Wednesday, July 19, 2006

The Risk of Silos of Fraud Detection...

The Silos of Detection are under scrutiny in many financial institutions who are plagued with fraud.

Mission-critical data and consumer-specific information often are the target for savvy thieves who prey on the financial services industry. Further, as consumers, employees and external business partners demand -- and are given -- greater access to sensitive data, banks are more susceptible than ever to internal security breaches.

Clearly, fraud is a costly fact of doing business. Approximately 3 million adults said they were victims of ATM or debit card abuse in 2005, according to a survey by Stamford, Conn.-based Gartner that focused on the global IT industry. These incidents resulted in $2.75 billion in losses, with an average loss of more than $900 per incident, Gartner reports. Another 1.9 million online financial services users were victims of illegal checking account transfers, the study adds. These hijacked accounts resulted in nearly $3.5 billion in losses -- an average of roughly $1,800 per incident. Banks absorbed most of these losses, Gartner points out.


Operational Risks are being tracked and counted. More processes are in place to try and get a grasp of the data and the trends to create new procedures. Transfer of risk is creating even more issues. Is any of this working as quickly or effectively as management would like?

If fraud is at the heart of operational risk, then human behavior is no doubt at the center of fraud. To understand how to minimize fraud, you must have a more substantial grasp on the human motives for fraud. And to better understand those human behaviors, a risk manager must know the clues and cues for detecting what people are exploiting the organization with deception and new tactics for achieving their goals across business boundaries. The USA Patriot Act is one tool that has targeted the center of this human behavior.

"These and other regulations are forcing companies to look at all customer activity, even across silos," says Rosenoer. That is where the CRO comes in. "The role of the CRO -- or chief risk officer -- is to ensure the bank is compliant across these regulations," he explains. "Further, the CRO bridges business continuity in the event of fraudulent events. Again, this is not just an online problem. CROs are evaluating money laundering rings, compromised internal systems or anything that is threatening the enterprise."

Friday, July 14, 2006

e-Discovery: A "Perfect Storm" for Corporate Chaos...

The FBI Task Force on "Backdating" options is in full swing in the Silicon Valley.

The U.S. attorney's office here has launched a stock options backdating task force to investigate allegations that Silicon Valley companies and individuals defrauded shareholders by retroactively changed grant dates for stock options.

The task force is currently investigating several Bay Area companies to determine the extent of alleged efforts to defraud shareholders in the dating and awarding of stock option grants, according to a statement released by the U.S. Attorney's Office. The task force includes members of the U.S. Attorney's Office and the FBI, the statement said.

If you are a company who is under scrutiny, then you should make your Document Retention Policy Team and on staff e-Disovery staff familiar with the new rules going into effect for electronic discovery.

New rules for electronic discovery of documents in civil cases go into effect in December -- and they could cost users millions or even billions of dollars if they fail to comply.

Last September, the Judicial Conference of the U.S. Supreme Court's Committee on Rules of Practice and Procedure recommended changes that force companies involved in a civil lawsuit to sit down and hammer out what records are fair game for electronic discovery. In general, the resulting 300-plus page document describing the new e-discovery criteria says that companies involved in civil litigation must meet within the first 30 days of a case's filing to discuss how to handle electronic data. The discussion must encompass retention practices, the types of records required and their electronic format, as well as what is considered "accessible" data, said John Bace, an analyst at Gartner Inc. in Stamford, Conn. Failure to comply with the new rules could be costly.


"Falsification or backdating of financial documents may call the integrity of companies' financial statements into question, can constitute fraud on the company, shareholders, and the market, and may give rise to tax violations," said U.S. Attorney Kevin V. Ryan, who is heading the task force.


Operational Risks associated with document retention, legal discovery and liability is a "Hot" topic for most Chief Risk Officers. More so, a continuing challenge for the CIO on how much money to budget for storage, back-up and archiving. However, if the companies policy and procedures are already up to date on the Business Crisis and Continuity Plan then most if not all of the organizations concerns on e-discovery issues should be trivial.

Unknown to the General Counsel and the Director of Business Continuity is where policies overlap and where there might be gaps. This is the place where risk exposure is extensive and the likelihood of an incident is high. A "Perfect Storm" of corporate chaos in the making.

Thursday, July 13, 2006

Avian Flu: The Risk of Pharma Divergence...

This McKinsey article on Avian Flu has some valid points:

• To counter the threat of a global flu pandemic, policy makers, health care organizations, and the pharmaceutical industry must collaborate to develop a market-based approach to expand vaccine production capacity.

• The most effective way of doing so would be to stimulate demand for the annual winter flu vaccine, finance research into the development of pandemic vaccines, and reach an agreement on the amount of additional capacity required around the world.

• Simultaneously, pharmaceutical companies must develop a fourth strain, targeting H5N1 and other avian-influenza strains, and seek regulatory approval to add it to the existing annual winter flu shot.

• Although these shots would not include the eventual pandemic strain—which cannot be known until it appears—people immunized with them would develop antibodies against a potentially deadly virus.

Monday, July 03, 2006

Crisis, Command and Control Training in Large Global Enterprises...

1SecureAudit Launches Operational Risk Solution for Crisis, Command and Control Training in Large Global Enterprises

Lessons learned from large-scale disasters and new blended threats require an adaptive Incident Command System (ICS) for training executives; crisis managers and emergency operations center staff


1SecureAudit, an emerging leader in Operational Risk Management Solutions for the Financial and Healthcare Services Sectors, and its strategic partner Innovative Management Concepts (IMC), today announced an Internet Web-Services Solution designed for an organizations executives and crisis staff to better prepare for wide area emergencies and global incidents.

“The challenges and concepts of network-centric warfare (NCW) are now being applied to post 9/11 scenarios as CxO’s, Incident Commanders and Emergency Operations Centers (EOC) are learning new standards and skills to be more resilient in a new “All-Hazards” worldview,” said Peter L. Higgins, Managing Director of 1SecureAudit.

The 1SecureAudit Crisis, Command & Control Training Management System (C3TMS) powered by IMC is a Network-Centric Web Services solution. It was designed and is currently deployed for Command and Control (C2) rehearsals in the US Air Force.

The US National Incident Management System (NIMS) is applicable across a full spectrum of potential commercial incidents and hazard scenarios, regardless of size or complexity. Clients will utilize C3TMS to make rehearsals more practical, less time consuming and at a significantly lower cost to produce. This means more exercises and tests in a safe and secure setting. It provides the continuity of operations team with real-time, realistic scenario simulations configured “On-The-Fly” to provide executives with the assurance to carry out their crisis missions with confidence and clarity.

1SecureAudit Crisis, Command & Control Training Management System is available immediately for organizations that require compliance with new regulatory and legal standards for business resiliency, emergency preparedness and continuity of operations planning.

Thursday, June 29, 2006

Turnover Risk: Emotional Intelligence Factors...

The turnover in personnel in your organization could increase your operational risk.

Freddie Mac (FRE) on Wednesday released its annual report for 2005, with Chairman and Chief Executive Richard Syron describing the year as one that brought "reason for pride" as well as "some disappointment."

Freddie Mac said elsewhere in its information statement that "we have recently experienced high employee turnover rates, which strain existing resources and contribute to increased operational risk.

"We are also assessing our standards of performance and how we enforce those standards to create a more effective culture of accountability," the firm added.


There are many examples of how strained resources and a lack of personnel contribute to the increase in operational risks. Today's search on their corporate website under careers produced 216 job postings that mention "risk" and 19 of these are operational risk. Enforcing standards of performance is another matter in itself and remains a challenge for any enterprise the size and complexity of Freddie Mac.

In this research paper Key Personnel: Identification and Assessment of Turnover Risk by Craig Schreiber and Kathleen Carley you can find some of the answers for this significant business issue:

Intellectual work is the central commodity of any knowledge-based enterprise. Personnel are not simply brought in to run the assets of these companies as they are for more traditional manufacturing and service based enterprises. The personnel are the assets and as such, identifying and retaining key personnel is a major concern for knowledge-based enterprise.

While this example from a study at NASA is not even close to the financial services environment from a workplace perspective, it is valid from a knowledge worker point of view. When your personnel are your assets, turnover risk can be a real and present threat. What can a CEO or Executive Management do to mitigate the growing threat of turnover in personnel?

Some of the answers may be found in "Emotional Intelligence" by Daniel Goleman.

"The airplane cockpit is a microcosm of any working organization. But lacking the dramatic reality check of an airplane crash, the destructive effects of miserable morale, intimidated workers, or arrogant bosses---or any of the dozens of other permutations of emotional deficiencies in the workplace----can go largely unnoticed by those outside the immediate scene. But the costs can be read in signs such as decreased productivity, an increase in missed deadlines, mistakes and mishaps, and an exodus of employees to more congenial settings. There is, enevitably, a cost to the bottom line from low levels of emotional intelligence on the job. When it is rampant, companies can crash and burn."


The Board of Directors may want to ask about the Emotional Intelligence of corporate management at the next board meeting and put this on the operational risk dashboard.

Monday, June 26, 2006

More Aspirational than Operational...

One day we could be asking ourselves about the insight gained from understanding aspiration, and then acting upon it. In the context of effective Operational Risk Management, understanding and detecting people's aspirations are critical to the safety and security of your business.

We should be thanking Robert S. Mueller, III and his team for preemption of what could be just one of many unknown operational plans by domestic terrorists. Here are a few words from his speech at the City Club of Cleveland June 23rd:

It has been nearly five years since the last terrorist attack on America. Yet there is no room for complacency. As we have seen in recent months, our enemies are adaptive and evasive. They are taking full advantage of technology. They are combining their resources and their expertise to great effect. We must do the same.

Our greatest weapon against terrorism is unity. That unity is built on information sharing and coordination among our partners in the law enforcement and the intelligence communities. It is built on partnerships with the private sector and effective outreach to the public as our eyes and ears. It is built on the idea that, together, we are smarter and stronger than we are standing alone.

No one person, no one agency, no one police department, and no one country has all the answers. We may not always know where and when terrorists will attempt to strike. But we do know they will try again. And we must combine our intelligence, our technology, and our resources to stop them.

We face many challenges today, both from overseas and from those living in our midst. But we must not let terrorism change our way of life.


Being vigilant is not enough these days. You also need courage and lot's of it. The courage to have unity. Organizations are doing just that and many are not waiting to find out if the FBI can preempt every possible plot to harm our economic way of life. Yet, they are doing it in collaboration and in cooperation with people they know and trust. People they can count on to preserve and protect our corporate assets. Organizations such as WashingtonDCFirst is just one example of how the private sector is working along side the public sector to increase the resiliency of our Critical Infrastructure. And the emphasis is on resiliency because everyone has finally concluded that "protection" in itself is a zero sum game.

People who aspire to be known for their criminal or terrorist act will continue to achieve their goal some of the time. Whether it is the lone homegrown variety or the organized and well funded class, we must remember that preemption in their aspirational phase is preferred over recovery in the operational phase. It is safe to say that regardless of the amount of money and manpower being applied to the security of the Sears Tower, it will never be enough. Bob Mueller is right. All we need is more "Unity".

Thursday, June 22, 2006

Protection vs. Resiliency: The New Standards for BCM...

The latest AT&T Business Continuity Study has been published and the results are surprising. Operational Risk Professionals should take note that 28 percent of the companies do not have adequate plans in place to cope with natural or other disasters.

AT&T Inc.'s fifth-annual Business Continuity Survey released Tuesday, which polled about 1,000 CIOs and IT executives at U.S. companies with more than $10 million in annual revenue.

Nearly 30 percent of executives who participated in the survey said their company has suffered from a disaster. Eighty-one percent of executives said cyber security is part of their overall business plan for interruptions in 2006, up from 75 percent in 2005.

Eight out of 10 companies have revised plans in the past 12 months, including 48 percent that say they've been updated in the past six months. Of those companies with plans in place, 40 percent say they have not tested their plan in the past year.

Companies in Los Angeles, Miami, New York and Washington, D.C. were among the most prepared and made their disaster recovery plan a high priority, compared with those less prepared in Detroit, St. Louis and Seattle.


Since 40 percent of those with plans in place have not tested in the past, the real question is why? Is it the lack of time or resources and money? Is it the fear that new planning will have to take place once "Lessons are Learned"? It may be all of the above. Dr. Sean Gorman a Ph.D from George Mason University has some answers that may become the standard for a "Methodology for Critical Infrastructure Resiliency."

His argument is this:

The first step in any comprehensive plan for ensuring the resilient operation and reliable delivery of services is the establishment of a methodology by which standards and metrics can be set. There needs to be a common methodology by which stakeholders can objectively quantify investment in business continuity by measuring resiliency.


His work at FortiusOne is catching the eye of Venture Capitalist's since the Operational Risk tools that he and his team are developing have significant impact with any firm with Enterprise Risk Management priorities. This includes financial hedge funds as much as the large commercial retailers who have logistics, transport and supply-chain applications.

FortiusOne’s target market encompasses both the public and private sector. The former includes federal, state, local and international segments, with primary emphasis on Homeland Security, National Defense, Intelligence and Emergency Management for critical infrastructure vulnerability assessments and consequence management.

FortiusOne’s private sector market addresses risk analysis for the Banking/Financial Services, Transportation, Energy, Telecommunications, Insurance and general Supply Chain segments with primary emphasis on business continuity planning, business optimization and disaster recovery. Market size exceeds $40B and is upward trending in both public and private sectors. Recent events and consequences related to hurricane Katrina, terrorist threats and attacks, and corporate management/mis-management events have created intense interest in FortiusOnes’s products and services.


Infrastructure Resiliency Methodology provides the enterprise with the business case for investment. How do you know where to spend valuable budget dollars to get the most value for your investment in terms of increased resiliency? The fact is that you have to test, exercise and provide scenario simulations to find the failures. This will provide the operational impact and economic analysis that management and the Board of Directors need to authorize budgets that have a significant return.

There is more help on the way for Business Continuity Management (BCM) as PAS56 evolves into BS 25999:

BS25999 v PAS56

PAS56, published in 2003, provided a series of recommendations for business continuity management good practice. It was always intended to be the forerunner of a new standards for BCM (BS 25999). The first draft has been commented on and returned as of June 19th. If you liked what you have seen in ISO 27001 then you will see a similar approach in the next relase of the Code of Practice for Business Continuity Management, BS 25999 Part 1. This standard is not intended to be a beginners guide to BCM and will not cover the activities of emergency planning.

In this new code of practice the taxonomy is established:

Resilience: Ability of an organization to resist being affected by an incident.

The Homeland Security Advisory Council (HSAC) Critical Infrastructure Task Force is setting the policy and the pace for the future. "While protection is a necessary component of building resilience, resilience is not an inevitable outcome of strategies that focus on protection." This provides the foundation for changing our mindset from Critical Infrastructure Protection (CIP) to Critical Infrastructure Resiliency (CIR).

Thursday, June 15, 2006

Board of Directors: Beware of Reputation Risk...

How do Board Directors understand risk vs. how their companies manage risk? A recent study by The Conference Board entitled "The Role of the US Corporate Board of Directors in Enterprise Risk Management" finds out the answers:

When we asked directors personally, many said they approach risk on a case-by-case basis in connection with a specific strategic issue such as a merger or acquisition or the entrance into a new market. This may not constitute a sufficiently robust process to satisfy directors’ fiduciary responsibilities.”

The new research found significant differences in how directors understand risk and how their companies manage risk. Moreover, directors may have more of a top down understanding of risk. The Conference Board study finds: Although 89.5 percent of directors say they fully understand the risk implications of the current strategy,

- Only 77.4 percent of directors say they fully understand the risk/return tradeoffs underlying the current strategy.

- Only 73.4 percent of directors say their companies fully manage risk.

- Only 59.3 percent of directors fully understand how business segments interact in the company’s overall risk portfolio.

- Only 54.0 percent have clearly defined risk tolerance levels.

- Only 47.6 percent of boards rank key risks.

- Only 42 percent have formal practices and policies in place to address reputational risk.

Directors are, however, sensitive to the need for additional information:

- While 71.8 percent of directors believe they have the right risk metrics and methodologies in making strategic decisions, 47.6 percent of directors would like to see more data analysis related to the company’s risk profile.


The good news is that almost half of those surveyed think that they need more data analysis to determine the companies true risk profile. The bad news is the same number of Boards actually rank their risks. This means that half of those surveyed, do not rank their risks. Is this possible?

Certainly these organizations are measuring risk. They have tools and systems to gather the data and to analyze it. They have some kind of Risk Model to assist in the ranking of those areas that have high impact and high exposure. These areas of risk in the upper right quadrant, correct?

The report, is authored by Carolyn Kay Brancato, Matteo Tonello, and Ellen Hexter of The Conference Board. These findings are based on a comprehensive research effort on the topic that incorporated personal interviews with 30 board members, analysis of Fortune 100 board committee charters, and a broad survey of 127 board members. The report has not yet been released, but is forthcoming.


It seems that at least with this small number of board members surveyed, the topic of Reputational Risk is still a mystery as 58% say they still don't have policy in place. In Brian Murray's book Defending the Brand his introduction says it all:

Digitalization and the convergence of networked communications mediums have forever changed the way we live and conduct business. Broadband and wireless technologies, networked appliances, and multipurpose consumer devices promise to embed digital networks even deeper into our everyday routines. Unfortunately, while such technological advances have created fantastic opportunities, they have also facilitated new, unscrupulous business tactics and provided a haven for criminals who thrive on the victimization of corporations and consumers alike.


The Board of Directors who are not taking "Reputation Risk" seriously may have more work ahead of them. Protecting your assets goes well beyond the surveillance cameras and the clear presence of armed guards. 9 out of 10 incidents that impact corporate reputation will begin with information. And it may end with that information being in the hands of those that will exploit you with piracy, fraud, counterfeiting and deceit. Mr. Murray is correct when he says: "Fierce competition and economic pressures have exacerbated the situation as ethics fall by the wayside in the struggle for profits and survival."

Friday, June 09, 2006

The Modernization of Investigative Techniques Act (MITA)

As the Canadian terror plot unfolds, financial district operational risk managers and contingency planners are hard at work. Targets including the Toronto Stock Exchange, an unspecified military installation and the headquarters of the Canadian Security Intelligence Service were at the center of the plan.

The Royal Canadian Mounted Police announced Saturday that authorities had foiled a terrorist attack and said 12 men and five teenagers had obtained 3 tons of ammonium nitrate fertilizer, three times the amount used in the 1995 Oklahoma City bombing that killed 168 people.

But some police later said that although the suspects had sought to obtain ammonium nitrate, they actually had been delivered a safe substance instead during a sting last Friday.

According to court documents cited by the Canadian Broadcasting Corp., 20-year-old Zakaria Amara led efforts to buy enough ammonium nitrate through sellers on the Internet to make three truck bombs and had obtained a remote triggering device that investigators found at his home in Mississauga, just west of Toronto.


And the legislators are listening now to the Royal Canadian Mounted Police (RCMP) and other risk managers about reviving the "Modernization Investigative Techniques Act" (MITA). Even though this plot was interdicted, there may be back up operations in place. This new bill will give the investigators with greater tools to do their job and keep Canadians from the same fate as those in Oklahoma City and New York. In both cases, an Ammonium Nitrate truck bomb was used to inflict hundreds of casualties and hundreds of millions in lost property.

Police have credited Internet surveillance with playing a key role in last week's arrests of 17 terror suspects who are alleged to have plotted attacks in Toronto and Ottawa.

Police and intelligence officials have insisted that their technological capabilities have not kept pace with new technologies used by terrorists and organized crime, and have asked for the law to require telephone and Internet networks to build in quick and easy access for wiretaps and surveillance.


The Modernization of Investigative Techniques Act (MITA) is intended to ensure that telecommunications service providers build and maintain an interception capability on their networks that allows for the lawful interception of communications by law enforcement agencies and the Canadian Security Intelligence Service (CSIS).

Similar legislation is already in place in many countries including the United States, the United Kingdom, France, Germany and Australia. This Act will also require service providers to provide subscriber contact information upon request and in accordance with strict privacy safeguards.

Thursday, June 08, 2006

ID Theft: "Data Encryption Utilized on Premises"

Now that data theft has hit the US Military not just the veterans, agency CIO's and CSO's will be on the operational risk hot seat.

Personal information stolen from the home of a US government employee included data on 2.2 million military, officials said on Tuesday.

It was previously thought the data only related to some 26 million veterans.

The Department of Veterans Affairs (VA) said as many as 1.1 million on active service, 430,000 National Guardsmen and 645,000 reservists may be affected.


The lawsuits have started and they are asking for $1,000 for each person affected. That's just the beginning. The Inspector General's and the Auditors will be ramping up this season to make sure nothing like this happens again. Unfortunately, it will. As information becomes the most valuable target for theft, the criminals will cease robbing banks and homes for cash and credit cards and just steal computers and hard disc storage. Recent news has shown that banks are being broken into and nothing but the computers are stolen. Home invasions of prominent business executives or government workers who may also have that valuable information on their laptop may soon be at greater risk.

What is the answer to try and deter this wave of crime? Deterrence for the information itself. While many have objected to the value of encryption or encrypting data because it's too expensive, hard to administer or slows down the process, now it may be a more relevant option. See PGP to learn more.

Mobile computers are quickly emerging as the industry standard for increasing user productivity and efficiency. The portable nature of these devices also increases the possibility of loss or theft. Operating system login authentication alone cannot protect sensitive data on disks. If a system is ever stolen or lost, an enterprise may be exposed to significant risk of financial loss, legal penalties, and brand damage.

PGP Whole Disk Encryption for Enterprises locks down the entire contents of a laptop, desktop, external drive, or USB flash drive, including boot sectors, system files, and swap files. Encryption runs as a background process that is transparent to the user, automatically protecting valuable data without requiring the user to take additional steps.


Sometime soon the warning signs on the front lawn or on the bank door will say:

"Data Encryption Utilized on Premises"

Monday, June 05, 2006

Backdating: What is your E-Discovery Readiness Factor?

There is additional volatility in the wind as the SEC steps up investigations of "Stock Option" grants prior to August of 2002. The focus is on Backdating of Grants to executives and whether the grant dates were backdated to a time when the stock price was at it's lowest. Stock Option grants are to be priced with an exercise price that equals the current price of the stock. "Backdating" is the intentional grant date setting to a point in the past when the price was lower, so to increase the gain upon exercising.

In general, government probes are being launched to determine whether the grants were backdated to a point shortly before the company announced good news, so option holders could capitalize on a lower market value. Although the practice is considered controversial by many investors, backdating is legal if disclosed in regulatory filings, allowed by the company's own policies, and accounted for properly.

Six of the 22 companies named in the Moody's report are rated by the agency. They are: Affiliated Computer Services, American Tower, Caremark Rx, Jabil Circuit, Juniper Networks, and UnitedHealth Group.


What are the implications?

Accounting restatements to start with. Tax issues to follow. Even the resignations of senior executives in the midst of a continuing investigation by the SEC and Justice Department. The fact is that backdating is a credit risk on paper. It is an Operational Risk in behavior.

Be prepared to produce all relevant records upon receipt of the discovery request. Even the most proactive organizations are already doing their own internal reviews before the financial auditors ask for this information. Send a message to all relevant personnel responsible for the information archives to be ready to produce the documents on all stock option grants for new hires and executives who receive regular grants as part of their total compensation.

Compensation Committee's will soon be dictating that future grant option dates be timed for the "open window" after earnings announcements. This will increase the confidence that executives are not getting special treatment upon hiring or for annual performance bonuses. Look to the savvy organizations to also time their annual performance reviews with employees so that any other stock option grants are done so in the next calendar "open window".

Caremark Rx Inc. shortchanged investors by granting senior executives backdated stock options, allowing them to buy shares at artificially low prices and exposing the company to costly legal actions.

That's according to a shareholder derivative lawsuit filed against the company in federal court here.

The company denies that any backdating of options occurred.


The plaintiff threat is now gaining momentum and it would be in most high profile companies to recheck their "E-Discovery" Readiness Factor. The documents produced five or six years ago will no doubt be under the magnifying glass of the auditors and investigators in the weeks and months ahead.

Tuesday, May 30, 2006

Reinventing Corporate Security for Business Survival...

The Reinvention of the T-Mobile security assurance functions is another example of continuing convergence strategy at global organizations.

Now, in one room sit three of the top security executives recruited to effect change at T-Mobile by creating a new asset protection division. They are: Frank Porcaro, vice president and director of the new asset protection division; Ed Telders, director of information security, policy and compliance; and Rick Roberts, senior manager of security services. With them in the room, of course, is the pink elephant.

The asset protection group—Porcaro's group—is the heart of the makeover. Asset protection will converge physical and information security and, at the same time, create two new groups, including an information security group and a full business continuity/disaster recovery group. In the past year alone, asset protection has grown from four employees to 18, with several of those new hires having CSO-level experience.

Meanwhile, as it's under construction, asset protection is also being moved to another division, risk management and assurance, to be closer to related functions like audit and investigations. In the end, T-Mobile hopes to have one department—risk management and assurance (RM&A)—through which all security functions flow.


The strategy for Business Survival begins with an understanding of how your corporate assets are being attacked, both online and offline. Both physical and digital.

Our corporate assets are under attack by a continuous barrage of new laws, new employees, new competitors and new exploits. Business survival in the next decade will require a more effective and robust risk strategy to deter, detect and defend against a myriad of new threats to the organization.

Modern day attackers include hackers, spies, terrorists, corporate raiders, professional criminals, vandals and voyeurs. Simply said, these attackers use tools to exploit vulnerabilities. They create an action on a target that produces an unauthorized result. They do this to obtain their objective.


The Mission
Deter the attacker from launching a salvo of new threats to compromise your organizations assets. You first have to understand the value of your corporate assets to determine what are the most valuable in the eyes of your adversary. You must make it increasingly more difficult for these valuable assets to be attacked or you will find yourself under the constant eye of those who wish to create a significant business disruption.

These attackers are individuals who take on these quests or objectives for several key reasons. They include financial gain, political gain, damage or the simple challenge, status or thrill. It’s your job to create deterrence for each one of these objectives.

The Take Away

In order to effectively deter potential risks to your corporate assets, first you have to understand what they are and how valuable they are in the eyes of each kind of attacker. The more valuable the target, the more deterrence it requires.

Thursday, May 25, 2006

OPS Risk Consultancy Growing at 10% Annually...

Bank spending on operational risk management (ORM) software and services is set to grow at a compound annual growth rate of 4.7% to reach $1.38bn by 2010, according to an annual study released by Chartis Research.

Chartis says the ORM software market - estimated to be $163m in 2006 - is set to grow at a compound annual growth rate of 7.7% to hit $219m by 2010.

Meanwhile ORM related consulting services will continue to grow at a healthy 10.2% compound annual rate. This will be fuelled by Sarbanes-Oxley, Basel II and other risk or governance regulations. As the second wave emerges, Chartis says it expects systems integrators to increase their activity in this area and derive increased revenue from it.


"One reason ORM is getting hotter is due to the fact that legal counsel and outside counsel are advising clients to error on the side of over-compliance", said Peter L. Higgins, Managing Director & Chief Risk Officer at 1SecureAudit. "Showing the auditors and investigators a trail of due care and evidence of doing the right thing in their transparency and reporting is paramount. Those who are left out can trace the root cause of their fines and operational losses from ignoring such significant issues as suspicious activity reporting (SAR)", Higgins concluded. Until now, some organizations did not realize that they too are subject to such requirements:

Financial institutions have been filing increasingly larger numbers of Suspicious Activity Report (SAR) forms since the 2001 terrorist attacks, according to statistics from the U.S. Treasury Department's Financial Crimes Enforcement Network (FinCen). Financial institutions filed more than 689,000 SAR forms in 2004, and the SAR tally for 2005 appears likely to eclipse that mark. The first half of 2005 alone saw more than 435,000 SAR forms filed. The figures for the second half of 2005 and beyond are not yet available. There are several reasons for the increase in filed reports, including an expanded definition of the types of firms that must report suspicious activity, as specified by the Patriot Act. Since January 2002, the list has been expanded to include money-order issuers, insurance companies, broker dealers, mutual funds, currency exchanges, and futures commission merchants. Another reason is that financial institutions are erring on the side of caution, filing anything remotely suspicious in order to minimize the risk of fines or regulatory hassles. "What the lawyers are telling the bankers is, when in doubt file a suspicious-activity report," explains banking consultant Bert Ely.


A recent example of ignoring the compliance laws for the Bank Secrecy Act(BSA) that include Anti-Money Laundering(AML) programs can be found at Liberty Bank of New York.

Liberty Bank failed to implement an adequate system of internal controls to ensure compliance with the Bank Secrecy Act and manage the risks of money laundering. Liberty Bank lacked adequate written policies, procedures and controls reasonably designed to ensure the detection and reporting of suspicious transactions. Liberty Bank's policies and procedures did not clearly delineate responsibility for detecting, evaluating and reporting suspicious activity, or provide guidance and instruction on the decision and approval process for suspicious activity reporting.


The reason that ORM consutling services are growing at +10% annually is because there are still people out there who don't think they are a Money Service Business(MSB) and secondly those that realize they are, have not implemented the programs effectivley even at some of the larger institutions.

Friday, May 19, 2006

Hurricane Preparedness Week: May 21-27...

"Preparation through education is less costly than learning through tragedy."
- MAX MAYFIELD, DIRECTOR
NATIONAL HURRICANE CENTER

History teaches that a lack of hurricane awareness and preparation are common threads among all major hurricane disasters. By knowing your vulnerability and what actions you should take, you can reduce the effects of a hurricane disaster. This year Hurricane Preparedness Week is May 21-27, 2006.

As NOAA will announce the 2006 Atlantic Hurricane Season Outlook at 11:00 AM EDT Monday, one can only wonder if we will have more than the 26 named storms last year. The preventive measures that have taken place are many and yet are we still as prepared as we could be? The 2005 hurricane season, the busiest and most destructive on record with 28 named storms, 15 of them hurricanes, has made many people along the Atlantic and Gulf coasts more wary as they prepare for a 2006 season. This year, researchers predict 17 named storms, including nine hurricanes.

In the 2005 Business Continuity - The Risk Management Expo survey of 251 companies raised many questions about the 30% who said they did not have a Business Continuity plan in place. The key concerns are as follows:

1. Even if there was existence of a plan in 70% of the respondents, only 27% of the key personnel are even trained on the plan.

2. Does the plan cover all hazards of just the ones that have been prioritized by the key staff?

3. How does staff communicate to their employees during the crisis?

4. How would share holders, institutional bond holders, and the board view the company when they find out that the company doesn't have or hasn't exercised their crisis management plan?


In any plan, people are the key to business recovery and survivability. And in post disaster analysis, little consideration was given to the supply-chain. The vendors, suppliers and service organizations that keep your corporate operations running each day. Many suffered tremendous delays in the recovery process because contingencies were not in place prior to the crisis event.

Communications is always the biggest failure during times of crisis. When the primary communications systems fail, that is when you will know if you have been training enough. Victims will soon find out how well you have prepared. Accurate, timely, consistent and relevant information are the foundation for any resilient framework for communications. Most city, state and federal emergency-management authorities still can't communicate by phone or radio in a crisis, because a $2 billion special outlay for so-called "interoperability" is mired in legislative wrangling or being spent without federal coordination.

Wednesday, May 10, 2006

Flu Pandemic: NIMS to the Rescue...

An operational risk benchmarking survey conducted by The Risk Management Association in April 2006 indicates that many financial institutions are preparing for a possible flu pandemic.

Key findings are:
-- Large North American institutions with asset sizes greater than $10 billion are taking the threat seriously. Least concerned are banks with assets of less than $500 million.
-- Most banks expect disruptions to last three to nine months.
-- Two-thirds expect 30% or more of their key workers to be absent during peak periods of disruption.
-- More than 60% have identified someone to lead the planning, but less than a third have rolled out plans and begun regular testing.
-- Only about a third of banks are well along in establishing policies for such things as employee compensation, evacuations, and reducing workplace transmission of risk.

Participants in RMA's "How Serious Is the Threat of a Pandemic and What Are Bankers Doing about It" included 190 financial institutions. Of those, 168 are from North America, 14 from Europe, and eight from Asia, Australia, and Africa. The results are broken out by geographic area and asset size, with respondents' asset sizes ranging from under $500 million to over $500 billion.


Continuity of Operations and Business Crisis Conintuity Management experts are prepared to handle the requirements from the two thirds of the banks who still HAVE NOT begun regular testing. Along with the typical exercises where a third of the work force stays home for a day to see how the IT assets handle the load, there is much to do with the testing of your third party suppliers and critical supply chain vendors.

Make sure that the people you trust to get you through the tests, exercises and consulting advice are NIMS compliant. The National Incident Management System (NIMS) in the US is the standard for a comprehensive, national approach to incident management that is applicable to a full spectrum of potential incidents. This includes a myriad of hazard scenarios, regardless of size or complexity.

All corporate officers who plan on being part of the Unified or Area Command must have the tools and the training far in advance to accomplish COOP or BCP goals. Here is the scenario:

"An outbreak of a suspicious flu-like virus has broken out throughout the State. So far, victims seem to have contracted the virus through personal contact, but public health officials cannot trace the source of the virus to naturally occurring outbreak. Because the contamination area is spreading, the entire region has been placed on alert. This incident should be managed by an Area Command."


Using Incident Command System (ICS) protocols in combination with the NIMS framework allows the organization to become more resilient to the risks associated with a major disruption in business operations. This may include denial of service, both online and offline, lack of key personnel, or quarantine of company facilities. For more information and answers to how to get your company NIMS compliant and ready for the next tornado, hurricane, earthquake or terrorsit incident, see WashingtonDC FIRST.

Monday, May 08, 2006

Criminal Intent: Digital Surveillance Dominates Q1...

Seventy percent of malware detected during the first quarter of 2006 was related to cyber crime and more specifically, to generating financial returns. This is one of the conclusions of the newly published PandaLabs report, which offers a global vision of malware activity over the first three months of the year. Similarly, the report offers a day by day analysis of the most important events in this area. This report can be downloaded from Panda.


This report confirms the trend of criminal intent of the developers of malicious code to steal information for financial gain. Most successful are the bots and spyware code that lives silently on your corporate executives lap top after spending a week away traveling. Since the tendency for using "Free WiFi" exists in many hotels and other travel zones, the lap top becomes vulnerable to an infection. And when that lap top is reconnected to the docking station back at HQ, the real threat begins.

Digital Surveillance using malicious code is not new. The art is now a science. Ask any 19 or 20 year old in the Engineering or Computer Science Department at a major university. The use of spam and other techniques for spreading the use of the malicious code makes it imperative that your detection and defense strategies are sound and operating on a daily if not hourly basis. Organizations are under a barrage of attacks that are random and sophisticated, and are deployed with a multifaceted approach to gain the required exploit results. These new blended threats include a salvo of virus and worm technology into an smart and yet elusive attack vehicle.

According to FBI studies, more attacks are propagated and launched internally than externally. Companies are deploying internal intrusion detection systems that place monitors or agents on multiple department segments, and e-mail anti-virus systems that prevent viruses from moving.


Many organizations are exploring new devices that IDC has coined Unified Threat Management(UTM) appliances: Effective UTM requires:

* Low total cost of ownership. Total system costs must be less than the expected loss if there are security breaches due to lack of control. The solution must decrease the time to protection and ongoing overhead to achieve a lower total cost of ownership. Security threats are constantly changing, and the system must adapt to these changes on a constant basis with little to no user intervention.

* Coordination. Security breaches can occur between mismatched technologies, so whenever possible layer the security approach. Since many threats have multiple attack signatures, one layer prevents a certain portion of an attack while another layer catches the rest. The network’s security posture must adapt in unison for comprehensive protection.


* Reduced complexity.
To achieve maximum security, solutions must be easy to implement, and the components must work well together; if not, incident detection (and resolution) becomes difficult if not impossible. Vital considerations include time-to-response and automation of appropriate protection.

Consider an evaluation of SonicWall to find all three advantages in your enterprise.

Wednesday, May 03, 2006

The Risk of External Supply-Chain Interdependencies...

In what countries do you operate? Do you source raw materials from politically unstable regions of the globe for your end products? Are you subject to a myriad of taxes, tariffs and duties including new security measures in our ports? How complex is your sales and distribution channels? At the end of the day the big question is: What is my financial, operational and economic risk exposure in the event of a disruption in our external supply-chain?

The risk of external supply-chain interdependencies has been talked about for many years. Monte Carlo simulations, scenario analysis and other methods have been effective in the determination of what the magnitude of a loss event may look like. Once the dollar analysis is done and you know that your exposure is $XXM. or $XB., then what do you do with that information?

Much of the outcome of this exercise may go into the next strategic planning phase on who you need to partner with or create an alliance with in order to satisfy certain future contingencies. Once you realize that you need more than one source for a raw material or a key service to run your business, then the real analysis begins. Who and where do I find the best alternatives for this vital component in my global supply-chain?

If you begin your due diligence now on the top 10 vital components in your supply-chain contingency planning exercise you might have these all completed, through the legal department and signed within a few months time. If you are lucky. Then you must really test the new supplier or source for your product or service to determine how smooth they operate when you pick up the phone or send the "Alert".

The ultimate architecture requires an "Adaptive Supply-Chain" that will provide cross-border agreements and resilient mutual-aid partners to assist in times of crisis. Just shifting production from one country to another may not be enough to mitigate the disruption in a vital component of the manufacturing process or delivery of services. Having a reflexive and responsive supply-chain is only one of many contingencies in a robust Business Crisis and Continuity Management plan.

When was the last time you reviewed your key suppliers and sourcers plans for continuous operations and their record for testing these plans? This will be the place you find your greatest weakness in external supply-chain management. In the US, it is now less than 30 days away from the next hurricane season. Gasoline prices and fuel costs are impacting every sector of the economy. One thing is for sure. You are in complete control of your readiness factor. And your readiness factor is directly proportional to your interdependencies in your supply-chain.

Friday, April 28, 2006

Bank Fraud | Chicken Little | Las Vegas. Learn the Connection...

The quest to tame bank fraud and money laundering is upon us. The OCC and other reg agencies in the US are finding the needles in the haystack. This latest Money Laundering Terrorist Connection is only the first of many such investigations:

The brother of a man suspected of ties to the al-Qaida terrorist group has been arrested in Utah and indicted on charges of loan fraud and money laundering. The question that federal authorities are trying to answer is whether Sharif Omar funneled some of that money to support terrorist activities. Omar is the brother of Shawqi Omar, who is being investigated for ties to al-Qaida in Iraq.

"We do have some indications of where the money went," said Greg Bretzing, a special agent with the FBI's Joint Terrorism Task Force in Utah. "We know some went to Jordan overseas and a lot went to personal accounts. What exactly it was spent on or what happened to it overseas is still under investigation."


And if that is not all the bankers have to worry about. International Phishing is gaining momentum:

The number of phishing attacks targeting non-English speaking financial institutions is on the rise.

Attacks targeting countries outside the English-speaking world now represents almost 40 per cent of worldwide phishing targets, according to data processed by RSA Security's Anti-Fraud Command Centre. RSA said it has shut down more than 10,000 phishing attacks hosted in 70 different countries.
Click here to find out more!

The primary phishing targets worldwide still remain English speaking countries such as the US and the UK, followed by Australia and Canada. The United States alone accounts for approximately half of fraudulent email attacks. Over the last six months or so there's been an upswing in attacks targeting European countries, including Spain, Germany and Italy, as well as the Netherlands, Scandinavia and France.


What is the answer to mitigating these Operational Risks in your institution? Look no further than the line items in the budget for safety, security and continuity of your next fiscal year. After the last three days at the GovSec|U.S. Law Enforcement| Ready Conference I'm convinced that the likes of people who are technology experts from firms like Akamai, Asst. Deputy's and former operators of 3 Letter agencies along with hundreds of other small business vendors for Homeland Security solutions have the same play book. It's titled: Chicken Little. Because the sky is falling. Every once in awhile it would be refreshing to see and hear a presentation about risk, security, safety and business continuity when the speaker is not talking about or yelling about how the "Sky is Falling" and the money isn't there to fix the problems.

Why is it that the people who are doing all of the presentations and speaking are from non-profits, government or lobby shops in DC? They are the people the private sector pays to get influence for their projects in Congress and they have to make sure they keep getting the funding to keep up their campaigns.

Bank fraud and Phishing will not ever be solved with more money from the US Treasury or any other countries reserves but it doesn't hurt to ear mark a percentage of revenues to fund the budget for safety, security and continuity of operations. If only some companies would behave like the pinnacle of publicly traded, high target and continuously operating organizations known on the planet as Las Vegas Casino Hotels.

For a real look into what the banks and other institutions, either public or private need to do to mitigate risk, protect assets and keep the enterprise safe, secure and operating 24/7 and 365 days a year, see InfraGard Nations Capital Members Alliance

Monday, April 24, 2006

AML & Data Theft: Risks to International Banks and Domestic Universities...

If you are a parent of a son or daughter at an institution of higher learning, this is a notice that makes you shake your head in disappointment. And if you are Chief Information Security Officer at University of Texas - McCombs you wonder how this could happen again?

Unauthorized Access of Computer Records Discovered at The University of Texas at Austin

AUSTIN, Texas –The University of Texas at Austin officials announced today (April 23) that an unknown person or persons has gained entry to the McCombs School of Business computers and gained unauthorized access to a large number of McCombs’ electronic records.

“It is our highest priority to notify those who may be affected by this security breach,” said university President William Powers Jr. “We have notified the attorney general and his Internet enforcement unit and are doing everything we can to protect those whose information has been accessed unlawfully.”

The security violation was discovered late Friday, April 21, and the university has devoted all available resources to identify the extent and source of the breach. Some of an estimated 197,000 records were accessed.

An investigation has determined that information from the business school’s computer system was obtained as early as April 11, including some Social Security numbers and possibly other biographical data, including those of alumni, faculty, staff and current and prospective students of the business school as well as corporate recruiters.


Even though the transnational nature of data theft is a major financial concern for law enforcement, the banking community and those potentially consumers impacted at this university, there are other priorities that may be of greater risk to US financial institutions. Money Laundering and the enforcement of the Bank Secrecy Act (BSA) is a continued United States Treasury priority along with the Office of the Comptroller of Currency (OCC).

Metropolitan Bank & Trust is one of the latest institutions to be penalized for violations of BSA.

An examination of Metrobank by the Office of the Comptroller of the Currency found deficiencies in Metrobank's anti-money laundering program, revealing that Metrobank had failed to implement an adequate system of internal controls to ensure compliance with the Bank Secrecy Act and manage the risks of money laundering involving funds transfers. The examination also revealed that Metrobank had failed to conduct adequate independent testing to allow for the timely identification and correction of Bank Secrecy Act compliance failures. These failures in internal controls and independent testing led, in turn, to failures by Metrobank to identify and report suspicious transactions in a timely manner. The failures of Metrobank to comply with the Bank Secrecy Act and the regulations issued pursuant to that Act were
significant.

Metrobank and Metro Remittance handle large volumes of funds transfers involving the Philippines and, since September 2003, the People's Republic of China. The volume of funds transfers to the Philippines in 2003 was 162,000 transactions totaling $208 million. Prior to February 11,2005, the Philippines was included in the list of Non-Cooperative Countries or Territories designated by the Financial Action Task Force on Money Laundering.


While this civil penalty will result in a fine of only $150,000., you could predict that the cost will be much higher. A system implemented to assist with due diligence installed in 2003 has not been effective and the use of manual controls is the source of much of the banks failures in a fully compliant Anit-money laundering (AML) program. The passage of the USA PATRIOT Act, after the terrorist attacks of September 11, 2001, has placed greater emphasis on AML issues. Increased scrutiny of potential laundering, and stringent requirements placed on institutions to increase their efforts to detect money laundering by terrorist groups, reinforces the importance of the need for certified professionals who protect institutions from potentially devastating laundering crimes.

The lack of oversight by banking institutions or universities comes back to a single aspect of Operational Risk Management. Without a framework for managing risk of all kinds and having an effective system for continuous risk monitoring, you are setting yourself up for a major loss.

Wednesday, April 19, 2006

The Next Wave of Operational Risk Innovation...

Today, if you are reading this blog you may have found your way here from Yahoo like tens of thousands of others have. Or maybe from another source on the web. However, when you search for Operational Risk Management at Yahoo, you get This Blog at the top of the first page of search results. Try searching on the same exact terms on Google, and the blog doesn't make the cut for the first page of search results. When you are searching for relevant information on "Operational Risk Management" (ORM), it's always important to look in more than one place and use more than one search engine. That's just life on the Internet in this age of paid advertising and mathmatical decisions on who deserves the top spots on search results.

Several years ago, there where only a few people who really had any idea what Operational Risk was all about. The US Navy / Marine Corps for one. They know that the work they performed was full of hazards and risk. If they didn't do something to systematically reduce operational risks in every process they performed or mission they executed, they knew that more people might be injured or die.

And what is the Navy's definition of ORM:

ORM is a decision making tool- used by people at all levels to increase operational effectiveness by anticipating hazards and reducing the potential for loss, thereby increasing the probability of a successful mission.

ORM is an effective tool for maintaining readiness in peacetime and success in combat because it helps conserve assets so they can be applied at the decisive time and place.

Applying the ORM process will reduce mishaps, lower injury and property damage costs, provide for more effective use of resources, improve training realism and effectiveness, and improve readiness.


At the same time, you have the Global Financial community wrestling with something called Basle:

The Basle Committee on Banking supervision has recently initiated work related to operational risk. Managing such risk is becoming an important feature of sound risk management practice in modern financial markets. The most important types of operational risk involve breakdowns in internal controls and corporate governance. Such breakdowns can lead to financial losses through error, fraud, or failure to perform in a timely manner or cause the interests of the bank to be compromised in some other way, for example, by its dealers, lending officers or other staff exceeding their authority or conducting business in an unethical or risky manner. Other aspects of operational risk include major failure of information technology systems or events such as major fires or other disasters.


The prudent Risk Manager today can see the similarities in what the US Marines and the Bankers are trying to accomplish. The good news is that the convergence of what the military has known for years and the knowledge that the bankers have gained from having their institutions fail, provides us with a vast foundation to begin the next wave of innovation.

The innovations surrounding Operational Risk Management are upon us. Now it's our duty as practitioners to "Walk the Talk" and to "Practice What We Preach". Get busy!

Sunday, April 16, 2006

The Speed of Loss in the Connected Economy...

Operational risks are also becoming more important in the large, complex financial institution as more technology and automated processes are used in all areas of operations. When banks used manual processes, errors were confined to the limited area where the employee worked. But in a modern technology setting, factors such as breakdowns in controls, errors in software code, and processing stream interruptions can have enterprisewide effects on the performance of the organization.

Recent history provides us with ample evidence that operational risk can be significant. Large financial institutions have reported operational losses from breakdowns in operating controls that, in some cases, have exceeded their credit- or market-related losses. In the area of legal risk, for example, many institutions have learned that failing to identify and promptly correct problems can result in losses that significantly exceed management's initial expectations. Over the past decade, large financial institutions have experienced more than 100 operational loss events in excess of $100 million each; some of these individual operational losses, resulting from fraud, rogue trading, and settlements stemming from questionable business practices, have exceeded $1 billion.


These remarks by Ms Susan Schmidt Bies, Member of the Board of Governors of the US Federal Reserve System, at the OpRisk USA 2006 Conference reflect a growing emphasis on Operational Risk. This focus translates to a greater regulatory attention to the quality of data that institutions are utilizing for their calculations.

The level of data quality has been a management challenge for decades. The speed of change in the connected economy has created an even larger tempest for institutions to grasp. The physical and logistical problems associated with moving, archiving and retrieval is only part of the data puzzle. As Ms. Schmidt Bies has so clearly concluded, the simple fact that "Automation" creates an even larger field of risk to monitor, provides an even greater opportunity for failure. The absence of data doesn't decrease the amount of risk. What risks should we focus on? The normal and expected risks from external data, or the unexpected risks that have been encountered before.

If you think about the places where the velocity of data is the greatest, then you have a place to begin. The processes and business functions associated with traditional annual financial audits and other external data give us a known history of loss events that need continuous scrutiny. However, it is those key risk indicators (KRI's) in places where the insitutions knowledge of the root operational risk causes combines with little or no history of losses that remains the nexus for concern.

Thinking beyond the current horizon is where the focus should be on active risk management scenarios.

Wednesday, April 12, 2006

CRO Strategy: Balancing Risk Across Functions...


RiskCenter (04/04/06) ; Kloman, H. Felix
At a recent Global Association of Risk Professionals (GARP) conference in New York, risk managers highlighted the importance of accurate data being provided to the appropriate decision makers in order to make the best decisions for a given situation, and risk managers also noted that they needed to be independent and objective at all times. Risk management tasks should not be absorbed by finance, accounting, or compliance functions, according to experts, because balance is needed between those functions and the risk managers' function as an educated "fortune-teller."

Chief risk officers (CRO), for instance, should be familiar enough with operational functions, while still remaining outside the internal politics of those functions, allowing them to make educated and objective decisions. Panelists at the conference touched upon the learning experiences they had from risk management mistakes and how they turned those mistakes into opportunities for their firms. For risk managers in the banking sector, Basel II is the latest challenge, especially when it comes to allying risks with capital holdings and the disclosure of how those calculations and decisions were made.


CRO's today are coming from more diverse backgrounds than from years past where they may have lived most of their careers in Finance or Internal Audit. Educated fortune tellers are a thing of the past as new tools, systems and sensors provide the modern CRO with new insight. As new tools are introduced to financial institutions to assist them with creating and mining loss event data, the regulators will be watching. What methodology and frameworks are acceptable? What process was utilized for critical calculations?

Lenders that are not banks or owned by banks--and therefore not subject to FDIC rules--are regulated by states. With the growth of these aggressive and potentially deceptive lending practices, state regulators have come under pressure to issue new rules or guidance to ensure that these "exotic loans" do not continue unchecked.


A Chief Risk Officer needs to be active with both state and national associations to keep in touch with the guidance that may be forthcoming.

Monday, April 10, 2006

Coaching to Mitigate Risks on the Front Line...

HR Troubles are growing in the corporate ranks.

New and various studies reveal that unethical activity continues to occur in the private sector, even while SOX watch dogs are in place and whistle blowers are amoung us. Studies also suggest that large investments in compliance programs have had little impact. Indeed, 16 percent of HR professionals say they have quit their jobs for ethical reasons, according to a 2005 survey by SHRM, the top five ethical lapses given for resigning are:

Lying by management

Title VII violations

The falsification of reports and records

Employee privacy violations

Employees committing fraud


It's not surprising that these compliance programs may be having trouble getting the human behaviors to change. Coaching employees on a regular and consistent basis is far more effective than a one-time class upon hire. Management behavior is the litmus test on whether the culture of an organization could have the potential to become more ethical.

The enforcement of ethical and legal issues is often left up to corporate human resources (HR) departments, when it should be handled daily by front line managers. This is where the behavior or incident is observed in real-time and has the most credibility for making a coaching or serious discussion successful.

Thursday, April 06, 2006

Phishing: Why it Works and What is Next...

If you have ever wondered Why Phishing Works, you need to read this article by Rachna Dhamija at Harvard University, J. D. Tygar, and Marti Hearst from UC Berkeley.

What makes a web site credible? This question has been addressed extensively by researchers in computer-human interaction. This paper examines a twist on this question:

What makes a bogus website credible?
In the last two years, Internet users have seen the rapid expansion of a scourge on the Internet: phishing, the practice of directing users to fraudulent web sites. This question raises fascinating questions for user interface designers, because both phishers and anti-phishers do battle in user interface space. Successful phishers must not only present a high credibility web presence to their victims; they must create a presence that is so impressive that it causes the victim to fail to recognize security measures installed in web browsers.


The phishers are very good and spoofing financial services web sites to the tune of more than 2 million users being fooled last year alone. The web site designers are doing their best to create a site that is so sophisticated in it's look that it is more difficult to replicate on a fraudulent site and URL. The point is, we as consumers are always being asked for information only we would know, or information that we have to authenticate ourselves.

Why can't we turn this problem upside down? Why can't I authenticate the banks web site by asking the bank for a piece of information that only they have or would know the answer to? Some tools and technologies already exist to help with this upside down thinking. Bank of America is using SiteKey, that retrieves a graphical image from it's database, one that I have personally picked and no one else "should" be able to replicate. The answers are on the way.

Chris Young
Senior Vice President and General Manager, Consumer Solutions Division
RSA Security

As senior vice president of the Consumer Division at RSA Security, Christopher Young is responsible for driving the company’s consumer identity protection strategy, including the delivery of RSA® Authentication Service to provide simple and secure layered and two-factor authentication to all online users.

Cyota FraudAction Service is just one example of some new and exciting anti-fraud solutions on the way.

Friday, March 31, 2006

An OPS Risk Refresher...

What are Operational Risks? Here is a refresher for the Financial Services Sector:

Key People Risks

Employee fraud or malice Including collusion, embezzlement, sabotage of bank reputation, money laundering, theft of physical and intellectual property, programming fraud including virus introduction

Unauthorized activity
Including misuse of privileged information, churning, market manipulation, activity leading to deliberate mis-pricing or with unauthorized counterpart or unauthorized product, limit breach, intentionally incorrect models such as deliberate changes to parameters, activity outside exchange rules, illegal/aggressive selling tactics, Ignoring/short-circuiting procedures deliberately

Employment law Including wrongful termination of employment, discrimination/equal opportunity, harassment, non-adherence to other employment law, non-adherence to Health and Safety regulations Workforce disruption Industrial action and other forms of disruption

Loss or lack of key personnel Lack of suitable employees and loss of key personnel



Key Systems Risks


Technology risk
Inappropriate architecture

Investment risk Including strategic platform or supplier risk, inappropriate definition of business requirements, incompatibility with existing systems, obsolescence of software

Systems development and implementation Including inadequate project management, cost/time overruns, programming errors (internal/external), failure to integrate and/or migrate from existing systems, failure of system to meet business requirements

Systems capacity
Including lack of adequate capacity planning, inadequate software Systems failuresIncluding network failure, interdependency risk, interface failure, hardware failure, software failure, internal telecommunication failure

Systems security breaches
Including external security breaches, internal security breaches, programming fraud, computer viruses


Key External Risks

Legal/public liabilities Including breach of fiduciary duty, etc. Criminal activitiesIncluding money laundering, terrorism, robberies, etc.

Outsourcing/supplier risk Including breach of service level agreement, supplier failure, etc.

Insourcing risk Including failure of firm as supplier of services to third-party

Disasters and infrastructural utilities failures Including fire, flood, and failure of critical supplies etc.

Regulatory risk
Including change of regulatory rules etc.

Political/government risk
Including expropriation of assets, changes in tax regime, law and industry regime, etc.

Remember, this does not even cover the largest category of Operational Risk, Processes. The process associated with our different procedures, protocols and mechanisms for doing business are one of the greatest areas to incur loss events. Errors, ommissions and lack of training are just a few of the areas that need to have consistent monitoring and continuous auditing.

Friday, March 24, 2006

Availability Bias: The Risk of Low Probabilities...

Should corporate America be concerned about weapons of mass destruction? How do you prepare for risks beyond your own workplace? Rad Jones from the School of Criminal Justice, Michigan State University, recently talked about a critical incident exercise he has prepared exclusively for CSO Magazine.

Rad Jones, formerly with the Secret Service and later on security projects with Ford Motor Company, emphasizes that you don't have a plan unless it has been exercised. This is especially true if you have not involved the local first responders in the local area. Role playing in exercises on scenarios that are real world and done on premises is a key component of the preparedness equation. What is left out in many instances during the exercise with the local police, fire or EMS is the Incident Command with the top brass or executives who may be in other locations across the country or the globe. This was witnessed in the Hurricane Katrina catastrophe.

Every metro area in harms way has the ability to do these exercises even on a micro basis. The single 15 story building, the business park surrounding the suburban mall or hotels and even a square block in a downtown city location is a good start. This coordination, planning and continuity builds a new level of resilience into the fabric of the community. This effort has been going on since 2003 with a consortium in Chicago, IL called ChicagoFIRST. This particular effort was spearheaded by the large financial institutions in the city who wanted to get a say and a seat inside the JOC (Joint Operations Center).

The spirit of ChicagoFIRST is spreading with the launch of WashingtonDCFIRST, a consortium based in the Wasington DC metro area. This project will be focused on the critical infrastructure private sector and the relevant interfaces to the local first responder jurisdictions. Collaboration with the Council of Governments (COG) will add the planning already underway for the past few years on issues such as interoperability and credentialing. As an example, the FCC has adopted a plan to establish a Public Safety and Homeland Security Bureau. The new Bureau is designed to provide a more efficient, effective, and responsive organizational structure to address public safety, homeland security, national security, emergency management and preparedness, disaster management, and other related issues.

Unlike other private sector initiatives, WashingtonDCFIRST will involve all the critical infrastructure sectors and the private companies who represent the largest employers around the beltway
including: Pepco, Verizon, Washington Gas, Exxon Mobil, AOL, and the Water Utilities. Much of the focus will be on availability bias.

Availability bias is why the U.S. has spent the past four years focusing on scenarios involving terrorism, after the so-called failure of imagination that preceded 9/11. What have politicians and citizens done for the past four years if not imagine terrorism?

And it's why many observers are now questioning whether the country should have spent that time planning not for terrorism but instead for other potential catastrophes. Like a deadly pandemic. Or major earthquake. Or hurricanes.

"One of the key dangers is that people are always focusing on the last catastrophe," says Robert Muir-Wood, the London-based chief research officer for Risk Management Solutions, which does economic risk modeling for the insurance industry. "It's a big challenge to keep everything in perspective and not be biased by what has last happened."

A true risk-based approach means that, when all else is equal, one must override the availability bias and focus on the most likely future scenarios. Unfortunately, figuring out the probability of any given scenario raises its own set of complexities.


The most probable risks that you train and exercise for, will be the incidents that you will be most prepared to handle. Suffice it to say, that the risks that you don't plan for because they are too low probability, will be the incidents or catastrophes that catch you off guard. Think about it. Not preparing and training for the low probability scenarios could cost you millions or billions and maybe your life.

Wednesday, March 22, 2006

Pandemic Flu: Financial Institutions Contingency Strategies...

The Board of Governors of the U.S. Federal Reserve System, the Federal Deposit Insurance Corporation, the Office of the Comptroller of the Currency, and Office of Thrift Supervision are issuing an interagency advisory to financial institutions and their technology service providers.

This advisory is intended to raise awareness regarding the threat of a pandemic influenza outbreak and its potential impact on the delivery of critical financial services. It further advises financial institutions and their service providers to consider this and similar threats in their event response and contingency strategies. This issuance discusses the National Strategy for Pandemic Influenza (National Strategy) and the roles and responsibilities it outlines for financial institutions.

Critical infrastructure entities also must be engaged in planning for a pandemic because of our society’s dependence upon their services. Both the private sector and critical infrastructure entities represent essential underpinnings for the functioning of American society. Responsibilities of the U.S. private sector and critical infrastructure entities include the following:

• Establishing an ethic of infection control in the workplace that is reinforced during the annual influenza season, to include, if possible, options for working offsite while ill, systems to reduce infection transmission, and worker education.

• Establishing contingency systems to maintain delivery of essential goods and services during times of significant and sustained worker absenteeism.

• Where possible, establishing mechanisms to allow workers to provide services from home if public health officials advise against non-essential travel outside the home.

• Establishing partnerships with other members of the sector to provide mutual support and maintenance of essential services during a pandemic.


For more information see the official U.S. Pandemic Flu site.

Thursday, March 16, 2006

Whistleblowers: The Risk of Unethical Corporate Behavior...

To some people, Sherron Watkins is a hero. To others, she is an Enron Whistleblower that has capitalized on her now famous memo.

Ms Watkins had previously sent Mr Lay an anonymous memo questioning the use of off-balance sheet financial partnerships which were then running up huge losses.

In the memo, which she read out in court, she had expressed concerns that Enron could "implode in a wave of accounting scandals".

She added: "This was not just aggressive accounting, it was fraudulent accounting. I couldn't believe we had done it."


Implementing an effective ethics and compliance program in corporations requires a robust educational and legal strategy. Awareness development, effective policy design and administration is imperative if the organization is going to have any chance of achieving high marks in Corporate Governance.

David Gebler makes some valid points in this article:
Moving in the Right Direction

How do compliance leaders move their organizations to these new directions?

1. The criteria for success of your ethics program must be outcomes-based. Merely checking off program elements, even from the seven steps of the Federal Sentencing Guidelines, is not enough to change behavior.

2. Each organization must identify its own key indicators of its culture. Only by assessing its own ethical culture can a company know what behaviors are the most influential in effecting change.

3. The organization must gauge how all levels of employees perceive adherence to values by others within the company. One of the surprising findings of the (2005 National Business Ethics Survey) (NBES) was that managers, especially senior managers, were out of touch with how non-management employees perceived their adherence to ethical behaviors. Non-managers are 27 percentage points less likely than senior managers to indicate that executives engage in all of the ethics-related actions outlined in the survey.

4. Formal programs are guides to shape the culture, and not vice-versa. People who are inclined to follow the rules appreciate the rules as a guide to behavior. Formal program elements need to reflect the culture in which they are deployed if they are going to be most effective in driving the company to the desired outcomes.


While there may be some who say that a whistleblower is just a discouraged or passed over employee, it may be the origin of a corporate environment that is ready to implode. Fraud and other unethical corporate behavior is a combination of poor operational risk management controls and the people who perpetuate the culture of dishonesty. In a recent survey by Protiviti, companies continue to admit to poor risk management practices.

Other findings of the survey:

* 43 percent of executives consider financial reporting and Sarbanes-Oxley Section 404 compliance to be very significant risks.

* 49 percent tie business success to client satisfaction, believing potential weaknesses in this area pose a very significant risk. Executives said the following risks affect their company's ability to sustain customer satisfaction: operating performance; materials procurement; business continuity; and fraud matters.

* 45 percent of executives cited information systems and IT security as potential areas of vulnerability.

Friday, March 03, 2006

Keeping Your Business Clean...Revisited

This two year old article is still so true. Worth revisiting in a more risk management conscious corporate environment.

Keeping Your Business Clean - CSO Magazine - June 2004

Take this quiz to test the ethical health and well-being of your business.


BY ANONYMOUS

A COLLEGE PAL OF MINE—a corporate lawyer at a major, publicly traded company—has been watching all of the corporate-integrity meltdowns from his not-so-distant vantage point. Just for fun, he helped me devise a quiz of sorts to check out the "uprightness" of my own situation at my company. I was shocked and disturbed enough with my results to share them here (under the protection of anonymity, of course).

Maybe I'm a good Samaritan, but I care about America's corporations, and I hope our times offer an opportunity to change some thinking. Take this little corporate hygiene quiz with a few of your trusted business pals over a latte or two. And since catharsis is good for the soul, I'll share my answers with you here. I used a scale of one (not so much) to five (absolutely) to get a numerical sense of where I stood.

To start, does your business depend on a complex technical environment with significant uptime reliability?


Aren't we all increasingly reliant on a networked environment with nodes, access points and critical intersections in places that we can't see or control? Uptime reliability is important for everybody these days, but it's an expected cornerstone of businesses that feel they need to hire a CISO. I give myself a four on this one.

Does your company have operations in any country below the equator?


Many U.S. companies have core business processes located in countries below the earth's beltline. Security risks exist there that make knowledgeable security professionals twitch every time their phone rings: kidnappings, corruption, incompetent and criminal law enforcement, Internet crime, organized crime, drugs, money laundering, an overall unsafe environment with too many Foreign Corrupt Practices Act temptations. But what are you going to do? The labor is cheap and we have to be competitive. My company is moving in that direction but not there whole hog yet. So I'll give us a three on this one.

Would you characterize the velocity of your company's business as high-speed?


How about warp speed? How else can we continue to satisfy Wall Street and our fickle shareholders? We're all being pushed to do more with less. And there's so much going on in the back draft of this fast pace, I wonder what the hell else I'm missing. I'll take a five on this one. I'd take a six if it were allowed.

Do you forgo a criticality rating to identify shortcomings in business controls and security measures?


With all the open books and disclosure emphasis these days, the lawyers are really nervous about recording any risk information that could come back to haunt us. As a security professional, I've always lived with criticality ratings—it's all about the likelihood of problems we need to be prepared to address. But I know for a fact that we have no organized process for doing this across the business. In the aftermath of Sarbanes-Oxley, our auditors now rank their findings; but that's ex post facto and, besides, an audit is cyclical and periodic. This is all about what keeps knowledgeable risk managers awake at night and what we are missing. I'd better take a four (and hope for the best).

Does your corporate risk-management model discourage individual managers from seeking out vulnerabilities in the system of controls?

My company doesn't have a risk-management model, per se—and then blame is typically parceled out to the lowest common denominator. I'll take a four on this one, too. (This isn't shaping up well is it?)

Are managers ill-informed about what to look for on control deficiencies or cues on risky behavior?


There's not a lot of sharing here, especially concerning errors or incidents. After all, who wants to shoot themselves in the foot? We have an active infosecurity awareness program, but it hasn't been integrated into any of the training and employee development programs we run on a continuous basis. HR owns management training, but it doesn't recognize that the manager's job has a core risk-management component. And what's the first question out of the CEO's mouth when it hits the fan? "Who's the manager of this disaster?" I can't vouch for manager awareness across the board. So let's score a three here.

Are there unaddressed vulnerabilities in your company's safeguards or other such exposures that could be exploited?

The fact that this question has to be included speaks volumes about the maturity of risk management. Of course there are known gaps! And it's the people who work here who know where to find the holes. The guy who is empowered to do you the most damage already works for you. The developers leave open doors in our applications, and our LAN administrators have the keys to the kingdom. There's no one place where all the data comes together to enable those of us on the firing line to see where the interconnections and interdependencies may exist. Besides, I get paid to think about "what if," so scoring anything less than a five would be dishonest.

Wednesday, March 01, 2006

The Wild West of the New Millennium...

Rather than engaging in a futile attempt to suppress technology, the music business should try to work with consumers. Murray writes: "The most sustainable solutions include the creation of favorable alternatives to piracy by making legitimate distribution channels more convenient." Bingo! Imagine how much more money the music industry would have made by creating pay-per-song download sites instead of paying lawyers to prosecute downloaders.


These words by Brian H. Murray were the writing on the wall in January 2004 in this article by Jonathan Jackson. Mr. Murray may have predicted the transition by the MPAA and other digital rights advocacy groups to change the industry from one of piracy to one of profits. Introduce Mr. Steve Jobs of Apple, the iPod and iTunes and now you have your 1 billionth download. That's .99 cents X 1,000,000,000.

How could you endorse the use of technology and tools like Weblogs to create new opportunities for your enterprise? Message boards and other chat web sites have been around for a decade making online brand management a necessity for any brand conscious entity. Defending The Brand was the title of Brian Murray's book published in 2004 and it is still a component of any comprehensive risk management strategy.

Managing Intellectual Property Rights and sensitive or proprietary information is a major concern for General Counsel's and Chief Marketing Officers. Making sure that trade secrets and ideas are protected is a priority. And when it comes to employees expressing their opinions about management, the watercooler and local bar has not been enough. When message boards, web sites or blogs post comments on a company or organization they typically are a way for discouraged, disgruntled or maybe even dangerous employees to vent their feelings.

The intersection of Civil Rights, Privacy, Cybercrime and White Collar Crime is creating a buzz. With whistleblowers sending anonymous email, posting to weblogs and a whole new spectrum of enforcement actions, sometimes you have to step back and see the big picture. General Public License, 3.0 and Open Source has created new subjects for debate.

The Operational Risks in your organization are growing at an exponential rate. Cooperation and information sharing is still a road block to progress. The answers are only clear if you can see the beauty in what Mr. Murray's thinking was over two years ago:

"I never cease to be amazed by the bold, clever, and unscrupulous behavior that is so common on the Internet. Through my experience defending brands, I can say with confidence that anything that you thought would never happen online is probably already going on, and anything you think couldn't possibly exist on the Internet is almost certainly there. Though it's an overused cliche, the Internet really is the Wild West of the new millennium."