Friday, May 19, 2006

Hurricane Preparedness Week: May 21-27...

"Preparation through education is less costly than learning through tragedy."
- MAX MAYFIELD, DIRECTOR
NATIONAL HURRICANE CENTER

History teaches that a lack of hurricane awareness and preparation are common threads among all major hurricane disasters. By knowing your vulnerability and what actions you should take, you can reduce the effects of a hurricane disaster. This year Hurricane Preparedness Week is May 21-27, 2006.

As NOAA will announce the 2006 Atlantic Hurricane Season Outlook at 11:00 AM EDT Monday, one can only wonder if we will have more than the 26 named storms last year. The preventive measures that have taken place are many and yet are we still as prepared as we could be? The 2005 hurricane season, the busiest and most destructive on record with 28 named storms, 15 of them hurricanes, has made many people along the Atlantic and Gulf coasts more wary as they prepare for a 2006 season. This year, researchers predict 17 named storms, including nine hurricanes.

In the 2005 Business Continuity - The Risk Management Expo survey of 251 companies raised many questions about the 30% who said they did not have a Business Continuity plan in place. The key concerns are as follows:

1. Even if there was existence of a plan in 70% of the respondents, only 27% of the key personnel are even trained on the plan.

2. Does the plan cover all hazards of just the ones that have been prioritized by the key staff?

3. How does staff communicate to their employees during the crisis?

4. How would share holders, institutional bond holders, and the board view the company when they find out that the company doesn't have or hasn't exercised their crisis management plan?


In any plan, people are the key to business recovery and survivability. And in post disaster analysis, little consideration was given to the supply-chain. The vendors, suppliers and service organizations that keep your corporate operations running each day. Many suffered tremendous delays in the recovery process because contingencies were not in place prior to the crisis event.

Communications is always the biggest failure during times of crisis. When the primary communications systems fail, that is when you will know if you have been training enough. Victims will soon find out how well you have prepared. Accurate, timely, consistent and relevant information are the foundation for any resilient framework for communications. Most city, state and federal emergency-management authorities still can't communicate by phone or radio in a crisis, because a $2 billion special outlay for so-called "interoperability" is mired in legislative wrangling or being spent without federal coordination.

Wednesday, May 10, 2006

Flu Pandemic: NIMS to the Rescue...

An operational risk benchmarking survey conducted by The Risk Management Association in April 2006 indicates that many financial institutions are preparing for a possible flu pandemic.

Key findings are:
-- Large North American institutions with asset sizes greater than $10 billion are taking the threat seriously. Least concerned are banks with assets of less than $500 million.
-- Most banks expect disruptions to last three to nine months.
-- Two-thirds expect 30% or more of their key workers to be absent during peak periods of disruption.
-- More than 60% have identified someone to lead the planning, but less than a third have rolled out plans and begun regular testing.
-- Only about a third of banks are well along in establishing policies for such things as employee compensation, evacuations, and reducing workplace transmission of risk.

Participants in RMA's "How Serious Is the Threat of a Pandemic and What Are Bankers Doing about It" included 190 financial institutions. Of those, 168 are from North America, 14 from Europe, and eight from Asia, Australia, and Africa. The results are broken out by geographic area and asset size, with respondents' asset sizes ranging from under $500 million to over $500 billion.


Continuity of Operations and Business Crisis Conintuity Management experts are prepared to handle the requirements from the two thirds of the banks who still HAVE NOT begun regular testing. Along with the typical exercises where a third of the work force stays home for a day to see how the IT assets handle the load, there is much to do with the testing of your third party suppliers and critical supply chain vendors.

Make sure that the people you trust to get you through the tests, exercises and consulting advice are NIMS compliant. The National Incident Management System (NIMS) in the US is the standard for a comprehensive, national approach to incident management that is applicable to a full spectrum of potential incidents. This includes a myriad of hazard scenarios, regardless of size or complexity.

All corporate officers who plan on being part of the Unified or Area Command must have the tools and the training far in advance to accomplish COOP or BCP goals. Here is the scenario:

"An outbreak of a suspicious flu-like virus has broken out throughout the State. So far, victims seem to have contracted the virus through personal contact, but public health officials cannot trace the source of the virus to naturally occurring outbreak. Because the contamination area is spreading, the entire region has been placed on alert. This incident should be managed by an Area Command."


Using Incident Command System (ICS) protocols in combination with the NIMS framework allows the organization to become more resilient to the risks associated with a major disruption in business operations. This may include denial of service, both online and offline, lack of key personnel, or quarantine of company facilities. For more information and answers to how to get your company NIMS compliant and ready for the next tornado, hurricane, earthquake or terrorsit incident, see WashingtonDC FIRST.

Monday, May 08, 2006

Criminal Intent: Digital Surveillance Dominates Q1...

Seventy percent of malware detected during the first quarter of 2006 was related to cyber crime and more specifically, to generating financial returns. This is one of the conclusions of the newly published PandaLabs report, which offers a global vision of malware activity over the first three months of the year. Similarly, the report offers a day by day analysis of the most important events in this area. This report can be downloaded from Panda.


This report confirms the trend of criminal intent of the developers of malicious code to steal information for financial gain. Most successful are the bots and spyware code that lives silently on your corporate executives lap top after spending a week away traveling. Since the tendency for using "Free WiFi" exists in many hotels and other travel zones, the lap top becomes vulnerable to an infection. And when that lap top is reconnected to the docking station back at HQ, the real threat begins.

Digital Surveillance using malicious code is not new. The art is now a science. Ask any 19 or 20 year old in the Engineering or Computer Science Department at a major university. The use of spam and other techniques for spreading the use of the malicious code makes it imperative that your detection and defense strategies are sound and operating on a daily if not hourly basis. Organizations are under a barrage of attacks that are random and sophisticated, and are deployed with a multifaceted approach to gain the required exploit results. These new blended threats include a salvo of virus and worm technology into an smart and yet elusive attack vehicle.

According to FBI studies, more attacks are propagated and launched internally than externally. Companies are deploying internal intrusion detection systems that place monitors or agents on multiple department segments, and e-mail anti-virus systems that prevent viruses from moving.


Many organizations are exploring new devices that IDC has coined Unified Threat Management(UTM) appliances: Effective UTM requires:

* Low total cost of ownership. Total system costs must be less than the expected loss if there are security breaches due to lack of control. The solution must decrease the time to protection and ongoing overhead to achieve a lower total cost of ownership. Security threats are constantly changing, and the system must adapt to these changes on a constant basis with little to no user intervention.

* Coordination. Security breaches can occur between mismatched technologies, so whenever possible layer the security approach. Since many threats have multiple attack signatures, one layer prevents a certain portion of an attack while another layer catches the rest. The network’s security posture must adapt in unison for comprehensive protection.


* Reduced complexity.
To achieve maximum security, solutions must be easy to implement, and the components must work well together; if not, incident detection (and resolution) becomes difficult if not impossible. Vital considerations include time-to-response and automation of appropriate protection.

Consider an evaluation of SonicWall to find all three advantages in your enterprise.

Wednesday, May 03, 2006

The Risk of External Supply-Chain Interdependencies...

In what countries do you operate? Do you source raw materials from politically unstable regions of the globe for your end products? Are you subject to a myriad of taxes, tariffs and duties including new security measures in our ports? How complex is your sales and distribution channels? At the end of the day the big question is: What is my financial, operational and economic risk exposure in the event of a disruption in our external supply-chain?

The risk of external supply-chain interdependencies has been talked about for many years. Monte Carlo simulations, scenario analysis and other methods have been effective in the determination of what the magnitude of a loss event may look like. Once the dollar analysis is done and you know that your exposure is $XXM. or $XB., then what do you do with that information?

Much of the outcome of this exercise may go into the next strategic planning phase on who you need to partner with or create an alliance with in order to satisfy certain future contingencies. Once you realize that you need more than one source for a raw material or a key service to run your business, then the real analysis begins. Who and where do I find the best alternatives for this vital component in my global supply-chain?

If you begin your due diligence now on the top 10 vital components in your supply-chain contingency planning exercise you might have these all completed, through the legal department and signed within a few months time. If you are lucky. Then you must really test the new supplier or source for your product or service to determine how smooth they operate when you pick up the phone or send the "Alert".

The ultimate architecture requires an "Adaptive Supply-Chain" that will provide cross-border agreements and resilient mutual-aid partners to assist in times of crisis. Just shifting production from one country to another may not be enough to mitigate the disruption in a vital component of the manufacturing process or delivery of services. Having a reflexive and responsive supply-chain is only one of many contingencies in a robust Business Crisis and Continuity Management plan.

When was the last time you reviewed your key suppliers and sourcers plans for continuous operations and their record for testing these plans? This will be the place you find your greatest weakness in external supply-chain management. In the US, it is now less than 30 days away from the next hurricane season. Gasoline prices and fuel costs are impacting every sector of the economy. One thing is for sure. You are in complete control of your readiness factor. And your readiness factor is directly proportional to your interdependencies in your supply-chain.

Friday, April 28, 2006

Bank Fraud | Chicken Little | Las Vegas. Learn the Connection...

The quest to tame bank fraud and money laundering is upon us. The OCC and other reg agencies in the US are finding the needles in the haystack. This latest Money Laundering Terrorist Connection is only the first of many such investigations:

The brother of a man suspected of ties to the al-Qaida terrorist group has been arrested in Utah and indicted on charges of loan fraud and money laundering. The question that federal authorities are trying to answer is whether Sharif Omar funneled some of that money to support terrorist activities. Omar is the brother of Shawqi Omar, who is being investigated for ties to al-Qaida in Iraq.

"We do have some indications of where the money went," said Greg Bretzing, a special agent with the FBI's Joint Terrorism Task Force in Utah. "We know some went to Jordan overseas and a lot went to personal accounts. What exactly it was spent on or what happened to it overseas is still under investigation."


And if that is not all the bankers have to worry about. International Phishing is gaining momentum:

The number of phishing attacks targeting non-English speaking financial institutions is on the rise.

Attacks targeting countries outside the English-speaking world now represents almost 40 per cent of worldwide phishing targets, according to data processed by RSA Security's Anti-Fraud Command Centre. RSA said it has shut down more than 10,000 phishing attacks hosted in 70 different countries.
Click here to find out more!

The primary phishing targets worldwide still remain English speaking countries such as the US and the UK, followed by Australia and Canada. The United States alone accounts for approximately half of fraudulent email attacks. Over the last six months or so there's been an upswing in attacks targeting European countries, including Spain, Germany and Italy, as well as the Netherlands, Scandinavia and France.


What is the answer to mitigating these Operational Risks in your institution? Look no further than the line items in the budget for safety, security and continuity of your next fiscal year. After the last three days at the GovSec|U.S. Law Enforcement| Ready Conference I'm convinced that the likes of people who are technology experts from firms like Akamai, Asst. Deputy's and former operators of 3 Letter agencies along with hundreds of other small business vendors for Homeland Security solutions have the same play book. It's titled: Chicken Little. Because the sky is falling. Every once in awhile it would be refreshing to see and hear a presentation about risk, security, safety and business continuity when the speaker is not talking about or yelling about how the "Sky is Falling" and the money isn't there to fix the problems.

Why is it that the people who are doing all of the presentations and speaking are from non-profits, government or lobby shops in DC? They are the people the private sector pays to get influence for their projects in Congress and they have to make sure they keep getting the funding to keep up their campaigns.

Bank fraud and Phishing will not ever be solved with more money from the US Treasury or any other countries reserves but it doesn't hurt to ear mark a percentage of revenues to fund the budget for safety, security and continuity of operations. If only some companies would behave like the pinnacle of publicly traded, high target and continuously operating organizations known on the planet as Las Vegas Casino Hotels.

For a real look into what the banks and other institutions, either public or private need to do to mitigate risk, protect assets and keep the enterprise safe, secure and operating 24/7 and 365 days a year, see InfraGard Nations Capital Members Alliance

Monday, April 24, 2006

AML & Data Theft: Risks to International Banks and Domestic Universities...

If you are a parent of a son or daughter at an institution of higher learning, this is a notice that makes you shake your head in disappointment. And if you are Chief Information Security Officer at University of Texas - McCombs you wonder how this could happen again?

Unauthorized Access of Computer Records Discovered at The University of Texas at Austin

AUSTIN, Texas –The University of Texas at Austin officials announced today (April 23) that an unknown person or persons has gained entry to the McCombs School of Business computers and gained unauthorized access to a large number of McCombs’ electronic records.

“It is our highest priority to notify those who may be affected by this security breach,” said university President William Powers Jr. “We have notified the attorney general and his Internet enforcement unit and are doing everything we can to protect those whose information has been accessed unlawfully.”

The security violation was discovered late Friday, April 21, and the university has devoted all available resources to identify the extent and source of the breach. Some of an estimated 197,000 records were accessed.

An investigation has determined that information from the business school’s computer system was obtained as early as April 11, including some Social Security numbers and possibly other biographical data, including those of alumni, faculty, staff and current and prospective students of the business school as well as corporate recruiters.


Even though the transnational nature of data theft is a major financial concern for law enforcement, the banking community and those potentially consumers impacted at this university, there are other priorities that may be of greater risk to US financial institutions. Money Laundering and the enforcement of the Bank Secrecy Act (BSA) is a continued United States Treasury priority along with the Office of the Comptroller of Currency (OCC).

Metropolitan Bank & Trust is one of the latest institutions to be penalized for violations of BSA.

An examination of Metrobank by the Office of the Comptroller of the Currency found deficiencies in Metrobank's anti-money laundering program, revealing that Metrobank had failed to implement an adequate system of internal controls to ensure compliance with the Bank Secrecy Act and manage the risks of money laundering involving funds transfers. The examination also revealed that Metrobank had failed to conduct adequate independent testing to allow for the timely identification and correction of Bank Secrecy Act compliance failures. These failures in internal controls and independent testing led, in turn, to failures by Metrobank to identify and report suspicious transactions in a timely manner. The failures of Metrobank to comply with the Bank Secrecy Act and the regulations issued pursuant to that Act were
significant.

Metrobank and Metro Remittance handle large volumes of funds transfers involving the Philippines and, since September 2003, the People's Republic of China. The volume of funds transfers to the Philippines in 2003 was 162,000 transactions totaling $208 million. Prior to February 11,2005, the Philippines was included in the list of Non-Cooperative Countries or Territories designated by the Financial Action Task Force on Money Laundering.


While this civil penalty will result in a fine of only $150,000., you could predict that the cost will be much higher. A system implemented to assist with due diligence installed in 2003 has not been effective and the use of manual controls is the source of much of the banks failures in a fully compliant Anit-money laundering (AML) program. The passage of the USA PATRIOT Act, after the terrorist attacks of September 11, 2001, has placed greater emphasis on AML issues. Increased scrutiny of potential laundering, and stringent requirements placed on institutions to increase their efforts to detect money laundering by terrorist groups, reinforces the importance of the need for certified professionals who protect institutions from potentially devastating laundering crimes.

The lack of oversight by banking institutions or universities comes back to a single aspect of Operational Risk Management. Without a framework for managing risk of all kinds and having an effective system for continuous risk monitoring, you are setting yourself up for a major loss.

Wednesday, April 19, 2006

The Next Wave of Operational Risk Innovation...

Today, if you are reading this blog you may have found your way here from Yahoo like tens of thousands of others have. Or maybe from another source on the web. However, when you search for Operational Risk Management at Yahoo, you get This Blog at the top of the first page of search results. Try searching on the same exact terms on Google, and the blog doesn't make the cut for the first page of search results. When you are searching for relevant information on "Operational Risk Management" (ORM), it's always important to look in more than one place and use more than one search engine. That's just life on the Internet in this age of paid advertising and mathmatical decisions on who deserves the top spots on search results.

Several years ago, there where only a few people who really had any idea what Operational Risk was all about. The US Navy / Marine Corps for one. They know that the work they performed was full of hazards and risk. If they didn't do something to systematically reduce operational risks in every process they performed or mission they executed, they knew that more people might be injured or die.

And what is the Navy's definition of ORM:

ORM is a decision making tool- used by people at all levels to increase operational effectiveness by anticipating hazards and reducing the potential for loss, thereby increasing the probability of a successful mission.

ORM is an effective tool for maintaining readiness in peacetime and success in combat because it helps conserve assets so they can be applied at the decisive time and place.

Applying the ORM process will reduce mishaps, lower injury and property damage costs, provide for more effective use of resources, improve training realism and effectiveness, and improve readiness.


At the same time, you have the Global Financial community wrestling with something called Basle:

The Basle Committee on Banking supervision has recently initiated work related to operational risk. Managing such risk is becoming an important feature of sound risk management practice in modern financial markets. The most important types of operational risk involve breakdowns in internal controls and corporate governance. Such breakdowns can lead to financial losses through error, fraud, or failure to perform in a timely manner or cause the interests of the bank to be compromised in some other way, for example, by its dealers, lending officers or other staff exceeding their authority or conducting business in an unethical or risky manner. Other aspects of operational risk include major failure of information technology systems or events such as major fires or other disasters.


The prudent Risk Manager today can see the similarities in what the US Marines and the Bankers are trying to accomplish. The good news is that the convergence of what the military has known for years and the knowledge that the bankers have gained from having their institutions fail, provides us with a vast foundation to begin the next wave of innovation.

The innovations surrounding Operational Risk Management are upon us. Now it's our duty as practitioners to "Walk the Talk" and to "Practice What We Preach". Get busy!

Sunday, April 16, 2006

The Speed of Loss in the Connected Economy...

Operational risks are also becoming more important in the large, complex financial institution as more technology and automated processes are used in all areas of operations. When banks used manual processes, errors were confined to the limited area where the employee worked. But in a modern technology setting, factors such as breakdowns in controls, errors in software code, and processing stream interruptions can have enterprisewide effects on the performance of the organization.

Recent history provides us with ample evidence that operational risk can be significant. Large financial institutions have reported operational losses from breakdowns in operating controls that, in some cases, have exceeded their credit- or market-related losses. In the area of legal risk, for example, many institutions have learned that failing to identify and promptly correct problems can result in losses that significantly exceed management's initial expectations. Over the past decade, large financial institutions have experienced more than 100 operational loss events in excess of $100 million each; some of these individual operational losses, resulting from fraud, rogue trading, and settlements stemming from questionable business practices, have exceeded $1 billion.


These remarks by Ms Susan Schmidt Bies, Member of the Board of Governors of the US Federal Reserve System, at the OpRisk USA 2006 Conference reflect a growing emphasis on Operational Risk. This focus translates to a greater regulatory attention to the quality of data that institutions are utilizing for their calculations.

The level of data quality has been a management challenge for decades. The speed of change in the connected economy has created an even larger tempest for institutions to grasp. The physical and logistical problems associated with moving, archiving and retrieval is only part of the data puzzle. As Ms. Schmidt Bies has so clearly concluded, the simple fact that "Automation" creates an even larger field of risk to monitor, provides an even greater opportunity for failure. The absence of data doesn't decrease the amount of risk. What risks should we focus on? The normal and expected risks from external data, or the unexpected risks that have been encountered before.

If you think about the places where the velocity of data is the greatest, then you have a place to begin. The processes and business functions associated with traditional annual financial audits and other external data give us a known history of loss events that need continuous scrutiny. However, it is those key risk indicators (KRI's) in places where the insitutions knowledge of the root operational risk causes combines with little or no history of losses that remains the nexus for concern.

Thinking beyond the current horizon is where the focus should be on active risk management scenarios.

Wednesday, April 12, 2006

CRO Strategy: Balancing Risk Across Functions...


RiskCenter (04/04/06) ; Kloman, H. Felix
At a recent Global Association of Risk Professionals (GARP) conference in New York, risk managers highlighted the importance of accurate data being provided to the appropriate decision makers in order to make the best decisions for a given situation, and risk managers also noted that they needed to be independent and objective at all times. Risk management tasks should not be absorbed by finance, accounting, or compliance functions, according to experts, because balance is needed between those functions and the risk managers' function as an educated "fortune-teller."

Chief risk officers (CRO), for instance, should be familiar enough with operational functions, while still remaining outside the internal politics of those functions, allowing them to make educated and objective decisions. Panelists at the conference touched upon the learning experiences they had from risk management mistakes and how they turned those mistakes into opportunities for their firms. For risk managers in the banking sector, Basel II is the latest challenge, especially when it comes to allying risks with capital holdings and the disclosure of how those calculations and decisions were made.


CRO's today are coming from more diverse backgrounds than from years past where they may have lived most of their careers in Finance or Internal Audit. Educated fortune tellers are a thing of the past as new tools, systems and sensors provide the modern CRO with new insight. As new tools are introduced to financial institutions to assist them with creating and mining loss event data, the regulators will be watching. What methodology and frameworks are acceptable? What process was utilized for critical calculations?

Lenders that are not banks or owned by banks--and therefore not subject to FDIC rules--are regulated by states. With the growth of these aggressive and potentially deceptive lending practices, state regulators have come under pressure to issue new rules or guidance to ensure that these "exotic loans" do not continue unchecked.


A Chief Risk Officer needs to be active with both state and national associations to keep in touch with the guidance that may be forthcoming.

Monday, April 10, 2006

Coaching to Mitigate Risks on the Front Line...

HR Troubles are growing in the corporate ranks.

New and various studies reveal that unethical activity continues to occur in the private sector, even while SOX watch dogs are in place and whistle blowers are amoung us. Studies also suggest that large investments in compliance programs have had little impact. Indeed, 16 percent of HR professionals say they have quit their jobs for ethical reasons, according to a 2005 survey by SHRM, the top five ethical lapses given for resigning are:

Lying by management

Title VII violations

The falsification of reports and records

Employee privacy violations

Employees committing fraud


It's not surprising that these compliance programs may be having trouble getting the human behaviors to change. Coaching employees on a regular and consistent basis is far more effective than a one-time class upon hire. Management behavior is the litmus test on whether the culture of an organization could have the potential to become more ethical.

The enforcement of ethical and legal issues is often left up to corporate human resources (HR) departments, when it should be handled daily by front line managers. This is where the behavior or incident is observed in real-time and has the most credibility for making a coaching or serious discussion successful.

Thursday, April 06, 2006

Phishing: Why it Works and What is Next...

If you have ever wondered Why Phishing Works, you need to read this article by Rachna Dhamija at Harvard University, J. D. Tygar, and Marti Hearst from UC Berkeley.

What makes a web site credible? This question has been addressed extensively by researchers in computer-human interaction. This paper examines a twist on this question:

What makes a bogus website credible?
In the last two years, Internet users have seen the rapid expansion of a scourge on the Internet: phishing, the practice of directing users to fraudulent web sites. This question raises fascinating questions for user interface designers, because both phishers and anti-phishers do battle in user interface space. Successful phishers must not only present a high credibility web presence to their victims; they must create a presence that is so impressive that it causes the victim to fail to recognize security measures installed in web browsers.


The phishers are very good and spoofing financial services web sites to the tune of more than 2 million users being fooled last year alone. The web site designers are doing their best to create a site that is so sophisticated in it's look that it is more difficult to replicate on a fraudulent site and URL. The point is, we as consumers are always being asked for information only we would know, or information that we have to authenticate ourselves.

Why can't we turn this problem upside down? Why can't I authenticate the banks web site by asking the bank for a piece of information that only they have or would know the answer to? Some tools and technologies already exist to help with this upside down thinking. Bank of America is using SiteKey, that retrieves a graphical image from it's database, one that I have personally picked and no one else "should" be able to replicate. The answers are on the way.

Chris Young
Senior Vice President and General Manager, Consumer Solutions Division
RSA Security

As senior vice president of the Consumer Division at RSA Security, Christopher Young is responsible for driving the company’s consumer identity protection strategy, including the delivery of RSA® Authentication Service to provide simple and secure layered and two-factor authentication to all online users.

Cyota FraudAction Service is just one example of some new and exciting anti-fraud solutions on the way.

Friday, March 31, 2006

An OPS Risk Refresher...

What are Operational Risks? Here is a refresher for the Financial Services Sector:

Key People Risks

Employee fraud or malice Including collusion, embezzlement, sabotage of bank reputation, money laundering, theft of physical and intellectual property, programming fraud including virus introduction

Unauthorized activity
Including misuse of privileged information, churning, market manipulation, activity leading to deliberate mis-pricing or with unauthorized counterpart or unauthorized product, limit breach, intentionally incorrect models such as deliberate changes to parameters, activity outside exchange rules, illegal/aggressive selling tactics, Ignoring/short-circuiting procedures deliberately

Employment law Including wrongful termination of employment, discrimination/equal opportunity, harassment, non-adherence to other employment law, non-adherence to Health and Safety regulations Workforce disruption Industrial action and other forms of disruption

Loss or lack of key personnel Lack of suitable employees and loss of key personnel



Key Systems Risks


Technology risk
Inappropriate architecture

Investment risk Including strategic platform or supplier risk, inappropriate definition of business requirements, incompatibility with existing systems, obsolescence of software

Systems development and implementation Including inadequate project management, cost/time overruns, programming errors (internal/external), failure to integrate and/or migrate from existing systems, failure of system to meet business requirements

Systems capacity
Including lack of adequate capacity planning, inadequate software Systems failuresIncluding network failure, interdependency risk, interface failure, hardware failure, software failure, internal telecommunication failure

Systems security breaches
Including external security breaches, internal security breaches, programming fraud, computer viruses


Key External Risks

Legal/public liabilities Including breach of fiduciary duty, etc. Criminal activitiesIncluding money laundering, terrorism, robberies, etc.

Outsourcing/supplier risk Including breach of service level agreement, supplier failure, etc.

Insourcing risk Including failure of firm as supplier of services to third-party

Disasters and infrastructural utilities failures Including fire, flood, and failure of critical supplies etc.

Regulatory risk
Including change of regulatory rules etc.

Political/government risk
Including expropriation of assets, changes in tax regime, law and industry regime, etc.

Remember, this does not even cover the largest category of Operational Risk, Processes. The process associated with our different procedures, protocols and mechanisms for doing business are one of the greatest areas to incur loss events. Errors, ommissions and lack of training are just a few of the areas that need to have consistent monitoring and continuous auditing.

Friday, March 24, 2006

Availability Bias: The Risk of Low Probabilities...

Should corporate America be concerned about weapons of mass destruction? How do you prepare for risks beyond your own workplace? Rad Jones from the School of Criminal Justice, Michigan State University, recently talked about a critical incident exercise he has prepared exclusively for CSO Magazine.

Rad Jones, formerly with the Secret Service and later on security projects with Ford Motor Company, emphasizes that you don't have a plan unless it has been exercised. This is especially true if you have not involved the local first responders in the local area. Role playing in exercises on scenarios that are real world and done on premises is a key component of the preparedness equation. What is left out in many instances during the exercise with the local police, fire or EMS is the Incident Command with the top brass or executives who may be in other locations across the country or the globe. This was witnessed in the Hurricane Katrina catastrophe.

Every metro area in harms way has the ability to do these exercises even on a micro basis. The single 15 story building, the business park surrounding the suburban mall or hotels and even a square block in a downtown city location is a good start. This coordination, planning and continuity builds a new level of resilience into the fabric of the community. This effort has been going on since 2003 with a consortium in Chicago, IL called ChicagoFIRST. This particular effort was spearheaded by the large financial institutions in the city who wanted to get a say and a seat inside the JOC (Joint Operations Center).

The spirit of ChicagoFIRST is spreading with the launch of WashingtonDCFIRST, a consortium based in the Wasington DC metro area. This project will be focused on the critical infrastructure private sector and the relevant interfaces to the local first responder jurisdictions. Collaboration with the Council of Governments (COG) will add the planning already underway for the past few years on issues such as interoperability and credentialing. As an example, the FCC has adopted a plan to establish a Public Safety and Homeland Security Bureau. The new Bureau is designed to provide a more efficient, effective, and responsive organizational structure to address public safety, homeland security, national security, emergency management and preparedness, disaster management, and other related issues.

Unlike other private sector initiatives, WashingtonDCFIRST will involve all the critical infrastructure sectors and the private companies who represent the largest employers around the beltway
including: Pepco, Verizon, Washington Gas, Exxon Mobil, AOL, and the Water Utilities. Much of the focus will be on availability bias.

Availability bias is why the U.S. has spent the past four years focusing on scenarios involving terrorism, after the so-called failure of imagination that preceded 9/11. What have politicians and citizens done for the past four years if not imagine terrorism?

And it's why many observers are now questioning whether the country should have spent that time planning not for terrorism but instead for other potential catastrophes. Like a deadly pandemic. Or major earthquake. Or hurricanes.

"One of the key dangers is that people are always focusing on the last catastrophe," says Robert Muir-Wood, the London-based chief research officer for Risk Management Solutions, which does economic risk modeling for the insurance industry. "It's a big challenge to keep everything in perspective and not be biased by what has last happened."

A true risk-based approach means that, when all else is equal, one must override the availability bias and focus on the most likely future scenarios. Unfortunately, figuring out the probability of any given scenario raises its own set of complexities.


The most probable risks that you train and exercise for, will be the incidents that you will be most prepared to handle. Suffice it to say, that the risks that you don't plan for because they are too low probability, will be the incidents or catastrophes that catch you off guard. Think about it. Not preparing and training for the low probability scenarios could cost you millions or billions and maybe your life.

Wednesday, March 22, 2006

Pandemic Flu: Financial Institutions Contingency Strategies...

The Board of Governors of the U.S. Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and Office of Thrift Supervision are issuing an interagency advisory to financial institutions and their technology service providers.

This advisory is intended to raise awareness regarding the threat of a pandemic influenza outbreak and its potential impact on the delivery of critical financial services. It further advises financial institutions and their service providers to consider this and similar threats in their event response and contingency strategies. This issuance discusses the National Strategy for Pandemic Influenza (National Strategy) and the roles and responsibilities it outlines for financial institutions.

Critical infrastructure entities also must be engaged in planning for a pandemic because of our society’s dependence upon their services. Both the private sector and critical infrastructure entities represent essential underpinnings for the functioning of American society. Responsibilities of the U.S. private sector and critical infrastructure entities include the following:

• Establishing an ethic of infection control in the workplace that is reinforced during the annual influenza season, to include, if possible, options for working offsite while ill, systems to reduce infection transmission, and worker education.

• Establishing contingency systems to maintain delivery of essential goods and services during times of significant and sustained worker absenteeism.

• Where possible, establishing mechanisms to allow workers to provide services from home if public health officials advise against non-essential travel outside the home.

• Establishing partnerships with other members of the sector to provide mutual support and maintenance of essential services during a pandemic.


For more information see the official U.S. Pandemic Flu site.

Thursday, March 16, 2006

Whistleblowers: The Risk of Unethical Corporate Behavior...

To some people, Sherron Watkins is a hero. To others, she is an Enron Whistleblower that has capitalized on her now famous memo.

Ms Watkins had previously sent Mr Lay an anonymous memo questioning the use of off-balance sheet financial partnerships which were then running up huge losses.

In the memo, which she read out in court, she had expressed concerns that Enron could "implode in a wave of accounting scandals".

She added: "This was not just aggressive accounting, it was fraudulent accounting. I couldn't believe we had done it."


Implementing an effective ethics and compliance program in corporations requires a robust educational and legal strategy. Awareness development, effective policy design and administration is imperative if the organization is going to have any chance of achieving high marks in Corporate Governance.

David Gebler makes some valid points in this article:
Moving in the Right Direction

How do compliance leaders move their organizations to these new directions?

1. The criteria for success of your ethics program must be outcomes-based. Merely checking off program elements, even from the seven steps of the Federal Sentencing Guidelines, is not enough to change behavior.

2. Each organization must identify its own key indicators of its culture. Only by assessing its own ethical culture can a company know what behaviors are the most influential in effecting change.

3. The organization must gauge how all levels of employees perceive adherence to values by others within the company. One of the surprising findings of the (2005 National Business Ethics Survey) (NBES) was that managers, especially senior managers, were out of touch with how non-management employees perceived their adherence to ethical behaviors. Non-managers are 27 percentage points less likely than senior managers to indicate that executives engage in all of the ethics-related actions outlined in the survey.

4. Formal programs are guides to shape the culture, and not vice-versa. People who are inclined to follow the rules appreciate the rules as a guide to behavior. Formal program elements need to reflect the culture in which they are deployed if they are going to be most effective in driving the company to the desired outcomes.


While there may be some who say that a whistleblower is just a discouraged or passed over employee, it may be the origin of a corporate environment that is ready to implode. Fraud and other unethical corporate behavior is a combination of poor operational risk management controls and the people who perpetuate the culture of dishonesty. In a recent survey by Protiviti, companies continue to admit to poor risk management practices.

Other findings of the survey:

* 43 percent of executives consider financial reporting and Sarbanes-Oxley Section 404 compliance to be very significant risks.

* 49 percent tie business success to client satisfaction, believing potential weaknesses in this area pose a very significant risk. Executives said the following risks affect their company's ability to sustain customer satisfaction: operating performance; materials procurement; business continuity; and fraud matters.

* 45 percent of executives cited information systems and IT security as potential areas of vulnerability.

Friday, March 03, 2006

Keeping Your Business Clean...Revisited

This two year old article is still so true. Worth revisiting in a more risk management conscious corporate environment.

Keeping Your Business Clean - CSO Magazine - June 2004

Take this quiz to test the ethical health and well-being of your business.


BY ANONYMOUS

A COLLEGE PAL OF MINE—a corporate lawyer at a major, publicly traded company—has been watching all of the corporate-integrity meltdowns from his not-so-distant vantage point. Just for fun, he helped me devise a quiz of sorts to check out the "uprightness" of my own situation at my company. I was shocked and disturbed enough with my results to share them here (under the protection of anonymity, of course).

Maybe I'm a good Samaritan, but I care about America's corporations, and I hope our times offer an opportunity to change some thinking. Take this little corporate hygiene quiz with a few of your trusted business pals over a latte or two. And since catharsis is good for the soul, I'll share my answers with you here. I used a scale of one (not so much) to five (absolutely) to get a numerical sense of where I stood.

To start, does your business depend on a complex technical environment with significant uptime reliability?


Aren't we all increasingly reliant on a networked environment with nodes, access points and critical intersections in places that we can't see or control? Uptime reliability is important for everybody these days, but it's an expected cornerstone of businesses that feel they need to hire a CISO. I give myself a four on this one.

Does your company have operations in any country below the equator?


Many U.S. companies have core business processes located in countries below the earth's beltline. Security risks exist there that make knowledgeable security professionals twitch every time their phone rings: kidnappings, corruption, incompetent and criminal law enforcement, Internet crime, organized crime, drugs, money laundering, an overall unsafe environment with too many Foreign Corrupt Practices Act temptations. But what are you going to do? The labor is cheap and we have to be competitive. My company is moving in that direction but not there whole hog yet. So I'll give us a three on this one.

Would you characterize the velocity of your company's business as high-speed?


How about warp speed? How else can we continue to satisfy Wall Street and our fickle shareholders? We're all being pushed to do more with less. And there's so much going on in the back draft of this fast pace, I wonder what the hell else I'm missing. I'll take a five on this one. I'd take a six if it were allowed.

Do you forgo a criticality rating to identify shortcomings in business controls and security measures?


With all the open books and disclosure emphasis these days, the lawyers are really nervous about recording any risk information that could come back to haunt us. As a security professional, I've always lived with criticality ratings—it's all about the likelihood of problems we need to be prepared to address. But I know for a fact that we have no organized process for doing this across the business. In the aftermath of Sarbanes-Oxley, our auditors now rank their findings; but that's ex post facto and, besides, an audit is cyclical and periodic. This is all about what keeps knowledgeable risk managers awake at night and what we are missing. I'd better take a four (and hope for the best).

Does your corporate risk-management model discourage individual managers from seeking out vulnerabilities in the system of controls?

My company doesn't have a risk-management model, per se—and then blame is typically parceled out to the lowest common denominator. I'll take a four on this one, too. (This isn't shaping up well is it?)

Are managers ill-informed about what to look for on control deficiencies or cues on risky behavior?


There's not a lot of sharing here, especially concerning errors or incidents. After all, who wants to shoot themselves in the foot? We have an active infosecurity awareness program, but it hasn't been integrated into any of the training and employee development programs we run on a continuous basis. HR owns management training, but it doesn't recognize that the manager's job has a core risk-management component. And what's the first question out of the CEO's mouth when it hits the fan? "Who's the manager of this disaster?" I can't vouch for manager awareness across the board. So let's score a three here.

Are there unaddressed vulnerabilities in your company's safeguards or other such exposures that could be exploited?

The fact that this question has to be included speaks volumes about the maturity of risk management. Of course there are known gaps! And it's the people who work here who know where to find the holes. The guy who is empowered to do you the most damage already works for you. The developers leave open doors in our applications, and our LAN administrators have the keys to the kingdom. There's no one place where all the data comes together to enable those of us on the firing line to see where the interconnections and interdependencies may exist. Besides, I get paid to think about "what if," so scoring anything less than a five would be dishonest.

Wednesday, March 01, 2006

The Wild West of the New Millennium...

Rather than engaging in a futile attempt to suppress technology, the music business should try to work with consumers. Murray writes: "The most sustainable solutions include the creation of favorable alternatives to piracy by making legitimate distribution channels more convenient." Bingo! Imagine how much more money the music industry would have made by creating pay-per-song download sites instead of paying lawyers to prosecute downloaders.


These words by Brian H. Murray were the writing on the wall in January 2004 in this article by Jonathan Jackson. Mr. Murray may have predicted the transition by the MPAA and other digital rights advocacy groups to change the industry from one of piracy to one of profits. Introduce Mr. Steve Jobs of Apple, the iPod and iTunes and now you have your 1 billionth download. That's .99 cents X 1,000,000,000.

How could you endorse the use of technology and tools like Weblogs to create new opportunities for your enterprise? Message boards and other chat web sites have been around for a decade making online brand management a necessity for any brand conscious entity. Defending The Brand was the title of Brian Murray's book published in 2004 and it is still a component of any comprehensive risk management strategy.

Managing Intellectual Property Rights and sensitive or proprietary information is a major concern for General Counsel's and Chief Marketing Officers. Making sure that trade secrets and ideas are protected is a priority. And when it comes to employees expressing their opinions about management, the watercooler and local bar has not been enough. When message boards, web sites or blogs post comments on a company or organization they typically are a way for discouraged, disgruntled or maybe even dangerous employees to vent their feelings.

The intersection of Civil Rights, Privacy, Cybercrime and White Collar Crime is creating a buzz. With whistleblowers sending anonymous email, posting to weblogs and a whole new spectrum of enforcement actions, sometimes you have to step back and see the big picture. General Public License, 3.0 and Open Source has created new subjects for debate.

The Operational Risks in your organization are growing at an exponential rate. Cooperation and information sharing is still a road block to progress. The answers are only clear if you can see the beauty in what Mr. Murray's thinking was over two years ago:

"I never cease to be amazed by the bold, clever, and unscrupulous behavior that is so common on the Internet. Through my experience defending brands, I can say with confidence that anything that you thought would never happen online is probably already going on, and anything you think couldn't possibly exist on the Internet is almost certainly there. Though it's an overused cliche, the Internet really is the Wild West of the new millennium."

Sunday, February 26, 2006

eDiscovery: New Threat or Opportunity?

In the midst of the Enron trial there are many CISO's and CEO's scratching their heads while they grab another pack of TUMS off the desk. eDiscovery is a compelling threat and opportunity for the organization. In either case, it will cost millions of dollars.

Conducting effective internal investigations and even thorough incident response requires a robust Governance Strategy. Just ask Morgan Stanley about it's $1.45 billion verdict in a default judgement when the bank failed to respond plaintiff's discovery requests for computer-based information.

An outsourced process for eDiscovery is quickly becoming a real board room issue. Not only because of the financial impact, $7K to $12K per hard drive but also the number of cases that are settled prematurely. Outside counsel handles the eDiscovery process on a per-case basis and is not typically interested in what the company must do internally to create and establish a long-term governance and risk management strategy.

The CISO who directs a system of consistent Information Security Risk Management will have the foundation for an in-house eDiscovery team and who can work side-by-side General Counsel for compliance and incident response.

Paul French is a computer forensics consultant with a few TIPS:

Ensuring Compliance

A good digital document retention policy is, of course, only as good as the method in which it is implemented. Here a few compliance guidelines you should have your clients consider:

* Establish a records compliance task force, so there are easily identifiable “go-to” people regarding retention activities.

* The compliance task force should create detailed logs of record-purging and back-up activities.

* Archiving procedures should be periodically reviewed and tested. More times than your clients would care to admit, electronic record back-ups are not properly performed or aren’t being performed at all. Incompetence is not a sound defense strategy! If back-up tape hardware is updated, be sure that there’s a back up plan for accessing date on old tapes--these likely will not work with newer hardware. Old back-up tapes stored in a seldom visited closet could pose an unpleasant surprise if they appear suddenly in discovery proceedings, particularly if your client is unable to find the hardware needed to review them.

* Make certain that all media are considered and accounted for in the purging policy. This includes not only servers, desktops, and laptops, but also PDAs, BlackBerries, and various removable media devices.

* It’s a good idea to have an objective third party periodically review and validate that policies are being followed. In doing so, the vendor should interview key personnel and review a sampling of data using forensic tools.


CISO's are seeing their budgets and powerbase grow yet the goal remains the same, Enterprise Risk Management. The Board of Directors now recognizes the significance of having a CISO with an established team for eDiscovery, no matter who may be asking for the timely information.

Friday, February 24, 2006

OPS Risk: From Basel to the Hearing Room...

The Basel Committee on Banking Supervision, an arm of Switzerland-based Bank for International Settlements, has defined the Basel II capital adequacy requirements for global banks. One of the committee's principal goals is to reduce risk in the financial system worldwide by aligning each banks capital requirements to more accurately reflect its credit, market and operational risks.

Archer Technologies (Archer), a leader in enterprise security and compliance solutions, has announced the release of its Vendor Management solution. Vendor Management enables organizations to consolidate disparate vendor information into a single application to optimize resources and reduce risk. Archer also announced its expansion into operational risk management with the introduction of the Sarbanes-Oxley (SOX) Compliance Management solution. This new offering complements Archer's Vendor Management product and enables companies to dramatically decrease the cost and effort associated with SOX compliance.

The significance of the new modules from Archer could be summed up in one or two words.

Convergence

Relevance


Due to the number of financial institutions currently utilizing these solutions for Enterprise Security Management it makes sense to add the modules that intersect with the Enterprise Risk Mission Critical Activities. Operational Risk Management is converging with some of the elements of the traditional CISO job function. Just ask any CISO (Chief Information Security Officer) at a public institution about the number of times the audit teams have been knocking on the door trying to get access.

The relevance of supply chain management and SOX Management modules for the CISO has to do with the real essence of what Operational Risk is all about. Three years ago just managing threats to the desktop PC's, Web Servers and other vital E-Commerce functions was enough. Not anymore.

Now you must add your inteligence feeds from providers such as iJet, OSAC, iDefense, Shavlik, and Stratfor. Then you combine your Real Estate assets including facilities, Gulfstream G5's and create a correlation of real-time enterprise risk to give you a 360-degree view. Combine this with a monitoring system for the ever changing controls in your ERP system and now you have a holistic mechanism for mananging Operational Risk in your enterprise.

That's the easy part. The hard part is yet to be done. The correlated information still requires the grey matter to make faster and more relevant decisions to accept, transfer or mitigate this threat. What are the implications of each? When do I act? How do I execute? All the knowledge from your tools and systems still leaves the most difficult aspect of Enterprise Risk Management.

Just ask all of the people sitting in SOC's, JFO's or any center where a fusion of information is creating the knowledge necessary to make these decisions. They all have the same answer:

You must create a “culture of preparedness” in which all people share responsibility for corporate risk management and homeland security. This includes strong partnerships between federal, state and local governments and especially the private sector. You never know where or when your next incident is going to occur:

The Phoenix hostage incident began about 3:30 p.m. (5:30 p.m. ET) when a man entered the offices of the National Labor Relations Board, grabbed a secretary and took her into a room where a hearing was being held, said Gordon Jorgensen, who retired last month from the board and had spoken with some of the NLRB employees.

"The guy was apparently in our reception area and wanted to talk to someone and ... one of our secretaries walked by. He pulled a gun on her" and escorted her into the room, where a hearing was being held.

One woman escaped early in the evening and a second woman was released about an hour before the man surrendered.

Dozens of police and fire crews were on the scene, and authorities evacuated the building and sealed the area.

Friday, February 10, 2006

Economic Espionage: Chasing 0's and 1's...

What do corporate executives worry about these days? The same thing Chief Security Officers and General Counsels have nightmares about. They all realize that globalization is truly upon us. Rapid transportation, open borders and the Internet have opened new doors for criminals and terrorists to move information quickly, deploy orders and even post stolen assets for sale in an underground world of ubiquitous trade.

Economic Espionage is the #2 issue at the FBI and for good reason. The recent indictment of Suibin Zhang illustrates just one example of a crime happening all too often and right under the corporate executives nose.

The United States Attorney for the Northern District of California announced that Suibin Zhang, 37, of San Jose, California, was charged late yesterday by a federal grand jury in San Jose in a nine-count indictment alleging computer fraud; theft and unauthorized downloading of trade secrets; and the unauthorized copying, transmission and possession of trade secrets.

The maximum penalties for each of the computer fraud counts is 5 years imprisonment, a $250,000 fine or twice the gross gain or loss and 3 years supervised release. The maximum penalties for each of the trade secret counts is 10 years imprisonment, a $250,000 fine or twice the gross gain or loss and 3 years supervised release.

An indictment simply contains allegations against an individual and, as with all defendants, Mr. Zhang must be presumed innocent unless and until convicted.


The people who work for your organization need to have a greater awareness of what the Economic Espionage Act of 1996 is all about. Whether the information that was presumed to be stolen is Mr. Zhang's property or the property of his employer will be at question here. Corporate Information Security Policy will have covered this yet the motivation and the lack of understanding of what constitutes intellectual capital or trade secrets is what needs the most clarification with employees.

VIII.B. The Economic Espionage Act of 1996, 18 U.S.C. §§ 1831- 1839
VIII.B.1. Overview of the statute The Economic Espionage Act of 1996 ("EEA") contains two separate provisions that criminalize the theft or misappropriation of trade secrets. The first provision, codified at 18 U.S.C. § 1831(a), is directed towards foreign economic espionage and requires that the theft of the trade secret be done to benefit a foreign government, instrumentality, or agent. It states: (a) In general. -- Whoever, intending or knowing that the offense will benefit any foreign government, foreign instrumentality, or foreign agent, knowingly - (1) steals, or without authorization appropriates, takes, carries away, or conceals, or by fraud, artifice, or deception obtains a trade secret; (2) without authorization copies, duplicates, sketches, draws, photographs, downloads, uploads, alters, destroys, photocopies, replicates, transmits, delivers, sends, mails, communicates, or conveys a trade secret; (3) receives, buys, or possesses a trade secret, knowing the same to have been stolen or appropriated, obtained, or converted without authorization; (4) attempts to commit any offense described in any of paragraphs (1) through (3); or (5) conspires with one or more other persons to commit any offense described in any of paragraphs (1) through (3), and one or more of such person do any act to effect the object of the conspiracy, shall, except as provided in subsection (b), be fined not more than $500,000 or imprisoned not more than 15 years, or both.

Tuesday, February 07, 2006

Grass Roots Risk Management...

When you set your organizational direction and adopt a common language and framework for managing risk you must include the measurable categories associated with credit, market and operational risk. Many choose to adapt the COSO Guidelines to create their unique risk management and control framework.

The question remains, Is that enough? Do you have enough categories to truly address the methodical management of all material risks?

The Board of Directors must be able to understand the framework to begin any meaningful programatic approach to identifying, assessing, managing and mitigating risks. Now what would happen if you added a few more categories to include:

1. Compliance
2. Legal
3. Strategic
4. Reputation

Certainly the Board understands that these are real and important categories to include in the framework. However, these are much more difficult to measure and merge with the new governance culture found in most SOX oriented organizations.

Creating the right environment for employees and supported by the correct processes is not enough these days. Now the front line must also have the right tools to help in performing risk assessments and analysis as change takes place in products and the market place. Creating a risk culture that is effective is a balancing act for employees who are trying to decide if they have a material risk to mitigate or an opportunity that has yet to be realized. Employees need to be able to embed this kind of decision making into the fabric of their daily work routines as opposed to a quarterly or annual exercise.

The largest institutions that have already established the framework, support processes and tools along with the staff are well on their way to meeting the goals of prudent corporate governance. Developing a more comprehensive and pervasive adoption rate across the Tier II and small to medium-sized intitutions is far from reality. We are just beginning this long and difficult journey.

Maybe the biggest question for these evolving risk management cultures is how and where to begin? The answer might be found in your current abilities to deal with "Change" itself. At the end of the day, any Operational Risk Management program is going to be about the ability to address the velocity of change. If you haven't been getting an "A" in this part of your report card then you can be sure that managing your new found material risks will be far from excellent.

A "Loss" is a financial impact from an event that shows up on the companies financial statements. This financial impact shows up as "write-downs" or other entries in the annual report. As you build a Loss Event Database to record losses across the organization you expose the organization to new risks that have never been known before. This is where resources are invested and where management realizes the beauty of having a "Grass Roots Risk Management" initiative.

Friday, February 03, 2006

Managing Strategic Change for Operational Risk...

There have not been more sweeping changes in business regulation and compliance since the Great Depression. The fall of Enron Corporation provided much of the catalyst for new laws and new corporate governance oversight. The Board of Directors and senior management are now tasked with the continuous risk of “operational volatility” with people, processes, systems and external events. Effective Operational Risk Management begins with an effective strategy to manage change in your organization.

What institutional fraud presents the greatest operational risk to companies? In a recent poll by Oversight Systems of 200+ Certified Fraud Examiners:

63% - Conflickt of Interest

57% - Fraudulent Financial Statements

31% - Billing Schemes

29% - Expense and Reimbursement Schemes

25% - Bribery/Economic extortion

20% - Inventory and Non-Cash Asset Misuse


From the conviction of former WorldCom CEO Bernie Ebbers to the acquittal of HealthSouth’s Richard Scrushy, corporate fraud continues to make headlines. Four years after Enron’s collapse, financial integrity remains a key issue for corporate America.

The 2005 Oversight Systems Report on Corporate Fraud surveys certified fraud examiners to report the trends, risks and major concerns that businesses face today.

While most fraud examiners view Sarbanes-Oxley (SOX) as an effective tool in fraud identification, few think it will change the culture of business leaders. Nearly two-thirds of respondents (65 percent) indicate that SOX has been somewhat or very effective in identifying incidences of financial-statement fraud. Only 19 percent of those surveyed found SOX to be ineffective or serve to prevent fraud identification.


·What are the consequences of ignoring need for change related to operational risks.

·What will be a starting point for initiating changes related to operational risk management?

·Is your organization ready for managing changes in order to manage operational risk? If yes, at what readiness level? If no, how can it become ready?

Are you a boardroom director or senior corporate manager? Does your organization have a culture that avoids an examination of organizational processes such as decision-making, planning and communication concerning the risk of change? Are you an executive who would like your organization to accept, adapt and therefore institutionalize and legitimize these processes related to operational risk?

If you said yes to any the questions above and nodded positively to the possibility for a change in your organization then first you must effectively
"Manage Strategic Change for Operational Risk".

Wednesday, February 01, 2006

Internet Crime Pandemic: The Botnet Outbreak...

If you thought that your INFOSEC team was busy last year, they haven't seen anything yet. The rise of Trojans & Botnets is becoming an Internet Crime Pandemic.

"Cyber-crime nowadays takes many forms, and perhaps even more dangerous than botnets are the targeted attacks that we have witnessed recently," explains Luis Corrons, director of PandaLabs. "The biggest problem lies in their secrecy: a large company could be serving the interests of a group of malware creators without realizing it. Many of their computers could be at the disposal of these cyber-crooks, with all the legal implications that this might have for the company itself." Until now it is a risk that companies have not considered sufficiently, but one which is no longer possible to ignore."


Most of the successful attacks exploit the most vulnerable facet of every companies defense. It's people. Targeting executives within a specific industry group such as the savings and loan sector is a good example. The global marketplace for reselling data about people is now showing exponential growth. Once the executive clicks on a link inside what looks like a legitimate email he has opened his network to a potential new "Zombie".

Why do the spammers, pharmers and spear phishers continue to invest in these types of attacks? It's good for their criminal business.

The FBI recently snared a 20-year-old hacker (Jeanson James Ancheta) whom they believe wrote computer code to assemble botnets and sell access rights after he was lured into a trap. Ancheta in his plea accepted responsibility for selling botnets and directing zombie machines to surreptitiously download adware besides intruding into government computers.

Ancheta is understood to have as a result benefited by $3,000 from botnet sales and $60,000 from the clandestine adware downloads. With close to 400,000 machines under his control, Ancheta was doing well enough to gift himself a BMW.

Friday, January 27, 2006

Travel Threat: Executive Operational Risk...

Operational Risk Management is a vital component for any Board Member or Corporate Manager who travel internationally.

Company executives who travel extensively on commercial airlines are constantly being subjected to a spectrum of new threats. The latest concern is putting executives in potential harms way with the rise in Avian Flu.

Once these highly compensated and important corporate officers reach a cities destination, there is of course the choice of hotel. Where and where not to stay is now a question many corporate travel departments are asking themselves. How do you know what is the most secure and safe place to stay?

Stratfor provides substantive tips and advice from their intelligence and publications. Terrorist attacks in past years against U.S., Israeli and Australian embassies forced Western countries to harden their diplomatic compounds abroad, turning them into veritable fortresses of security. In response, terrorists began focusing on softer symbols of Western influence, such as large hotels and resorts. By attacking a Marriott, a Hyatt, a Moevenpick or another popular Western chain, the perpetrators can cause mass casualties and gain international media attention -- and all without having to penetrate extreme security.


As a saavy travel department and global corporate security chief already know, there are some other choices that should be considered namely, iJet:

iJET was incorporated in 1999 with a mission of protecting international travelers through the use of our proprietary technology and services platform. That mission has evolved and broadened over time as our Worldcue® Risk Management System has been applied to protecting both employees and other assets of multinational corporations. Today, iJET has over 350 corporate clients that rely on iJET to monitor, protect, and respond to operating risks around the world.

The escalation of terrorism, infectious diseases, and unforeseen natural disasters has forced multinational organizations and their employees to re-evaluate their perception of risk. Such events are often beyond a company's control, yet corporate liability and responsibility to employees and assets continues to increase. As a result, corporations need a fresh approach and new set of tools to meet the operational risk management demands in today's business environment.


This part of the equation is an easy one. Get real-time intelligence while on the go and utilize strategic tools and solutions for risk mitigation along the way. Moreover, travel light and without a huge entourage of large NFL size body guards in tow. You might as well paint a bulls eye on your back.

The hard part of the equation is getting your executives and highly valued employee assets trained and ready. Having all of the "What Could Happen" and "Be Careful of" in your head will not be enough unless you train, practice and test. Many global companies are doing just that, training their employees in threat detection and giving them new skills and strategy to save themselves from potential attacks of all kinds. See Threat Detection and Management to learn how.

Tuesday, January 24, 2006

Supply Chain Risk: Spending Time with The Right People...

What is the largest obstacle within your organization to address risks such as corporate fraud, natural disasters and disruptions to your supply chain?

According to top responses in a recent poll of 600 financial executives accross the United States, the UK and Europe:

33% - Insufficient Time

23% - Inadequate Personnel

19% - Insufficient Budget

13% - Not Viewed as a priority


Does this mean that the Board of Directors has transfered risks using vehicles like insurance? The same study asked what percentage of risk management budgets are allocated to "Risk Control" vs. "Risk Transfer":

Risk Control - 56%

Risk Transfer - 44%


While there are new and innovative new insurance policies being marketed these days, these typically can not cover many of the losses from damaged corporate reputation, a drop in market share or lost sales. As Board of Directors raise the priority above a 13% response, this should cascade to impact the insufficient budget. Now the question remains on how to deal with the "Inadequate Personnel" and "Insufficient Time".

You can hire dedicated people, add additional responsibilities to existing personnel or you can even Insource. In every case, you will need to find more time for planning and training to make sure that new risk controls are implementated and monitored. Without a systematic program that is culturally institutionalized, even these new initiatives will fail.

To quote one of the leading global business continuity membership organizations Survive:

Business Continuity Management is about not making excuses. It's about being wise before the event. It is a state of mind that understands great organizations never moan they didn't do well because of the state of the economy, a fire at the warehouse, an internal fraud, or a strike by a key group of workers. Great organizations do well anyway.

Friday, January 20, 2006

OFAC Compliance: Ensure Your Transactions are Legal...

Archaic and ineffective name searching technology is still in use today across all levels of intelligence agencies and law enforcement. Names remain the single most important means for identifying persona non grata at our borders. Biometrics are only useful the second time you meet someone. Everyone in the world knows how easily security at America’s borders can be circumvented — except Americans.

Language Analysis Systems is the world's recognized leader in providing multi-cultural name recognition software solutions for mission critical applications. We have worked with U.S. Intelligence and Border Protection agencies for nearly two decades, developing a revolutionary and patent-pending approach to name matching and searching, going far beyond simplistic Soundex and key-based approaches. We offer a variety of proven commercial products to government, law enforcement, and commercial organizations that solve a multitude of name related problems.


How else can this technology be used to help our DHS with the war on terror? Are you a U.S. business? If you are, then you must comply with OFAC especially if you are a financial institution, mortgage broker, car dealer, boat dealer, real estate agency or insurance broker.

OFAC administers and enforces economic and trade sanctions against targeted foreign countries, terrorism sponsoring organizations and international narcotics traffickers.

Pay attention. Dutch bank giant ABN Amro Bank , has agreed to pay a total of $80 million in US fines for violating regulations to prevent money-laundering, regulators and the bank said last month.

The Financial Crimes Enforcement Network at the Treasury Department said that ABN's "serious, longstanding and systemic" problems allowed people from Russia and other former Soviet republics to move $3.2 billion to shell companies in the United States from August 2002 to September 2003.

Investigations by state and federal officials also found that the Chicago and New York branches of the bank participated in wire transfers and trade transactions from 1997 to 2004 that violated economic sanctions on Libya and Iran.

ABN AMRO said on Monday that it recognises that serious mistakes were made and accepts the sanctions.


There are now dozens of software solutions and programs available to help with compliance of BSA and AML compliance. The question is, which one is right for your organization? If you do not have a step in your customer or client acquisition process that intersects with compliance then you are at significant risk.

Sales and business development personnel, business development or broker networks must be able to have a high degree of confidence that the business or person they are creating the quotation or proposal for is not an SDN, or Specially Designated National.

Are you an insurance company who uses a network of brokers? What are you doing to implement the policies and programs to comply with this new requirement:

The final rules apply to insurance companies that issue or underwrite certain products that present a high degree of risk for money laundering or the financing of terrorism or other illicit activity. The insurance products subject to these rules include:

• permanent life insurance policies, other than group life insurance policies;

• annuity contracts, other than group annuity contracts;

• any other insurance products with features of cash value or investment features.

At minimum, insurance companies subject to the rule requiring an anti-money laundering program must establish a program that comprises four basic elements:

• A compliance officer who is responsible for ensuring that the program is implemented effectively;

• Written policies, procedures, and internal controls reasonably designed to control the risks of money laundering, terrorist financing, and other financial crime associated with its business;

• Ongoing training of appropriate persons concerning their responsibilities under the program; and

• Independent testing to monitor and maintain an adequate program.

Thursday, January 19, 2006

Scenario Analysis: The Value of the Hypothesis...

In the December 2005 issue of OpRisk and Compliance Magazine Dean Lamble from Hewlett-Packard has this to say in the article on "Planning for Disaster":

Key areas will include security, evolving threats of terrorism, and how to cope with a pandemic outbreak such as bird flu. Companies will be paying far more attention to how the contingency plans perform when tested. Compliance continues to be a key concern, with increasing legislation directing responsibility to the board.

More than 25,000 banks around the world will work to comply with Basel II over the next five years. One of its most controversial aspects is the inclusion of Operational Risk Management. While banks have attempted to manage operational risks for many years, now for the first time they must measure it.


Most money center banks have already achieved high levels of competency with capturing loss events and with risk self-assessments. Scenario analysis and KRI (Key Risk Indicators) is still a distant goal. OPS Risk is still a maturing discipline and regulators are allowing some flexibility here. However, financial institutions are still stuck to some degree on imagining incidents that have not occured to them in the past. Probabilities are not low just because they haven't happen to your institution historically.

A hypothesis is the place to begin.

hy·poth·e·sis ( P ) Pronunciation Key (h-pth-ss) n. pl. hy·poth·e·ses (-sz)

1. A tentative explanation for an observation, phenomenon, or scientific problem that can be tested by further investigation.

2. Something taken to be true for the purpose of argument or investigation; an assumption.

3. The antecedent of a conditional statement.


If an event has happened to another insitution is it so improbable that it could also happen to your own firm? The starting point for effective scenario analysis is the intelligence and the external data that provides the evidence of such an incident. Then the goal is to gain "insight" on how it could happen and what the impact would be in your own environment. Capture of data on extreme events is imperative even if only one $10M. event has occured in the last ten years.

Today, an audio tape from Osama bin Laden has been posted on the Internet along with a transcript of his comments. The authenticity is being validated as he has not been heard from for over one year. Has your scenario analysis included potential events of the magnitude of the 7/7 bombings in London or the 11/9 Amman Jordan suicide attacks on three Western hotels?

"Bruce Newsome, a terrorism researcher at the think tank RAND, said the plot carried out by four men in London is a "likely model for future U.S. attacks." The bombers, all British citizens, had no criminal records, weren't on any watch lists and had no extremist pasts. (A fifth man, believed to be the mastermind of the plot, has been arrested in Egypt.) Tracking such potential perpetrators is nearly impossible because there are no warning signs, Newsome said."


Somewhere in your contingency planning and scenario analysis there must be hypothetical loss events on the magnitude beyond our imagination.

Tuesday, January 17, 2006

You've Been Indicted. The Most Feared Words in the Boardroom...

Over two years ago this corporate governance article appeared in Corporate Board Member Magazine.

June 25, 2003
You've Been Indicted. The Most Feared Words in the Boardroom

By Peter L. Higgins


Every Fortune caliber organization from financial services to health care has already implemented a pervasive compliance program to mitigate the risk of ending up with the SEC or US Attorney in the lobby.

The catalyst behind these initiatives is generated from the U.S. Sentencing Commission's Organizational Sentencing Guidelines. They allow for more lenient sentencing if an organization has evidence of an "effective program to prevent and detect violations of law."

The Guidelines contain criteria for establishing an "effective compliance program."

These include oversight by high level officers, effective communication to all employees, and reasonable steps to achieve compliance such as:

* Systems for monitoring and auditing
* Incident response and reporting
* Consistent enforcement including disciplinary actions


Yet the corporate incivility continues. Why is it that we can’t pick up the morning paper or listen to the news on the way to work without hearing about a new indictment of a top ranking officer?

Here lies the question many Board of Directors are scratching their heads about these days. How can we avoid these ethical and legal dilemmas and how can they be addressed without creating a state of fear and panic?

The answer lies in the human factors of what motivates people’s behavior. This requires programs, controls and good old fashioned vocational counseling. However, the real facts are that all of these alone will not be able to stem the tides of corporate malfeasance.

A guest column by Jacob Blass
President, Ethical Advocate
highlights the past few years:

The number of companies around the world that reported incidents of fraud increased 22% in the last two years according to the 2005 biennial survey by PriceWaterhouseCoopers (PWC), which interviewed more than 3,000 corporate officers in 34 countries. In England, a recent Ernst & Young survey of the Times Top 1000, indicated the average cost of each fraud exceeded $200,000.
But fraud is not the only problem. There's also misconduct, unethical behavior, lying, falsification of records, sexual harassment, and drug and alcohol abuse.

PWC found that “accidental” ways of detecting fraud, such as calls to hotlines or tips from whistleblowers, accounted for more than 33% of the cases. Internal audits were responsible for detecting fraud about 26% of the time.


If these latest figures are correct than this means that 59% of the detection was a result of effective operational risk management. Let's just hope that the remainder is the result of corporate managers and leaders doing their job to mitigate new risks on a daily basis.

As indicated, the great manager can impact the lives of tens or hundreds of people in your company. Conversely, the uncivil manager can wreak havoc with a similar numbers of lives. The position of management is ever so powerful to influence those around them.

Your company wide compliance initiative has the elements that provide guidance for creating a program that the government is likely to look favorably upon. The problem is that these same criteria inadvertently communicate the message that implies building a program based on this formula is enough. It isn’t.


Maybe it’s time the Board of Directors looked into who is managing the organization into a future of civil or uncivil destiny. We have a clear choice.

Wednesday, January 11, 2006

HSAC: Private Sector Information Sharing Task Force...

At first glance the room full of Homeland Security Advisory Council members looked like any other agency briefing. C-Span setting the stage for people to look good and say the right thing for the public record. Items such as we need to use a systematic risk management approach to funding and we should replace the word "Protection" with the word "Resiliency" were the highlights. And underneath, the audience was disturbed by the presentations because of it's lack of solid recommendations.

What happened later in the closed door session is where the rubber meets the road and serious work gets done. Yet the take away was this. After reading the 80 page report from the Private Sector Information Sharing Task Force there was one recommendation that stood out.

DHS should respond to private sector concerns about liability risks associated with sharing security information with DHS. This is why they recommend that the Critical Infrastructure Information Act (CIIA) should be fully implemented. If this could ever be clarfied and the legal counsels of the private sector gave it a major blessing then we would be well on our way to achieving a greater degree of safety, security and peace of mind.

In fact, Attachment D of the report goes so far as to list the categories of information that the government is seeking from the private sector on the critical infrastructure that they own. The number one item on the list is "Cyber Threats to U.S. Infrastructure". The number two item is "Terrorism".

It's no surprise that these are the two largest threats to the U.S. in the eyes of the task force.

Friday, January 06, 2006

OPS Risk: An Ocean of Continuous Change...

In the latest issue of OpRisk & Compliance Magazine Eric Holmquist from Advanta makes the case for the Small to Medium sized institution. His brilliance continues and it's one of the reasons why we are an Advanta customer. They understand and practice OPS Risk hands down.

Overseeing an operational risk programme never ceases to fascinate me. There are aspects to op risk that are overwhelmingly unique from any other risk discipline. As I have said previously, it has the most moving parts. It involves every single person in the company, without exception. It is constantly in motion, involving an ever-changing set of assumptions and forces. And it is, ironically, sometimes unfortunately, and perhaps more importantly, the most intuitive.


Eric singles out the large mistake many organizations have made. Certification of controls for SOX 404 misses many of the OP risk factors and is all to focused on the financial control itself. Operational Risk assessments properly look at the potential and the likelihood of failures in the process so far, as well as potential threats to the process in a high moving parts environment.

The hint in his article about evaluation of core processes under the "heat lamp" is most critical. When people and systems are concerned, there are all too many opportunities for a failure and potential losses to occur. And those people are exactly who are the ones to be in the drivers seat to analyze those places that the proper tools in the right hands could exploit a known vulnerability. They may not know all of the ways to mitigate the threat, yet they are where you are going to get your "intuition" on what could happen.

As Eric says, "Operational Risk is constantly in motion", and assumptions change as often as the weather.


As the discipline of OPS Risk matures in the white collar world of Wall Street and the blue collar world of small community banking one thing is certain. No one will ever be able to predict or provide a scenario analysis that prepares exactly for the next incident. Mother Nature may act the same over and over to some degree and that helps us think in terms of magnitudes and categories. What about the person sitting in the next office who makes a random decision to inflate last months expense report? What about that electrical fire in the storage room?

Those who can master the art of change and rapidly adapt as unforeseen events occur will be here tomorrow to take on that next unplanned scenario.

Wednesday, January 04, 2006

Security vs. Privacy: A Public Private Paradox...

If your are interested in what is on the minds of some of the PowerBase for information security and privacy you need to look no further. The comments and posts on Bruce Schneier's weblog tell the truth. His post on the Top Ten Privacy concerns from EPIC, (The Electronic Privacy Information Information Center)has created some very interesting points.

And to add to the concerns, comments and controversy is this:

Cyber Security Industry Alliance (CSIA), the only advocacy group dedicated to ensuring the privacy, reliability and integrity of information systems, today called on the federal government to assert greater leadership in the protection of our information infrastructure in 2006. Its release of the "National Agenda for Government Action on Information Security" identifies 13 specific actions required to improve information security for consumers, industry, and governments globally. As part of the Agenda, CSIA also provides a report of the government's limited progress in information security in 2005 and releases a new "Digital Confidence Index" that reflects the public's lack of confidence in our nation's critical infrastructure.


What is the paradox? The feds may need to show more leadership yet the private sector owns a majority of the critical infrastructure. Any lack of confidence should be an indicator that the private sector hasn't invested enough money and resources in information security and protection of our country's vital corporate assets.