your network, and thereby OpenDNS provides the most efficient protection available.

Built-in botnet protection stops trojans, key loggers and other persistent malware and viruses on machines in your network from sending out confidential data and personal information to hackers outside the firewall.


These are just three examples that we have found to be reliable, cost effective and easy for the small-to-medium size company to hedge against some of the infrastructure risks and bad behavior by employees. So what else could the savvy VP of Operational Risk inject into the organization to address some of the other types of "Insider Threat"?

Provided as a resource by the Association of Certified Fraud Examiners (ACFE), EthicsLine serves as an internal control tool through which companies can detect and deter fraud. Powered by Global Compliance, EthicsLine includes hotline, case management and analytics to empower organizations to prevent, detect and investigate instances of organizational fraud and abuse.

EthicsLine provides expertise and experience. As the power behind EthicsLine, Global Compliance introduced the original ethics and compliance hotline and is the largest provider of hotline, case management, and analytic solutions worldwide – supporting over 25 million client employees in almost 200 countries. Global Compliance also provides additional products and services that integrate with EthicsLine and protect an organization from fraud and abuse.


The employee who knows how to circumvent the "Rule Sets" as it pertains to the Acceptable Use Policy for the corporate digital assets may also be the same person who is stealing from the company. Whether they are stealing actual cash from the register, using vendor billing schemes or other occupational fraud tactics they understand how to get around the control objectives. Operational Risk Managers need to look at the employee population as an ecosystem of risk and that a certain percentage of those employees will be trying to surf Internet gambling sites and simultaneously misappropriating assets.

As you spend more time in OPS Risk, the more you understand the intersections with human behavior. The tools will assist you along the way yet it is the day to day interaction with people that will help you predict where and how someone may be increasing the risk to your enterprise.

23 July 2010

Top Secret America: Analysis of Competing Hypotheses...

Operational Risk Management Executives are still digesting the latest Washington Post investigative reporting from Dana Priest and William M. Arkin, "Top Secret America". The U.S. Intelligence Community (IC) and the Defense Industrial Base (DIB) employees in the suburbs of Virginia, Maryland and DC will be debating the impact over whispered dialogue around the weekend BBQ or over a candle light dinner in their favorite Georgetown restaurant.

The aftermath of the disclosure, increased transparency and ongoing investigation will continue for months and most likely years. New questions, new facts and new ideas will be put on the table for consideration inside the board rooms of private sector companies, law firm lobby shops and the government program management offices. Risk Management and the topics of risk exposure and the likelihood of incident categories will be the center of the conversation.

Since the Safety and Security of the United States is the foundation for the article, it makes the nexus of all the newspaper writing, blogposts, TV interviews and Internet "Tweets" relevant to Operational Risk Management.

As professionals in the IC and DIB continue to evolve their solutions on the ever changing threat to US citizens, you only have to look to the requirements placed in front of them. What risk are we trying to mitigate? What exposure do we have now? What is the likelihood that this will happen to us and how soon?

The requirements dictate the solution. The understanding of the threat dictates the requirements. The solution is not going to be implemented one time, one place and then it's over. It's going to be adaptive and it's going to evolve at the speed of the threat. The question that is always being asked by everyone is, how fast can we adapt?

Dana Priest and Bill Arkin may have done our country a great service at this point in time. The "Analysis of Competing Hypotheses" (ACH) may be utilized to ultimately prove the correct course and to make even more sound analytical judgments about our national security evolution. By actually using the data facts uncovered by their current research the process of eliminating errors in the data can begin. And once the data has been normalized and cleansed so that all agree that it is the true baseline, then the ACH can begin.

As the DNI provides the leadership and works through the governance cycles with all of the IC Director's and Secretary's, then the use of a vetted methodology such as ACH combined with the entire risk management exercise, may indeed reveal some operational risk vulnerabilities. It would be through the analytic process, risk matrix and the future enterprise architecture work that a more robust, resilient and economic model is developed and implemented.

Now about the question on whether our national security has been compromised or the risk to our private sector assets has increased as a result of the Washington Post article. Only time will tell as the possibility of future VBIED incidents, take out the facades of previously unknown or unnoticed IC or DoD facilities identified and validated in the newspaper's research.

Even now however, the vulnerability of our vital national security assets are most likely to be copied, stolen, corrupted or deleted by the logic bombs lying in wait, before major kinetic disruptions. It will no doubt be a 4GW blended attack on our homeland that combines the effects of both that experts predict is our greatest threat.

This brings us back to the quote at the top of this blog:

"The Only Thing Necessary For Evil To Triumph Is For Good Men To Do Nothing." --E. Burke

God's Speed to the United States of America...

06 July 2010

Black Swan: Consumer Financial Protection Bureau...

The Consumer Financial Protection Bureau has been born out of the 2,300 pages of the final US Federal Financial regulation of 2010. The tone on what and how the CFPB operates is spelled out in the legislation and Operational Risk Managers are actively scouring the fine print to determine the compliance and legal ramifications. Yet the new Director's leadership may spell out the impact more than any of the new rules. The WSJ enlightens us:

The legislation says the bureau's purpose is to "regulate the offering and provision of consumer financial products or services." Details are left largely up to the new director, who would serve a five-year term. The law creates offices for research, tracking consumer complaints, consumer financial literacy and fair lending, among others.

Among the director's first tasks will be refining the agency's mission. Critics and supporters, though agreeing on the importance of the new agency, differ on what will constitute success.


Institutions will be adjusting their behavior to the new rules and it will be adjusting to how it continues to do proprietary trading. It's hedge fund ownership is now limited to 3% and the "Volcker Rule" is the same percentage for trading Tier 1 capital. The entire financial services industry is essentially gearing up for more of the same with minor adjustments on how it implements it's various risk management strategies. So what has changed and what will change?

Large banks and their supply chains will be looking for new ways to leverage their ability to improve margins. And when you look for ways to improve margins, you raise rates add more fees and incrementally gain a tremendous avenue for increased cash flows. Enterprise Risk Management will try to find a way to hedge against the "Black Swan" event from ever happening again. Even today, the business is still in the dark on the mathematical equations that caused the last implosion of world markets and the unraveling of the financial trust that is the foundation for the system to operate with efficiency and market speed.

Going forward the risk management professionals will be dissecting the final law to determine how it will impact their business, institution or agency for the next few years. As business owners and corporate institutions begin to see what direction the new Consumer Financial Protection Bureau (CFPB) chief will be taking, they will be devoting resources and budgets to adjust to these market changes.

And while all of this is evolving in the open and transparent world of finance you can bet that the next "Black Swan" event is on the horizon. As "Operational Risk Managers" who witness the speed and the complexity everyday in the trading pits, software development units and on the white boards of countless conference rooms will tell you; the next one is out there:

"A Black Swan is a highly improbable event with three principal characteristics: It is unpredictable; it carries a massive impact; and, after the fact, we concoct an explanation that makes it appear less random, and more predictable, than it was." Nassim Nicholas Taleb, from his book The Black Swan - The Impact of the Highly Improbable

Sens. Chris Dodd (D., Conn.) and Blanche Lincoln (D., Ark.) are trying to calm the fury among bankers and business groups over a last-minute change to the financial overhaul bill that critics now say could upend the way companies hedge against risk.

In the early hours of Friday June 25, Democrats altered a key provision to the derivatives section of the financial overhaul bill. It has a completely different meaning depending on who you ask. Some believe the language would require all people engaging in derivatives contracts to post “margin,” or more costs to engage in a deal. Others believe it would apply only to big banks and major derivatives dealers. The difference could swing billions of dollars one direction or another.

The confusion stems from a part of the section, tucked into the 2,300-page financial overhaul bill, that says margin requirements “shall” be set against “all” uncleared swaps. Some companies believe they should be exempted because they aren’t risky derivatives speculators, and fear it will drive up their costs. Several companies and business groups have said the language is such a glaring mistake that it could undermine the entire derivatives market, particularly for companies using these products simply to hedge risk.

But the language is in sections of the bill setting rules for “swap dealers,” which are essentially banks or large derivatives traders regulators plan to place tougher restrictions on. Depending on how it is interpreted, the language could apply only to those “swap dealers.”

Regardless, the confusion has led to an uproar…


01 July 2010

Fraud Terrorism Nexus: Public-Private Partnerships...

The ACFE "Report To The Nations on Occupational Fraud and Abuse has been published in the July/August mailing of Fraud Magazine. There are some tell tale signs that Operational Risk Management is working and yet we have so far to go on this journey towards a more transparent, ethical and safe workplace environment.

Here are some of the highlights and findings from this annual survey:

  • 5% of annual revenues are lost to fraud
  • 25% of the fraud incidents involved losses of $1,000,000.00 or more
  • Frauds lasted a median of 18 months before being detected
  • Small organizations are much more likely to be victims
  • Fraud perpetrators often display warning signs they are engaging in illicit activities

While these are consistent with previous years results the article in this latest issue that caught our eye is worth further investigation and analysis. "The Fraud-Terror Link: Terrorists are Committing Fraud to Fund Their Activities."

The threat of terrorism has become the principal security concern in the United States since 9/11. Some might perceive that fraud isn’t linked to terrorism because white-collar crime issues are more the province of organized crime, but that perception is misguided. Terrorists derive funding from a variety of criminal activities ranging in scale and sophistication – from low-level crime to organized narcotics smuggling and fraud. CFEs need to know the latest links between fraud and terror.

Credit card fraud, wire fraud, mortgage fraud, charitable donation fraud, insurance fraud, identity theft, money laundering, immigration fraud, and tax evasion are just some of the types of fraud commonly used to fund terrorist cells. Such groups will also use shell companies to receive and distribute illicit funds. On the surface, these companies might engage in legitimate activities to establish a positive reputation in the business community.

Financing is required not just to fund specific terrorist operations but to meet the broader organizational costs of developing and maintaining a terrorist organization and to create an enabling environment necessary to sustain their activities. The direct costs of mounting individual attacks have been relatively low considering the damage they can yield.

The nexus between those who wish to attack our physical or digital infrastructure assets are after the same outcomes. High number of victims and media exposure. The threshold for financing overt attacks is coming down and the face of terrorism is changing. It has morphed into a pattern of behavior that requires the OPS Risk professionals to see the link and to study the reasons why the Fraud-Terror convergence is happening now.

Small groups of people who are doing pre-operational surveillance on targets in both physical locations and online Internet points of presence are in need of funding. Yet it doesn't take much. The London Bombings of 2005 were financed with a budget of around $15K. Now let's go back to the stats from the latest survey for a minute.

"Internal controls alone are insufficient to fully prevent occupational fraud. Though it is important for organizations to have strategic and effective anti-fraud controls in place, internal controls will not prevent all fraud from occurring, nor will they detect most fraud once it begins."

So where is this wave of fraud schemes coming from and attacking the average person on the street. Actually it's in cyberspace. This is where a tremendous amount of non-profit, charitable and other mechanisms for generating revenue and funding for terrorism occurs. Identity Fraud, Mortgage Fraud, Insurance Fraud and Immigration Fraud all are the precursors to the collection and potential dissemination of funds to those who are planning to harm people and our economic way of life.

We have found in that the best approach to this threat is education, awareness and sharing of best practices. To jump start the conversation in your metro area of the United States you only have to look to your local InfraGard chapter. This is a good first step in opening up the dialogue on topics such as transnational economic crime and who is behind these operations. Here is a good example of what's happening in the Washington, DC area:

Topic:

"The Communication Infrastructure and Organization of Transnational Cyber Criminal Syndicates"

This Intelligence Briefing will address the tradecraft employed by cyber criminals who participate in private, organized transnational criminal operations using self-created and self-maintained infrastructures rather than the tradecraft of those in traditional underground forums that exist on the Internet. Included in the briefing will be discussion of technical infrastructures, communication methods and division of labor of cyber criminal organizations.


Once the Certified Fraud Examiner, IT cybersecurity professional and the intelligence analysts finish their brown bag lunch, you can see the collaboration wheels turning. In the grand scheme of millions and billions of dollars that are spent on sensors, anti-terrorism technologies for homeland security or the dollars wasted on procurement, the simple public-private partnership wins every time. Again, reflecting on the latest Occupational Fraud survey:

Occupational frauds are much more likely to be detected by tip than by any other means. This finding has been consistent since 2002 when the ACFE began tracking data on fraud detection methods.

22 June 2010

Workplace Privacy: Ontario Prevails on Data Audit...

Operational Risk Management professionals in corporate America have been following the Quon vs. City of Ontario case for five plus years. Now the Supreme Court of the United States has ruled 9-0 to increase the clarity on the new age of electronic privacy in the workplace. The LA Times explains:

Washington…In its first ruling on the rights of employees who send messages on the job, the Supreme Court rejected a broad right of privacy for workers Thursday and said supervisors may read through an employee's text messages if they suspect the work rules are being violated.

In a 9-0 ruling, the justices said a police chief in southern California did not violate the constitutional rights of an officer when he read the transcripts of sexually explicit text messages sent from the officer's pager.

In this case, the high court said the police chief's reading of the officer's text messages was a search, but it was also reasonable.

Police Sgt. Jeff Quon had sued the chief and the city of Ontario, California after he learned the chief had read through thousands of text messages he had sent to his wife and a girl friend. Quon won in the 9th Circuit Court of Appeals, but lost in the Supreme Court Thursday.


The scope of the investigation by the employer was not unreasonable and within the scope of determining whether the large amount of text messages was work related. What kind of corporate risk initiatives will be impacted by this ruling?

As corporations continue to battle the "Insider" risk associated with occupational fraud, workplace violence related stalking or sexting, industrial espionage, corruption and violations of acceptable use policies this case will become an example. What will continue to be the challenge for OPS Risk professionals who are responsible for internal monitoring, digital asset audits and insider investigations of potential malfeasance is the scope and reasonable nature of the case.

Get ready for a rush to the local Verizon Wireless or AT&T store for your own personal PDA or iPhone due to Justice Kennedy's ruling:

What’s more, Kennedy suggested that privacy in the modern age has more than one meaning.

“Cell phone and text message communications are so pervasive that some persons may consider them to be essential means or necessary instruments for self-expression, even self identification. That might strengthen the case for an expectation of privacy. On the other hand, the ubiquity of those devices has made them generally affordable, so one could counter that employees who need cell phones or similar devices for personal matters can purchase and pay for their own. And employer policies concerning communications will of course shape the reasonable expectations of their employees, especially to the extent that such policies are clearly communicated. “


If you are the CxO responsible for the auditing of digital assets within the enterprise, or the responsible party for insuring privacy in the workplace it's time to convene a two day workshop to review. Take a few days to bring the legal, privacy, IT and business unit deal makers to the same hotel resort country club to converge on this vital issue. The Operational Risks associated with executive communications that were previously thought to be private may be monitored and audited anytime when company assets are being utilized.

The opportunity to work through different workplace related scenarios, highlight the legal rulings and discuss the "What if's" could mean the difference between adversarial litigation and "Achieving a Defensible Standard of Care."

This is also a good time to establish the foundation for the "Corporate Intelligence Unit" within the enterprise:

Beyond the utilization of threat assessment or management teams, enterprises are going to the next level in creating a "Corporate Intelligence Unit" (CIU). The CIU is providing the "Strategic Insight" framework and assisting the organization in "Achieving a Defensible Standard of Care."

The framework elements that encompass policy, legal, privacy, governance, litigation, security, incidents and safety surround the CIU with effective processes and procedures that provides a push / pull of information flow. Application of the correct tools, software systems and controls adds to the overall milestone of what many corporate risk managers already understand.

The best way in most cases to defend against an insider attack and prevent an insider incident is to continuously help identify the source of the incident, the person(s) responsible and to correlate information on other peers that may have been impacted by the same incident or modus operandi of the subject.

07 June 2010

FCPA Readiness: Training Corporate Aviators...

Operational Risk Management is a topic that rarely comes up at a social event, unless you happen to be talking with a "Naval Aviator". In just a few minutes of explaining the focus of this writers subject matter expertise, the dialogue took on a whole new level. Mike M. immediately began to talk about the many facets of Operational Risk in the context of flying his missions across the globe. He sipped his drink in the back yard under flaming torches as the backyard BBQ buzz was in high gear.

As we continued the conversation on the OPS Risk "All Hazards" point of view and the vulnerability of false or failed information he was clear about one thing. When all fails in the face of pre-planning, contingency exercises and the dawn of a new twist in your mission objectives becomes apparent, your training instinct is what takes over. This may be a true statement when it comes to the military worldview and their obsession with continuous training exercises yet it remains a lofty and sometimes elusive goal in the ranks of the private sector and Fortune 1000 companies.

The private sector company is still eons away from the level of readiness and the ability to call their employees in top shape as it pertains to corporate fundamentals. The Corporate 101 of ethics, compliance and legal risk is typically an hour orientation on the first week of the job. The training associated with protecting company assets and personnel is left to a few people in the Facilities Security Office. Providing the awareness of online threats, phishing and data leakage or privacy is often an online web "Flash" based learning module you must answer to correctly if you want access to the corporate e-mail server.

The serious nature of Operational Risk on the deck of the aircraft carrier operating in the Arabian Sea is light years away from the mind set of the Board of Directors at the latest Quarterly Meeting after a round of golf. You have to ask yourself why there is a difference?

The topic of Risk Management in the context of the corporate enterprise in many cases comes down to lawyers and insurance companies. The perception is that these two devices for risk management will be able to solve any problem that arises or any incident that could eventually occur. This mindset by corporate management is in many cases what causes their eventual downfall.

Investing in the education, training and awareness building of your company employees will in the long run provide tremendous business resilience and longevity. Exercising special diligence in the implementation of the proactive controls for early warning and effective detection will at some point pay off. Just ask companies such as HP or Avon:

Fitch Ratings says there could be rating implications to U.S. corporate issuers with modest free-cash flow or liquidity for violating the Foreign Corrupt Practices Act (FCPA). This is in addition to management distraction, reputational risk and added compliance costs according to a new special report issued today.

In April 2010 alone, three corporations rated by Fitch were the subject of news stories related to the FCPA, including Avon Products Inc. (Avon), Hewlett-Packard Co., and BHP Billiton, Plc. Violation of the FCPA is a criminal offense and average fines have started to increase. Mere indictment can trigger onerous reporting requirements, civil lawsuits and business losses. More important, enforcement activity is set to increase with a primary focus on the pharmaceutical industry.

In the U.S., proposed financial reform legislation in the House and Senate includes rewards for whistleblowers which provide added impetus for corporations to self-report violations. The cost of investigating violations on a worldwide basis can be relatively high, as noted in Avon's recent disclosure that the cost of its current FCPA investigation is expected to be in the $85 million to $95 million range during 2010 after being $35 million in 2009. The $85 million would represent approximately 55% of Avon's 2009 free cash flow. However, Avon maintains substantial cash balances which can easily fund these FCPA investigatory costs.


The Operational Risk associated with corruption on the front-line of business operations is growing. The reason is because of the continued pressure that is being put on the deal-makers and the "Rain Makers" to increase revenue. Companies that must fill the product pipeline with new inventory and the best pricing will continue to operate in risky waters, especially if they are selling their goods and services on a global scale.

As we finished our smoked beef BBQ, corn bread and baked beans "Naval Aviator Mike" came to the bottom line. "When the mission plan goes haywire or the equipment begins to fail, there is only one thing you have left. Your instinct. That instinct is directly hard wired to your training."

We agree and will continue our advocacy of the direct link between an organizations dedication and investment in Business Resilience, Training and Exercises and their ability to survive in today's hostile corporate environment.

28 May 2010

Memorial Day: Vigilance Reminder...

What does Memorial Day mean this weekend in the United States? A time to reflect on all those who have served and sacrificed their lives for our freedom and continued way of life. At the same time it is an opportunity to look into the minds of those who will determine the future course for our security strategy. The U.S. National Security Strategy articulates this future vision. How does Secretary of State Clinton see the new strategy?

The strategy calls on the United States to build its economy “and to shape the global system so that it is more conducive to meeting our overriding objectives: security, prosperity, the explanation and spread of our values, and a just and sustainable international order,” Clinton said.

The threats are diverse, the secretary of state continued, and include terrorism, proliferation of weapons of mass destruction and the means to deliver them, climate change, cybersecurity, energy security and many others. Responding to these threats, she said, also produces opportunities, new modes of cooperation, new capacities to improve lives and tangible efforts to bridge great gaps in understanding.

“We are in a race between the forces of integration and the forces of disintegration, and we see that every day,” Clinton said. “And part of our challenge is to define American leadership in relevant terms to the world of today and tomorrow, and not merely looking in the rearview mirror, which makes it very hard to drive forward.”



If you are sitting in a "Mud Hut" in Kandahar right now or standing on the grave of a loved one in "Section 60" at Arlington National you could be asking yourself, what does this all mean to me?

The thoughts and words of world leaders may change about what is the proper way to go about the "Global Housekeeping" this year or decade yet it will never change the threat that continues to be our greatest Operational Risk. The human beings on the planet that get up every morning to fight on the battlefield, find food and water for their family, commute to a chaotic and quiet room in a major city to read, analyze and think about new information or even pray to their god, have the same vulnerability.

A complacent point of view. A lack of vigilance to help defeat the evil behavior of other humans, prepare for the hazards thrown at us by mother nature and the will to utilize civility in our approach to solving all of the problems before us. Complacency is the greatest operational risk before us.

com·pla·cen·cy

–noun, plural -cies.

1.
a feeling of quiet pleasure or security, often while unaware of some potential danger, defect, or the like; self-satisfaction or smug satisfaction with an existing situation, condition, etc.

It is the reason there are so many people still scratching their heads on such topics as:

  • AIG
  • Bernie Madoff
  • SEC
  • Freddie Mac
  • Fannie Mae
  • Conficker
  • Umar Farouk Abdulmutallab
  • Qods Force (IRGC-QF)
  • Zeus
  • Faisal Shahzad
  • ‘Volume Algo’
  • Deep Water Horizon
And the list goes on. Memorial Day each year is a dedication to those who have served our country and still are serving our country. The operational risks are many and they are not slowing down. This Memorial Day 2010 requires that we all make the pledge to purge ourselves of any complacent attitudes. Our vigilance is the last opportunity we all have to make a difference on this planet.

19 May 2010

Hawaladars: Domestic Extremism Risk...

Are a network of "Hawaladars" operating within your organization? Or perhaps your online charity? Maybe it's both. This Operational Risk is real and still not on the radar of many NGO's or charitable non-profits. The clandestine method for moving money without a paper trail is ancient and it is still operating to fuel transnational criminal and terrorist operations in the high tech world of mobile phones, money service businesses and stored-value cards. "Domestic Extremism" is a national security issue. Bryan Bender of the Boston Globe explains:

An informal money-exchange network known as “hawala’’ — a centuries-old system that operates outside conventional banking networks — is at the center of the investigation into three Pakistanis arrested Thursday in Massachusetts and Maine with alleged ties to the suspect in the failed Times Square bomb plot, law enforcement officials said yesterday.

The men, who were detained on immigration charges after several raids across the Northeast, were described by government officials as having funneled money to Pakistani-born Faisal Shahzad, who is in federal custody for trying to set off a car bomb earlier this month. The three men are being investigated for possibly using the hawala system to provide money that Shahzad used to finance the plot, the officials said yesterday.

Detecting the use of a "Hawala"-based system is not going to be easy with high technology tools, systems and software that are in place with financial institutions. Even those legal citizens in country have found ways to move money back to relatives still in their native homeland before they took the citizenship exam and pledged their allegiance to their new country.

Operational Risks in your environment include the behaviors by employees, suppliers and 3rd parties that touch this anonymous and prolific network for moving money for potential use by criminal or terrorist non-state actors. Do you run the operations for a large charitable organization or non-governmental organization (NGO)? How many entities now are operating alone on the Internet acting as 501(c)3 organizations in the United States involved with Haiti Relief, Aide to Congo Refugees or even now environmentalists who claim to be advocates for cleaning up the Gulf of Mexico oil disaster?

The financial safeguards for even the most legitimate organizations who operate in the movement of funds for use in religious, community food banks and other non-profit charities must be continuously monitored. The controls for detecting the possible illegal transfer of money from an individual or business to another individual or transnational entity is a risk management priority. Utilizing capabilities from firms like World-Check in combination with even the most simple system for cross-checking transactions can be an initial step for those legitimate businesses who are still Operational Risk neophytes.

Anti-Money Laundering compliance has been part of the banking systems regulatory framework for decades. According to World-Check:

According to the KPMG Global Anti Money Laundering Survey published in 2007, a staggering US$ 1 trillion per year is being laundered by financial criminals, drugs dealers and arms traffickers worldwide. With this much laundered money in the wrong hands, criminal syndicates are able to expand their operations, resulting in more violence, higher levels of addiction and a range of related socio-economic problems throughout the world.

Laundered money is also known to finance highly coordinated international terrorist activities; a phenomenon that poses a clear and present danger to worldwide political and economic stability.

As such, Anti Money Laundering and the Combating of Terrorist Financing (CTF) can only be treated as pressing objectives of global concern. A sharp worldwide increase in the amount of wealth in private hands, combined with the multinational expansion of leading financial institutions, further necessitated the expansion of supranational legislation and law enforcement structures to combat money laundering and related financial crimes.


Entities such as the Financial Action Task Force (FATF), Wolfsberg Group and Basel Committee are key drivers of the regulatory policy-making process, and are closely involved in the standardization and enforcement of related compliance mandates.

So where do you begin as a consumer or a small and legitimate charitable organization? One place is with the "Top Ten Best Practices of Savvy Donors" at Charity Navigator. As a consumer this will give you a better idea on what to look for when you are providing money to a particular cause or to aid your favorite religious organization. As a charitable organization, it will give you an understanding of what you should be putting in place to become compliant and to attract the kind of donors you are looking for online. Here are "Six Questions to Ask Before Donating":

At Charity Navigator, we advocate that all potential donors take the time to ask charities questions about their programs, mission, and goals before they decide to support them. For those people who don't have the time or resources for this, we provide our services as a guide, so you can give with confidence. In addition, we have developed a list of questions that you as a donor should ask before you begin the act of supporting a charity.

Be alert and be vigilant. If the entity that you are engaging with doesn't pass the sniff test on these 16 questions then observe, document and report what you have experienced with the proper authorities within your organization or by contacting your local law enforcement. Follow the money.

30 April 2010

Resilience: Homeland Security Strategy...

Homeland Security is under siege the past few weeks in the United States. The "Deep Horizon" oil rig disaster in the Gulf of Mexico is threatening the states of Louisiana, Mississippi, Alabama and Florida. The Coast Guard is the lead agency. On the other front is the battle for the southern border with the state of Arizona and their quest to stem the flow of humans and millions of pounds of illegal narcotics from infiltrating the country.

For several years we have advocated the arguments for "Resiliency" for the corporate operational risk paradigm and now it seems that Homeland Security is making it's way towards the migration away from "Protection." And for good reason:

For example, resilience is listed as one of the five homeland security missions in the recently published Quadrennial Homeland Security Review, which defines it as “fostering individual, community, and system robustness, adaptability, and capacity for rapid recovery.”

Typically, the response to resilience is focused on critical infrastructure and the protection of these assets, such as our electrical, information technology and telecommunications sectors. At some point in the asymmetric warfare being waged daily online you realize that the the only strategy has to be that of resilience as the barriers of protection continue to fail. If you think about any system that has so many moving parts, complexity and shear breadth of vulnerabilities you realize that spending all of your efforts and resources on protection is fruitless.

Now if we apply the thoughts of resilience to the physical aspects of drilling for oil offshore and defending the borders that are thousands of miles long, what comes to mind? Remember, there is no possible way to eliminate the vulnerabilities completely to an unprotected mile of the border or a blowout on the drilling platform.

You see, as you come at the problem from a point of view that has to do with "Resilience" not just protection, you begin to think of new ideas that certainly should be considered going forward.

Notably, Dr. James Carafano of the Heritage Foundation spoke to this issue at a congressional hearing on resilience in the homeland in 2008. He said, “The current paradigm of ‘protecting’ infrastructure is unrealistic. We should shift our focus to that of resiliency. Resiliency is the capacity to maintain continuity of activities even in the face of threats, disaster, and adversity.”

So what would be some of the activities that we must have the capacity to maintain as we defend our U.S. borders? And what activities would we deploy, to keep oil from reaching the magnitude it has so far in the DeepWater Horizon breach in the Gulf? If you are one of these companies your Operational Risk teams are billing overtime:

Transocean Ltd (RIGN.S) (RIG.N) - The Zug, Switzerland-based company owned and operated the Deepwater Horizon Rig. The rig went into service in 2001 and was drilling the Macondo prospect about 40 miles off the coast of Louisiana.

BP Plc (BP.L) (BP.N) - BP hired Transocean's rig at a rate of about $500,000 per day to drill the well. BP is the project's operator and has a 65 percent working interest in the well.

Anadarko Petroleum Corp (APC.N) - The Houston company owns a 25 percent nonoperating interest in the well.

Cameron International Corp (CAM.N) - The Houston company supplied a piece of equipment known as a blowout preventer. Blowout preventers are put in place to stop an uncontrolled flow of oil or gas. The Deepwater Horizon's blowout preventer failed to operate and seal the well.

Halliburton Co (HAL.N) - The oilfield services company, which has headquarters in Dubai and Houston, provided a number of services on the Deepwater Horizon. The company was providing cementing on the well to stabilize its walls, according to Transocean's website. (Reporting by Anna Driver in Houston; Editing by Lisa Von Ahn)


In each case these are wake up calls to the work that is still to be done and the ideas yet conceived to address the key issues. One item of certainty will be the increased focus on compliance and regulatory oversight. The government is already mandating the inspection of all the Gulf oil rigs for the types of safety and security measures that may be mandated for these types of incidents.

And when it comes to the kinds of resiliency strategies for the continued influx of humans and contraband coming into the U.S., from Canada, from Mexico and from almost every other nation through our ports and airports, we have to be more creative. And the strategies have to be more robust.

Take it from someone who has been dealing with insurrections, 4th Generation Warfare and other irregular methods for dealing with systemic threats to our well being and our security interests:

"Insurgents are living proof of why man is at the top of the food chain. We are the most creative, treacherous, loyal, aggressive and determined life form to yet evolve. Any nation that assumes it is inherently superior to another is setting itself up for disaster." Colonel Thomas X. Hammes, USMC

24 April 2010

FCPA: OPS Risk in Pharma & Small Business...

If you are a large U.S. based pharmaceutical company the odds are that over a third of your annual sales are overseas. Selling drugs in the EU, Asia and South America into the health care systems is a tremendous pipeline for Eli Lilly, Pfizer and others who find these markets hungry for their products. What kind of Operational Risks might exist for these firms and should be on "Red Alert" status with the General Counsel?

The DOJ is currently pursuing 120-130 FCPA investigations, and now it has set its sights on enforcement in the pharmaceutical industry where on an annual basis “close to $100 billion dollars, or roughly one-third, of total sales … [are] generated outside of the United States.” The DOJ’s new focus stems in part from the fact that many foreign health systems are regulated, operated and financed by government entities, and competition is intense, which creates more opportunities to “pay off foreign officials for the sake of profit,” and a perceived need for greater supervision from law enforcement.

The head of the Criminal Division of the United States Department of Justice (DOJ), Assistant Attorney General Lanny A. Breuer has indicated their interest in looking at this industry with increased scrutiny. So if you are a General Counsel at one of the companies in the cross-hairs of the government what are you doing about it?

First, you have to call together the right people and create your own internal FCPA Task Force within the enterprise. The General Counsels Office has the lead on bringing together four to six people from Sales & Marketing, Finance, Information Technology, and Internal Audit. This team will have the autonomy, funding and jurisdiction to work specifically on the vulnerabilities that exist on a global basis.

Second, you have to understand the culture, governments and the "Ground Truth" in each country you are selling your pharmaceuticals in, to map the processes and the people associated with the heath care systems, hospitals or the military that are the actual consumers of the medicines and drugs.

Finally, you have to educate your work force on the fact that pharmacists, doctors, lab technicians and other health care consultants may indeed be officials of the government of that country based upon who they work for. Why is this important?

The FCPA has a broad definition under the law that pertains to the foreign officials. In some countries it's entirely possible that if the medical institutions are owned by the government that almost everyone who works in these facilities could be considered under the FCPA. So what is the task force going to do to ensure that the company does not violate the law?

Beyond the focus on compliance and education of employees, there is much work to be done in the collection, analysis and actions within the enterprise of relevant information. Predictive analysis of data that is coming from the CRM, ERP and other open sources can provide the task force with the "Corporate Intelligence" and "Red Flag" warning to prevent a violation of the law. The ability of the company to utilize data collection and predictive analytics to not only head off any DOJ investigation also can be effective in providing voluntary disclosure to government.

Wait a minute. You mean, tell the government that we have identified a violation of the law and bring the wrath of the law and the possible impact on our corporate reputation? Yes and this is why.

Under Federal Sentencing Guidelines, those organizations that do a rigorous internal investigation and share the results with the government can avoid such sanctions as the mandate for a costly independent compliance monitor. Deferred prosecutions are not unheard of and the government can in some cases help you save money in terms of getting fines on the lower end of the sentencing guidelines.

The General Counsel's "Corporate Intelligence Unit" that is focused on the analytics of relevant data, combined with the education, awareness and compliance processes will be well on there way to keeping the legal risk and Operational Risk events associated with the Foreign Corrupt Practices Act (FCPA) from impacting their global pharmaceutical enterprises. And just when you think that the DOJ is only looking at the Fortune 500, then think again:

More focus on small and mid-sized companies: As part of their increased FCPA-related efforts, the DOJ and SEC are expected to look more at small and mid-sized firms which do business overseas. The majority of such companies have a small established compliance program, or none at all, yet some may conduct billions of dollars in foreign transactions.

Companies that are not household names have long believed that they were under law enforcement’s radar. Smaller firms have also thought that the DOJ would not expend the resources to investigate their overseas sales. That comfortable illusion no longer exists.

If you are a small disadvantaged supplier to a large Defense Industrial Base (DIB) company working on a sub-contract, then you too should be standing up your FCPA Task Force now:

On January 18, 2010 twenty-two business executives were arrested and over 100 FBI agents conducted related searches. These actions were based on sealed federal indictments handed down by a grand jury several weeks earlier, which in turn stemmed from a two-and-a-half year undercover operation. The indictments claimed that the defendants believed that they were involved in a scheme to acquire a US$15 million defense contract to outfit the presidential guard of an unnamed country. They allegedly agreed to pay a 20 percent bribe to a sales agent, supposedly representing the defense minister but really an undercover FBI officer. This was the first large-scale use of undercover law enforcement techniques to investigate Foreign Corrupt Practices Act (FCPA) violations.

21 April 2010

Operational Risks: Undercover Boss to the Rescue...

Operational Risk Management is becoming a more relevant topic these days in the Board Room. Does "John Q. Public" realize that these events are the result of "Operational Risk" incidents:

  • Fabrice Tourre, the Goldman Sachs Group Inc. banker at the center of fraud
  • No doubt, Gizmodo has turned the tech news cycle on its head this week with its exclusive on the iPhone 4G. Everybody from MSNBC to Good Morning America, and even the ladies on The View are talking about what is arguably the biggest leak in consumer technology history.
  • Twelve people were missing and seven critically injured after an explosion and fire at an oil-drilling rig in the Gulf of Mexico.
  • Airports across Europe began reopening Wednesday, six days after ash from an Icelandic volcano forced the shutdown of airspace and stranded thousands of passengers around the world.

Each quarter, Boards of Directors and Executive Management are becoming more concerned about the risk of loss resulting from inadequate or failed processes, people and systems or from external events. Operational Risk includes the exposure to litigation from all aspects of an institution’s activities.

Operational risk is not new yet it is being talked about in a whole different context these days. At it's origin in the financial services industry the focus and discipline fell into the categories that market risk and credit risk did not substantially address. Today, Operational Risk Management is a core discipline that spans the flight decks of naval aircraft carriers to the halls of corporate enterprises as they study the latest plaintiff litigation matter that just arrived by courier.

In the past six plus years that we have been blogging on this subject and becoming more of a subject matter expert each day the clarity of effective operational risk management improves. To understand the interdependent attributes of a "Credit Default Swap", the details of a sophisticated transnational eCrime syndicate or the exposure to the loss of life from workplace violence or acts of mother nature requires a sound framework, methodology and systems thinking approach.

In many incidents the after action reporting, lessons learned and the investigative report find that human behavior was a factor in the failure. When earthquakes hit or volcanoes erupt the question set focuses on resilience and preparedness because these are events that we can't predict yet know will occur.

It is with great amazement that still to this day the corporate enterprise is deluged with the amount of human perpetuated fraud incidents that could be mitigated with the proper controls, awareness building and training sessions. Whether it be the insider who has embezzled from the accounts payable supervisor position or the external ID Theft non-state actors who have targeted your institution for ACH cyber bank thefts the fact remains that people's behavior is the culprit in the operational risk incident.

Regardless if you are a small business owner or the CEO of Goldman Sachs you can be sure that "Operational Risks" are present in your organization. Even the likes of companies in the US such as Walmart have recognized the impact of a robust OPS Risk program that spans the front office to the logistics and transportation departments. Understanding the risks themselves however is only a very small part of the equation. Realizing and exploring the interdependent relationships between assets and entities will remain the most unsolved challenge.

In light of the recent US over haul of the financial industry to abate future operational risks and the legislation pending to increase the oversight and compliance mechanisms, one can only wonder what will change? Hopefully the law will compel the CEO's to become a participant in the latest CBS series "Undercover Boss."

Michael Corkery at WSJ has a great idea:

With news that the reality show “Undercover Boss” is coming to Wall Street, Deal Journal couldn’t help but suggest some plot lines.

The CBS show features CEOs going “undercover” at their own companies and working along side their every day employees. The first episode involved a top executive of Waste Management disguising himself as a blue collar worker.

What is the Wall Street equivalent of a hauling trash or cleaning out porta potties? We thought we’d run down the list of possible roles for the various CEOs, starting with JP Morgan’s Jamie Dimon.

Dimon has been joining other big bankers in pushing back on calls to modify mortgages of underwater home owners. Well, it might make for good TV watching Dimon man the phone lines at a JP Morgan call center, fielding calls from some of those borrowers. How would the CEO who Forbes magazine recently dubbed “Master Banker, Master Schmoozer” stack up against that unemployed family, looking for a principal reduction on their Option ARM mortgage?

How about Lloyd Blankfein, of Goldman Sachs? We suggest he spend some time with the programmers who run the firm’s super computers, which are driving a good deal of Goldman’s profit machine. Blankfein might just meet the firm’s next CEO. Hello Hal.

22 March 2010

Legal Risk: Forensic Intel for Investigations...

A wide spectrum of Operational Risk incidents are in the news. Executive Management in the private sector, law enforcement and the military are investigating cases of identity fraud, cyber hacking and insider digital sabotage, transnational economic crime, intellectual property theft, ACH cyber robbery, counterfeiting, workplace violence and industrial espionage. Government agencies and regulatory authorities are increasing oversight, compliance and reporting requirements with the private sector and federal contractors. Inspector Generals and Internal Affairs are addressing whistleblower claims and internal corruption. Homeland security and "Connecting the Dots" are on almost every Americans mind.

All of these Operational Risk Management (ORM) challenges require comprehensive, efficient and legally compliant intelligence-led investigations to establish the ground truth and then to enable a "DecisionAdvantage." The legal framework that establishes your organizations ability to provide a "Duty to Care", "Duty to Warn", "Duty to Act" and "Duty to Supervise" is imperative.

When does information that is collected become a violation of a persons privacy or legal rights? At the point it is collected from a source or how and when it is analyzed by a human? These questions and more will be discussed as the dialogue pursues the latest challenges in Forensic Intelligence, a fast and forensically sound data acquisition, analysis and review solution for front line officers from the corporate investigations, law enforcement and government communities.

These Intelligence-led investigations also leverage the use of new forensically sound methods and proven legal procedures for collection of digital data from a myriad of technology platforms including laptops, PDA's and cell phones and more. These methods have been tested and certified in the forensic sciences for decades and follow many of the legally bound and court tested rules associated with evidence collection, preservation and presentation. Digital Forensic tools and 21st century capabilities enable global enterprises, law enforcement and governments to not only discover what they are looking for and when to use this in a court of law to find the truth.


08 March 2010

Quants: Fear and Loathing in Computer Code...

The Operational and Systemic risk is still lurking in the zero's and one's masking itself in the mathematical blur of algorithms designed by the "Quants". Is "SkyNet" just a few lines of computer code away from creating an incident that no insider can reverse?

Jeremy Grant and Michael Mackenzie of FT are establishing an argument discussed on this blog soon after the economic meltdown began to take place:

Not long after lunchtime one day on the New York Stock Exchange three years ago, unusual things started to happen. Hundreds of thousands of “buy” and “sell” messages began flooding in, signalling for orders to be made and simultaneously cancelled.

The volume of messages sent in was so large that the traffic coming into the NYSE from thousands of other trading firms slowed, acting as a drag on the trading of 975 shares on the board.

The case was made public only last month when the disciplinary board of the NYSE fined Credit Suisse for failing adequately to supervise an “algorithm” developed and run by its proprietary trading arm – the desk that trades using the bank’s own money rather than clients’ funds.

Algorithms have become a common feature of trading, not only in shares but in derivatives such as options and futures. Essentially software programs, they decide when, how and where to trade certain financial instruments without the need for any human intervention. But in the Credit Suisse case the NYSE found that the incoming messages referred to orders that, although previously generated by the algorithm, were never actually sent “due to an unforeseen programming issue”.

It was a close call for the NYSE. Asked if the exchange could have been shut down as it was bombarded with false trades, an exchange official says: “If you had multiplied this many times you’d have had a problem on your hands.”


The Operational Risks associated with the software computer code and the development of the trading algorithms is at the center of the still untouched regulation of how financial products are designed. Once the SEC get's educated on a market practice that is creating substantial systemic risk then the wheels of monitoring and potential "Cramdown" begins to take place.


The difficulty is that responsibility for risk controls does not lie entirely with exchanges and trading platforms. Much of it rests instead with brokers, which increasingly provide access to such venues under an arrangement known as “sponsored access” whereby any trading firm that is not a member of an exchange can “piggyback” on a broker’s membership to gain direct access to an exchange. Until recently, before the SEC clamped down on the practice, traders were able to use a form of this process – “naked access” – to gain access to exchanges without brokers conducting pre-trade risk checks to ensure their algorithms were functioning properly.


In the latest books written by "Reporters" on the so called "Quant risk" going on within the ranks of trading firms across the globe, the focus is on the people themselves more than the systems. Comparing poker players to bridge players is only a small part of the issue at hand with regard to a quantitative traders point of view and mathematical orientation.

Imagine for a moment the complexity of the software systems that now control the trading mechanisms across the world. From Hong Kong to Wall Street, London to Tokyo, the software is written to accomplish tasks that the human is not capable of executing in the multi-split seconds that it takes for buyers to match sellers. One only has to spend a few weeks or a month inside the software coding life cycle management process within the walls of a JP Morgan, Goldman Sachs or Credit Suisse to better understand the Operational Risks that exist for the market as a whole.

The sheer complexity of the systems software code alone is enough to give an uneducated eTrader worry over whether the portfolio they are managing with their retirement nest egg is going to get destroyed by the likes a a super "Cyber Algorithm" designed to out smart and out think that last strategy from the previous nights episode of MSNBC's "Jim Kramer."

The next economic crisis will not be a war of who had toxic assets in their asset portfolio's. It will be a single line of computer code that initiated a sequence of risk mitigation strategies to hedge against another previously executed trade the month before. And because of the error that creates this cyber incident, the market detects a new "Fear Factor" on the horizon.

How about a little Deja Vu:

All of us have been watching the gyrations of Wall Street and the stock market in recent days. With the collapse of Bear Stearns and Lehman, the "rescue" of the failing Fannie Mae-Freddie Mac, and the bail-out of AIG, many people wonder, "Have investors completely lost their minds?" Well, the answer may be, "Sometimes". Here's how we might look at anxious investing during a time of market volatility, uncertainty, bad news, and fear.

How does the anxious investor think? Let's consider two possible investors--- one who is reasonably optimistic and the other who is pessimistic.

02 March 2010

ID Risk Management: Dubai Investigation Links to Workplace Violence...

What is your name? Where do you live? What is your phone number? Where were you born? What is your social security number? What is your passport number? Where was it issued? What evidence do you have that this is all true? Your identity is at stake and Operational Risk Management is on the line.

These questions and more are asked of us on a regular basis to establish our true identity. The entity asking these questions is considering you to be granted access, access to what? It could be to establish an account at a banking institution, get a drivers license or become a member of a trusted community of people. Or it could be a country deciding whether to grant you a visa to visit or work for a period of time.

SOCA is in the midst of interviewing people who had their identity stolen. This investigation is about a form of ID Theft that goes beyond the international scandal associated with the Dubai homicide incident. The Washington Post reports:

Agents from Britain's Serious Organized Crime Agency are in Israel investigating the use of forged British passports by people who Dubai officials allege were part of an assassination squad run by Israel's Mossad spy agency. The 27 members of the group used European or Australian passports -- some forged -- to enter Dubai, officials say. In several cases, the names and other information on the passports matched those of Israeli citizens who hold dual nationality and who claim that their identities were "borrowed" by those involved in the operation.

Two SOCA agents will interview the 10 British-Israelis who were affected and issue them new passports, a British Embassy spokesman said. According to Israeli news reports, Australian investigators are planning a similar visit. The European Union last week condemned the use of forged travel documents in the killing of Hamas commander Mahmoud al-Mabhouh, without mentioning Israel specifically.


Whether you are the UAE, admitting people into your country or a Global 500 company allowing someone access to your corporate facilities, digital assets or place of business; you must have ways to effectively validate who people say they are, and who they really are. Even if you asked all of the questions above in the early stages of the company hiring process, would you really have the entire picture? This changes over time and events in a persons life. Identity Management and the use of both "known to many" and "known to few" attributes about who you are and who you know, is a reality in today's blur of global commerce.

When a country has a breach of security admitting people, who are not who they purport to be, is it any different in the context of a Defense Industrial Base company headquartered in Chicago, IL or an Investment Banking firm in Geneva, Suisse? What are different are the motives and the outcomes from the fraudulent acts.

What are the current arguments and the leading reasons why our policies, methods and tools associated with Identity Management are in a state of chaos in the United States? The FTC's latest report gives you a better idea of the breadth of the privacy problem trying to be solved:


The Federal Trade Commission released a report listing top complaints consumers filed with the agency in 2009. It shows that while identity theft remains the top complaint category, identity theft complaints declined 5 percentage points from 2008.

The report breaks out complaint data on a state-by-state basis and also contains data about the 50 metropolitan areas reporting the highest per capita incidence of fraud and other complaints. In addition, the 50 metropolitan areas reporting the highest incidence of identity theft are noted.

The top complaint was Identity Theft, which accounted for 21% of all complaints for the year.

A complete list of complaints can be found at: http://www.ftc.gov/sentinel/reports/sentinel-annual-reports/sentinel-cy2009.pdf.


What is interesting is that the same people who are coming to work every day with their TWIC or CAC cards are also victims of ID Theft as consumers. The same individuals who walk into the SCIF or the bank vault may very well be people who have active investigations going on regarding their identity being used to perpetrate crimes or other fraudulent motivations. So what are some of the most important issues on the Identity Management horizon?

In all of the breaches, all of the incidents there is a root cause for the failure in the people, process, systems or external factor that opened up the vulnerability for the attacker to exploit and obtain their objective. It's called Continuous Monitoring. This issue is found in all places in Appendix G of the US NIST sp800-37 that illustrates the reason why continuous monitoring is critical especially in information systems:

Private Sector companies have a duty to invest in resources, policy refinement and new methods or tools to keep continuous monitoring as vigilant as possible:

"Conducting a thorough point-in-time assessment of the deployed security controls is a necessary but not sufficient condition to demonstrate security due diligence. A well designed and well-managed continuous monitoring program can effectively transform an otherwise static security control assessment and risk determination process into a dynamic process that provides essential, near real-time security status-related information to organizational officials in order to take appropriate risk mitigation actions and make cost-effective, risk-based decisions regarding the operation"


Whether you are the United Arab Emirates or the University of Alabama-Huntsville the Identity Management problem is much the same. David Swink at Psychology Today has this to say on the other growing virus named "Workplace Violence" that is invading corporate America:


In the aftermath of school and workplace attacks, it is often discovered that there were warning signs that the perpetrator was moving down a path toward violence. In some circumstances, people reported the troubling behavior and the information was not forwarded to the people who could prevent an attack. Sometimes the troubling behavior didn't reach a threshold, in the judgment of the person receiving the report, that something needed to be done. There is often confusion about what information can or cannot be shared under privacy laws like FERPA or HIPPA.

Threatening behavior may come to the attention of multiple departments within an organization that generally don't share information with each other. Without clear policies, procedures, and training, large organizations may find it challenging to channel widely dispersed information about potential threats to a central reporting entity.

With a single report of threatening behavior, the situation may not look that bad, but when the other "dots" are connected, a clear image emerges that this person is someone that needs to be assessed and managed in order to prevent violence.


Much of what we know about our employees is found in their HR files, background reports (if ever done) and what co-workers say about their behaviors in the workplace. Corporate Security, Risk Management, General Counsel, Information Technology, Public Relations and even the EAP (Employee Assistance Program) executive managers shall create, maintain and continuously operate a Corporate Intelligence Unit and Threat Assessment Team. Without it, the consequences of not knowing a persons true identity or current state of mind could cost you more than the loss of life. It could cost you your global reputation.