Showing posts with label basel III. Show all posts
Showing posts with label basel III. Show all posts

Saturday, March 18, 2023

Reliable: Who Do You Have Faith In?

When you think of the person you would recommend for a particular task or to perform defined professional services, who comes to mind?

There are many ways and words to describe a person or the business, yet if you had only one word to choose from, what would it be?

Reliable  adjective

1: suitable or fit to be relied on: DEPENDABLE

2: giving the same result on successive trials

Reliable noun

1: one that is reliable

In many cases, this is the word people really mean to use, as the basis for their recommendation.

Whether a business or a person is reliable, makes all the difference in your world, especially if you must rely on the outcomes of their service or duty.

When someone or something you pay for, does not meet a series of positive results, you begin to question your decision to utilize the service or receive the product for use.

Unfortunately for many people and businesses, this word “Reliable” is not considered or even measured on a consistent or measurable basis.

"Over the course of time in your life, think of one person or business you could say was truly reliable."

Think of this one person or business you have utilized for more than ten years that is reliable.

In any professional capacity, becoming reliable takes many years of practice and substantial learning. It requires the development of people, processes, systems and real innovation.

Now, think about someone or an entity (business, product, government agency) that you have lost faith in.

The people or businesses that you have stopped interaction with, have become “Unreliable” for your particular requirements or expectations of quality of service.

How would our world change for the better if there was more learning and focus on being “Reliable”?

How can you as a person or business become top of mind, when someone is asked “Who would you recommend” to: _________________?

You too, can become truly reliable…

Friday, September 16, 2022

ORM Tools: So Many Choices...So Little Time

As the software marketplace begins to mature with the newest systems for various facets of Operational Risk, how do you know what software tools are right for your organization?

For starters, there are dozens if not hundreds of specific tools on the market today for helping you manage everything from Risk and Control Self Assessments (RCSA), Supply Chain Risk to documenting processes for SOX 404 compliance. 

"You can benefit from building your structures for processes, business strategy and tests for procedures. This still leaves many choices to evaluate and vendors who will flog you with powerpoints."

There are several key components of the ORM Framework Management that are essential when considering software tools to assist you:  

Policy 

Create security policies, standards and procedures, distribute them online, educate and train employees, and track compliance, exceptions and violations.  

Threat 

Comprehensive and customizable early warning system providing notification of physical and digital threats, vulnerabilities and malicious code to help prevent attacks before they affect the enterprise.  

Assets 

Manage enterprise assets such as buildings, vehicles, inventory, servers, applications or data centers and their relationships to ensure you are protecting your critical assets according to management expectations. 

Risks 

Perform online risk assessments to determine the proper controls to be implemented on specific assets based on their use and risk to the enterprise. 

Incidents 

Report incidents, manage their escalation, track investigations and analyze resolutions.

In evaluating the current information security, regulatory and legal environment, consider these five key flaws with today’s ORM software solution programs:

1. Dependence on inadequate and incomplete technology-based point solutions; 

2. Failure to integrate people, process and systems into an effective operational risk program; 

3. Lack of decision support and an actionable understanding of the threat to the entire spectrum of corporate assets; 

4. Reactive response to perceived problems rather than proactive initiatives based on sound risk management principles; and

5. Cost and shortage of properly skilled IT personnel to suport the programs.

The Gartner Group has identified three major questions that executives and boards of directors need to answer when confronting significant issues: 

  •  Is your policy enforced fairly, consistently and legally across the enterprise.
  •  Would our employees, contractors and partners know if a violation was being committed?
  •  Would they know what to do about it if they did recognize a violation?

If you don't know the answers to these questions then there is much more work to do and much more strategic planning necessary before any software system is implemented for Operational Risk Management...

Saturday, January 19, 2019

International Risk: Cyberwarfare Rules of Engagement...

When the financial private sector views the actions of government, in terms of regulation and compliance, it is often considered another risk to its operations. Why? More rules and the need to report on oversight, creates new obstacles to other more valuable revenue producing activities.

CDOs were a focus in the movie "The Big Short" and is an example of a financial product that explains why the government regulation mechanisms continue to exist. Yet the implementation of internal controls, to thwart the embezzlement of funds or the theft of proprietary intellectual secrets, is something that is encouraged and welcomed in the banking community. This paradox is something that continues to occur in the cyber risk management domain.

The dawn of Internet banking, spawned many of the Operational Risks associated with using public networks for our various banking transactions. The oversight of cyber risk management in the financial institution, is still a major challenge yet becoming more mature by the day.

Government is more effectively learning how to apply the right oversight with private sector institutions, through the use of International Standards such as ISO 27001 and NIST best practices to protect Critical Infrastructure.

The newest strategies for cyber risk management have been a robust topic of global conversation. New reports on the origin of state sponsored hacking and cyber crime data breach incidents, has produced some new theories on how to address these international Operational Risks:

"Deadly force against organized hackers could be justified under international law, according to a document created by a panel of legal and cyber warfare experts. Use of lethal force on those behind a cyberattack on a nation would be legal if the virtual attack meets criteria similar to those currently accepted for real-world warfare, said Michael N. Schmitt, chairman of the International Law Department at the U.S. Naval War College in Newport, R.I. Schmitt is the editor of the Tallinn Manual on the International Law Applicable to Cyber Warfare, a 300-page book put together by a score of experts at the request of NATO and published by Cambridge University Press."

Even the most knowledgeable cyber experts, are at odds over the topic of "Active Defense" and the use of asymmetric cyber force, to retaliate against a so called attack or denial of service. A kinetic response is much more clear, based upon the source or attribution evidence of the attack. In the cyber domain, the word "Attribute" has some very interesting ramifications.

The State-of-Play will remain the same and for good reason. The governments of the world do not have issue with each other performing reciprocal cyber espionage. This practice is just a new version of intelligence collection and the next manifestation of Tinker Tailor Soldier Spy. However, if there should be any visible or kinetic damage to infrastructure, then the Tallinn Manual will be a vital resource for all. The question remains, what is a cyberattack? Jim Lewis said over five years ago:
“Cyberattack” is one of the most misused terms in the discussion of Chinese hackers. With very few exceptions, China has not used force against the United States in cyberspace. What it has been doing is spying. And spying, cyber or otherwise, is not an attack or grounds for war, even if military units are the spies. Spying isn’t even a crime under international law, and it wouldn’t be in Washington’s interest to make it so."
  Cyberwarfare Rules of Engagement remains a significant international Operational Risk...

Saturday, April 14, 2012

Too Big to Fail: Basel III to ID Theft...

Now that the Basel III wheels are in motion and the "Top 29" vital Global banking institutions have been identified, Operational Risk Management is on everyones mind. The capital reserves will continue to assist them in becoming more resilient to the systemic volatility ahead. Are you feeling the uncertainty starting to disappear? Not for a minute.

As these banking institutions try to withstand the economic impact of a nation state failure like Greece, the consumers who are the customers of the "Top 29" too big to fail, are being simultaneously barraged and systemically targeted by international crime rings. Identity thieves have set up transnational operations, that will continue to plague millions of consumers at these same banking institutions. Their own governments continue to try and deal with the nexus of criminal elements, consumer privacy and law enforcement. How bad is it for the U.S. Treasury, as one example:
Identity theft involving tax fraud is increasing faster than law enforcement and government officials can deal with it, according to testimony today before a House oversight subcommittee. Identity theft to scam fraudulent tax refunds from the government has increased 100 percent in just three years.
”As of Aug. 31 of this past year, IRS incident tracking reports indicated that the numbers of taxpayers affected by identity theft has more than doubled since 2008 to over 580,000 taxpayers this year alone,” said J. Russell George, Treasury Department inspector general for tax administration.
The crime has become too easy. It’s like a party, according to Rep. Richard Nugent, R-Fla., whose district has a problem with tax-related identity theft.
“Tampa Police Department has busted what the lawbreakers call ‘make it rain’ parties, where criminals get together in a hotel room with Internet access and file fake return after fake return,” Nugent told the committee.
How does paying out billions of dollars to these fraud crime rings using your social security number and date of birth increase the operational risks on our banking institutions? Everyone who is a consumer at one of these banks who is a victim of fraud, will one day deal with the aftermath. If the fraudsters are filing a fraudulent tax return that impacts you, then the odds are that you may end up paying a higher interest rate and this will not be the only place they are using your ID Theft misfortune for financial gains.
For the victims of tax fraud identity theft, the people who had fraudulent tax returns filed in their names, getting the problem fixed and their lawful refund paid could take a year and a half.
“A typical path for an identity theft refund case that is not complex may take as long as 18 months to resolve,” said J. Russell George, Treasury Department Inspector General for tax administration.
The cost of dealing with Identity Theft has so many dimensions. The protection of Personal Identifiable Information (PII). The fact that the IRS and law enforcement have difficulty sharing information on the consumers themselves due to privacy laws. The technology and online Internet forums for buying and selling fraudulent identities is prevalent. The continuous salvo of attacks on financial institutions to compromise the cyber defenses that they have established is a 24 x 7 battle.

To exacerbate the problem, the "Death Master File" (DMF) is the genesis for much of the Identity Theft and tax fraud when this information gets into the wrong hands. The U.S. Social Security Administration has been publishing this list of 90 million dead Americans since 1980 to help the "Top 29" fight fraud. At the same time, the Identify Theft fraudsters are using the same data to perpetuate their schemes:

Identity thieves are cashing in on dead children across the nation, stealing their Social Security numbers to collect fraudulent tax refunds from the Internal Revenue Service.
Grieving families — including the Watters family of Lake Forest — say their anguish is amplified by the realization that the crooks get help from an unexpected source: the Social Security Administration’s “Death Master File,” which records and lists information about everyone who dies in the United States.
Armed with the deceased child’s Social Security number and other personal information, crooks falsely claim them as dependents and have the refunds routed to them.

One reason that the financial institutions, government agencies and law enforcement are going in circles is because "Operational Risk Management" processes and tools are still not as robust as they could be. As the Basel III regulatory mandates kick in along with other new laws, methods and tools, all of the impacted parties will get better at deterring, detecting, defending and documenting in this complex information age.

In the mean time, consumer beware. Look long and hard at the "Top 29" list and decide if you need to move your funds to somewhere else. And before you do, look at the online banking login page for that institution. Are they still using only a single factor user name and password? Multi-factor authentication is not fool proof, yet it does tell us whether the institution is serious about Operational Risks in the area of Information Security. This is a key indicator of their ability and capability to try and keep your data out of the hands of the transnational eCrime rings.

Finally, you have to take the monitoring of your own Identity, and all of your family members identities seriously. It will be far more proactive, than anything else that will be done by governments or financial institutions alone. Regardless how fast they implement the latest tools and technology the fraudsters are moving just as fast. By adding your own diligence on top of the banking institution, government agency or other entity (Doctors / Lawyers / Dentists/ Insurers) that may have your Personal Identifiable information, you are decreasing your odds of becoming an Identity Theft and fraud victim.

Financial risks for the banks and the consumers will continue to be the current state-of-play. Basel III alone will not eliminate the threat of failure or the possibility of a serious bank fraud. Monitoring services or checking your credit report on a quarterly basis, will not keep the ID Theft criminals from stealing your PII. Implementing both on a proactive and pervasive basis will make a positive difference over time. This is what Operational Risk Management is all about, in the global institution board room and at your own home office.

Saturday, December 31, 2005

Managing Operational Risks: On the Wall at 100 Ft...

After days taking in the magnificent sights at 100+ feet below the surface off Grand Cayman Island, we were reminded how Operational Risk Management is prevalent in even remote places like this.

Take for example the mandate for using dive computers, as a guest of Wall to Wall Diving. For those not initiated with Scuba Diving, you might not realize that "sensors" are utilized in measuring potential threats to your life from something called "The Bends", or decompression sickness.

Giles Charlton-Jones and his wife Deanna from Wall to Wall Diving use a combination of proven Operational Risk Management processes and tools to reduce the risks to their clients. They do this because their small business is no different than that of a Fortune 500 company. As the owners and primary shareholders of any organization, it is the law in most cases to provide Duty of Care.

Decompression sickness, (DCS), diver's disease, the bends, or caisson disease is the name given to a variety of symptoms suffered by a person exposed to a reduction in the pressure surrounding their body. It is a type of diving hazard.

Dive computers perform a continuous calculation of the partial pressure of gases in the body based on the actual dive profile. As the dive computer automatically measures depth and time, it reduces the need for the diver to carry a separate watch and depth gauge and is able to warn of excessive ascent rates and missed decompression stops.

Many dive computers also provide additional information to the diver, for example, the water temperature, or the pressure of the remaining breathing gas in the diving cylinder.

The key point is, that these sensors attached to each diver, help Deter and Detect potential threats associated with decompression sickness. This even includes a calculation when it is safe again to fly on an airplane.

Like other manufacturers in the high technology systems sector, SCUBA (Self-contained Underwater Breathing Apparatus) has it's own champions of companies who focus on the latest tools and solutions to help you manage risks. Who plan for future threat scenarios based upon collected intelligence over years of experience.

Suunto is just one example of a Finnish company, who have been developing instruments for measurement and sensors for various outdoor pursuits. Whether it be on the mountain at 20,000 ft. or underwater at 125 ft..

Weather and our Earths environment will always play a part in the daily risks mountaineers and divers face and who are proactive with the use of the correct tools, so they can operate in a more safe and secure manner.

Yet without the investment with “True Professionals” who have years of the relevant training, decades of experience and brilliant intuition, all the best tools will never be quite enough.

“How often do you encounter situations where the new threat intelligence collected and the automatic warning alerts have not been enough, to keep you out of harms way?”

As a global Fortune 500 company, the Board of Directors represents the interests of shareholders, as oversight owners of the company, in optimizing value by overseeing management performance on the shareholders' behalf.

The Board of Directors responsibilities in performing this oversight function include a Duty of Care and a Duty of Loyalty.

A Director's Duty of Care, refers to the responsibility to exercise appropriate due diligence in overseeing the management of the company, while continuously making OPS Risk decisions and performing other vital mitigation actions.

It remains refreshing to witness that even on a small island in the British West Indies, that the owners/operators are true professionals who are applying the practice of “Operational Risk Management” (ORM) in their own small employee-owned business.

First, they utilize it each day because they are Professionals. Second, they do it instinctively, because they know that it can mean the difference between life and death or predictive harm in an organizations daily operations.

As we near the end of another year of growing risks in 2021, we say congratulations to all of you who have found the science of “Operational Risk Management”.

Thank you to all of you, who have applied your own professional services “Art”, to make our world, more safe and secure in 2022! Godspeed!