01 September 2018

Trusted Leaders: This I Believe...

In 2018 our global challenges are in many ways, no different than years or centuries past.  Leadership across nation states and even now our private sector companies, that have revenues larger than some countries, are in conflict.

People across our world, now have the technological ability in the palm of their hands, to express their thoughts to millions, almost instantaneously.

During John McCain's celebration of life service today in Washington, D.C., there were many gathered to pay tribute to one of our countries greatest leaders.  Remembering his life and his military journey through a life of leadership, these words from his own "This I Believe Essay" and today's experience shall stay with us forever:
"Years later, I saw an example of honor in the most surprising of places. As a scared American prisoner of war in Vietnam, I was tied in torture ropes by my tormentors and left alone in an empty room to suffer through the night. Later in the evening, a guard I had never spoken to entered the room and silently loosened the ropes to relieve my suffering. Just before morning, that same guard came back and re-tightened the ropes before his less humanitarian comrades returned. He never said a word to me.
Some months later on a Christmas morning, as I stood alone in the prison courtyard, that same guard walked up to me and stood next to me for a few moments. Then with his sandal, the guard drew a cross in the dirt. We stood wordlessly there for a minute or two, venerating the cross, until the guard rubbed it out and walked away."
What do you believe in?  Is it possible that your ability to be a leader in life, has much to do with your own belief system?

Many leaders would say that their beacon in life, is burning bright and it is so obvious what direction to follow.  Others are lost, without a way to find the path to leadership, as their tools for navigation become broken or outdated.

The truth is, that John McCain never lost sight of what leadership is really all about.  He maintained his skills around how to navigate a path in life, that would always make a difference to others.  You see, a true leader never loses faith, or the continuous pursuit of what they really believe in.

You have met people in your life who you would call a leader.  Maybe they had some of the same traits and a belief system, that you could identify with.  Maybe the first time you met them in person, you walked away saying to yourself, "Wow__that is someone that I could follow or I wish we had more time to get to know each other."

Our world if full of potential leaders, who shall never find their entire ability to make a difference in life.  Why?

The debate might start with a discussion about a person's upbringing, where they were born or how their parent(s) nurtured them.  Yet science and research has studied this for decades if not more and it will be continued, for the foreseeable future.  Why one person becomes a leader and another does not, is an interesting dialogue to have with someone, you trust.

When you make a decision to trust, remarkable results are possible.  "TrustDecisions" are a purposeful act, to engage in the very rules you have adopted in your life.  To stand by those rights, wrongs and the spirit of your life beliefs, that have guided you during your trust decisions.  And more.

Leadership and John McCain are synonymous, alike in meaning or significance.  What if?

What if our children, now were asked to study the life of John McCain, as history has asked them to study others?  Our United States founding fathers or other leaders across the world, who are now in our history books.

Just as John McCain, your life journey begins with "This I Believe."  Your decisions to trust will follow from there.  Godspeed Senator McCain!

25 August 2018

Homeland Resilience: Operational Risks in the Supply Chain...

The U.S. Homeland Security Intelligence (HSI) priorities, are good indicators of what the private sector can expect for government intelligence focus, coordination, cooperation and collaboration.

Operational Risks to business operations in the United States, are ever more so complex and increasingly tied to the supply chain security of the Homeland.

In many cases, the private sector has the answers, that can pave the way for improved relevancy and accuracy of information for the government. This translates to greater Operational Risk Management (ORM) insight, that would not previously be known.

It also enhances the clarity of the insights already known, by our Homeland Security Intelligence mechanisms.

Here are a few of the top of mind categories, that the Private Sector and the Public Sector could be forging new partnerships and strategies together:
  • Global Maritime Shipping
  • International Banking & Finance
  • New and Developing E-Commerce & Artificial Intelligence Technologies
  • Application and Use of Social Media - Charting Cultural Topography
  • Modeling Human Behavior - Patterns and Applications of Usage
  • Nanotechnology
  • Robotics and Automation - New and Developing Technologies and Uses
Why should the private sector be working on these and sharing what they know with the appropriate channels in the U.S. Government? For one, to reduce your own Operational Risks, as you run your business operations across the country and as you operate on a more global basis. Overall, Homeland Security is reliant on a Resilient "Global Supply Chain".

International trade has been and continues to be a powerful engine of United States and global economic growth. In recent years, communications technology advances and trade barrier and production cost reductions have contributed to global capital market expansion and new economic opportunity. The global supply chain system that supports this trade is essential to the United States’ economy and is a critical global asset.

Through the National Strategy for Global Supply Chain Security (the Strategy), we articulate the United States Government’s policy to strengthen the global supply chain, in order to protect the welfare and interests of the American people and secure our Nation’s economic prosperity.


Our focus in this Strategy, is the worldwide network of transportation, postal, and shipping pathways, assets, and infrastructures by which goods are moved from the point of manufacture until they reach an end consumer, as well as supporting communications infrastructure and systems. The Strategy includes two goals:

Goal 1: Promote the Efficient and Secure Movement of Goods – The first goal of the Strategy is to promote the timely, efficient flow of legitimate commerce while protecting and securing the supply chain from exploitation, and reducing its vulnerability to disruption.

Goal 2: Foster a Resilient Supply Chain – The second goal of the Strategy is to foster a global supply chain system that is prepared for, and can withstand, evolving threats and hazards and can recover rapidly from disruptions.


One of the vital linchpins for these goals to occur, will be a converged and globally accepted management system for supply chain resilience. This blog has discussed ISO 28000 in the past and the U.S. White House has published the policy direction for this and is a private sector imperative:
ISO 28002 Standard for Resilience in the Supply Chain

ISO 28002:2011 specifies requirements for a resilience management system in the supply chain to enable an organization to develop and implement policies, objectives, and programs, taking into account legal, regulatory and other requirements to which the organization subscribes; information about significant risks, hazards and threats that may have consequences to the organization, its stakeholders, and on its supply chain; protection of its assets and processes; and management of disruptive incidents.
For those private sector organizations that are for some reason not familiar with the ISO 28002, you should be.

It is the path towards creating a more resilient private sector, that will have the lions share of responsibility for keeping the supply chain operating after any significant disruption, whether physical, cyber or both.

So what?  So what does all of this mean for the Operational Risk Management Professional of a U.S. business today?

It means that you have to take it up a notch. Gather the heads of your risk silos from Finance, Information Technology, Corporate Security, Human Resources and your Crisis or Continuity of Operations section.

Look at ISO 28002 as a team and begin the process of digesting what it means to your organization.

How could you internalize and even operationally collaborate to increase your level of resilience from 36 hours to 72 hours?  The clock is ticking...

19 August 2018

Information Threat: Battle for Superiority...

What continues to be the greatest economic threat to your organization? Is it "Internal" or "External" to your institution? Could it be both?

Insiders rarely work alone and therefore the nexus with some outside influence, whether it be a person, life factors or some other entity are typically in play.

Is an engineer in R&D copying precious intellectual property information from within the enterprise company, that could be worth hundreds of thousands or even millions to the highest competitive global bidder? Could your small business have an accounting supervisor that has been diverting funds to a private bank account for the past two years?

Would it be possible that a supplier or 3rd party partner is capable of inflating the number of billable hours on a project?

Whether it's IP Theft, Fraud or other white collar corporate malfeasance, these Operational Risks are real and growing at a double-digit percentage rate annually. The greatest economic threat to your organization could be complacency or an apathetic staff, who works without adequate resources and little communication with the Executive "Powerbase".

The compliance and oversight mechanism's are in full swing from the federal governments around the world as highly regulated critical infrastructure organizations are implicated in a myriad of corruption, scandal, ethics and criminal matters.

Litigation is an Operational Risk that many organizations have realized the necessity for more robust internal teams to address the continuous requests for information from the government.

There is one common denominator across all of the insider threats, external forces and other vectors that seem to be attacking our institutions night and day. That common denominator is "Information".

And underlying this is the data and meta data that all to often ends up being the key or clue to finding the "Smoking Gun" and the source or person(s) associated with the scheme or attack on the organization.

Managing information in a mobile and interconnected planet is a major issue in any global company. Providing the tools and the right information faster and more accurately than the competition can be the difference in your own survival on the corporate battlefield.

So how does the CxO suite even begin to address the risks, opportunities and resilience in our demanding "Information-centric" environment?

They believe in having a strong culture of ethics, training and continuous monitoring of employees, systems and their supply chain. They understand the importance of providing the vital resources to the people on the front line of risk management and to make sure that their early warning systems and methods are not compromised.

This breed of CxO's are the new breed of organizational management, that are leveraging information to their most significant advantage:
Whether you are trading in a marketplace, analyzing assets on a map or manufacturing widgets and selling them to qualified buyers, operational risk management begins and ends with information. Managing that information effectively and more accurately than your competition is the name of the game. What have you done today to insure your survivability in the face of the next crisis?

05 August 2018

Supply Chain: Interdependencies Risk...

In the U.S., it is now less than 30 days away from the next cyclone season.  One thing is for sure. You are in complete control of your readiness factor.

In what countries do you operate? Do you source raw materials from politically unstable regions of the globe for your end products? Are you subject to a myriad of taxes, tariffs and duties including new security measures in our ports? How complex are your sales and distribution channels?

At the end of the day. the big question is: What is my financial, operational and economic risk exposure in the event of a disruption in our external supply-chain?

The risk of external supply-chain interdependencies has been talked about for many years. Monte Carlo simulations, scenario analysis and other methods have been effective in the determination of what the magnitude of a loss event may look like. Once the dollar analysis is done and you know that your exposure is $XXM. or $XB., then what do you do with that information?

Much of the outcome of this exercise may go into the next strategic planning phase on who you need to partner with or create an alliance with in order to satisfy certain future contingencies. Once you realize that you need more than one source for a raw material or a key service to run your business, then the real analysis begins. Who and where do I find the best alternatives for this vital component in my global supply-chain?

If you begin your due diligence now on the top 10 vital components in your supply-chain contingency planning exercise, you might have these all completed, through the legal department and signed within a few months time. If you are lucky. Then you must really test the new supplier or source for your product or service to determine how smooth they operate when you pick up the phone or send the "Alert".

The ultimate architecture requires an "Adaptive Supply-Chain" that will provide cross-border agreements and resilient mutual-aid partners to assist in times of crisis. Just shifting production from one country to another may not be enough to mitigate the disruption in a vital component of the manufacturing process or delivery of services.

Having a reflexive and responsive supply-chain is only one of many contingencies in a robust Business Crisis and Continuity Management plan.

When was the last time you reviewed your key suppliers and sourcers plans for continuous operations and their record for testing these plans? This will be the place you find your greatest weakness in external supply-chain management.

And your readiness factor, is directly proportional to your interdependencies in your supply-chain.

28 July 2018

Certainty: Solutions for an Unpredictable World...

As the moon rises on a distant horizon, vital leaders across our globe are gaining new strategic foresight to continuously adapt their enterprise.

The future horizons in the mid-2000's are now on their mind and for good reason.  All of us are operating at increasing speed, in an unpredictable world:
What is the certainty that the Operational Risks in the next 20 years, will be a replay of the variety and spectrum of loss events we have witnessed in the past 18 years.  The difference is that they are accelerating.  What have we learned?  What are we doing about it?  How are we changing?  Why?

Solutions for resilience in motion in our "Unpredictable World" span the domains of people, processes, systems and external events.  Operational Risk Management (ORM) is a discipline that can be applied in most any size enterprise including government.

When you are seated around the meeting room with your leadership team, what do you see?  People who are in charge of teams, business units, departments, subsidiaries, portfolio investments and other assets of the enterprise.  You are counting on them to be prepared, to be predictive and to be proactive.  Are they?

You see, after all of the lessons learned and the After Action Reports (AAR) have been written and published, it seems to come back to the fundamentals.  It is history repeating itself.  Will our future world continue to be unpredictable?

If you said yes, then what are you doing about it?  Let's go back to that group of leaders sitting around the conference table.  Who have they engaged outside your enterprise to back them up to help them be more prepared, predictive and proactive?

The truth is, that you are behind the solutions curve.  Even your simple, yet effective Business Continuity Plan is outdated and gathering dust on the bookshelf.  The crisis team is far too preoccupied with the next news story or "Tweet," that may have an impact on the stock price.
The truth is, our unpredictable world is actually certain and we only have a limited amount of time until the next crisis, to prepare and adapt...

21 July 2018

Remember His Name: The Long War Ahead...

"Edward Wilson believed in America, and he would sacrifice everything he loved to protect it."

In "The Good Shepard" Matt Damon's character, Edward Wilson, is partly based upon the founder of the CIA's counterintelligence operations, James Jesus Angelton. As we look back over the past year, one can only wonder what Mr. Angelton would have to say, if he were alive today.

This September 11, 2018, brings all kinds of thoughts and emotions thinking about what our world has become since the days after World War II. Edward Wilson and Jim Angelton were both focused on the risks of finding out the truth.

Getting answers to questions that few others would even contemplate to ask. For the love of their country alone.

We are reminded of other professionals with the same mission. On September 11th, 2006 on the cover of Sports Illustrated Magazine, sits another patriot in a tree near the Afghanistan-Pakistan border. His name is Pat Tillman.

And as the SI cover story title says: "Remember His Name." Journalist Gary Smith captures the essence of what it means to walk in the shoes of men like Pat Tillman, who seek answers even more than life itself.
Everybody who thought he'd enlisted purely out of patriotism, they missed reality by a half mile. Sure, he loved America and felt compelled to fight for it after more than 2,600 people at the World Trade Center were turned to dust. But his decision sprang from soil so much richer than that. The foisting of all the dirty work onto people less fortunate than an NFL safety clawed at his ethics.
He had uncles and grandfathers on both sides who'd fought in World War II and the Korean War, one who'd taken a bullet in his chest, another who'd lost a finger and one who'd been the last to leap out of a plane shot from the sky. On a level deeper than almost any other American, he'd reaped the reward of those sacrifices: the chance his country afforded him to be himself, all of himself.

He yearned to have a voice one day that would carry, possibly in politics, and he was far from the sort of man who could send others into a fire that he had skirted. His relentless curiosity, his determination to live his life as if it were a book that would hold its reader to the last word, pushed him into the flames as well. The history of man is war, he told a family member, so how, without sampling it, could he ever know man or himself completely?
The Operational Risks we choose to face as professionals, keeps us focused on the fears that haunt us most. Someday, we hope that the fear will disappear, if we face it long enough and often enough. And then it dawns on us, that this will never happen. The "Long War" ahead will not have an end point.

Nor will it's end, ever be celebrated with a ticker tape parade in New York City.

The long war ahead, requires leaders who understand what Jim Angleton and Pat Tillman both have in common. It begins with a renewed hope for conquering the fears ahead...

15 July 2018

Enterprise Risk: The Future of Public Private Partnerships...

When it comes to the overall Business Resilience in a city or geographic region, there are a plethora of Public Private Partnerships that have been in development for decades between government entities and the private sector.

The goal for some, is the simple exchange of information on relevant topics of community and local or federal jurisdictions. Others have a very distinct role and measurable outcomes designed into their structure, to achieve a mutual purpose. The Houston Ship Channel Security District is a rare example:
The Houston Ship Channel Security District, a unique public-private partnership, improves security and safety for facilities, employees and communities surrounding the Houston Ship Channel.
There are other Public Private Partnerships (PPP) that help address the safety and security of the United States, including the FBI's InfraGard program. This is an approach to engaging with private and public sector individuals in a region or sector of critical infrastructure, as opposed to a specific business entity.

The combination of an individual-based intelligence sharing organization of subject matter experts, combined with a more business owner-operator and city, county and state governments model, is one that needs continuous care and oversight to remain effective.

There are hundreds of other local and national models that converge on the goal of a true public private partnership, that never achieve excellence. They continuously miss the mark from several levels of information exchange, coordination, cooperation and collaboration.

These failed attempts at getting the private sector working in concert with government, still comes back to one key criteria for success; people. Regardless of whether you have the funding resources or not, a single or handful of motivated, dedicated and smart people, can and will make the relationship work.

Simultaneously, people can also be the roadblock, the resistance or the problem in getting a public private partnership working as effectively as it could be, to achieve the mission. This is when the mechanisms of governance, oversight and common sense are needed to guide the respective initiatives and operations of the entity either public or private, in the right direction.

You only have to look at the leadership in many cases to understand why there is continuing success in achieving SMART objectives or why there is failure. Service before self-interest is what becomes a major facet of why many of these organizations perish and then you have to examine who is really the beneficiary of the work being done by these dedicated volunteers.

Another effective public private example is the Intelligence National Security Alliance (INSA):
"INSA provides a nonpartisan forum for collaboration among the public, private, and academic sectors of the intelligence and national security communities that bring together committed experts in and out of government to identify, develop, and promote practical and creative solutions to national security problems."
When you are able to converge the thought leaders from a particular vertical discussion area, to produce the best thinking on an Operational Risk topic, the output is extraordinary. The key is to keep these same set of thought leaders together long enough and often enough, for the trust factors to build and for the true sense of collaboration to emerge.

INSA has accomplished this with the "Homeland Security Intelligence Council". Formed in 2010 and now renamed the "Domestic Security Council" and working continuously on a monthly and even bi-weekly basis, they have produced several valuable outcomes from their work together. One example is the white paper produced soon before the tenth and also the fifteenth anniversary event of 9/11.

Homeland Security Intelligence is a discipline that depends on the successful fusion of foreign and domestic intelligence to produce the kind of actionable intelligence necessary to protect the homeland. INSA is one private private organization that realizes this more than others.
The key to public private partnerships in the U.S., the "Enterprise" is not just government when it comes to intelligence and situational awareness. One only has to look at the number of iPhones and camera enabled devices being carried around by hundreds of millions of people to understand this today. Social Media and global real-time information discovery will remain our continuous situational awareness challenge.

The private sector companies, who in many cases are the owners of critical infrastructure assets in the nation remain the power base. The willingness or reluctance to share the right information at the most appropriate time from government and combine it with private sector capabilities, will always be the largest challenge for the public private enterprise going forward.

08 July 2018

ORM: The Science & The Art...

Operational Risk Management today is a true "science", with the "art" becoming more of a key component in connecting the dots. Yes there are plenty of standards from various disciplines to assist professionals in the assessment and measurement of risk.

The tools that have been developed over decades to help predict risk, dates back to the insurance industries inception. Actuaries are indeed a key component in this evolution of the science. What happens when you put several other factors into the equation? Like dates in time when various events are converging on a single window of potential risk consequences and implications:
Actuaries are those with a deep understanding of financial security systems, their reasons for being, their complexity, their mathematics, and the way they work (Trowbridge 1989, p. 7). They evaluate the likelihood of events and quantify the contingent outcomes in order to minimize losses, both emotional and financial, associated with uncertain undesirable events.

Actuarial science
applies mathematical and statistical methods to finance and insurance, particularly to risk assessment. Actuaries are professionals who are qualified in this field through examinations and experience.

Actuarial science includes a number of interrelating disciplines, including probability and statistics, finance, and economics. Historically, actuarial science used deterministic models in the construction of tables and premiums. The science has gone through revolutionary changes during the last 30 years due to the proliferation of high speed computers and the synergy of stochastic actuarial models with modern financial theory (Frees 1990).
The art of Operational Risk comes into play with practitioners and professionals who have the "Grey Matter" to see the big picture. They have the ability to think like the enemy, or examine the window of opportunity. Working with windows in time and the ability to see the convergence of particular events, allows for the creation of scenarios, to draw more strategic insight.

This ability to create filters and extract true meaning from raw data, segmented information and then from cognitive analysis creates the true vision we seek. This is an "Art" as much as it is a "Science".

Forecasters in the hurricane, typhoon and tsunami warning centers around the globe know the meaning of using the science as much as the art of risk management. The nexus of security and terrorism puts another dimension on the meaning of operational risk management and now you have the Terrorism Screening Center (TSC) assisting with the fusion of intelligence to counter potential individuals from terrorist acts.

If you were planning an event for your organization in downtown Washington, DC for the 3rd week in July 2018, what are the factors that are taken into consideration? Have you scheduled to fly in all of your key executives for a Board of Directors Meeting and a round of golf at RTJ?

What about all of the other events and organizers who have made the decision to hold their event the same week or day in July? What impact will any of these other events have on you and your organizations ability to facilitate a safe, secure and productive meeting for your participants, members or customers?

The truth is, that many event planners and organizers are not even tied into the same database or the systems as the Chief Security Officer. The CSO in many cases is not aware that the sales or marketing organization has scheduled a customer summit or new product kick-off the same time as a scheduled anti-[insert activist group here] march. Or maybe it's just a PGA golf tournament.

So what? So what does the "science" of operational risk have to do with the "art" of operational risk?


Think clearly and use both when it comes time to develop your own "Fusion Center" for risk in your organization. Make sure you include the people and the data that could create the perfect storm when a combination of events all take place within the same time window. There are only so many hotels, convention centers and airports for people to utilize for the logistics of these meetings.

The competition is fierce to get the location, dates and venues you seek to impress your audience. It's not always about the number of things going on at the same time, it is the combination of each unique entity that makes the "Art" of Operational Risk imperative.

Any combination of ingredients by itself can be harmless. But when you mix them together in the right amounts, in the right place, you could be facing a loss event that could not have been predicted looking at the science alone...

01 July 2018

4th of July: Risk of Complacency...

This new nation state is turning 242 years old on July 4th, 2018. The United States of America will be celebrating another birthday and the Republic, will reflect on what we have learned, so far.

"Rule of Law" is an ever so powerful component of a democratic way of life and is the envy of so many nations who still seek its most true form. Operational Risk Management permeates the essence of the laws and rights of U.S. citizens in the work place, companies and organizations in global commerce and the government who provides oversight on all of it.

The balance of power between individual citizens and the government responsible for the protection of life, liberty and the pursuit of happiness is always in flux. Yet in the end, "The Union" has endured some of the most significant "Operational Risks" and disruptions one can imagine.

It is the analysis of "The Union" and the incredible resilience of all the moving parts that make the United States what it is today. Weathering the storms of mother nature by hurricanes, tornados, earthquakes and droughts to the economic threats of depression, mortgage or Wall Street implosion has not put a dent in "The Union's" ability to bounce back.

Withstanding the challenges to our Constitution and the rights proclaimed to each and every citizen, has only made us stronger. What cases to the Supreme Court have changed our future?

When you look at your own organization and examine the components of your people, processes, systems and potential external events, does it have what it takes to endure 242 years? Certainly there are risks that exist today that are prevalent in the eyes of shareholders, Board Members and even executive management.

The question really is "What are you doing about it?" This in itself, could be the biggest threat to the United States and your own organization. Complacency.

complacency

[kuh m-pley-suh n-see]
  1. a feeling of quiet pleasure or security, often while unaware of some potential danger, defect, or the like; self-satisfaction or smug satisfaction with an existing situation, condition.
It is the perception of the quiet pleasure or security of your organization or your own country, that may very well be the greatest threat to it's existence. Ignoring the cues and clues to the deterioration of the balance of power, the rule of law and the economic engine necessary to sustain the necessities of life, such as food, water and cash flow may be the reason for your demise.

Your own business resilience will continue to be a factor of the correct mixture of the ingredients that sustain and organically grow the enterprise. Those who try to grow to quickly without regard to quality will in many cases fail.

Those who let the power base become significantly imbalanced, so too will find the ability to endure a tremendous hardship. Those who ignore the constant requirement for monitoring and governance will suffer the realities of human factors. Motivations that are often defined as greed, jealousy and hate, soon will emerge.
"Relationships remain vital to our family unit, the neighborhood we live in and the cities, counties and states that oversee our way of life."
It is those same relationships within our business and government ecosystems, that will determine whether they perpetuate your healthy growth, or its inevitable deterioration.
 
Those same family units, neighborhoods, and government jurisdictions have the power and the ability to avoid complacency and mitigate the Operational Risks that will be present in each. Look around the country of the United States or the nations of the world and you will see who has been complacent, and who has been the most effective in OPS Risk Management.

"I pledge allegiance to the flag of the United States of America, and to the republic for which it stands, one nation under God, indivisible, with liberty and justice for all."

The flag consists of 13 alternating red and white stripes that represent the 13 original colonies, and 50 white stars on a blue field, with each star representing a state. The colors on the flag represent:
  • Red: valor and bravery
  • White: purity and innocence
  • Blue: vigilance, perseverance, and justice
Happy Birthday Uncle Sam!

24 June 2018

SOC: Statement of Truth...

Global transnational organizations who provide 24x7 Business Resilience Intelligence and executive security protective details are on the rise. Corporate personnel who must travel to high risk regions of the globe, realize the requirement for a minimal, yet comprehensive security envelope.

Back at the Business Resilience or "Security Operations Center" (SOC), you will find a team of subject matter experts working in concert, to continuously enhance the Operational Risk Management matrix. One set of analysts are tasked with the media review and real-time intelligence collection from Open Sources. One example could be CNN or even more regional sources such as Alhurra:
Alhurra (Arabic for “The Free One”) is a commercial-free Arabic language satellite television network for the Middle East devoted primarily to news and information. In addition to reporting on regional and international events, the channel broadcasts discussion programs, current affairs magazines and features on a variety of subjects including health and personal fitness, entertainment, sports, fashion, and science and technology. The channel is dedicated to presenting accurate, balanced and comprehensive news. Alhurra endeavors to broaden its viewers' perspectives, enabling them to make more informed decisions.
Another set of analysts are sifting through online intelligence portals such as Opensource.gov or Data.gov . However, when you have a specific executive who is traveling to a specific country, there are more detailed plans and substantial advance work that takes place.

These facets of corporate enterprise risk and operational risk management (ORM) are vital to protect human assets and the ongoing continuity of business operations. Situational awareness enhancement is a 24/7 x 365 day process.

Whether your business takes you to Pakistan, Paris, Toronto or London the risk of bombing, or criminal elements are a real potential threat:
LONDON — An 18-year-old Iraqi asylum seeker was sentenced on Friday to life in prison in Britain after he was convicted of attempted murder in the botched bombing last September of a rush-hour train on the London Underground, which injured 30 people.

Ahmed Hassan was convicted last week after he left the bomb that partially exploded one stop after he had disembarked. The explosion triggered a stampede that injured tens of passengers.
Executive Protection details have been utilizing the compendium of wisdom and research that is found in Gavin De Becker's publication, "Just 2 Seconds" and for good reason:
"Think of every assassination you've ever heard about. For most people, a few of these major ones come to mind: Caesar, Abraham Lincoln, John Kennedy, Martin Luther King, Mahatma Gandhi, Indira Gandhi, Anwar Sadat, John Lennon, Israel’s Prime Minister Rabin, Pakistan’s Benazir Bhutto.
From start to finish, all of these attacks — combined — took place in less than one minute. And the hundreds of attacks studied for this book, all of them combined, took place in less than a half-hour. Those thirty minutes, surely the most influential in world history, offer important insights that can help today’s protectors defeat tomorrow’s attackers."
Operational Risk is far more pervasive than just the detection of fraud, mitigating the loss events from internal information theft or the "All Threats, All Hazards" approach to the "Continuity of Business Operations."  It's been said here before and it's worth repeating again this statement of truth:

"Attackers use tools to exploit a vulnerability to create an action on a target that produces an unauthorized result to obtain their objective."

Whether you utilize this statement within the context of your digital domains, physical domains or the vast set of processes within the enterprise, it does not matter.

What does matter, is that those individuals responsible for the survivability and the defensible standard of care of the organization,  "Never Forget"...

17 June 2018

Father's Day 2018: 30 Years of Wisdom...

On the dawn of the day in America, known as Father's Day we reflect and we acknowledge him.  For many, their Father was a major influence in their life.  All to often, others never really knew who he was.  Father's are all Operational Risk Management (ORM) professionals in many ways.

This Father has two adult children, a daughter and a son about 19 months apart in their late twenties.  Fatherhood started in mid-September, 1988.  That gives you some perspective on our years of experience together.  So to all those Father's out there, who are planning a family someday, here are a few thoughts.

First off, the role consumes you.  Seeing that first born baby, changes you forever.  You suddenly realize the word "I" is no longer in your vocabulary.  Most certainly, you thought you loved your wife tremendously, before you watched your first daughter born.  Yet the overwhelming feeling of new love you have for your wife at that time and moment, is ever so special.  Incredible!

Second, becoming a Father becomes a life long responsibility and a new life mission.  You find yourself having memory moments, decades later about your children's greatest achievements in life.  The day they walked for the first time.  The special birthday party with friends in that old neighborhood.  The day they walked up on stage to get their College/University Diploma.  At that point in your life, when you were working 12 hour days.

Father's Day as long as you are alive, shall be a day of remembrance, a day of memories and a day of looking into what lies ahead.  You have watched them grow up.  You have counseled them, taught them, trained them and loved them.  When is your role as Father over?  Not until your last day on Earth.

Being a Father makes you a better husband.  It gives you the role of being all those things that your wife can't be or won't be at that particular point in time.  As your kids grow up, you will both find your path, as a mate and a parent.  One thing is for certain.  Being married now 30+ years and raising two kids, who are both college graduates and now in challenging careers, makes you realize you might have made a difference.

Finally, being a Father makes you think about your own Father and how you want to be the same or different.  After all, where did you learn many of the things that will influence how you might parent.  When I saw my Father on the day he died, I cried.  And yet, I saw a look of joy on his face as if to say, I know I was not perfect, but I loved you very much.

On this Father's Day in America, this one is so proud.  This Father loves his wife dearly and realizes that our two kids love us so much too.  Having a son makes you strive to be your best.  To be a model husband, to live ethically, morally and spiritually.  And now that we have a new Son-in-Law, loving him like my own.  Walking my daughter down that aisle, was almost as joyful as the day I saw her born...

Happy Father's Day...Onward!

09 June 2018

Crisis Readiness: Future of Risk Response...

One of the key components of effective Operational Risk Management (ORM) is a robust Crisis and Incident Readiness Response Team. This team shall have practiced and exercised multiple scenarios over the course of their training together. Why?

The ability to adapt on the fly regardless of the kind or type of incident is the core of what OPS Risk professionals are able to do, time and time again. The more unknowns that are encountered in any space of time, requires the ability to Observe, Orient, Decide and Act.

Yet this is not so much about the use of the OODA Loop or any other process in effectively adapting to your new and rapidly changing environment. It is about having the right sensors and early warning capabilities in place to detect and to deter the potential for new threats and new vulnerabilities, that may disrupt your mission.

Why do you read about Global 500 organizations that have seen their stock price erode in a day, week or month due to the ineffective response to a crisis incident? In many cases, it is a simple fact. The Crisis and Incident Response Team was caught in a scenario that they had never imagined.

An unfolding situation that they had never thought of and simply didn't plan for because it's likelihood was just too low. This author has talked about this before and it deserves repeating that exercising for the low likelihood and high impact events is where you need to spend most of your time.

The 1-in-100 year events are no longer the case. They are 1-in-50 or less. Just ask your property and casualty insurance carrier about how their actuarial Quants are thinking about this very topic. Whether is it global climate change or unregulated nuclear power industries in emerging nations, the low likelihood and high impact events are becoming more of a risk.

So what is the answer? To begin, you must first start the culture change and mind set shift to the future and to your own Strategic Foresight Initiative. Looking into the future is not exactly the exercise. Pick a point in time, five years, ten or twenty-five years into the future. Select a scenario that you can't even fathom is a possibility of actually coming true that will impact your organization. Then start your own "Backwards from Perfect" strategic foresight initiative.

What this process will do, is to get all the focus on what you still need to accomplish between now and then to get yourself into a position so that your people, systems and organization will be able to withstand the scenario incident. Welcome to Global Enterprise Business Resilience.

Across every sector of society, decision-makers are struggling with the complexity and velocity of change in an increasingly interdependent world. The context for decision-making has evolved, and in many cases has been altered in revolutionary ways. In the decade ahead, our lives will be more intensely shaped by transformative forces, including economic, environmental, geopolitical, societal and technological seismic shifts.

The signals are already apparent with the re-balancing of the global economy, the presence of over seven billion people and the societal and environmental challenges linked to both. The resulting complexity threatens to overwhelm countries, companies, cultures and communities.

FLASHBACK TO THE:  Global Risks 2012 Seventh Edition

What if you happen to be a Non Governmental Organization (NGO)? What are some of the risks that may impact you from a "Geopolitical" perspective that today have a high likelihood?
  • Global Governance Failure
  • Terrorism
  • Failure of Diplomatic Conflict Resolution
  • Pervasive Entrenched Corruption
  • Critical Fragile States
  • Entrenched Organized Crime
  • Widespread Illicit Trade
Crisis impact will be specific to your particular stakeholder group. These will be higher or lower depending on whether you are a:
  • NGO
  • Business
  • Government
  • International Organization
  • Academia
There are however, three main cross cutting observations by all of the these stakeholders from the Global Risks 2012 report and even to present day:
  • Decision-makers need to improve understanding of incentives that will improve collaboration in response to global risks
  • Trust, or lack of trust, is perceived to be a crucial factor in how risks may manifest themselves. In particular, this refers to confidence, or lack thereof, in leaders, in the systems which ensure public safety and in the tools of communication that are revolutionizing how we share and digest information 
  • Communication and information sharing on risks must be improved by introducing greater transparency about uncertainty and conveying it to the public in a meaningful way.
The way that the global citizen decides to digest information in five or twenty years will be different than it is today. The world has already started to see this with the proliferation of mobile smart phone technologies, GPS, cameras, and other Twitter-like knowledge systems networks such as FrontlineSMS and Ushahidi.

Do you really believe that CNN and AlJazeera will be the source of truth in the next two decades? Social Media is here to stay and the only reason that formal news organizations will exist, is to try to validate and verify.

Operational Risk Management (ORM) and Crisis Readiness shall continue to be one of the most dynamic and challenging places for global enterprises for years to come...

20 May 2018

Memorial Day 2018: The Risk of Service is Understood...

Memorial Day weekend will soon be upon us in the U.S. and on the final Monday of May 2018, we reflect on this remembrance.

In order to put it all in context, we looked back 5 years to our 2013 blog post here.  It was only a few weeks since a fellow colleague from Team Rubicon had ended his battle at home, after several tours of duty with AFSOC.  Neil had joined the ranks of those fallen heroes who survive deployment tagging and tracking the enemy in the Hindu Kush.  He was also one of the 22 that day in early May, that could not defeat the legacy of demons he fought each night, as he fell deep asleep.

On Memorial Day 2018, we again honor Neil in Section 60 at Arlington Memorial Cemetery and all those other military members who have sacrificed and defended our freedoms for 242 years. Simultaneously, we do the same for the people behind the "Stars" on a wall in Langley, Va for those officers who have done the same.

Together we are on the front lines or inside the wire at the FOB.  Whether you are in Tampa, FL, Stuttgart, Germany or Arlington, VA.  Whether you are on your beat cruising the streets of a major metro USA city.  Whether you are watching a monitor at IAD, LAX or DFW.  Whether you are deep in analysis of Internet malware metadata or reviewing the latest GEOINT from a UAS.  We are all the same, in that we share the mission that gets each one of us out of bed each day.  Our countries "Operational Risk Management (ORM)."

The Operational Risk Management mission of the U.S. Homeland is vast and encompasses a spectrum of activity, both passive and kinetic.  Digital and physical.  It requires manpower and resources far beyond the capital that many developed countries of the world could to this day comprehend.  There are only a few places across the globe, where a normal citizen would say that the mission and the capital expenditures are worth every dollar and every drop of blood.

Memorial Day in the United States is exactly this:
Memorial Day is a United States federal holiday which occurs every year on the final Monday of May.[1] Memorial Day is a day of remembering the men and women who died while serving in the United States Armed Forces.[2] Formerly known as Decoration Day, it originated after the American Civil War to commemorate the Union and Confederate soldiers who died in the Civil War. By the 20th century, Memorial Day had been extended to honor all Americans who have died while in the military service[3].
So this Memorial Day weekend as we walk among the headstones, reflect on our colleagues who gave their service and their own lives, we will stand proud.  We understand the risks.  We know why we serve.  In the spotlight or in the shadows.  The tradition and the mission continues...

13 May 2018

InTP: Insider Threat Via Critical Infrastructure...

The private sector organizations of the United States are vital to the protection and security of the Homeland.  The private sector owns a majority of our assets and Critical Infrastructure Protection (CIP) remains a priority as a result of the latest asymmetric threats.  Securing Critical Infrastructure sectors includes:
  • Chemical:
  • Commercial Facilities:
  • Communications:
  • Critical Manufacturing:
  • Dams:
  • Defense Industrial Base:
  • Emergency Services:
  • Energy:
  • Financial Services:
  • Food and Agriculture:
  • Government Facilities:
  • Healthcare and Public Health:
  • Information Technology:
  • Nuclear Reactors, Materials, and Waste:
  • Transportation Systems:
  • Water and Wastewater Systems:
The National Strategy to Secure Cyberspace, emphasizes the importance of public/private partnerships in securing these critical infrastructures and improving national cyber security.
Similarly, one focus of the Department of Homeland Security is enhancing protection for critical infrastructure and networks by promoting working relationships between the government and private industry.

The federal government has acknowledged that these relations are vital because most of America’s critical infrastructure is privately held.  Further, the networks of our global super-infrastructure are tightly “coupled”—so tightly interconnected, that is, that any change in one has a nearly instantaneous effect on the others.

Attacking one network is like knocking over the first domino in a series: it leads to cascades of failure through a variety of connected networks, faster than most human managers can respond.

We realize that there are many facets of CIP, yet where should we be allocating resources?  The vigilance within our organizations has not changed and is based upon previous studies done by CERT and the US Secret Service:
"A system administrator, angered by his diminished role in a thriving defense manufacturing firm whose computer network he alone had developed and managed, centralized the software that supported the company’s manufacturing processes on a single server, and then intimidated a coworker into giving him the only backup for that software. Following the system administrator’s termination for inappropriate and abusive treatment of his coworkers, a logic bomb previously planted by the insider detonated, deleting the only remaining copy of the critical software from the company’s server. The company estimated the cost of damage in excess of $10 million, which led to the layoff of some 80 employees." U.S Secret Service and CERT Coordination Center/SEI Insider Threat Study: Computer System Sabotage in Critical Infrastructure Sectors

Insider Characteristics

The majority of the insiders were former employees.

• At the time of the incident, 59% of the insiders were former employees or contractors of the affected organizations and 41% were current employees or contractors.

• The former employees or contractors left their positions for a variety of reasons. These included the insiders being fired (48%), resigning (38%), and being laid off (7%).

Most insiders were either previously or currently employed full-time in a technical position within the organization.

• Most of the insiders (77%) were full-time employees of the affected organizations, either before or during the incidents. Eight percent of the insiders worked part-time, and an additional 8% had been hired as contractors or consultants. Two (4%) of the insiders worked as temporary employees, and one (2%) was hired as a subcontractor.

• Eighty-six percent of the insiders were employed in technical positions, which included system administrators (38%), programmers (21%), engineers (14%), and IT specialists (14%). Of the insiders not holding technical positions, 10% were employed in a professional position, which included, among others, insiders employed as editors, managers, and auditors. An additional two insiders (4%) worked in service positions, both of whom worked as customer service representatives.


Making sure that you have a robust workplace awareness program is yet one key component in addressing the "Insider Threat" and our resilience.

More importantly, the timing may have been the perfect launch point for other malfeasance from non-state actors who lie in their "Lone Wolf" mode, waiting to strike.

And while the scenario could be well contained, the timing could create opportunities for the "Black Swan" outlier inside your enterprise.

It's never to early to plan for the unimaginable, all happening in the same geography and the same time frame.  Revisit your "Insider Threat Program" (InTP) and Critical Infrastructure Resilience today...

06 May 2018

IO Convergence: Cyber Warfare Unified Taxonomy...

Information Operations (IO) is an Operational Risk Management priority in both the public and private sector these days. Is it lawful for a U.S. company and U.S. citizens to train and perform cyber warfare activities on behalf of a foreign country?

Flashback to 2012, The Washington Post reports:

By Ellen Nakashima, Published: November 22
"In the spring of 2010, a sheik in the government of Qatar began talks with the U.S. consulting company Booz Allen Hamilton about developing a plan to build a cyber-operations center. He feared Iran’s growing ability to attack its regional foes in cyberspace and wanted Qatar to have the means to respond.

Several months later, officials from Booz Allen and partner firms met at the company’s sprawling Tysons Corner campus to review the proposed plan. They were scheduled to take it to Doha, the capital of the wealthy Persian Gulf state.

That was when J. Michael McConnell, then a Senior Vice-President at Booz Allen and former Director of National Intelligence in the George W. Bush administration, learned that Qatar wanted U.S. personnel at the keyboards of its proposed cyber-center, potentially to carry out attacks on regional adversaries.

“Are we talking about actually conducting these operations?” McConnell asked, according to several people at the meeting. When someone said that was the idea, McConnell uttered two words: “Hold it.”
A common taxonomy was developed years ago for the cyber terms of the computer and network incident domain. Now we need to make sure we all understand what we mean when we say Information Operations policy as it pertains to the digital world.

As an example, in the context of the digital attacker we have Sandia Labs Taxonomy:
  • Hacker
  • Spies
  • Terrorists
  • Corporate Raiders
  • Professional Criminals
  • Vandals
  • Voyeurs
Each is unique and has its own domain or category. We are sure that the same could be used for the context of attackers in the non-digital world, possibly with the exception of Hacker. However, the definition of corporate raider in the off line domains may not be synonymous with the on line domain of cyber incidents.

If we look at the categories that make up the entire "Incident" that Sandia Labs has utilized, we see the following:
  • Attackers
  • Tool
  • Vulnerability
  • Action
  • Target
  • Unauthorized Results
  • Objectives
Without combining the context under each category, we lose the impact of what we are trying to make contextual with regard to an "Incident". We need to make sure that the anti-terrorism taxonomies of the off line and on line domains can be utilized together to describe the attributes of an "Incident". We need to break down the sub-categories as well. For instance, in the Sandia Labs Taxonomy for the Objectives category we have:
  • Challenge, Status, Thrill
  • Political Gain
  • Financial Gain
  • Damage
When we move to the off line domain and are doing risk mitigation and preparedness exercises for anti-terrorism we utilize another set of words to describe and evaluate infrastructure threats and hazards.  Here are Five factors:
  • Existence addresses the question of who is hostile to the assets of concern?
  • Capability addresses the question of what weapons have been used in carrying out past attacks?
  • History addresses the question of what has the potential threat element (aggressor) done in the past and how many times?
  • Intention addresses the question of what does the potential threat element hope to achieve?
  • Targeting addresses the question of do we know if an aggressor is performing surveillance on our assets?
Two years later, the Washington Post reports:

By Ellen Nakashima, Published: November 14
President Obama has signed a secret directive that effectively enables the military to act more aggressively to thwart cyber­attacks on the nation’s web of government and private computer networks.
Presidential Policy Directive 20 establishes a broad and strict set of standards to guide the operations of federal agencies in confronting threats in cyberspace, according to several U.S. officials who have seen the classified document and are not authorized to speak on the record. The president signed it in mid-October. The new directive is the most extensive White House effort to date to wrestle with what constitutes an “offensive” and a “defensive” action in the rapidly evolving world of cyberwar and cyberterrorism, where an attack can be launched in milliseconds by unknown assailants utilizing a circuitous route. For the first time, the directive explicitly makes a distinction between network defense and cyber-operations to guide officials charged with making often-rapid decisions when confronted with threats.
The policy also lays out a process to vet any operations outside government and defense networks and ensure that U.S. citizens’ and foreign allies’ data and privacy are protected and international laws of war are followed.

“What it does, really for the first time, is it explicitly talks about how we will use cyber-operations,” a senior administration official said. “Network defense is what you’re doing inside your own networks. . . . Cyber-operations is stuff outside that space, and recognizing that you could be doing that for what might be called defensive purposes.”
We believe that as our cultures, countries, agencies and professionals work together on Information Operations (IO) and online counter-terrorism initiatives, we are going to have to develop a solid taxonomy. It will provide the foundation for our clear and accurate risk management methodologies and incident management systems, being developed by relevant organizations in mutual collaboration.

Once we have accomplished this fundamental understanding, then true Critical Infrastructure Protection (CIP) cooperation and coordination will occur.

22 April 2018

Unthinkable: Adapting in New World Disorder...

Will 2018 bring more data breaches, lost laptops and insider threats than 2017?  This is why CSO's, CPO's and corporate General Counsels have their teams working overtime.

When the enemy is increasing their attacks, utilizing new strategies and leveraging the existing base of compromised organizational intellectual and data assets, the future horizon becomes ever more clear. 

The statistics don't lie.  1579 documented Data Breaches occurred in 2017. Up 44.7% according to reports by the Identity Theft Resource Center (ITRC) compared to the previous year.  It is the new normal.

The Insider Threat Program (InTP) however, remains a key focus for Operational Risk Management (ORM) professionals because human behaviors are exaggerated during periods of stress, fear and uncertainty. This means that people who may have never considered doing something to jeopardize their reputations, may now be up against a wall.

When there is no obvious exit and no way out, people will do extraordinary things to get ahead, beat the odds and hedge their own risk portfolio of life.

In Joshua Cooper Ramo's book "The Age of the Unthinkable", "Why the New World Disorder Constantly Surprises Us and What We Can Do About It" the author discusses the concept of Deep Security. His analogy of how to think about "Deep Security" is the biological immune system:
"A reactive instinct for identifying dangers, adapting to deal with them, and then moving to control and contain the risk they present."
The key word in Ramo's writing is "Adapt".  Being Adaptive.  However, prior to this there are two other very vital words that we feel are even more imperative. Instinct. Identifying. In other words, Proactive Intuition.

Ask any savvy investigator on how she solved the case and you may hear just that, "I had a hunch."

Talk with a Chief Privacy Officer in any Global 500 company.  You might get them to admit they have a sense that their organization will be the target of an "Insider data breach" incident in the coming year or two.

Do you remember signing off on reading and your acceptance of the employee handbook?  When did your organization last make changes to the Corporate Employee policies?  We would start with the updates to the following sections:
  • MEDIA CONTACT
  • SOCIAL MEDIA POLICY
  • REMOTE ACCESS POLICY
  • E-MAIL, VOICE MAIL AND COMPUTER NETWORK SYSTEM PRIVACY
  • (YOUR ORGANIZATION) RIGHT TO ACCESS INFORMATION
  • SYSTEMS USE RESTRICTED TO COMPANY BUSINESS
  • FORBIDDEN CONTENT
  • PASSWORD SECURITY AND INTEGRITY
  • INTERNET ACCEPTABLE USE POLICY
  • POLICY ON USE OF SOFTWARE
  • COMPANY PROPERTY
  • PROTECTION OF TRADE SECRETS/NON-DISCLOSURE OF COMPANY INFORMATION 
Due to the increasing complexity of IT systems, cloud computing, data networks and the hundreds or thousands of laptops and mobile devices circling the globe with company executives and employees is enough to predict that a major breach will occur.

Being adaptive and having proactive intuition in the modern enterprise does not come natural. You have to work at it and it requires a substantial investment in time and resources to make it work effectively.  Proactive Intuition.

Once you realize that all of the controls, technology and physical security are not going to keep you out of harms way, you are well on your way to reaching the clairvoyance of "The Age of the Unthinkable."

15 April 2018

Social Strategy 140: Direct Action #Risk...

Twitter real-time direct action (DA) "Information Warfare" between nation states is a daily task. Current and future Operational Risk Management (ORM) priorities will encompass the imperative to staff "Corporate Intelligence Unit" Fusion Centers.

A prudent Operational Risk strategy, shall include a "Big Data" capability combined with deep social intelligence analysis. Here is a historical FLASHBACK in time, to one example of why leadership is devoting new resources and investment to these internal risk management capabilities:
New Diplomatic Avenue Emerges, in 140-Character Bursts
By SOMINI SENGUPTA October 3, 2013
UNITED NATIONS — "Countries all over the world, dictatorships and democracies alike, have in the last few years sought to tame — or plug entirely — that real-time fire hose of public opinion known as Twitter. 
But on the sidelines of the General Assembly meeting over the last couple of weeks, ministers, ambassadors and heads of state of all sorts, including those who have tussled with Twitter the company, seized on Twitter the social network to spin and spread their message. 
At the height of the diplomatic negotiations last week over a United Nations Security Council resolution that would require Syria to turn over its stockpile of chemical weapons, the American ambassador to the United Nations, Samantha Power, used Twitter to preempt criticism of the measure as lacking teeth because it had no automatic enforcement provision."
What does this mean for the global enterprise, who circumnavigates the planet to initiate and manage daily business operations?  It means that "Information Warfare" and intelligence collection and analysis for the enterprise continues, as a top strategic and operational function.  It requires continuous Operational Risk strategy oversight.

How an organization directs personnel and manages daily decisions, is more mobile information-centric than ever before.  Just stand at any major sidewalk intersection in a major city across the world and count the number of people looking at their "Smart Phones" as they cross the street.

The speed of business that is fueled by leaders commenting via social media, can even influence commodity traders in futures markets and operational planners in the "E-ring."

Leadership has the ability to by-pass the traditional media juggernauts to get their message heard in seconds.   The President of a major stock exchange or of a G20,  has a "Duty of Care" to it's constituents to make the correct public decisions.  At the same time, a moral and ethical context begins to evolve, in the vast battle space of 140 digital characters.

The use of a social media post or Tweet from the Board Room to the Court Room; from San Francisco to Tehran, or from Wall Street to Hong Kong, is a risk-oriented asymmetric information tactic delivered in plain sight.

Those social tactics, visual in the landscape of our modern day quest for influence, notoriety or outcry, shall forever shape the breadth of our enterprise digital risk management spectrum...

07 April 2018

Privacy by Design: Trust-Based Business Integrity...

The truth is, your enterprise is under assault.  The asymmetric warfare tactics that are targeting the firewall and the e-mail Inbox, will continue to be a digital challenge.  Intellectual Property (IP) Lawyers and government regulators are gearing up, for another salvo of mandates to enable "Privacy by Design" and increase consumer protection.

Operational Risk Management (ORM), is the discipline to focus the organization, with proven tools, methods and strategies to assist in the risk mitigation associated with nation states, rogue criminal syndicates and even your own employees.

Achieving digital trust with your company and your customers is a continuous process.  It requires substantial resources and specialized subject matter expertise to remain effective.

Without a purposeful "Privacy by Design" approach within your enterprise and a renewed focus on the pervasive problem-set now clearly before us, our digital infrastructure integrity is destined for failure.
Privacy by Design states that any action a company undertakes that involves processing personal data must be done with data protection and privacy in mind at every step. This includes internal projects, product development, software development, IT systems, and much more. In practice, this means that the IT department, or any department that processes personal data, must ensure that privacy is built in to a system during the whole life cycle of the system or process. Up to now, tagging security or privacy features on at the end of a long production process would be fairly standard. 
By reading this definition of "Privacy by Design", you may assume this problem is the responsibility of the Information Technology department to fix or manage.  Until you ascertain it is not just an Information Technology challenge.

It is an Organizational Culture issue, that persists at the Board of Directors level, either before an incident, or certainly soon thereafter.  The Board of Director's may question the market value of a Fortune Magazine web page, dedicated to updating the public on the developing company crisis:

"Facebook in recent weeks has been plagued by yet another scandal, as the social networking giant struggles to deal with the fallout from the Cambridge Analytica controversy.

On Wednesday, it was revealed that initial figures estimating Facebook exposed the data of 50 million users without direct consent were actually much higher than reported, closer to 87 million instead. And Facebook CEO Mark Zuckerberg is now set to testify in front of Congress next week.

But this isn’t the first time Facebook has been embroiled in controversy. The social media company has been involved in a number of scandals just over the past week alone."


So how do you mitigate and start to remedy an "Organizational Culture" issue like this one?  Before the government decides to try and fix it for you.

You have to start with building proactive data privacy awareness with every employee.  Especially if your revenue model is based upon selling advertising.  What is your organizations revenue model?  Are you aggregating members or users data and offering a free service platform?  Buyer beware.

What is ahead of us, as we approach a digital "dead mans curve"?  Jeffrey Ritter best explains this:
"To shift toward building digital trust, nation-states must acknowledge that sanctions become increasingly difficult to enforce and must, instead, move toward a regulatory scheme that favors, and provides incentives for, stakeholders that commit to trust-based business methods. Already, both in the United States and other nations, companies that can certify their compliance with third party standards are receiving direct benefits from government agencies."
How are you improving the trustworthiness of your organization? With employees, partners and customers. Think about it long and hard during purposeful learning sessions with your Board of Directors.

So what?

What are you doing today to increase the integrity of your TrustDecisions, to enable and perpetuate your foundation for digital business integrity?

As you analyze your current state, pages of words written by lawyers in "Terms of Service" policies are not enough to satisfy your customer.

Have you strategically implemented all that is possible so far, to address your organizational culture with the pursuit of achieving digital trust?

Leadership of any organization, must perpetuate and transfer the morals and ethics of our society, into the trusted digital products and solutions that our enterprises design, distribute and sell to the public.

01 April 2018

Leadership: The Life Journey of Discovering "X"...

There, can you hear it?  The sound of the helicopters in the distance.  Where is the sun this dawn lit morning, to join all the incredible sounds of nature?  The birds with their unique languages and the insects sending their clear signals of distress.

What will this new day bring before us, this Easter Sunday, April 1, 2018?  How will our leadership be challenged with new problem-sets and the speed of making the right trust decisions?  There is one certainty today, that is unrefutable, to prove wrong by argument or evidence.

As a recognized leader in your current role, how would you describe your particular style?  Do you lead by example or do you just sit back and wait for others to make it happen?  Maybe you do it all and never let anyone else learn from their mistakes and learn the feeling of success or failure.

It all begins with your up-bringing and where and how you were raised as a child.  The roots of your leadership in many ways, has been influenced by your early years, before you were even in your mid 20's.

Maybe somewhere along the path of your career, you were administered a psychological profile test.  You know, some form of questions or exercise instrument, to help you determine what particular "Quadrant" or dichotomies of cognitive learning style you are in, as it pertains to the psychologists descriptions:

Cognitive learning styles
Yet by the time you have reached the age where an employer, agency or other unit has a reason to peel back that facade you wear on a daily basis, you are already destined.  By DNA and by your parents.

Now the question is, who do you want to be and how are you going to train or re-train to be that kind of person?  That kind of leader.  To learn how to behave in a way, that truly makes a difference in other peoples lives.

The answers that you seek will be determined by your actions.  You have heard this before.  Who you are becoming and how you will judge your progress, is worth examining further.  What is your measuring device?  How do you feel at the end of the day, if you "Have" or "Have not" seen, heard or accomplished "X"?

What is "X" in your life?  Is it a signature on the bottom of a new contract?  Is it the smile on a loved ones face?  Is it a 3 mile run or ride?  Is it a "Thumbs Up" on your latest social media posting?  Perhaps it is simple as five hours of solid sleep.  Everyone has their own particular metrics by which they are judging their progress each day.  What is yours?

Metrics and your personal measuring device may determine who you are and what you are becoming.  Discovering and knowing that "X" in your life is perhaps more of an influence than you ever anticipated.  What the psychologists and the research has proven over the years, is that DNA and environment in your early years will be a major influence on your life.

Yet when you are ready to lead yourself or others in the small world you live in, think about what "X" has been for you this particular day.  Write it down and explain it to yourself each day.  Call it a journal, or a blog or just a composition notebook.  Without writing it out and explaining it to yourself you will have missed the opportunity.
The opportunity, is your own version of leadership:   To guide on a way especially by going in advance, to direct the operations, activity, or performance of, to guide someone or something along a way...
Now, listen carefully.  Do you hear the birds singing and see the sun rising... Happy Easter!