13 February 2011

Digital Domains: Threats to Nation States and Corporate Board Rooms...

The last two plus weeks the planet Earth has witnessed the use of Digital Social Media to help facilitate the overthrow of the 30 year reign of Hosni Mobarak in Egypt. Is this the last example of how the use of the Internet combined with the masses of humanity can overthrow government leadership? The Operational Risk to nations states and the implications of the impact on business, commerce and political outcomes is increasingly being subjected to the new digital influence of social networking apps.

(CBS) The revolution in Egypt was historic not only for toppling President Hosni Mubarak after 30 years, but for revealing the awesome power social media had amassed - enough to be the instrument that inspired hundreds of thousands of people already staunchly opposed to the regime to rise up and act as one.

Now the questions are already being asked - can social media's power be used that way again and if so, where and when?

The protesters In Egypt were mobilized largely via the use of Facebook and Twitter, over 18 long days.

Special Section: Historic Change in Egypt

The revolt there is already being dubbed the Social Media Revolution.

It started Jan. 25, with a call-to-action -- from a Facebook page dedicated to Khalid Said, an Egyptian businessman who was beaten to death by police last summer after threatening to expose police corruption.

Millions of Egyptian youth are big users of Facebook, and saw the page.

Over time, a few prominent faces emerged from the masses. One, Google executive Wael Ghonim, identified by Mubarak's government as the creator of that first Facebook page, was detained.

But the movement had already gained momentum.

Facebook and Twitter, said one protester, "It's a very good way for communication. It has no power or control from anyone."

Now that the US State Department has established a Twitter feed in Arabic, the odds are that the strategy to more effectively communicate US policy to the muslim world will grow. The risks associated with the speed of communications via the Internet and the "Ground Truth" situational awareness have forever changed the meaning of an "Intelligence-led" enterprise. The continuous news cycles fueled by the masses will provide the Fortune 500 executives and the nations states world leaders with the sentiment of their brand, their policy or their reputation at the touch of a personal "Blackberry" or "iPhone."

What has not changed however, is the requirement for increased confidentiality, integrity and assurance of information whether that be streaming from the US State Department feed or the public relations department of a company such as Cisco. Will human behavior begin to migrate from reading the latest official press releases or the Facebook and Twitter feeds to better understand the current state of affairs on the company. The answer is both. It will just be a matter of what lens you want to look through to determine the truth about a subject or situation with the organization that you are investigating.

The information integrity conversation is ongoing from the board room to battle field. How do you continuously insure that the Intel or the digital data you are receiving is the truth and not changed along the path to the leaders decision support consoles? Monitoring the information streams within an organization is not only a strategic necessity, it is a survival requirement.

The company that runs the Nasdaq stock market said Saturday that hackers had penetrated a service that handles confidential communications between public companies and their boards.

The service run by Nasdaq OMX Group Inc. carries strategic information for about 300 companies. The company said it appears no customer data was compromised.

Nasdaq OMX said the hacking attempts did not affect its trading systems. Nasdaq is the largest electronic securities trading market in the U.S. with more than 2,800 listed companies.

The targeted application, Directors Desk, is designed to make it easier for companies to share documents with directors between scheduled board meetings. It also allows online discussions and Web conferencing within a board.

Since board directors have access to information at the highest level of a company, penetrating the service could be of great value for insider trading. The application's Web page says "Directors Desk provides multiple layers of security to protect our clients' most vital corporate records."

The Digital Domains will continue to be threats to Nations States and Corporate Board Rooms for years and decades to come.

07 February 2011

LEO: The Economics of Remote Digital Forensics...

At the speed of the modern global enterprise, cyber incidents are a growing component of operational risk, according to 1SecureAudit Managing Director and Chief Risk Officer Peter L. Higgins. Digital forensics intelligence provides analysts, investigators and management the ability to make more informed decisions regarding a prudent course of action. Utilizing digital evidence can mean the timely detection of unethical behavior by an employee or the intelligence nexus with kidnapping, child pornography, industrial espionage or terrorism. The legal process in a specific state or country and the preservation of evidence, chain of custody and even early case assessment are now a converging area of concern with local and state law enforcement, prosecutors and defense law firms.

"The 1SecureAudit Digital Forensics Practice capitalizes on the Digital Forensic POD powered by Evidence Talks Ltd. Our systems enable our team of subject matter experts to work on clients cases across the country or across the world," said Higgins. "Our certified professionals using the Digital Forensics POD gives a client quick access to resources that can help with an investigation without the high cost of flying people across the country or the globe."

"A good lesson learned from my first-hand experience in Afghanistan is that we depend on support back home from subject matter experts to help our soldiers remotely without the need to be in the actual combat zone," said Cristian Balan (CISSP, CHFI) of NY Computer Networks.

"We recognized that many police agencies, as well as law firms, needed an affordable solution to help clear up their digital forensics back log," said Craig Cantwell, SVDFL Forensics Laboratory Director. "By teaming up with 1SecureAudit and Cristian Balan and using our remote digital forensics POD systems, we are able to offer more clients a better economy of scale and service at a price that they can justify."

Counselors initial conferences and additional motions for discovery during litigation results in the need for additional digital forensics capacity. The Digital Forensics POD assists with case backlog especially as court dates approach rapidly or many cases at the same time. "We are excited to be working with Peter Higgins and the team at 1SecureAudit, as well as Cristian Balan of NY Computer Networks who brings his full Digital Forensic and Incident Response capabilities to the team," said Cantwell.

1SecureAudit has assembled a team of professionals that are ready to work on clients cases for a secure and timely response. With the advent of Remote Digital Forensics powered by Evidence Talks, the level of service and responsiveness that first responders can provide has increased tenfold. The firm's MetaLogic early case assessment services will ensure both civil and criminal cases are ready for an initial meeting with the legal teams. FlexResponse professional services ensures that client have the additional expertise available on demand as a case unfolds. The law enforcement organization, state or county prosecutors and private law practice now has access to experts across the country or the world at a moment's notice.

For more information visit RemoteForensics.us (http://www.RemoteForensics.us) or e-mail Dispatch@RemoteForensics.us.

30 January 2011

Crisis Management: ORM & Public Relations Convergence...

Operational Risk Management Executives will be tuning into CBS 60 Minutes Sunday night. If you are a Bank of America stakeholder and your stock dropped 3% on November 30, 2010 because of a WikiLeaks document release, this episode should be on your mind:

(Reuters) - WikiLeaks founder Julian Assange says he enjoys making banks squirm thinking they might be the next targets of his website which has published U.S. diplomatic and military secrets.

"I think it's great. We have all these banks squirming, thinking maybe it's them," Assange told the CBS television program "60 Minutes" in an interview.

CBS released a partial transcript on Friday ahead of Sunday's broadcast of the full segment.

Bank of America Corp shares fell more than 3 percent on November 30 on investor fears that the largest U.S. bank by assets would be the subject of a document release.

Interviewer Steve Kroft asked Assange whether he had acquired a five-gigabyte hard drive belonging to one of the bank's executives, as Assange had previously asserted.

"I won't make any comment in relation to that upcoming publication," said Assange, who is under a form of modified house arrest in England, awaiting an extradition hearing to Sweden for questioning over alleged sex offences that he denies.



WikiLeaks will not be the last whistleblower web site to provide the dirty laundry on what a government agency or public company may or may not be doing as it does it's daily business. The CBS or TMZ media mechanisms remain the outlet for an information economy that fuels the behaviors of modern day paparazzi or contributors to WikiLeaks and it's future competitors.

What are Operational Risk Managers thinking about when these loss events happen? Another lost or stolen laptop by one of the thousands of corporate executives is now a major incident, not one to be taken lightly, perhaps as it has in years past. This is also why these same managers are working in a diligent strategy to emphasize the use of products that will encrypt the whole hard drive on the mobile systems that are being toted around in taxi cabs and on airplanes. The thought of a loss of these tools will be less of an issue as these programs are implemented and every bit of every data on these mobile devices is now encrypted.

The External Affairs, Public Relations and Corporate Communications strategy for a Fortune 500 company is extensive. With Social Media becoming a major component of the Web 2.0 integration and the booming number of PDA's, iPhones and other mobile devices, "Crisis Management" and "Operational Risk" will continue to be two disciplines that need each other more than ever.

Bank of America will survive just as others have before it once the information is released and people have a chance to determine how damaging it could be or not worth the hype to pay attention to it. What will perpetuate beyond the latest PR crisis is the fact that the speed of data, videos, Tweets and Blogs continues to pile up on the hard disks, Jump Drives, IronKeys and servers in "The Enterprise Cloud." How you manage it, secure it and dispose of data is an Operational Risk that will not diminish any time soon.

Who has seen the light when it comes to the utilization of Cloud Computing, and effective document encryption in transit with embedded information security compliance standards? Uncle Sam for one.

WASHINGTON – The U.S. General Services Administration announced today that federal, state, local, and tribal governments will soon have access to cloud-based Infrastructure as a Service (IaaS) offerings through the government’s cloud-based services storefront, Apps.gov. GSA’s IaaS contract award allows vendors to provide government entities with cloud storage, virtual machines, and Web hosting services to support a continued expansion of governments’ IT capabilities into cloud computing environments.

“Offering IaaS on Apps.gov makes sense for the federal government and for the American people. Cloud computing services help to deliver on this Administration’s commitment to provide better value for the American taxpayer by making government more efficient,” said federal Chief Information Officer Vivek Kundra. “Cloud solutions not only help to lower the cost of government operations, they also drive innovation across government.”


The use of new technologies or platforms such as these only provides the Operational Risk Professional with new found ways to mitigate risks, not eliminate them. Therefore, whether you are the CIO at B of A or part of the Federal CIO Council in the United States the fact remains that people will continue to use lost or leaked information to their advantage. This is a threat to the enterprise no different than the loss of power, catastrophic fire or natural disaster. When you have a known threat out there such as WikiLeaks, then you now realize that this must be addressed in your vulnerability assessments and your risk management planning.

Google Apps is now FISMA Certified. Whether the number of incidents increases or diminishes will still remain with the behavior of people and the ability for OPS Risk management to continue to be part of the executive conversation on the risks of data getting into the wrong hands. With this being an inevitable situation, the convergence of crisis management, PR and media communications will increasingly become part of the Enterprise Risk Management team. Let's just hope they keep a seat for the 28 year old IT staffer who supports the implementation of their enterprise apps and the exponential growth of their information cloud.

22 January 2011

Digital Paradox: Privacy v. Security...

The media communications and advertising industries are buzzing over the new U.S. Federal Trade Commission report and framework entitled: Protecting Consumer Privacy in an Era of Rapid Change. The Operational Risk Management implications to your enterprise could be significant if you currently do not understand how your marketing department provides disclosures or manages consumer collected data. If you think that you are protected because you outsource to a 3rd party, then think again. The power to the consumer is increasing and the data privacy laws are playing a quick game of catch-up on regulation:

Scope: The framework applies to all commercial entities that collect or use consumer data that can be reasonably linked to a specific consumer, computer, or other device.

Companies should promote consumer privacy throughout their organizations and at every stage of the development of their products and services.

With 500 Million plus people who are self-profiling themselves on Facebook these days, you might wonder if they even truly think about their privacy. See Controlling How You Share, Facebook
A variety of business models involve practices that fall outside the proposed “commonly accepted practices” category. These include, for example, a retailer collecting purchase information directly from a consumer and then selling it to a data broker or other third party that may be unknown to the consumer. Other examples include online behavioral advertising, in which an online publisher allows third parties to collect data about consumers’ use of the website, as well as social media services, where the service or platform provider allows third party applications to collect data about a consumer’s use of the service. In addition, as noted above, using deep packet inspection to create marketing profiles of consumers would not be a commonly accepted practice.

The new framework and panel discussions has focused on the Operational Risks associated with collecting, storing and sharing data on consumers. The regulations that change going forward to assist in consumer protections and disclosures may not have much impact on whether the consumers "Personal Identifiable Information" (PII) is disclosed to nefarious transnational criminal syndicates without their permission.

If you are a U.S. government military employee you may have received notice lately from your PenFed Credit Union that you too may have your PII in the hands of people that will use it for monetary gain. The continuous loss of data by institutions has now been verified as just another criminal business enterprise by organized crime and in many cases sanctioned by nation states. The data protection and data theft game is the modern equivalent of bank robbery yet it is moving at the speed of electrons across fiber optic networks world wide.

And now that this accelerating consumer issue of cybersecurity has made it's way to The White House, one can only wonder what may change. The cost to business is now $204.00 per record according to well respected research by Ponemon Institute. The MOU with DHS, Department of Commerce and the Financial Services Sector Coordinating Council (FSSCC) remains the window dressing on another unfunded effort to deter the cyber plague before us.

There is no shortage of people reporting about the breaches (this blog included), the hacks and the data leakage via employees using Peer 2 Peer file sharing software within the walls of their Fortune 500 company or government agency. Some people who are disclosing the information are doing it with alternative motives and rarely try to provide a potential solution to the problem.

So what can a PenFed or major U.S. Government agency do, to stem the tide of the growing digital tsunami of data thefts and transnational economic crime or acts of espionage? There is not one solution nor is there ever going to be a day when it all comes to an end. Which brings us to the mind set shift that is necessary to make a difference.

The Security vs. Privacy legal topic is somewhere in the mix of the solution. The education of our digital natives at a young age is another. Many kids know how to type with their thumbs better than they can write a legible letter to grand mother. And finally, the implementation of new technologies that will enable law enforcement to their jobs more effectively.

Now back to the mind set shift. Cecilia Kang of the Washington Post reports:

As the United States looks at ways to better protect Internet users’ privacy, Europe is going through its own update of online privacy rules. The 27-nation European Union is taking a more aggressive approach to privacy by setting higher bars for how data can be collected on Web users.

European laws prohibit Web sites from tracking users without their permission. The E.U. is also weighing legislation that would let users delete all their information from a Web site, such as Facebook, and transfer data from one wireless provider to another without leaving profiles behind.

Viviane Reding, the vice president of the E.U. Justice Commission and head of privacy regulation, visited The Post on Wednesday to talk about her approach to protecting users in the age of Internet over-sharing. On Thursday, she is scheduled to meet with U.S. Attorney General Eric Holder to discuss ways the E.U. and U.S. can cooperate on safeguarding consumers' personal information, including data on travel and finances. The talks may also touch on the recent disclosure of classified documents by Wikileaks.


09 January 2011

Cyber Theft Rings: A Nexus with Terrorism...

BSA/AML compliance is an Operational Risk that continues to plague even the largest institutions. The ability to effectively program information systems to address "Politically-Exposed Persons" (PEP) and the risk to the banks reputation are still a challenge for some executives.

Why is this still an OPS Risk issue? In many cases, the lack of procedures being followed by adequate staff in the alert investigations unit where backlogs are prevalent. This becomes a business risk because there continues to be a lack of closure on these alerts. The simple monitoring of funds transfers to ensure timely reporting of suspicious activity associated with PEP's should be AML 101.

Retaining and deploying an independent consultant to review compliance and systems controls is the primary responsibility of an Audit Committee chair of the Board of Directors. For those institutions that have found themselves under the recent oversight of the OCC in the United States, many realize they have underfunded this obligation and the staff requirements to stay in pace with the expanding volume of electronic transactions.

Monitoring accounts of current or former senior political figures is well within the PEP definition and includes their families and any close associates. Therefore, the BSA officer will require even more robust budgets, staffs and systems programming to continue to be effective in regulatory compliance of the Bank Secrecy Act and Anti-Money Laundering statutes. And this just covers the risks associated with the banks regulatory obligations in the United States and many other countries of the world.

Yet this is the area that has traditionally been the foundation for the 20th century criminals and other entities who need to move money to places in large sums or to perpetuate fraudulent activities. Now what about the 21st century asymmetric threat, "Cyber Theft Rings"?

Malware exploiters purchase malware on the black market Internet and use it to steal victims banking credentials. They launch attacks from systems that are already compromised across the globe in small businesses and other commercial or government organizations. This allows the transnational cyber criminal to transfer stolen funds and deter the tracking of their activities. Money Mule networks then transfer funds to other accounts or get cash from ATM's and then buy stored value cards before they ship them back overseas to the crime syndicates.

The victims remain the financial institutions and the owners of the infected systems. So how large is this method of cyber theft? In 2010 the FBI reported close to 400 cases that had attempted loss of $220M and actual losses of $70M.

Today's (October 1, 2010) coordinated operation demonstrates that these 21st-century bank robbers are not completely anonymous; they are not invulnerable. Working with our colleagues here and abroad, we will continue to attack this threat and bring cyber criminals to justice."

Most of the accused hailed from Eastern Europe; many were based in Ukraine, where several worked as Web developers. Ten suspects were arrested in New York on Thursday, with another 10 having been arrested previously. The FBI is still seeking 17 others .


Where is the money going and what is it being used for? In a recent study by officials at the New York State Intelligence Center titled: "The Vigilance Project: An Analysis of 32 Terrorism Cases Against the Homeland", the statistics are the face of the US challenges with money laundering and terrorism:

  • 82 % were between the ages of 18 and 33.
  • 61 % attended some college and of these 64% of the educated terrorists were engineering majors.
  • 50 of the 80 suspects in the study whose citizenship could be identified were born in the U.S. .
  • 11 of the 32 cases studied happened in the past two years. In these cases, 17 of the 19 defendants were in the United States legally.
The banking community understands that it has to remain vigilant when it comes to BSA/AML regulations. Not only to avoid the millions of dollars in potential fines, but also because of the potential nexus with counterterrorism.

31 December 2010

Denial: Resolution for a New Year...

On the eve of the New Year, 2011 approaches with new perspectives and new found learning on the risks before us. Operational Risk is about managing "All Hazards" and "All Crimes" whether you are working within the ranks of the largest global 500 organization, or managing self as J. Q. Citizen. OPS Risk is just not about a government or corporate perspective any longer and is becoming more personal for many professionals in their daily lives. Managing their families, their households and the risks associated with spouses, parents, siblings and even those who you don't even know. But they know you.

In Dr. Jessica Stern's latest book "Denial: A Memoir of Terror" you will find that her story is very much about your own personal operational risk management. It will transport you into thoughts about all of the ways that people can learn about you and your personal life through good old fashioned surveillance or today on Facebook or Twitter. Yet this isn't about this new age phenomenon of digital stalkers or voyeurs. This story is about "Denial" and the risk of denial in the context of observation or your own behavior and the others who surround you.

"Denial is almost irresistibly seductive, not only for victims who seek to forget the traumatic event but also for those who observe the pain of others and find it easier to ignore or "forget." In the long run, denial corrodes integrity--both of individuals and of society. We impose a terrible cost on the psychically wounded by colluding in their denial."
In this skillfully wrought, powerful study, a terrorism expert, national security adviser (The Ultimate Terrorists), and lecturer at Harvard, returns to a definitive episode of terror in her own early life and traces its grim, damaging ramifications. Having grown up in Concord, Mass., in 1973, Stern, then 15, and her sister, a year younger, were forcibly raped at gunpoint by an unknown intruder; when the police reopened the case in 2006, Stern was compelled to confront the devastating experience. The police initially tied the case to a local serial rapist, who served 18 years in prison before hanging himself. Stern's painful journey takes her back to the traumatic aftershocks of the rape, when she began to affect a stern, hard veneer not unlike the stiff-upper-lip approach to survival her own German-born Jewish father had assumed after his childhood years living through Nazi persecution. Covering up her deep-seated sense of shame with entrenched silence, Stern had a classic post-traumatic stress disorder—which she was only able to recognize after her own work interviewing terrorists. Stern's work is a strong, clear-eyed, elucidating study of the profound reverberations of trauma.

Dr. Stern brought to light in her process of interviewing people, that "Denial" can be a true "Operational Risk" in itself. How many times have you observed someone's behavior and thought to yourself, that doesn't feel right. How many times have you said to yourself, this behavior is not good for my own well-being? This self-talk is something that all of us need to pay more attention to, as we embark on this New Year and the next decade of the 21st century.

What behavior have you witnessed lately that you are in denial about? Make a New Year's eve wish, pledge or resolution that this has to end. What ever the behavior that has occurred or will soon occur, the risks are too great to remain in denial. The trauma that exists in your mind or the potential impact that a future trauma may have, can be managed from a risk management point of view. What is the likelihood and the impact to you, your organization or your friends and family?

As we all watch the ball drop tonight at 12:00 midnight in the USA in Times Square New York City, reflect on the 2010 risks that you took by continuing to be in denial. Think about all of those people you encounter everyday at work, in the local grocery store and even in your own neighborhood. Open your eyes and your mind to the behaviors that just don't seem right. Manage your risk exposure when it comes to the people you associate with and the people who are watching you, without your knowledge.

The contributor(s) to this Operational Risk Management blog wish you a Happy and Prosperous New Year!

03 December 2010

Remote Digital Forensics: OPSEC Continuous Monitoring...

What do Operational Risk Management, continuous monitoring and "Remote Digital Forensics" Intelligence have in common? The digital age is challenging the global enterprise and the speed and depth of new found transnational threats requires bold outside-of-the-box thinking. Strategic decisions to prevent incidents of data leakage, theft of trade secrets or corporate espionage are on the minds of CEO’s and the Office of the General Counsel.

An organizations ability to proactively deter, detect and defend it’s vital corporate assets requires a focused lens to view the vast digital complexities and simultaneously gain deeper insights. Effective risk management in Global 500 companies encompasses the collection, analysis and action on relevant information. Is the relevant information stored on a mobile laptop, network attached desktop or mobile PDA? Could there be a copy of the document on the server in the form of an e-mail attachment? The objective seems obvious. Think a few steps ahead in order to mitigate the quantity and size of potential loss events where and when they will happen.

In order to achieve a “Game Changing” strategy to stay one step ahead of today’s digitally equipped adversary demands an adaptive process, tools and very smart people. Timely and accurate intelligence-led investigations have historically proven to save many organizations from catastrophic impact to their reputation. That is precisely why Digital Forensics Intelligence (DFI) has been gaining tremendous momentum with the Chief Risk Officer, Chief Security Officer, Chief Information Officer and the General Counsel. One example, is the ability for an organization to add forensic intelligence to almost any investigation, to provide additional dimensions of insight and to ascertain whether an employee is a true insider threat or just in non-compliance with your latest “Acceptable Use Policy.”

Corporate Digital Forensics Intelligence provides the corporate first responders with the potential evidence required by analysts, investigators and decision makers to make more informed decisions. The ability to more effectively determine a prudent course of action, can mean the difference between detecting a simple Internet policy violation or the beginning of a prolonged investigation with a corporate espionage nexus. The legal process in your state or country and the preservation of evidence, chain of custody and even early case assessment are now a converging area of concern with the office of the General Counsel and outside retained law firms.

“Achieving A Defensible Standard of Care” in your organization requires a digital risk governance framework that will withstand the tests of local law enforcement and judicial systems, inspector generals and global federal investigations. Remote and SPEKTOR Digital Forensics Triage has been gaining momentum with corporate enterprise, law enforcement and military investigators for years.

The reason is that certain kinds of investigations can't wait for days, weeks or a month to gain insight and evidence on the digital data stored on a suspects laptop, desktop or PDA. With the legal corporate policy in place or search warrants the fast Digital Forensics Triage process allows First Responders to quickly examine and determine what digital assets need to be seized and those that do not have any major "Red Flags". This keeps the corporate Digital Forensics Lab or RCFL from being overburdened with devices that hold no relevancy to a particular case and therefore minimizes the mountain of unexamined digital evidence.

The use of both Digital Forensic Triage and Real-Time Network Forensics solutions directly addresses the compliance requirements in the US Government for "Continuous Monitoring."

How can organizations address advanced persistent cyber threats?

To address the advanced persistent cyber threat requires a multi‐pronged effort by organizations. First, it requires a major change in strategic thinking to understand that this class of threat cannot always be kept outside of the defensive perimeter of an organization. Rather, this is a threat that in all likelihood, has achieved a foothold within the organization. This situation requires that organizations employ methods to constrain such threats in order to ensure the resiliency of organizational missions and business processes. Second, it requires the development and deployment of security controls that are intended to address the new tactics, techniques and procedures (TTPs) employed by adversaries (e.g., supply chain attacks, attacks by insiders, attacks targeting critical personnel). NIST Special Publication 800‐53, Revision 3, includes many new security controls and enhancements (most not selected in any of the control baselines) that are specifically intended to address some of these TTPs. Finally, to enable cyber preparedness against the advanced persistent cyber threat, organizations must enhance risk management and information security governance in several areas.

These include, but are not limited to: (i) development of an organizational risk management and information security strategy; (ii) integration of information security requirements into the organization’s core missions and business processes, enterprise architecture, and system development life cycle processes; (iii) allocation of management, operational, and technical security controls to organizational information systems and environments of operation based on an enterprise security architecture; (iv) implementation of a robust continuous monitoring program to understand the ongoing security state of organizational information systems; and (v) development of a strategy and capability for the organization to operate while under attack, conducting critical missions and operations, if necessary, in a degraded or limited mode.

Operational Risk Management calls for a robust and smart Information Governance Framework whether you are a Global Enterprise or a National Government. As the international WikiLeaks aftermath unfolds it will finally unveil the facts about "How" this incident could have happened. What is certain today is that the answer does not lie with new technology or tools. Human Factors and social engineering will always have the upper hand.

09 November 2010

Operational Risk: 7 years and counting...

After writing this blog now since 2003, it is amazing how some items seem to be coming back full circle. Operational Risk does not change; only the places and the particular circumstances change. Do you know where a loss event will impact you and your organization next?

The US has intensified its war on terrorism on the financial front, targeting an ancient, informal system of money transfers that officials believe funnelled millions of dollars to Osama Bin Laden's al-Qaeda network.

The system is known as hawala, and it has been used for hundreds of years to move money across distances and around legal and financial barriers in South Asia and the Middle East.

The California Public Employees' Retirement System (Calpers) is opposing Freddie Mac's reappointment of auditor PricewaterhouseCoopers and the reelection of members of the mortgage finance company's audit committee, according to the Washington Post.

Any board member or executive today is well aware of the direct impact an adverse event or significant business disruption can have on shareholder value and customer confidence. When it does happen, how many people just throw up their hands and shout, Murphy's Law!

Murphy's Law ("If anything can go wrong, it will") was born at Edwards Air Force Base in 1949 at North Base.

It was named after Capt. Edward A. Murphy, an engineer working on Air Force Project MX981, (a project) designed to see how much sudden deceleration a person can stand in a crash.

Corporate Governance in the board room itself is blazing out of control at Hewlett Packard (HP) as a result of an internal investigation. The finger pointing, board resignations and ethics questions are all in the news. And that is just a very small story on the entire landscape of corporate digital surveillance or internal investigations. This is a business your insurance company is funding and for good reason.

These snapshots of the past demonstrate the variety, breadth and depth of the Operational Risk Management challenges before the Fortune 500 and the small-medium-enterprise (SME) that has limited staff and resources. Yet the time, effort and resources dedicated to the INFOSEC, OPSEC, Internal Audit and Risk Management functions within the enterprise are in many cases dwarfed by the Marketing and Advertising line items in the budget.

Will one more 30 second spot of an insurance lizard (GEICO) or vikings doing their banking (CAPITAL ONE) really make us change brands? Doubtful. On the other hand, if you were to show us that the bank is now using Multi-factor biometrics for it's online banking access and transactions you might make us switch. Perhaps the insurance carrier could make us change with a difference of 45% not just 15% savings because we doubt you will be able to hedge the risk of another driver running into the back of my automobile on a rainy day on the freeway.

Operational Risk will continue to evolve as much as an "Art" as it is a "Science" because there will never be the perfect algorithm or software program to give you a sensor alert in time or in the right place. You need human factors to use such mechanisms as "Intuition", "Reid Technique", and other senses that only the Homosapien has the ability to process with a brain that contains a large cerebrum. Without lot's of these brains making sensual observations, analyzing and processing the possibilities; the likelihood of an adverse event will increase dramatically.

We are still amazed that organizations are spending more time and effort on sophisticated sensors and technology and less on the human factors. Yet the right ratio of both can get you to that place that tips the scales in your favor and your enterprise is on the verge of being more proactive, preventive and predictive.

When was the last time you spent a day on the front lines with your OPS Risk Team? It could be a CEO's wake up call...

19 October 2010

OPS Risk: Diversifying Systems Portfolio...

What kind of testing, experiments and operational risk projects are your organization running simultaneously right now? As an example, do you have an OPS Risk project where a business unit has moved entirely to using "Google Apps" for their entire computing utility platform? Migrated the e-mail system to Gmail, eliminated the use of Microsoft Office Suite and Outlook for the purpose of increasing your understanding of the benefits, vulnerabilities or other metrics. If you have not, the question is why not?

We recommend you do this now. Move an entire business unit, such as the crisis management team or operational risk management department to jump off the "Microsoft Mother Ship" and develop several metrics categories. Buy everyone a Blackberry or Android based smart phone and couple this with an Android-based Tablet PC or soon to the market the Blackberry Playbook. Enable a domain for use by the team for all participants to get on Google Apps and keep the team dedicated to being enterprise connected, yet possibly more resilient to any major internal business disruption.

You must establish metrics beyond the technology and app compatibility and focus in on productivity, accessibility and any failures in the systems themselves. Once you have untethered your team from the Microsoft-centric platforms in the enterprise and now are living in the virtual cloud or outsourced world of using Google Apps or other SaaS or IaaS-based solutions, the testing is only beginning.

The behaviors that your employees now take upon themselves to work within this new set of tools, devices and services may very well pave the way for the organization to be more resistant to several corporate plagues. Besides the normal scourge of Microsoft related exploits by Malware and Trojan horses it would be interesting to measure how people actually feel. Do they feel or have an attitude of being more productive or less? Are the new behaviors that they are experimenting with doing their work giving them more insight, increased speed to answers or greater reach into the information they need to make important decisions?

And even if this team was finding that there were missing capabilities from their Microsoft Exchange and Outlook apps, you could still migrate them to a hosted solution outside your own enterprise. This outsourced yet hosted somewhere else Microsoft-based platform could be the answer where you have teams that must be using a Microsoft-based OS desktop, tethered to a Microsoft-based enterprise app. There are even now governments making the case for the exodus to Google Apps:

The debate continues about whether cloud computing and hosted services put sensitive data at risk or actually realize the cost savings that are promised. Some local governments have determined that the return on investment for moving to cloud-based services isn’t sufficient yet to justify moving in that direction. But the concern isn’t universal. Orlando, Fla.; Washington, D.C.; and some departments in New Mexico and Colorado have already migrated to Google Apps.

This year, Google even launched a version of its productivity suite tailored for government customers that meets federal IT security benchmarks. According to the company, Apps for Government is the first cloud computing suite to receive Federal Information Security Management Act-moderate accreditation, designed to standardize IT security across the government and relieve concerns about perceived security risks.

“By the end of the migration, most customers are convinced that data would be safer in Google data centers,” Cohn said.

Not all governments believe in cloud computing as the smart solution. Some local governments don’t see the cost benefits in migrating unless it’s a last resort. Some observers believe that was the case in L.A.

Last year, the city decided to implement Gmail on more than 30,000 desktops and adopt the suite. The five-year deal made L.A. the first government of its scale to choose Gmail for the enterprise.

Whether you are the City of Los Angeles, Washington, D.C. or other smaller jurisdictions, you can start to see that the momentum is starting to take effect. So the Operational Risk Management team at your organization might be on to something as they break away from the corporate Mother Ship, to test and try the resiliency and the productivity of another platform outside the Microsoft Suite.

As you begin to explore the number of new apps that are working on the integration with Google you start to see other places that maybe, you can eliminate Microsoft Excel, Word and Project Management:

The Google Apps Marketplace offers products and services designed for Google users, including installable apps that integrate directly with Google Apps. Installable apps are easy to use because they include single sign-on, Google's universal navigation, and some even include features that integrate with your domain's data.

Operational Risk Management is about testing and experimenting to find the vulnerabilities in your current environment. It's about establishing teams with new and different ways to running their day to day business in order to increase the resilience of certain core capabilities within the enterprise. Have you ever had a financial planner say, "You need to diversify your portfolio."? Let's just hope you listened to this piece of wise advice these past two years...

04 October 2010

Stuxnet: Digital Sabotage of Critical Infrastructure...

The Chief Information Security Officer's (CISO) are getting significant new understanding of the new threat emerging in the digital domains. The Energy, Chemical, Water, Transportation and other Critical Infrastructure sectors are on high alert. The Operational Risks associated with their Programmable Logic Controller (PLC) systems using Siemens technologies are being attacked. Stuxnet is a new worm that has emerged over the past few months and is being analyzed from several vectors. One analysis that is forthcoming is who developed this new sophisticated industrial sabotage cyber weapon? Let's consider this logic from Ralph Langner:

Many aspects of Stuxnet are so completely different from malware as we know it that it's only natural that so many hard-working experts at some point in the analysis ended in frustration. The best way to approach Stuxnet is not to think of it as a piece of malware like Sasser or Zotob, but to think of it as part of an operation -- operation myrtus. Operation myrtus can be broken down into three major stages: Preparation, infiltration, and execution.
Stage 1, preparation:
- Assemble team, consisting of multiple units (intel, covert ops, exploit writers, process engineers, control system engineers, product specialists, military liaison)
- Assemble development & test lab, including process model
- Do intel on target specifics, including identification of key people for initial infiltration
- Steal digital certificates

Stage 2, infiltration:
- Initial infiltration using USB sticks, perhaps using contractor's comprised web presence
- Weapon spreads locally via USB stick sharing, shared folders, printer spoolers
- Contact to command & control servers for updates, and for evidence of compromise
- Update local peers by using embedded peer-to-peer networking
- shut down CC servers

Stage 3, execution:
- Check controller configuration
- Identify individual target controllers
- Load rogue ladder logic
- Hide rogue ladder logic from control system engineers
- Check PROCESS condition
- Activate attack sequence

For the CISO and executives who are sitting around the latest emergency CISCO Telepresence call at companies such as Entergy, American Electric Power, Dominion Resources and dozens of others in the power grid industry; the reliability factor is uncertain.

If this new malware had an initial project budget cost of seven figures $,$$$,$$$.00 to achieve the three stages described previously, preparation, infiltration, and execution then the price will soon be more affordable. A price for a malware exploit kit such as this one as it is reengineered for other purposes or types of targets will decrease dramatically as it propagates across the Internet.

The significance of the decrease in price is that now it will be more affordable for the transnational economic crime syndicates. How they will utilize the new Stuxnet capability in their toolkit for cyber extortion, digital sabotage and other schemes remains to be seen. What is certain is that it will not be long before this becomes a reality. Gary McGraw comments further:

Stuxnet is a fascinating study in the future of malware. Not only did it reveal at least 4 0days (which are still being patched by Microsoft), it clearly demonstrated that physical process control systems of the sort that control power plants and safety-critical industrial processes are ripe for compromise.

Now that the genie is out of the bottle, it is hardly possible to stuff it back in. Expect the techniques and concepts seen in Stuxnet to be copied. Attacks on process control systems are no longer the fantasies of paranoids in tinfoil hats — they are here.


The next Operational Risk that will be on the horizon are the plaintiff law suits, each time we have an event like this one:


Pacific Gas and Electric Co. on Monday announced it would put as much as $100 million towards rebuilding areas of the Crestmoor neighborhood destroyed in the flames. PG&E president Chris Johns maintained that money in that relief fund would be spent on reconstructing the San Bruno neighborhood, not paying off potential legal claims. Nonetheless, the utility company reportedly already cut the city a $3 million check to cover expenses associated with responding to the disaster. PG&E is also expected to pay victims whose homes were destroyed up to $50,000 to help pay for their everyday necessities. “I realize money can’t return lives. It can’t heal scars, it can’t replace memories… But there does come a time for healing and for rebuilding, and we are committed to helping that happen,” Johns added.

A full probe would be required to determine what might have caused the 30-inch high-pressure gas pipeline to burst at Earl Avenue and Glenview Drive around 6:15 p.m. that Thursday evening. Thirty-seven homes were apparently leveled in the blast. A 30-foot-wide crater could also be seen in the aftermath of the explosion. Authorities evacuated over 100 people in the area immediately after the blast. Now the California Public Utilities Commission has ordered PG&E to check all high-pressure gas lines located in densely populated areas. The National Transportation Safety Board (NTSB) is leading the investigation into the fatal San Bruno natural gas explosion.


It is too early to determine the exact nature of the cause of the San Bruno, CA disaster yet the corporate general counsel's of major utilities are preparing for their defense. The legal risks could go well beyond the exact scene of the explosion. Why? As the plaintiffs examine the number of PLC and SCADA controllers involved in the area of the incident, you can be certain they will be looking at the software systems associated with them. They will be requesting the Information Technology organization at PG&E to produce evidence of their policies, procedures, and best practices as it pertains to SCADA exploits such as the Stuxnet worm.

Managing the Operational Risks associated with the Energy and Chemical "Critical Infrastructure" sectors goes well beyond the norm of security and safety. Even BP has established a new Operational Risk initiative in the aftermath of their Gulf of Mexico catastrophe.

BP is to create a new safety division with sweeping powers to oversee and audit the company’s operations around the world.

The Safety & Operational Risk function will have authority to intervene in all aspects of BP’s technical activities.

It will have its own expert staff embedded in BP’s operating units, including exploration projects and refineries. It will be responsible for ensuring that all operations are carried out to common standards, and for auditing compliance with those standards.

The powerful new organisation is designed to strengthen safety and risk management across the BP group. It will be headed by Mark Bly and report directly to incoming chief executive Bob Dudley.

The company said the decision to establish the new function follows the Deepwater Horizon accident in the Gulf of Mexico and BP’s investigation into the disaster. It is one of a number of major changes announced by Dudley as he prepares to take over his new role on October 1.

Who will be in charge of the "Stuxnet Task Force" ?

18 September 2010

China Syndrome: FCPA & Rating Agencies...

A modern day "Operational Risk China Syndrome" is making the Board of Directors nervous these days. The new syndrome otherwise called the Foreign Corrupt Practices Act (FCPA) has been the buzz at rating agencies for months. Are you sure about your ability to withstand the scrutiny of a FCPA litmus test? Board Member Magazine explains:

On June 2nd, Fitch Ratings agency announced that Foreign Corrupt Practices Act violations could result in ratings downgrades. That’s one more reason boards should educate themselves on FCPA and how their companies are monitoring FCPA-related risks. It appears, though, that many boards do not feel comfortable with their companies’ compliance programs. In a soon-to-be released survey from KPMG’s Audit Committee Institute, only 27 percent of U.S. audit committee members said they were satisfied that their company had an effective process to manage Foreign Corrupt Practices Act risks, and other risks associated with doing business in Brazil, Russia, India, China and other emerging markets. 35 percent of respondents were only somewhat satisfied, and 9 percent said process improvements were needed in conducting such business, which may include sourcing, outsourcing, manufacturing, or sales and distribution channels.

As your Business Development teams fan out across the globe to satisfy the appetite of the Chinese economy for critical infrastructure, establish a sound and effective awareness, training and audit program. What are the ramifications of putting unprepared personnel on the ground to do business in the Chinese Markets?

American companies or individuals who enter joint ventures with foreign partners, as well as those who hire foreign agents or distributors in China, must be extremely cautious of the vicarious liability that they may face as a result of a third party's violation of the principles set forth in the FCPA. According to the Justice Department, an American company will be subject to liability under the FCPA if it makes payments to an intermediary third party with the knowledge that such payments will go to a foreign official for corrupt purposes. Conscious disregard is enough to satisfy the requirement; if the American company is aware of a "high probability" that such payments will occur, the knowledge requirement will be satisfied. More importantly, a joint venture partner, agent, or distributor will be considered an intermediary third party for purposes of the FCPA. Therefore, any violation of FCPA standards by one of those parties could result in the American company being vicariously liable under the FCPA.

In order for the Board of Directors to have peace of mind on the emerging markets business opportunities first a substantial compliance framework needs to be established. Next, the implementation of predictive analytics software to manage the complexity of companies, people and relationships as you do business in any of these countries. This includes the subscription to several databases that include the constantly changing landscape of specially designated nationals (SDN) and politically exposed persons (PEP). World check explains:

During the period 2005 to 2007 alone, more than 310 elections and by-elections took place around the world – that’s an average of nearly 10 elections per month. (Source: ElectionGuide.org). This means that your existing clients may be elected to public office, and hence become PEPs, without your business knowing it. It may be that you only apply your due diligence processes to new customers and so miss a whole category of individuals that do not meet your corporate risk appetite. As such, routine and ongoing PEP risk screening is not only considered best practice, but is also a legal requirement.
In practice, full compliance with PEP legislation has not come without major operational challenges. In the post-9/11 era, the proliferation of regulatory compliance laws, combined with the need to screen hundreds of thousands of users and accounts on a routine basis, has created a substantial administrative burden for businesses subject to PEP legislation.

The sheer magnitude of the due diligence challenge has subsequently led to the adoption of a risk-based approach to regulatory compliance, but nevertheless Enhanced Due Diligence and ongoing risk management is still required for PEPs. Broadly speaking, the risk-based approach entails the identification of risks that exceed your business’ stated risk appetite (including the need for regulatory compliance), and then matching individuals and entities against these heightened risks during the preliminary stages of due diligence. Should a person fall into one or more of the specified heightened risk categories, additional due diligence is then required.

As your company establishes it new China-based strategy for partnerships, joint ventures or actually putting employees in country the operational risks become exponential. Remember, a sound and prudent risk framework includes a 4D approach:

  • Deter
  • Detect
  • Defend
  • Document

With these established and operating on a global basis the Board of Directors will be sleeping more soundly. Or perhaps not...learn more.

11 September 2010

Remembering 9/11: Teaching the Children...

Where were you on September 11th, 2001? Everyone seems to remember...

On a cool sky blue morning, 9 years ago in Northern Virginia, sitting in a hotel restaurant having breakfast around 8:00AM with a business colleague. A little over 40 minutes into our discussion, we heard some people talking quite loud in the bar next to us as they tuned into CNN. As cell phones rang around us, they were all loved ones checking in and urging us to hurry home.


8:46:40: Flight 11 crashes at roughly 490 mph (790km/h or 219m/s or 425 knots) into the north face of the North Tower (1 WTC) of the World Trade Center, between floors 93 and 99. (Many early accounts gave times between 8:45 and 8:50). The aircraft enters the tower mostly intact. It plows to the building core, severing all three gypsum-encased stairwells, dragging combustibles with it. A massive shock wave travels down to the ground and up again. The combustibles and the remnants of the aircraft are ignited by the burning fuel. As the building lacks a traditional full cage frame and depends almost entirely on the strength of a narrow structural core running up the center, fire at the center of the impact zone is in a position to compromise the integrity of all internal columns. People below the severed stairwells start to evacuate—no one above the impact zone is able to do so.

8:49:34: The first network television and radio reports of an explosion or incident at the World Trade Center. CNN breaks into a Ditech commercial at 8:49. The CNN screen subtitle first reads "World Trade Center disaster." Carol Lin, the first TV network anchor to break the news of the attacks, says:

"This just in. You are looking at obviously a very disturbing live shot there. That is the World Trade Center, and we have unconfirmed reports this morning that a plane has crashed into one of the towers of the World Trade Center. CNN Center right now is just beginning to work on this story, obviously calling our sources and trying to figure out exactly what happened, but clearly something relatively devastating happening this morning there on the south end of the island of Manhattan. That is once again, a picture of one of the towers of the World Trade Center."


Walking to the parking lot, the proximity of the kids high school and middle school to the CIA created a feeling of great internal anxiety and it soon turned to fear.

9:37:46: Flight 77 crashes into the western side of the Pentagon and starts a violent fire. The section of the Pentagon hit consists mainly of newly renovated, unoccupied offices. All 64 people on board are killed, as are 125 Pentagon personnel.

Looking around the crowd this evening at our 9/11 Memorial Ceremony in our little village, some of the kids were not old enough to remember that day. We said prayers and recited the names of the six men and women who were from our little town. "Friends of the Freedom Memorial" formed in 2002 to build the site and dedicated to the residents who have given their lives for our freedom.

The Boy Scouts handed out programs and lead us in the Pledge of Allegiance. We sang the National Anthem. "America the Beautiful". We starred at the six candles lit in their honor.

What this day is about every year beyond these memories, is the renewed vow of vigilance. A time to revisit all the reasons why you have made the decisions you have since that Tuesday morning nine years ago. Never forget that day. Never forget why you wake each morning.

9/11 vigilance is about being adaptive. It is about resilience. For those of us who have never paid the same price as those who have served, supported and are the mothers, fathers, brothers, sisters or relatives of those who have, we can never know or really feel what they have. We can only pledge our vigilance in continuing our respective missions.

Most of all. The mission is not America's alone and the entire planet understands this. As they teach the history of 9/11 in the schools of New York City, Haiti, Chile, Pakistan, India and even Saudi Arabia, what do you think the lesson is about? If it is not about vigilance and resilience, then we are doing our children a disservice. We must be preparing them for the future threats that this globe will be facing in the years and decades before us.

Whether it is the wrath of "Mother Nature" or the evil planning of ordinary people does not matter. We can never predict exactly the day the hour or when and where the next attack will occur. Whether it will impact our buildings, bridges, rivers, schools or the Internet is unknown. If all of us on this 3rd rock from the sun, have done our job teaching our kids about vigilance and resilience, then we should all be able to have a peaceful nights sleep. Devoid of nightmares.

Remember that Tuesday in September across the globe for the lessons we have all learned since that infamous day in New York City, Washington, DC and Shanksville, Pennsylvania. For the children, teach them the truth.

06 September 2010

Protective Security: Discovery Lessons Learned...

Operational Risks at Discovery Communications are on the agenda for the next Board of Directors Meeting. The lessons learned are being discussed and there are many legal considerations after a gun man strapped with explosive devices held hostages in the lobby of the Silver Spring, Maryland company on September 1, 2010.

A security guard who called 911 after a gunman entered Discovery Channel's headquarters calmly told the operator: "You're probably going to need a sniper."

The call, released Friday, was one of several placed minutes after a gunman entered the lobby and took three hostages. Other callers described the propane tanks strapped to the gunman's body, and a blinking device in his left hand.

After hours of negotiating with James Lee, 43, police shot him to death as the hostages were preparing to make a break for it, police said.

Even in the first minutes after the siege began, Discovery security had an idea of who they were dealing with. A security employee told a 911 operator that they believed the man was in the lobby was Lee. He told the operator Lee appeared disoriented, had propane tanks strapped to his chest and at least one person on the ground.

"It looks like he's got an IED. He looks like he's setting up an explosive device in the lobby, you're probably going to need a sniper," he tells the operator. "You gotta move fast."

In police radio transmissions, an officer described the suspect as an "Asian male following the do-not-admit sign Discovery has."

Since the attack on the Holocaust Museum in Washington, DC where another lone gun man walked into the lobby with a rifle there has been hours and hours of debriefing. There has been presentations on the protective security measures that worked. There are lessons learned on those measures and policies that failed. Yet one thing is certain in both of these incidents. The protective security strategy for an active shooter scenario is still up for debate.

The Holocaust Museum and Discovery Communications have differing philosophies about the design of a layered defense as it pertains to this type of threat. Discovery did not have protective security that was able to disarm and prevent Mr. Lee from entering their facility and taking hostages.

This blog has discussed the vulnerability that exists in every facility or digital network in terms of how attackers will exploit the vulnerability of Design, Implementation or Configuration. It is obvious in the case of Discovery that the attacker had done his homework and knew in advance that they do not have "Armed Guards" in the lobby. The larger lesson to both Discovery and to others is not so much about the decision of "Armed" vs. "Unarmed", as much as it might be on how and where visitors are allowed to access the building itself. The design of the Discovery Protective Security Process and design of the facility is a major Operational Risk.

Perhaps this message also needs to be sent to the commercial architects and the developers of buildings about why it is important to design protective security measures into the physical engineering of the facility to begin with. Making decisions about whether to arm your guard force with weapons however may not even need to be discussed, if the process and design of your building security is done correctly.

  • First, the visitors entrance and lobby area shall not be the same for employees. Ideally, the employees enter the building from the parking garage directly, that is also secured. Or even a secure side entrance if they commute to work. It is never good design to have employees entering in the same space with visitors.
  • Second, design the building so that the visitors entrance is set back a minimum of 75 yards from the main facility, detached or connected only through a covered walkway or enclosed hallway. Ideally, the visitor screening and registration all occurs in this detached building with the first layer of the protective security team.
  • Third, once visitors are screened and given the green light, they may proceed to the secondary waiting lobby in the main facility. This again, is a holding area until the visitor is greeted and escorted into the building with the company employee.

As good as the Discovery guards were at describing the situation unfolding before them, the fact remains that the attacker should never had the opportunity to take any hostages. The Board of Directors may be taking into consideration many new ideas and digesting the lessons learned from Corporate Security. One can only wonder if they will increase the budget to be commensurate with the threat before them. The legal teams will be gearing up for a number of attempts to use this event as a platform for adversarial plaintiff suits.

Domestic Extremism is not just about a lone wolf who has a history of psychological issues. Violent activist groups who are active in the international movement to use animals, "The Earth" or other religious causes to fuel their justification are a growing threat, here and abroad.

Until last month, the small market town of Langnau in the rolling Swiss hills had two claims to fame: it was a centre for the production of Emmental cheese and one of the sunniest places in Switzerland.

Now, thanks to a routine police traffic inquiry, it has the dubious honour of being the location where one of Europe's biggest alleged acts of eco-terrorism was foiled.

On the night of April 15, 2010, local officers pulled over a car on one of the town's quiet streets.

Inside the vehicle they found a large cache of explosives, primed and ready to detonate.

The three people in the car are alleged to have been members of the murky Italian anarchist group Il Silvestre, who were reportedly on a mission to blow up the unfinished £55 million ($118 million) IBM nanotechnology facility.

The apparent attack is believed to be part of a new co-ordinated wave of eco-terror on the continent.

The IBM site is due to be opened next year and will be the most advanced centre for nanotech and biological scientific research in Europe. The group, formed in Tuscany, is considered by some to be one of the rising "eco-terror" groups in Europe, with a rigid cell structure, access to explosives, and a membership that supposedly has no qualms about killing to achieve its goals.


Protective Security measures to mitigate Operational Risks such as these require a comprehensive yet adaptive strategy. What may be most disturbing on the Discovery Channel incident is that the attacker all but announced his attentions on his website in advance. If you don't currently monitor the digital domains for your organizations benefit, then start this soon. You may be amazed at the "Open Source Intelligence" (OSINT) that exists on what Domestic Extremists are saying and planning for your company.

Even after the Twin Towers fell, environmental extremism was seen as a severe threat and, in 2006, Congress passed legislation - the Animal Enterprise Terrorism Act - which classified certain acts of civil disobedience, such as blockades, trespassing, property damage and the freeing of animals, as acts of terrorism.

An FBI assessment continued to reinforce fear of environmental radicals when it stated "together eco-terrorists and animal rights extremists are one of the most serious domestic terrorist threats in the US".

It warned that tactics were "becoming increasingly violent, with threats to life, not just to property".