25 January 2005

Lessons Learned...

What did the US learn about security from the Presidential Elections and the respective conventions in New York and Boston? Michael Smith and Fred Klapetzky remind us of a few of them:

Lesson 1: Preparation Equals Prevention

Lesson 2: Security Saturation makes an Attack more Difficult

Lesson 3: Heightened Awareness makes all the Difference

Lesson 4: Monitoring News Coverage can be Helpful


All of the companies and organizations in these two metro areas should be better prepared than others in the country, right? A recent study (8/2004) by AT&T entitled, "Disaster Planning in the Private Sector: A Post 9/11 Look at the State of Business Continuity in the U.S., surveyed 1000 executives from 10 large metro areas. The survey indicated, surprisingly, that New York and Washington, DC were among those least prepared. In both cities, nearly 25% of companies lacked a plan. According to the survey, even those with BC plans are failing to test or update them on a regular basis. See BC Study

Let's just hope the convention has changed the stats in NYC.

24 January 2005

Compliance is a Strategic Differentiator...

We have to agree with Simon Moss of Mantas.

Prior to September 11th and the USA PATRIOT Act, financial institutions had a similar outlook and level of investment into their anti-money laundering efforts. "The systemic 'wall' to stop money launderers was generally at the same height," says Moss.

Differences in the size of that wall are beginning to emerge. "Over the last three years, firms have been making decisions that have essentially changed that landscape," notes Moss. "The firms that invest more into a serious culture of awareness, serious technology, serious training, and take this problem seriously, will drive money launderers or fraudsters or employees looking to do malfeasant actions to other institutions."


The feds are coming to an institution near you, and they will most likely be the neighborhood or community regional bank. These unfortunately are the institutions that the OCC and other US federal regulators are concerned about. Their programs are going to be tested for CIP (Customer ID Programs) compliance and other BSA/AML/OFAC related issues.

20 January 2005

ChoicePoint: Your Identity is Big Business...

Why are people getting nervous about companies like ChoicePoint? This article in the Washington Post by Robert O'Harrow comes from his book, "No Place to Hide," published by Free Press, copyright 2005. O'Harrow also received financial assistance from the Center for Investigative Reporting. He outlines the arguments from both sides of the "Big Brother" issues:

Now the little-known information industry giant is transforming itself into a private intelligence service for national security and law enforcement tasks. It is snapping up a host of companies, some of them in the Washington area, that produce sophisticated computer tools for analyzing and sharing records in ChoicePoint's immense storehouses. In financial papers, the company itself says it provides "actionable intelligence.


The question remains whether legislation will ever have as much control over ChoicePoint as they have over companies like Equifax or the other credit reporting agencies. However, everyone must accept that our lives are about full disclosure of who we are and what our historical "Modus Operandi" can tell someone about how we might act into the future.

Public information is there because each one of us has opend a bank account, filled out a credit application, applied for a job and traveled on an airplane. ChoicePoint is there to make sure that risks are managed and losses are mitigated. Period.

One only has to imagine in these times of Identity Theft and Suspicious Activity Reports how important it is for the good and law abiding citizen not to be confused with the person with a questionable history. Frankly, I don't want to be mixed up with the other John Q. Public's on the planet. All the decisions I have made in my life have defined who I am, the zip code I live in, the car I drive and the schools and jobs that I've had.

There is one word of advice for those who don't mind the fact that their information is available to any one who wants to buy it. Make sure that it is accurate. This is where the Fair and Accurate Credit Transactions Act (FACT Act) and other legislation allows the consumer to get access to a majority of the information on file and to see that it is correct. If you can't live with what you are reading, then maybe it's time to make some changes in your life.

17 January 2005

COSO: Operational Risk Standard?

Will COSO become the Operational Risk standard for Basel II? This paper by Patrick McConnell argues:

The wording of Basel II is sufficiently vague that banks are in danger of developing internal ORM systems that run the risk of not complying with interpretations of Basel II by local supervisors.

However, there are mature frameworks2 from other industries upon which the processes of Operational Risk Management could be based.

In particular, there are two risk management standards - AS/NZS 4360/2004 and COSO/ERM – that, alone or in combination, could satisfy the requirements of Basel II for systems that are ‘conceptually sound’; and

The adoption of operational risk management processes that are based on proven, practical and usable standards, should reduce the overall costs to the industry of complying with Basel II.


COSO notes that the ERM Framework is “purposefully broad”, capturing “key concepts fundamental to how companies and other organizations manage risk, and may be applied across “organizations, industries, and sectors.”

13 January 2005

People: Travel Risk Management...

This iJet advertorial explains many of the benefits of having a travel risk management provider for your global corporate executives.

"They were rushing to catch the overnight train and wondered whether that was a secure option. With the train leaving in five minutes, he asked if they should get on? He was advised to take the train only if the meeting was absolutely time-critical. If they took the train, he was cautioned to stay awake for the second half of the trip because people had recently been robbed, removed from the trains and beaten up after crossing into Macedonia."


Combining real-time intelligence with a focused surveillance and threat detection-training program is exactly what savvy corporate executives and Chief Security Officers are looking for from a single source. Personnel threat management is a prudent risk mitigation solution. This combination is one key strategy to mitigate the operational risks associated with key personnel in any global organization.

Without the application of survivability and surveillance skills with relevant intelligence, employees traveling in harms way will continue to be at significant risk. The CSO is responsible for getting the correct INTEL and even more important, making sure those employees can take care of themselves without having to rely on third party executive protection or outsourced security firms. Sometimes you just have to think and act on your own.

10 January 2005

OFAC Compliance in U.S. Financial Institutions...

Foreign Assets Control Regulations for the U.S. Financial Services industry is a vital area of operational risk management in the enterprise. Institutions need to make sure that their employees and not just the compliance officer are enforcing the regulations.

The Office of Foreign Assets Control (OFAC) administers a series of
laws that impose economic sanctions against hostile targets to further
U.S. foreign policy and national security objectives. Economic sanctions
are powerful foreign policy tools. Their success requires the active
participation and support of every financial institution. The use of
sanctions by the U.S. goes back to the earliest days of the Republic
through trade embargoes, blocked assets controls, and other commercial
and financial restrictions. Many of them have been multilateralized
within the global community against pariah countries, as well as being
used against groups, such as narcotics traffickers and terrorists, who
threaten the security, economy, and safety of the United States.
Management of sanctions on the U.S. side is entrusted to the Secretary of
the Treasury.


It is often difficult to balance the demands of Federal and State bank
examiners with limitations on time, resources, and manpower imposed
by bank management. While every financial institution must comply
with the same laws and regulations, no one compliance program can be
prepackaged for everyone in the open marketplace. Every program must
be tailored to meet the needs and structure of individual financial
institutions.


"financial institutions" include:

* banks, including:
o insured
o commercial
o trust companies
o private bankers
o U.S. branches of foreign banks
o credit unions
o thrift institutions
* introducing brokers
* commodities broker dealers
* commodity trading advisors
* commodity pool operators
* securities broker dealers
* futures commission merchants
* issuers, redeemers or cashers of travelers checks, checks, money orders, or similar instruments
* operators of credit card systems
* telegraph companies
* insurance companies
* loan or finance companies
* investment bankers or companies
* persons or companies involved in real estate closings and settlements
* currency exchanges
* casinos, card clubs, and gaming establishments
* money transmitters
* pawnbrokers
* travel agencies
* automobile, airplane and boat dealers
* dealers in precious metals, stones or jewels
* U.S. Postal Service or any agency of U.S., state or local government carrying out a duty or power of business

Under the provisions of the Patriot Act, the Department of Treasury has, or soon will specify anti-money laundering compliance program regulations specific to each above-listed industry. The Patriot Act, at a minimum, requires that these programs include:

1. the development of internal policies, procedures, and controls;
2. the designation of a compliance officer;
3. an ongoing employee training program; and
4. an independent audit function to test programs.

Each financial institution is also required to implement a Customer Identification Program (CIP) that includes reasonable procedures to:

1. collect identifying information about customers opening an account
2. verify that the customers are who they say they are
3. maintain records of the information used to verify their identity
4. determine whether the customer appears on any list of suspected terrorists or terrorist organizations

For more information on how you can tailor your compliance program for your institution contact 1SecureAudit who can provide you with:

Compliance Policies & Procedures Customization

> Employee Training

> Due Diligence & Internal Investigations

> Automated Systems for SDN

> Independent Audits

> Anti-Money Laundering Compliance Programs

06 January 2005

Ops Risk for Tier II Institutions...

Operational Risk is not just for the big banking institutions any longer. The latest research from Financial Insights indicates that the ramifications of Basel II are impacting four key areas of U.S. financial institutions:

1. Integration difficulties. Although most large institutions have robust risk-management processes, there's much to be done to achieve Basel II compliance. Most risk processes and systems that are currently used grew up within the individual silos of particular business units. The systems aren't integrated and may have different data requirements and formats.

2. New competitive pressures. Even small banks that aren't required to comply with Basel II will face peer pressure, and they may need to comply anyway. If they don't comply, they'll be at a competitive disadvantage.

3. Consistent methodologies for different risks. Regulators require that different risks be treated the same. Institutions using the advanced internal-ratings-based approach for credit and market risk must also use the advanced-measurement approach for operational risk. This poses problems since credit and market risk are well-established practices in most firms, but operational risk is not.

4. Continuing presence of silos.
Silos between business units and systems must be removed for effective risk management. This task is especially daunting for larger institutions, since there are more people and systems involved.

04 January 2005

What is your 2005 Corporate Resolution?

If you don't have one yet, consider this one:

A Model 2005 Operational Risk Resolution

The organization shall develop, implement, maintain and continually improve a documented risk management system. Identify a method of risk assessment that is suited for the organizations business information to be protected, regulatory requirements and corporate goverance guidelines. Identify the assets and the owners of these assets. Identify the threats to those assets. Identify the vulnerabilities that might be exploited by the threats. Identify the impacts that losses of confidentiality, integrity and availability may have on the assets. Assess the risks. Identify and evaluate options for the treatment of risks. Select control objectives and controls for treatment of risks. Implement and operate the system. Monitor and review the system. Maintain and improve the system.


If you can agree with this then you are already a candidate for implementing a management system and becoming a BS 7799 compliant organization.

For more info see: BSI Management Systems

03 January 2005

Tsunami Contingency Planning and Early Warning...

The latest catastrophic Tsunami natural disaster as a result of a huge undersea earthquake reminds us of the need for effective contingency planning and preparedness. The warning signs and detection devices can only go so far in helping with the potential threats that our planet throws our way.

This article by Beldeu Singh compares the sequence of events and makes the point for a more effective early warning system.

Firstly, it is common knowledge that undersea earthquakes cause tsunamis and these waves can come ashore within minutes of nearby earthquakes. An undersea earthquake must have been picked up by some seismic center in the region but it failed to issue. This inaction exacerbated the death toll because most people in this region do no know what to do in the event of a "felt" earthquake in low lying coastal areas. There was little or no preparation by the Governments in the region for catastrophic calamities caused by convulsions of nature with the exception of an incipient disaster relief systems more suitable for monsoon floods. Typical in Asian management culture is the lack of contingency planning or planning for the uncertain outcomes of events or worst case scenario planning. Structured long term models with comprehensive plans, strategies, systems, logistics and training is also not a norm. The management speaks more of tactical responses and reactions after the tragedy.


On a planet continually being challenged by all types of natural catastrophic events there seems to be only one real way to mitigate the potential losses. Intelligence from early warning systems are only a part of the answer. Emergency Preparedness and Response is the other proactive strategy for dealing with the risk of future threats of this magnitude by mother nature.

Beldeu makes the comparison of this event to the Japanese attack on Pearl Harbor in 1941.

Half a century later, in spite of advances in seismic science and a vast network of modern communications supported by satellite technology, the world relives another day of infamy in the month of December that bears some semblance to the attack on Pearl Harbour. Only this time, it was not failure of collection or analysis of data but one of communication and proper response. In fact, the situation as it unfolded in the region devastated by the tsunami shows that there was no organized response to protect people from the impending impact of the tsunami.

22 December 2004

Whistle-blower laws go global...

As the U.S. recovers from yet another accounting scandal at Fannie Mae, other countries are getting on board with the Sarbanes-Oxley Act.

Japan is considering a new whistle-blower law if a local worker has his way in court.

A JAPANESE executive allegedly forced to weed the company car park for 30 years is at the centre of a major shake-up in corporate whistle-blowing law.

Tomorrow a district court in Toyama will hand down a verdict that could shape Japanese business practice for years to come. If Hiroaki Kushioka is successful in his suit against his employer, Tonami Transportation, the way could be open for startling revelations from within corporate Japan. If he fails, the culture of bullying and cover-ups will be given a tacit vote of support. The Kushioka case comes as Japan is preparing a massive overhaul of its legal treatment of whistle-blowers.


Fannie Mae executives may be some of the first to be successfully prosecuted under the laws in the U.S. that require companies to set up a whistle-blower program. It seems that Mr. Kushioka is finally getting his revenge for ratting on workers over 30 years ago thanks to the trend in improving corporate governance across the globe.

20 December 2004

External Events: Legal Liability

Pfizer has 10% of it's revenues coming to a halt as a result of the Celebrex Warnings about it's link to greater risk of Heart Attacks.

Pfizer Inc. said it would immediately stop advertising arthritis drug Celebrex to consumers after a study showed that high doses were associated with an increased risk of heart attacks, according to a published report.

The suspension of advertising is indefinite and includes television, radio, newspaper and magazine ads and other promotions to consumers, The New York Times reported on its Web site Relevant Products/Services from Verisign -- Free E-Commerce Start-up Kit, citing Pfizer spokeswoman, Mariann Caprino. Some magazine ads may appear for a few more weeks because of the long lead time of magazine advertising, she said.


If the Merck scenario with Vioxx is any indicator of the legal implications then Pfizer can also expect a series of class action suits to follow.

17 December 2004

Who is the right choice for the US DHS Secretary?

In the rush to get someone into the job, most high level qualified candidates have already said no and the current US administration is scrambling after the Kerik affair. So who is the best candidate for the next US Secretary of the Department of Homeland Security?

What the country needs is a career CEO. Not a cop, a lawyer or a politician. Think about what this job is all about and you can see that with over 170,000 employees and warring business units over a finite budget it's going to take someone from private sector business who also understands security.

The kind of security that we have been focused on for the past three years is on the physical aspects of homeland security more so than the intelligence side of the equation. And now with the new Intelligence Act signed and sealed, it's about time we hired someone who truly understands the fusion of data, information, and knowledge to gain "wisdom" aspects of the job.

We already have plenty of cops on the streets keeping their eyes and ears open. What we need now is someone who can get all of the DHS business units working in "concert" and more importantly with the DOD. Homeland Defense is gearing up more than you know and Northern Command is now expanding it's reach beyond it's traditional borders.

Our prediction is that someone will emerge from the ranks of the private sector to take on this enourmous task of getting all of the pieces of the "Homeland Security" puzzle put together. Let's also pray that they understand the difference between Phishing and Fishing. In that case, look hard in the financial services sector.

15 December 2004

Tower Group Study: $362.B for Financial Services IT

The latest Tower Group Study says spending will be up to $362.B with 72% in North America and the EU.

Tower said consumer banking will dominate spending globally. The firm predicted that consumer spending will continue to represent the largest share of IT spending while wholesale banking will experience a continued recovery during the year.

As for the securities and investment industry, TowerGroup projects IT spending in the segment will grow four percent during 2005, partially driven by a return to markets by investors who were burned by declining stock markets a few years ago.

14 December 2004

People Risk: Avian Flu

The Gartner Group has determined that their clients need to prepare for the upcoming Avian Flu pandemic that is being discussed among the World Health Organization (WHO)as a possibility.

On 13 December 2004, health leaders from around the world met in Geneva to discuss the potential threat posed by the predicted future mutation of avian influenza into a highly contagious and virulent form that could quickly pass from person to person. The World Health Organization (WHO) has warned that avian flu variant H5N1 ("bird flu") could combine with an influenza strain already contagious in humans to cause a pandemic that might kill millions of people. H5N1 has been found in poultry in 11 Asian countries. Attempts to eradicate the disease have not succeeded, despite the destruction of 100 million birds. To date, 44 human cases of avian influenza have been reported, all in Thailand and Vietnam. Most of the victims had direct contact with birds; 32 of the victims died.


The difference with this virus and the digital type is that this one can take out key personnel and requires a whole different contingency planning mindset.

Recommendations:

* Use scenario planning to understand and prepare for the possible impact on your business.
* Make your workforce aware of the avian flu threat and the steps you are taking to prepare for it.
* Assess your business continuity preparedness and try to improve it.
* Assign someone in your business to track biological threats such as avian flu. He or she should regularly review business continuity plans and update them in response to new information.
* Establish or expand policies and tools that enable employees to work from home, with broadband access, appropriate security and network access to applications.
* Expand online transaction and self-service options for customers and partners.
* Work with customers and partners to minimize disruption by developing coordinated crisis response capabilities.


While these are great recommendation from Gartner, I think most savvy contingency planners might have a big yawn reading these over.

13 December 2004

ORM: Systems Integration Challenges

In Deloitte's 2004 Risk Management Survey more than half of the respondents say integration of systems to handle Operational Risk is a big concern. More Chief Risk Officers (CRO)have been hired and are reporting directly to the CEO or the Board of Directors.

Operational risk management - according to the survey, operational risk management (ORM) continues to be a relatively new and developing field compared to the more established risk management disciplines, with the majority of respondents still in the beginning stages of implementation. However, the survey shows an increase over 2002 in the number of firms that have established ORM programs. The capability of ORM systems continues to be a challenge for a substantial majority of respondents who indicated that at least some improvement in functionality is needed.

Risk systems and technology - while information technology is considered to be the key enabler of a risk management architecture, respondents report a host of continuing challenges in developing adequate risk systems. More than half (52 percent) cited a lack of integration among systems as a major concern and 42 percent cited it as a minor concern. Lack of flexibility and scalability as well as performance issues were also noted as key challenges. Improving regulatory related systems capabilities and implementing operational risk management and advanced credit risk systems were the three highest priority items cited by respondents in the systems development and technology area.


"Financial institutions are recognizing the need for strong risk management governance, now more than ever," said Jack Ribeiro, managing partner of Deloitte's Global Financial Services Industry practice. "They are responding to increased expectations from regulators, counterparties, the public, and others to ensure sound governance of their risk management programs."

09 December 2004

The Most Feared Words in the Boardroom...

You have been indicted. This Boardmember article by Peter Higgins of 1SecureAudit articulates the essence of an effective OPS Risk compliance program. Even today it is a great reminder of why ethics and education are a key component of an effective system.

Every Fortune caliber organization from financial services to health care has already implemented a pervasive compliance program to mitigate the risk of ending up with the SEC or US Attorney in the lobby.

The catalyst behind these initiatives is generated from the U.S. Sentencing Commission's Organizational Sentencing Guidelines. They allow for more lenient sentencing if an organization has evidence of an "effective program to prevent and detect violations of law."

The Guidelines contain criteria for establishing an "effective compliance program."

These include oversight by high level officers, effective communication to all employees, and reasonable steps to achieve compliance such as:

* Systems for monitoring and auditing
* Incident response and reporting
* Consistent enforcement including disciplinary actions


Yet the corporate incivility continues. Why is it that we can’t pick up the morning paper or listen to the news on the way to work without hearing about a new indictment of a top ranking officer?

Here lies the question many Board of Directors are scratching their heads about these days. How can we avoid these ethical and legal dilemmas and how can they be addressed without creating a state of fear and panic?

The answer lies in the human factors of what motivates people’s behavior. This requires programs, controls and good old fashioned vocational counseling. However, the real facts are that all of these alone will not be able to stem the tides of corporate malfeasance.


07 December 2004

ERM: Here to stay...

Last summer Scott Berinato penned this article. It sums up the many facets of Enterprise Risk Management (ERM) and the challenges for the CIO. As a CIO, he should know right?

Are you on board with enterprise risk management? You had better be. It's the future of how businesses will be run.

What would you do if, two months after your company went public, one of the two major markets you sell products to simply vanished? If, in the span of seven days, $500 million in sales just disappeared?

Would you throw your hands up and say, No one could have foreseen the events of 9/11, and then just stand by as the company tore off a half-dozen bad quarters? Would you just absorb the discomfiting cuts to your budget and your staff, and eschew any strategic plans you had set up to help the business grow, because, well, no one could have been prepared for such a catastrophe?


ERM is hard work. Not to sound too much like the last GOP campaign who had a similar sound bite, "We are workin hard", but Enterprise Risk Management is a culture shift and also one found in an old project managers tool kit called "Change Management".

So Why Now?

Just why ERM is important now is complex, but the reasons include IT as a primary risk to operations.

First, several macro-trends have accrued to expose operational risks to the business from IT that in the past were blissfully ignored. Start with Y2K - the realization that IT systems we depended on were vulnerable. Then came 9/11 and the (literally) thousands of risks to businesses that it exposed. Computer viruses have continually interrupted work, illuminating the risks of using bad software. More recently, the risks to a corporation's reputation have announced themselves in the form of massive thefts of personal data. There is, of course, terrorism, political unrest, war and weather, among other global risks to consider.

The reason these risks are suddenly being accounted for is because the systems are becoming ever more critical. Today, one bad IT decision can severely hamper - or even take down - a company.

The second factor driving ERM now is the regulatory environment
, along with efforts within some industries to protect companies from the volatile global business environment.

For example, the Basel II Accord, an effort spearheaded by the Group of 10 countries' leading financial services stakeholders, dictates that by year-end 2006, a financial services company must carry a predetermined amount of capital to offset the level of risk found in the company, as determined by guidelines in the Accord. Unlike the first version of this regulation from 1988, Basel II addresses not just capital risk, but also operational risk, including the risks IT systems create for the company. In other words, it mandates some form of enterprise risk management.

Likewise, the Treadway Commission's Committee on Sponsoring Organizations (COSO), a voluntary private-sector organization formed in 1985 to combat fraudulent financial reporting, produced an enterprise risk management framework. The Information Systems Audit and Control Association (Isaca) developed Cobit (the Control Objective for Information and related Technology), a document that also lays out how to set up an enterprise risk management framework. Both are efforts designed to jump-start the use of ERM in corporations.

Of course, there's Sarbanes-Oxley too. While not the engine driving ERM, Sarbox might be the spark plug. CEOs, after all, don't want to go to gaol. Says David Weymouth, CIO of Barclays, the UK-based financial services company: "We've spent something like £136 million on a regulatory program. Non-compliance is a huge risk we need to manage."


The bottom line is this. Operational Risk is old and it is new. It is not something to be ignored and underfunded. It's constantly changing and requires exceptional people, processes, systems and technology to make it work.

06 December 2004

Phishing moving to prime time...

With an estimated 4.5 million "Phishing" attacks last month now being reported by Messagelabs our customers and clients need to be even more aware of this growing threat. This is especially true since the Phishers have figured out how to extract valuable information without someone clicking on a hyperlink in the email itself.

The boom in phishing attacks -- spam that masquerades as messages from legitimate companies that tries to dupe users into divulging confidential information, such as bank or credit card account numbers -- has been phenomenal. MessageLabs tracked a mere 279 phishing e-mails in September 2003, but a year later, monitored over two million in the same month. During November 2004, MessageLabs tallied a whopping 4.52 million phishing-related messages.

And if you think that's bad, wait until next year, said Natasha Staley, an information security analyst with U.K.-based MessageLabs. "Phishing is really only 12 to 18 months old. It's not even in its prime."

Phishers, who are believed to be composed primarily of organized criminal gangs, many of them based in central and eastern Europe, including the republics of the former Soviet Union, are quickly refining their techniques, added Staley, to make their bogus messages even more enticing or effective.


You have to have diligent awareness campaigns for your customers, members and clients if you are going to mitigate the risks of operational losses. Banks, e-commerce sites and any other big brand on the net is being targeted by a growing criminal element.

03 December 2004

H.R. 4830 - Private Sector Preparedness Act of 2004

What is H.R. 4830?

A bill introduced last summer in the U.S. House of Representatives to amend the Homeland Security Act of 2002 to direct the Secretary of Homeland Security to develop and implement a program to enhance private sector preparedness for emergencies and disasters.

Program Elements- In carrying out the program, the Secretary shall develop guidance and identify best practices to assist or foster action by the private sector in--

`(1) identifying hazards and assessing risks and impacts;

`(2) mitigating the impacts of a wide variety of hazards, including weapons of mass destruction;

`(3) managing necessary emergency preparedness and response resources;

`(4) developing mutual aid agreements;

`(5) developing and maintaining emergency preparedness and response plans, as well as associated operational procedures;

`(6) developing and maintaining communications and warning systems;

`(7) developing and conducting training and exercises to support and evaluate emergency preparedness and response plans and operational procedures;

`(8) developing and conducting training programs for security guards to implement emergency preparedness and response plans and operations procedures; and

`(9) developing procedures to respond to external requests for information from the media and the public.


Congress has found out the following:


Identifying standards and best practices is necessary to promote emergency preparedness by private sector organizations, in addition to educational activities to effectively communicate such standards and best practices.


As business waits for this bill to get out of committee, business leaders around the country are not standing around. They realize that contingency planning and continuity of operations is imperative for their business survival. We can only hope that no one is waiting around for what the standards body or best practices authority will be. Let's pray that the private sector has gone beyond developing plans and now is exercising Corporate Emergency Response Team (CERT)training in all the facilities deemed to be soft targets. Without this, we will certainly not be as ready as we could be. And once we have trained and tested numerous times, we will know what to improve and how to change the procedures accordingly.

01 December 2004

Some SOX relief for smaller firms...

US companies with a market cap between $75 and $700 Million will get a 45 day extension for compliance with SOX (Sarbanes-Oxley Act of 2002). According to the SEC Statement:

The online statement quoted SEC Chief Accountant Donald Nicolaisen, saying: "The Commission is sensitive to resource constraints at accounting firms and at smaller public companies, and is taking this step to facilitate the successful and effective implementation of the Section 404 internal control requirements." Alan Beller, director of the Division of Corporation Finance, added that the exemption should "encourage companies to file important information for investors, including audited financial statements, on a timely basis, while providing an appropriate accommodation for internal control reports."

Eligible companies now have 45 days after the expiration of their 75-day reporting window to add the required management reports on internal controls, along with auditors' comments, the SEC said. The PCAOB's ruling allows auditors to sign off of internal reports at a later date than financial reports. The temporary rule is expected to be in effect until July 15, 2005.

30 November 2004

People Risk: Whistleblowers are winning...

This article from Charles Baldwin highlights the recent rulings under the Whistleblower provisions under the Sarbanes-Oxley Act of 2002. If this is the trend, then employers need to spend more time educating employees and making sure they are in compliance with the letter of the law.

Of major significance to the employer-employee relationship, the Act requires the newly mandated audit committees of corporate boards of directors to establish procedures for the anonymous, confidential submission of employee concerns relating to improper corporate financial, accounting, or auditing practices and creates new civil and criminal liabilities relating to informants. In addition to requiring internal complaint procedures, Section 806 of the Act created a new federal civil claim under the title "Whistleblower Protection for Employees of Publicly Traded Companies." The nature of the claim is broader and imposes fewer burdens on a claimant than other federal whistleblower laws; thus, employers should expect to encounter more claims and litigation arising from the Act.


Recent rulings by the U.S. Department of Labor include:

Getman v. Southwest Securities Inc, No. 2003- SOX-00008, DOL ALJ
Welch v. Cardinal Bankshares Corp., 2003-SOX-15, DOL ALJ
Morefield v. Exelon Servs. Inc., DOL ALJ, No. 2004-SOX-2


In addition to complying with all of Sarbanes-Oxley’s requirements regarding financial reporting controls and corporate governance, prudent employers—whether public or private—must be proactive in implementing policies and procedures to navigate the post-Sarbanes-Oxley landscape. We recommend that employers first conduct a top-to-bottom review of existing policies and practices, ideally in a manner that will maintain all available legal privileges and protections. A review of insurance coverage, including but not limited to Directors’ and Officers’ liability coverage, must be a part of that review. Following that review and follow-up, employers should be in a position to show, at a minimum:

* A code of conduct that spells out specifically the duties of all employees;
* A code of ethics for senior financial officers;
* Establishment and a clear publication of a hotline and other avenues for confidential, anonymous complaints;
* Personnel policies and procedures that comply with the law’s requirements on handling of complaints, document handling and retention, and non-retaliation;
* A clear designation and publication of those persons within the company who have the authority to investigate, discover, or terminate financial misconduct;
* Personnel policies clearly addressing inappropriate conduct, e.g., prohibited conduct regarding media contact, removal of documents, destruction of documents, refusing to participate in investigations;
* Benefit plans and practices that comply with all requirements and prohibitions;
* Procurement practices and procedures to ensure proper screening of human resources consultants and auditors;
* Hiring practices and procedures to ensure proper screening of executives; and
* Comprehensive and documented training programs for all employees that implement the requirements of Sarbanes-Oxley.

24 November 2004

Managing Operational Risk in Banking...

This latest article by McKinsey may have some interesting insight:

Banks are increasing their coverage against operational risk to comply with new international banking rules, but they may be underestimating the extent of the risks they face. The declines in market value of financial institutions that experienced an operational crisis—such as an embezzlement or breach of regulations—were much greater than the actual financial loss caused by the event, our research found.

The take-away

Banks that understand the true scale of the operational risk they face can take a more realistic approach to controlling it.


This article includes the following exhibits:

* Exhibit 1: Impact of operational crises on market returns
* Exhibit 2: The five most harmful kinds of operational crises

23 November 2004

UK: Civil Contingencies Act...

The UK's Civil Contingencies Act is on the door step and David Honor of Continuity Central has the following observations:

No UK organisation can afford to ignore the Civil Contingencies Act. The category one and two organisations which will be directly impacted will receive information, advice and support from the Cabinet Office on how and when to implement measures. Other organisations would be well-advised to do the following:


• Get a copy of the Act and read it
• Assess your current business continuity plan against the Act’s provisions. Does the Act make any difference to the scenarios you have planned for?
• Redevelop the business continuity plan where necessary and re-test it.
• Liaise with your local authority emergency planning department. This is good practice which is listed as one of the BCI’s Ten Key Disciplines of Business Continuity, but now becomes even more important since local authorities will become one of the key sources of local business continuity information and advice.

19 November 2004

OSAC 19th Annual Briefing...

The topics of the annual Overseas Security Advisory Council Briefings and 8th Annual Transnational Crime Seminar indicate what's on the minds of most CSO's across America and the globe. See if you can see the common thread:

"Managing Risks and Threats in Challenging Environments" - Bureau of Diplomatic Security

"From Suppliers to Satellites: Balancing Business and Security" - Delphi Corporation

"Coping with Istanbul" - HSBC Holdings, PLC

"Managing World Security Trends"

"Communicating with Employees under Heightened Threat Conditions"

"What do Employees Expect, What do They Need"

"Perception of Bio-security Dangers and the True Vulnerabilities"

"International Kidnapping and Hostage Taking"

"Emergency Preparedness and Business Continuity"


After two days of hearing presentations by some of the most informed individuals on the topics and issues of global security, one individual made a very interesting point:

On the topic of Practice Preparedness and Training Programs for employees he asked, "What do your people do in the event of [Pick a Diaster Scenario]?" The point is, you won't know what they do unless you exercise, drill and experiment with different scenarios. He went on to say that we need to be Leaders of Safety, Health and Operations and that the likes of SARS and Avian Flu will not be stopped by more guards, gates and guns.

Invisible contagious agents that are autonomous will be something we encounter on a mass scale sooner than we think. As professionals paid to worry, this is the one that we don't ever want to encounter and don't know much about how to mitigate the threat to our organizations.

Another vital topic on Abduction Prevention and Hostage Survival promoted the thinking about training to detect surveillance and to make rational and tactical decisions to prevent from being kidnapped. However, in the event of abduction, there are only four outcomes:

1. Negotiate
2. Rescue
3. Escape
4. Death

The point here is that you must maximize survivability and minimize exploitability. Finally, employees and organizations need to have a Personnel Recovery Architecture that includes a continuum for guideance and a crisis management framework.

Operational Risk and Continuity Management is what this 1.5 day briefing was all about. If there was one thing that stands out from all the presentations and the conversations is that our employees are looking for people they can "TRUST". It's our duty to make sure that we do everything in our power to make this a reality.

Perception drives Attitude that drives Behavior.

18 November 2004

ID Theft: Banks vs. Consumers...

The banks have a different perspective on ID Theft and privacy than consumers. As this Bank Tech article points out.

Late last month, four servers containing names, addresses and Social Security numbers of thousands of Wells Fargo & Co. mortgage and student-loan customers were stolen from an Atlanta company that prints loan statements. There's no indication the information has been misused, the bank says, but it's advising affected customers to monitor their accounts for suspicious activity. It's also offering a free one-year credit-protection program and has established a toll-free hotline.

The incident was the latest reminder of how pervasive the threat of identity theft has become, as well as how much of a risk it is for banks and credit-card issuers and their customers. According to the Federal Trade Commission, 9.9 million Americans were identity-theft victims last year. Of those, 6.6 million reported fraudulent use of existing accounts while more than 3 million reported new accounts opened in their names. That cost businesses $48 billion and consumers $5 billion in economic losses.


As banks and other financial institutions outsource operations such as printing statements and sending out direct mail they are going to be continually subjected to incidents like this. What is commonly the case, and astonishing to say the least is that these 3rd parties are not always as "buttoned-up" as they should be with their risk detection, prevention and protection programs. If the consumer has anything to fear, it is that their bank is not taking the time to effectively audit and monitor their outsourced service providers.

16 November 2004

NIMS set to be approved...

The National Incident Management System is soon to be approved.

An integrated national plan for response to terrorist attacks and other national emergencies is likely to be approved by Cabinet secretaries by the end of this week, Deputy Homeland Security Secretary James Loy said Tuesday.

By this time next year, the final National Response Plan will have replaced the disparate plans now in effect at federal agencies that work terrorism response, the former Coast Guard commandant said at a maritime-security conference in Washington organized by Defense Today and held at George Washington University.

A February 2003 directive by President Bush required the fledgling Homeland Security Department to design and implement the National Response Plan and the associated National Incident Management System in a bid to "establish a single, comprehensive approach" to managing terrorist attacks, natural disasters and other large-scale emergencies.


The system establishes "standardized incident management processes, protocols and procedures" for incident command organization, communications and preparedness, Homeland Security said in a March fact sheet. The effort is intended to allow first responders from different jurisdictions and disciplines to better coordinate responses to natural and unnatural disasters.

15 November 2004

SOX 404 Deadline today...

The long anticpated compliance date with Sarbanes-Oxley Section 404 arrived today and many organizations are not ready.

Although many companies are reportedly not ready for it, the era of internal-controls compliance begins in earnest today. That's when Section 404 of the Sarbanes-Oxley Act goes into effect for all companies whose fiscal year ends after today.

There will be nothing to file on Tuesday. But by early next year, the vast majority of companies that report on a calendar-year will have to assess the effectiveness of their internal controls over financial reporting and state in their annual reports whether the controls are operating effectively. The companies' outside auditors also must evaluate the in-house assessment and render an independent report on it.


The average cost to a organization to get in compliance is estimated at $5M and rising for a Fortune caliber public company.

12 November 2004

Global Assurance Office...

As the corporate risk management factions realize that they need to converge in their coordination, global assurance management will take hold.

Soon enough the global 500 will realize the requirement for a more consolidated, coordinated and cohesive entity within the organization for risk management, information security, business continuity, crisis management and emergency response.

The combined expertise in finance, compliance, legal, IT, internal audit, operations, security, human resources and purchasing will all be working together to create the organizations single global assurance office.


This will be the team and staff that manages an "All Hazards" approach to mitigating the threats to the organization. They will be responsible for the single task of making sure that the business is running no matter what event or incident may try and bring it down.

A few savvy organizations have already moved this direction and even those that thought they had a single responsible team are now adding new dimensions and capabilities to the team.

11 November 2004

1SecureAudit Prepares WTG Properties Tenants For All Hazards And Catastrophic Incidents

Risk mitigation training solution delivers greater confidence, lower costs, and increased peace of mind for this Washington, D.C. commercial real estate firm

For Immediate Release

MCLEAN, Va./EWORLDWIRE/Nov. 10, 2004 --- 1SecureAudit LLC, an emerging leader in operational risk management solutions, today announced a client success story for WTG Properties in Washington, D.C.

Many companies throughout the Washington, D.C. area are asking the same important question, especially since Sept. 11, Hurricane Isabel and the Northeast blackout. That is: How can businesses be better prepared in the case of serious hazards, incidents and emergencies?

The residents of WTG's N Street property were no exception. "My tenants were asking what we were doing to be better prepared in case of another attack," said John Lane, president of WTG Properties Inc. "Which was logical, given their proximity to the White House.

"But I wanted a proactive and preventative all-hazards program that would cover everything," continued Lane. "I wasn't just worried about terrorists, but also about serious incidents like floods, fires, and hurricanes. That's when I started my conversations with Peter Higgins of 1SecureAudit."


1SecureAudit is a risk management solutions firm that worked with Lane and the residents of the property to teach them how to better cope with emergency situations that may arise.

Higgins explained: "You've heard the term first responders. Well, the fire fighters, police and EMTs are actually the second responders. Employees and tenants are the first responders in a crisis, and they need to be competent, confident and as prepared as possible to handle the situation until the emergency personnel get there - whether it's minutes, hours or days."


Think all hazards. Think convergence of BCCM, ISMS and Corporate Governance. That equals total Global Assurance. The future is here now.

09 November 2004

Business Process Outsourcing: A Real Threat to Security or IP Theft?

Business Process Outsourcing is a hot issue and as this article by The Heritage Foundation so clearly states:

Defending the nation against terrorists, promoting economic growth, and protecting constitutional lib­erties are all prerequisites for a sound homeland security strategy. At one time or another, outsourc­ing[1] has been labeled a threat to all three. These crit­icisms are simply overblown. In fact, if the U.S. partners with nations that share a commitment to the rule of law, transparency, and open competition, it can use sensible outsourcing to enhance the protec­tion of the privacy of American citizens, promote better security practices, and contribute to economic prosperity. Effective outsourcing can provide both cost-effective services and appropriate protections for government and commercial activities supported by overseas vendors.


Now if you talk with the major U.S. technology companies who have outsourced operations in India and China they will tell you their nightmares. Intellectual Property theft is running rampant and the laws and trade representative sanctions will be hard pressed to make major changes in the near term. The security of the nation is not going to be compromised by these organizations and the real loss events will occur when their source code is posted on the Internet.

Conclusion

The goal of increasing domestic security and protecting the privacy of U.S. citizens should not be an obstacle to strengthening economic ties with the developing world. Rather, market forces and sensible outsourcing can be used both to promote better global security practices and to encourage economic growth.

08 November 2004

Judgment Calls...

Regulations such as Sarbanes-Oxley are sending auditors to the pencil sharpener. CSOs must learn to cooperate and share expertise, without getting too close to these empowered examiners.


Malcolm Wheatley is a freelance writer in England. And this "Judgment Calls" article was dead on with good advice especially number four:

Strategy No. 4: Teach Them Security Heim’s mention of a back-and-forth negotiation between auditors and security executives carries with it an important conclusion: Security-savvy auditors are a must.

Communicating with auditors as part of a cooperative process is one way of educating them about the security function. Another solution, according to Radianz’s Hession, is to obtain the requisite combination of skills and separation by turning security folks into auditors.


How can you have an effective Information Security Management System without auditors who know “Risk Management” from an IT perspective? The answer is, you can’t. And you can’t have an effective audit for legal compliance issues without IT security professionals who understand the intent of the law. To do this you must have a cooperative team who thinks like a criminal and that is not easy to create.”

“The reciprocity between CSO, CIO, CRO, CFO and General Counsel is imperative if any sizeable company is going to mitigate the threats from internal and external attackers. And as this article clearly points out, a healthy set of objectivity and anxiety is imperative if you are going to have professionals on the front lines do their jobs within the intent of the law.

03 November 2004

Bush defeats Kerry for US Presidency...

George W. Bush won his Second Term as President of the United States today.

"To make this nation stronger and better, I will need your support and I will work to earn it," Bush, referring to Democratic supporters who bitterly oppose his presidency and re-election, said in a speech at the Reagan Center to a cheering partisan crowd.

"I will do all I can do to earn your trust ... we have one country, one constitution and one future that binds us."


The risks have not changed and the way we detect, deter and defend our precious assets will continue to gain momentum for the next four years.

02 November 2004

Advanced Citizenship in Critical Infrastructure Protection...

The dialogue from a recent CSO Conference that focused on information sharing keeps coming back to why it is so hard to accomplish.

Only Bill Boni from Motorola was bold enough to tell the real reason why the cyber world is still not getting the attention it deserves.

Boni: I think the real driving issue here, if you go back and look at [how sprinkler systems came to be in factories], such safeguards come out of the experience of factories burning down and people dying. And until we see mass-casualty events that are critical to information security failures, I don't think you're going to have that same sense of urgency. And, probably, as a society we shouldn't. But, the challenge is to make sure that organizations are doing their reasonable best to not be the cause of part of that event. But my belief is that until we see mass casualty situations that arise from information security, we won't make that transition, and we shouldn't. Unfortunately, I think that it is going to happen at some point. Whether that's before or after I retire from my current employment is a very important deliverable.


It's amazing to find out that even as we speak there are people who are still unprepared to handle the zero day exploit or the next catastrophic incident. Even when they are considered a "soft target" they still have not exercised and tested to the degree necessary to improve their defense and to plan for the various outcomes possible. Boni is right, if it doesn't happen to me then why should I spend the time and resources to prepare? For the same reason you pray at your place of worship. You know it's inevitable and yet you don't know when it is going to happen to you.

29 October 2004

Threat Detection & Management...

Robert Young Pelton's Travel Tips may be common sense. These are also the type of tips you get from those expensive executive seminars where no one ever gets out of their seat for two days.

If you are going to take an attitude of really protecting your organizations most valuable assets then you have to train your people in real life scenarios. The goal is to overcome the panic modes and replace them with smart actions to save your life and your companies precious information.

For those who travel on business into regions of political or religious instability it should be company policy that each individual travel with at least an experienced partner. Also essential is that both have gone through extensive hands on training to detect surveillance as well as manage emergency situations with smart decisions. For more on this visit: Threat Detection & Management

27 October 2004

Compliance and outsourcing: Oil and water or fine vinaigrette?

John and Stan could not have said it any better....

By John Van Decker and Stan Lepeak
10 May 2004 | Meta Group

One common misperception that still survives in the market is that existing outsourcing audit mechanisms, primarily the SAS 70 audit, are adequate for SOX compliance. The growing consensus is that even an SAS 70 Type 2 audit may not prove enough for SOX. The SAS 70 standard was developed long before SOX regulations and was not designed to focus on the type of controls that SOX addresses. In addition, there have been no requirements for users to request an SAS 70 audit, and many have not. One SAS 70 audit could potentially suffice for multiple clients of an outsourcer, whereas with SOX compliance, this is likely unacceptable. We are seeing more cases where aggressive/thorough clients are demanding additional controls and documentation beyond an SAS 70 Type 2 audit to enable what they estimate is "good enough" SOX compliance. It is not expected that the PCAOB will define requirements above and beyond an SAS 70 for SOX compliance until later this year.

A final challenge to SOX compliance that affects outsourcers is interenterprise compliance. Users must approach process compliance holistically, covering insourced and outsourced processes, as well as intersection points and continuums of processes that span supply and service chains. For example, how can a user's controls account for the breakdown in a supplier's financial controls that could lead to a parts shortage, which could impact revenue/profits that would then require a timely disclosure? Clearly, organizations cannot address SOX compliance in an isolated fashion. Outsourcers have the added dimension of being intertwined in multiple-clients compliance efforts across multiple process areas. This in itself increases the outsourcer's risk and demands greater focus on enabling compliance, for its own sake as much as its clients'.

Bottom Line: Business process and IT outsourcing currently do not mix well with SOX and related compliance requirements. However, outsourcers and their clients cannot wait for regulatory clarification and must define, document, and rationalize interim best-faith efforts for gaining and evidencing SOX compliance for affected outsourced functions and processes.

26 October 2004

Systems: Data Quality Risk...

The quality of data is becoming a risk management issue again according to this latest Banking Study of 1700 banks in 63 countries. Sarbanes-Oxley and Basel II are helping CIO's to increase their budgets yet the study finds that data quality is still one of the biggest operational risks.

The survey quizzed banks about eleven key topics involving reference data management and risk management and shows that financial institutions worldwide are making considerable efforts to deepen their data management and increase data quality.

These efforts are being driven, besides cost pressures and increased transaction volumes, by regulatory requirements such as Sarbanes-Oxley and Basel II, which will be implemented in more than 100 countries within the next few years. "The results show that companies realize the close connection between comprehensive data management and efficient risk management," explains Martin Buchberger, head of marketing at AIM Software.


Workflow management is a key concern and 54% of the respondents plan to spend money in this software as it is a vital component in managing operational risk. Furthermore, outsourcing and COTS solutions are outpacing proprietary development.

Looking further at standardization, 42 percent of the survey respondents plan to purchase an off-the-shelf data management solution or to buy and adapt a solution to their own needs. 26 percent of the respondents rely on proprietary development. "This is a significantly smaller proportion than in the past, when data management was still regarded as an internal core competency.

25 October 2004

Phishing goes Corporate...

Phishing is making it's way inside corporations and represents a new threat by hackers.

The ploy is to send an email that looks legitimate about upgrading a software component or windows program. The hackers site then downloads the Malicious Code.

“Companies must make their employees understand their role in improving security within the organisation,” he said.

A proper security policy must also be in place and the role of each individual who manages the security policy must be clearly defined, he said.

It must also be made clear to employees that the security policy is in place for their protection and not just for the company.

And finally, companies must be prepared for the worse. There should be an incident response team should the company's security be compromised."

22 October 2004

SOX a Ticking Time Bomb?

In the latest issue of Corporate Board Member you will find some very interesting statistics and comments. This one got our attention:

Is That A Ticking Clock Or A Time Bomb?

Has meeting Sarbanes-Oxley's requirements left directors enough time to think about other issues?

The answer is yes, but only because you're spending more time on the job than ever before.

The SOX Factor
Do directors think Sarbanes-Oxley has created an environment where management is so distracted that company performance will be affected?

No: 44%
Not Sure: 36%
Yes: 20%


I would say that over one third don't know, don't care or are too scared to really find out. One fifth think that performance will be impacted. That leaves the remaining 40+ % feeling confident that SOX will not affect corporate performance. Let's just hope that the "NO" voters do really know that this is the case.

19 October 2004

People: Travel & Safety...

Travel risk to corporate executives is on the rise. Even if you are not an executive who can afford the services of personal body guards and armored cars, there are some prudent ways to mitigate the risk of traveling to the global hot spots.

Travel safety is becoming more of a main stream issue with savvy operational risk managers. In fact, the likes of some new firms are emerging by former FBI or other law enforcement heavy weights. The fact is, most of these so called travel safety courses are being taught from only one side of the equation.

Today, CSOs are often tasked with building their company's corporate travel safety programs. The job calls for a proactive approach to educate employees about precautions they can take to stay safe, whether they're the CEOs of multibillion-dollar conglomerates who fly on company jets that land on secured tarmacs or rank-and-file staff riding in commercial airline coach.


Business has to be done in some of the most dangerous places on the planet, even when it comes to being exposed to kidnapping, terrorism and corrupt governments. Our advice is to make sure your instructor transfers skills to people on "how" to detect, deter and defend against the attackers. Not just the "What to do".

For the real difference, visit: Threat Detection & Management

18 October 2004

Business Performance & Basel II...

The Tower Group is shouting the need for banks to automate now in the midst of the Basel II momentum. While business performance has converged with Basel II, the key understanding needed is what do Business Performance & Basel II have to do with my survivability as a money center bank?

Basel II introduces a convergent framework of risk management and controls that will encourage banks to invest wisely in IT and improve the efficiency of their business operations. Banks that adopt effective enterprise risk management platforms will reap business benefits that go well beyond regulatory compliance.


Knowledge Management is coming to banking in a way that the bean counters never imagined. With the focus on Operational Risks, the only way to be able to correlate new threats with the current asset base is through automation.

The industry is now at the implementation phase of Basel II. Few banks have the perspective and resources to experiment and establish their own enterprise risk management models that include this new field of operational risk. Notwithstanding their attention to business continuity and reputational risk matters, most banks have still to inscribe operational risk procedures in the broader picture of business management and operational efficiency. Not only may banks improve their operational efficiency by streamlining business processes, but they also can tap important benefits in operational resilience, responsiveness and flexibility to innovate. By adopting automation models for integrated business and risk management, proactive banks may derive significant returns from a concerted enterprise approach.

15 October 2004

External Events: The Risk of Loss from Eliot...

What other risk will the financial services industry find to be more of a threat? With the latest litigation filed by the now famous Eliot Spitzer the insurance industry is in for the same treatment as Wall Street. Clean up your act.

The New York AG's suit against insurance broker Marsh & McLennan and other heavyweights may change the way the industry does business

America's biggest insurers have found themselves in the midst of a scandal that could change the very nature of the business. On Thursday, Oct. 14, New York Attorney General Eliot Spitzer charged Marsh & McLennan (MMC ), the huge financial-services firm and world's largest insurance broker, with fraud. In a civil complaint filed in New York State Supreme Court, Spitzer alleges that the firm engaged in bid-rigging, price-fixing, and accepted payoffs from insurers. Marsh's stock has plummeted -- it opened on Oct.14 at $46.01 but is trading on Oct. 15 at around $28.20, a drop of roughly 38%.


The scrutiny of the sales process at every insurer in the country has now begun. If you have a P & C policy on your building with Marsh, it might be worth getting a competitive bid now. This is going to be another lesson in Management 101.

14 October 2004

Operational Risk driving new spending...

The latest surveys from PwC ASIA paints a rosey picture for a rise in Information Security spending.

About 67 per cent of information technology executives in Asia say they will increase spending on security, compared with a global average of 64 per cent in PwC's survey of 8,000 companies conducted this year.


There are four key areas driving this and 1SecureAudit has already figured this out:

Governance

Compliance

Liability

Reputation


Gartner and IDC also have some interesting predictions for growth in these areas.

Worldwide technology spending, including on telecommunications, will grow by 5.4 per cent to US$2.38 trillion (HK$18.56 trillion) this year, according to research firm Gartner.

However, global spending on business continuity and IT security solutions, at US$70 billion last year, is growing much faster, and will reach US$118 billion by 2007, according to International Data Corporation figures.


Operational risks are at the heart of all of this growth, especially in ASIA where Basel II is taking hold.

``Governance and compliance issues are driving the need for information security,'' partner Rick Heathcote said. ``In Hong Kong, we have observed that in order to comply with new laws and regulations such as Basel 2 [an international standard for capital requirements], personal data privacy laws and anti-money laundering obligations, companies are recognising the need for enhanced security and internal control.''

13 October 2004

CFO as CRO?

There seems to be some discussion on whether the CFO should also act as the Chief Risk Officer?.

These days, however, the risk management "tent" has grown into a "big top" called enterprise risk management (ERM). To be sure, the discipline should help companies cope with natural disasters, worker injuries, lawsuits against directors and officers, and other traditionally insurable perils, according to the long-awaited ERM framework issued late last month by The Committee of Sponsoring Organizations of the Treadway Commission (COSO).


Believe me, the CFO is way too focused on getting the financials right to add the equally important tasks of a CRO. The next thing they will be asked to do is take on duties associated with the CIO. This has to end.

But there's a big obstacle on that rosy career path. If a single executive manages the potential upside as well as the possible downside of a company's moves, there's the chance that the executive's decisions might be overly biased. If the CFO/CRO is especially fond of taking risks, then the company might end up excessively exposed to disaster; if the officer is too risk-averse, opportunities could be missed.

That, apparently, was the reasoning of the Office of Federal Housing Enterprise Oversight (OFHEO) when it sharply criticized J. Timothy Howard's dual roles as CFO and CRO at Fannie Mae in a September report on the mortgage company's accounting.


The Board of Directors has figured this out in most savvy financial services companies already. In fact, the CRO may soon have more of a powerbase inside the executive management ranks than the Chief Financial Officer if the trend continues.

12 October 2004

Operational Risk Headlines...

The newspapers are full of headlines today displaying the operational risks we contend with in these volatile days ahead of the US Presidential election:

Oil Prices Reach $54, a New Record - New York Times

US seizes independent media sites - BBC News

UN watchdog concerned by disappearance of nuclear material from Iraq - UN News Centre

U.S. Subpoenas Chiron Over Flu-Shot Shortage - SmartMoney.com

Fannie Mae faces DOJ probe, 8 investor lawsuits - Reuters

Feds: Hurricanes devastated Florida's citrus crops - Ft. Wayne News Sentinel

Westar testimony will include lavish lifestyles - CNN


The Global 500 company is dealing with a myriad of operational risks. Those that have proactive risk mitigation and management systems will survive. The question now is what will happen once the new President of the United States is finally decided.

What will happen with the price of oil? The corporate governance enforcement? World Trade and Diplomacy? The only thing of certainty is that the outcome of the elections will not affect the weather. Prepare.

11 October 2004

IPR making headway...

The Special 301 process is gaining some new attention in the IPR battle. The WIPO conference in Geneva has also produced some new headway in fighting the spread of Intellectual Property Rights violations.

“Special 301” is the part of U.S. trade law that requires the U.S. Trade Representative (USTR) to identify countries that deny adequate protection for intellectual property rights (IPR) or that deny fair and equitable market access for U.S. persons who rely on IPR.

Under Special 301, countries that have the most egregious acts, policies, or practices, or whose acts, policies, or practices have the greatest adverse impact (actual or potential) on relevant U.S. products and are not engaged in good faith negotiations to address these problems, must be identified as “priority foreign countries.” If so identified, the country could face bilateral U.S. trade sanctions if changes are not made that address U.S. concerns.


The 2004 Special 301 report has identified 34 trading partners and placed them on the watch list.

China and Paraguay, due to their serious IP-related problems are subject to another part of the statute, Section 306 monitoring, because of previous bilateral agreements reached with the United States to address specific problems raised in earlier reports.

07 October 2004

Beyond SOX: Keeping Up with Corporate Governance Changes

Most CIOs have been intimately involved in meeting Sarbanes-Oxley (SOX) deadlines and setting up auditing reporting processes. But if you're tempted to sigh in relief as your company becomes compliant - don't. Rather, this is the time to investigate the talk you've heard of "beyond SOX." As the reality of corporate boards' new accountabilities is played out, the CIO will be highly impacted. What specifically should you be doing now to keep up with fundamental changes in corporate governance?

The five things that A.T. Kearney consultants are recommending makes some sense. The close kinship with EDS makes the items look like they are designed for a CIO. The point is that the IT organization has a tremendous responsibility to continue to try and move as fast as the business is changing. This by itself is a formidable task. The key to keeping the business in alignment with Information Systems is to make sure you have a robust Enterprise Architecture initiative.

For more on this visit: Adaptive

06 October 2004

U.K. - Insurers Threaten to Pull Terrorist Cover -Continued

In last month’s Survive newsletter Patrick Roberts commented on an interesting article in the Times about insurance companies proposing to deny cover for terrorist attacks to businesses unless they can demonstrate a satisfactory level of business continuity planning. In response to this, Peter Higgins from 1SecureAudit sent us a few thoughts from a white paper the company has written on similar subjects:

In order to introduce new changes in process or design that impacts the physical or operational aspects of critical infrastructures (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners. Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety. Consistently the conversations are not about “if” something is going to happen, it is about “where” or “when” it is going to happen. Therefore, it is imperative we initiate a proactive hedge against the inevitability of a loss event occurring in the future. First however, we must understand the character of terrorism risk in critical infrastructure and some of the anti-terrorism tools currently available to help manage that risk.

The recognition by insurers that owners will continue to invest in terrorism risk reduction and building safety with the proper incentives is vital to overall risk management of critical infrastructures. The assessment of terrorism vulnerability in key structures identified as soft targets can be a key component of the rating of risk for a specific structure. In order for owners to benefit from the potential of reduced premiums from direct insurers they must be able to demonstrate a combination of risk mitigation measures and programs to help improve the survivability of the infrastructure or to reduce it’s vulnerability to certain threat profiles. These need to be exercised on a continuous timetable with extensive documentation, training and reporting.

In order for insurance brokers to accurately represent their buyers mitigation programs and measures to the direct insurers they must have a foundation of knowledge about the structures physical vulnerabilities. However, even more essential is the understanding of the operational and human attributes of the building that are contributing to the proactive tactics to prevent losses and further exposures to potential terrorism risk. If this step takes place, the insurers can better evaluate these operational and human elements to determine the value and effectiveness of these tactics so that they can be considered for premium reductions. The building itself, two miles from the White House, has little chance of moving outside the high-risk zone for terrorist events. The only methods for reducing risk exposures are to dramatically impact the operational and human elements of the building to mitigate hazards and increase the survivability of the people and systems that are resident. Insurance losses resulting from a catastrophic events fall into several key areas:

• Property losses to the target building and adjacent structures, incurred by the owners themselves.

• Liability losses for claims due to inadequate procedures for evacuation or fire prevention incurred by building owners.

• Workers compensation, health and life insurance losses resulting from death or injury of tenants or visitors to the building.

• Business income and rent loss due to inability to occupy the structures incurred by tenants and owners.

• Financial losses by various lenders and investors in mortgage-backed securities associated with the mortgage notes themselves.


The real estate finance community and building owners associations have been subjected to a substantial debate since 9/11 about the exclusions of Terrorism Risk insurance. The real estate and lending environments in target cities such as New York, Washington, DC and Los Angeles have been in turmoil over the unavailability or terrorism risk insurance at reasonable prices.

Anti-Phishing Consortium created...A Risky Business

As the newest band of banks collaborate on Anti-Phishing strategies one can only wonder what they will do differently to mitigate this operational risk.

The Financial Services Technology Consortium, a financial-industry research group, said Monday that 11 financial institutions--which include Citicorp, J.P. Morgan Chase, Comerica, Visa USA, ABN Amro, KeyBank, Capital One, and University Bank--will define technical and operating requirements for counter-phishing measures, and clarify the infrastructure fit, requirements, and impact of technologies when deployed in concert with customer education, enforcement, and other industry initiatives. The consortium named Gene Neyer, managing executive of its Security Standing committee, to lead the initiative.


The banks own FDIC has also been a recent target of this social engineering trend. Hopefully they will soon find out that these attackers are not using scripts, data taps or autonomous agents as their tools. A new generation of firewall will not stop this threat. These attackers are not exploiting vulnerabilities in design, implementation or configurations of web services.

These attackers are using social engineering stategies and tactics to create the unauthorized result that they seek:

1. Increased Access
2. Disclosure of Information
3. Corruption of Information
4. Denial of Service
5. Theft of Resources


These attackers only have the following general objectives:

A. Challenge, Status, Thrill
B. Political Gain
C. Financial Gain
D. Damage


And the trend will continue to escalate as fast as new people are getting online. Think about all of the 60+ people in the world who are now moving to online banking and other e-commerce services. A whole new generation of naive kids getting on the Internet before they are in middle school are falling prey to the social engineers we sometimes call voyeurs.

It's a risk to be doing business on the web today. The strategies of these criminals have not changed. What has changed is that now they can do it from the other side of the globe in countries our own FBI will continue to have challenges getting their cooperation. This is one risk we will be living with for some time to come.

04 October 2004

CIO SOX Report Card

A recent study has found that 93% of CIO's that were polled were clueless on their Section 404 compliance responsibilities of Sarbanes-Oxley.

"What they've failed to recognize is that 30-40% of a corporation's internal controls over financial reporting are information technology specific and that CIOs and other senior IT executives have a significant role in the process," he continued. "As a result, most corporate IT executives remain in the dark about their full responsibilities, even at this late stage, placing their companies at serious risk for failure. In fact, under the guidelines, if a company's CIO does not understand Sarbanes-Oxley Section 404 requirements, that alone demonstrates a deficiency in the control system."

Sarbanes-Oxley requires issuers of financial instruments in the U.S. - including all public companies whose shares trade on U.S. stock exchanges - to identify their significant financial accounts, the business processes that support those financial accounts and the applications and IT systems that support those business processes. Companies must then document and test the adequacy and effectiveness of controls at the financial reporting level, the application level, the IT infrastructure level and the IT management level. The deadline for the majority of public companies for Section 404 compliance is December 31, 2004 .

Continuity of Business: Hurricanes Lessons Learned

As the estimates come in from the losses from Florida hurricanes it looks like it will exceed $22 Billion.

The total economic impact is yet to be realized as this estimate is only the insurance claim payments estimate. Now that business has a better perspective on what being prepared really means, we should see some interesting Business Crisis and Continuity Management lessons learned here.

For example, how many organizations had their contracts in place with the diesel fuel supplier to replenish their back up generators after several days? Most prudent continuity planners would have such supplier arrangements already in place. However, if the supplier can't get to the business or their own plans have been disrupted then even the most well written contract will not hold up in the face of what happened over the course of a few weeks in Florida.

More importantly, the topic of outsourcing and redundant data centers continues to be a top strategic subject among COO's and CIO's as the operational risk events continue to surprise us. Let's just make sure that we take the time to exercise those plans and contingencies so that we go far beyond the contracts and actually test, learn and adapt.

30 September 2004

Operational Risk: People

After stopping by the booth at the ASIS conference in Dallas this week I'm convinced that Bruce McIndoe and his team are on to something great. Mitigating the risk of the loss of key personnel and other corporate assets is a vital priority.

iJet: ® Announces New Global Protection System
Ground-breaking Worldcue® GPS Application Employs Advanced Mapping, Notification, and Intelligence Capabilities to Better Protect Traveling Employees and Fixed Assets

Annapolis, Md - September 27, 2004 - iJET® Travel Risk Management (iJET), the industry leader in delivering real-time intelligence and proactive travel risk management services to multinational corporations and the travel industry, today introduced Worldcue® GPS, an innovative global protection system (GPS) for safeguarding people and assets, wherever they may be around the world. Worldcue® GPS employs advanced mapping, notification, and intelligence capabilities to make planning, monitoring, and crisis response more efficient and effective for those managing global risks.
"
Combining this capability with a focused surveillance and threat detection training program for employees could be exactly what our less than saavy corporate executives need. Peace of mind and to come home from their next business trip safely is the name of the game. The Threat Detection Program from 1SecureAudit provides a two day hands on course to educate and provide skills on various threats to individual security. These threats could include recruitment by a hostile service, kidnapping or assassination by terrorist and criminal elements or compromise by business competitors. Students are given intense, real-time instruction in surveillance detection and countersurveillance so that they can take appropriate actions.

Individuals whose occupations place them at risk may include people with access to valuable proprietary information or holders of high level security clearances, attorneys, judges, the wealthy and those responsible for their safety. This combination is one key strategy to mitigate the operational risks associated with key personnel in your organization.

29 September 2004

NFPA 1600 Tour...Will it come up short?

NFPA has announced that is has scheduled a series of workshops aimed at helping facility emergency managers understand and use NFPA 1600. The events will start in Miami in November and will be held in a dozen or so other major-city locations throughout the US over the span of a few months.

The question now is, who is going to attend and what is going to happen afterwards. A classic case of new standards and no action. The "What" known as NFPA 1600 is the new ANSI and National Fire Protection Association guidelines.

The standards are a taxonomy of common criteria for business continuity programs. In addition, it provides a list of resources within the fields of business continuity planning. Again, a worthy cause to get everyone on the same page. Now we have the "What". But do we have the "How"?

The tour is a great idea to create awareness. Now all we need to do is make sure that the owners of major infrastructure put it all into action. What needs to be done is always easier than how do it. The important step is to hire a reputable firm to guide your organization through the planning, execution and lessons learned of a Business Continuity or Disaster Recovery Exercise so that the next time it works even faster and is without major flaws.

27 September 2004

Fannie Mae Takes New Approach in Crisis

By Jeffrey H. Birnbaum and David A. Vise
Washington Post Staff Writers
Monday, September 27, 2004; Page A01

Fannie Mae, one of Washington's largest and most influential companies, is facing a serious crisis. Federal regulators have accused the mortgage-finance giant of cooking its books, in part to make room for huge bonuses for its top executives.

When confronted with emergencies in the past -- legislative efforts to tax the company or to end federal ties that give it a competitive advantage -- Fannie Mae has used a brass-knuckles approach. Its political machine, comprised of hired lobbyists, executives and directors of both political parties and grassroots groups nurtured by donations from its foundation, has long been able to run over its adversaries.

But this time, Fannie Mae is acting differently. While whispering to Wall Street that all the fuss is nothing more than a difference over accounting interpretations, the company's board has commissioned an independent probe led by former Sen. Warren Rudman (R-N.H.), making it clear that the directors want to put the matter behind the firm even if it means throwing some top executives overboard.

'I don't think they have ever faced a crisis like this. Political muscle is not going to fix this problem,' said Washington attorney Bill Lightfoot, who tangled with Fannie Mae over tax issues while a member of the D.C. Council."

26 September 2004

Securities Industry Subject to Basel II...

Since 1999, Basel II has been coming to a bank near you in America: "At the time, the Federal Reserve announced that the top nine banks - some of which, such as JPMorgan Chase, Citigroup and Wachovia, have brokerage businesses in addition to commercial banking arms - would have to comply and adopt the advanced measurement approach for their capital adequacy requirements for credit and operational risks."

The US securities industry including firms such as Merrill, Goldman Sachs and Bear Stearns will now be subject to BASEL II under the SEC's Consolidated Supervised Entities regime. The big question is whether the smaller brokerages will adopt the same approach to operational risk as many of the smaller regional banks have done.

To improve their operational-risk-assessment capabilities, firms are targeting three initiatives, says Dushyant Shahrawat, senior analyst in TowerGroup's securities practice: upgrading core infrastructure, including building data warehouses; using integration and business-process-management technology to improve operations workflow; and exploring newer technologies such as Web services and grid computing to improve operational-risk management.

23 September 2004

DHS: Ready for Business launch today...

The Department of Homeland Security launches the Ready for Business Campaign at the US Chamber of Commerce today.

The extension of the Get Ready site for business is supported by the following organizations:

* ASIS International
* Business Executives for National Security
* The Business Roundtable
* International Safety Equipment Association
* International Security Management Association
* National Association of Manufacturers
* National Federation of Independent Business
* Society for Human Resource Management
* U.S. Chamber of Commerce

The private sector is responsible for securing the infrastructure that they own and that is vital to our nations economy. Then why haven't the large owners of commercial real estate invested in pervasive preparedness initiatives to "Get Ready" for business disruptions? The simple answer is that they don't have enough incentives to do so.

Unfortunatley for the people who happen to be tenants in the largest commercial office buildings, the landlords believe that it should be everybody for themselves. And as owners of stock in Real Estate Investment Trusts (REITS), your question should be: What is the company doing to better protect our corporate assets (buildings, malls, manufacturing plants, hospitals) from a myriad of operational risks, including catostrophic events such as tornados and terrorism?

If the DHS "Ready for Business" campaign does nothing more than get owners feeling guilty about their level of committment to preparedness, then it has done the first part of the job. The rest will be left up to business itself to demand that their leased facilities are more secure, have properly trained staff to handle incidents of any kind and exercises to test and learn on a continuous basis.