11 November 2012

Team Rubicon: Bridge the Gap...

On Sunday morning, observing Veterans Day in the United States began with a few words from a leader from the American Red Cross at a local shelter near North Brunswick, NJ  USA.  We heard his words of recognition and what it felt like for him to return to our country after serving in Vietnam and being ridiculed and spit upon.  The veterans in the room were all gearing up for another day on the front lines of a new domestic battle with the aftermath of Hurricane Sandy.  Team Rubicon and it's growing presence of agile, selfless and highly skilled professionals have been working along side other national and international NGOs.  They are projecting a rapid and significant force on the ground, from New York to previously unrecognized communities such as Union Beach and Montoloking, NJ.

Operational Risk Management was practiced and observed as disaster first responders descended on the front lines of the Hurricane Sandy disaster area.  Highly equipped, veteran war fighters and first responders are deployed each day to tackle and mitigate substantial risks to homeowners, businesses and communities.  Working in concert with city, county, state and federal authorities to provide the most effective response results, where other NGOs stood by in amazement.

City officials, emergency management, law enforcement, community associations, religious organizations all working in coordination to provide their citizens and members what they needed, when they needed it and more.  The destruction and the aftermath of this disaster was significant and will be recognized as one of the most costly economic impacts to the nation.

Yet this is more about a mission by those who know they want to continue to "Bridge the Gap".   To serve beyond what they have already done in life.  To be hugged by perfect strangers for rescuing a loved one trapped in their home or assisting in the mitigation of operational risks to life and property in their neighborhood.  The mission is clear and each day a whole new example of a purpose driven life is explored and realized.

As our U.S. veterans and their families are returning to our cities and communities remember this.  1%.  They represent only 1 percent of our U.S. population and deserve our respect and continued devotion to their service.  They have been making a difference in uniform and will continue to do so if we leverage the leadership, knowledge, wisdom and courage they all possess:
Team Rubicon Saves Lives. 
Since its creation in January 2010, TR has impacted thousands of lives – in Haiti, Chile, Burma, Pakistan, Sudan, and here at home, in Vermont, Maryland, Missouri, and Alabama.  TR reaches victims outside the scope of where traditional aid organizations venture; victims on the fringe. 
Team Rubicon Engages Veterans. 
Hundreds of US military veterans, many returning home after fighting ten years of war, find a renewed sense of purpose for their skills and experiences through TR. 
Team Rubicon Sets Itself Apart In the Nonprofit World. 
Is it a disaster relief organization? A veteran-focused enterprise?  The truth is it’s both. TR pioneered a new paradigm in disaster response while redefining the meaning of veteran reintegration into society. 
Team Rubicon Pioneered the Concept of Veteran-Focused Disaster Response. 
On the streets of Port-au-Prince, in the immediate aftermath of the Haiti earthquake, TR’s military veterans realized a simple truth – natural disasters present many of the same problems that confront troops in Iraq and Afghanistan: unstable populations, limited resources, horrific sights, sounds and smells.  The skills cultivated on those same battlefields – emergency medicine, risk assessment and mitigation, teamwork and decisive leadership – are invaluable in disaster zones.
This Veterans Day remembrance will never be forgotten.  It has been an honor to serve along side so many dedicated professionals to continue to mitigate operational risks to our friends, family and loved ones.  Continue to "Bridge the Gap"!

04 November 2012

U.S. Resilience: Hurricane, Terrorism, Political Risks...

One week ago today, Hurricane Sandy was making her way up the Eastern seaboard of the United States with a wind field 800 to 900 miles wide.  There are estimates of $50B. in economic damages to the country and that tells you only part of the impact story.  The direct impact in lives lost, people displaced and the continuous risks to the Whole Community unfolds in real-time.  Business Resilience and consumers patience is being tested by the hour, ever since the reality of the crisis started to reach the Executive Suites of critical infrastructure sectors such as Financial, Energy, Telecom, Transportation, Maritime, Retail, and the other thirteen or so others.  All have been exercising their COG, COOP and DR plans as part of the their organizational Operational Risk Management programs.

sandy.locative.us will provide you with a snap shot from aerial imagery of the Hurricane Sandy aftermath and geographic locations that could have a spectrum of damage from light to heavy.  This is just one example of how crowdsourced apps are being used to assist, with the ongoing situational awareness and damage assessments but also the long term recovery of those most impacted areas.  At the same time, resources are in high demand for certain areas such as gasoline.  The power companies are making progress and as the supply chain mobilizes and the electricity comes back on, the commodities shortages will soon begin to dissipate.

The Sunday Washington Post and New York Times are telling stories of heroism, tragedy and the effect on the Presidential election on November, 6 2012.  The politically charged atmosphere is primed for more of a perfect storm as the fiscal cliff approaches, regardless who becomes the next President of the United States of America.  This minute, there are tens of thousands of people wondering where they are going to live and stay warm this week in the Mid-Atlantic and Northeast region.  Simultaneously, the September 11, 2012 terrorism investigation continues and in the next few weeks, the world will better understand the timeline and the vulnerabilities that still remain to U.S. assets in the Middle East.  The Associated Press reports:

WASHINGTON (AP) — The deadly military-style assault on the U.S. Consulate in Benghazi, Libya, has raised numerous foreign policy and national security questions and fueled a fierce, partisan election debate over the Obama administration's handling of the attack. 
The strike that killed U.S. Ambassador Chris Stevens and three other Americans is either proof of President Barack Obama's leadership failures or a tragic event that occurred despite the administration's best efforts to protect the compound and respond in the aftermath of the attack, according to highly charged arguments on both sides.
Administration officials have warned against drawing conclusions from individual documents that have leaked into the public sphere. They maintain that a full picture of what happened and any assessment of blame can only be determined after a complete review of all the evidence. But as documents continue to surface in the final days of the presidential campaign, the intensity of allegations of administration impropriety or incompetence has risen. 
A look at what is known, what is still unanswered and who is investigating the incident that has called into doubt Washington's ability to predict such events, secure American personnel in dangerous places and track down those responsible.

Courageous people who have special skills, talents and subject matter expertise are activated or being deployed at this minute, on billets to address a set of continuous operational risks across the globe.  These American first responders and long term recovery professionals all have one thing in common.  A desire to close their eyes each night, with the confidence that they did make a difference that day.  The peace of mind, that they did their small part to add to the tremendous challenges of securing the safety and long term security of their loved ones and those in need.  God, Family, Nation.

27 October 2012

Dark Pools: OPS Risk of Rogue Algorithms...

When you begin to think about the potential Operational Risks we face everyday, they are so wide and so numerous that each organization has developed their own methods for Enterprise Risk Management.  Depending upon the industry you are in and the speed of your business will determine the subject matter expertise that is required to deter, detect, defend and document your particular operational risks.

This is business as usual in the Financial Services industry.  Yet what about those low probability and high consequence incidents that are looming over the horizon?  The "Black Swans" as they have been defined in the past few years.  What if these "Black Swans" were known to exist everyday and could be witnessed swimming around in what are known as "Dark Pools."  You know, the places where the "Algo Bots", Quants and those who win, are doing so at the speed of light.  In the milliseconds of time it takes, for one algorithm to buy and another to sell within the trading exchanges, we can only continue to pray that the mathematics does not go rogue:
A news-breaking account of the global stock market's subterranean battles, Dark Pools portrays the rise of the "bots"- artificially intelligent systems that execute trades in milliseconds and use the cover of darkness to out-maneuver the humans who've created them.
In the beginning was Josh Levine, an idealistic programming genius who dreamed of wresting control of the market from the big exchanges that, again and again, gave the giant institutions an advantage over the little guy. Levine created a computerized trading hub named Island where small traders swapped stocks, and over time his invention morphed into a global electronic stock market that sent trillions in capital through a vast jungle of fiber-optic cables.  
By then, the market that Levine had sought to fix had turned upside down, birthing secretive exchanges called dark pools and a new species of trading machines that could think, and that seemed, ominously, to be slipping the control of their human masters. 
Dark Pools is the fascinating story of how global markets have been hijacked by trading robots--many so self-directed that humans can't predict what they'll do next. 
Managing Operational Risk with the underground "Dark Pools" is a stretch.  No different than trying to understand something as easy as CDO's or a tranche of sub-prime mortgages from a zip code in Las Vegas all packed up in a Wall Street product you now recognize as a Mortgage-Backed Security (MBS):
Low quality mortgage-backed securities backed by subprime mortgages played a major role in the 2007–2012 global financial crisis. By 2012 the market for high quality mortgage-backed securities had recovered and was a profit center for banks in the United States.
High Frequency Trading (HFT) is not new.  It has been evolving for years.  The battle for speed, has even changed the way organizations think about buying their circuits for telecommunications and data communications, between these increasingly complex and sophisticated computing critical infrastructures.  Here is one example:

Ridgeland, MS - September 17, 2012 -Spread Networks, LLC, a privately owned telecommunications provider, today announced the deployment of 100G technology on Spread's industry leading Chicago to New York fiber backbone. Spread's new service offers customers access to 100 gigabits per second of optical bandwidth, unregenerated, on Spread's 14.6 millisecond round-trip best-latency-in-class Ultra Low Latency Chicago-New York Wavelength service.  Spread's flagship Ultra Low Latency Chicago-New York Dark Fiber service is now operational at a roundtrip latency of 12.98 milliseconds roundtrip, a 100 microsecond improvement from Spread's previous 13.1 millisecond offering.  The latency improvement over Spread's dark fiber, which is already implemented, is the result of continuous route improvements that Spread has undertaken since going live in August, 2010.  Spread's 12.98 millisecond dark fiber offering provides customers with unlimited bandwidth on a 99.999% available service at the lowest latencies achievable by fiber optic networks between these two financial centers.  For financial customers who value low-latency and reliability for their mission critical trading applications, there is no other comparable solution.
Most people at the SEC, Federal Reserve and the DOJ fully understand the need for business to do whatever it takes to create a competitive advantage.  What however still remains our "Single-Point-of-Failure" is the math.  The mathematics that make up the algorithms.  The zeros and ones of software code that tell the computers what to do and when to do it.  How many people really can understand it and explain it?

So how do you mitigate the potential risk of a rogue algorithm?  Some have devised a mechanism called a circuit-breaker.  In other words, an alarm that something is not normal.  Let's slow down until we can understand what is going on here.  What are some other ways that we could potentially address the threat or the vulnerability?  Was the "Flash Crash" a weak signal of a pending melt down of the complete system?
We are increasingly dependent on computers for all that we do, and the government won’t always be able to prevent their malfunctioning from causing serious problems. But the many glitches that have plagued financial markets in the past couple of years should serve as a sobering reminder that financial markets have evolved much more quickly in the past decade than regulators have.As Scott Patterson, author of Dark Poolsa book about high-frequency trading, said to Yahoo Finance Monday, “We have seen a massive revolution in how exchanges work. It’s been put in place extremely fast . . . the problem is that the race for profits at the exchanges and at the high-frequency firms has outpaced their ability to manage risk.”  Read more: http://business.time.com/2012/08/08/high-frequency-trading-wall-streets-doomsday-machine/#ixzz2AWeXPorn

21 October 2012

Starfish: A Community of Resilience...

When is the last time you were in an environment where trust was implicit?  A place where the people you were working along side, shared a unity of purpose and a single mission.  Once you experience this, it is forever engraved in your mind and felt deep in your soul.  A "Starfish Community," walking together with such a high degree of mutual trust, it will endure and remain resilient against all Operational Risks that may be encountered.

Enabled by the wisdom and thinking from Rod Beckstrom and Ori Brafman's book "Starfish and the Spider:  The Unstoppable Power of Leaderless Organizations, the "Starfish Community" is growing rapidly across the globe.  A group of decentralized networks that are able to work without hesitancy and with moral courage.  It does not matter if the model is used on the battlefield or in business, the desired outcomes are the same.  Joby Warrick at the WP describes the latest work of al-Qaeda:
Authorities in Jordan have disrupted a major terrorist plot by al-Qaeda-linked operatives to launch near-simultaneous attacks on multiple civilian and government targets, reportedly including the U.S. Embassy in the capital, Amman, said Western and Middle Eastern officials Sunday.  The Jordanian government issued a statement confirming the plot and saying that 11 people with connections to al-Qaeda’s affiliate in Iraq have been arrested. 
The foiled attack, described as the most serious plot uncovered in Jordan since 2005, was viewed with particular alarm by intelligence agencies because of its sophisticated design and the planned use of munitions intended for the Syria conflict — a new sign that Syria’s troubles could be spilling over into neighboring countries, the officials said.
The alleged plotters are Jordanian nationals. The officials said the group had amassed a stockpile of explosives and weapons from Syrian battlefields and devised a plan to use military-style tactics in a wave of attacks across Amman.  
The scheme called for multiple strikes on shopping centers and cafes as a diversionary tactic to draw the attention of police and security officials, allowing other operatives to launch attacks against the main targets, which included government buildings and embassies.  A Western official briefed on details of the plot confirmed that the U.S. Embassy in Amman was among the targets. Like others interviewed for this report, the official spoke on the condition of anonymity because the investigation is still unfolding.
The ability for the Starfish Community to evolve, adapt and to consistently execute against its agreed upon mission manifests itself in terrorist acts and simultaneously in humanitarian and disaster response.  The ability for the human race to at one moment be so evil and at the same moment so forgiving and good, will continue to amaze us all:
Syrian Arab Republic, 2012
HISG has provided food, blankets, medicine, and other assistance to families that have been affected the by political turmoil in Syria. Many of these people have lost their only source of income because businesses have shut down. Others have simply fled the larger cities to escape the violence. 
The assistance has gone to families like these: In one household, the mother had died from illness, leaving the father to care for five small children. He was not able to keep his job, and now sells small items door to door or on the streets, but it was not enough to provide for his children. When his family received food packs and heating oil in the winter, he was overwhelmed with gratitude. 
Late 2011 and early 2012 brought on an unusually cold winter in Syria, and the harsh temperatures coupled with the protests and demonstrations drove the price of heating oil to 4 times its usual price. The blankets were delivered to insulate people from the cold and help them survive the bitter cold.
The business world evolves around us with mergers and acquisitions, incidents of fraud and corruption while a silent and clandestine army of cyber warriors wage conflict on our critical infrastructure and copy or steal our intellectual assets.  The ability for the "Starfish Community" to survive in the virtual environment of the Internet is no different than the cities of Aleppo or Amman.  This is why Wikipedia and other open source projects are able to continuously adapt, grow and survive the threats or vulnerabilities to this resilient and self-healing network.

How have organizations like Google and others designed their business to withstand the tests of both physical and virtual threats to it's global well-being?  
8.  The need for information crosses all borders.
Our company was founded in California, but our mission is to facilitate access to information for the entire world, and in every language. To that end, we have offices in more than 60 countries, maintain more than 180 Internet domains, and serve more than half of our results to people living outside the United States. We offer Google’s search interface in more than 130 languages, offer people the ability to restrict results to content written in their own language, and aim to provide the rest of our applications and products in as many languages and accessible formats as possible. Using our translation tools, people can discover content written on the other side of the world in languages they don’t speak. With these tools and the help of volunteer translators, we have been able to greatly improve both the variety and quality of services we can offer in even the most far–flung corners of the globe. 
A crisis appears in your business only when you are unable to adapt and withstand the impact of the virtual or physical forces thrust upon you.  Whether it is the economic well being of the U.S. or the privacy laws in Europe.  The shock wave of a VBIED or insider threat.  Your organization could reach an Operational Risk crisis state, if you have not embraced the architecture of the "Starfish Community".  Learn from the best on how to withstand the test of time and and all that humanity has in store for us.  And to all of those who are on the front lines of crisis everyday.  God Speed.  You know who you are.

11 September 2012

9/11/01: Remembering Eleven Years Later...

September 11, 2012 and 11 years later, it has not changed the amount of tears that flow on this date.  This is "No Easy Day" for many reasons.

May 1, 2011 was an event in history and deserves its significance among all the other millions of micro events, in our continued vigilance.  The single success of "Operation Neptune Spear" is a lonely celebration point for those countless thousands who contributed to the accomplishment of the mission.  Analysts included.  Our "OPS Risk" professionals adapted that night and all of our team came home safe.

Remembering those who didn't make it home that original 9/11 morning of terror, is why we will never forget, nor shall we ever surrender.  That is why we also remember, all those who have made the ultimate sacrifice this past decade.  They also number in the thousands.  Fallen on foreign soil.  And even to this day, back here at home.  This is our next front.  If you have not donated to Got Your Six, Wounded Warrior Project , Team Rubicon or others yet, what are you waiting for?

This day is also about the survivors.  Those who have not forgotten and have given so much since then.  The survivors are the people we continue to encourage, to keep fighting the fight and to make sure that the rest of us do so as well.

 Remembering September 11th

04 July 2012

July 4th, 2012: U.S. Vets Bring 236 Years of Freedom...

Operational Risk professionals know and understand that on this July 4th, 2012, we celebrate our freedom because of one reason.  Our veterans who serve and those who have served, the United States of America.  In this year, we ask you to do your best to hire a veteran for your business.  They make excellent Operational Risk Management experts and here are the other reasons your company should hire a vet:

  1. Companies Value Veterans' Leadership and Teamwork Skills
  2. Veterans Character Makes Them Good Employees
  3. Veterans are Disciplined, Follow Processes Well and Operate Safely
  4. Companies Seek Veterans' Expertise
  5. Veterans Adapt and Perform Well in Dynamic Environments
  6. Veterans are Effective Employees
  7. Veterans in the Organization are Successful
  8. Veterans are Resilient
  9. Veterans are Loyal to their Organization
  10. Hiring Veterans Carries Public Relations Benefits
  11. Hiring Veterans is the "Right Thing to Do"

Source:  Employing America's Veterans - Perspectives from Businesses

Happy 236th Birthday America!  Hire a Vet this year...

02 July 2012

Derecho: OPS Risk in the NCR...

The Operational Risk professionals in the Washington, D.C. region are scrambling these past few days as a rare "Derecho" swept across Ohio, West Virginia, Virginia, and the National Capital Region of the United States on Friday night.  The power generators are now humming at full capacity and the diesel fuel trucks are going into action for the myriad of data centers impacted by the massive power outage:

Widespread hurricane-force winds associated with a multiple-state derecho has taken out power to millions and left at least 15 dead. 
A derecho defined as a widespread, long-lived wind-storm with a band of rapidly moving showers or thunderstorms, formed in northern Indiana and raced east and southeast into the Mid-Atlantic states within 10 hours, according to the Storm Prediction Center (SPC). 
Widespread high wind gusts in excess 70 to 90 mph were reported as the derecho downed thousands of trees, power lines and damaged homes and other structures along its estimated 600 to 700-mile path Friday afternoon into late Friday night.

The term "Business Resilience" is now becoming a more widely used term beyond just Business Continuity, as corporate and small enterprises focus on being able to withstand at least a 72 hour (3 day) incident of this magnitude.  Not forecasted and unlike a hurricane, where business may have days to prepare, this is a real wakeup call for many.

Even when you are the mighty Amazon Web Services, mother nature can take her toll.  Several high profile sites were down for some period as a result of the massive Derecho:
A severe patch of storms that rumbled across the Eastern U.S. — leaving nine people dead and millions without power — also disrupted an Amazon Web Services data center, affecting service for social media sites like Pinterest, Instagram and Netflix, which host their services at Amazon’s data centers.
Business Resiliency is about bouncing back, quickly.  Ten minutes later, the power services were restored and they were up and running.  Power yes, data is a different issue.  The Amazon Web Services (AWS) is just one reason why the "Cloud" is here to stay and the adoption rate by many business CIOs is rising.  Now, are there some cloud providers capable of withstanding a strong thunderstorm such as this?  Absolutely.  If you are a business with mission critical applications that are reliant on the cloud service providers infrastructure, you may ask what due diligence has your organization done?   What are the interdependencies of your cloud service provider?

When you tour one of these data centers, you will see the massive CAT diesel generators and your tour guide may tell you that they spin up in "xx" number of seconds upon power failure.  The next question is, what is the size of the fuel supply?  The rest of the Business Continuity 101 questions then get answered. So how do you know for sure that you WILL NOT be impacted because of an adverse event such as this one, in the National Capital Region this weekend?

You don't.  Regardless of the data hosting or cloud provider the risk is real and data availability will never be 100%.  This brings us back to resilience and the degree to which an Operational Risk professional visualizes and has effective strategy execution for those processes and systems that are the lifeblood of almost every enterprise today.  Even though we have some so far, the business case for resilience continues to become more apparent on a daily basis:
"Even as the impact of disruptions was growing, so too was their frequency, velocity and unpredictability.  Who anticipated a Japanese reactor meltdown, a deep water oil spill or an Icelandic volcano what closed trans-Atlantic traffic?  In the age of volatility, companies must develop the capacity to manage the outcomes of disruption, irrespective of trigger."  U.S. Resilience Project - Resilience Roundtable Report 

Here in the metro region of the United States Capital, critical infrastructure is being tested.  At hundreds of roadway intersections with traffic lights out, at senior citizen centers, gas stations, restaurants and all those impacted without air conditioning as the temperature soars to the high 90s again today.  Saving data or saving lives, the people and the organizations who have the resources, time and correct tools will continue to try and hedge risk, mitigate risk and avoid risk.

It is only those who deny the existence of risk in their environment, that will become victims of this or a future event.  For each person or organization who has the resources, time and tools and then still becomes a victim, we can only ask why?  Why would you put yourself in this situation?

Questions for Future Consideration:

  1. How can the public and private sectors better collaborate to address emerging risks?
  2. How can the competitive advantages of resilience be balanced against the shared value of collaboration and information-sharing around best practices, processes and tools?
  3. How can the private sector leverage best practices in risk management and resilience to identify opportunities to streamline rules and regulations?
  4. What are the new skill sets needed to create a resilient workforce able to anticipate and manage volatility and uncertainty?

16 June 2012

London: Olympic Games Risk Management...

As the summer approaches the world is gearing up for the 2012 Olympic Games in London in about 41 days.  The athletes are making their respective rounds on television and other media to discuss their thoughts.  The U.K. Home Office is on high alert and has been preparing the "Operational Risk Strategy Execution" for years.

The private sector is finalizing plans for the millions of dollars in advertising and promotions on television.  The rest of the world will be watching from their easy chairs in Kansas City USA, the mountain villages of Switzerland, the outback of Australia to the most remote locations in the Sahel.

Every two years the humanity of the Olympic Games comes alive and we all realize that it is possible to get along, to cooperate and to coordinate.  For the historical and cultural reasons the world comes together to compete.  And in every venue and each sport the rules change.  The distance, the accuracy, the time.  They are all measured and the rule-sets have been determined in advance.  The competitor knows and understands the measures by which they will be judged.  In the swimming pool, on the track  mat or field or in front of the target.

The collaboration across the planet somehow brings us all to the point of a temporary "Time Out."  Where it almost seems calm and peaceful for those days and weeks.  A time when humanity can say to themselves that it really is possible to all get along.  A time to show ourselves what really is possible if we have the will and the heart to make it all happen, on time and without incident.

The social media buzz on a daily basis will be coming live from millions of Twitter and Blog posts.  The use of Crowdmap will be utilized to assist in the event of a crisis.  The mobile device will continue to be a valuable way for the authorities to have continuous opportunity for situational awareness.  Applications from companies such as RealityMobile provide real-time streaming video from any camera enabled PDA device.  All of the communications equipment to collect, view and analyze information will remain a part of the layered defense in depth to deter, detect and prevent an adverse incident.  The London Olympics in 2012 will have the same challenges and the identical set of risks as Beijing or Greece in 2008 or 2004.  What is different this time?

This summer 2012 Olympic Games may be one of the most technology enabled risk management projects ever.  At the same time, the social scientists have been working on the analysis of the organizational risk facets of such a gathering in London.  Human factors and social demographics of the people attending have a major consideration in operational risk management planning:

"It is necessary for most of us these days to have some insight into the motives and responses of the true believer. For though ours is a godless age, it is the very opposite of irreligious. The true believer is everywhere on the march, and both by converting and antagonizing he is shaping the world in his own image. And whether we are to line up with him or against him, it is well that we should know all we can concerning his nature and potentialities."
Hoffer, Eric (2011-05-10). The True Believer: Thoughts on the Nature of Mass Movements (Perennial Classics) . Harper Collins, Inc..

The 1951 classic by Eric Hoffer is already Operational Risk reading 101 and the modern day Arab Spring is a perfect example of what messages Hoffer has reminded us to consider over 60 years later.  Yet those who continue to study the social science of mass movements, realize that our greatest risk mitigation tool will continue to be one of the least technical and most effective.  Education and Awareness.

We encourage all of our Operational Risk professionals to educate and increase the awareness of your employees and friends and family who will be attending the London Olympic Games 2012:

Official London 2012 Join In App

In the summer of 2012 London and the UK will come alive with events, celebrations and activities during the Olympic and Paralympic Games.
The Official London 2012 Join In app is a mobile guide to help you plan, enjoy and share your Games experience.
This free app is an essential planning tool for everyone, whether you have tickets for a sporting event or not. From the start of the Olympic Torch Relay to the Olympics and Paralympics, the Opening and Closing Ceremonies, plus all the cultural, city and community celebrations happening across the UK, Join In is your essential companion.

Official London 2012 Results App

The Official London 2012 Results app provides all the latest news, schedules and results, allowing users to keep up-to-date with the latest action live across all Olympic sports and Paralympic sports.
Key features include results, live updates, calendar schedule, details of sports, medal tables and athlete profiles. Users can also follow specific countries, receiving official news and updates tailored to them all in one app.
It’s the essential app for all sports fans to share the excitement of London 2012!

03 June 2012

NLE 2012: Trustworthiness of the System...

The National Level Exercise (NLE) 2012 Capstone will soon be taking place and the private sector is embracing for potential cyber domain blowback.  NLE 2012 is based upon an exercise scenario that is not only timely, but also an expanding Operational Risk to the U.S. critical infrastructure.  This comes months after the secure communications channel has been established between Washington and Moscow, in the event of a damaging digital attack to prevent any escalation to full hostilities.

National Level Exercise (NLE) 2012 is part of a series of congressionally mandated preparedness exercises designed to educate and prepare participants for potential catastrophic events. The NLE 2012 process will examine the nation’s ability to coordinate and implement prevention, preparedness, response and recovery plans and capabilities pertaining to a significant cyber event or a series of events. NLE 2012 will examine national response plans and procedures, including the National Response Framework (NRF), NRF Cyber Incident Annex, Interim National Cyber Incident Response Plan (NCIRP) and the International Strategy for Cyberspace. Unique to NLE 2012 will be an emphasis on the shared responsibility among all levels of government, the private sector and the international community to secure cyberspace and respond together to a significant cyber incident.

Simultaneously, the  U.N.'s International Telecommunication Union (I.T.U.) is mediating the future of the Internet.  Hamadoun Toure will be meeting in Dubai as I.T.U. secretary-general later this year as 193 nation states debate the new rules of engagement.   The lines have already been drawn in the sand between rogue groups and Western democracies, private companies, law enforcement and hacktivists.

As strategic media leaks are continuously debated and clandestine operations are exposed, the Operational Risks for the private sector continue to soar.  Whether it is the threat to the Olympic Games in London this summer or the covert "Olympic Games" in cyberspace, there continues to be a set of consistent taxonomy developed years ago by Sandia Labs researchers, that this blog has highlighted before:
"Attackers use tools to exploit vulnerabilities, to create an action on a target, that produces an unauthorized result to obtain their objective."
The three areas that you need to focus on continue to be:
  • Design
  • Implementation
  • Configuration

Whether it is through physical attack, information exchange, user commands, scripts, programs, autonomous agents, toolkits or data taps you can be assured that these tools are being utilized to exploit you. They are being directed at the design, implementation or configuration of your "Controls" in order to achieve the action they desire:

  • Probe
  • Scan
  • Flood
  • Authenticate
  • Bypass
  • Spoof
  • Read
  • Copy
  • Steal
  • Modify
  • Delete
All of these actions are directed at their target. Accounts, people, processes, data, components, computers, networks or internetworks. They are looking for and unauthorized result:
  • Increased Access
  • Disclosure of Information
  • Corruption of Information
  • Denial of Service
  • Theft of Resources
And sadly, when you boil it down to the reasons or objectives they seek to achieve; it usually falls into one of four categories:
  • Challenge, Status, Thrill
  • Political Gain
  • Financial Gain
  • Damage
Once you understand the entire taxonomy of an "Incident", you are far better equipped to prevent and preempt attacks on your valuable corporate assets.
Now the question to be answered is, who is your adversary?  Answering this question and putting a face on those who are attacking you, somehow seems to be more important these days by some.  Attribution is only one key facet of asymmetric warfare.



at·tri·bu·tion

  [a-truh-byoo-shuhn]  Show IPA
noun
1.
the act of attributing ascription.
2.
something ascribed; an attribute.
3.
Numismatics a classification for a coin, based on itsdistinguishing features, as date, design, or metal.
4.
Archaic authority or function assigned, as to a ruler,legislative assembly, delegate, or the like.


at·trib·ute

  [v. uh-trib-yoot; n. a-truh-byoot]  Show IPA
verb, at·trib·ut·ed, at·trib·ut·ing, noun
verb (used with object)
1.
to regard as resulting from a specified cause; consider ascaused by something indicated (usually followed by to ): She attributed his bad temper to ill health.
2.
to consider as a quality or characteristic of the person, thing, group, etc., indicated: He attributed intelligence to his colleagues.
3.
to consider as made by the one indicated, especially withstrong evidence but in the absence of conclusive proof: to attribute a painting to an artist.
4.
to regard as produced by or originating in the time, period, place, etc., indicated; credit; assign: to attribute a work to particular period; to attribute a discovery to a particular country.
noun
5.
something attributed as belonging to a person, thing, group,etc.; a quality, character, characteristic, or property:Sensitivity is one of his attributes.


Regardless of the ability to attain the identity of your attacker, your focus should remain on your trusted systems and your resilience factor.  The trustworthiness of the system requires evaluation and a trust decision to use the system.  "The risk calculus evaluates whether the probability that the services as a result of using the system, will exceed the risks that may occur as valued by a user.  The cost component of a trust decision includes an evaluation that the use of a system will occur at an acceptable cost and will produce economically acceptable results."  [US 7240213]

19 May 2012

Telecom DataTecture: Cloud Resilience in 4GW...

The Enterprise Cloud computing environment is not only a topic of many private sector CIO forums this year, it is also spawning new discussions in government intelligence community circles. Simultaneously, the new economics and the aversion to buying hardware and software to house your own brick and mortar data center, is slowly but surely taking the business community by storm.

Companies such as Terremark Worldwide that already serves some of the most highly classified data traffic and storage for the intelligence and other civilian agencies, is gaining tremendous momentum in the marketplace. Why? Visit their NAP of the Capital Region 60 miles or so outside Washington, DC and you will witness part of the answer. The other part of why can be found in Terremark's sophisticated VMware-powered "Infinistructure" that provides the modern enterprise to more easily scale in bandwith and storage commensurate with daily, weekly or monthly utilization of dynamic computing utility requirements.

In order for a Small-to-Medium-Enterprise (SME) to grow with new HP or IBM Servers, EMC or NetAPP storage and sub-systems for load balancing, back-up power generation, disaster recovery and managed security services requires a substantial new Capital Expenditure (CAPEX). This strategy for a Telecom DataTecture (Cloud Data Centers) is one that architects of critical infrastructure resiliency teams can no longer ignore.

What does "Business Resilience" and critical infrastructure have to do with Operational Risk Management? At the core of OPS Risk is the concept that vulnerabilities exist in your organization across a spectrum of people, processes, systems and external events. Executives now have a new mindset that sounds like this. "I know that it's just a matter of time until we experience a significant business disruption to the organization. Now the question remains, what, who, when, where and how?". By the "Insider" who has been stealing precious intellectual property or facilitating some occupational fraud scheme to the "External" attacker that enables a data breach of "Personal Identifiable Information" (PII) at a minimum. The serious adversary will only care about major disruption or destruction; Mother Nature (Haiti) or Aurora (Hack).

Once you have achieved this mindset and the reality of the future attack, you transition to "Enabling Enterprise Business Resiliency" and a series of measures towards your own survivability. These measures in the Information Technology sector of your business or government enterprise will determine your future posture in a post incident cyber scenario. The magnitude of the incident itself is growing on a vector that now even Richard Clarke has shed more light on:

CYBER WAR:
THE NEXT THREAT TO NATIONAL SECURITY AND WHAT TO DO ABOUT IT

Cyber War is a powerful book about technology, government, and military strategy; about criminals, spies, soldiers, and hackers. This is the first book about the war of the future -- cyber war -- and a convincing argument that we may already be in peril of losing it. 
Cyber War goes behind the "geek talk" of hackers and computer scientists to explain clearly and convincingly what cyber war is, how cyber weapons work, and how vulnerable we are as a nation and as individuals to the vast and looming web of cyber criminals. From the first cyber crisis meeting in the White House a decade ago to the boardrooms of Silicon Valley and the electrical tunnels under Manhattan, Clarke and coauthor Robert K. Knake trace the rise of the cyber age and profile the unlikely characters and places at the epicenter of the battlefield. They recount the foreign cyber spies who hacked into the office of the Secretary of Defense, the control systems for U.S. electric power grids, and the plans to protect America's latest fighter aircraft.

The warnings and doom and gloom has been around for years and one more book will not likely change the current state of cyber arm wrestling going on around the Washington, DC 495 beltway. The Net-centric warrior of the next decade will no doubt have to rely on a much more resilient set of technologies and countermeasures to circumvent the latest nations state cyber armies, or cyber criminal syndicates. Even more important is the current state of the domestic ability to withstand the 4th Generation Warfare (4GW) being waged on our financial, energy and defense industrial base.

This asymmetry, in which we are developing offensive capability but doing little to prevent a devastating cyber attack, began in the Bush administration. In the last year of his eight-year presidency, George W. Bush signed a national-security decision called PDD-54. That directive, still classified, ordered steps be taken to improve the security of the Department of Defense and other federal-government computer networks. Critics say it did almost nothing to address the weaknesses of the national infrastructure.

13 May 2012

Red Alert: Operational Risk Quotient...

Operational Risk is in the U.S. news again this past week.  Several prominent CEOs and the Board of Directors are under fire in the United States for failures to comply with documented best practices and governance processes.  The failure to execute these processes for the effective management of Operational Risk has now become a "Red Alert" for organizations in the financial services and banking industry.   The ranks of those tasked with vetting and validating candidates for high profile positions in public companies are also under increased scrutiny.  We should look at these one at a time.  JPMorgan first:

FAIR GAME
At JPMorgan, the Ghost of Dinner Parties Past
By 
Published: May 12, 2012 
WHAT goes around comes around. Sometimes it happens sooner than you’d think.  That round wheel turned on JPMorgan Chase last week, which disclosed that it had suffered a $2 billion trading loss in credit derivatives. That such a hit had befallen the mightiest of banks was perhaps more stunning than the size of the loss. 
So where does the karma come in? The loss, and the embarrassment it held for Jamie Dimon, the bank’s imperious chief executive, came just one month after a private dinner party in Dallas at which he assailed two respected public figures who have pushed for policies that would make banks like JPMorgan smaller and less risky. 
One was Paul Volcker, the former Federal Reserve chairman, whose remedy for risky trading by too-big-to-fail banks is known as the Volcker Rule.


The story is not about losing $2B. USD in trading derivatives.  And as Gretchen Morgenson has stated, we are witnessing a paradox.  The same rules JPMorgan is opposing in regard to proprietary trading could very well be the same rules that could provide a "Red Alert" that a threat is on the horizon.  The cost to the institution is far beyond the loss of the trade in terms of reputation and overall market value.  The credit ratings agencies and the SEC are now moving into place for their respective response to this incident.

Now let us take a look at Yahoo and a CEO who is embroiled in an error on his curriculum vitae:

Exclusive: Yahoo’s Thompson Out; Levinsohn In; Board Settlement With Loeb Nears Completion  Published on May 13, 2012  
by Kara Swisher 
Yahoo’s embattled CEO Scott Thompson (pictured here) is set to step down from his job at the Silicon Valley Internet giant, in what will be dramatic end to a controversy over a fake computer science degree that he had on his bio, according to multiple sources close to the situation. 
The company will apparently say he is leaving for “personal reasons.”  But the evolving crisis — which is just over a week old — centered on his botched resume and how he handled the thorny issue is clearly the key reason for the abrupt leaving.

This Operational Risk loss is a failure of a process that may have been outsourced to an executive recruiting firm or to the Board Director responsible for the vetting and validation of each candidates information.  What is even more compelling to think about are all of the other CEOs that are now losing sleep over night because of the same issue at their own organization.  So where did someone go wrong in this case?  Was it a missed step in the process for hiring or a simple lack of integrity by the CEO himself, Scott Thompson?

This brings us to the convergence of our discussion on Operational Risk Management for both of these incidents.  There are aspects of transparency, governance and finding the truth.  And the truth is, we are all human.  Whether we are trading derivatives to hedge risk or we are vetting the information on a resume, the human factors and behavior associated with the actual risk management tasks themselves are the focus here.  Humans will make mistakes and that is precisely why we need the controls in place, to mitigate the potential for human error, omission and stupidity.

You see, it is the rules that matter in either case that have been ignored, disregarded or as a result of a lack of awareness.  The rule-sets are vital to the effectiveness of risk management whether they are best practices, international standards of conduct or the code of law within a particular jurisdiction.  These rule-sets have been discussed on this blog in the past, back in April of 2008:  Rule-Set Reset and others such as this one in May of 2004 on NYSE Rule 446:

Operational risk focuses on firms' abilities to maintain communications with customers and to retrieve key activity records through their "mission critical systems." Financial risk relates to firms' abilities to continue to generate revenue and to retain or obtain adequate financing and sufficient capital. In this regard, an eroding financial condition could be exacerbated or caused by deterioration in the value of a firm's investments due to the lack of liquidity in the broader market, which would also hinder the ability of the firm's counter-parties to fulfill their obligations. A firm would be expected to periodically assess changes in these exposures, and in the event of a significant business disruption, the firm would consult its plan and take appropriate action contemplated by its plan. Members' and member organizations' procedures should be written and implemented to reflect the interrelationship among these risks.

What rule-sets govern your organization?  Have you created a comprehensive governance map to help you guide yourself as a CEO and the remainder of your company through the maze of ethical, regulatory, legal and even sustainable rules that are before you?  Leadership in any organization whether it is in Silicon Valley, on Wall Street or the US Navy requires a prudent and clear path, to understanding the rules and the map to navigate both securely and safely.  Even with these rules and the map, you can predict that human behavior will intervene and deliver that next surprising blow to your institution.  Now it is just a matter of how often and the magnitude of the event.

Ask yourself:  What is our "Operational Risk Management" Quotient?