Friday, December 03, 2004

H.R. 4830 - Private Sector Preparedness Act of 2004

What is H.R. 4830?

A bill introduced last summer in the U.S. House of Representatives to amend the Homeland Security Act of 2002 to direct the Secretary of Homeland Security to develop and implement a program to enhance private sector preparedness for emergencies and disasters.

Program Elements- In carrying out the program, the Secretary shall develop guidance and identify best practices to assist or foster action by the private sector in--

`(1) identifying hazards and assessing risks and impacts;

`(2) mitigating the impacts of a wide variety of hazards, including weapons of mass destruction;

`(3) managing necessary emergency preparedness and response resources;

`(4) developing mutual aid agreements;

`(5) developing and maintaining emergency preparedness and response plans, as well as associated operational procedures;

`(6) developing and maintaining communications and warning systems;

`(7) developing and conducting training and exercises to support and evaluate emergency preparedness and response plans and operational procedures;

`(8) developing and conducting training programs for security guards to implement emergency preparedness and response plans and operations procedures; and

`(9) developing procedures to respond to external requests for information from the media and the public.


Congress has found out the following:


Identifying standards and best practices is necessary to promote emergency preparedness by private sector organizations, in addition to educational activities to effectively communicate such standards and best practices.


As business waits for this bill to get out of committee, business leaders around the country are not standing around. They realize that contingency planning and continuity of operations is imperative for their business survival. We can only hope that no one is waiting around for what the standards body or best practices authority will be. Let's pray that the private sector has gone beyond developing plans and now is exercising Corporate Emergency Response Team (CERT)training in all the facilities deemed to be soft targets. Without this, we will certainly not be as ready as we could be. And once we have trained and tested numerous times, we will know what to improve and how to change the procedures accordingly.

Wednesday, December 01, 2004

Some SOX relief for smaller firms...

US companies with a market cap between $75 and $700 Million will get a 45 day extension for compliance with SOX (Sarbanes-Oxley Act of 2002). According to the SEC Statement:

The online statement quoted SEC Chief Accountant Donald Nicolaisen, saying: "The Commission is sensitive to resource constraints at accounting firms and at smaller public companies, and is taking this step to facilitate the successful and effective implementation of the Section 404 internal control requirements." Alan Beller, director of the Division of Corporation Finance, added that the exemption should "encourage companies to file important information for investors, including audited financial statements, on a timely basis, while providing an appropriate accommodation for internal control reports."

Eligible companies now have 45 days after the expiration of their 75-day reporting window to add the required management reports on internal controls, along with auditors' comments, the SEC said. The PCAOB's ruling allows auditors to sign off of internal reports at a later date than financial reports. The temporary rule is expected to be in effect until July 15, 2005.

Tuesday, November 30, 2004

People Risk: Whistleblowers are winning...

This article from Charles Baldwin highlights the recent rulings under the Whistleblower provisions under the Sarbanes-Oxley Act of 2002. If this is the trend, then employers need to spend more time educating employees and making sure they are in compliance with the letter of the law.

Of major significance to the employer-employee relationship, the Act requires the newly mandated audit committees of corporate boards of directors to establish procedures for the anonymous, confidential submission of employee concerns relating to improper corporate financial, accounting, or auditing practices and creates new civil and criminal liabilities relating to informants. In addition to requiring internal complaint procedures, Section 806 of the Act created a new federal civil claim under the title "Whistleblower Protection for Employees of Publicly Traded Companies." The nature of the claim is broader and imposes fewer burdens on a claimant than other federal whistleblower laws; thus, employers should expect to encounter more claims and litigation arising from the Act.


Recent rulings by the U.S. Department of Labor include:

Getman v. Southwest Securities Inc, No. 2003- SOX-00008, DOL ALJ
Welch v. Cardinal Bankshares Corp., 2003-SOX-15, DOL ALJ
Morefield v. Exelon Servs. Inc., DOL ALJ, No. 2004-SOX-2


In addition to complying with all of Sarbanes-Oxley’s requirements regarding financial reporting controls and corporate governance, prudent employers—whether public or private—must be proactive in implementing policies and procedures to navigate the post-Sarbanes-Oxley landscape. We recommend that employers first conduct a top-to-bottom review of existing policies and practices, ideally in a manner that will maintain all available legal privileges and protections. A review of insurance coverage, including but not limited to Directors’ and Officers’ liability coverage, must be a part of that review. Following that review and follow-up, employers should be in a position to show, at a minimum:

* A code of conduct that spells out specifically the duties of all employees;
* A code of ethics for senior financial officers;
* Establishment and a clear publication of a hotline and other avenues for confidential, anonymous complaints;
* Personnel policies and procedures that comply with the law’s requirements on handling of complaints, document handling and retention, and non-retaliation;
* A clear designation and publication of those persons within the company who have the authority to investigate, discover, or terminate financial misconduct;
* Personnel policies clearly addressing inappropriate conduct, e.g., prohibited conduct regarding media contact, removal of documents, destruction of documents, refusing to participate in investigations;
* Benefit plans and practices that comply with all requirements and prohibitions;
* Procurement practices and procedures to ensure proper screening of human resources consultants and auditors;
* Hiring practices and procedures to ensure proper screening of executives; and
* Comprehensive and documented training programs for all employees that implement the requirements of Sarbanes-Oxley.

Wednesday, November 24, 2004

Managing Operational Risk in Banking...

This latest article by McKinsey may have some interesting insight:

Banks are increasing their coverage against operational risk to comply with new international banking rules, but they may be underestimating the extent of the risks they face. The declines in market value of financial institutions that experienced an operational crisis—such as an embezzlement or breach of regulations—were much greater than the actual financial loss caused by the event, our research found.

The take-away

Banks that understand the true scale of the operational risk they face can take a more realistic approach to controlling it.


This article includes the following exhibits:

* Exhibit 1: Impact of operational crises on market returns
* Exhibit 2: The five most harmful kinds of operational crises

Tuesday, November 23, 2004

UK: Civil Contingencies Act...

The UK's Civil Contingencies Act is on the door step and David Honor of Continuity Central has the following observations:

No UK organisation can afford to ignore the Civil Contingencies Act. The category one and two organisations which will be directly impacted will receive information, advice and support from the Cabinet Office on how and when to implement measures. Other organisations would be well-advised to do the following:


• Get a copy of the Act and read it
• Assess your current business continuity plan against the Act’s provisions. Does the Act make any difference to the scenarios you have planned for?
• Redevelop the business continuity plan where necessary and re-test it.
• Liaise with your local authority emergency planning department. This is good practice which is listed as one of the BCI’s Ten Key Disciplines of Business Continuity, but now becomes even more important since local authorities will become one of the key sources of local business continuity information and advice.

Friday, November 19, 2004

OSAC 19th Annual Briefing...

The topics of the annual Overseas Security Advisory Council Briefings and 8th Annual Transnational Crime Seminar indicate what's on the minds of most CSO's across America and the globe. See if you can see the common thread:

"Managing Risks and Threats in Challenging Environments" - Bureau of Diplomatic Security

"From Suppliers to Satellites: Balancing Business and Security" - Delphi Corporation

"Coping with Istanbul" - HSBC Holdings, PLC

"Managing World Security Trends"

"Communicating with Employees under Heightened Threat Conditions"

"What do Employees Expect, What do They Need"

"Perception of Bio-security Dangers and the True Vulnerabilities"

"International Kidnapping and Hostage Taking"

"Emergency Preparedness and Business Continuity"


After two days of hearing presentations by some of the most informed individuals on the topics and issues of global security, one individual made a very interesting point:

On the topic of Practice Preparedness and Training Programs for employees he asked, "What do your people do in the event of [Pick a Diaster Scenario]?" The point is, you won't know what they do unless you exercise, drill and experiment with different scenarios. He went on to say that we need to be Leaders of Safety, Health and Operations and that the likes of SARS and Avian Flu will not be stopped by more guards, gates and guns.

Invisible contagious agents that are autonomous will be something we encounter on a mass scale sooner than we think. As professionals paid to worry, this is the one that we don't ever want to encounter and don't know much about how to mitigate the threat to our organizations.

Another vital topic on Abduction Prevention and Hostage Survival promoted the thinking about training to detect surveillance and to make rational and tactical decisions to prevent from being kidnapped. However, in the event of abduction, there are only four outcomes:

1. Negotiate
2. Rescue
3. Escape
4. Death

The point here is that you must maximize survivability and minimize exploitability. Finally, employees and organizations need to have a Personnel Recovery Architecture that includes a continuum for guideance and a crisis management framework.

Operational Risk and Continuity Management is what this 1.5 day briefing was all about. If there was one thing that stands out from all the presentations and the conversations is that our employees are looking for people they can "TRUST". It's our duty to make sure that we do everything in our power to make this a reality.

Perception drives Attitude that drives Behavior.

Thursday, November 18, 2004

ID Theft: Banks vs. Consumers...

The banks have a different perspective on ID Theft and privacy than consumers. As this Bank Tech article points out.

Late last month, four servers containing names, addresses and Social Security numbers of thousands of Wells Fargo & Co. mortgage and student-loan customers were stolen from an Atlanta company that prints loan statements. There's no indication the information has been misused, the bank says, but it's advising affected customers to monitor their accounts for suspicious activity. It's also offering a free one-year credit-protection program and has established a toll-free hotline.

The incident was the latest reminder of how pervasive the threat of identity theft has become, as well as how much of a risk it is for banks and credit-card issuers and their customers. According to the Federal Trade Commission, 9.9 million Americans were identity-theft victims last year. Of those, 6.6 million reported fraudulent use of existing accounts while more than 3 million reported new accounts opened in their names. That cost businesses $48 billion and consumers $5 billion in economic losses.


As banks and other financial institutions outsource operations such as printing statements and sending out direct mail they are going to be continually subjected to incidents like this. What is commonly the case, and astonishing to say the least is that these 3rd parties are not always as "buttoned-up" as they should be with their risk detection, prevention and protection programs. If the consumer has anything to fear, it is that their bank is not taking the time to effectively audit and monitor their outsourced service providers.

Tuesday, November 16, 2004

NIMS set to be approved...

The National Incident Management System is soon to be approved.

An integrated national plan for response to terrorist attacks and other national emergencies is likely to be approved by Cabinet secretaries by the end of this week, Deputy Homeland Security Secretary James Loy said Tuesday.

By this time next year, the final National Response Plan will have replaced the disparate plans now in effect at federal agencies that work terrorism response, the former Coast Guard commandant said at a maritime-security conference in Washington organized by Defense Today and held at George Washington University.

A February 2003 directive by President Bush required the fledgling Homeland Security Department to design and implement the National Response Plan and the associated National Incident Management System in a bid to "establish a single, comprehensive approach" to managing terrorist attacks, natural disasters and other large-scale emergencies.


The system establishes "standardized incident management processes, protocols and procedures" for incident command organization, communications and preparedness, Homeland Security said in a March fact sheet. The effort is intended to allow first responders from different jurisdictions and disciplines to better coordinate responses to natural and unnatural disasters.

Monday, November 15, 2004

SOX 404 Deadline today...

The long anticpated compliance date with Sarbanes-Oxley Section 404 arrived today and many organizations are not ready.

Although many companies are reportedly not ready for it, the era of internal-controls compliance begins in earnest today. That's when Section 404 of the Sarbanes-Oxley Act goes into effect for all companies whose fiscal year ends after today.

There will be nothing to file on Tuesday. But by early next year, the vast majority of companies that report on a calendar-year will have to assess the effectiveness of their internal controls over financial reporting and state in their annual reports whether the controls are operating effectively. The companies' outside auditors also must evaluate the in-house assessment and render an independent report on it.


The average cost to a organization to get in compliance is estimated at $5M and rising for a Fortune caliber public company.

Friday, November 12, 2004

Global Assurance Office...

As the corporate risk management factions realize that they need to converge in their coordination, global assurance management will take hold.

Soon enough the global 500 will realize the requirement for a more consolidated, coordinated and cohesive entity within the organization for risk management, information security, business continuity, crisis management and emergency response.

The combined expertise in finance, compliance, legal, IT, internal audit, operations, security, human resources and purchasing will all be working together to create the organizations single global assurance office.


This will be the team and staff that manages an "All Hazards" approach to mitigating the threats to the organization. They will be responsible for the single task of making sure that the business is running no matter what event or incident may try and bring it down.

A few savvy organizations have already moved this direction and even those that thought they had a single responsible team are now adding new dimensions and capabilities to the team.

Thursday, November 11, 2004

1SecureAudit Prepares WTG Properties Tenants For All Hazards And Catastrophic Incidents

Risk mitigation training solution delivers greater confidence, lower costs, and increased peace of mind for this Washington, D.C. commercial real estate firm

For Immediate Release

MCLEAN, Va./EWORLDWIRE/Nov. 10, 2004 --- 1SecureAudit LLC, an emerging leader in operational risk management solutions, today announced a client success story for WTG Properties in Washington, D.C.

Many companies throughout the Washington, D.C. area are asking the same important question, especially since Sept. 11, Hurricane Isabel and the Northeast blackout. That is: How can businesses be better prepared in the case of serious hazards, incidents and emergencies?

The residents of WTG's N Street property were no exception. "My tenants were asking what we were doing to be better prepared in case of another attack," said John Lane, president of WTG Properties Inc. "Which was logical, given their proximity to the White House.

"But I wanted a proactive and preventative all-hazards program that would cover everything," continued Lane. "I wasn't just worried about terrorists, but also about serious incidents like floods, fires, and hurricanes. That's when I started my conversations with Peter Higgins of 1SecureAudit."


1SecureAudit is a risk management solutions firm that worked with Lane and the residents of the property to teach them how to better cope with emergency situations that may arise.

Higgins explained: "You've heard the term first responders. Well, the fire fighters, police and EMTs are actually the second responders. Employees and tenants are the first responders in a crisis, and they need to be competent, confident and as prepared as possible to handle the situation until the emergency personnel get there - whether it's minutes, hours or days."


Think all hazards. Think convergence of BCCM, ISMS and Corporate Governance. That equals total Global Assurance. The future is here now.

Tuesday, November 09, 2004

Business Process Outsourcing: A Real Threat to Security or IP Theft?

Business Process Outsourcing is a hot issue and as this article by The Heritage Foundation so clearly states:

Defending the nation against terrorists, promoting economic growth, and protecting constitutional lib­erties are all prerequisites for a sound homeland security strategy. At one time or another, outsourc­ing[1] has been labeled a threat to all three. These crit­icisms are simply overblown. In fact, if the U.S. partners with nations that share a commitment to the rule of law, transparency, and open competition, it can use sensible outsourcing to enhance the protec­tion of the privacy of American citizens, promote better security practices, and contribute to economic prosperity. Effective outsourcing can provide both cost-effective services and appropriate protections for government and commercial activities supported by overseas vendors.


Now if you talk with the major U.S. technology companies who have outsourced operations in India and China they will tell you their nightmares. Intellectual Property theft is running rampant and the laws and trade representative sanctions will be hard pressed to make major changes in the near term. The security of the nation is not going to be compromised by these organizations and the real loss events will occur when their source code is posted on the Internet.

Conclusion

The goal of increasing domestic security and protecting the privacy of U.S. citizens should not be an obstacle to strengthening economic ties with the developing world. Rather, market forces and sensible outsourcing can be used both to promote better global security practices and to encourage economic growth.

Monday, November 08, 2004

Judgment Calls...

Regulations such as Sarbanes-Oxley are sending auditors to the pencil sharpener. CSOs must learn to cooperate and share expertise, without getting too close to these empowered examiners.


Malcolm Wheatley is a freelance writer in England. And this "Judgment Calls" article was dead on with good advice especially number four:

Strategy No. 4: Teach Them Security Heim’s mention of a back-and-forth negotiation between auditors and security executives carries with it an important conclusion: Security-savvy auditors are a must.

Communicating with auditors as part of a cooperative process is one way of educating them about the security function. Another solution, according to Radianz’s Hession, is to obtain the requisite combination of skills and separation by turning security folks into auditors.


How can you have an effective Information Security Management System without auditors who know “Risk Management” from an IT perspective? The answer is, you can’t. And you can’t have an effective audit for legal compliance issues without IT security professionals who understand the intent of the law. To do this you must have a cooperative team who thinks like a criminal and that is not easy to create.”

“The reciprocity between CSO, CIO, CRO, CFO and General Counsel is imperative if any sizeable company is going to mitigate the threats from internal and external attackers. And as this article clearly points out, a healthy set of objectivity and anxiety is imperative if you are going to have professionals on the front lines do their jobs within the intent of the law.

Wednesday, November 03, 2004

Bush defeats Kerry for US Presidency...

George W. Bush won his Second Term as President of the United States today.

"To make this nation stronger and better, I will need your support and I will work to earn it," Bush, referring to Democratic supporters who bitterly oppose his presidency and re-election, said in a speech at the Reagan Center to a cheering partisan crowd.

"I will do all I can do to earn your trust ... we have one country, one constitution and one future that binds us."


The risks have not changed and the way we detect, deter and defend our precious assets will continue to gain momentum for the next four years.

Tuesday, November 02, 2004

Advanced Citizenship in Critical Infrastructure Protection...

The dialogue from a recent CSO Conference that focused on information sharing keeps coming back to why it is so hard to accomplish.

Only Bill Boni from Motorola was bold enough to tell the real reason why the cyber world is still not getting the attention it deserves.

Boni: I think the real driving issue here, if you go back and look at [how sprinkler systems came to be in factories], such safeguards come out of the experience of factories burning down and people dying. And until we see mass-casualty events that are critical to information security failures, I don't think you're going to have that same sense of urgency. And, probably, as a society we shouldn't. But, the challenge is to make sure that organizations are doing their reasonable best to not be the cause of part of that event. But my belief is that until we see mass casualty situations that arise from information security, we won't make that transition, and we shouldn't. Unfortunately, I think that it is going to happen at some point. Whether that's before or after I retire from my current employment is a very important deliverable.


It's amazing to find out that even as we speak there are people who are still unprepared to handle the zero day exploit or the next catastrophic incident. Even when they are considered a "soft target" they still have not exercised and tested to the degree necessary to improve their defense and to plan for the various outcomes possible. Boni is right, if it doesn't happen to me then why should I spend the time and resources to prepare? For the same reason you pray at your place of worship. You know it's inevitable and yet you don't know when it is going to happen to you.

Friday, October 29, 2004

Threat Detection & Management...

Robert Young Pelton's Travel Tips may be common sense. These are also the type of tips you get from those expensive executive seminars where no one ever gets out of their seat for two days.

If you are going to take an attitude of really protecting your organizations most valuable assets then you have to train your people in real life scenarios. The goal is to overcome the panic modes and replace them with smart actions to save your life and your companies precious information.

For those who travel on business into regions of political or religious instability it should be company policy that each individual travel with at least an experienced partner. Also essential is that both have gone through extensive hands on training to detect surveillance as well as manage emergency situations with smart decisions. For more on this visit: Threat Detection & Management

Wednesday, October 27, 2004

Compliance and outsourcing: Oil and water or fine vinaigrette?

John and Stan could not have said it any better....

By John Van Decker and Stan Lepeak
10 May 2004 | Meta Group

One common misperception that still survives in the market is that existing outsourcing audit mechanisms, primarily the SAS 70 audit, are adequate for SOX compliance. The growing consensus is that even an SAS 70 Type 2 audit may not prove enough for SOX. The SAS 70 standard was developed long before SOX regulations and was not designed to focus on the type of controls that SOX addresses. In addition, there have been no requirements for users to request an SAS 70 audit, and many have not. One SAS 70 audit could potentially suffice for multiple clients of an outsourcer, whereas with SOX compliance, this is likely unacceptable. We are seeing more cases where aggressive/thorough clients are demanding additional controls and documentation beyond an SAS 70 Type 2 audit to enable what they estimate is "good enough" SOX
compliance. It is not expected that the PCAOB will define requirements above and beyond an SAS 70 for SOX compliance until later this year.

A final challenge to SOX compliance that affects outsourcers is interenterprise
compliance. Users must approach process compliance holistically, covering insourced and outsourced processes, as well as intersection points and continuums of processes that span supply and service chains. For example, how can a user's controls account for the breakdown in a supplier's financial controls that could lead to a parts shortage, which could impact revenue/profits that would then require a timely disclosure? Clearly, organizations cannot address SOX compliance in an isolated fashion. Outsourcers have the added dimension of being intertwined in multiple-clients compliance efforts across multiple process areas. This in itself increases the outsourcer's risk and demands greater focus on enabling compliance, for its own sake as much as its clients'.

Bottom Line: Business process and IT outsourcing currently do not mix well with SOX and related compliance requirements. However, outsourcers and their clients cannot wait for regulatory clarification and must define, document, and rationalize interim best-faith efforts for gaining and evidencing SOX compliance for affected outsourced functions and processes.

Tuesday, October 26, 2004

Systems: Data Quality Risk...

The quality of data is becoming a risk management issue again according to this latest Banking Study of 1700 banks in 63 countries. Sarbanes-Oxley and Basel II are helping CIO's to increase their budgets yet the study finds that data quality is still one of the biggest operational risks.

The survey quizzed banks about eleven key topics involving reference data management and risk management and shows that financial institutions worldwide are making considerable efforts to deepen their data management and increase data quality.

These efforts are being driven, besides cost pressures and increased transaction volumes, by regulatory requirements such as Sarbanes-Oxley and Basel II, which will be implemented in more than 100 countries within the next few years. "The results show that companies realize the close connection between comprehensive data management and efficient risk management," explains Martin Buchberger, head of marketing at AIM Software.


Workflow management is a key concern and 54% of the respondents plan to spend money in this software as it is a vital component in managing operational risk. Furthermore, outsourcing and COTS solutions are outpacing proprietary development.

Looking further at standardization, 42 percent of the survey respondents plan to purchase an off-the-shelf data management solution or to buy and adapt a solution to their own needs. 26 percent of the respondents rely on proprietary development. "This is a significantly smaller proportion than in the past, when data management was still regarded as an internal core competency.

Monday, October 25, 2004

Phishing goes Corporate...

Phishing is making it's way inside corporations and represents a new threat by hackers.

The ploy is to send an email that looks legitimate about upgrading a software component or windows program. The hackers site then downloads the Malicious Code.

“Companies must make their employees understand their role in improving security within the organisation,” he said.

A proper security policy must also be in place and the role of each individual who manages the security policy must be clearly defined, he said.

It must also be made clear to employees that the security policy is in place for their protection and not just for the company.

And finally, companies must be prepared for the worse. There should be an incident response team should the company's security be compromised."

Friday, October 22, 2004

SOX a Ticking Time Bomb?

In the latest issue of Corporate Board Member you will find some very interesting statistics and comments. This one got our attention:

Is That A Ticking Clock Or A Time Bomb?

Has meeting Sarbanes-Oxley's requirements left directors enough time to think about other issues?

The answer is yes, but only because you're spending more time on the job than ever before.

The SOX Factor
Do directors think Sarbanes-Oxley has created an environment where management is so distracted that company performance will be affected?

No: 44%
Not Sure: 36%
Yes: 20%


I would say that over one third don't know, don't care or are too scared to really find out. One fifth think that performance will be impacted. That leaves the remaining 40+ % feeling confident that SOX will not affect corporate performance. Let's just hope that the "NO" voters do really know that this is the case.

Tuesday, October 19, 2004

People: Travel & LIfe Safety...

Travel risk to corporate executives is on the rise. Even if you are not an executive who can afford the services of personal body guards and armored cars, there are some prudent ways to mitigate the risk of traveling to the global hot spots.

Travel safety is becoming more of a main stream issue with savvy operational risk managers. In fact, the likes of some new firms are emerging by former FBI or other law enforcement heavy weights. The fact is, most of these so called travel safety courses are being taught from only one side of the equation.

Today, CSOs are often tasked with building their company's corporate travel safety programs. The job calls for a proactive approach to educate employees about precautions they can take to stay safe, whether they're the CEOs of multibillion-dollar conglomerates who fly on company jets that land on secured tarmacs or rank-and-file staff riding in commercial airline coach.


Business has to be done in some of the most dangerous places on the planet, even when it comes to being exposed to kidnapping, terrorism and corrupt governments. Our advice is to make sure your instructor transfers skills to people on "how" to detect, deter and defend against the attackers. Not just the "What to do".

For the real difference, visit: Threat Detection & Management

Monday, October 18, 2004

Business Performance & Basel II...

The Tower Group is shouting the need for banks to automate now in the midst of the Basel II momentum. While business performance has converged with Basel II, the key understanding needed is what do Business Performance & Basel II have to do with my survivability as a money center bank?

Basel II introduces a convergent framework of risk management and controls that will encourage banks to invest wisely in IT and improve the efficiency of their business operations. Banks that adopt effective enterprise risk management platforms will reap business benefits that go well beyond regulatory compliance.


Knowledge Management is coming to banking in a way that the bean counters never imagined. With the focus on Operational Risks, the only way to be able to correlate new threats with the current asset base is through automation.

The industry is now at the implementation phase of Basel II. Few banks have the perspective and resources to experiment and establish their own enterprise risk management models that include this new field of operational risk. Notwithstanding their attention to business continuity and reputational risk matters, most banks have still to inscribe operational risk procedures in the broader picture of business management and operational efficiency. Not only may banks improve their operational efficiency by streamlining business processes, but they also can tap important benefits in operational resilience, responsiveness and flexibility to innovate. By adopting automation models for integrated business and risk management, proactive banks may derive significant returns from a concerted enterprise approach.

Friday, October 15, 2004

External Events: The Risk of Loss from Eliot

What other risk will the financial services industry find to be more of a threat? With the latest litigation filed by the now famous Eliot Spitzer the insurance industry is in for the same treatment as Wall Street. Clean up your act.

The New York AG's suit against insurance broker Marsh & McLennan and other heavyweights may change the way the industry does business

America's biggest insurers have found themselves in the midst of a scandal that could change the very nature of the business. On Thursday, Oct. 14, New York Attorney General Eliot Spitzer charged Marsh & McLennan (MMC ), the huge financial-services firm and world's largest insurance broker, with fraud. In a civil complaint filed in New York State Supreme Court, Spitzer alleges that the firm engaged in bid-rigging, price-fixing, and accepted payoffs from insurers. Marsh's stock has plummeted -- it opened on Oct.14 at $46.01 but is trading on Oct. 15 at around $28.20, a drop of roughly 38%.


The scrutiny of the sales process at every insurer in the country has now begun. If you have a P & C policy on your building with Marsh, it might be worth getting a competitive bid now. This is going to be another lesson in Management 101.

Thursday, October 14, 2004

Operational Risk driving increased spending...

The latest surveys from PwC ASIA paints a rosey picture for a rise in Information Security spending.

About 67 per cent of information technology executives in Asia say they will increase spending on security, compared with a global average of 64 per cent in PwC's survey of 8,000 companies conducted this year.


There are four key areas driving this and 1SecureAudit has already figured this out:

Governance

Compliance

Liability

Reputation


Gartner and IDC also have some interesting predictions for growth in these areas.

Worldwide technology spending, including on telecommunications, will grow by 5.4 per cent to US$2.38 trillion (HK$18.56 trillion) this year, according to research firm Gartner.

However, global spending on business continuity and IT security solutions, at US$70 billion last year, is growing much faster, and will reach US$118 billion by 2007, according to International Data Corporation figures.


Operational risks are at the heart of all of this growth, especially in ASIA where Basel II is taking hold.

``Governance and compliance issues are driving the need for information security,'' partner Rick Heathcote said. ``In Hong Kong, we have observed that in order to comply with new laws and regulations such as Basel 2 [an international standard for capital requirements], personal data privacy laws and anti-money laundering obligations, companies are recognising the need for enhanced security and internal control.''


Wednesday, October 13, 2004

CFO as CRO?

There seems to be some discussion on whether the CFO should also act as the Chief Risk Officer?.

These days, however, the risk management "tent" has grown into a "big top" called enterprise risk management (ERM). To be sure, the discipline should help companies cope with natural disasters, worker injuries, lawsuits against directors and officers, and other traditionally insurable perils, according to the long-awaited ERM framework issued late last month by The Committee of Sponsoring Organizations of the Treadway Commission (COSO).


Believe me, the CFO is way too focused on getting the financials right to add the equally important tasks of a CRO. The next thing they will be asked to do is take on duties associated with the CIO. This has to end.

But there's a big obstacle on that rosy career path. If a single executive manages the potential upside as well as the possible downside of a company's moves, there's the chance that the executive's decisions might be overly biased. If the CFO/CRO is especially fond of taking risks, then the company might end up excessively exposed to disaster; if the officer is too risk-averse, opportunities could be missed.

That, apparently, was the reasoning of the Office of Federal Housing Enterprise Oversight (OFHEO) when it sharply criticized J. Timothy Howard's dual roles as CFO and CRO at Fannie Mae in a September report on the mortgage company's accounting.


The Board of Directors has figured this out in most savvy financial services companies already. In fact, the CRO may soon have more of a powerbase inside the executive management ranks than the Chief Financial Officer if the trend continues.

Tuesday, October 12, 2004

Operational Risk Headlines...

The newspapers are full of headlines today displaying the operational risks we contend with in these volatile days ahead of the US Presidential election:

Oil Prices Reach $54, a New Record - New York Times

US seizes independent media sites - BBC News

UN watchdog concerned by disappearance of nuclear material from Iraq - UN News Centre

U.S. Subpoenas Chiron Over Flu-Shot Shortage - SmartMoney.com

Fannie Mae faces DOJ probe, 8 investor lawsuits - Reuters

Feds: Hurricanes devastated Florida's citrus crops - Ft. Wayne News Sentinel

Westar testimony will include lavish lifestyles - CNN


The Global 500 company is dealing with a myriad of operational risks. Those that have proactive risk mitigation and management systems will survive. The question now is what will happen once the new President of the United States is finally decided.

What will happen with the price of oil? The corporate governance enforcement? World Trade and Diplomacy? The only thing of certainty is that the outcome of the elections will not affect the weather. Prepare.

Monday, October 11, 2004

IPR making headway...

The Special 301 process is gaining some new attention in the IPR battle. The WIPO conference in Geneva has also produced some new headway in fighting the spread of Intellectual Property Rights violations.

“Special 301” is the part of U.S. trade law that requires the U.S. Trade Representative (USTR) to identify countries that deny adequate protection for intellectual property rights (IPR) or that deny fair and equitable market access for U.S. persons who rely on IPR.

Under Special 301, countries that have the most egregious acts, policies, or practices, or whose acts, policies, or practices have the greatest adverse impact (actual or potential) on relevant U.S. products and are not engaged in good faith negotiations to address these problems, must be identified as “priority foreign countries.” If so identified, the country could face bilateral U.S. trade sanctions if changes are not made that address U.S. concerns.


The 2004 Special 301 report has identified 34 trading partners and placed them on the watch list.

China and Paraguay, due to their serious IP-related problems are subject to another part of the statute, Section 306 monitoring, because of previous bilateral agreements reached with the United States to address specific problems raised in earlier reports.

Thursday, October 07, 2004

Beyond SOX: Keeping Up with Corporate Governance Changes

Most CIOs have been intimately involved in meeting Sarbanes-Oxley (SOX) deadlines and setting up auditing reporting processes. But if you're tempted to sigh in relief as your company becomes compliant - don't. Rather, this is the time to investigate the talk you've heard of "beyond SOX." As the reality of corporate boards' new accountabilities is played out, the CIO will be highly impacted. What specifically should you be doing now to keep up with fundamental changes in corporate governance?

The five things that A.T. Kearney consultants are recommending makes some sense. The close kinship with EDS makes the items look like they are designed for a CIO. The point is that the IT organization has a tremendous responsibility to continue to try and move as fast as the business is changing. This by itself is a formidable task. The key to keeping the business in alignment with Information Systems is to make sure you have a robust Enterprise Architecture initiative.

For more on this visit: Adaptive

Wednesday, October 06, 2004

U.K. - Insurers Threaten to Pull Terrorist Cover -Continued

In last month’s Survive newsletter Patrick Roberts commented on an interesting article in the Times about insurance companies proposing to deny cover for terrorist attacks to businesses unless they can demonstrate a satisfactory level of business continuity planning. In response to this, Peter Higgins from 1SecureAudit sent us a few thoughts from a white paper the company has written on similar subjects:

In order to introduce new changes in process or design that impacts the physical or operational aspects of critical infrastructures (to reduce terrorism risk), it is important to better understand how these change levers can provide the incentives for owners. Being forced is never as appetizing as being induced to do anything. In order for changes to take place, the environment must reward investments in preparedness and safety. Consistently the conversations are not about “if” something is going to happen, it is about “where” or “when” it is going to happen. Therefore, it is imperative we initiate a proactive hedge against the inevitability of a loss event occurring in the future. First however, we must understand the character of terrorism risk in critical infrastructure and some of the anti-terrorism tools currently available to help manage that risk.

The recognition by insurers that owners will continue to invest in terrorism risk reduction and building safety with the proper incentives is vital to overall risk management of critical infrastructures. The assessment of terrorism vulnerability in key structures identified as soft targets can be a key component of the rating of risk for a specific structure. In order for owners to benefit from the potential of reduced premiums from direct insurers they must be able to demonstrate a combination of risk mitigation measures and programs to help improve the survivability of the infrastructure or to reduce it’s vulnerability to certain threat profiles. These need to be exercised on a continuous timetable with extensive documentation, training and reporting.

In order for insurance brokers to accurately represent their buyers mitigation programs and measures to the direct insurers they must have a foundation of knowledge about the structures physical vulnerabilities. However, even more essential is the understanding of the operational and human attributes of the building that are contributing to the proactive tactics to prevent losses and further exposures to potential terrorism risk. If this step takes place, the insurers can better evaluate these operational and human elements to determine the value and effectiveness of these tactics so that they can be considered for premium reductions. The building itself, two miles from the White House, has little chance of moving outside the high-risk zone for terrorist events. The only methods for reducing risk exposures are to dramatically impact the operational and human elements of the building to mitigate hazards and increase the survivability of the people and systems that are resident. Insurance losses resulting from a catastrophic events fall into several key areas:

• Property losses to the target building and adjacent structures, incurred by the owners themselves.

• Liability losses for claims due to inadequate procedures for evacuation or fire prevention incurred by building owners.

• Workers compensation, health and life insurance losses resulting from death or injury of tenants or visitors to the building.

• Business income and rent loss due to inability to occupy the structures incurred by tenants and owners.

• Financial losses by various lenders and investors in mortgage-backed securities associated with the mortgage notes themselves.


The real estate finance community and building owners associations have been subjected to a substantial debate since 9/11 about the exclusions of Terrorism Risk insurance. The real estate and lending environments in target cities such as New York, Washington, DC and Los Angeles have been in turmoil over the unavailability or terrorism risk insurance at reasonable prices.

Anti-Phishing Consortium created...A Risky Business

As the newest band of banks collaborate on Anti-Phishing strategies one can only wonder what they will do differently to mitigate this operational risk.

The Financial Services Technology Consortium, a financial-industry research group, said Monday that 11 financial institutions--which include Citicorp, J.P. Morgan Chase, Comerica, Visa USA, ABN Amro, KeyBank, Capital One, and University Bank--will define technical and operating requirements for counter-phishing measures, and clarify the infrastructure fit, requirements, and impact of technologies when deployed in concert with customer education, enforcement, and other industry initiatives. The consortium named Gene Neyer, managing executive of its Security Standing committee, to lead the initiative.


The banks own FDIC has also been a recent target of this social engineering trend. Hopefully they will soon find out that these attackers are not using scripts, data taps or autonomous agents as their tools. A new generation of firewall will not stop this threat. These attackers are not exploiting vulnerabilities in design, implementation or configurations of web services.

These attackers are using social engineering stategies and tactics to create the unauthorized result that they seek:

1. Increased Access
2. Disclosure of Information
3. Corruption of Information
4. Denial of Service
5. Theft of Resources


These attackers only have the following general objectives:

A. Challenge, Status, Thrill
B. Political Gain
C. Financial Gain
D. Damage


And the trend will continue to escalate as fast as new people are getting online. Think about all of the 60+ people in the world who are now moving to online banking and other e-commerce services. A whole new generation of naive kids getting on the Internet before they are in middle school are falling prey to the social engineers we sometimes call voyeurs.

It's a risk to be doing business on the web today. The strategies of these criminals have not changed. What has changed is that now they can do it from the other side of the globe in countries our own FBI will continue to have challenges getting their cooperation. This is one risk we will be living with for some time to come.


Monday, October 04, 2004

CIO Sox Report Card

A recent study has found that 93% of CIO's that were polled were clueless on their Section 404 compliance responsibilities of Sarbanes-Oxley.

"What they've failed to recognize is that 30-40% of a corporation's internal controls over financial reporting are information technology specific and that CIOs and other senior IT executives have a significant role in the process," he continued. "As a result, most corporate IT executives remain in the dark about their full responsibilities, even at this late stage, placing their companies at serious risk for failure. In fact, under the guidelines, if a company's CIO does not understand Sarbanes-Oxley Section 404 requirements, that alone demonstrates a deficiency in the control system."

Sarbanes-Oxley requires issuers of financial instruments in the U.S. - including all public companies whose shares trade on U.S. stock exchanges - to identify their significant financial accounts, the business processes that support those financial accounts and the applications and IT systems that support those business processes. Companies must then document and test the adequacy and effectiveness of controls at the financial reporting level, the application level, the IT infrastructure level and the IT management level. The deadline for the majority of public companies for Section 404 compliance is December 31, 2004 .

Continuity of Business: Hurricanes Lessons Learned

As the estimates come in from the losses from Florida hurricanes it looks like it will exceed $22 Billion.

The total economic impact is yet to be realized as this estimate is only the insurance claim payments estimate. Now that business has a better perspective on what being prepared really means, we should see some interesting Business Crisis and Continuity Management lessons learned here.

For example, how many organizations had their contracts in place with the diesel fuel supplier to replenish their back up generators after several days? Most prudent continuity planners would have such supplier arrangements already in place. However, if the supplier can't get to the business or their own plans have been disrupted then even the most well written contract will not hold up in the face of what happened over the course of a few weeks in Florida.

More importantly, the topic of outsourcing and redundant data centers continues to be a top strategic subject among COO's and CIO's as the operational risk events continue to surprise us. Let's just make sure that we take the time to exercise those plans and contingencies so that we go far beyond the contracts and actually test, learn and adapt.

Thursday, September 30, 2004

Operational Risk: People

After stopping by the booth at the ASIS conference in Dallas this week I'm convinced that Bruce McIndoe and his team are on to something great. Mitigating the risk of the loss of key personnel and other corporate assets is a vital priority.

iJet: ® Announces New Global Protection System
Ground-breaking Worldcue® GPS Application Employs Advanced Mapping, Notification, and Intelligence Capabilities to Better Protect Traveling Employees and Fixed Assets

Annapolis, Md - September 27, 2004 - iJET® Travel Risk Management (iJET), the industry leader in delivering real-time intelligence and proactive travel risk management services to multinational corporations and the travel industry, today introduced Worldcue® GPS, an innovative global protection system (GPS) for safeguarding people and assets, wherever they may be around the world. Worldcue® GPS employs advanced mapping, notification, and intelligence capabilities to make planning, monitoring, and crisis response more efficient and effective for those managing global risks.
"
Combining this capability with a focused surveillance and threat detection training program for employees could be exactly what our less than saavy corporate executives need. Peace of mind and to come home from their next business trip safely is the name of the game. The Threat Detection Program from 1SecureAudit provides a two day hands on course to educate and provide skills on various threats to individual security. These threats could include recruitment by a hostile service, kidnapping or assassination by terrorist and criminal elements or compromise by business competitors. Students are given intense, real-time instruction in surveillance detection and countersurveillance so that they can take appropriate actions.

Individuals whose occupations place them at risk may include people with access to valuable proprietary information or holders of high level security clearances, attorneys, judges, the wealthy and those responsible for their safety. This combination is one key strategy to mitigate the operational risks associated with key personnel in your organization.

Wednesday, September 29, 2004

NFPA 1600 Tour...Will it come up short?

NFPA has announced that is has scheduled a series of workshops aimed at helping facility emergency managers understand and use NFPA 1600. The events will start in Miami in November and will be held in a dozen or so other major-city locations throughout the US over the span of a few months.

The question now is, who is going to attend and what is going to happen afterwards. A classic case of new standards and no action. The "What" known as NFPA 1600 is the new ANSI and National Fire Protection Association guidelines.

The standards are a taxonomy of common criteria for business continuity programs. In addition, it provides a list of resources within the fields of business continuity planning. Again, a worthy cause to get everyone on the same page. Now we have the "What". But do we have the "How"?

The tour is a great idea to create awareness. Now all we need to do is make sure that the owners of major infrastructure put it all into action. What needs to be done is always easier than how do it. The important step is to hire a reputable firm to guide your organization through the planning, execution and lessons learned of a Business Continuity or Disaster Recovery Exercise so that the next time it works even faster and is without major flaws.

Monday, September 27, 2004

Fannie Mae Takes New Approach in Crisis...

By Jeffrey H. Birnbaum and David A. Vise
Washington Post Staff Writers
Monday, September 27, 2004; Page A01

Fannie Mae, one of Washington's largest and most influential companies, is facing a serious crisis. Federal regulators have accused the mortgage-finance giant of cooking its books, in part to make room for huge bonuses for its top executives.

When confronted with emergencies in the past -- legislative efforts to tax the company or to end federal ties that give it a competitive advantage -- Fannie Mae has used a brass-knuckles approach. Its political machine, comprised of hired lobbyists, executives and directors of both political parties and grassroots groups nurtured by donations from its foundation, has long been able to run over its adversaries.

But this time, Fannie Mae is acting differently. While whispering to Wall Street that all the fuss is nothing more than a difference over accounting interpretations, the company's board has commissioned an independent probe led by former Sen. Warren Rudman (R-N.H.), making it clear that the directors want to put the matter behind the firm even if it means throwing some top executives overboard.

'I don't think they have ever faced a crisis like this. Political muscle is not going to fix this problem,' said Washington attorney Bill Lightfoot, who tangled with Fannie Mae over tax issues while a member of the D.C. Council."

Sunday, September 26, 2004

Securities Industry Subject to Basel II...

Since 1999, Basel II has been coming to a bank near you in America: "At the time, the Federal Reserve announced that the top nine banks - some of which, such as JPMorgan Chase, Citigroup and Wachovia, have brokerage businesses in addition to commercial banking arms - would have to comply and adopt the advanced measurement approach for their capital adequacy requirements for credit and operational risks."

The US securities industry including firms such as Merrill, Goldman Sachs and Bear Stearns will now be subject to BASEL II under the SEC's Consolidated Supervised Entities regime. The big question is whether the smaller brokerages will adopt the same approach to operational risk as many of the smaller regional banks have done.

To improve their operational-risk-assessment capabilities, firms are targeting three initiatives, says Dushyant Shahrawat, senior analyst in TowerGroup's securities practice: upgrading core infrastructure, including building data warehouses; using integration and business-process-management technology to improve operations workflow; and exploring newer technologies such as Web services and grid computing to improve operational-risk management.

Thursday, September 23, 2004

DHS: Ready for Business launch today...

The Department of Homeland Security launches the Ready for Business Campaign at the US Chamber of Commerce today.

The extension of the Get Ready site for business is supported by the following organizations:

* ASIS International
* Business Executives for National Security
* The Business Roundtable
* International Safety Equipment Association
* International Security Management Association
* National Association of Manufacturers
* National Federation of Independent Business
* Society for Human Resource Management
* U.S. Chamber of Commerce

The private sector is responsible for securing the infrastructure that they own and that is vital to our nations economy. Then why haven't the large owners of commercial real estate invested in pervasive preparedness initiatives to "Get Ready" for business disruptions? The simple answer is that they don't have enough incentives to do so.

Unfortunatley for the people who happen to be tenants in the largest commercial office buildings, the landlords believe that it should be everybody for themselves. And as owners of stock in Real Estate Investment Trusts (REITS), your question should be: What is the company doing to better protect our corporate assets (buildings, malls, manufacturing plants, hospitals) from a myriad of operational risks, including catostrophic events such as tornados and terrorism?

If the DHS "Ready for Business" campaign does nothing more than get owners feeling guilty about their level of committment to preparedness, then it has done the first part of the job. The rest will be left up to business itself to demand that their leased facilities are more secure, have properly trained staff to handle incidents of any kind and exercises to test and learn on a continuous basis.

Tuesday, September 21, 2004

Phishing: Preventive strategies

As Symantec has recently been publishing their version of the losses sustained from Phishing, the vendors are busy trying to grab market share. Preventive strategies and tools to thwart Phishing attacks are getting more mainstream as companies respond to the new threats.

All of the social engineering that goes into "Phishing" scams will heavily out maneuver the vendors new tools. The consumer is still running windows without patches and will continue to click on bogus e-mail that looks identical to the ones coming from their bank. ScamBlocker, Phishnet and the rest of them will continue to evolve yet the financial losses will continue.

The Symantec point of view is nothing new. What is interesting is the increase of the number of "bots" and other malware roaming the web:

Symantec also recorded a rise in the detection of bots -- "programs that are covertly installed on a targeted system", according to the company, allowing the hacker to control the computer remotely -- from 2,000 detections per day to more than 30,000. The number peaked at 75,000 in one day.


Symantec said malicious code also increased by more than 4.5 times the number it was in the same period in 2003, equating to over 4,496 new Windows viruses and worms, with most aimed at the Win32 operating system.


Symantec says that phishing costs banks $1.2B. If this is true, you can bet who is paying for all of these operational losses.

Monday, September 20, 2004

SAS gains momentum...

More global companies have selected the operational risk measurement framework from SAS, and they seem to be gaining momentum in the marketplace.

The more than 10,000 loss events include events where losses were incurred due to inadequate or failed internal processes, people or systems as well as external events. These could be anything from failed hardware, forgery, embezzlement, and fraud, to natural events such as earthquakes and floods. When assessing the impact of operational risk scenarios on its business, Royal & SunAlliance will use the SAS data both in the scenario analysis process as well as a benchmark for its own internal data.

Friday, September 17, 2004

1SecureAudit ORM...

Operational risk management protects and enhances shareholder value. 1SecureAudit enhances shareholder value as a primary benefit of its impact on operational risk management (ORM). Clients utilize baseline knowledge, industry experience and ORM decision support to increase operational mission effectiveness by anticipating threats/hazards and reducing the potential for loss. Change and the speed of change continue to provide a challenging environment for the entire financial and health care services industry.

Some of the key trends include:

1. Innovations in products, technology and distribution channels

2. The effect of globalization and regulatory modernization

3. The convergence of capital markets and the ever evolving pace of competition

The many challenges facing health care and financial institutions today are forcing senior management to address the totality of risks and opportunities in various lines of business and in different markets and regulatory environments. Protection of critical infrastructure assets is a Homeland Security priority.

Thursday, September 16, 2004

Flawed FAA system: Operational Risk Super-Sized

The operational risk associated with process error is a major concern these days. Especially when a human is concerned with the continuity and safety of people flying every major airline in the Southwestern U.S.. According to several reports, an FAA worker did not update a flawed FAA system that handles critical communications between controllers and pilots.

The system that failed — a high-tech touch screen tool that allows air traffic controllers to quickly communicate with planes in transit — shut itself down at the Palmdale communications center shortly after 4:30 p.m. Tuesday after a worker did not complete required monthly maintenance.

Then, the backup system failed to work because technicians had rigged it improperly, FAA officials said.


When it comes to processes and the risks associated with them, a software system flaw such as this can cause tremendous business disruption at the minimum. It's the cost of human lives that gets situations like this as much news coverage as it has garnered already. The more interesting news is that these kinds of operational incidents occur in business daily and the public will never know about it. Unless they are on the magnitude of this event. ATM's shelling out too much money. Patients being prescribed the wrong drugs. Both are errors in the systems or processes associated with running a service business. What is more alarming and still yet on the brink of discovery is how much our rush to fix Y2K problems rushed our programmers in making shortcuts, eliminating proper security code at the application level and getting the applications online at the sacrifice of good quality assurance.

Don't blame the FAA. Blame the company they hired to develop the system at the lowest bid, and the highest cost to people who are exposed to it.

Wednesday, September 15, 2004

Risk Mitigation Training in Prep for Ivan

Hey New Orleans, got Hurricane Ivan yet? RMS predicts from $4 to $10B in damages.

Business continuity plans are being exercised. People are evacuating. Now we wait for the storm surge that could put New Orleans under 20 feet of water. What about the cities North who will no doubt be experiencing tornados and other severe weather as Ivan roars across Alabama?

Hopefully the owners of buildings and critical infrastructures have provided their employees and tenants with risk mitigation training. For an example of what WTG Properties in Washington, DC has done on this very topic, see this client case. Teaming up with Operational Risk Management firm, 1SecureAudit, they provided their tenants and staff with the training, tools and resources they needed to survive a catastrophic event.

Let's just hope the owners in New Orleans have done the same to prepare for Ivan.

Tuesday, September 14, 2004

Cyber Extortion Study is complete...

The Heinz School at Carnigie Mellon has finished it's survey on Cyber Extortion and some of it's findings are surprising.

Companies are still slow to implement preventive strategies and only 21% of the companies surveyed have formal education programs for their employees. Even more shocking is that 63% have not performed a security assessment in the last six months.

Although cognizant of the most commonly perceived security threats and countermeasures, (The most common types of attacks and misuse as reported by the participants of the CSI/FBI survey were virus attacks, unauthorized access and web use by insiders, and denial of service attacks. Ibid) businesses relying on IT often do not address one of the most complex and potentially damaging exposures: Cyber-extortion.

This research has two goals: First, generate the first academically available statistics on the advent and threat of cyber extortion against small and medium sized businesses. Second, create immediately usable guidelines for organizations that may be "at risk" to extortion. The guidelines will describe the most common methods extortionists use against their targets, how to ready your information infrastructures against this, and what to do if you become a victim of extortion - regardless if you plan to work with law enforcement or not.

Monday, September 13, 2004

Malicious Code: Managed Mail Protection Emerges

When the image contains text you might be vulnerable to a new scam online. This new advertising headline may soon be in vogue, Malicious Code: Managed Mail Protection Emerges.

In a new wave of phishing variants, companies like Citibank are constantly making changes in their systems to adapt to the new online threats from new malicious strategies.

"We continually modify our systems to enhance safeguards for our customers," said a spokesperson for Citibank, a unit of Citigroup Inc., in New York. "It is also important that consumers be aware of these issues and act appropriately."

While individual filtering tools from large vendors have proved largely powerless against the new threat, some security vendors are preparing help in the managed e-mail model as well.

McAfee Inc., of Santa Clara, Calif., will launch a Managed Mail Protection service for small and midsize businesses. The service, which may be extended to large enterprises in the coming months, comprises anti-spam, anti-virus and content filtering. All inbound e-mail goes through McAfee servers before it hits the customer network.

Saturday, September 11, 2004

Third Anniversary of 9/11

As We Mark The Third Anniversary of 9/11 one can imagine how the world will be in the next three years. A globe pock marked by terrorist incidents. Russia, Malaysia are of recent headlines. How soon will the terror strike the US again? Many say before the election and only then will we have what we need to reinforce what work has already been accomplished, and will never be completed.

The people of the free world know in their hearts that the struggles of real estate and religion will continue for decades to come. Only those who are proactive, preventive and aware of the continuously changing threat will survive.

God bless us all.

Wednesday, September 08, 2004

PWC Study on Risk...

PricewaterhouseCoopers has found the Ten Attributes they say leads to a world class risk management organization:

• Pay equal attention to quantifiable and unquantifiable risks
• Identify, report and quantify all possible risks
• Let an awareness of risk pervade the enterprise
• Make risk management everybody’s responsibility
• Avoid products and businesses the enterprise does not understand
• Accept that uncertainty exists
• Monitor your risk mangers
• Good risk management delivers value
• Define and enshrine your company’s risk culture.


They also say that reputational risk is the greatest threat in financial institutions. Phil Rivett, global leader, banking/capital markets group, PricewaterhouseCoopers said: “Financial institutions have made significant strides since our last risk management survey two years ago, but our latest findings have revealed that too many organisations are still concentrating on calculating market and credit risk to a further order of accuracy and too few on understanding the totality of the risks they face in order to give themselves a competitive advantage.

Tuesday, September 07, 2004

The Wheel of Misfortune

What are some classic cases of operational risk out of control? Check out The Wheel of Misfortune.

One of the best ways to develop risk awareness is to learn from others' mistakes. The Wheel of Misfortune contains instructive case studies of a dozen infamous financial disasters.

Each case study includes a description of the event, an analysis of what happened and exactly what went wrong, and the risk management lessons to be learned.


Your organization could do the same by creating a learning tool for existing and new employees. After all, the best way to keep awareness at a high level is to consistently place reminders about lessons learned.

Friday, September 03, 2004

WPA2 standard reduces risk

The new wireless networks in your enterprise are now becoming more secure as a result of the WPA2 standard,says the Wi-Fi Alliance.

WPA2 is ideally suited for enterprises in both the public and private sectors," said Frank Hanzlik, Wi-Fi Alliance managing director. "Products that are certified for WPA2 give IT managers the assurance that the technology meets interoperability standards and in turn helps them manage support and deployment costs."

The 802.11i standard has components of WPA2 already embedded in it and should make the enterprise Wi-Fi solutions finally worth considering on a more enterprise scale. Those organizations who have already deployed previous standards are wide open to vulnerabilities and interception of their sensitive data transmissions.

Thursday, September 02, 2004

The summer of 2004...

The Terrorism Risk Insurance business is on the rise according to a recent Marsh Report on Terrorism Risk. The percentage of policy holders who buy terror coverage increased from 44% to 46% by midyear.

In November 2002, President Bush signed the Terrorism Risk Insurance Act (TRIA) into law. TRIA made it illegal for providers of property & casualty (P&C) insurance to exclude terrorism coverage in their policies. Still, the act did not specify how much insurers could charge for the coverage, and as a result, the price for TRIA coverage varied greatly.

The summer of 2004 will continue to be a prime window for the “What if” discussions of potential terrorist attacks on United States assets located domestically or abroad. It is important to remember several key items as we move into more proactive, preventive and preparedness modes within our global organizations and U.S. based business communities.

The soft targets for these catastrophic plans by our terrorist enemies will continue to focus on the places, events and structures that will provide the most impact, both in loss of life and the long-term economic impact. Based on analysis by RMS in their latest Catastrophe, Injury and Insurance study, the study looks at those cities with the highest density of population at 2:00PM. In the RMS report, New York, Chicago and Washington DC are the top three cities in the US for potential impact of a terrorist incident. San Francisco, Boston, Philadelphia and Los Angeles are next in the line up of populations that are the highest density within several miles of the city center.

The five factors for anti-terrorism threat analysis are Existence, Capability, History, Intention and Targeting. Further defined as follows:

1. Who is hostile to the asset?
2. What tools/weapons have been used in carrying out past attacks?
3. What has the threat element done in the past and how many times?
4. What does the potential threat element or aggressor hope to achieve?
5. Do we know if an aggressor is performing surveillance on our building / asset?

When answering these questions for your particular building, city, business park or community you should keep in mind the goal of our attackers. They want to do the most harm to the most number of people for the longest period of time. While we may not be able to totally prevent a planned incident from happening, we can reduce the impact on our personnel, property and business operations.

Wednesday, September 01, 2004

Frances Slams Allstate's stock

Frances Slams Allstate's stock upon fears that the hurricane is going to make landfall any day in Florida.

Shares of Allstate Corp., Ace Ltd. and other insurers fell today as Hurricane Frances approached the Florida coast, threatening to become the second storm packing 140- mile-per-hour winds to hit the state in three weeks.

The impact to the bottom line goes far beyond just the claims by it's customers. In this case, the institutional investors are taking a profit after a 50% increase over the past 18 months.

The other possibility is that they may already be "stretched" after hurricane Charley. Should Frances make landfall in Florida with its current wind strength, it would mark the first time since 1915 that two storms of that magnitude hit the U.S. in the same year, the Miami- based hurricane center's data show.