Showing posts with label FBI. Show all posts
Showing posts with label FBI. Show all posts

Saturday, November 16, 2019

Intelligence Fusion: The Race Against Time...

 Human intelligence may be the most sought after way to prevent new threats to your organization.

Yet that is never enough to give you total peace of mind. You have to implement multiple collection points for real-time and relevant information.

The front line of intelligence analysis begins far in advance of the actual event or incident taking place. Companies like "Quid" have provided some of the tools to detect the presence of new and relevant information in the hundreds of millions of active web sites across the Internet.

You may also see Dataminr in the corporate Security Operations Center (SOC) and even the local Fusion Center for more Real-Time information.

They assist CxO's in navigating their operational risk strategy execution across a competitive and increasingly threatening global landscape.

The fusion of intelligence from the Internet and broadcast media requires not only sophisticated software, hardware and talented Intelligence Analysts, it requires good old fashioned investigative tactics. And when you combine all of these to create the closest version of reality, then you have found true "Integrity."

Keeping information truely confidential is a difficult task. Assurance that the information will be there when you need it, is also equally important. Yet it is the "Integrity" of the information that we are in constant pursuit of.

Data fusion involves the exchange of information from different sources—including "John Q. Public" with his mobile phone, Ring and other IoT sensors, Law Enforcement, Public Safety, and especially the Private Sector—and, with analysis, can result in meaningful and actionable intelligence and information.
In a wide-ranging hearing on the myriad threats to the U.S. homeland, from white supremacist terrorists, border security, school shooters, and cyber attackers, the director of the FBI gave a glimpse of how the agency is using technology to blunt one of those threats.

FBI Director Christopher Wray, testifying before the Senate Homeland Security and Governmental Affairs Committee, said his agency has implemented a new threat-sharing capability on its Law Enforcement Enterprise Portal (LEEP).
The fusion process turns this information and intelligence into actionable knowledge. Fusion also allows for relentless reevaluation of existing data, in context with new data in order to provide constant updates.

The Private Sector is still the biggest challenge. Trusted relationships need to be continually fostered. New mechanisms for public-private coordination are consistently being discussed.

Fusion Center's are not the only answer. It still remains a significant piece of a very complex operational security challenge, that we will be facing for still years to come...

Sunday, April 30, 2017

Complacency Risk: The Next Attack...

 In Ronald Kessler's book "The Terrorist Watch" you get the impression that this journalist, author and nonfiction story teller is walking a thin line. A line between telling us too much, because it could compromise national security and not telling us enough, so that the public can really visualize what the truth is.

"Inside the desperate race to stop the next attack". This book tag line says it all.
Drawing on unprecedented access to FBI and CIA counterterrorism operatives, New York Times bestselling author Ronald Kessler presents the chilling story of terrorists’ relentless efforts to mount another devastating attack on the United States and of the heroic efforts being made to stop those plots.

Kessler takes you inside the war rooms of this battle—from the newly created National Counterterrorism Center to FBI headquarters, from the CIA to the National Security Agency, from the Pentagon to the Oval Office—to explain why we have gone so long since 9/11 without a successful attack and to reveal the many close calls we never hear about. The race to stop the terrorists, Kessler shows, is more desperate than ever.

Never before has a journalist gained such access to the FBI, the CIA, the National Counterterrorism Center, and the other agencies that are doing the unheralded work of finding and capturing terrorists.

Ronald Kessler’s you-are-there narrative tells the real story of the war on terror and will transform the way you view the greatest problem of our age.
OK, so what? So how does this war on terror and media leaks within the context of Operational Risk impact your institution or organization? Here are a few ways:
  • Will your company have staffing challenges as a result of new immigration legislation or limits on H1-B Visas? Remember the 9/11 hijackers?
  • Will your institution require new systems and processes to meet increased compliance or regulatory mandates? Remember the Patriot Act?
  • Will you or a senior staff member be the target of a kidnapping, ransom or extortion plot at the hands of a terrorist cell? Remember Danny Pearl?
  • Will your organization be impacted by the leaks in the press regarding your operational strategy or Board Room discussions? Remember pretexting at Hewlett Packard (HP)?
Sharing information. Too much or not enough. The paradox of our generation as we all go digital. The speed of business in the connected economy and 24 hour news cycles has created a beast that will not ever be tamed or controlled.

Operational risks are a result of the continuous challenges to the collection, dissemination and analysis of information. Think about your own institution and those who hold the keys to the most valuable information.

Those who disclose operational secrets could be putting that "deal" in jeopardy just as easily as putting that "life" in harms way. Those who try to sleep at night in close proximity of their "Blackberry" know the feeling of information overload, or starvation. Both represent operational risks that keep the same people grabbing the Prilosec OTC or the AmbienCR.

Ronald Kessler's book is a wake-up call for all of us in the United States. A Presidential election is behind us and there has been over eight years of testing and waiting by those who wish to do us harm.
"To many fail to recognize that al Qaeda's long-term goal is to send the US the way of the Roman Empire. And too many in the press are willing to take the chance of compromising the lives of innocent Americans by running stories that gratuitously disclose operational secrets."
The risk of complacency is and will continue to be our greatest threat...

Saturday, January 21, 2017

Asymmetric Advantage: Dawn Across Arlington...

One only has to stand behind the "Tomb of the Unknowns" and gaze across the national mall past the Washington Monument to begin to feel the magnitude of the challenges ahead.  As the wind swirls around the grave markers and the sound of sirens and jets are distantly present, you can feel an emotional wave of inspiration.

Today in Washington, D.C., the dawn of a new government administration is waking up and the rest of the world is waiting.  How will the asymmetric problems we face be solved faster?  Why does the decision to use "Solution X" make sense over "Solution Y", to address our nations adaptive Operational Risks?

Why would a U.S. citizen feel inspired this day and from this vantage point in Arlington?  It is because the future will bring new conflicts that are different than years past.  It will bring new opportunities for us to excel.  Every decade that wars occur, there are far less warfighters actually put into harms way.  The number of casualties slows.  Why?

The reason is that the kinetic types of wars are using new inventions and technologies to save lives.  Whether it is MWRAP's or tourniquets built into uniforms, or sophisticated "Geospatial Intelligence", the goal is to keep our warfighters safe and alive.

Now also in parallel, the conflicts are being waged 24 x 7 x 365 in another growing operational domain, where the IO Analyst is navigating electronic networks and complex lines of software code.  Information Operations are full of new challenges and substantial learning curves in order to gain the advantage.

Welcome to the #Virtual Caliphate:
Decades of border disputes, violent conflict, and shifting refugee populations have left millions of Muslims without a clear national identity. ISIL’s virtual caliphate offers them citizenship free from terrestrial constraints, which can be accessed from anywhere in the world.
How the United States responds to this threat of a growing set of virtually-inspired terrorists, who carry out their physical acts in the homeland, remains a substantial problem-set.  What else is in store for our Homeland?

"The U.S. is considered a high-priority intelligence target by many foreign intelligence entities. While traditionally the threat has been to our political, military, and diplomatic interests at home and abroad, the loss of sensitive economic information and technology is a growing threat to our national security. In recent years, economic espionage conducted by foreign intelligence entities, corrupt insiders, and corporate competitors has exploited vulnerabilities in cyberspace that may weaken our economic advantage. Cyber espionage has not replaced traditional espionage as a way to steal secrets, but the ability to focus technology on lesser protected information is a significant and growing threat." DNI.gov Domestic Approach to National Intelligence

The rules will be changing soon.  The tools will be too powerful and the threats too great, for the military to have their hands tied or their legal authorities limited.  The next generation of domestic cyber warfighters will now go into action, side-by-side from CyberCom, Homeland Security, FBI, CIA and a new coalition of advanced private sector contractors.  They will work across the Homeland from SCIFs in every state, with a new enhanced mission and a new unified command.

How will this save lives and give all of our warfighters what they need?

As the billion dollar budgets within the Pentagon shift their focus to platforms such as DIUx, or IARPA, innovative answers will be more apparent.  The growing solutions pipeline will become the basis for rapid deployment to our Operators.  The new Corps of men and women raising their hands from classrooms across the Homeland, will become exponential...they will serve in new roles and in new ways.

The future is bright and the changing of the guard at the "Tomb of the Unknowns", will soon see fewer ceremonies to bury our heroes or even hang another star on a wall in Langley...

Saturday, May 21, 2016

Social Engineering: CxO Leadership for BEC...

In the context of cyber security, many practitioner experts are already familiar with the "Business E-Mail Compromise" (BEC).  Operational Risk Management (ORM) professionals know this:
"Amateurs attack machines, Professionals attack people"

The BEC is a global scam with subjects and victims in many countries. The IC3 has received BEC complaint data from victims in every U.S. state and 45 countries. From 10/01/20131 to 12/01/2014, the following statistics are reported: 

  • Total U.S. victims: 1198
  • Total U.S. dollar loss: $179,755,367.08
  • Total non-U.S. victims: 928
  • Total non-U.S. dollar loss: $35,217,136.22
  • Combined victims: 2126
  • Combined dollar loss: $214,972,503.30
The FBI assesses with high confidence the number of victims and the total dollar loss will continue to increase.
What executives at most organization understand, is that they are a potential target for all kinds of threats from inside and outside the company.  Fortune 500 companies already have sophisticated internal accounting controls and "Personal Protection Specialists" who are doing advance work, for travel that the CxO takes across town or overseas.  Yet what about the Small-to-Medium Enterprise with just tens of millions of dollars in annual revenues?  Are they prepared as they could be for the BEC?

It does not take much for the financial controls and the accounts payable process to break down for companies and organizations, that have not prepared for this continuous threat, by your own insiders (employers, partners, suppliers) cooperation.  The numbers tell the whole story.  Countless times each year, companies are convinced to act upon a simple e-mail crafted by clever "Social Engineering" experts, to transfer money out of their corporate banking accounts.

So what are you doing to prepare, educate and deter this continuous wave of "Social Engineering" attacking your employees and key stakeholders?  How many computers and iPhones in your business or organization receive e-mail on a daily basis?  Each one of these is a threat vector, along with each one of your employees who is the human factor behind the device.

What is amazing today, is that a cyber threat like this, that has been talked about for over a year, is still growing.  Perhaps it is a leadership problem.  Perhaps it is a public safety announcement campaign problem.  In either case, you have to realize, there are some very specific remedies that can be exercised by your organization to deter, detect and defend yourself from "Business E-mail Compromise" (BEC).

Executives and senior staff are busy.  They are running the business and rarely have time for that two hour or half day training session.  This is your largest vulnerability to begin with at your organization.  An apathetic CEO or senior staff is the perfect target for any transnational organized crime (TOC) syndicate on the other side of the globe.

As a CxO, when was the last time you had a campaign within the organization to address these threats?  Weeks, Months, Years?  Why haven't you incorporated a continuous program to keep your employees and staff up to date?  If you have 1247 employees, then you have 1247 vulnerabilities walking around in your enterprise.

When you look at the line item in the Information Technology budget this year for hardware, software, maintenance and cloud computing, look a little further.  Where is the line item for the education program and the tactical awareness, to keep your people on the leading edge of deterring the social engineering wave of attacks in your organization?
There has been a lot of news in 2016 about a particular species of phish, the so-called Business Email Compromise (BEC). In this scenario, the attacker poses as an executive of a company, asking someone--usually a subordinate employee--to perform a wire transfer or similar action. When the employee complies and completes the transfer, the company realizes--too late--that it has just given a large payment to a criminal. An investment company in Troy, Michigan, recently lost $495,000 from a BEC phish, so this is not a small matter.

It even hit close to my (professional) home: DomainTools’ CFO recently received a spear phish purporting to come from our CEO, asking her to make a wire transfer of funds. The sending email address was a clever look-alike of “domaintools.com,” using some substituted characters. Fortunately our CFO is very savvy and knew right away that her boss wouldn’t actually make such a request in that way. But it underscores how common this kind of BEC phish is -- and how easy it is for criminals to spoof legitimate emails.
This is just a small example, of the continuous trend across the small-to-medium enterprise landscape.  You have the control and the ability to make a difference in your enterprise.  The time and the services exist for you to keep your organization more safe and secure than it is today.  When will you decide it is your "Duty of Care" to protect corporate assets and to start using some of the tools to make "Business E-mail Compromise" (BEC) extinct?

Saturday, February 27, 2016

RSA 2016: Ascending into a Trust Mindset...

Building awareness to a vulnerability, potentially heightens ones sensitivity to defend or build resilience to minimize damage or loss.  This is one of the foundations of Operational Risk Management (ORM), understanding what your assets are and what vulnerabilities exist.  Good old fashioned Risk Management 101, tells us to mitigate risks in the enterprise and even in our personal lives.

Is traditional Risk Management dead?  We think it is and through the eyes and inspiration of others we can now see why.  Our ability to make "Trust Decisions" is far more complex than just an emotion.  As we have evolved away from small villages where the food and water and other life essential resources were shared, trust factors have become more distant.  More shallow and less personal.  Our digital lives spanning continents and countries at light speed, now has given us a new perspective.  We must find our Trust Mindset.

As the RSA Conference opens on February 29, 2016 in San Francisco, thousands of eager professionals will converge on an event that has it's foundation and it's future built on "Achieving Digital Trust".  As we walk the Moscone Exhibition Halls observing, learning, engaged in dialogue or debate we must remind ourselves of the wisdom that comes from Jeffrey Ritter:
I have always viewed the emergence of the Internet and global computing as powerful tools to increase the velocity of the next solutions that enabled greater inter-dependence, greater accessibility to commerce, and more small steps toward peace. Through my work, however, I learned those tools were vulnerable unless, as a global society, we determine how to also build across the digital dimensions of cyberspace the capacity for humans to achieve what each transaction first requires—an affirmative decision to trust.
Jeffrey's latest book has been an inspiration for so many that have researched and lived in the Venn Diagram of the Law, Digital Technology and eCommerce.  Yet what about those people who have studied and modeled the human skills and behaviors to build trust with others that have yet to read Jeffrey's' book?  What is the fusion between the factors associated with building trust human-to-human and in a world of machines-to-machines?

"Trust Decisions" are being made by humans and computers each second of each day.  And one thing is certain about the decisions to trust by people and by the machine in your pocket, brief case or purse.  It is continuously learning and sharing.

The halls of the RSA Conference will be buzzing about trust.  In all of it's manifestations, the ecosystem of the event is about "Trust Decisions" and in many cases, man and machine.  The iPhone vs. the FBI.  Security vs. Privacy.  Cloud vs. Hybrid Cloud.  Secret Clearance or Top Secret Clearance.  Pre-hire background check.  FICO.  LinkedIn profile.  You name it and the fundamental question set, comes back to a "decision to trust."

Living an ethical life of integrity and willingness to share begins at an early age.  Sharing information responsibly with your peers, director or commander, requires a process for building trust over time and with each transaction of information exchange, either building or eroding the future decision to trust.

Here is one recent example.  Sitting in a room with a dozen strangers the other day was a mini-case study.  The purpose of this particular meeting was for this group of people to establish a forum for future trusted information exchange.  We were all part of the same ISAO if you will, not the same company.

The agenda called out for each person to introduce themselves, all for the first time.  The specific rules for the introductions were not spelled out by the host and then agreed by all of the meeting participants.  What happens next is a classic example of trust erosion, when the rules are absent.  As we proceeded around the room, each person took it upon themselves to determine how much or little information they would share with the rest of the group.

Some people introduced themselves with their name, company affiliation and a "one liner" on the business they were in.  Others in addition, took the opportunity to tell us all about their entire product/service line and why the solution was something that we should be interested in.  The first impressions were already building or eroding our perceptions of trust.  Our own reality.

It should be our ambition to continuously heighten our sensitivity to behavior in an environment absent of rules and how this builds or erodes our future trust decisions.  When you share, do you always have an expectation of reciprocity?  When you boast about yourself or your organization, is it for your own ego or self-satisfaction?  Do you ever even ask the question, "How are you" or "How can I help" you?  What are the rules?

Extraordinary trust is rare these days.  True Leadership is scarce.  Courage is almost extinct.  Think about how you can stand out and at the same moment, project a feeling of care, of concern and generosity.  Giving without any expectation of return, is what is going to help you build trust in your life.  And when you achieve that with your wife, husband, children, church, business partners, employees, clients and suppliers, then you know you are well on your way to substantial well being.

If you are alone and without many true and deep relationships in your life without cyberspace, there is a good reason why.  Achieving and building trust inside your organization (company or family) has been written about for years.  Happy employees make happy customers.  You have heard this before no doubt.   Building awareness to a vulnerability, potentially heightens ones sensitivity to defend or build resilience to minimize damage or loss.  This is where we started this blog post.

As we descend on the RSA Conference with the focus on "Trust Decisions", it will be with an ascent towards a continuous mindset of sharing, of caring and of learning.

Sunday, December 13, 2015

Beware of the Cowboy: Risk Driven by Fear...

Beware of the cowboy.  Operational Risk Management (ORM) spans the hazards on the flight deck on the USS Ronald Reagan (CVN 76) or behind enemy lines or even to employee behavior on the front lines of the private sector on Wall Street:
"The recent conviction of Michael Coscia in the Federal District Court in Chicago in the first prosecution for “spoofing” provides more clarity to high-frequency trading firms about how they can operate. The message is to tread carefully when a strategy depends on using orders that will be quickly canceled because the government may claim they are an effort to manipulate the market by fooling others into trading.

Spoofing was made illegal in the Dodd-Frank Act, which prohibits “bidding or offering with the intent to cancel the bid or offer before execution.”
Believe it when we say that people who try to be cowboys in your organization are operating without regard to risk. Now multiply the number of cowboys by the number of people that they surround on their team, who think that this is the way to operate. It doesn't take long to find out that these are the root causes of many of the operational risks in your organization. And it starts out with the basics even in the vast private sector beyond Wall Street:
  • Revenue is not booked according to the rules. Products sit in the warehouse yet revenue ends up on the sales reps commission report because (s)he had a signed order.
  • Assets are not valued correctly. Bank accounts are not validated to make sure they actually exist and accounts receivables are inflated.
These are just two of the many facets of occupational fraud that starts with a few cowboys who have little regard for managing risk and all the incentives to line their pockets with new found cash or bonuses.

From Leadership Lessons of the Navy SEALS

The Cowboy
"Neither of us knows if such a thing has ever been tolerated in modern commando teams. Yes, sometimes you need to charge forward. But, there are simply too many potential casualties and too much political currency resting on commando missions to entrust one to a cowboy. Authorization for an operation depends on the accurate calculation of operational risk. This requires an assessment of proven forces ability to perform a task. All this is contrary to the cowboy philosophy of depending on experimentation, pluck, and luck in order to succeed."
"The problem with being a cowboy is that your bosses won't employ you if they can't trust you, and they can't trust you if they don't know what you'll do. And then you're stuck with the reputation."
        --LT. CMDR. Jon Cannon

You might think that the reason is ego or just plain greed. However, the real motive may not be so clear. More than likely, the motive is fear. And that fear is something that grows until it gets to the point of creating harm, loss and destruction. You have to find the cowboys in your organization and you have to follow the mantra of quality gurus from years past, "Drive out Fear".

Sunday, May 04, 2014

Consumer Privacy USA: The Risk of Viceroy Tiger and Keyhole Panda...

There is a flurry of Operational Risk Management (ORM) activity around the DC beltway and across Silicon Valley in order to gain new consumer confidence.  The confidence that their personal metadata and information is being protected with encryption software and that privacy policies are in place to notify users, when their information is requested by the government.  Interesting.

Much of this wasted bandwidth is focused on competitive strategies.  If LinkedIn gets 3 or 4 stars from the EFF "Who Has Got Your Back Report" then our social media company should aspire to do the same. Transparency to the consumer end user on how data is protected and when you are notified of it being lost, leaked, hacked or handed over to law enforcement is the buzz right now.  Why?
Apple, Facebook, others defy authorities, notify users of secret data demands 
By Craig Timberg, Published: May 1 
Major U.S. technology companies have largely ended the practice of quietly complying with investigators’ demands for e-mail records and other online data, saying that users have a right to know in advance when their information is targeted for government seizure.
This increasingly defiant industry stand is giving some of the tens of thousands of Americans whose Internet data gets swept into criminal investigations each year the opportunity to fight in court to prevent disclosures. Prosecutors, however, warn that tech companies may undermine cases by tipping off criminals, giving them time to destroy vital electronic evidence before it can be gathered. 
Fueling the shift is the industry’s eagerness to distance itself from the government after last year’s disclosures about National Security Agency surveillance of online services. Apple, Microsoft, Facebook and Google all are updating their policies to expand routine notification of users about government data seizures, unless specifically gagged by a judge or other legal authority, officials at all four companies said. Yahoo announced similar changes in July. 
As this position becomes uniform across the industry, U.S. tech companies will ignore the instructions stamped on the fronts of subpoenas urging them not to alert subjects about data requests, industry lawyers say. Companies that already routinely notify users have found that investigators often drop data demands to avoid having suspects learn of inquiries.
Enterprise business are now waking up to the reality of investing in more robust Operational Risk Management (ORM) practices within their Enterprise Architecture Framework.  Areas that have been neglected in the architecture for data transport are now finally being updated.  Even the fact that the latest versions of SSL capabilities are being exposed as a result of the "Heartbleed" vulnerability, has finally motivated many to upgrade to TLS 1.2 and add Forward Secrecy.  Even LinkedIn, who gets multiple stars from EFF (and only a "B" from Qualys SSL Labs) doesn't even use TLS 1.2 nor does the average consumer even understand why Forward Secrecy is an important capability or why Google uses it within the popular Gmail service.

The privacy policies and opt-out capabilities the consumer really needs, are from the private sector companies that are currently trading your personal information.  Your browsing history. Your purchases at national retailers.  When was the last time you gave your phone number to a cashier at the register, to earn buy 1 get 1 coupons or a discount at the local gasoline pump?  Where do you think all of this activity-based behavior about you the consumer is being resold?

The marketing of privacy and security will continue to become a product or service differentiator.  The government agencies will continue to follow the law to obtain your information.  The magistrate judges will make sure of this.  The adversaries however, are becoming more productive and will find new exploits to attack your infrastructure in new ways, on vectors that you have not even thought of yet.

Who are some of the adversaries?  A few worth noting:

  • Iran:  Cutting Kitten
  • India:  Viceroy Tiger
  • China:  Comment Panda, Deep Panda, Foxy Panda, Keyhole Panda, Union Panda, Vixen Panda et al

These cyber adversaries are in many cases focused on cyber espionage and the theft of your Intellectual Property or Research and Development.  This leaves hundreds of other capable crime-ware driven organizations across the globe, who are targeting other valuable data to perpetuate their fraudulent activities.  So what have you done at the Board of Directors level and the Executive "C" Suite, to pave the way for more effective collaboration with the G-man?

Collaboration with the FBI, Secret Service, SEC, FTC, OFAC, U.S. Attorney, State Attorney General or even the local county prosecutor is a prudent and wise Operational Risk Management strategy. "Complacency"--this could be one of the greatest vulnerabilities that your share holders and stake holders have ignored.  A proactive organization has established protocols, implemented best practices and tested policies.  They are already in place to work collaboratively with local, state and federal government.  These organizations will ultimately be the marketplace front runners.
“In an era where very sophisticated and determined criminals have proven capable of successfully attacking a wide range of computer networks, we must all increase our level of vigilance. Michaels is committed to working with all appropriate parties to improve the security of payment card transactions for all consumers.”
This is just one more example of what is becoming the new normal.  The Operational Risk Management (ORM) professionals in your organization are ready and willing to support corporate executives and the Board of Directors new found enlightenment.  Your new government partners will even share information with you, on the latest modus operandi of "Keyhole Panda"...

Sunday, November 27, 2011

Intelligence Analysis: Robust and Resilient...

Operational Risks are on the rise for Top Secret America. Now that the "Super Committee" has thrown in the towel, there are several companies beginning to ask what it will mean in the next few years. Intelligence Analysis has been a tremendous windfall for large and small businesses especially in the National Capital Region of the United States.

The analysis of information, from open sources (e.g., information that appears in the news media or on the Internet) to the most sensitive information collected or gleaned from human and technical sources. Since 9/11, there has been an explosion of the amount of information obtained via technical means, particularly imagery and communications intercepts, necessitating new analytic methods of sorting and exploiting incoming information, as well as data mining to discover patterns of information and intelligence contained within huge quantities of data. Document exploitation (DOCEX) and forensic methods are also growing areas of intelligence analysis for captured materials and site exploitation.


39 government organizations and 358 companies are at the nexus of "Intelligence Analysis" according to the work by Dana Priest and William Arkin of the Washington Post. The next 24 months will tell us how this vital discipline begins to morph from agency to agency and company to company based upon who is deemed most essential and what information is most highly valued.

40 large companies, 57 medium companies and 261 small companies, comprise the majority of the firms who are the supply chain to many of the core intelligence apparatus of the U.S. Government. When these supply chains are impacted by the quantity and potential quality of intel, the opportunity for operational risks will increase. If you can imagine a pipeline of information coming from the street and keyboard level, all the way up to the Presidential Daily Brief (PDB) 365 days a year, this is what is at stake.

So what could you expect to happen in the next few years when it comes to the "Intelligence Analysis" pipeline and the rate and quality of information that is flowing to provide "Decision Advantage"? It's going to increase and for good reason. The traditional nation states and the threat of an attack from conventional means is diminishing. The new threats are morphing into the new normal. The asymmetric methods of warfare in the digital domain:

Congress will pay the FBI an additional $18.6 million to better investigate computer hacking cases, following a federal study that found a third of bureau agents probing breaches significant to national security lacked the necessary networking and counterintelligence skills.

A spending package passed Nov. 17 to fund many federal agencies through September 2012 includes President Obama's full request for $166.5 million to tackle computer crimes, an 11.2 percent increase over last year's appropriations. The bureau must use the money to hire an additional 42 computer security professionals, including 14 special agents, according to a report accompanying the legislation.


The new funds will also assist in the continuous analysis of information, to ascertain the origin and the legitimacy of attacks agains U.S. Critical Infrastructure, the next frontier for insider threats and cyber terrorists:

An ongoing investigation into the possible hack of a U.S. water plant should trigger a methodical analysis of the security of the nation's industrial systems to avoid jumping to the wrong conclusions, former federal cybersecurity officials say.

The Homeland Security Department's cyber response team and the FBI are gathering facts about a report of a water pump failure in Springfield, Ill., according to DHS officials. Their actions follow a state fusion center alert, first reported by noted security specialist Joe Weiss and later publicized by media outlets, that apparently suggests intruders may have lingered in the system for weeks. Some security experts familiar with the report are attributing the malfunction to a targeted attack originating from a Russian network access point, or IP address. If the report bears truth, then this incident represents the first known intentional intrusion into a U.S. industrial control system.

But some experts caution that many organizations don't have the computer forensics expertise to pinpoint the cause of suspicious network events, let alone the identities of perpetrators.


Intelligence Analysis is alive and well and the education and quality of the analysis will not be disrupted regardless of what law makers may fail to do behind closed doors. Operational Risk Management in the 358 companies is on high alert, yet diligently working to ensure the supply chain is robust and resilient for a long time to come.

Saturday, April 24, 2010

FCPA: OPS Risk in Pharma & Small Business...

If you are a large U.S. based pharmaceutical company the odds are that over a third of your annual sales are overseas. Selling drugs in the EU, Asia and South America into the health care systems is a tremendous pipeline for Eli Lilly, Pfizer and others who find these markets hungry for their products. What kind of Operational Risks might exist for these firms and should be on "Red Alert" status with the General Counsel?

The DOJ is currently pursuing 120-130 FCPA investigations, and now it has set its sights on enforcement in the pharmaceutical industry where on an annual basis “close to $100 billion dollars, or roughly one-third, of total sales … [are] generated outside of the United States.” The DOJ’s new focus stems in part from the fact that many foreign health systems are regulated, operated and financed by government entities, and competition is intense, which creates more opportunities to “pay off foreign officials for the sake of profit,” and a perceived need for greater supervision from law enforcement.

The head of the Criminal Division of the United States Department of Justice (DOJ), Assistant Attorney General Lanny A. Breuer has indicated their interest in looking at this industry with increased scrutiny. So if you are a General Counsel at one of the companies in the cross-hairs of the government what are you doing about it?

First, you have to call together the right people and create your own internal FCPA Task Force within the enterprise. The General Counsels Office has the lead on bringing together four to six people from Sales & Marketing, Finance, Information Technology, and Internal Audit. This team will have the autonomy, funding and jurisdiction to work specifically on the vulnerabilities that exist on a global basis.

Second, you have to understand the culture, governments and the "Ground Truth" in each country you are selling your pharmaceuticals in, to map the processes and the people associated with the heath care systems, hospitals or the military that are the actual consumers of the medicines and drugs.

Finally, you have to educate your work force on the fact that pharmacists, doctors, lab technicians and other health care consultants may indeed be officials of the government of that country based upon who they work for. Why is this important?

The FCPA has a broad definition under the law that pertains to the foreign officials. In some countries it's entirely possible that if the medical institutions are owned by the government that almost everyone who works in these facilities could be considered under the FCPA. So what is the task force going to do to ensure that the company does not violate the law?

Beyond the focus on compliance and education of employees, there is much work to be done in the collection, analysis and actions within the enterprise of relevant information. Predictive analysis of data that is coming from the CRM, ERP and other open sources can provide the task force with the "Corporate Intelligence" and "Red Flag" warning to prevent a violation of the law. The ability of the company to utilize data collection and predictive analytics to not only head off any DOJ investigation also can be effective in providing voluntary disclosure to government.

Wait a minute. You mean, tell the government that we have identified a violation of the law and bring the wrath of the law and the possible impact on our corporate reputation? Yes and this is why.

Under Federal Sentencing Guidelines, those organizations that do a rigorous internal investigation and share the results with the government can avoid such sanctions as the mandate for a costly independent compliance monitor. Deferred prosecutions are not unheard of and the government can in some cases help you save money in terms of getting fines on the lower end of the sentencing guidelines.

The General Counsel's "Corporate Intelligence Unit" that is focused on the analytics of relevant data, combined with the education, awareness and compliance processes will be well on there way to keeping the legal risk and Operational Risk events associated with the Foreign Corrupt Practices Act (FCPA) from impacting their global pharmaceutical enterprises. And just when you think that the DOJ is only looking at the Fortune 500, then think again:

More focus on small and mid-sized companies: As part of their increased FCPA-related efforts, the DOJ and SEC are expected to look more at small and mid-sized firms which do business overseas. The majority of such companies have a small established compliance program, or none at all, yet some may conduct billions of dollars in foreign transactions.

Companies that are not household names have long believed that they were under law enforcement’s radar. Smaller firms have also thought that the DOJ would not expend the resources to investigate their overseas sales. That comfortable illusion no longer exists.

If you are a small disadvantaged supplier to a large Defense Industrial Base (DIB) company working on a sub-contract, then you too should be standing up your FCPA Task Force now:

On January 18, 2010 twenty-two business executives were arrested and over 100 FBI agents conducted related searches. These actions were based on sealed federal indictments handed down by a grand jury several weeks earlier, which in turn stemmed from a two-and-a-half year undercover operation. The indictments claimed that the defendants believed that they were involved in a scheme to acquire a US$15 million defense contract to outfit the presidential guard of an unnamed country. They allegedly agreed to pay a 20 percent bribe to a sales agent, supposedly representing the defense minister but really an undercover FBI officer. This was the first large-scale use of undercover law enforcement techniques to investigate Foreign Corrupt Practices Act (FCPA) violations.

Friday, June 26, 2009

Digital Forensics: Right to Question CSI's...

The US Supreme Courts ruling in MELENDEZ-DIAZ v. MASSACHUSETTS will have significant impact on Digital Forensics expert practitioners. Legal cases utilizing the examination of computers and other digital assets containing relevant information will have more testimony by CSI analyst experts. The New York Times report by Adam Liptak says:

Crime laboratory reports may not be used against criminal defendants at trial unless the analysts responsible for creating them give testimony and subject themselves to cross-examination, the Supreme Court ruled Thursday in a 5-to-4 decision.

Noting that 500 employees of the Federal Bureau of Investigation laboratory in Quantico, Va., conduct more than a million scientific tests each year, Justice Kennedy wrote, “The court’s decision means that before any of those million tests reaches a jury, at least one of the laboratory’s analysts must board a plane, find his or her way to an unfamiliar courthouse and sit there waiting to read aloud notes made months ago.”

The outcome of the ruling for the prosecution is that forensic examiners and scientists will be more thoroughly scrutinized in the tests they perform. The process will require more effective documentation and the ability to play back for a jury exactly the process utilized to support any facts of evidence. This will not be difficult as Best Practices today are being utilized such as the video taping of the entire test and examination. Achieving a "Defensible Standard of Care" will however be even more of a priority for Operational Risk Management professionals.

The defendant will have the ability to cross-examine the analyst, whether is was making a determination on what the blood type was of the accused attacker or the date, time, and place that the defendant sent an e-mail from the office computer to a co-conspirator.

In the digital forensics environment, the ruling means that the subject matter experts will simply be spending more time in court and on the witness stand. This will impact the time it takes to conduct the trial yet the rights to examine the process, expertise and documented procedures for the evidence that has been introduced is an important issue.

From an Operational Risk Management point of view, this means that your eDiscovery and Digital Forensics certified examiners will be under the magnifying glass and subject to the questioning by counsel. We see an increased attention to related matters coming soon. Several states are asking that the entities associated with inspection of digital assets be licensed by the state itself, as a Private Investigator. This provision would subject the expert authority to also being legally certified in the knowledge of state laws pertaining to civil procedure, chain of custody and legal procedures on the handling of evidence.

The question remains on whether the Supreme Court Justice's were thinking beyond the test for the presence of a drug, as this case was focused on in MELENDEZ-DIAZ v. MASSACHUSETTS. The defense bar will be utilizing this ruling to go beyond the criminal courts to the civil trials where white collar cases are largely based upon the documents, e-mails and other digital evidence that has been retrieved using forensic procedures.

It will be interesting to see how this ruling impacts the professional licensing, certifications and documentation of examinations for the 21st century Digital Forensic "CSI".

Tuesday, November 11, 2008

AML: Transnational eCrime Ecosystem...

The Operational Risk threat matrix from "Advance Fee Fraud", "Nigerian Letter (419) Fraud, Foreign Lottery/Sweepstakes Fraud and "Overpayment Fraud" is still growing exponentially. During our current economic crisis, the spike in these consumer Mass Marketing schemes is to be expected. Global Anti-Money Laundering (AML) operations are in high gear at home and abroad.

The "Transnational Economic Crime Ecosystem" is thriving and the major phases of the environment continue to be a major challenge for global financial institutions and law enforcement:

  1. Collection
  2. Monetization
  3. Laundering

Let's take a closer look at "Overpayment Fraud":

Overpayment Fraud - Victims who have advertised some item for sale are contacted by buyers who remit counterfeit instruments, in excess of the purchase price, for payment. The victims are told to cash the payments, deduct any expenses, and return or forward the excess funds to an individual identified by the buyer, only to discover they must reimburse their financial institution for cashing a counterfeit instrument.

The predominantly transnational nature of the mass marketing fraud crime problem presents significant impediments to effective investigation by any single agency or national jurisdiction. Typically, victims will reside in one or more countries, perpetrators will operate from another and the financial/money services infrastructure of numerous additional countries utilized for the rapid movement and laundering of funds. For these reasons, the FBI is uniquely positioned to assist in the investigation of these frauds through its network of Legal Attache offices located in over 60 U.S. embassies around the world. By leveraging its global presence and network of liaison contacts, the FBI has successfully cooperated with other domestic and foreign law enforcement agencies to combat, disrupt, and dismantle international mass marketing fraud groups.

Despite the best inter-agency enforcement efforts to combat mass farketing fraud, the FBI remains cognizant of the fact that the only enduring remedy for this crime problem lies in consumer education and fraud prevention programs. Towards this end, the FBI has not only produced its own mass marketing fraud prevention pamphlet but coordinates on other public information efforts with the DOJ, FTC, and the USPIS. The FBI also supports a consumer fraud prevention website in conjunction with the USPIS which can be located on the web at: http://www.lookstoogoodtobetrue.gov.

While the number of Mass Marketing Fraud cases has declined over the past few years, the number of new money laundering cases has risen to over 500 in FY 2007 alone. This is to some degree as a result of the cooperation being given to law enforcement by the financial instituions themselves. And for good reason. There is a new sheriff in town.

(Reuters) - A U.S. tax investigation into UBS AG (UBSN.VX: Quote, Profile, Research, Stock Buzz) is concentrating on senior and midlevel executives and bankers, and could result in one or more indictments, the New York Times said, citing people briefed on the matter.

Investigators are sifting through more than 70 names and related account details of American clients provided by UBS over the last few months to the Justice Department, which has passed the details to the Internal Revenue Service for further scrutiny, the paper said.

The Justice Department and the IRS plan to build both civil and criminal tax-evasion cases against some of the clients, the people told the paper.

The U.S. tax investigation risks compounding damage to UBS's reputation at a time it has been forced to make bigger writedowns than any other European bank in the credit crisis.

The U.S. Department of Justice is investigating UBS over offshore services provided to U.S. clients from 2000 to 2007 to find out whether UBS helped wealthy Americans dodge taxes. The Swiss bank was singled out by U.S. President-elect Barack Obama as one of the banks who helped "tax cheats." It decided earlier this year to stop offering offshore Swiss bank accounts to U.S. citizens.


Yet the collection phase of mass marketing fraud is not about "70" or a "100" UBS clients who are trying to cheat on their taxes. It is still about the millions of phishing and spam messages that circle the digital globe in search of their targets or prey. These illusive criminal organizations behind this organized cybercrime wave are continually exploiting the vulnerabilities of our financial institutions and our own human behavior.

"Merchandise Mules"
are being recruited by the hundreds if not thousands to reship goods outside North America. These criminals are utilizing stolen identities and credit cards to purchase goods on eCommerce sites and eBay and then requesting to ship the goods overseas. Unfortunately, those who are elderly or even just down on their economic luck fall victim to this tremendous economic crime tsunami:

Much of the modern organized crimes are very similar to the old. The most significant transformation from the streets to cyberspace has enlarged the territory of individuals and organized groups.

Enabled by the Internet, criminals can operate in cyberspace where less governance, a transnational stage, and a multitude of transactions to monitor complicate surveillance and enforcement. From counterfeiting drugs and software to identity theft and credit-card fraud, illegal transactions are increasingly infiltrating legitimate businesses where counterfeited goods and money laundering are buried in the billions of legitimate computer transactions made daily around the globe.

Counterfeited products are rising through global distribution via Internet sites. According to the World Health Organization, 50 percent of the medicines sold online are counterfeit.

The expanse of international criminal activity has been followed with an increase in prosecution through cooperating international law enforcement agencies willing to join the fight against globalized crime.

Wednesday, June 25, 2008

Transnational eCrime: Leaderless Networks...

Transnational crime and the multi-phase process of Collection, Monetization and Laundering is no better illustrated than in this Citibank case of this past year. This week more arrests have occurred as the informants intelligence has been utilized in capturing those who are part of this international criminal network. Kevin Poulson at Wired writes:

The FBI has recently made at least six more arrests in New York -- bringing the total to 10 -- thanks to information from arrested scam suspects, a lucky traffic stop, and an undercover operation that at one point had Eastern European hackers chasing a female FBI agent through the streets of New York, trying to mug her for ATM-card-programming gear. Six months after the 2007 breach, Wired.com is receiving scattered reports of Citibank customers still suffering mysterious withdrawals from their bank accounts.

The FBI believes the brains behind the operation is a Russian man, who's receiving the lion's share of the profits through international wire transfers and online-payment systems. While Citibank and federal officials are being closed-mouthed about the PIN theft and the ensuing fraud, the Citibank heist provides a rare look at how a single high-value breach reverberates through the international "carding" community of bank-card fraudsters. What's more, neither Citibank nor the third-party transaction processor involved in the breach has warned consumers to watch for fraudulent withdrawals, raising questions about the disclosure policies in the financial industry.


The case is unfolding in the media and the finger pointing will continue on where the breach occurred. Was it on a Citibank network or an outsourced third party supplier of 7-Eleven who operates the retail stores where the ATM's are located? ID Theft is not the real issue here as much as a bold database hack of accounts, PIN's and counterfeiting of ATM cards.

This facet of Operational Risk is another lesson learned about the safety and security of customer data especially when it is outside your own corporate domain. Service Level Agreements (SLA) are too often the only item that is consistently presented as evidence of the due diligence of auditing a third-party processor of customer data. The actual physical audits are few and typically are not done on a rigid schedule. Resources and funding are the excuse more often than a total lack of oversight.

Transnational crimes such as piracy, illegal traffic of drugs and humans, counterfeiting and intellectual property theft or espionage is not new to the Operational Risk Managers of global enterprises and international organizations. What the financial motivations are and where the proceeds are going is potentially the greatest challenge any investigator has on their agenda. Where does it all lead? What does the target plan to do with the money gained from these illegal activities and incidents?

The answer is that there is no single target. The target is a network. And like a starfish, it can reconstitute itself from any severed part; there is no brain. Douglas Farah captures the thinking on why leaderless networks are a continuous threat:


Any one piece of the leaderless network can reconstitute itself with little difficulty, without waiting around for someone to give an order and for that order to move down the chain of command.

Clearly, it seems, there are better and worse individuals within the network, and taking out the really good ones takes something of a toll. And leaderless groups are not highly efficient. But they survive.

If you have a system of enterprising freelance operations acting on impulses (the urge for profit, the urge to carry out attacks, the urge to acquire weapons etc.), these impulses will overlap. The actions will be taken to benefit all parties, and the networks can thrive with no one person making the important decisions.

This strikes me a perhaps the most dangerous mutation that both organized crime groups and terrorist groups (particularly Islamist terror groups, who seem more adept at moving through nerve impulses, without specific orders, than most), can take.

Successfully countering these groups and their growing reach will require a radical new assessment of both strategy and tactics in the military, intelligence community and law enforcement. But that will require a willingness to dump old assumptions and paradigms, something that has not really happened since 9-11.

Thursday, May 08, 2008

Legal Ecosystem: Survival of the Fittest...

The life cycle of monetary policy and financial fraud is being mapped once again in concert with new investigations into corporate malfeasance. As economic trends run their systemic course so do the highs and lows of human behavior to create new schemes to defraud customers, partners and even fellow employees.

Prosecutors in the Eastern District of New York in Brooklyn are stepping up their scrutiny of players in the subprime-mortgage crisis, focusing on Wall Street firms and mortgage lenders, the Wall Street Journal said on its Web site.

A task force of federal, state and local agencies will look into potential crimes ranging from mortgage fraud by brokers to securities fraud, insider trading and accounting fraud, the Journal said.

The Federal Bureau of Investigation is already targeting major corporate insiders and criminal groups in its investigation of fraud in the mortgage lending industry. The FBI has said it is investigating 19 companies in mortgage cases.

The formation of the task force amplifies efforts already under way in Brooklyn, where prosecutors are investigating whether investment bank UBS AG (UBSN.VX: Quote, Profile, Research) improperly valued its mortgage-securities holdings, the report said.

Also being investigated are the circumstances surrounding the failure of two hedge funds at Bear Stearns Cos (BSC.N: Quote, Profile, Research), which collapsed last summer because of losses tied to mortgage-backed securities, the report said.

Fraud, like other crimes of opportunity, have three common attributes:

  1. A growing supply of motivated offenders
  2. The availability of prospective or ideal targets
  3. The lack of consistent oversight mechanisms—control systems or someone to monitor the business

Beyond the typical motivations for initiating deceptive practices and fraud are the underlying mind sets. "Neutralization" creates the road map for nullifying internal moral objections. The type of fraud is not the issue here as much as that offenders seek to justify or rationalize their actions and methods. Grace Duffield and Peter Grabosky have captured the four main categories of fraud in their paper, "The Psychology of Fraud."

  • Fraud committed against an organisation by a principal or senior official of that organisation
  • Fraud committed against an organisation by a client or employee
  • Fraud committed against one individual by another in the context of face-to-face interaction
  • Fraud committed against a number of individuals through print or electronic media, or other indirect means

Now the IT departments will be buzzing as they will be under orders to preserve e-mail archives as evidence as soon as notices arrive on the doorsteps of not only the large funding institutions themselves, but the hundreds of organizations in the corporate supply-chain.

The duty to preserve attaches immediately once the company is on notice. Once an investigation or lawsuit is reasonably anticipated or a complaint is received, the requirement to preserve materials attaches and preservation efforts need to be undertaken as soon as possible. There are no cases that provide definitive guidance as to how quickly litigation hold notices must be sent once the duty is triggered, but any such case will be evaluated in hindsight, i.e., after relevant materials have been destroyed, and very little if any delay is likely to be tolerated by the courts.

Let's do some simple math here. Multiply the number of banking branches x the number of mortgage brokers for each branch x the number of appraisal firms and you start to understand the magnitude of the volume of data. While some larger banking institutions have centralized underwriting operations for all of the branches, they still rely on a supply-chain of small businesses in the local market to address the valuations and appraisals of property.

The next trend line we will see is the up tick in court filings and the litigation wars for the next few years to come. One fact remains obvious. Organizations large and small will be drawn into these Operational Risk Management challenges without the proper policies, practices and behavior to prevail. In any "legal ecosystem" we know about the phrase "Survival of the Fittest" comes to mind and this one, will be no different.

"Survival of the fittest" is sometimes claimed to be a tautology. The reasoning is that if one takes the term "fit" to mean "endowed with phenotypic characteristics which improve chances of survival and reproduction" (which is roughly how Spencer understood it), then "survival of the fittest" can simply be rewritten as "survival of those who are better equipped for surviving".

Monday, April 28, 2008

Corporate Governance: Testing for Organizational Disease...

In our continuing series on Security Governance we now turn to Corporate Governance: Testing for Organizational Disease.

It's been three years since a 25 year sentence was handed down in the Worldcom corporate governance and fraud case, it's obvious that prosecuting white collar crime cases is a real challenge.

In the HealthSouth Corp. fraud trial, the jury made a different decision and the CEO was acquited.

Some lawyers suggested white-collar cases are inevitably difficult to present to jurors, whether they live in Birmingham or New York. "It's different from a drug deal or a bank robbery," said Donald Stern, a Boston attorney who was formerly that city's top federal prosecutor. "It's not obvious that a crime has been committed."


What the Board of Director's and Executive Management do know is that it's time to make some more changes in Corporate Governance initiatives. The relationships with the shareholders is bound to continue to be a challenge for any management team and they realize that they must be creating a culture full of ethics and risk management principles.

At the end of the day it comes down to the evidence presented to the jury. And the evidence is typically a presentation of information utilizing forensic methods of discovery. Dr. Thomas R. O'Connor at NCWC has some interesting background on the subject of "Investigative Methods of Forensic Accounting."

Signs of financial crime can be initially detected in a variety of ways -- by accident, by whistle-blowing, by auditors, by data mining, by controls and testing, or by the organization's top management requesting an inspection on the basis of mere suspicion. Ideally, fraud detection ought to be recognized as an important responsibility throughout every organization, and every employee in an organization ought to be familiar with the disciplinary consequences for breach of trust as well as failure to report criminal misdeeds against the organization. On a practical level, however, there are steps to the investigative method used in an organizational context that are far from these ideals, and reaching the "breakthrough" point is more an art than science. It is the purpose of this lecture note to outline the investigative methods and procedures used in most cases.


Red Flags of Organizational Behavior:

1. Unrealistic performance compensation packages -- the organization will rely almost exclusively, and to the detriment of employee retention, on executive pay systems linked to the organization's profit margins or share price.

2. Inadequate Board oversight -- there is no real involvement by the Board of Directors, Board appointments are honorariums for the most part, and conflicts of interest as well as nepotism (the second cousin to corruption) are overlooked.

3. Unprofitable offshore operations -- foreign operation facilities that should be closed down are kept barely functioning because this may be where top management fraudsters have used bribes to secure a "safe haven" in the event of need for swift exit.

4. Poor segregation of duties -- the organization does not have sufficient controls on who has budget authority, who can place requisitions, or who can take customer orders, and who settles or reconciles these things when the expenses, invoices, or receipts come in.

5. Poor computer security -- the organization doesn't seem to care about computer security, has slack password controls, hasn't invested in antivirus, firewalls, IDS, logfiles, data warehousing, data mining, or the budget and personnel assigned to IS. Simultaneously, the organization seems over-concerned with minor matters, like whether employees are downloading music, chatting, playing games, or viewing porn.

6. Low morale, high staff turnover, and whistleblowers -- Low morale and staff shortages go hand-in-hand, employees feel overworked and underpaid, frequent turnover seems to occur in key positions, and complaints take the form of whistleblowing.


As we move forward on strategies for improving ethics and protecting corporate assets it's clear that educating board members and employees to the symptoms of corporate disease can be a key initiative. That education and awareness program could be the beginning of a whole new era of high performing companies. And for that matter, the programs effectiveness may be the first test of any organizations health.

Thursday, March 29, 2007

DRP: Document Retention Policy...

Corporate Fraud is nothing new and seems to be going in cycles. Now we are back to the days of the real estate financing and mortgage lending wrong doing but this time it might be a larger issue than the past. When this issue gets on the docket over at the Daily Caveat, you can bet this is not going to be a trivial matter.

Atlanta-based Beazer Homes USA is facing scrutiny from the FBI over allegedly fraudulent practices in the company's mortgage lending business. Beazer, a public company, operates as a home builder in 21 states.

The bureau's report said mortgage fraud comes in two broad varieties: "fraud for profit," which is largely committed by industry insiders and involves practices such as falsely inflating property values, and "fraud for housing," which is committed by borrowers and involves actions such as acquiring a house under false pretenses.

The bureau said it is cooperating with trade associations representing mortgage bankers and the government-sponsored companies that purchase mortgages, Fannie Mae and Freddie Mac, to raise awareness of mortgage fraud.

Whenever you have boom times, you can bet that the opportunities and the malfeasance will be higher and that the investigations won't gear up until well after the peak. Even if the situation has equalized and the market place is doing all the right things to adjust, you still need to put a light on those who are prone to bad behavior.

Operational Risk is all about internal and external fraud mitigation. The tools, cues and clues that an OPS Risk professional utilizes are all after the truth and for the future good of all impacted by these serious loss events.

Fraud

A risk difficult to model is fraud. Booms tend to induce fraud, misrepresentation and scandals. To quote Bagehot again:

"The good times of too high price almost always engender much fraud."

Or the great economic historian, Charles Kindleberger:

"The propensity to swindle grows parallel with the propensity to speculate during a boom. The implosion of an asset price bubble always leads to the discovery of fraud and swindles."

And now the search begins for evidence. The evaluation of the Document Retention Policy (DRP) at Beazer Homes will no doubt be a subject of discussion today and for weeks to come. If they are like most prudent organizations who have completed their DRP and have employees educated on day one of their employment, it should be crystal clear:

Here is some sample language from a standard DRP:
Our records include virtually all of the records you produce as an ABC Corporation employee. Such records can be in electronic or paper form. Thus, items that you may not consider important, such as interoffice emails, desktop calendars and printed memoranda are records that are considered important under this policy. If you are ever uncertain as to any procedures set forth in this policy (e.g., what records to retain or destroy, when to do so, or how) it is your responsibility to seek answers from ABC Corporation’s DRP Manager.

The goals of this DRP are to:

  • Retain important documents for reference and future use;
  • Delete documents that are no longer necessary for the proper functioning of ABC Corporation;
  • Organize important documents for efficient retrieval; and
  • Ensure that you, as an ABC Corporation employee, know what documents should be retained, the length of their retention, means of storage, and when and how they should be destroyed.
Yes, a policy about destruction of documents. This is where many organizations fail to mitigate the risk of data theft or even eDiscovery of data that could become relevant in a future investigation. However, these days, everybody is saving everything and for what looks like could be a very long time.

"If a lawsuit is filed or imminent, or a legal document request has been made upon ABC Corporation, ALL RECORD DESTRUCTION MUST CEASE IMMEDIATELY.

"ABC Corporation’s DRP Manager may suspend this DRP to require that documents relating to the lawsuit or potential legal issue(s) be retained and organized. A critical understanding of this section is imperative. Should you fail to follow this protocol, you and/or ABC Corporation may be subject to fines and penalties, among other sanctions."

The phone has just got to be ringing off the hook over at Stratify!

Sunday, February 18, 2007

Economic Intelligence: Wake-up Call...

Chris Cooper plays a traitor in the movie based on the true story of Robert Hanssen. "Breach" is a wake up call for the United States to continue its counterintelligence initiatives with vigor. However, this story is written not from the perspective of Hanssen, but that of another FBI employee who assisted in his capture and prosecution.

Based on the true story, FBI upstart Eric O'Neill enters into an operational risk power game with his boss, Robert Hanssen, an agent who was ultimately convicted of selling secrets to the Soviet Union. Eric now lives in Washington, DC and is an attorney, he never became an FBI agent. His role played by Ryan Phillippe, shows the audience how even Eric was skeptical that someone like Hanssen could be a traitor.

Critical to the agency’s ability to arrest and convict Hanssen was the placement of 26-year-old special surveillance operative Eric O’Neill in Hanssen’s office. Working directly under Hanssen, O’Neill was able to provide the team of investigators with information needed to take down one of the worst spies in the history of the United States.

Shortly after being intimately involved in the Hanssen investigation, O’Neill left the FBI to study law. O’Neill also took time to work on a book based on his experiences, which ultimately led to Breach, a film about his involvement in the Hanssen case.

Counterintelligence is the number 2 priority behind Counterterrorism at the FBI.

The Cold War is not over, it has merely moved into a new arena: the global marketplace. The FBI estimates that every year billions of U.S. dollars are lost to foreign competitors who deliberately target economic intelligence in flourishing U.S. industries and technologies, and who cull intelligence out of shelved technologies by exploiting open source and classified information known as trade secrets. Foreign competitors who criminally seek economic intelligence generally operate in three ways to create their spy networks:

1. They aggressively target and recruit susceptible people (often from the same national background) working for U.S. companies and research institutions;

2. They recruit people to locate economic intelligence through operations like bribery, discreet theft, dumpster diving (in search of discarded trade secrets), and wiretapping; and,

3. They establish seemingly innocent business relationships between foreign companies and U.S. industries to gather economic intelligence including classified information.

In an effort to safeguard our nation's economic secrets, the Economic Espionage Act (EEA) was signed into law on October 11, 1996.

How to Protect Your Business from Espionage: 6 steps
1. Recognize there is a real threat.
2. Identify and valuate trade secrets.
3. Implement a definable plan for safeguarding trade secrets.
4. Secure physical trade secrets and limit access to trade secrets.
5. Confine intellectual knowledge.
6. Provide ongoing security training to employees.

Thursday, February 01, 2007

Future Jihad: Financing Systemic Ideology...

One only has to listen to a few stories from experts in Counterterrorism to realize that vigilance is still the mantra. Yesterday the facts and observations from Walid Phares made us ever so more aware and even more focused on the mission. Funding of the war of ideas.

His point is clear that the funding of education and systemic transfer of ideology across the globe is why we are still so vulnerable. "The class room. The news room. To the War room."
For the United States, winning the War on Terror depends on two battlefields. The first is overseas, where Washington must confront jihadi forces and help allies to win their own struggles with terrorism. This will require the United States to support democratic change abroad, both as a counterweight to jihadist lobbies and as a means of assisting Arab and Muslim democrats to win the conflict within their own societies.

The second, however, is closer to home. Homeland security planners must be thinking seriously about a duo of unsettling questions. First, are jihadists already in possession of unconventional weapons on American soil, and how can the U.S. government deter them? This crucial issue tops all other challenges, for a terrorist nuclear strike on the U.S. has the potential to transform international relations as we know them. Second, how deeply have jihadist elements infiltrated the U.S. government and federal agencies, including the Federal Bureau of Investigation, the Department of Homeland Security, the Department of Defense, and various military commands, either through sympathizers or via actual operatives?

In a recent Economist Intelligence Unit survey on Operational Risk Management the question is asked:

Which of the following types of threats receive the most attention in your organisation's consideration of Operational Risk?

  • 42% - Loss of Data
  • 36% - Systems Failure
  • 28% - Supply Chain Disruption
  • 27% - Worm or Other Malicious code attack
Unplanned downtime of systems was tied with malicious code, next was human error at 26%, human malfeasance such as theft or fraud at 20% followed by a tie for:
  • 15% - Terrorism
  • 15% - Application Failure
Why is terrorism tied for 8th on this list? Maybe it is because institutions have more confidence in our Homeland Security and the FBI than they do in their own IT department. Or could it be the frequency of the threat that puts these items so high or low on the list of concerns. One thing is certain, the financing of "Future Jihad" is not going away.

In fact, the funding mechanisms are morphing and adapting as new Anti-Money Laundering initiatives and Regulator oversight creates even more difficult avenues for terrorist financing to occur. The private sector still remains the Deputy Sheriff as new transactions take place outside the traditional banking controls of Citi, B of A and HSBC. Hedge funds, insurance companies and other broker / dealers still provide the weak link in the chain for tracking the movement of zeros and ones across a global financial grid.

This multi-dimensional problem is not something to ignore. When you really think about Terrorism, what is your definition? What is a terrorist?

The day will come when you finally realize that a terrorist is and could be increasingly responsible for the top 4 items on the EIU list. It's all a matter of your own worldview.