Showing posts with label ORM. Show all posts
Showing posts with label ORM. Show all posts

Sunday, July 26, 2026

Trust Decisions: Future Risk Architecture...

Leadership within the enterprise requires "Trust Decisions" that they can count on.  Operational Risk Officers have a fiduciary duty to provide top executives with the confidence that the data and information they provide is trusted.

So how do you assist any corporate leader, who has the responsibility and accountability to the Board of Directors to make informed and sound decisions?  The answer is, that it depends on how willing the CxO's in the enterprise are to engineer a "Trust Decision" model and framework for the business.

The truth is, most executive managers have their own way of doing this.  The process that the CEO makes decisions, is quite different from how the CFO makes decisions and the COO may have a documented and tested way to make their decisions.  The point is, that major "Trust Decisions" for the good and welfare of the enterprise are being made by people who are each doing it differently.  These human decision makers are relying on a number of ways to get to the final answer.  The decisions from leadership are not as trusted and reliable as they could be.

As an Operational Risk executive charged with making timely and correct decisions you have no choice but to have the tools and the trusted sources to enhance your situational awareness.  The safety and security of the facility, information or peoples lives are at stake.  That is why you test and continually improve the process so your analytics dashboard, intelligence feeds and data sensors are all operating with integrity and in real-time.

You are relying on information that changes by the nanosecond and a system designed to provide decision support.  Intelligence-led investigations or reacting to the latest incident requires systems designed and tested to support human "Trust Decisions."  Now back to the executive leadership and their process for decision-making.  What is it?  How does the CEO make the final decisions for the future wealth of the company and it's stakeholders?  Are they trustworthy?

Unless you have seen the "Trust Decision" process and trusted data framework engineered for your enterprise, then probably not.  Think about all of the leadership level projects and how they turned out.  How did executive leadership decide to buy that other company or merge with their favorite supplier?  What process did they use to ensure all of the due diligence data was correct?  Why are the sources of data trusted?

We have the opportunity to improve and to arrive at a point where we make "Trust Decisions" our priority and a prerequisite.  After all, our employees, customers, shareholders and even mankind deserve it.  The challenge begins.

Whenever you encounter your next major business decision with your CxO, ask them how they arrived at the decision.  Ask them to explain the process they used and the sources of trusted data they relied on.  Ask them why they think the architecture of the decision at hand, is the most sound and trusted decision that can be made with the time available.

You are now well on your way to better understanding the power and the future risk architecture of TrustDecisions.

Saturday, July 29, 2017

OPS Risk: Choosing Service Over Self-Interest...

Accountability and ownership are two vital elements of any operational risk professionals mindset, if they are to accomplish real results.  In order to gain this mindset as a professional, you have to be able to work along side others, who have these ingrained into their character and DNA.

What are you accountable for in your team or organization?  You are accountable for the stewardship of your particular mission at this point in time with a clear vision of the results that are envisioned.

You are not accountable to anyone but yourself and the team you have assembled for this particular set of tasks and outcomes.  The Operational Risks that you will encounter and those that you decide to mitigate or avoid are entirely up to you and your team, long before you set out to accomplish the mission.

Do you have ownership of the results desired?  You must have ownership of the operational risks that may and will occur if you and your team are to survive whatever known and unknown challenges may come your way.  Who are some of the best of the best in the profession of Operational Risk Management (ORM) over the past few decades?

Neil Armstrong and Buzz Aldrin are just two:
Of course, it was less than a year later that Armstrong himself would make the biggest step. After a three day trip to the moon, Armstrong, Aldrin and Collins entered lunar orbit on July 19. On July 20, Armstrong and Aldrin began their descent towards the surface inside Eagle, the lunar landing module. The flight to the surface did not quite go as planned. During the descent several alarms from the flight guidance computer distracted the astronauts. The onboard computers were inundated with extraneous radar information, but the alarms were determined not to be a problem. 
But Armstrong also noticed he and Aldrin were flying faster than expected across the lunar surface and were likely going to overshoot their landing site. As the Eagle passed 1,500 feet above the surface, Armstrong saw they were heading for a crater. He thought this might be a good option as it would have “more scientific value to be close to a large crater.” But the steep slope and big rocks did not provide a safe place to land. 
As they continued to fly over areas covered with large rocks and boulders, Armstrong took over control of the Eagle and continued flying it manually. He was able to use his training from the LLTV to maneuver as they continued to descend to the surface. But all of the maneuvering was using up propellant. At 200 feet above the surface, Armstrong finally was able to find a place to land. 
Aldrin: Eleven [feet per second] forward. Coming down nicely. Two hundred feet, four and a half down.
Armstrong: Gonna be right over that crater.
Aldrin: Five and a half down.
Armstrong: I got a good spot.
Aldrin: One hundred and sixty feet, six and a half down. Five and a half down, nine forward. You’re looking good. 
As they passed 75 feet mission control in Houston determined the Eagle only had 60 seconds of fuel left. Armstrong says he wasn’t terribly concerned about the low fuel situation, “typically in the LLTV it wasn’t unusual to land with 15 seconds left of fuel.”
About 40 seconds later Armstrong made a final few maneuvers before announcing the landing was complete. 
Armstrong: Shutdown.
Aldrin: Okay. Engine stop.
Houston: We copy you down, Eagle.
Armstrong: Houston, Tranquility Base here. The Eagle has landed.
Think about your team.  Is the boss dictating from the top on your every move or are they side-by-side with equal accountability and ownership of the results of the mission.  NASA puts rock star top gun pilots behind the controls of lunar missions for a good reason.  It is because they know that they are not in control, ultimately the pilots are working together.

So if you find that in your next corporate or organizational project that the boss from afar is telling you what to do at every moment, it's time to eject.  A true Operational Risk professional understands the mission and the desired results.

They have accountability and ownership of the tasks necessary to achieve the results.  Their stewardship of the project, with their fellow team members will be able to adapt to any changing environment or sudden challenges.

If you are the boss that has responsibility for the team and the successful outcome of the mission, what have you done to enhance each of their skills, knowledge and experience to deal with operational risks?    You may be asking at this point "How" do I do this?  This isn't about giving you suggestions or to show you where it is working and how to do it.

This is about service before self-interest and your ability to think of yourself as an equal on the team. Just one more vital asset with the same sense of accountability and ownership for the overall mission. That's it.

Your team needs you as one more set of brains, hands and talents to solve the operational risks that will be on their way.  How you behave and perform in light of these new found challenges, may very well be the one thing that determines whether your team lives, or survives.
To serve. To be safe. To know what freedom feels like.
Author, Peter Block - Stewardship - Choosing Service Over Self-Interest
Neil Armstrong was a true Operational Risk Professional...God speed.

Saturday, May 06, 2017

Quiet Professional: A Leader Remembered...

Leadership has been written about since humans have been writing and recording history.  How leaders have been described, documented and chronicled over our existence here on Earth, comes back to the definition of leadership:  noun, the act or instance of leading - the office or position of a leader.

The leader and the characteristics of a particular person, are typically what is written about to document someone who is in a position of leadership.  It may start as an oldest sibling, leading younger sisters or brothers when Mother or Father is not around, or even deceased.

It may have all started in a school or church group, or as camp counselor, President of that social group, and then someday even also as a Mother or Father.  Leaders and leadership have so many facets and is in many cases just present, or absent in someone's life.

Over history, the definition of a person who has been or is a current leader, has several synonyms:

Synonyms boss man, captain, chief, foreman, head, headman, helmsman, honcho, jefe, kingpin, boss, master, taskmaster

In the broad and complex world we live in, these synonyms only describe a small facet of what true leadership is all about.  The vast realm of Operational Risk Management (ORM) also gives us additional context, when it comes to true leadership and the goal of ever increasing our overall safety, security and trust.

When someone writes your eulogy as an Operational Risk Leader, what will they say.  How will they describe you?  Perhaps none of the synonyms above are even mentioned.  Why?

It is because you are known as a "Quiet Professional."  Someone who is a leader and continues to exemplify the act of leading in so many ways and far too detailed to describe in words.  Yet you continue to aspire to improve, to listen, to learn.  You don't know it yet, but at your eulogy, others will describe you as a "Quiet Professional."

The "Quiet Professional" operates through life serving others, doing their best to continuously learn and improve on their greatest skills.  Yet at the same time, the true leader also recognizes the areas of knowledge and expertise they don't possess and so they will create alliances with others who do.

The small group, the team, the cohort, the class, the board, the executive office, the assembly, the country - they have a combination of leaders who are diverse in their skills, knowledge and aspirations and yet simultaneously, they have the same single mission.

How others will describe you and your leadership at your eulogy, is completely in your control as a human.  What are the characteristics of your particular way of leading and operating as a "Quiet Professional (QP)?"  Maybe it will sound like this:

QP was a person that not many people knew very well and that was just fine with them.  QP worked on becoming and performing each day, as the best they could be, with each person they encountered in life, one-to-one.  As a brother or sister, as a mother or father, as a friend and servant leader of others.

QP was always watching out for others.  Looking around the corner or over the horizon.  It was for three reasons.  Curiosity, building trust and continuous learning.  It was because QP always wanted to improve and to aspire for that next level of perfection.  QP wanted others close to them to feel safe and secure.

QP wanted others to feel as if they could do anything and could achieve anything.  What ever their particular mission was that day, month or year.  QP wanted those closest to them to know, they were always going to be cared for and looked after,  no matter what happened.

QP will always be remembered for their kind heart and tremendous courage.  QP will be remembered for their fierce competitiveness and simultaneous compassion.  They will be remembered for their ability to love.  Their ability to forgive.  And QP will always be remembered for their leadership.

Are you a "Quiet Professional"?...

Sunday, September 25, 2016

ORM: "All Threats & All Hazards"...

If you are new to the discipline of Operational Risk Management (ORM) your entry point in it's vast spectrum is a vital realization. The business problem that you are trying to solve with the utilization of an effective set of protocols, policy and risk management framework, may take years to accomplish. Do you have that much time?

Operational Risk Management 101 requires an "All Threats & All Hazards" point of view from day one. It also requires a protocol that your whole organization can understand, implement and put to work on a daily basis. Whether you are in banking, drilling for oil, flying an AV-8B out of hostile conditions or preparing for hundreds of people for a "State Dinner" on the South lawn; Operational Risk Management is the versatile discipline that will enhance your safety and security.

Practitioners of ORM know, that the next threat or the unexpected hazard is almost impossible to defend against. Once you realize that you are always in "degrees of vulnerability" your mindset changes about where to spend your activity, effort and resources to maximize your returns. Did anyone see the process of turning sub-prime mortgage portfolios into securities and selling them to investors on wall street, as a future threat to our economic prosperity? Yes. The same people bought instruments to hedge this risk in the form of "Credit Default Swaps" (CDS):
Credit default swaps are often used to manage the credit risk (i.e., the risk of default) which arises from holding debt. Typically, the holder of, for example, a corporate bond may hedge their exposure by entering into a CDS contract as the buyer of protection. If the bond goes into default, the proceeds from the CDS contract will cancel out the losses on the underlying bond.
Prudent Operational Risk practitioners look at the threat and invent the correct tool, product, or countermeasure to hedge the risk. It happens on Wall Street and it happens on the urban battlefields of cities across America. A US Justice Department researcher, Lester Shubin utilized a DuPont fabric intended for tires and developed the Kevlar bulletproof vest. This inventor passed away about seven years ago and is credited with helping to save the lives of over 3,000 law enforcement officers. A heart attack took the life of a man who understood the core value of "Operational Risk Management." Godspeed Lester.

Shubin and his advocates had many obstacles to overcome in order for their idea, invention and risk management habit to succeed. First there was testing, then the legal hurdles to get companies to manufacture vests because of liability and then finally getting street cops to use them. This practitioner of Operational Risk did not stop there. He was also one of the first to suggest the use of canines to find explosives.

If you enter the ORM discipline from a safety orientation the perspective may be different than one who enters it from a security orientation. What they both have in common is managing risk. The most effective 21st century experts in Operational Risk Management realize that an "All Threats & All Hazards" mindset is crucial to the entire profession. So how do you know where to invest your activity, effort and resources? That depends on your industry sector, the environment you are operating in and the pace of the processes being performed.

Being an effective Operational Risk expert today requires a multi-faceted, mosaic-based, pervasive protocol in order to be adaptive. Working and operating in the trading pit at the Chicago Mercantile Exchange (CME) or the deck of CVN-77 in the middle of the Arabian Sea both require the same set of skills, knowledge and training. If done effectively, it will save lives and millions of dollars simultaneously.

Saturday, December 19, 2015

Cyber Domain: International Law of Asymmetric Warfare...

The international laws and human understanding of what crosses a "Red Line" are being defined in cyberspace in real-time.  The operations of the Chief Security Officer (CSO) and Chief Information Security Officer (CISO) are now becoming more adaptive.  The Operational Risk Management (ORM) enterprise architecture, will soon call for three standard mission functions:
  • Computer Network Attack (CNA): Includes actions taken via computer networks to disrupt, deny, degrade, or destroy the information within computers and computer networks and/or the computers/networks themselves.
  • Computer Network Defense (CND): Includes actions taken via computer networks to protect, monitor, analyze, detect, and respond to network attacks, intrusions, disruptions, or other unauthorized actions that would compromise or cripple defense information systems and networks.
  • Computer Network Exploitation (CNE): Includes enabling actions and intelligence collection via computer networks that exploit data gathered from target or enemy information systems or networks.
 Computer Network Defense (CND) has been the norm for many organizations and now, that is no longer enough.  Yet before we can determine why we must  add CNA and CNE, we better understand the breadth and depth of the cyber realm.  The "Over-the-Horizon" view, of the reality of that domain, is rapidly developing into a proactive risk management imperative, for Global 500 organizations.  Why?

The non-state actors are organizing and evolving into what could be coined for the laymen, as a modern day "Cyber al-Qaida."  A "Cyber  Taliban."  Or even a "Cyber 1st Amendment or 4th Amendment cadre of affiliated entities.  These digital non-state actors following a set of ideologies, as opposed to a set of true investigative journalists or independent non-partisan watch dogs, are metastasizing at an exponential rate.

This ideology fueled by cyber activism and directed at a particular organization or country, is on a digital battlefield that spans the globe.  It has long been said that the Internet is nothing more than a mirror, of the good and evil in our physical world.  The existence of cyber warriors who are interested in going beyond the goal of financial crimes to kinetic destruction of critical infrastructure, is a well known fact.

Who are these cyber warriors that identify with a movement or cause, that attack the well being of other humans or destroys the property or economic assets of another organization.  They are the same ideologues that have existed long before the Internet.  The difference is that the reach, speed and ubiquitous nature of the digital medium accelerates the threat and the requirement for an effective counter balance.  Putting actual skill sets aside for a moment, the real differentiator has been on a "White Hat" or ethical warrior focus:
Regarding whether there were different rules of armed conflict for cyberwarfare in dealing with states like Iran, versus terror entities like Hamas or al­-Qaida, he first noted that while there is “no consensus,” the “US, Israel, England and others” argue that “self ­defense” principles justify attacks against terror groups, even if they are not states.  --IDF Col. Sharon Afek-- Article by Yonah Jeremy Bob
The CNA, CND and CNE operations in the digital Global 500, will now employ those individuals who have an ideology that is more directly opposed to the worldview of a "Cyber al-Qaida."  In the long war, the cyber "White Hats" will endure.  The asymmetric warfare of the next decade, will encompass operational risk professionals behind the network, who have a different context.  Why? Because they believe in a ideology far more patriotic than their predecessors.  They are the "Quiet Professionals" who have retired from SOCOM active duty and now span the ranks of the corporate private sector.

The international laws of the cyber domain are in play for our prosperity or our peril.

Sunday, January 25, 2015

Insider Threat: Trusted Systems of the Future...

In the Defense Industrial Base in particular, corporate executives are on edge these days, anticipating the next game changing crisis phone call from the General Counsel.  The conversation is one that every CxO expects to have at some point in their career, yet the pace of multi-million dollar incidents is rapidly increasing.  The origin typically begins somewhere within the Operational Risk Management (ORM) landscape including People, Processes, Systems or External events.

 INTRODUCTION

The Board of Directors are evaluating the current funding levels for Operational Risk Management programs.  The focus on "Insider Threat" is a renewed area of scrutiny in light of the number of intellectual property thefts and national security classified information leaks.  This means increased funding potential for programs of Defensive Counterintelligence.  Next we shall look at the strategic challenges involving Homeland SecurityDomestic Intelligence and Technological Innovation.

STRATEGIC CHALLENGES

You may have heard that Corporate Security and Operational Risk Officers are consistently using the acronym M.I.C.E. to describe the motivations for rogue insider employees. Money, Ideology, Compromise and Ego are the main categories that human behavior can be associated with, when the realization that an incident has occurred.

The "Why" question is asked early on by the General Counsel and the Chief Risk Officer (CRO), to try and understand the motivation by the employee.

One challenge is the current ecosystem of Homeland Security in the United States. Consistently oriented on the protection of catastrophic threats to the homeland in general and not to an individual company, much of the Homeland Security Intelligence (HSI mechanism is myopic and not predictive. The laws associated with U.S. persons and the current state of employee protections is a white paper in itself. However, the scrutiny of laws associated with the theft of intellectual property and corporate trade secrets is gaining momentum.

The challenges of "Domestic Intelligence" and the intersection of "Technological Innovation" is now on a collision course in the courts.  Previous legal decisions such as United States v. Jones, 132 S. Ct. 945, 565 U.S. ___ (2012) was a Supreme Court Case that sets an example.  As interpretations of the constitutional rights of U.S. citizens are decided where the legal evidence of metadata is collected from technology innovations and is deemed to violate those rights, the challenges for domestic intelligence applications become more apparent.  This includes law enforcement and internal corporate security programs within the private sector enterprises.

CORPORATE CULTURE ISSUES

There are three competing perspectives within the enterprise organization that present a continuous cultural tug-of-war:
  • Human Resources
  • Privacy & Legal Governance
  • Security & Risk Management
In a recent break out session of a private industry focused "Information Sharing Initiative" workshop, the comments were heard by all of us present.  A Chief Security Officer in the room came right out and admitted that his team does everything they can to avoid interaction with personnel from the Human Resources department.  This "Elephant-in-the-Room" topic is one that most corporate officers need to get out on the table.  The cultural friction between a Human Resources department tasked with protecting the privacy and integrity of the employees personal data, typically clashes with those charged with securing the assets of the organization.

Even though the U.S. does not have anything close to the EU Data Protection Directive, the legal precedents are being played out in the courts.  In the U.S., workplace privacy is a rapidly evolving spectrum of technology, metadata and big data analytics:
Employees typically must relinquish some of their privacy while at the workplace, but how much they must do so can be a contentious issue. The debate rages on as to whether it is moral, ethical and legal for employers to monitor the actions of their employees. Employers believe that monitoring is necessary both to discourage illicit activity and to limit liability. Although, with this problem of monitoring of employees, many are experiencing a negative effect on emotional and physical stress including fatigue and lack of motivation within the workplace.
RECOMMENDATIONS

The "Insider Threat" and Defensive Counterintelligence strategies are up against the employee privacy and data governance legal battles in the U.S..  However, there is a a way forward to design the future architecture for this particular Operational Risk Management domain, beyond more legally detailed "Acceptable Use Agreements".

Just as any agreement on standards or rules takes a process and a dedicated architecture, so will this arena of human behavior, technology innovations and vital digital information assets.  Effective and transparent "Trust Decisions" that become embedded in the architecture to enable application of the agreed upon rulesets, is the ultimate goal.  Once humans have the confidence in a mechanism for making these Trust Decisions consistently and with integrity, the presence of prudent risk management will then be realized.

The private sector will lead this effort in collaboration with government, yet it will design it's own protocols and rulesets to plug-in to new federal standards.  The application of continuous monitoring of threats within the private sector workplace will evolve quickly by using these new frameworks and new tools.  Trust Decisions will be made in milliseconds, as systems execute the rules that have been coded into software and the latest big data analytics logic.

We recommend that the private sector continue to establish a consortium of cross-sector companies to interface with the new ISE.gov framework entitled "The Data Aggregation Reference Architecture."
The need for greater interoperability is clear. To protect national interests, intelligence and law enforcement agencies must be able to collect, accurately aggregate, and share real-time analytical information about people, places, and events in a manner that also protects privacy, civil rights, and civil liberties. The President’s National Strategy for Information Sharing and Safeguarding (NSISS) recognizes this as a priority national security issue, and speaks directly to this challenge. The Data Aggregation Reference Architecture (DARA) is in direct response to NSISS Priority Objective 10, “Develop a reference architecture to support a consistent approach to data discovery and entity resolution and data correlation across disparate datasets,” The DARA provides a reference architecture that can enable rapid information sharing, particularly for
correlated data, but also for raw data, by providing a framework for interoperability between systems, applications and organizations.
These private sector companies need to standardize across sectors, just as the government is embarking on the mission to improve this across agencies.  You see, the blind spots that the government has discovered in sharing information across it's own departments and agencies is no different in private industry.  The failure of Energy companies sharing information with other Energy companies or the same within the Financial Services industry ISAC model is not new.  However, the speed and integrity of future "Trust Decisions" on Insider Threats will always depend on the timeliness and quality of the data.

The international agreements on ISO standards has a long history.  Quality and Environmental standards are most common.  The 21st century has delivered us privacy and information security "management system" standards established and agreed upon internationally.  The standards and rulesets integrated with government shall have interoperability with the private sector.  The private sector shall collaborate with government on the architecture for information sharing.  The future state outcomes will enhance our trust in the management systems that have been designed from the ground up, to execute the rules.  A good example from ISO follows:
Cloud computing is quite possibly the hottest, most discussed and often misunderstood topic in IT today. This revolutionary concept has reached unexpected heights in the last decade and is recognized by governments and private-sector organizations as major game-changing technology.

In the January/February 2015 ISOfocus issue, we address some of the basic questions surrounding cloud computing (including the savings and business utility the technology can offer). We also explore security concerns of the cloud services industry and how these are addressed by ISO/IEC 27018, the first International Standard on safeguarding personal data in the cloud.
CONCLUSION

 The future of the "Insider Threat" solutions will not be designed by just one company or one government.  Just as the Internet standards that have evolved to support billions of IP addressable devices using data science and machine learning, so too will the private sector discover the way forward on transparency and data governance.  What are the odds that an "Insider Actor" hired at company "A" may then move to Company "B" once and if they determine the controls and processes are too difficult or will catch them in their unauthorized activities?

The safety, security and privacy of our organizations in concert with an international community is imperative.  People must believe in the integrity of the "Trust Decisions" being made each second by the Internet devices they hold in their hands and simultaneously by the organizations they devote their working lives to each day.

Sunday, November 09, 2014

Veterans Day 2014: Leading the Enterprise to Victory...

The 1% are soon to be recognized on Tuesday, November 11, Veterans Day.  CxO's across the country who have served in the military know all about "Operational Risk Management" (ORM). They understand that the safety and security of their personnel is paramount, if they are to achieve the mission assigned to them by the Board of Directors and the majority stakeholders.

It makes sense that if only 1% of the country serve in the military, and fewer make it to the rank of CxO in commercial industry, why ORM remains so esoteric.  Only an enlightened few truly understand the value of investing in continuous training, cultural and ethical development and the safety and security of not only employees, but also intellectual capital and information assets.

Indeed, this Veterans Day is a time to focus on our 1%.  Those who have served the United States of America in the Armed Forces.  At the top of each of these branches including the Army, Marine Corps, Navy, Air Force and Coast Guard are people that have seen, smelled, heard, felt and lived with the logic and the necessity for Operational Risk Management.  Why is the Navy leadership focused on ORM?
ORM is the guiding Navy instruction for implementing the ORM program. The naval vision is to develop an environment in which every individual (officer, enlisted and civilian) is trained and motivated to personally manage risk in everything they do on and off duty, both in peacetime and during conflict, thus enabling successful completion of all operations or activities with the minimum amount of risk. 
The most common idea of what ORM revolves around is a simple five-step process that is most frequently used in planning. These five steps are:
  • Identify hazards
  • Assess the hazards
  • Make risk decisions
  • Implement controls
  • Supervise and watch for change
Another level of ORM is Time Critical Risk Management which involves a quick, committed-to-memory process and a set of skills that allow our people to manage risk when in the execution of a plan or event. The standard for the Navy is being developed, however it might be thought of in simple terms such as:
  • What can go wrong or is changing
  • How can I keep it from effecting the mission without hurting me
  • Act to correct the situation
  • Telling the right people if you are unable to take the right action
If you were retired from the Marine Corps and now the CxO of a Global 500 company, do you think that ORM would be a forgotten system?  Would you neglect to focus on this, if you were running FedEx?  Fred Smith is not a former pilot, but was vital as a "Forward Air Controller":

Frederick Wallace "Fred" Smith (born August 11, 1944), is the founder, chairman, president, and CEO of FedEx, originally known as Federal Express, the first overnight express delivery company in the world, and the largest in the world. The company is headquartered in Memphis, Tennessee. 
Smith was commissioned in the U.S. Marine Corps, serving for three years (from 1966 to 1969) as a platoon leader and a forward air controller (FAC), flying in the back seat of the OV-10
As a Marine, Smith had the opportunity to observe the military's logistics system first hand. He served two tours of duty in Vietnam, flying with pilots on over 200 combat missions. He was honorably discharged in 1969 with the rank of Captain, having received the Silver Star, the Bronze Star, and two Purple Hearts. While in the military, Smith carefully observed the procurement and delivery procedures, fine-tuning his dream for an overnight delivery service.[5] 
A primary function of a Forward Air Controller is ensuring the safety of friendly troops. Enemy targets in the Front line ("Forward Edge of the Battle Area" in US terminology) are often close to friendly forces and therefore friendly forces are at risk of friendly fire through proximity during air attack. The danger is twofold: the bombing pilot cannot identify the target clearly, and is not aware of the locations of friendly forces.
Fred Smith not only implemented the mindset of a "Forward Air Controller" running FedEx, he also has been able to build a culture focused on Operational Risk Management (ORM).
FedEx Corporation will produce superior financial returns for its shareowners by providing high value-added logistics, transportation and related business services through focused operating companies. Customer requirements will be met in the highest quality manner appropriate to each market segment served. FedEx will strive to develop mutually rewarding relationships with its employees, partners and suppliers. Safety will be the first consideration in all operations. Corporate activities will be conducted to the highest ethical and professional standards.
Now back to Veterans Day, November 11.  Are you starting to make the connection between the 1%, becoming a global CxO and the reason why ORM has such tremendous applications inside the global enterprise?

The opportunity now is for us to unleash our emerging and proactive "Vetrepreneurs," to take their years of knowledge and understanding of ORM and now apply it within the ranks of their new companies or new positions, just as Fred Smith has done at FedEx.  These veterans have the practical knowledge, skills and valuable use cases on how Operational Risk Management contributes to the overall mission.

If you are a 1% entrepreneur (Vetrepreneur) and have Co-founder or CxO as your title, then your proactive nature should allow you the opportunity to apply ORM within your organization.  Here are three places you can begin your program focus:
Inside:  Develop a culture of trust that begins by teaching employees how to find the truth.  A culture that promotes and teaches people how to apply the rules to the business that you are operating in.  A culture where no one can hide and that understanding our own vulnerabilities makes the overall organization more resilient each day.
Outside:  Architect the enterprise from the ground up to make more informed "Trust Decisions."  The architecture must first assemble and organize the rule-base and contextual framework associated with the environment that you will be operating in both physically and virtually.  The interdependencies of the automated machines developed to operate the enterprise, shall exist in a transparent and highly governed "system-of- systems". 
In-The-Middle:  Create new learning scenarios on a consistent but random basis.  Test the enterprise Inside and Outside with these exercise scenarios.  Determine how the humans and/or machines behave.  Establish what is normal and create your baseline. Continue to test and to measure the gaps of performance and make changes to improve the quality, accuracy or resiliency of the entire enterprise architecture.
On this Veterans Day 2014, scan the horizon for the organizations that stand out and are remarkable. With the 1% at the helm, in the cockpit or now the HQ Board Room, Operational Risk Management (ORM) is leading the enterprise to victory!

Sunday, July 13, 2014

ID Analytics: Risk of the Unknown...

Operational Risk Management (ORM) has been at the top of the news in the past few weeks.  Digital media and the metadata of "Big Data" is the topic of choice.  It is a revealing look behind the curtain of what is possible these days, with the tools and capabilities that exist for exploitation and analysis.  Is too much privacy an operational risk to your personal and professional well being?  What "Trust Decisions" did you make to arrive on this page in the universe of the Internet?

In the spirit of full disclosure, if you are reading this now, we tracked how you found this blog and perhaps what search terms you used to be referred here.  Some of you, revealed their company identity. So why do we do this?  The main reason is that we want to make sure that we understand what is on your mind these days, when it comes to the global Operational Risk Management (ORM) universe. Here are a few examples in the past day or so that caught our eye:
  • management of operational risk - Latvia
  • operational risk management - Nigeria, Illinois, South Dakota, The Vanguard Group
  • common board of directors mistakes - Turkey
  • lessons learning from fail in operational risk - Malaysia
  • predictive intelligence - North America
  • rogue trader operational risk - United Kingdom
  • fund industry operation management discussion topic - Luxembourg
  • operational risk management game - Unknown
  • reputation risk management process - Unknown
  • operational risks in bank call center - Qatar
  • coso definition of operational risk - Unknown
  • black swan incident that occurs once in a lifetime - Unknown
  • ubs operational risk case analysis - Unknown
  • business resiliency definition - JP Morgan Chase
  • "operational risk" outliers - France
  • a risk effect on a daily operation - DeVry
  • examples of smart objectives risk - United Kingdom
  • black swan incident\ - South Carolina
  • black swan incident - Computer Sciences Corporation
  • what is a black swan incident - South Carolina
  • duty of care board of directors - United Kingdom
Collection of data is one thing.  Relevance and sense-making is another.  Can you imagine some of the search terms that are tracked just by Google or Bing?

What about the companies that know us the best?  Those marketing and personal data sites that keep track of where you live, how much you spend on your credit cards and where, or even the name of your pets.  How often do you give them your phone number or e-mail address at the point-of-sale (POS) to get a discount at the local retailer, gas station or pharmacy?  Believe us when we say that there are hundreds of organizations that know more about you in the private sector than some government across the world.

The trail of "digital finger prints" you leave behind everyday are vast.  A snap shot of your face at the local ATM or a snap shot of your desktop when you login to the online banking web site.  In either case, these examples are just a few of the ways that your habits, locations, preferences and lifestyle are profiled each and every day.  Where did all of this begin?  Fraud Management.  Not Homeland Security.

As a citizen traveling across the country or a consumer, you willingly give up these digital bread crumbs of your journey through life.  Your goal now, is to make sure that you are not mistaken for someone else.  After all, you or your organization have developed a profile and a reputation that is being recorded and therefore, it could be a prudent strategy to make sure that you are not mixed up with another person or organization with the same name or brand identity.

How can you do this?  Operational Risk Management (ORM) is about monitoring yourself and your organization to make sure you understand your competition (good or bad) for the same personal or business identity space.  Do you have Biometric and DNA samples of all of your key executives?  If you don't, then the question is why not?  You may have considered this in light of some of the places that your executives are traveling.  Cities and countries across the globe with the risk of kidnapping, improvised explosive devices (IED) and other risks to their lives.

As we look into the crystal ball of our digital futures, we see the scenes from movies past that have already captured our own human imagination.  A world where everyone is known and you may even choose to "opt-in" to be tracked.  After all, you are unique.  You make your own choices in life.  The risks that you face may very well be greater, for those who choose a life to remain private, anonymous and even unknown.

Tuesday, January 05, 2010

Deja Vu: Operational Risk in Decade Past...

The WWW is dynamic and the operational risks you take while navigating it's vast depth and breadth is part of the process. Who or what should you trust? As an example, at this very moment when you search Google for Operational Risk Management it returns this blog as the number #1 top link. Perhaps that is how you arrived here at this blog on Operational Risk.

You trusted Google that when you clicked on the link that you would find relevant information on your desired topic. Or perhaps you navigated to this site devoted to Operational Risk Management because one of the almost 1,000 postings since 2003 covered your question, topic or issue. In both cases, the information returned may have relevancy but only after careful examination of the words, concepts, ideas and arguments do you make the decision on whether to "Bookmark" this site.

And for the many that have bookmarked us or added us as your RSS Feed then we know who you are. Our mutual quest for the relevancy of "Operational Risk Management" in the current world we live in will continue. With each new incident, accident, or breach our purpose is further defined and more extensively documented.

As we encounter 2010 and the next decade we promise to provide the content you require and the relevancy to your role in the profession. Let's go back in time for a minute and see if any of our previous posts over the past 7 years have a point today:

28 October 2003

More banks hit by email fraud


U.S. Issues Saudi Alert Saying Terrorists Targeting Airlines


24 February 2004


Greenspan: Curb Fannie, Freddie Growth


24 June 2005

Negative Stock Price Reaction to Announcements of Operational Loss Events...


31 December 2006

Remember His Name: The Long War Ahead...


24 May 2007

Hedge Funds: Crystal Ball on Regulation...


11 October 2007

Fear: The Elements of Prediction...


31 March 2008

Volatility: Enemy #1...


08 May 2008

Legal Ecosystem: Survival of the Fittest...


22 September 2008

Decision Advantage: OPS Risk Intel...


25 April 2009

Human Factors: Early-Warning System...


17 August 2009

Business Resilience: Beyond Readiness...


Are you having a deja vu moment? A flashback to the future. Why is it that "lessons learned" are continuously ignored? Forgotten. Lost. History and the knowledge of that history can save you. Some use log analysis of their precious computing resources, firewalls and IDS/IPS systems to learn from the past. Others don't remember that last time they fell down the stairs, slipped on the ice or banged their head. Even those individuals who have been on the other side of the desk when the "Boss" is making their position "Extremely Clear" about their performance measures are subject to having a deja vu moment.

Operational Risk is a daily and continuous 24x7x365 process. A way of life. Not an event or a meeting at the end of the quarter. Each person and stakeholder at your organization or institution is responsible for it and should live each day embracing it. We like to say, Operational Risk Management saves lives, protects corporate assets and enables global enterprise business resilience. That's something everyone can remember, practice and strive for every waking moment and in every situation.

What do you think?

Monday, March 31, 2008

Volatility: Enemy #1...

Organizations implement Operational Risk solutions to lower "volatility" in earnings growth and return on capital. The focus on volatility is because no institution likes to see peaks and valleys in their earnings or their return on capital. A steady and consistent growth curve without "Volatility" is the goal by many steadfast organizations.

Contrary to the goal of minimized "volatility" there are also those who feed off of the chaos and the large swings between these highs and lows in the marketplace and with specific companies in vital sectors of the financial economy. Will a Blueprint for Regulatory Reform be the answer?

As a hedge fund investor, can you explain what the strategy is for your investment fund? Do you know what your money is being invested in? Does your hedge fund manager provide transparency on calculating your return on funds invested? What was the reason you invested in alternative investments to begin with?

Carrying this analogy to the operational processes within your organization, the goal is to keep the processes running smoothly. When people or systems deviate from the agreed upon "Rule Sets" then change ensues along with the volatility of the performance measures. Errors, Omissions and systemic "glitches" are the catalysts to volatility that creates fear, uncertainty and doubt. Do you understand the Math? When the process gets to this stage and people don't trust the rules anymore, you are on the brink of a failure and impending loss, in dollars or peoples lives.

Operational Risk Management is a discipline that is emerging in corporate ranks because it has already proven that it saves lives. The regulators and inspector generals are going to demand it. The "Rule Sets" of playing business in the financial, health care and energy sectors are not the only ones being subjected to this increased scrutiny and renewed focus on OPS Risk. Now the Defense Industrial Base (DIB) and the Defense Department are under increased oversight at the highest echelons of the Pentagon as a result of a failure in Operational Risk Management.

Last week, the Department of Defense learned that four non- nuclear nose cone assemblies and their associated electrical components for a ballistic missile where mistakenly shipped to Taiwan in the fall of 2006. These items were originally shipped in March 2005 from F.E. Warren Air Force Base in Wyoming to the Defense Logistics Agency warehouse at Hill Air Force Base in Utah. There are no nuclear or fissile materials associated with these items.
Upon learning of the error, the U.S. government took immediate action to acquire positive control of the components and arranged for their safe and secure recovery to the United States. These items have now been safely returned to the United States.

Lessons learned are being discussed in the ranks of the U.S. Treasury Department and the Department of Defense all relating to the failure of people, processes, systems and or external events. Operational Risk is all around us and now ready for prime time focus in terms of strategy execution, implementation and measurement.

Whether you utilize Operational Risk Management (ORM) in the Defense Industrial Base or in the Financial Services sector it's important to revisit what it is NOT:

Operational Risk is Not:

  • About avoiding risk
  • A safety only program
  • Limited to complex-high risk evolutions
  • A program -- but a process
  • Only for on-duty
  • Just for your boss
  • Just a planning tool
  • Automatic
  • Static
  • Difficult
  • Someone else’s job
  • A well kept secret
  • A fail-safe process
  • A bunch of checklists
  • Just a bullet in a briefing guide
  • “TQL”
  • Going away

The goal of Risk Management is not to eliminate risk, but to manage risk so the mission can be accomplished with minimum impact. We manage risk to operate, not avoid risk as a means to prevent loss.


Tuesday, January 23, 2007

ORM: Automation Revolution...

The revolution has begun. There are many organizations out there evaluating the now more mature Operational Risk platforms for their institutions. Just as the dawn of Enterprise Resource Management (ERM) such as Peoplesoft, SAP and others; there will be a fight for maket share and end users will look to their trusted advisors for expert resources. How do you know what application is right for your organization?

The question remains, are you ready? Is your department and staff up to speed on what this means for the process changes necessary in your enterprise for an ORM application to succeed?

OpenPages ORM automates the process of identifying, measuring and monitoring operational risk, integrating all risk data – risk and control self assessments, loss events and key risk indicators – in a single solution. OpenPages ORM combines powerful document and process management with a monitoring and decision support system that enables organizations to analyze, manage and mitigate risk in a simple and efficient manner.

Risk self-assessment capabilities enable organizations to document and evaluate their risk frameworks, including processes, risks, events, key risk indicators and controls. Executive-level dashboard and reports provide visibility into key risk metrics and policy compliance, while business process automation capabilities provide for real-time event escalation; automated risk processes, such as loss event root-cause analysis; and, streamlined remediation of issues and action items.

With loss event tracking, risk managers can track loss incidents and near misses, recording amounts, determine root causes and ownership. OpenPages ORM provides statistical and trend analysis capabilities and enables end-users to track remedies and action plans. Key risk indicators provide capabilities for tracking risk metrics and thresholds, with automated notification when thresholds are breached. OpenPages ORM provides facilities for both manual and automatic data inputs from internal and external data sources.

With OpenPages ORM, organizations can embed operational risk management and governance into the corporate culture, making procedures more effective and efficient while providing management with peace-of-mind that the corporate brand is protected.

How do you make a decision on OpenPages, SunGard or SAS? Like the implemention of ERM platforms you end up with new challenges, both technical and human oriented. Making a choice requires at some point a consensus of the end user, the departments impacted by the decision and the costs of customization or configuration. The total project will also require:

  • Choosing the correct technology solutions with your specific business challenges.
  • Rapidly integrating new technology with the remainder of your IT infrastructure.
  • Effectively fine-tuning business processes to address your organization.
  • Continuously re-evaluating the deployment to ensure maximum ROI.
As with most large IT projects it's important to have Program Management Office (PMO) functions up and running prior to making a final purchase. And if you are a true Operational Risk Management professional, you have already performed your analysis of the threats and hazards to the successful implementation, training and launch of your new ORM system.