Robert Young Pelton's Travel Tips may be common sense. These are also the type of tips you get from those expensive executive seminars where no one ever gets out of their seat for two days.
If you are going to take an attitude of really protecting your organizations most valuable assets then you have to train your people in real life scenarios. The goal is to overcome the panic modes and replace them with smart actions to save your life and your companies precious information.
For those who travel on business into regions of political or religious instability it should be company policy that each individual travel with at least an experienced partner. Also essential is that both have gone through extensive hands on training to detect surveillance as well as manage emergency situations with smart decisions. For more on this visit: Threat Detection & Management
29 October 2004
27 October 2004
Compliance and outsourcing: Oil and water or fine vinaigrette?
John and Stan could not have said it any better....
By John Van Decker and Stan Lepeak
10 May 2004 | Meta Group
One common misperception that still survives in the market is that existing outsourcing audit mechanisms, primarily the SAS 70 audit, are adequate for SOX compliance. The growing consensus is that even an SAS 70 Type 2 audit may not prove enough for SOX. The SAS 70 standard was developed long before SOX regulations and was not designed to focus on the type of controls that SOX addresses. In addition, there have been no requirements for users to request an SAS 70 audit, and many have not. One SAS 70 audit could potentially suffice for multiple clients of an outsourcer, whereas with SOX compliance, this is likely unacceptable. We are seeing more cases where aggressive/thorough clients are demanding additional controls and documentation beyond an SAS 70 Type 2 audit to enable what they estimate is "good enough" SOX compliance. It is not expected that the PCAOB will define requirements above and beyond an SAS 70 for SOX compliance until later this year.
A final challenge to SOX compliance that affects outsourcers is interenterprise compliance. Users must approach process compliance holistically, covering insourced and outsourced processes, as well as intersection points and continuums of processes that span supply and service chains. For example, how can a user's controls account for the breakdown in a supplier's financial controls that could lead to a parts shortage, which could impact revenue/profits that would then require a timely disclosure? Clearly, organizations cannot address SOX compliance in an isolated fashion. Outsourcers have the added dimension of being intertwined in multiple-clients compliance efforts across multiple process areas. This in itself increases the outsourcer's risk and demands greater focus on enabling compliance, for its own sake as much as its clients'.
Bottom Line: Business process and IT outsourcing currently do not mix well with SOX and related compliance requirements. However, outsourcers and their clients cannot wait for regulatory clarification and must define, document, and rationalize interim best-faith efforts for gaining and evidencing SOX compliance for affected outsourced functions and processes.
26 October 2004
Systems: Data Quality Risk...
The quality of data is becoming a risk management issue again according to this latest Banking Study of 1700 banks in 63 countries. Sarbanes-Oxley and Basel II are helping CIO's to increase their budgets yet the study finds that data quality is still one of the biggest operational risks.
Workflow management is a key concern and 54% of the respondents plan to spend money in this software as it is a vital component in managing operational risk. Furthermore, outsourcing and COTS solutions are outpacing proprietary development.
The survey quizzed banks about eleven key topics involving reference data management and risk management and shows that financial institutions worldwide are making considerable efforts to deepen their data management and increase data quality.
These efforts are being driven, besides cost pressures and increased transaction volumes, by regulatory requirements such as Sarbanes-Oxley and Basel II, which will be implemented in more than 100 countries within the next few years. "The results show that companies realize the close connection between comprehensive data management and efficient risk management," explains Martin Buchberger, head of marketing at AIM Software.
Workflow management is a key concern and 54% of the respondents plan to spend money in this software as it is a vital component in managing operational risk. Furthermore, outsourcing and COTS solutions are outpacing proprietary development.
Looking further at standardization, 42 percent of the survey respondents plan to purchase an off-the-shelf data management solution or to buy and adapt a solution to their own needs. 26 percent of the respondents rely on proprietary development. "This is a significantly smaller proportion than in the past, when data management was still regarded as an internal core competency.
25 October 2004
Phishing goes Corporate...
Phishing is making it's way inside corporations and represents a new threat by hackers.
The ploy is to send an email that looks legitimate about upgrading a software component or windows program. The hackers site then downloads the Malicious Code.
The ploy is to send an email that looks legitimate about upgrading a software component or windows program. The hackers site then downloads the Malicious Code.
“Companies must make their employees understand their role in improving security within the organisation,” he said.
A proper security policy must also be in place and the role of each individual who manages the security policy must be clearly defined, he said.
It must also be made clear to employees that the security policy is in place for their protection and not just for the company.
And finally, companies must be prepared for the worse. There should be an incident response team should the company's security be compromised."
22 October 2004
SOX a Ticking Time Bomb?
In the latest issue of Corporate Board Member you will find some very interesting statistics and comments. This one got our attention:
I would say that over one third don't know, don't care or are too scared to really find out. One fifth think that performance will be impacted. That leaves the remaining 40+ % feeling confident that SOX will not affect corporate performance. Let's just hope that the "NO" voters do really know that this is the case.
Is That A Ticking Clock Or A Time Bomb?
Has meeting Sarbanes-Oxley's requirements left directors enough time to think about other issues?
The answer is yes, but only because you're spending more time on the job than ever before.
The SOX Factor
Do directors think Sarbanes-Oxley has created an environment where management is so distracted that company performance will be affected?
No: 44%
Not Sure: 36%
Yes: 20%
I would say that over one third don't know, don't care or are too scared to really find out. One fifth think that performance will be impacted. That leaves the remaining 40+ % feeling confident that SOX will not affect corporate performance. Let's just hope that the "NO" voters do really know that this is the case.
19 October 2004
People: Travel & Safety...
Travel risk to corporate executives is on the rise. Even if you are not an executive who can afford the services of personal body guards and armored cars, there are some prudent ways to mitigate the risk of traveling to the global hot spots.
Travel safety is becoming more of a main stream issue with savvy operational risk managers. In fact, the likes of some new firms are emerging by former FBI or other law enforcement heavy weights. The fact is, most of these so called travel safety courses are being taught from only one side of the equation.
Business has to be done in some of the most dangerous places on the planet, even when it comes to being exposed to kidnapping, terrorism and corrupt governments. Our advice is to make sure your instructor transfers skills to people on "how" to detect, deter and defend against the attackers. Not just the "What to do".
For the real difference, visit: Threat Detection & Management
Travel safety is becoming more of a main stream issue with savvy operational risk managers. In fact, the likes of some new firms are emerging by former FBI or other law enforcement heavy weights. The fact is, most of these so called travel safety courses are being taught from only one side of the equation.
Today, CSOs are often tasked with building their company's corporate travel safety programs. The job calls for a proactive approach to educate employees about precautions they can take to stay safe, whether they're the CEOs of multibillion-dollar conglomerates who fly on company jets that land on secured tarmacs or rank-and-file staff riding in commercial airline coach.
Business has to be done in some of the most dangerous places on the planet, even when it comes to being exposed to kidnapping, terrorism and corrupt governments. Our advice is to make sure your instructor transfers skills to people on "how" to detect, deter and defend against the attackers. Not just the "What to do".
For the real difference, visit: Threat Detection & Management
18 October 2004
Business Performance & Basel II...
The Tower Group is shouting the need for banks to automate now in the midst of the Basel II momentum. While business performance has converged with Basel II, the key understanding needed is what do Business Performance & Basel II have to do with my survivability as a money center bank?
Knowledge Management is coming to banking in a way that the bean counters never imagined. With the focus on Operational Risks, the only way to be able to correlate new threats with the current asset base is through automation.
Basel II introduces a convergent framework of risk management and controls that will encourage banks to invest wisely in IT and improve the efficiency of their business operations. Banks that adopt effective enterprise risk management platforms will reap business benefits that go well beyond regulatory compliance.
Knowledge Management is coming to banking in a way that the bean counters never imagined. With the focus on Operational Risks, the only way to be able to correlate new threats with the current asset base is through automation.
The industry is now at the implementation phase of Basel II. Few banks have the perspective and resources to experiment and establish their own enterprise risk management models that include this new field of operational risk. Notwithstanding their attention to business continuity and reputational risk matters, most banks have still to inscribe operational risk procedures in the broader picture of business management and operational efficiency. Not only may banks improve their operational efficiency by streamlining business processes, but they also can tap important benefits in operational resilience, responsiveness and flexibility to innovate. By adopting automation models for integrated business and risk management, proactive banks may derive significant returns from a concerted enterprise approach.
15 October 2004
External Events: The Risk of Loss from Eliot...
What other risk will the financial services industry find to be more of a threat? With the latest litigation filed by the now famous Eliot Spitzer the insurance industry is in for the same treatment as Wall Street. Clean up your act.
The New York AG's suit against insurance broker Marsh & McLennan and other heavyweights may change the way the industry does business
The scrutiny of the sales process at every insurer in the country has now begun. If you have a P & C policy on your building with Marsh, it might be worth getting a competitive bid now. This is going to be another lesson in Management 101.
The New York AG's suit against insurance broker Marsh & McLennan and other heavyweights may change the way the industry does business
America's biggest insurers have found themselves in the midst of a scandal that could change the very nature of the business. On Thursday, Oct. 14, New York Attorney General Eliot Spitzer charged Marsh & McLennan (MMC ), the huge financial-services firm and world's largest insurance broker, with fraud. In a civil complaint filed in New York State Supreme Court, Spitzer alleges that the firm engaged in bid-rigging, price-fixing, and accepted payoffs from insurers. Marsh's stock has plummeted -- it opened on Oct.14 at $46.01 but is trading on Oct. 15 at around $28.20, a drop of roughly 38%.
The scrutiny of the sales process at every insurer in the country has now begun. If you have a P & C policy on your building with Marsh, it might be worth getting a competitive bid now. This is going to be another lesson in Management 101.
14 October 2004
Operational Risk driving new spending...
The latest surveys from PwC ASIA paints a rosey picture for a rise in Information Security spending.
There are four key areas driving this and 1SecureAudit has already figured this out:
Governance
Compliance
Liability
Reputation
Gartner and IDC also have some interesting predictions for growth in these areas.
Operational risks are at the heart of all of this growth, especially in ASIA where Basel II is taking hold.
About 67 per cent of information technology executives in Asia say they will increase spending on security, compared with a global average of 64 per cent in PwC's survey of 8,000 companies conducted this year.
There are four key areas driving this and 1SecureAudit has already figured this out:
Governance
Compliance
Liability
Reputation
Gartner and IDC also have some interesting predictions for growth in these areas.
Worldwide technology spending, including on telecommunications, will grow by 5.4 per cent to US$2.38 trillion (HK$18.56 trillion) this year, according to research firm Gartner.
However, global spending on business continuity and IT security solutions, at US$70 billion last year, is growing much faster, and will reach US$118 billion by 2007, according to International Data Corporation figures.
Operational risks are at the heart of all of this growth, especially in ASIA where Basel II is taking hold.
``Governance and compliance issues are driving the need for information security,'' partner Rick Heathcote said. ``In Hong Kong, we have observed that in order to comply with new laws and regulations such as Basel 2 [an international standard for capital requirements], personal data privacy laws and anti-money laundering obligations, companies are recognising the need for enhanced security and internal control.''
13 October 2004
CFO as CRO?
There seems to be some discussion on whether the CFO should also act as the Chief Risk Officer?.
Believe me, the CFO is way too focused on getting the financials right to add the equally important tasks of a CRO. The next thing they will be asked to do is take on duties associated with the CIO. This has to end.
The Board of Directors has figured this out in most savvy financial services companies already. In fact, the CRO may soon have more of a powerbase inside the executive management ranks than the Chief Financial Officer if the trend continues.
These days, however, the risk management "tent" has grown into a "big top" called enterprise risk management (ERM). To be sure, the discipline should help companies cope with natural disasters, worker injuries, lawsuits against directors and officers, and other traditionally insurable perils, according to the long-awaited ERM framework issued late last month by The Committee of Sponsoring Organizations of the Treadway Commission (COSO).
Believe me, the CFO is way too focused on getting the financials right to add the equally important tasks of a CRO. The next thing they will be asked to do is take on duties associated with the CIO. This has to end.
But there's a big obstacle on that rosy career path. If a single executive manages the potential upside as well as the possible downside of a company's moves, there's the chance that the executive's decisions might be overly biased. If the CFO/CRO is especially fond of taking risks, then the company might end up excessively exposed to disaster; if the officer is too risk-averse, opportunities could be missed.
That, apparently, was the reasoning of the Office of Federal Housing Enterprise Oversight (OFHEO) when it sharply criticized J. Timothy Howard's dual roles as CFO and CRO at Fannie Mae in a September report on the mortgage company's accounting.
The Board of Directors has figured this out in most savvy financial services companies already. In fact, the CRO may soon have more of a powerbase inside the executive management ranks than the Chief Financial Officer if the trend continues.
12 October 2004
Operational Risk Headlines...
The newspapers are full of headlines today displaying the operational risks we contend with in these volatile days ahead of the US Presidential election:
Oil Prices Reach $54, a New Record - New York Times
US seizes independent media sites - BBC News
UN watchdog concerned by disappearance of nuclear material from Iraq - UN News Centre
U.S. Subpoenas Chiron Over Flu-Shot Shortage - SmartMoney.com
Fannie Mae faces DOJ probe, 8 investor lawsuits - Reuters
Feds: Hurricanes devastated Florida's citrus crops - Ft. Wayne News Sentinel
Westar testimony will include lavish lifestyles - CNN
The Global 500 company is dealing with a myriad of operational risks. Those that have proactive risk mitigation and management systems will survive. The question now is what will happen once the new President of the United States is finally decided.
What will happen with the price of oil? The corporate governance enforcement? World Trade and Diplomacy? The only thing of certainty is that the outcome of the elections will not affect the weather. Prepare.
Oil Prices Reach $54, a New Record - New York Times
US seizes independent media sites - BBC News
UN watchdog concerned by disappearance of nuclear material from Iraq - UN News Centre
U.S. Subpoenas Chiron Over Flu-Shot Shortage - SmartMoney.com
Fannie Mae faces DOJ probe, 8 investor lawsuits - Reuters
Feds: Hurricanes devastated Florida's citrus crops - Ft. Wayne News Sentinel
Westar testimony will include lavish lifestyles - CNN
The Global 500 company is dealing with a myriad of operational risks. Those that have proactive risk mitigation and management systems will survive. The question now is what will happen once the new President of the United States is finally decided.
What will happen with the price of oil? The corporate governance enforcement? World Trade and Diplomacy? The only thing of certainty is that the outcome of the elections will not affect the weather. Prepare.
11 October 2004
IPR making headway...
The Special 301 process is gaining some new attention in the IPR battle. The WIPO conference in Geneva has also produced some new headway in fighting the spread of Intellectual Property Rights violations.
The 2004 Special 301 report has identified 34 trading partners and placed them on the watch list.
“Special 301” is the part of U.S. trade law that requires the U.S. Trade Representative (USTR) to identify countries that deny adequate protection for intellectual property rights (IPR) or that deny fair and equitable market access for U.S. persons who rely on IPR.
Under Special 301, countries that have the most egregious acts, policies, or practices, or whose acts, policies, or practices have the greatest adverse impact (actual or potential) on relevant U.S. products and are not engaged in good faith negotiations to address these problems, must be identified as “priority foreign countries.” If so identified, the country could face bilateral U.S. trade sanctions if changes are not made that address U.S. concerns.
The 2004 Special 301 report has identified 34 trading partners and placed them on the watch list.
China and Paraguay, due to their serious IP-related problems are subject to another part of the statute, Section 306 monitoring, because of previous bilateral agreements reached with the United States to address specific problems raised in earlier reports.
07 October 2004
Beyond SOX: Keeping Up with Corporate Governance Changes
Most CIOs have been intimately involved in meeting Sarbanes-Oxley (SOX) deadlines and setting up auditing reporting processes. But if you're tempted to sigh in relief as your company becomes compliant - don't. Rather, this is the time to investigate the talk you've heard of "beyond SOX." As the reality of corporate boards' new accountabilities is played out, the CIO will be highly impacted. What specifically should you be doing now to keep up with fundamental changes in corporate governance?
The five things that A.T. Kearney consultants are recommending makes some sense. The close kinship with EDS makes the items look like they are designed for a CIO. The point is that the IT organization has a tremendous responsibility to continue to try and move as fast as the business is changing. This by itself is a formidable task. The key to keeping the business in alignment with Information Systems is to make sure you have a robust Enterprise Architecture initiative.
For more on this visit: Adaptive
The five things that A.T. Kearney consultants are recommending makes some sense. The close kinship with EDS makes the items look like they are designed for a CIO. The point is that the IT organization has a tremendous responsibility to continue to try and move as fast as the business is changing. This by itself is a formidable task. The key to keeping the business in alignment with Information Systems is to make sure you have a robust Enterprise Architecture initiative.
For more on this visit: Adaptive
06 October 2004
U.K. - Insurers Threaten to Pull Terrorist Cover -Continued
In last month’s Survive newsletter Patrick Roberts commented on an interesting article in the Times about insurance companies proposing to deny cover for terrorist attacks to businesses unless they can demonstrate a satisfactory level of business continuity planning. In response to this, Peter Higgins from 1SecureAudit sent us a few thoughts from a white paper the company has written on similar subjects:
In order to introduce new changes in process or design that impacts the physical or operational aspects of critical infrastructures (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners. Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety. Consistently the conversations are not about “if” something is going to happen, it is about “where” or “when” it is going to happen. Therefore, it is imperative we initiate a proactive hedge against the inevitability of a loss event occurring in the future. First however, we must understand the character of terrorism risk in critical infrastructure and some of the anti-terrorism tools currently available to help manage that risk.
The recognition by insurers that owners will continue to invest in terrorism risk reduction and building safety with the proper incentives is vital to overall risk management of critical infrastructures. The assessment of terrorism vulnerability in key structures identified as soft targets can be a key component of the rating of risk for a specific structure. In order for owners to benefit from the potential of reduced premiums from direct insurers they must be able to demonstrate a combination of risk mitigation measures and programs to help improve the survivability of the infrastructure or to reduce it’s vulnerability to certain threat profiles. These need to be exercised on a continuous timetable with extensive documentation, training and reporting.
In order for insurance brokers to accurately represent their buyers mitigation programs and measures to the direct insurers they must have a foundation of knowledge about the structures physical vulnerabilities. However, even more essential is the understanding of the operational and human attributes of the building that are contributing to the proactive tactics to prevent losses and further exposures to potential terrorism risk. If this step takes place, the insurers can better evaluate these operational and human elements to determine the value and effectiveness of these tactics so that they can be considered for premium reductions. The building itself, two miles from the White House, has little chance of moving outside the high-risk zone for terrorist events. The only methods for reducing risk exposures are to dramatically impact the operational and human elements of the building to mitigate hazards and increase the survivability of the people and systems that are resident. Insurance losses resulting from a catastrophic events fall into several key areas:
• Property losses to the target building and adjacent structures, incurred by the owners themselves.
• Liability losses for claims due to inadequate procedures for evacuation or fire prevention incurred by building owners.
• Workers compensation, health and life insurance losses resulting from death or injury of tenants or visitors to the building.
• Business income and rent loss due to inability to occupy the structures incurred by tenants and owners.
• Financial losses by various lenders and investors in mortgage-backed securities associated with the mortgage notes themselves.
The real estate finance community and building owners associations have been subjected to a substantial debate since 9/11 about the exclusions of Terrorism Risk insurance. The real estate and lending environments in target cities such as New York, Washington, DC and Los Angeles have been in turmoil over the unavailability or terrorism risk insurance at reasonable prices.
Anti-Phishing Consortium created...A Risky Business
As the newest band of banks collaborate on Anti-Phishing strategies one can only wonder what they will do differently to mitigate this operational risk.
The banks own FDIC has also been a recent target of this social engineering trend. Hopefully they will soon find out that these attackers are not using scripts, data taps or autonomous agents as their tools. A new generation of firewall will not stop this threat. These attackers are not exploiting vulnerabilities in design, implementation or configurations of web services.
These attackers are using social engineering stategies and tactics to create the unauthorized result that they seek:
1. Increased Access
2. Disclosure of Information
3. Corruption of Information
4. Denial of Service
5. Theft of Resources
These attackers only have the following general objectives:
A. Challenge, Status, Thrill
B. Political Gain
C. Financial Gain
D. Damage
And the trend will continue to escalate as fast as new people are getting online. Think about all of the 60+ people in the world who are now moving to online banking and other e-commerce services. A whole new generation of naive kids getting on the Internet before they are in middle school are falling prey to the social engineers we sometimes call voyeurs.
It's a risk to be doing business on the web today. The strategies of these criminals have not changed. What has changed is that now they can do it from the other side of the globe in countries our own FBI will continue to have challenges getting their cooperation. This is one risk we will be living with for some time to come.
The Financial Services Technology Consortium, a financial-industry research group, said Monday that 11 financial institutions--which include Citicorp, J.P. Morgan Chase, Comerica, Visa USA, ABN Amro, KeyBank, Capital One, and University Bank--will define technical and operating requirements for counter-phishing measures, and clarify the infrastructure fit, requirements, and impact of technologies when deployed in concert with customer education, enforcement, and other industry initiatives. The consortium named Gene Neyer, managing executive of its Security Standing committee, to lead the initiative.
The banks own FDIC has also been a recent target of this social engineering trend. Hopefully they will soon find out that these attackers are not using scripts, data taps or autonomous agents as their tools. A new generation of firewall will not stop this threat. These attackers are not exploiting vulnerabilities in design, implementation or configurations of web services.
These attackers are using social engineering stategies and tactics to create the unauthorized result that they seek:
1. Increased Access
2. Disclosure of Information
3. Corruption of Information
4. Denial of Service
5. Theft of Resources
These attackers only have the following general objectives:
A. Challenge, Status, Thrill
B. Political Gain
C. Financial Gain
D. Damage
And the trend will continue to escalate as fast as new people are getting online. Think about all of the 60+ people in the world who are now moving to online banking and other e-commerce services. A whole new generation of naive kids getting on the Internet before they are in middle school are falling prey to the social engineers we sometimes call voyeurs.
It's a risk to be doing business on the web today. The strategies of these criminals have not changed. What has changed is that now they can do it from the other side of the globe in countries our own FBI will continue to have challenges getting their cooperation. This is one risk we will be living with for some time to come.
04 October 2004
CIO SOX Report Card
A recent study has found that 93% of CIO's that were polled were clueless on their Section 404 compliance responsibilities of Sarbanes-Oxley.
"What they've failed to recognize is that 30-40% of a corporation's internal controls over financial reporting are information technology specific and that CIOs and other senior IT executives have a significant role in the process," he continued. "As a result, most corporate IT executives remain in the dark about their full responsibilities, even at this late stage, placing their companies at serious risk for failure. In fact, under the guidelines, if a company's CIO does not understand Sarbanes-Oxley Section 404 requirements, that alone demonstrates a deficiency in the control system."
Sarbanes-Oxley requires issuers of financial instruments in the U.S. - including all public companies whose shares trade on U.S. stock exchanges - to identify their significant financial accounts, the business processes that support those financial accounts and the applications and IT systems that support those business processes. Companies must then document and test the adequacy and effectiveness of controls at the financial reporting level, the application level, the IT infrastructure level and the IT management level. The deadline for the majority of public companies for Section 404 compliance is December 31, 2004 .
"What they've failed to recognize is that 30-40% of a corporation's internal controls over financial reporting are information technology specific and that CIOs and other senior IT executives have a significant role in the process," he continued. "As a result, most corporate IT executives remain in the dark about their full responsibilities, even at this late stage, placing their companies at serious risk for failure. In fact, under the guidelines, if a company's CIO does not understand Sarbanes-Oxley Section 404 requirements, that alone demonstrates a deficiency in the control system."
Sarbanes-Oxley requires issuers of financial instruments in the U.S. - including all public companies whose shares trade on U.S. stock exchanges - to identify their significant financial accounts, the business processes that support those financial accounts and the applications and IT systems that support those business processes. Companies must then document and test the adequacy and effectiveness of controls at the financial reporting level, the application level, the IT infrastructure level and the IT management level. The deadline for the majority of public companies for Section 404 compliance is December 31, 2004 .
Continuity of Business: Hurricanes Lessons Learned
As the estimates come in from the losses from Florida hurricanes it looks like it will exceed $22 Billion.
The total economic impact is yet to be realized as this estimate is only the insurance claim payments estimate. Now that business has a better perspective on what being prepared really means, we should see some interesting Business Crisis and Continuity Management lessons learned here.
For example, how many organizations had their contracts in place with the diesel fuel supplier to replenish their back up generators after several days? Most prudent continuity planners would have such supplier arrangements already in place. However, if the supplier can't get to the business or their own plans have been disrupted then even the most well written contract will not hold up in the face of what happened over the course of a few weeks in Florida.
More importantly, the topic of outsourcing and redundant data centers continues to be a top strategic subject among COO's and CIO's as the operational risk events continue to surprise us. Let's just make sure that we take the time to exercise those plans and contingencies so that we go far beyond the contracts and actually test, learn and adapt.
The total economic impact is yet to be realized as this estimate is only the insurance claim payments estimate. Now that business has a better perspective on what being prepared really means, we should see some interesting Business Crisis and Continuity Management lessons learned here.
For example, how many organizations had their contracts in place with the diesel fuel supplier to replenish their back up generators after several days? Most prudent continuity planners would have such supplier arrangements already in place. However, if the supplier can't get to the business or their own plans have been disrupted then even the most well written contract will not hold up in the face of what happened over the course of a few weeks in Florida.
More importantly, the topic of outsourcing and redundant data centers continues to be a top strategic subject among COO's and CIO's as the operational risk events continue to surprise us. Let's just make sure that we take the time to exercise those plans and contingencies so that we go far beyond the contracts and actually test, learn and adapt.
30 September 2004
Operational Risk: People
After stopping by the booth at the ASIS conference in Dallas this week I'm convinced that Bruce McIndoe and his team are on to something great. Mitigating the risk of the loss of key personnel and other corporate assets is a vital priority.
iJet: ® Announces New Global Protection System
Ground-breaking Worldcue® GPS Application Employs Advanced Mapping, Notification, and Intelligence Capabilities to Better Protect Traveling Employees and Fixed Assets
Annapolis, Md - September 27, 2004 - iJET® Travel Risk Management (iJET), the industry leader in delivering real-time intelligence and proactive travel risk management services to multinational corporations and the travel industry, today introduced Worldcue® GPS, an innovative global protection system (GPS) for safeguarding people and assets, wherever they may be around the world. Worldcue® GPS employs advanced mapping, notification, and intelligence capabilities to make planning, monitoring, and crisis response more efficient and effective for those managing global risks.
"
Combining this capability with a focused surveillance and threat detection training program for employees could be exactly what our less than saavy corporate executives need. Peace of mind and to come home from their next business trip safely is the name of the game. The Threat Detection Program from 1SecureAudit provides a two day hands on course to educate and provide skills on various threats to individual security. These threats could include recruitment by a hostile service, kidnapping or assassination by terrorist and criminal elements or compromise by business competitors. Students are given intense, real-time instruction in surveillance detection and countersurveillance so that they can take appropriate actions.
Individuals whose occupations place them at risk may include people with access to valuable proprietary information or holders of high level security clearances, attorneys, judges, the wealthy and those responsible for their safety. This combination is one key strategy to mitigate the operational risks associated with key personnel in your organization.
iJet: ® Announces New Global Protection System
Ground-breaking Worldcue® GPS Application Employs Advanced Mapping, Notification, and Intelligence Capabilities to Better Protect Traveling Employees and Fixed Assets
Annapolis, Md - September 27, 2004 - iJET® Travel Risk Management (iJET), the industry leader in delivering real-time intelligence and proactive travel risk management services to multinational corporations and the travel industry, today introduced Worldcue® GPS, an innovative global protection system (GPS) for safeguarding people and assets, wherever they may be around the world. Worldcue® GPS employs advanced mapping, notification, and intelligence capabilities to make planning, monitoring, and crisis response more efficient and effective for those managing global risks.
"
Combining this capability with a focused surveillance and threat detection training program for employees could be exactly what our less than saavy corporate executives need. Peace of mind and to come home from their next business trip safely is the name of the game. The Threat Detection Program from 1SecureAudit provides a two day hands on course to educate and provide skills on various threats to individual security. These threats could include recruitment by a hostile service, kidnapping or assassination by terrorist and criminal elements or compromise by business competitors. Students are given intense, real-time instruction in surveillance detection and countersurveillance so that they can take appropriate actions.
Individuals whose occupations place them at risk may include people with access to valuable proprietary information or holders of high level security clearances, attorneys, judges, the wealthy and those responsible for their safety. This combination is one key strategy to mitigate the operational risks associated with key personnel in your organization.
29 September 2004
NFPA 1600 Tour...Will it come up short?
NFPA has announced that is has scheduled a series of workshops aimed at helping facility emergency managers understand and use NFPA 1600. The events will start in Miami in November and will be held in a dozen or so other major-city locations throughout the US over the span of a few months.
The question now is, who is going to attend and what is going to happen afterwards. A classic case of new standards and no action. The "What" known as NFPA 1600 is the new ANSI and National Fire Protection Association guidelines.
The standards are a taxonomy of common criteria for business continuity programs. In addition, it provides a list of resources within the fields of business continuity planning. Again, a worthy cause to get everyone on the same page. Now we have the "What". But do we have the "How"?
The tour is a great idea to create awareness. Now all we need to do is make sure that the owners of major infrastructure put it all into action. What needs to be done is always easier than how do it. The important step is to hire a reputable firm to guide your organization through the planning, execution and lessons learned of a Business Continuity or Disaster Recovery Exercise so that the next time it works even faster and is without major flaws.
The question now is, who is going to attend and what is going to happen afterwards. A classic case of new standards and no action. The "What" known as NFPA 1600 is the new ANSI and National Fire Protection Association guidelines.
The standards are a taxonomy of common criteria for business continuity programs. In addition, it provides a list of resources within the fields of business continuity planning. Again, a worthy cause to get everyone on the same page. Now we have the "What". But do we have the "How"?
The tour is a great idea to create awareness. Now all we need to do is make sure that the owners of major infrastructure put it all into action. What needs to be done is always easier than how do it. The important step is to hire a reputable firm to guide your organization through the planning, execution and lessons learned of a Business Continuity or Disaster Recovery Exercise so that the next time it works even faster and is without major flaws.
27 September 2004
Fannie Mae Takes New Approach in Crisis
By Jeffrey H. Birnbaum and David A. Vise
Washington Post Staff Writers
Monday, September 27, 2004; Page A01
Fannie Mae, one of Washington's largest and most influential companies, is facing a serious crisis. Federal regulators have accused the mortgage-finance giant of cooking its books, in part to make room for huge bonuses for its top executives.
When confronted with emergencies in the past -- legislative efforts to tax the company or to end federal ties that give it a competitive advantage -- Fannie Mae has used a brass-knuckles approach. Its political machine, comprised of hired lobbyists, executives and directors of both political parties and grassroots groups nurtured by donations from its foundation, has long been able to run over its adversaries.
But this time, Fannie Mae is acting differently. While whispering to Wall Street that all the fuss is nothing more than a difference over accounting interpretations, the company's board has commissioned an independent probe led by former Sen. Warren Rudman (R-N.H.), making it clear that the directors want to put the matter behind the firm even if it means throwing some top executives overboard.
'I don't think they have ever faced a crisis like this. Political muscle is not going to fix this problem,' said Washington attorney Bill Lightfoot, who tangled with Fannie Mae over tax issues while a member of the D.C. Council."
Washington Post Staff Writers
Monday, September 27, 2004; Page A01
Fannie Mae, one of Washington's largest and most influential companies, is facing a serious crisis. Federal regulators have accused the mortgage-finance giant of cooking its books, in part to make room for huge bonuses for its top executives.
When confronted with emergencies in the past -- legislative efforts to tax the company or to end federal ties that give it a competitive advantage -- Fannie Mae has used a brass-knuckles approach. Its political machine, comprised of hired lobbyists, executives and directors of both political parties and grassroots groups nurtured by donations from its foundation, has long been able to run over its adversaries.
But this time, Fannie Mae is acting differently. While whispering to Wall Street that all the fuss is nothing more than a difference over accounting interpretations, the company's board has commissioned an independent probe led by former Sen. Warren Rudman (R-N.H.), making it clear that the directors want to put the matter behind the firm even if it means throwing some top executives overboard.
'I don't think they have ever faced a crisis like this. Political muscle is not going to fix this problem,' said Washington attorney Bill Lightfoot, who tangled with Fannie Mae over tax issues while a member of the D.C. Council."
26 September 2004
Securities Industry Subject to Basel II...
Since 1999, Basel II has been coming to a bank near you in America: "At the time, the Federal Reserve announced that the top nine banks - some of which, such as JPMorgan Chase, Citigroup and Wachovia, have brokerage businesses in addition to commercial banking arms - would have to comply and adopt the advanced measurement approach for their capital adequacy requirements for credit and operational risks."
The US securities industry including firms such as Merrill, Goldman Sachs and Bear Stearns will now be subject to BASEL II under the SEC's Consolidated Supervised Entities regime. The big question is whether the smaller brokerages will adopt the same approach to operational risk as many of the smaller regional banks have done.
To improve their operational-risk-assessment capabilities, firms are targeting three initiatives, says Dushyant Shahrawat, senior analyst in TowerGroup's securities practice: upgrading core infrastructure, including building data warehouses; using integration and business-process-management technology to improve operations workflow; and exploring newer technologies such as Web services and grid computing to improve operational-risk management.
The US securities industry including firms such as Merrill, Goldman Sachs and Bear Stearns will now be subject to BASEL II under the SEC's Consolidated Supervised Entities regime. The big question is whether the smaller brokerages will adopt the same approach to operational risk as many of the smaller regional banks have done.
To improve their operational-risk-assessment capabilities, firms are targeting three initiatives, says Dushyant Shahrawat, senior analyst in TowerGroup's securities practice: upgrading core infrastructure, including building data warehouses; using integration and business-process-management technology to improve operations workflow; and exploring newer technologies such as Web services and grid computing to improve operational-risk management.
23 September 2004
DHS: Ready for Business launch today...
The Department of Homeland Security launches the Ready for Business Campaign at the US Chamber of Commerce today.
The extension of the Get Ready site for business is supported by the following organizations:
* ASIS International
* Business Executives for National Security
* The Business Roundtable
* International Safety Equipment Association
* International Security Management Association
* National Association of Manufacturers
* National Federation of Independent Business
* Society for Human Resource Management
* U.S. Chamber of Commerce
The private sector is responsible for securing the infrastructure that they own and that is vital to our nations economy. Then why haven't the large owners of commercial real estate invested in pervasive preparedness initiatives to "Get Ready" for business disruptions? The simple answer is that they don't have enough incentives to do so.
Unfortunatley for the people who happen to be tenants in the largest commercial office buildings, the landlords believe that it should be everybody for themselves. And as owners of stock in Real Estate Investment Trusts (REITS), your question should be: What is the company doing to better protect our corporate assets (buildings, malls, manufacturing plants, hospitals) from a myriad of operational risks, including catostrophic events such as tornados and terrorism?
If the DHS "Ready for Business" campaign does nothing more than get owners feeling guilty about their level of committment to preparedness, then it has done the first part of the job. The rest will be left up to business itself to demand that their leased facilities are more secure, have properly trained staff to handle incidents of any kind and exercises to test and learn on a continuous basis.
The extension of the Get Ready site for business is supported by the following organizations:
* ASIS International
* Business Executives for National Security
* The Business Roundtable
* International Safety Equipment Association
* International Security Management Association
* National Association of Manufacturers
* National Federation of Independent Business
* Society for Human Resource Management
* U.S. Chamber of Commerce
The private sector is responsible for securing the infrastructure that they own and that is vital to our nations economy. Then why haven't the large owners of commercial real estate invested in pervasive preparedness initiatives to "Get Ready" for business disruptions? The simple answer is that they don't have enough incentives to do so.
Unfortunatley for the people who happen to be tenants in the largest commercial office buildings, the landlords believe that it should be everybody for themselves. And as owners of stock in Real Estate Investment Trusts (REITS), your question should be: What is the company doing to better protect our corporate assets (buildings, malls, manufacturing plants, hospitals) from a myriad of operational risks, including catostrophic events such as tornados and terrorism?
If the DHS "Ready for Business" campaign does nothing more than get owners feeling guilty about their level of committment to preparedness, then it has done the first part of the job. The rest will be left up to business itself to demand that their leased facilities are more secure, have properly trained staff to handle incidents of any kind and exercises to test and learn on a continuous basis.
21 September 2004
Phishing: Preventive strategies
As Symantec has recently been publishing their version of the losses sustained from Phishing, the vendors are busy trying to grab market share. Preventive strategies and tools to thwart Phishing attacks are getting more mainstream as companies respond to the new threats.
All of the social engineering that goes into "Phishing" scams will heavily out maneuver the vendors new tools. The consumer is still running windows without patches and will continue to click on bogus e-mail that looks identical to the ones coming from their bank. ScamBlocker, Phishnet and the rest of them will continue to evolve yet the financial losses will continue.
The Symantec point of view is nothing new. What is interesting is the increase of the number of "bots" and other malware roaming the web:
Symantec says that phishing costs banks $1.2B. If this is true, you can bet who is paying for all of these operational losses.
All of the social engineering that goes into "Phishing" scams will heavily out maneuver the vendors new tools. The consumer is still running windows without patches and will continue to click on bogus e-mail that looks identical to the ones coming from their bank. ScamBlocker, Phishnet and the rest of them will continue to evolve yet the financial losses will continue.
The Symantec point of view is nothing new. What is interesting is the increase of the number of "bots" and other malware roaming the web:
Symantec also recorded a rise in the detection of bots -- "programs that are covertly installed on a targeted system", according to the company, allowing the hacker to control the computer remotely -- from 2,000 detections per day to more than 30,000. The number peaked at 75,000 in one day.
Symantec said malicious code also increased by more than 4.5 times the number it was in the same period in 2003, equating to over 4,496 new Windows viruses and worms, with most aimed at the Win32 operating system.
Symantec says that phishing costs banks $1.2B. If this is true, you can bet who is paying for all of these operational losses.
20 September 2004
SAS is gaining momentum...
More global companies have selected the operational risk measurement framework from SAS, and they seem to be gaining momentum in the marketplace.
The more than 10,000 loss events include events where losses were incurred due to inadequate or failed internal processes, people or systems as well as external events. These could be anything from failed hardware, forgery, embezzlement, and fraud, to natural events such as earthquakes and floods. When assessing the impact of operational risk scenarios on its business, Royal & SunAlliance will use the SAS data both in the scenario analysis process as well as a benchmark for its own internal data.
17 September 2004
1SecureAudit ORM...
Operational risk management protects and enhances shareholder value. 1SecureAudit enhances shareholder value as a primary benefit of its impact on operational risk management (ORM). Clients utilize baseline knowledge, industry experience and ORM decision support to increase operational mission effectiveness by anticipating threats/hazards and reducing the potential for loss. Change and the speed of change continue to provide a challenging environment for the entire financial and health care services industry.
Some of the key trends include:
1. Innovations in products, technology and distribution channels
2. The effect of globalization and regulatory modernization
3. The convergence of capital markets and the ever evolving pace of competition
The many challenges facing health care and financial institutions today are forcing senior management to address the totality of risks and opportunities in various lines of business and in different markets and regulatory environments. Protection of critical infrastructure assets is a Homeland Security priority.
Some of the key trends include:
1. Innovations in products, technology and distribution channels
2. The effect of globalization and regulatory modernization
3. The convergence of capital markets and the ever evolving pace of competition
The many challenges facing health care and financial institutions today are forcing senior management to address the totality of risks and opportunities in various lines of business and in different markets and regulatory environments. Protection of critical infrastructure assets is a Homeland Security priority.
16 September 2004
Flawed FAA system: Operational Risk Super-Sized
The operational risk associated with process error is a major concern these days. Especially when a human is concerned with the continuity and safety of people flying every major airline in the Southwestern U.S.. According to several reports, an FAA worker did not update a flawed FAA system that handles critical communications between controllers and pilots.
When it comes to processes and the risks associated with them, a software system flaw such as this can cause tremendous business disruption at the minimum. It's the cost of human lives that gets situations like this as much news coverage as it has garnered already. The more interesting news is that these kinds of operational incidents occur in business daily and the public will never know about it. Unless they are on the magnitude of this event. ATM's shelling out too much money. Patients being prescribed the wrong drugs. Both are errors in the systems or processes associated with running a service business. What is more alarming and still yet on the brink of discovery is how much our rush to fix Y2K problems rushed our programmers in making shortcuts, eliminating proper security code at the application level and getting the applications online at the sacrifice of good quality assurance.
Don't blame the FAA. Blame the company they hired to develop the system at the lowest bid, and the highest cost to people who are exposed to it.
The system that failed — a high-tech touch screen tool that allows air traffic controllers to quickly communicate with planes in transit — shut itself down at the Palmdale communications center shortly after 4:30 p.m. Tuesday after a worker did not complete required monthly maintenance.
Then, the backup system failed to work because technicians had rigged it improperly, FAA officials said.
When it comes to processes and the risks associated with them, a software system flaw such as this can cause tremendous business disruption at the minimum. It's the cost of human lives that gets situations like this as much news coverage as it has garnered already. The more interesting news is that these kinds of operational incidents occur in business daily and the public will never know about it. Unless they are on the magnitude of this event. ATM's shelling out too much money. Patients being prescribed the wrong drugs. Both are errors in the systems or processes associated with running a service business. What is more alarming and still yet on the brink of discovery is how much our rush to fix Y2K problems rushed our programmers in making shortcuts, eliminating proper security code at the application level and getting the applications online at the sacrifice of good quality assurance.
Don't blame the FAA. Blame the company they hired to develop the system at the lowest bid, and the highest cost to people who are exposed to it.
15 September 2004
Risk Mitigation Training in Prep for Ivan
Hey New Orleans, got Hurricane Ivan yet? RMS predicts from $4 to $10B in damages.
Business continuity plans are being exercised. People are evacuating. Now we wait for the storm surge that could put New Orleans under 20 feet of water. What about the cities North who will no doubt be experiencing tornados and other severe weather as Ivan roars across Alabama?
Hopefully the owners of buildings and critical infrastructures have provided their employees and tenants with risk mitigation training. For an example of what WTG Properties in Washington, DC has done on this very topic, see this client case. Teaming up with Operational Risk Management firm, 1SecureAudit, they provided their tenants and staff with the training, tools and resources they needed to survive a catastrophic event.
Let's just hope the owners in New Orleans have done the same to prepare for Ivan.
Business continuity plans are being exercised. People are evacuating. Now we wait for the storm surge that could put New Orleans under 20 feet of water. What about the cities North who will no doubt be experiencing tornados and other severe weather as Ivan roars across Alabama?
Hopefully the owners of buildings and critical infrastructures have provided their employees and tenants with risk mitigation training. For an example of what WTG Properties in Washington, DC has done on this very topic, see this client case. Teaming up with Operational Risk Management firm, 1SecureAudit, they provided their tenants and staff with the training, tools and resources they needed to survive a catastrophic event.
Let's just hope the owners in New Orleans have done the same to prepare for Ivan.
14 September 2004
Cyber Extortion Study is complete...
The Heinz School at Carnigie Mellon has finished it's survey on Cyber Extortion and some of it's findings are surprising.
Companies are still slow to implement preventive strategies and only 21% of the companies surveyed have formal education programs for their employees. Even more shocking is that 63% have not performed a security assessment in the last six months.
Companies are still slow to implement preventive strategies and only 21% of the companies surveyed have formal education programs for their employees. Even more shocking is that 63% have not performed a security assessment in the last six months.
Although cognizant of the most commonly perceived security threats and countermeasures, (The most common types of attacks and misuse as reported by the participants of the CSI/FBI survey were virus attacks, unauthorized access and web use by insiders, and denial of service attacks. Ibid) businesses relying on IT often do not address one of the most complex and potentially damaging exposures: Cyber-extortion.
This research has two goals: First, generate the first academically available statistics on the advent and threat of cyber extortion against small and medium sized businesses. Second, create immediately usable guidelines for organizations that may be "at risk" to extortion. The guidelines will describe the most common methods extortionists use against their targets, how to ready your information infrastructures against this, and what to do if you become a victim of extortion - regardless if you plan to work with law enforcement or not.
13 September 2004
Malicious Code: Managed Mail Protection Emerges
When the image contains text you might be vulnerable to a new scam online. This new advertising headline may soon be in vogue, Malicious Code: Managed Mail Protection Emerges.
In a new wave of phishing variants, companies like Citibank are constantly making changes in their systems to adapt to the new online threats from new malicious strategies.
"We continually modify our systems to enhance safeguards for our customers," said a spokesperson for Citibank, a unit of Citigroup Inc., in New York. "It is also important that consumers be aware of these issues and act appropriately."
While individual filtering tools from large vendors have proved largely powerless against the new threat, some security vendors are preparing help in the managed e-mail model as well.
McAfee Inc., of Santa Clara, Calif., will launch a Managed Mail Protection service for small and midsize businesses. The service, which may be extended to large enterprises in the coming months, comprises anti-spam, anti-virus and content filtering. All inbound e-mail goes through McAfee servers before it hits the customer network.
In a new wave of phishing variants, companies like Citibank are constantly making changes in their systems to adapt to the new online threats from new malicious strategies.
"We continually modify our systems to enhance safeguards for our customers," said a spokesperson for Citibank, a unit of Citigroup Inc., in New York. "It is also important that consumers be aware of these issues and act appropriately."
While individual filtering tools from large vendors have proved largely powerless against the new threat, some security vendors are preparing help in the managed e-mail model as well.
McAfee Inc., of Santa Clara, Calif., will launch a Managed Mail Protection service for small and midsize businesses. The service, which may be extended to large enterprises in the coming months, comprises anti-spam, anti-virus and content filtering. All inbound e-mail goes through McAfee servers before it hits the customer network.
11 September 2004
Third Anniversary of 9/11
As We Mark The Third Anniversary of 9/11 one can imagine how the world will be in the next three years. A globe pock marked by terrorist incidents. Russia, Malaysia are of recent headlines. How soon will the terror strike the US again? Many say before the election and only then will we have what we need to reinforce what work has already been accomplished, and will never be completed.
The people of the free world know in their hearts that the struggles of real estate and religion will continue for decades to come. Only those who are proactive, preventive and aware of the continuously changing threat will survive.
God bless us all.
The people of the free world know in their hearts that the struggles of real estate and religion will continue for decades to come. Only those who are proactive, preventive and aware of the continuously changing threat will survive.
God bless us all.
08 September 2004
PWC Study on Risk...
PricewaterhouseCoopers has found the Ten Attributes they say leads to a world class risk management organization:
They also say that reputational risk is the greatest threat in financial institutions. Phil Rivett, global leader, banking/capital markets group, PricewaterhouseCoopers said: “Financial institutions have made significant strides since our last risk management survey two years ago, but our latest findings have revealed that too many organisations are still concentrating on calculating market and credit risk to a further order of accuracy and too few on understanding the totality of the risks they face in order to give themselves a competitive advantage.
• Pay equal attention to quantifiable and unquantifiable risks
• Identify, report and quantify all possible risks
• Let an awareness of risk pervade the enterprise
• Make risk management everybody’s responsibility
• Avoid products and businesses the enterprise does not understand
• Accept that uncertainty exists
• Monitor your risk mangers
• Good risk management delivers value
• Define and enshrine your company’s risk culture.
They also say that reputational risk is the greatest threat in financial institutions. Phil Rivett, global leader, banking/capital markets group, PricewaterhouseCoopers said: “Financial institutions have made significant strides since our last risk management survey two years ago, but our latest findings have revealed that too many organisations are still concentrating on calculating market and credit risk to a further order of accuracy and too few on understanding the totality of the risks they face in order to give themselves a competitive advantage.
07 September 2004
The Wheel of Misfortune
What are some classic cases of operational risk out of control? Check out The Wheel of Misfortune.
Your organization could do the same by creating a learning tool for existing and new employees. After all, the best way to keep awareness at a high level is to consistently place reminders about lessons learned.
One of the best ways to develop risk awareness is to learn from others' mistakes. The Wheel of Misfortune contains instructive case studies of a dozen infamous financial disasters.
Each case study includes a description of the event, an analysis of what happened and exactly what went wrong, and the risk management lessons to be learned.
Your organization could do the same by creating a learning tool for existing and new employees. After all, the best way to keep awareness at a high level is to consistently place reminders about lessons learned.
03 September 2004
WPA2 standard reduces risk...
The new wireless networks in your enterprise are now becoming more secure as a result of the WPA2 standard,says the Wi-Fi Alliance.
WPA2 is ideally suited for enterprises in both the public and private sectors," said Frank Hanzlik, Wi-Fi Alliance managing director. "Products that are certified for WPA2 give IT managers the assurance that the technology meets interoperability standards and in turn helps them manage support and deployment costs."
The 802.11i standard has components of WPA2 already embedded in it and should make the enterprise Wi-Fi solutions finally worth considering on a more enterprise scale. Those organizations who have already deployed previous standards are wide open to vulnerabilities and interception of their sensitive data transmissions.
WPA2 is ideally suited for enterprises in both the public and private sectors," said Frank Hanzlik, Wi-Fi Alliance managing director. "Products that are certified for WPA2 give IT managers the assurance that the technology meets interoperability standards and in turn helps them manage support and deployment costs."
The 802.11i standard has components of WPA2 already embedded in it and should make the enterprise Wi-Fi solutions finally worth considering on a more enterprise scale. Those organizations who have already deployed previous standards are wide open to vulnerabilities and interception of their sensitive data transmissions.
02 September 2004
The summer of 2004...
The Terrorism Risk Insurance business is on the rise according to a recent Marsh Report on Terrorism Risk. The percentage of policy holders who buy terror coverage increased from 44% to 46% by midyear.
In November 2002, President Bush signed the Terrorism Risk Insurance Act (TRIA) into law. TRIA made it illegal for providers of property & casualty (P&C) insurance to exclude terrorism coverage in their policies. Still, the act did not specify how much insurers could charge for the coverage, and as a result, the price for TRIA coverage varied greatly.
The summer of 2004 will continue to be a prime window for the “What if” discussions of potential terrorist attacks on United States assets located domestically or abroad. It is important to remember several key items as we move into more proactive, preventive and preparedness modes within our global organizations and U.S. based business communities.
The soft targets for these catastrophic plans by our terrorist enemies will continue to focus on the places, events and structures that will provide the most impact, both in loss of life and the long-term economic impact. Based on analysis by RMS in their latest Catastrophe, Injury and Insurance study, the study looks at those cities with the highest density of population at 2:00PM. In the RMS report, New York, Chicago and Washington DC are the top three cities in the US for potential impact of a terrorist incident. San Francisco, Boston, Philadelphia and Los Angeles are next in the line up of populations that are the highest density within several miles of the city center.
The five factors for anti-terrorism threat analysis are Existence, Capability, History, Intention and Targeting. Further defined as follows:
1. Who is hostile to the asset?
2. What tools/weapons have been used in carrying out past attacks?
3. What has the threat element done in the past and how many times?
4. What does the potential threat element or aggressor hope to achieve?
5. Do we know if an aggressor is performing surveillance on our building / asset?
When answering these questions for your particular building, city, business park or community you should keep in mind the goal of our attackers. They want to do the most harm to the most number of people for the longest period of time. While we may not be able to totally prevent a planned incident from happening, we can reduce the impact on our personnel, property and business operations.
In November 2002, President Bush signed the Terrorism Risk Insurance Act (TRIA) into law. TRIA made it illegal for providers of property & casualty (P&C) insurance to exclude terrorism coverage in their policies. Still, the act did not specify how much insurers could charge for the coverage, and as a result, the price for TRIA coverage varied greatly.
The summer of 2004 will continue to be a prime window for the “What if” discussions of potential terrorist attacks on United States assets located domestically or abroad. It is important to remember several key items as we move into more proactive, preventive and preparedness modes within our global organizations and U.S. based business communities.
The soft targets for these catastrophic plans by our terrorist enemies will continue to focus on the places, events and structures that will provide the most impact, both in loss of life and the long-term economic impact. Based on analysis by RMS in their latest Catastrophe, Injury and Insurance study, the study looks at those cities with the highest density of population at 2:00PM. In the RMS report, New York, Chicago and Washington DC are the top three cities in the US for potential impact of a terrorist incident. San Francisco, Boston, Philadelphia and Los Angeles are next in the line up of populations that are the highest density within several miles of the city center.
The five factors for anti-terrorism threat analysis are Existence, Capability, History, Intention and Targeting. Further defined as follows:
1. Who is hostile to the asset?
2. What tools/weapons have been used in carrying out past attacks?
3. What has the threat element done in the past and how many times?
4. What does the potential threat element or aggressor hope to achieve?
5. Do we know if an aggressor is performing surveillance on our building / asset?
When answering these questions for your particular building, city, business park or community you should keep in mind the goal of our attackers. They want to do the most harm to the most number of people for the longest period of time. While we may not be able to totally prevent a planned incident from happening, we can reduce the impact on our personnel, property and business operations.
01 September 2004
Frances Slams Allstate's stock
Frances Slams Allstate's stock upon fears that the hurricane is going to make landfall any day in Florida.
Shares of Allstate Corp., Ace Ltd. and other insurers fell today as Hurricane Frances approached the Florida coast, threatening to become the second storm packing 140- mile-per-hour winds to hit the state in three weeks.
The impact to the bottom line goes far beyond just the claims by it's customers. In this case, the institutional investors are taking a profit after a 50% increase over the past 18 months.
The other possibility is that they may already be "stretched" after hurricane Charley. Should Frances make landfall in Florida with its current wind strength, it would mark the first time since 1915 that two storms of that magnitude hit the U.S. in the same year, the Miami- based hurricane center's data show.
Shares of Allstate Corp., Ace Ltd. and other insurers fell today as Hurricane Frances approached the Florida coast, threatening to become the second storm packing 140- mile-per-hour winds to hit the state in three weeks.
The impact to the bottom line goes far beyond just the claims by it's customers. In this case, the institutional investors are taking a profit after a 50% increase over the past 18 months.
The other possibility is that they may already be "stretched" after hurricane Charley. Should Frances make landfall in Florida with its current wind strength, it would mark the first time since 1915 that two storms of that magnitude hit the U.S. in the same year, the Miami- based hurricane center's data show.
30 August 2004
Corporations can learn ORM from the US Navy
What is it that corporate management and the US Navy have in common? Corporations can learn ORM from the US Navy principles to earn top safety honors and contribute to mission success.
This is just one example of how the US miltary is using the effectiveness of Operational Risk Management to mitigate the risk of hazards on the job and to ensure the safety of fellow team mates on the job.
“It was evident the first time I came on board and saw the crew’s attention to detail and dedication to their work,” said Capt. Mike D. Budney, commanding officer, Emory S. Land. “But it’s remarkable to note that with the tremendous day-to-day operations, no serious safety mishaps occurred.”
“With a crew this size and the never-ending upkeep that takes place, safety is and will always be our number one priority,” Budney added. “Our Sailors know that and are living proof. I am extremely proud of them!”
While safety is paramount on every ship and submarine in the fleet, these submariners know that safety is not about winning awards, it’s about managing risk to avoid injuries and possible loss of life.
This is just one example of how the US miltary is using the effectiveness of Operational Risk Management to mitigate the risk of hazards on the job and to ensure the safety of fellow team mates on the job.
“It was evident the first time I came on board and saw the crew’s attention to detail and dedication to their work,” said Capt. Mike D. Budney, commanding officer, Emory S. Land. “But it’s remarkable to note that with the tremendous day-to-day operations, no serious safety mishaps occurred.”
“With a crew this size and the never-ending upkeep that takes place, safety is and will always be our number one priority,” Budney added. “Our Sailors know that and are living proof. I am extremely proud of them!”
While safety is paramount on every ship and submarine in the fleet, these submariners know that safety is not about winning awards, it’s about managing risk to avoid injuries and possible loss of life.
27 August 2004
The next very long war....Cyber Terror
"The Internet is the bold new frontier of crime, but we're the new sheriff in town. For cyber criminals who operate out of Los Angeles or any location around the globe, this posse will bring you to justice," said United States Attorney Debra Wang.
The Six Cyber Terrorists arrested by the US DOJ have set the stage for a long and evasive war. The hope is that the private sector will begin to share more information with the feds to get to the big fish, but this will take time, money and lot's of cooperation with our global partners. China, Korea(s) and the Russian states are the sources of many of our DoS attacks and while we know who they are it is difficult to navigate international laws and jurisdictions.
The good news is that the private sector is working more closely with InfraGard and the 12,000+ members who are helping to protect our critical infrastructures. Money is being allocated to specialized enforcement teams to assist the US Attorney's in doing their jobs more effectively.
It's just going to be a very long war that has to be fought every single day.
The Six Cyber Terrorists arrested by the US DOJ have set the stage for a long and evasive war. The hope is that the private sector will begin to share more information with the feds to get to the big fish, but this will take time, money and lot's of cooperation with our global partners. China, Korea(s) and the Russian states are the sources of many of our DoS attacks and while we know who they are it is difficult to navigate international laws and jurisdictions.
The good news is that the private sector is working more closely with InfraGard and the 12,000+ members who are helping to protect our critical infrastructures. Money is being allocated to specialized enforcement teams to assist the US Attorney's in doing their jobs more effectively.
It's just going to be a very long war that has to be fought every single day.
25 August 2004
Share Price: A Factor of Corporate Governance?
Corporate Governance is good for the bottom line but even Google hasn't found this out...yet. Their recent coporate governance quotient is 0.2 out of 100.
But, as Ric Marshall, chief analyst for the Corporate Library, notes, it's not necessarily a bad thing. "There is this tendency to dumb things down by making all boards look the same,'' Marshall told the San Francisco Chronicle. "By doing something different and unconventional -- in terms of how the IPO has gone, the multiple share classes, the makeup of the board -- Google is creating something that is different and unusual. Good corporate governance is the creative interaction between directors on the board. What concerns me is the ethics of the people involved and their ability to be creative."
But, as Ric Marshall, chief analyst for the Corporate Library, notes, it's not necessarily a bad thing. "There is this tendency to dumb things down by making all boards look the same,'' Marshall told the San Francisco Chronicle. "By doing something different and unconventional -- in terms of how the IPO has gone, the multiple share classes, the makeup of the board -- Google is creating something that is different and unusual. Good corporate governance is the creative interaction between directors on the board. What concerns me is the ethics of the people involved and their ability to be creative."
24 August 2004
Real Estate: Antiterrorism Laws
Is the commercial real esate industry subject to our latest antiterrorism laws?
See the viewpoints of two legal eagles from Holland & Knight in the DC area on this very topic.
Executive Order 13224 and the prohibited parties list of the Office of Foreign Assets Control (OFAC) is in effect now. It has civil and criminal penalties.
The Money Laundering Control Act, a criminal statute, is in effect now.
The USA PATRIOT Act/Bank Secrecy Act, which requires certain anti-money laundering compliance activities, will result in regulations directly affecting the real estate industry within a matter of months.
See the viewpoints of two legal eagles from Holland & Knight in the DC area on this very topic.
18 August 2004
H.R. 1731 Identity Theft Law
The identity theft penalty enhancement act expands the capabilities of the Justice Department to investigate I.D. theft. See the synopsis here at CSO Online. I.D. theft is one way for the terrorists to keep themselves hidden in the US for a long period of time. It will also help in credit card fraud cases.
17 August 2004
Increased Regulatory Scrutiny for Bank INFOSEC
Banks INFOSEC departments have increasing roles in audits. The Information Security departments must have a systematic program for managing risk in their day to day operations as regulatory requirements for business overlap.
Comprehensive risk management programs are being broadened to encompass operational risk in many banking institutions. This is due to the increasing prevalence of legislation such as Gramm-Leach-Bliley (GLBA) and even sections of Sarbanes-Oxley. The convergence of information security and business is finally making it apparent that the two are very much inseparable.
Comprehensive risk management programs are being broadened to encompass operational risk in many banking institutions. This is due to the increasing prevalence of legislation such as Gramm-Leach-Bliley (GLBA) and even sections of Sarbanes-Oxley. The convergence of information security and business is finally making it apparent that the two are very much inseparable.
13 August 2004
Survey identifies main stumbling blocks to successful operational risk management
Survey identifies main stumbling blocks to successful operational risk management:
Difficulties in collating clean data and poor awareness among staff are the major obstacles to effective operational risk management, according to a recent survey by Risk Waters Group and SAS.
The survey of more than 250 financial institutions and regulators identified managing data quality as the number one issue, with respondents reporting difficulties in collating sufficient volumes of historical data and in ensuring reliable data. The second most pressing issue was the poor overall awareness of operational risk issues by staff, due largely to lack of clear education programs in operational risk, lack of communication and limited knowledge sharing.
Regulations such as Basel II place a growing emphasis on operational risk management within financial institutions. Banks are compelled to gather data that they do not currently collect; they are also required to bring that data together from a host of disparate systems into one pool for analysis.
'The two key barriers to financial institutions achieving success relate to basic issues such as data quality and awareness amongst staff. A basic lack of awareness amongst staff often results in insufficient data being collected,' said Peyman Mestchian, head of the risk management practice, SAS UK.
'Employees may not always report losses and therefore impact the accuracy of data available. They need to be educated to a level where they are providing consistent information therefore improving data accuracy. Organisations can use the most sophisticated analytical tools in the world, however if they are not working with comprehensive, real-world data they will miss the real dangers. Inconsistent and inaccurate data will only provide problems and create disagreements. These issues need to be addressed as a matter of some urgency, particularly with latest draft of the New Basel Accord (Basel II) published in June,' continued Mestchian.
To comply with new regulations, organisations require systems that are both scalable and flexible. Systems need to combine qualitative and quantitative data and be able to link external data with internal data. Yet for many having the correct systems in place is still a major challenge.
Survey respondents ranked IT systems failure as the main source of operational risk. An area of growing importance was identified as customer relationship risk, with regulatory and compliance issues (including taxation) third."
Difficulties in collating clean data and poor awareness among staff are the major obstacles to effective operational risk management, according to a recent survey by Risk Waters Group and SAS.
The survey of more than 250 financial institutions and regulators identified managing data quality as the number one issue, with respondents reporting difficulties in collating sufficient volumes of historical data and in ensuring reliable data. The second most pressing issue was the poor overall awareness of operational risk issues by staff, due largely to lack of clear education programs in operational risk, lack of communication and limited knowledge sharing.
Regulations such as Basel II place a growing emphasis on operational risk management within financial institutions. Banks are compelled to gather data that they do not currently collect; they are also required to bring that data together from a host of disparate systems into one pool for analysis.
'The two key barriers to financial institutions achieving success relate to basic issues such as data quality and awareness amongst staff. A basic lack of awareness amongst staff often results in insufficient data being collected,' said Peyman Mestchian, head of the risk management practice, SAS UK.
'Employees may not always report losses and therefore impact the accuracy of data available. They need to be educated to a level where they are providing consistent information therefore improving data accuracy. Organisations can use the most sophisticated analytical tools in the world, however if they are not working with comprehensive, real-world data they will miss the real dangers. Inconsistent and inaccurate data will only provide problems and create disagreements. These issues need to be addressed as a matter of some urgency, particularly with latest draft of the New Basel Accord (Basel II) published in June,' continued Mestchian.
To comply with new regulations, organisations require systems that are both scalable and flexible. Systems need to combine qualitative and quantitative data and be able to link external data with internal data. Yet for many having the correct systems in place is still a major challenge.
Survey respondents ranked IT systems failure as the main source of operational risk. An area of growing importance was identified as customer relationship risk, with regulatory and compliance issues (including taxation) third."
11 August 2004
Summer in the City: Unconventional Insurance and Olympian Security in Age of Terrorism Risk
Summer in the City: Unconventional Insurance and Olympian Security in Age of Terrorism Risk:
By Andrew G. Simpson, Jr.
A little more than a year ago, Britain's Prince William celebrated his 21st birthday with a costume party at Windsor Castle. While William was addressing the partying crowd, a stranger wearing a black beard, white turban and pink dress and looking a lot like Osama bin Laden bounded onto the stage, grabbed the microphone, spoke to the crowd and then planted a kiss on Prince William's cheek.
Despite the fact that the Osama look-alike was a comedian, few thought it a laughing matter. If the intruder had been a suicide bomber he could have killed all the senior members of the royal family who were onstage with William. British security forces were promptly taken to task for allowing the stranger to get so close. Immediate steps were taken to beef up security surrounding the royal family.
Summer Security
This summer, while the world is watching the Democratic National Convention (DNC) in Boston, the Republican National Convention (RNC) in New York City and the 2004 Olympic Games in Athens, security forces will be on full alert to prevent breaches like the one that concerned British security a year ago. In Boston, New York and Athens, officials maintain that every precaution is being taken to protect the participants and properties at these events from a close encounter with terrorism."
By Andrew G. Simpson, Jr.
A little more than a year ago, Britain's Prince William celebrated his 21st birthday with a costume party at Windsor Castle. While William was addressing the partying crowd, a stranger wearing a black beard, white turban and pink dress and looking a lot like Osama bin Laden bounded onto the stage, grabbed the microphone, spoke to the crowd and then planted a kiss on Prince William's cheek.
Despite the fact that the Osama look-alike was a comedian, few thought it a laughing matter. If the intruder had been a suicide bomber he could have killed all the senior members of the royal family who were onstage with William. British security forces were promptly taken to task for allowing the stranger to get so close. Immediate steps were taken to beef up security surrounding the royal family.
Summer Security
This summer, while the world is watching the Democratic National Convention (DNC) in Boston, the Republican National Convention (RNC) in New York City and the 2004 Olympic Games in Athens, security forces will be on full alert to prevent breaches like the one that concerned British security a year ago. In Boston, New York and Athens, officials maintain that every precaution is being taken to protect the participants and properties at these events from a close encounter with terrorism."
10 August 2004
A Radical Leap in Trust...A Security Lesson
The other day I received a package in the mail from Fast Company Magazine. I opened the brown padded envelope with the "Security Radar" that this looked like a questionable package. You know, the kind that they warn you about these days. The label looks like it was created by a 4th grader and the package is about a half inch thick and weighs in at about a pound and a half. Could this be the work of a clever "Social Engineer" who knows my modus operandi?
So I held my breath and opened it with great anticipation and fear at the same time. I had no idea it was coming. It's contents was not surprising. A book. A note. And a business card. The card was that of Heath Row, Fast Company Editorial and Community Director. Former Social Capitalist before the uprising. The Book was entitled The Radical Leap, by Steve Farber. The note from the publisher offering 40% off the retail price with orders of ten or more.
The real radical leap on this day was my faith in the label Fast Company. My vulnerability had been exploited by someone known to me. My trust in FC and the brand prompted me to forget everything I have been taught about suspicious packages like this one. Now I'm practicing LEAP every day. Cultivate Love. Generate Energy. Inspire Audacity, and Provide Proof. The lesson here is simple. A radical leap in trust can sometimes blind us from clear thinking. Be careful out there.
So I held my breath and opened it with great anticipation and fear at the same time. I had no idea it was coming. It's contents was not surprising. A book. A note. And a business card. The card was that of Heath Row, Fast Company Editorial and Community Director. Former Social Capitalist before the uprising. The Book was entitled The Radical Leap, by Steve Farber. The note from the publisher offering 40% off the retail price with orders of ten or more.
The real radical leap on this day was my faith in the label Fast Company. My vulnerability had been exploited by someone known to me. My trust in FC and the brand prompted me to forget everything I have been taught about suspicious packages like this one. Now I'm practicing LEAP every day. Cultivate Love. Generate Energy. Inspire Audacity, and Provide Proof. The lesson here is simple. A radical leap in trust can sometimes blind us from clear thinking. Be careful out there.
06 August 2004
Dangerous Waters
Dangerous Waters: "
Distributed denial-of-service attacks may reshape the way courts evaluate liability for network security breaches.
BY WILLIAM COOK
Distributed denial-of-service (DDOS) attacks—the creation of a hostile computer network used to remotely shut down another network or website—continue to plague the Internet. In the past two years the Internet has experienced a 2,000 percent increase in worm-driven DDOS attacks. Some e-commerce websites have been completely shut down by the attacks and have reported as much as $250,000 in lost sales per half hour that they were down. But the damage doesn't stop there. The users of a victimized system can also suffer significant reputational loss from being unable to conduct business.
However, the legal response to DDOS attacks has been mixed. In the U.S. legal system, civil liability can arise from contract law, tort law or regulation. If one party breaches its contractual obligations, the law provides a remedy to the aggrieved party. Contract law, however, often fails to cover damage to third parties. Suppose a hacker breaks into Company A's inadequately secured network and then uses that network to attack Company B. The attack against Company B disables its networks, causing it to fail to deliver promised services to its customers. Although Company B has no contractual relationship with Company A, can B sue A for losses?
From a tort standpoint, many legal scholars, major law firms and a National Research Council Committee assert that the downstream victim can bring civil action for negligence against the upstream systems that were used as part of the DDOS attack. Reasoning that civil law intends to deter undesirable or wrongful conduct and to compensate those harmed by such conduct, legal theory posits that victims should be allowed to recover losses from third parties that were negligent if that negligence was the direct cause of the loss. In the Internet environment, negligent third parties may be the only source of loss recovery, since criminal law offers no compensation to the victim if the computer criminal cannot be identified. Furthermore, establishing the legal precedent to impose civil damages on a third party, such as a service provider that is proven to be negligent, could motivate companies to invest the necessary resources in improving security.
Distributed denial-of-service attacks may reshape the way courts evaluate liability for network security breaches.
BY WILLIAM COOK
Distributed denial-of-service (DDOS) attacks—the creation of a hostile computer network used to remotely shut down another network or website—continue to plague the Internet. In the past two years the Internet has experienced a 2,000 percent increase in worm-driven DDOS attacks. Some e-commerce websites have been completely shut down by the attacks and have reported as much as $250,000 in lost sales per half hour that they were down. But the damage doesn't stop there. The users of a victimized system can also suffer significant reputational loss from being unable to conduct business.
However, the legal response to DDOS attacks has been mixed. In the U.S. legal system, civil liability can arise from contract law, tort law or regulation. If one party breaches its contractual obligations, the law provides a remedy to the aggrieved party. Contract law, however, often fails to cover damage to third parties. Suppose a hacker breaks into Company A's inadequately secured network and then uses that network to attack Company B. The attack against Company B disables its networks, causing it to fail to deliver promised services to its customers. Although Company B has no contractual relationship with Company A, can B sue A for losses?
From a tort standpoint, many legal scholars, major law firms and a National Research Council Committee assert that the downstream victim can bring civil action for negligence against the upstream systems that were used as part of the DDOS attack. Reasoning that civil law intends to deter undesirable or wrongful conduct and to compensate those harmed by such conduct, legal theory posits that victims should be allowed to recover losses from third parties that were negligent if that negligence was the direct cause of the loss. In the Internet environment, negligent third parties may be the only source of loss recovery, since criminal law offers no compensation to the victim if the computer criminal cannot be identified. Furthermore, establishing the legal precedent to impose civil damages on a third party, such as a service provider that is proven to be negligent, could motivate companies to invest the necessary resources in improving security.
04 August 2004
IT Spending for Compliance: From SOX 404 to Comprehensive Compliance
IT Spending for Compliance: From SOX 404 to Comprehensive Compliance:
Financial Insights estimates that North American financial institutions spent over $100 million on enterprise performance management solutions in the U.S. and Canada in 2003. This number will grow to $174 million in 2004 and will reach $450 million 2008.
Beyond Sarbanes-Oxley, Comprehensive Compliance
Given the similarities in the applications and infrastructure components required to comply with new regulations impacting financial services firms, including the PATRIOT Act and Basel II, we estimate that a key long-term trend in the market for compliance solutions will be application and infrastructure integration.
On the infrastructure side, we foresee that the data infrastructure supporting compliance activities will become more and more integrated through data warehouses or through applications that can connect to disparate sources. On the application side, we are already seeing firms invest in solutions that meet both anti-money laundering requirements prescribed by the PATRIOT Act as well as SEC and Sarbanes-Oxley-related requirements to monitor for internal fraud and for compliance breaches with securities laws. Investments in such AML/Surveillance solutions have been particularly strong among securities firms.
Specific to Sarbanes-Oxley compliance, we estimate that SOX 404 solutions will become more and more integrated with enterprise performance management applications to facilitate the regulatory reporting process.
Integration will take time. Technologically, it is already here today and IT vendors have been ready with partnerships and attractive solutions. Culturally and organizationally, it is not. Financial services firms have much internal work to do before they can begin to combine disparate compliance processes. Until this time, investments in IT for compliance will continue to remain focused on specific regulations. "
Financial Insights estimates that North American financial institutions spent over $100 million on enterprise performance management solutions in the U.S. and Canada in 2003. This number will grow to $174 million in 2004 and will reach $450 million 2008.
Beyond Sarbanes-Oxley, Comprehensive Compliance
Given the similarities in the applications and infrastructure components required to comply with new regulations impacting financial services firms, including the PATRIOT Act and Basel II, we estimate that a key long-term trend in the market for compliance solutions will be application and infrastructure integration.
On the infrastructure side, we foresee that the data infrastructure supporting compliance activities will become more and more integrated through data warehouses or through applications that can connect to disparate sources. On the application side, we are already seeing firms invest in solutions that meet both anti-money laundering requirements prescribed by the PATRIOT Act as well as SEC and Sarbanes-Oxley-related requirements to monitor for internal fraud and for compliance breaches with securities laws. Investments in such AML/Surveillance solutions have been particularly strong among securities firms.
Specific to Sarbanes-Oxley compliance, we estimate that SOX 404 solutions will become more and more integrated with enterprise performance management applications to facilitate the regulatory reporting process.
Integration will take time. Technologically, it is already here today and IT vendors have been ready with partnerships and attractive solutions. Culturally and organizationally, it is not. Financial services firms have much internal work to do before they can begin to combine disparate compliance processes. Until this time, investments in IT for compliance will continue to remain focused on specific regulations. "
03 August 2004
Recovery Point provides comprehensive, availability end-user hotsite recovery services
Recovery Point
Recovery Point Systems provides comprehensive, availability end-user hotsite recovery services for mission critical, business continuity conscious clients to implement disaster recovery plans including server mirroring, serverhosting, electronic vaulting, workgroup recovery, off-site storage and co-location.
"The replacement facilities on which you stake your organization's ability to survive during a crisis must function smoothly and reliably. We've built redundancy and durability into every critical component of the site so you can rely on our high availability services every day.
* Secure facility with CCTV, access control and 365-day staffing 100 acoustical workspaces with locking storage, expandable to 200
* Owner-occupied site with private parking
* Convenient to major highway, rail and air transportation
* All weather, voice/data 'hitching post' for connectivity to mobile technologies
* Dual diverse fiber feeds via SONET self-healing ring to redundant central offices
* Full UPS support for entire recovery center
* Secure server and telecommunications facilities
* Redundant generator power, ATS and seven-day fuel supply
* Redundant HVAC services
* Full truck loading facilities to support client re-supply during occupancy
* Conference room with satellite TV feed and video-conferencing
* kitchenette, strategy room and six semi-private offices
* UL master building label for lightning protection
Recovery Point Systems is an affiliate of First Federal Corporation, the Baltimore-Washington DC region's leading provider of secure, off-site data storage services for over 20 years. We have the experience, the staff and the resources to meet your recovery requirements in today's complex environment."
Recovery Point Systems provides comprehensive, availability end-user hotsite recovery services for mission critical, business continuity conscious clients to implement disaster recovery plans including server mirroring, serverhosting, electronic vaulting, workgroup recovery, off-site storage and co-location.
"The replacement facilities on which you stake your organization's ability to survive during a crisis must function smoothly and reliably. We've built redundancy and durability into every critical component of the site so you can rely on our high availability services every day.
* Secure facility with CCTV, access control and 365-day staffing 100 acoustical workspaces with locking storage, expandable to 200
* Owner-occupied site with private parking
* Convenient to major highway, rail and air transportation
* All weather, voice/data 'hitching post' for connectivity to mobile technologies
* Dual diverse fiber feeds via SONET self-healing ring to redundant central offices
* Full UPS support for entire recovery center
* Secure server and telecommunications facilities
* Redundant generator power, ATS and seven-day fuel supply
* Redundant HVAC services
* Full truck loading facilities to support client re-supply during occupancy
* Conference room with satellite TV feed and video-conferencing
* kitchenette, strategy room and six semi-private offices
* UL master building label for lightning protection
Recovery Point Systems is an affiliate of First Federal Corporation, the Baltimore-Washington DC region's leading provider of secure, off-site data storage services for over 20 years. We have the experience, the staff and the resources to meet your recovery requirements in today's complex environment."
02 August 2004
Bush Backs Creating U.S. Antiterrorism Chief
Bush Backs Creating U.S. Antiterrorism Chief
By Frank Csongos
The United States is planning to undertake new measures to fight the Al-Qaeda network and its allies.
Washington, 2 August 2004 (RFE/RL) -- U.S. President George W. Bush has endorsed creating the position of a national intelligence director to oversea the United States' domestic- and foreign-intelligence operations in combating terrorism.
Bush, speaking at the White House today, said the new intelligence chief would be appointed by the president and subject to confirmation by the U.S. Senate.
'The national intelligence director will serve as the president's principal intelligence adviser and will oversee and coordinate the foreign and domestic activities of the intelligence community,' Bush said.
The president said the reorganization of U.S. intelligence services is aimed at creating a better integrated, thoroughly united, and more efficient antiterrorism operation.
The new post was among the recommendations of the official commission that investigated lapses in intelligence that left the United States vulnerable to the 11 September 2001 terrorist attacks.
'The best way to protect the American homeland is to stay on the offense.' -- Bush
'Oversight of intelligence and of...homeland security must be restructured and made more effective,' Bush said. 'There are too many committees with overlapping jurisdiction, which wastes time and makes it difficult for meaningful oversight and reform.'
Bush also adopted another key recommendation of the 9-11 commission -- that of creating a National Counterterrorism Center.
'This new center will build on the analytical work -- the really good analytical work -- of the Terrorist Threat Integration Center and will become our government's knowledge bank for information about known and suspected terrorists,' Bush said. 'The new center will coordinate and monitor counterterrorism plans and activities of all government agencies and departments.'
Leaders of the bipartisan 9-11 commission have insisted that the center and the position of national-intelligence director be placed in the executive office of the president. But Bush said he wants them to be set up outside the White House.
The president said the director and the center should be a 'stand- alone group' to better coordinate.
Bush also dismissed critics who said the war on Iraq has detracted U.S. efforts to fight terrorism.
'The best way to protect the American homeland is to stay on the offense. It is a ridiculous notion to assert that because the United States is on the offense, more people want to hurt us,' Bush said.
Under the reorganization, the Central Intelligence Agency would be managed by a separate director. The national-intelligence director would assume greater responsibility for leading and coordinating intelligence operations both inside and outside the United States.
The president's endorsement for the new post came after U.S. law enforcement authorities strengthened security at financial institutions in New York City; Washington, D.C.; and Newark, New Jersey, following what the U.S. government called extraordinary specific terror threats."
By Frank Csongos
The United States is planning to undertake new measures to fight the Al-Qaeda network and its allies.
Washington, 2 August 2004 (RFE/RL) -- U.S. President George W. Bush has endorsed creating the position of a national intelligence director to oversea the United States' domestic- and foreign-intelligence operations in combating terrorism.
Bush, speaking at the White House today, said the new intelligence chief would be appointed by the president and subject to confirmation by the U.S. Senate.
'The national intelligence director will serve as the president's principal intelligence adviser and will oversee and coordinate the foreign and domestic activities of the intelligence community,' Bush said.
The president said the reorganization of U.S. intelligence services is aimed at creating a better integrated, thoroughly united, and more efficient antiterrorism operation.
The new post was among the recommendations of the official commission that investigated lapses in intelligence that left the United States vulnerable to the 11 September 2001 terrorist attacks.
'The best way to protect the American homeland is to stay on the offense.' -- Bush
'Oversight of intelligence and of...homeland security must be restructured and made more effective,' Bush said. 'There are too many committees with overlapping jurisdiction, which wastes time and makes it difficult for meaningful oversight and reform.'
Bush also adopted another key recommendation of the 9-11 commission -- that of creating a National Counterterrorism Center.
'This new center will build on the analytical work -- the really good analytical work -- of the Terrorist Threat Integration Center and will become our government's knowledge bank for information about known and suspected terrorists,' Bush said. 'The new center will coordinate and monitor counterterrorism plans and activities of all government agencies and departments.'
Leaders of the bipartisan 9-11 commission have insisted that the center and the position of national-intelligence director be placed in the executive office of the president. But Bush said he wants them to be set up outside the White House.
The president said the director and the center should be a 'stand- alone group' to better coordinate.
Bush also dismissed critics who said the war on Iraq has detracted U.S. efforts to fight terrorism.
'The best way to protect the American homeland is to stay on the offense. It is a ridiculous notion to assert that because the United States is on the offense, more people want to hurt us,' Bush said.
Under the reorganization, the Central Intelligence Agency would be managed by a separate director. The national-intelligence director would assume greater responsibility for leading and coordinating intelligence operations both inside and outside the United States.
The president's endorsement for the new post came after U.S. law enforcement authorities strengthened security at financial institutions in New York City; Washington, D.C.; and Newark, New Jersey, following what the U.S. government called extraordinary specific terror threats."
01 August 2004
Secretary Ridge Announces Threat Level Code Orange for Financial Sector in New York City, Northern New Jersey and Washington, D.C.
DHS | Department of Homeland Security | DHS Home Page:
August 1, 2004 - Good afternoon. President Bush has told you, and I have told you, when we have specific credible information, we will share it.
This afternoon, we do have new and unusually specific information about where al Qaida would like to attack. As a result, today, the United States Government is raising the threat level to Code Orange for the financial services sector in New York City, Northern New Jersey and Washington, D.C.
Since September 11th, 2001, leaders of our commercial financial institutions have demonstrated exceptional leadership in improving its security. However, in light of new intelligence information, we have made the decision to raise the threat level for this sector, in these communities, to bring protective resources to their highest capacity. This will allow us to increase protection in and around those buildings that require it and also raise awareness for employees, residents, customers and visitors. We know from experience that increased physical protection and added vigilance from citizens can thwart a terrorist attack. And that is our goal.
This is the first time we have chosen to use the Homeland Security Advisory System in such a targeted way. Compared to previous threat reporting, these intelligence reports have provided a level of detail that is very specific. The quality of this intelligence, based on multiple reporting streams in multiple locations, is rarely seen and is alarming in both the amount and specificity of the information.
While we are providing you with this immediate information, we will continue to update you as the situation unfolds. As of now, this is what we know: reports indicate that al Qaida is targeting several specific buildings, including the International Monetary Fund and World Bank in D.C.; Prudential Financial in Northern New Jersey; and Citigroup buildings and the New York Stock Exchange in New York. Let me assure you, actions to further strengthen security around these buildings are already underway. Additionally, we’re concerned about targets beyond these and are working to get more information."
August 1, 2004 - Good afternoon. President Bush has told you, and I have told you, when we have specific credible information, we will share it.
This afternoon, we do have new and unusually specific information about where al Qaida would like to attack. As a result, today, the United States Government is raising the threat level to Code Orange for the financial services sector in New York City, Northern New Jersey and Washington, D.C.
Since September 11th, 2001, leaders of our commercial financial institutions have demonstrated exceptional leadership in improving its security. However, in light of new intelligence information, we have made the decision to raise the threat level for this sector, in these communities, to bring protective resources to their highest capacity. This will allow us to increase protection in and around those buildings that require it and also raise awareness for employees, residents, customers and visitors. We know from experience that increased physical protection and added vigilance from citizens can thwart a terrorist attack. And that is our goal.
This is the first time we have chosen to use the Homeland Security Advisory System in such a targeted way. Compared to previous threat reporting, these intelligence reports have provided a level of detail that is very specific. The quality of this intelligence, based on multiple reporting streams in multiple locations, is rarely seen and is alarming in both the amount and specificity of the information.
While we are providing you with this immediate information, we will continue to update you as the situation unfolds. As of now, this is what we know: reports indicate that al Qaida is targeting several specific buildings, including the International Monetary Fund and World Bank in D.C.; Prudential Financial in Northern New Jersey; and Citigroup buildings and the New York Stock Exchange in New York. Let me assure you, actions to further strengthen security around these buildings are already underway. Additionally, we’re concerned about targets beyond these and are working to get more information."
30 July 2004
Terrorism Risk Management
Over the past few months’ 1SecureAudit LLC has conducted an independent online poll to determine the areas of Operational Risk that are the largest focus of organizations right now. The results are as follows:
People - 22%
Processes - 31%
Systems - 28%
External Events - 19%
Processes (31%) and Systems (28%) are the two areas that CxO’s have the most control over and are the two main areas that they are working on right now to help mitigate risks.
This means that they have transferred or accepted the risk in the other two areas of Operational Risk Management, People (22%) and External events (19%). The key mechanism for the transfer of risk of people (fraud) and external events (natural disaster) is through insurance. There is a tremendous amount of existing data that the insurance industry understands and therefore they can create the economical products to effectively serve the interests of the corporate organization to hedge these areas of risk, except one. Terrorism Risk.
Terrorism Risk Management
Terrorism Risk includes the risk from attackers both internal and external to the organization. These attackers are using conventional (incendiary explosive devices) and unconventional (digital worms) methods to disrupt the operations and economic well being of corporate organizations, the real estate finance industry and of our critical infrastructures.
The process and systems for managing Terrorism Risk are rapidly changing as the commercial real estate finance and building owners strive to establish new standards. Critical Infrastructure Protection is now a national priority. The key catalysts for change could further motivate infrastructure owners to implement new risk reduction programs and measures.
Some of the key catalysts for change are:
· Insurance – those institutions that are sharing risks that a building owner faces.
· Finance – banks, REIT’s (Real Estate Investment Trusts), and others such as pension funds that provide the capital for investments in commercial infrastructure.
· Regulation – Federal, State and Local jurisdictions that regulate building design, construction and operations.
Overall Terrorism Risk reduction begins with these key catalysts in concert with owners of critical infrastructure, whether that is a corporate office building, a hospital, subway, or a hotel. These soft targets are where the risk management decision-making is already taking new directions.
In order to introduce new changes in process or design that impacts the physical or operational aspects of critical infrastructures (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners. Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety. Consistently the conversations are not about “if” something is going to happen, it is about “where” or “when” it is going to happen. Therefore, it is imperative we initiate a proactive hedge against the inevitability of a loss event occurring in the future. First however, we must understand the character of terrorism risk in critical infrastructure and some of the anti-terrorism tools currently available to help manage that risk.
The recognition by insurers that owners will continue to invest in terrorism risk reduction and building safety with the proper incentives is vital to overall risk management of critical infrastructures. The assessment of terrorism vulnerability in key structures identified as soft targets can be a key component of the rating of risk for a specific structure. In order for owners to benefit from the potential of reduced premiums from direct insurers they must be able to demonstrate a combination of risk mitigation measures and programs to help improve the survivability of the infrastructure or to reduce it’s vulnerability to certain threat profiles. These need to be exercised on a continuous timetable with extensive documentation, training and reporting.
People - 22%
Processes - 31%
Systems - 28%
External Events - 19%
Processes (31%) and Systems (28%) are the two areas that CxO’s have the most control over and are the two main areas that they are working on right now to help mitigate risks.
This means that they have transferred or accepted the risk in the other two areas of Operational Risk Management, People (22%) and External events (19%). The key mechanism for the transfer of risk of people (fraud) and external events (natural disaster) is through insurance. There is a tremendous amount of existing data that the insurance industry understands and therefore they can create the economical products to effectively serve the interests of the corporate organization to hedge these areas of risk, except one. Terrorism Risk.
Terrorism Risk Management
Terrorism Risk includes the risk from attackers both internal and external to the organization. These attackers are using conventional (incendiary explosive devices) and unconventional (digital worms) methods to disrupt the operations and economic well being of corporate organizations, the real estate finance industry and of our critical infrastructures.
The process and systems for managing Terrorism Risk are rapidly changing as the commercial real estate finance and building owners strive to establish new standards. Critical Infrastructure Protection is now a national priority. The key catalysts for change could further motivate infrastructure owners to implement new risk reduction programs and measures.
Some of the key catalysts for change are:
· Insurance – those institutions that are sharing risks that a building owner faces.
· Finance – banks, REIT’s (Real Estate Investment Trusts), and others such as pension funds that provide the capital for investments in commercial infrastructure.
· Regulation – Federal, State and Local jurisdictions that regulate building design, construction and operations.
Overall Terrorism Risk reduction begins with these key catalysts in concert with owners of critical infrastructure, whether that is a corporate office building, a hospital, subway, or a hotel. These soft targets are where the risk management decision-making is already taking new directions.
In order to introduce new changes in process or design that impacts the physical or operational aspects of critical infrastructures (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners. Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety. Consistently the conversations are not about “if” something is going to happen, it is about “where” or “when” it is going to happen. Therefore, it is imperative we initiate a proactive hedge against the inevitability of a loss event occurring in the future. First however, we must understand the character of terrorism risk in critical infrastructure and some of the anti-terrorism tools currently available to help manage that risk.
The recognition by insurers that owners will continue to invest in terrorism risk reduction and building safety with the proper incentives is vital to overall risk management of critical infrastructures. The assessment of terrorism vulnerability in key structures identified as soft targets can be a key component of the rating of risk for a specific structure. In order for owners to benefit from the potential of reduced premiums from direct insurers they must be able to demonstrate a combination of risk mitigation measures and programs to help improve the survivability of the infrastructure or to reduce it’s vulnerability to certain threat profiles. These need to be exercised on a continuous timetable with extensive documentation, training and reporting.
29 July 2004
Sarbanes-Oxley Readiness...
Following are sample questions from the Sections 302 and 404 Readiness Assessment by Deloitte.
Has your company:
1. Adopted a formal implementation plan (including a timetable) to address the requirements of Sections 302 and 404 of Sarbanes-Oxley?
2. Established communication channels among management, the board of directors, and the audit committee to ensure a timely discussion of the status and issues related to Sections 302 and 404 of Sarbanes-Oxley?
3. Incorporated steps within its implementation plan to address all five elements (control environment, risk assessment, control activities, information and communication and monitoring) of the COSO internal control framework?
4. Established an enterprise-wide control and risk management program in which controls and procedures are documented and continually reevaluated in response to major process or organizational changes?
Has your company:
1. Adopted a formal implementation plan (including a timetable) to address the requirements of Sections 302 and 404 of Sarbanes-Oxley?
2. Established communication channels among management, the board of directors, and the audit committee to ensure a timely discussion of the status and issues related to Sections 302 and 404 of Sarbanes-Oxley?
3. Incorporated steps within its implementation plan to address all five elements (control environment, risk assessment, control activities, information and communication and monitoring) of the COSO internal control framework?
4. Established an enterprise-wide control and risk management program in which controls and procedures are documented and continually reevaluated in response to major process or organizational changes?
28 July 2004
Top 10 Most Effective Cybercrime Policies
Top 10 Most Effective Cybercrime Policies
CSO recently partnered with Carnegie Mellon's CERT Coordination Center and the U.S. Secret Service to survey the cybercrime landscape. Here are the methods that our 500 respondents identified as the most effective to fight e-crime.
1. Engage in internal employee monitoring.
2. Have a written inappropriate-use policy.
3. Require employees and contractors to sign acceptable-use policies.
4. Monitor Internet connections.
5. Require internal reporting to management of insider misuse and abuse.
6. Host employee education and awareness programs.
7. Develop a corporate security policy.
8. Conduct new employee security training.
9. Do periodic risk assessments.
10. Conduct regular security audits."
CSO recently partnered with Carnegie Mellon's CERT Coordination Center and the U.S. Secret Service to survey the cybercrime landscape. Here are the methods that our 500 respondents identified as the most effective to fight e-crime.
1. Engage in internal employee monitoring.
2. Have a written inappropriate-use policy.
3. Require employees and contractors to sign acceptable-use policies.
4. Monitor Internet connections.
5. Require internal reporting to management of insider misuse and abuse.
6. Host employee education and awareness programs.
7. Develop a corporate security policy.
8. Conduct new employee security training.
9. Do periodic risk assessments.
10. Conduct regular security audits."
27 July 2004
64% of Companies Have Dedicated Regulatory Compliance Budgets
64% of Companies Have Dedicated Regulatory Compliance Budgets
By: SmartPros Editorial Staff
-- Sixty-four percent of companies currently have budgets dedicated to financial regulatory compliance, with the average budget projected to be $7.2 million in 2005. Among those companies without a current budget, more than half (54 percent) plan to allocate money for compliance initiatives within the next 12 months.
META Group Inc. released its study, 'Organizational Trends in Sarbanes-Oxley and Regulatory Compliance Issues,' which found that companies are dispersing compliance-related spending across a wide range of financial and accounting regulations:
* 56 percent of companies surveyed have allocated resources for compliance with Sarbanes-Oxley (SOX) and the Health Insurance Portability and Accountability Act (HIPAA) regulations
* 48 percent are reserving a portion of compliance spending for USA PATRIOT Act-related initiatives.
* 35 percent have earmarked money for compliance with Financial Modernization Act and 33 percent for Basel II requirements.
* 28 percent have allocated budget for SEC Rule 17a-4, and 27 percent for International Accounting Standards initiatives.
Despite the broad range of funding, the study found one dominant compliance driver: 'SOX has had a significant impact on how regulatory compliance has been viewed and managed,' said Jon Van Decker, vice president with META Group's Enterprise Application Strategies. 'What makes SOX different is the heightened level of security around non-compliance. CIOs as well as other officers of a company can be liable for inaccurate information or insufficient controls, with the possibility of fines or prison sentences.'
Although the severity of non-compliance has elevated SOX management to the highest executive levels within organizations, the study found that most compliance stakeholders are unclear as to where they fit in the compliance plan, relative to their peers. Moreover, those executives presumed to be in charge of compliance may be taking a much more limited role than previously thought.
Less than one-third of study respondents indicated reliance on the CFO as the primary role within compliance. In addition, only 16 percent of companies have tasked the CFO with supervision of the chief compliance officer (CCO) position. Similarly, while many compliance solutions are initially perceived as services solutions, the CIO is often not involved in the final decision-making stages. As a result, only 14 percent of CCOs report into the CIO position."
By: SmartPros Editorial Staff
-- Sixty-four percent of companies currently have budgets dedicated to financial regulatory compliance, with the average budget projected to be $7.2 million in 2005. Among those companies without a current budget, more than half (54 percent) plan to allocate money for compliance initiatives within the next 12 months.
META Group Inc. released its study, 'Organizational Trends in Sarbanes-Oxley and Regulatory Compliance Issues,' which found that companies are dispersing compliance-related spending across a wide range of financial and accounting regulations:
* 56 percent of companies surveyed have allocated resources for compliance with Sarbanes-Oxley (SOX) and the Health Insurance Portability and Accountability Act (HIPAA) regulations
* 48 percent are reserving a portion of compliance spending for USA PATRIOT Act-related initiatives.
* 35 percent have earmarked money for compliance with Financial Modernization Act and 33 percent for Basel II requirements.
* 28 percent have allocated budget for SEC Rule 17a-4, and 27 percent for International Accounting Standards initiatives.
Despite the broad range of funding, the study found one dominant compliance driver: 'SOX has had a significant impact on how regulatory compliance has been viewed and managed,' said Jon Van Decker, vice president with META Group's Enterprise Application Strategies. 'What makes SOX different is the heightened level of security around non-compliance. CIOs as well as other officers of a company can be liable for inaccurate information or insufficient controls, with the possibility of fines or prison sentences.'
Although the severity of non-compliance has elevated SOX management to the highest executive levels within organizations, the study found that most compliance stakeholders are unclear as to where they fit in the compliance plan, relative to their peers. Moreover, those executives presumed to be in charge of compliance may be taking a much more limited role than previously thought.
Less than one-third of study respondents indicated reliance on the CFO as the primary role within compliance. In addition, only 16 percent of companies have tasked the CFO with supervision of the chief compliance officer (CCO) position. Similarly, while many compliance solutions are initially perceived as services solutions, the CIO is often not involved in the final decision-making stages. As a result, only 14 percent of CCOs report into the CIO position."
26 July 2004
eEye Digital Security - Vulnerability Management Solutions
eEye Digital Security - Vulnerability Management Solutions: "
Why Does the Industry Need Blink?
Unknown vulnerabilities represent the greatest threat to enterprises’ digital assets. Contrary to popular belief, many hackers do not wish for worms to be released, as this galvanizes enterprises to patch machines that could otherwise be used as doors into a network. This will continue to be a growing issue as enterprises become more successful at proactive vulnerability assessment and remediation – hackers will focus on ways to compromise systems in a “zero-day” fashion. Since Blink operates by stopping the activity that results from an attack rather than the signature of the attack itself, this technology is able to stop even unknown vulnerabilities from being exploited.
Additionally, as the window continues to shrink between the time vulnerabilities are announced and when enterprises are able to patch their systems, the costs incurred by companies through patch management will continue to grow. A company with thousands of machines in its network can expect to experience millions of dollars in lost productivity and business disruption when patching is immediately required. As a result, enterprises need the ability to defer patching to scheduled maintenance cycles, as well as intermediate protection from attacks that intend to leverage the unpatched vulnerability. By protecting individual machines, Blink allows corporations to patch their systems on a less disruptive, more cost-effective schedule.
Likewise, although the vast majority of enterprises have network-level security elements in place (e.g., firewalls, IDS/IPS, etc.), many remote workers, such as mobile workers, teleworkers, contractors and others, unintentionally acquire vulnerabilities “in the wild” and introduce these vulnerabilities to the corporate network once they reconnect. This internal attack vector is becoming a frequent cause of worms and virus outbreaks. Blink provides the means to isolate and evaluate each machine prior to its reconnection to the network. If any of Blink’s security mechanisms detect unusual behavior, the machine is isolated via its application and system-level firewalls, and the attack is prevented.
Blink also helps enterprises enforce policy compliance by constantly auditing corporate security standard configurations to reduce the risk of compromise. Finally, traditional security measures offer no defense against socially engineered security threats that attack from inside the organization. Even if a user unwittingly downloads a virus or worm, Blink is able to recognize the harmful activity, shut down the offending application, and isolate the machine from the rest of the network.
Why Does the Industry Need Blink?
Unknown vulnerabilities represent the greatest threat to enterprises’ digital assets. Contrary to popular belief, many hackers do not wish for worms to be released, as this galvanizes enterprises to patch machines that could otherwise be used as doors into a network. This will continue to be a growing issue as enterprises become more successful at proactive vulnerability assessment and remediation – hackers will focus on ways to compromise systems in a “zero-day” fashion. Since Blink operates by stopping the activity that results from an attack rather than the signature of the attack itself, this technology is able to stop even unknown vulnerabilities from being exploited.
Additionally, as the window continues to shrink between the time vulnerabilities are announced and when enterprises are able to patch their systems, the costs incurred by companies through patch management will continue to grow. A company with thousands of machines in its network can expect to experience millions of dollars in lost productivity and business disruption when patching is immediately required. As a result, enterprises need the ability to defer patching to scheduled maintenance cycles, as well as intermediate protection from attacks that intend to leverage the unpatched vulnerability. By protecting individual machines, Blink allows corporations to patch their systems on a less disruptive, more cost-effective schedule.
Likewise, although the vast majority of enterprises have network-level security elements in place (e.g., firewalls, IDS/IPS, etc.), many remote workers, such as mobile workers, teleworkers, contractors and others, unintentionally acquire vulnerabilities “in the wild” and introduce these vulnerabilities to the corporate network once they reconnect. This internal attack vector is becoming a frequent cause of worms and virus outbreaks. Blink provides the means to isolate and evaluate each machine prior to its reconnection to the network. If any of Blink’s security mechanisms detect unusual behavior, the machine is isolated via its application and system-level firewalls, and the attack is prevented.
Blink also helps enterprises enforce policy compliance by constantly auditing corporate security standard configurations to reduce the risk of compromise. Finally, traditional security measures offer no defense against socially engineered security threats that attack from inside the organization. Even if a user unwittingly downloads a virus or worm, Blink is able to recognize the harmful activity, shut down the offending application, and isolate the machine from the rest of the network.
23 July 2004
Experts laud U.S. program to counter bioterror attack
Experts laud U.S. program to counter bioterror attack:
Matthew B. Stannard, Chronicle Staff
San Diego -- Fast action and the right medicines can save tens of thousands of lives in the event of a bioterror attack, a Stanford expert told a bioweapons conference just hours after President Bush announced Project BioShield, a $5.6 billion program to develop stockpiles of vaccines and antidotes for chemical and biological weapons.
'The most important thing for saving people is ... treating people before they become symptomatic,' said Dean Wilkening, director of science at Stanford's Center for International Security and Cooperation.
Bioweapons, which require days or weeks of incubation to become deadly, provide a crucial window of opportunity to treat those at risk, Wilkening said at a program Wednesday on public policy and biological threats for the Institute on Global Conflict and Cooperation at UC San Diego.
'You have to detect the event and get medicine into people's mouths within this window of opportunity,' he said. 'If enough people become symptomatic ... you've lost the game.'
In the case of anthrax, for example, which has a 2- to 4-day incubation period, if exposed people are treated before that window closes, as many as 95 percent may be saved, Wilkening estimated. But if it takes two weeks to procure the antidote, that figure could drop to 20 percent.
Project BioShield, which Bush signed into law on Wednesday, provides incentives to the drug industry to research and develop bioterror countermeasures, speeds up the approval process for antidotes and lets the government distribute treatments in an emergency, even before they receive Food and Drug Administration approval.
In signing the legislation, Bush said, 'We refuse to remain idle while modern technology might be turned against us,' and promised to enlist American science to 'confront the greatest danger of our time.' He noted that many of the legislators who passed it had 'experienced bioterror firsthand when anthrax and ricin were found on Capitol Hill.''"
Matthew B. Stannard, Chronicle Staff
San Diego -- Fast action and the right medicines can save tens of thousands of lives in the event of a bioterror attack, a Stanford expert told a bioweapons conference just hours after President Bush announced Project BioShield, a $5.6 billion program to develop stockpiles of vaccines and antidotes for chemical and biological weapons.
'The most important thing for saving people is ... treating people before they become symptomatic,' said Dean Wilkening, director of science at Stanford's Center for International Security and Cooperation.
Bioweapons, which require days or weeks of incubation to become deadly, provide a crucial window of opportunity to treat those at risk, Wilkening said at a program Wednesday on public policy and biological threats for the Institute on Global Conflict and Cooperation at UC San Diego.
'You have to detect the event and get medicine into people's mouths within this window of opportunity,' he said. 'If enough people become symptomatic ... you've lost the game.'
In the case of anthrax, for example, which has a 2- to 4-day incubation period, if exposed people are treated before that window closes, as many as 95 percent may be saved, Wilkening estimated. But if it takes two weeks to procure the antidote, that figure could drop to 20 percent.
Project BioShield, which Bush signed into law on Wednesday, provides incentives to the drug industry to research and develop bioterror countermeasures, speeds up the approval process for antidotes and lets the government distribute treatments in an emergency, even before they receive Food and Drug Administration approval.
In signing the legislation, Bush said, 'We refuse to remain idle while modern technology might be turned against us,' and promised to enlist American science to 'confront the greatest danger of our time.' He noted that many of the legislators who passed it had 'experienced bioterror firsthand when anthrax and ricin were found on Capitol Hill.''"
22 July 2004
Phishing Attacks Linked To Organized Crime
Bank Systems & Technology > Phishing Attacks Linked To Organized Crime:
Michael Cohn, Security Pipeline
'There's a lot of activity in the former Soviet bloc, the Eastern bloc, Latvia and Ukraine,' says John Curran, supervisory special agent with the Federal Bureau of Investigation's Internet Crime Complaint Center. 'It definitely looks like there are organized groups.'
Phishing involves sending fraudulent e-mails that appears to be from a legitimate organization -- such as a bank, credit card company, online merchant or Internet service provider -- asking the recipient to divulge personal and financial information like birth dates, Social Security numbers and PIN codes. Unlucky victims are then subject to identity theft, monetary losses and credit card fraud.
While Curran notes that a broad array of criminals appears to be involved in phishing attacks, ranging from teenagers to grandmothers, the FBI is investigating links to organized crime. So far, Curran hasn't seen any indication that crime syndicates with ties to the Mafia are involved.
The U.S. Secret Service has also noted an increase in organized crime involvement in phishing. At AIT Global's Annual InfoSec Meeting at the United Nations in June, Robert Caltabiano, assistant to the special agent in charge in the New York Field Office of the U.S. Secret Service, pointed to the increasing presence of organized crime in phishing attacks. Although Caltabiano recommended that victims first go to local law enforcement for help, he noted, 'With phishing attacks, the information goes global.'"
Michael Cohn, Security Pipeline
'There's a lot of activity in the former Soviet bloc, the Eastern bloc, Latvia and Ukraine,' says John Curran, supervisory special agent with the Federal Bureau of Investigation's Internet Crime Complaint Center. 'It definitely looks like there are organized groups.'
Phishing involves sending fraudulent e-mails that appears to be from a legitimate organization -- such as a bank, credit card company, online merchant or Internet service provider -- asking the recipient to divulge personal and financial information like birth dates, Social Security numbers and PIN codes. Unlucky victims are then subject to identity theft, monetary losses and credit card fraud.
While Curran notes that a broad array of criminals appears to be involved in phishing attacks, ranging from teenagers to grandmothers, the FBI is investigating links to organized crime. So far, Curran hasn't seen any indication that crime syndicates with ties to the Mafia are involved.
The U.S. Secret Service has also noted an increase in organized crime involvement in phishing. At AIT Global's Annual InfoSec Meeting at the United Nations in June, Robert Caltabiano, assistant to the special agent in charge in the New York Field Office of the U.S. Secret Service, pointed to the increasing presence of organized crime in phishing attacks. Although Caltabiano recommended that victims first go to local law enforcement for help, he noted, 'With phishing attacks, the information goes global.'"
21 July 2004
Operational Risk Enterprise Architecture (OREA)
The operational risks facing corporate organizations today are found across a wide spectrum:
Now take this and multiply by the number of business units or lines of business in your organization. Now multiply this by the industry environments you operate in, the countries you operate in and the number of transactions you do on an annual basis. This will give you an idea of all of the places you have the potential to experience a "Loss Event." These add up over the course of a day, week, month and quarter to erode your earnings, performance and competitive position.
The only way to come close to managing such a dynamically changing foe is to first understand how the architecture of your business is interdependent or dependent on various components that make up it's structure. Only then can you begin to understand why certain loss events happen and what environment or characteristics make it more probable that they will occur.
Recently, a new law in the US called the Identity Theft Penalty Enhancement Act was signed by President Bush. What is interesting about this fact is that it wasn't until Phishing victims lost $1.2 Billion to identity theft related fraud between 2003 and 2004 that the banking industry, the FTC and our legislators understood one of the important facts in accelerating the mitigation of these loss events. Make the penalties for getting caught more severe, if they ever get caught. The law also allows the US Sentencing Commission to potentially increase the penalties for employees who steal sensitive information from their employers. Watch for more on this in the months to come.
The speed of change in the connected economy has finally subjected modern criminal organizations to finally be acknowledged that they are a larger target for law enforcement and our justice system. Only through effective operational risk architecture will our institutions be able to detect, deter and defend against the next wave of threats to our people, processes, systems and critical infrastructures.
- People
- Processes
- Systems
- External Events
Now take this and multiply by the number of business units or lines of business in your organization. Now multiply this by the industry environments you operate in, the countries you operate in and the number of transactions you do on an annual basis. This will give you an idea of all of the places you have the potential to experience a "Loss Event." These add up over the course of a day, week, month and quarter to erode your earnings, performance and competitive position.
The only way to come close to managing such a dynamically changing foe is to first understand how the architecture of your business is interdependent or dependent on various components that make up it's structure. Only then can you begin to understand why certain loss events happen and what environment or characteristics make it more probable that they will occur.
Recently, a new law in the US called the Identity Theft Penalty Enhancement Act was signed by President Bush. What is interesting about this fact is that it wasn't until Phishing victims lost $1.2 Billion to identity theft related fraud between 2003 and 2004 that the banking industry, the FTC and our legislators understood one of the important facts in accelerating the mitigation of these loss events. Make the penalties for getting caught more severe, if they ever get caught. The law also allows the US Sentencing Commission to potentially increase the penalties for employees who steal sensitive information from their employers. Watch for more on this in the months to come.
The speed of change in the connected economy has finally subjected modern criminal organizations to finally be acknowledged that they are a larger target for law enforcement and our justice system. Only through effective operational risk architecture will our institutions be able to detect, deter and defend against the next wave of threats to our people, processes, systems and critical infrastructures.
20 July 2004
Fact Sheet: A Better Prepared America: A Year in Review
DHS | Department of Homeland Security | Fact Sheet: A Better Prepared America: A Year in Review:
Fact Sheet: A Better Prepared America: A Year in Review
“Much like homeland security in general, America’s preparedness requires everyone’s help. That’s why we’ve called you together – to continue building an important partnership – one that will result in an enduring and successful strategy for emergency preparedness across the country.”
– Secretary of Homeland Security Tom Ridge
Today, the Department of Homeland Security, the American Red Cross, the George Washington University Homeland Security Policy Institute and the Council for Excellence in Government brought together leaders in disaster preparedness, and response and recovery as part of the “Public Preparedness – A National Imperative” Symposium. Working together, leaders identified certain challenges and barriers to citizen preparedness as well as specific recommendations that will support the Department of Homeland Security’s National Strategy for all Hazards Preparedness to be released later this year.
Preparedness is the responsibility of every American. At the Department of Homeland Security, we are hard at work creating and implementing preparedness plans; developing procedures and policies that will guide our actions in the event of a terrorist attack; conducting training and exercises to ensure that our first responders possess a necessary level of preparedness; enhancing partnerships with state and local governments, private sector institutions and other organizations; and funding the purchase of much-needed equipment for first responders, states, cities, and towns. These activities, along with an active American community, contribute to a level of national preparedness that is critical to achieving our goal of a better prepared America."
COMMENT:
==================================================
Some enlightened citizen soldiers have already been busy preparing Americans for a spectrum of incidents. For more information see:
Risk Mitigation for the Commercial Real Estate Industry
Fact Sheet: A Better Prepared America: A Year in Review
“Much like homeland security in general, America’s preparedness requires everyone’s help. That’s why we’ve called you together – to continue building an important partnership – one that will result in an enduring and successful strategy for emergency preparedness across the country.”
– Secretary of Homeland Security Tom Ridge
Today, the Department of Homeland Security, the American Red Cross, the George Washington University Homeland Security Policy Institute and the Council for Excellence in Government brought together leaders in disaster preparedness, and response and recovery as part of the “Public Preparedness – A National Imperative” Symposium. Working together, leaders identified certain challenges and barriers to citizen preparedness as well as specific recommendations that will support the Department of Homeland Security’s National Strategy for all Hazards Preparedness to be released later this year.
Preparedness is the responsibility of every American. At the Department of Homeland Security, we are hard at work creating and implementing preparedness plans; developing procedures and policies that will guide our actions in the event of a terrorist attack; conducting training and exercises to ensure that our first responders possess a necessary level of preparedness; enhancing partnerships with state and local governments, private sector institutions and other organizations; and funding the purchase of much-needed equipment for first responders, states, cities, and towns. These activities, along with an active American community, contribute to a level of national preparedness that is critical to achieving our goal of a better prepared America."
COMMENT:
==================================================
Some enlightened citizen soldiers have already been busy preparing Americans for a spectrum of incidents. For more information see:
Risk Mitigation for the Commercial Real Estate Industry
19 July 2004
Carpe Diem
Carpe Diem:
Yesterday's balkanized approach isn't going to get you where you want to go—or reduce your company's risk. CSOs need to seize the opportunities now to centralize security or pay the price later.
BY ANONYMOUS
CSO Magazine
IT'S BECOMING CLEARER and clearer to me that members of the information security community are enamored with the CSO title and have taken it for their own. And apparently there's nobody to challenge them or to correct this overstatement of responsibilities.
In fact, this very magazine recently ran an article noting the creation of the Global Council of CSOs comprising highly regarded information risk management professionals. In it, Howard Schmidt was asked to comment on the apparent lack of inclusion of physical security in the Council's scope. Schmidt confessed that he's "been forgetting to do that." Unfortunately, such oversight sums up the current landscape where we CSOs are unable even to define the elements of corporate protection within our scope of responsibility. (I'm just as dismayed, by the way, at the prospect of a CSO who owns only physical security and investigations as I am by one who is the sole proprietor of information security.)
Why does this balkanized viewpoint bother me? Because security is fundamentally about risk. The business imperative is sponsored by broader, deeper and more immediate risk, and the consequences potentially include corporate and executive survival. Board members and senior executives can no longer think simplistically about securing their corporation with antivirus software and a physical security program comprising a low-bid guard contract and an access control system. CSOs need a business model that clearly defines the scope of security responsibilities and a job description that includes oversight of securing every aspect of the organization.
Yesterday's balkanized approach isn't going to get you where you want to go—or reduce your company's risk. CSOs need to seize the opportunities now to centralize security or pay the price later.
BY ANONYMOUS
CSO Magazine
IT'S BECOMING CLEARER and clearer to me that members of the information security community are enamored with the CSO title and have taken it for their own. And apparently there's nobody to challenge them or to correct this overstatement of responsibilities.
In fact, this very magazine recently ran an article noting the creation of the Global Council of CSOs comprising highly regarded information risk management professionals. In it, Howard Schmidt was asked to comment on the apparent lack of inclusion of physical security in the Council's scope. Schmidt confessed that he's "been forgetting to do that." Unfortunately, such oversight sums up the current landscape where we CSOs are unable even to define the elements of corporate protection within our scope of responsibility. (I'm just as dismayed, by the way, at the prospect of a CSO who owns only physical security and investigations as I am by one who is the sole proprietor of information security.)
Why does this balkanized viewpoint bother me? Because security is fundamentally about risk. The business imperative is sponsored by broader, deeper and more immediate risk, and the consequences potentially include corporate and executive survival. Board members and senior executives can no longer think simplistically about securing their corporation with antivirus software and a physical security program comprising a low-bid guard contract and an access control system. CSOs need a business model that clearly defines the scope of security responsibilities and a job description that includes oversight of securing every aspect of the organization.
Subscribe to:
Posts (Atom)