Thursday, November 30, 2006

Red Flags: Mobile Data Encryption Policy...

Have any of your executives been waving any "Red Flags" lately? If you are like many CISO's across the globe, you may have to change this to a "White Flag" and surrender.

IDC reports in a recent study, that the projected number of global mobile employees would grow beyond 878 million by 2009. IDC’s report, "Comply on the Fly: Keeping Pace with the Management Challenges of Mobile Data Management," explores whether businesses are implementing initiatives to provide internal controls and address data security risks from mobile device use.

A Recent IDC Report cited at the Business Performance Management (BPM) Forum reminds the CxO's to batten down the hatches on mobile devices. Blackberry is only one of a few companies (RIM) who are being subjected to greater pressure to provide encrypted data at the device level.

The IDC report contained the following information:

* Nearly half of all respondents report that a minimum of 25 percent of all mobile devices in their organization carry mission-critical applications and information.

* Forty percent of respondents have no measures at all to manage mobile data tracking, backup and archiving for regulatory compliance purposes.

* Smaller companies ($100 million in revenue and under) face a greater risk of violations, with just 32.4 percent implementing formal mobile compliance policies.

* There is disconnect between IT executives who recognize mobile device compliance and security risks, and C-level executives who see benefits, not risks.


Yet it seems that employee's will not obey or even heed the policies set forth by their enterprise to try and protect customer information and valuable intellectual property. Thousands of laptops and other PDA's are left in taxi cabs as "On The Go" executives run for their meetings, interviews or flights.

In this digital age, the value of information on these stolen or lost devices is increasing and the losses to the enterprise far exceed the replacement of the phone, PDA or laptop. The loss extends to the notification of the customers who have exposed Personal Indentifiable Information. Studies by the Ponemon Institute have calculated this amount to be $182.00 per record.

According to the study’s 2006 findings, data breaches cost companies an average of $182 per compromised record, a 31 percent increase over 2005. The Ponemon Institute analyzed 31 different incidents for the study. Total costs for each ranged from less than $1 million to more than $22 million.

The 2006 Cost of a Data Breach Study tracks a wide range of cost factors, including legal, investigative, and administrative expenses, as well as stock performance, customer defections, opportunity loss, reputation management, and costs associated with customer support such as information hotlines and credit monitoring subscriptions. "The burden companies must bear as a result of a data breach are significant, making a strong case for more strategic investments in preventative measures such as encryption and data loss prevention," said Dr. Larry Ponemon, chairman and founder of The Ponemon Institute. "Tough laws and intense public scrutiny mean the consequences of poor security are steep—and growing steeper for companies entrusted with managing stores of consumer data."


The CxO on the go now realizes the importance of encryption for all mobile devices. Unfortunately for those few who still have not reallocated the funding to accomplish this important task, may cost millions more.

In yet another instance of laptop theft potentially endangering personal data, Kaiser Permanente Colorado is notifying some 38,000 members of a possible breach of their private health information.

The information was located on a laptop stolen from the personal car of a national Kaiser Permanente employee in California, reports the Rocky Mountain News and other media outlets.


Let's see: 38,000 x $182.00 = $6,916,000.00 in operational losses.

Monday, November 27, 2006

Backdating: Culture Makes All the Difference...

Looking back upon your last stock option exercise, did you realize the price you were granted was backdated? If you did, then your ethical misbehavior is just another example of how corporate compensation is bringing the house down. The question now remains, how many more companies will be announcing that they need to restate their numbers for the latest financial period.

Affiliated Computer Services replaced CEO Mark A. King and CFO Warren D. Edwards on Monday, saying they had violated the company’s "Backdating" code of ethics for senior financial officers, as the company completed an internal investigation of its stock option-granting practices.

The Dallas-based outsourcing company named COO Lynn Blodgett as the new chief executive, and John Rexford, the company’s executive vice president of corporate development, as the new chief financial officer.

Mr. King and Mr. Edwards are just the latest of about 60 corporate executives who have been pressured to step down as companies have probed their stock option grants and the backdating of those grants to benefit executives. The options fallout has ensnared more than 150 companies so far.

The two ACS executives resigned effective Sunday and entered into separation agreements with the company.


You can bet that anyone who is now considering a new position where stock options will be part of the compensation package will question the ratio between incentive in stock and the cash bonus. Incentive compensation is the root of much of the corporate malfeasance we have all witnessed over the past five years. And if you look at where this story really begins, you have to look hard at the compensation consultants, head hunters or just plain human resources processes.

When you look at the way people are compensated, you generally can figure out what type of behavior you are trying to influence. The corporate governance of our companies continues to see new fraud, new corruption and a continuous stream of finger pointing. A Code of Ethics is easy to create and yet much more difficult to get people to follow. What would Warren have to say about it?

Warren Buffett's "Tone at the Top"

A few months ago, Warren Buffett sent this memo to managers at Berkshire Hathaway:

To: Berkshire Hathaway Managers ("The All-Stars")
From: Warren E. Buffett

Date: September 27, 2006

The five most dangerous words in business may be "Everybody else is doing it." A lot of banks and insurance companies have suffered earnings disasters after relying on that rationale.

Even worse have been the consequences from using that phrase to justify the morality of proposed actions. More than 100 companies so far have been drawn into the stock option backdating scandal and the number is sure to go higher. My guess is that a great many of the people involved would not have behaved in the manner they did except for the fact that they felt others were doing so as well. The same goes for all of the accounting gimmicks to manipulate earnings - and deceive investors - that has taken place in recent years.

You would have been happy to have as an executor of your will or your son-in-law most of the people who engaged in these ill-conceived activities. But somewhere along the line they picked up the notion - perhaps suggested to them by their auditor or consultant - that a number of well-respected managers were engaging in such practices and therefore it must be OK to do so. It's a seductive argument.

But it couldn't be more wrong. In fact, every time you hear the phrase "Everybody else is doing it" it should raise a huge red flag. Why would somebody offer such a rationale for an act if there were a good reason available? Clearly the advocate harbors at least a small doubt about the act if he utilizes this verbal crutch.

So, at Berkshire, let's start with what is legal, but always go on to what we would feel comfortable about being printed on the front page of our local paper, and never proceed forward simply on the basis of the fact that other people are doing it.

A final note: Somebody is doing something today at Berkshire that you and I would be unhappy about if we knew of it. That's inevitable: We now employ well over 200,000 people and the chances of that number getting through the day without any bad behavior occurring is nil. But we can have a huge effect in minimizing such activities by jumping on anything immediately when there is the slightest odor of impropriety. Your attitude on such matters, expressed by behavior as well as words, will be the most important factor in how the culture of your business develops. And culture, more than rule books, determines how an organization behaves. Thanks for your help on this. Berkshire's reputation is in your hands.


What kind of culture exists in your organization?

Friday, November 17, 2006

Enterprise Resilience: Investing in Intellectual Capital...

This weeks 21st Annual OSAC (Overseas Security Advisory Council) Briefing was entitled Global Resiliency: Operating in Challenging Environments.

The United States Department of State Bureau of Diplomatic Security sent a clear message that Enterprise Resilience is going to be a major theme moving forward as global firms experience extended supply chains. As this footprint becomes more expansive and spans multiple continents, so too are the operational risks. The conference was opened by Ms. Deborah Wince-Smith of the Council on Competitiveness who presented a case for why private sector CEO's should care about this strategic initiative:

There are at least four reasons why CEOs should care about integrating security and resilience into their business strategy.

1. Business risks are growing, irrespective of 9/11 and the threat of global terrorism.

2. Resilience, in the face of increasing risk, is a shareholder value issue.

3. New corporate governance rules may mandate more rigorous integrated management systems than are currently in place.

And for many firms, operational risk management is not a priority. According to recent surveys:

Only 36% of U.S. CEOs believe that risk management is a priority concern, versus 45% of European CEOs and 67% of Asian CEOs (Conference Board, 2006).

Only 25% of Directors of non-financial companies report that the Board considers all major risks to the company, versus 55% of financial industry directors (Conference Board 2006).

During the past 12 months, 1 in 5 companies surveyed suffered significant damage from a failure to manage risk and over half had experienced at least one near miss (Economist Intelligence Unit and Lloyds, 2006).

4. Industry continues to face a risk of reactive regulation for homeland security.

5. Empirical evidence from the case studies highlight missed opportunities to leverage security investments to increase efficiencies and revenues.


The conference also had keynotes from our own (DNI) Ambassador John D. Negroponte and the CEO of Archers Daniel Midland, Patricia Woertz who made a case for the "Chief Resiliency Officer". Yet the most compelling remarks and insight comes from someone who has lived on the front lines for decades. Someone who understands the threats corporations, NGO's and governments face on the new global battlefield. Henry (Hank) Crumpton is now the Ambassador-at-Large and Coordinator for Counterterrorism after joining the CIA in the early 80's. He led the CIA's Afghan campaign in the first critical months of this new strategy against "Non-State Actors."

These small, nimble and flexible attack units known as "Micro-Actors" can deliver "Macro-Impact" using cover of corporations, exploiting our modern transporation and communications networks and gaining new 4th generation weapons. We must realize the innovations and the technologies we create will be utilized against us.

Here are some words of wisdom from one of the most admired and fearless patriots of the United States:

1. We must begin investing more in our own Intellectual Capital and to better understand the enemy.

2. We must build interdependencies and strong interdependent networks. (People)

3. People need to demand more from government to build stronger partnerships.

4. The private sector needs to give more to the government. (Intelligence)

5. We need more leadership.


Resilient organizations learn and adapt. It changes and morphs as new risks evolve. Given the new revolution of protection converging with recovery, we can only pray that business leaders finally realize that this is not about mitigating losses. It is about putting on a new pair of glasses with a new prescription that is perfect. Clarity of the new lens allows people to see that new found investments can Enable Global Enterprise Business Resilience.

Sunday, November 12, 2006

Safeguards Rule: The ID Theft Battle...

Unlike Europe and other forward thinking regions of the globe, the United States is still wrestling with a national data security and privacy law. If the new democratic powerbase is successful, the ID Theft and privacy battle ground will now shift from a corporate focus to a more consumer focus.

A new ID theft task force comprised of 17 US Government agencies has been working on a strategy report that is due by February 2007. It will be highlighting "ID Theft Red Flags" or rules that need to be addressed when they occur. The Federal Trade Commission (FTC) will be gearing up enforcement on those companies who provide PII (Personal Identifiable Information) Intel such as they did this past year with ChoicePoint and others.

Organizations are being pressured to retain data longer, up to two years as a more modern FISA (Foreign Intelligence Surveillance Act) is contemplated. This will assist law enforcement and corporate security departments in evidence collection and investigative process to detect and defend our company assets and national security from "Lone Wolf" terrorists and everyday fraudsters, counterfeiters or pirates. If you are currently a consumer using Vonage, Skype or someother VOIP service, you can bet that all of your calls are going to be accessible for some time to come.

As the Federal Civil Rules on Electronic Discovery change December 1st, the records retention policies and data categorization or mapping exercises will be in full swing. If they aren't, be prepared for quick judgements and settlements from your organization if your litigation readiness factor is in the red or even the yellow zone. In terms of your 3rd Party or outsourced relationships, you can bet that a SAS 70 Type II will not be enough to ensure that your partner has been doing enough to protect your customers PII.

So what does all of this mean? SO What!


It means that the 8 Million+ small and medium enterprises in the US will be subjected to the FTC scrutiny on the SafeGuards Rule:

According to Orson Swindle, former commissioner of the U.S. Federal Trade Commission,

We're going to probably see a broadening or extension of the safeguard rule in the Gramm-Leach-Bliley Act to cover a significant number of organizations that handle sensitive information but that aren't financial services institutions. There is a new awareness that personal information is very valuable, and it needs to be protected whether we're talking about a financial institution or a university or a shoe store.


As the committee's in congress are sorted out and the first 100 hours of the new Democratic regime take hold, don't be surprised if your organization is now in the cross hairs of the governments regulatory enforcement teams. The US Attorney in your jurisdiction is ready to begin a new era to get business to invest in soundness and safety, even if you are not traditionally a highly regulated entity. You think ID Theft is just another bother?

Woe to you, friend, if that's your attitude. Data security may be dead in Congress this year, but the Federal Trade Commission is on the case, and that could mean trouble for lax companies.

"The FTC has stepped into the void," said Emilio Ciividanes, a partner in Venable LLP. "And every proposal for comprehensive legislation has the FTC playing an important role."

For one thing, the commission is now putting its finishing touches on its ID Theft Red Flags Rule, requiring that companies spot and address identity theft risks.

What would constitute a red flag? If there are multiple addresses for a credit-card holder, according to Joel Winston, associate director of the Privacy and Identity Protection division of the FTC's Bureau of Consumer Protection, speaking at DMA06 in San Francisco.

And the FTC is aggressively pursuing companies for allowing security breaches to occur or for not having protections in place. And why not? It is getting 15,000-20,000 consumer messages a week through its Identity Theft Website and telephone number.


If you are one of the millions of Small to Medium Enterprises (SME) in the United States without a full-time Chief Information Security Officer (CISO) you may be at significant risk. Especially if your General Counsel has little or a non-existent relationship with the person you have charged with keeping the networks running and the infrastructure maintained. Be forwarned. The next new hire in your organization may be a lawyer with a CISSP or even a person with a MIS and a J.D. degree. In either case, the government is going to come knocking and your reputation is on the line.

Monday, November 06, 2006

Foreign Corrupt Practices: Oil, Corruption & Borat...

Global commerce is on an upward curve of growth as the planet becomes flat or smaller based upon the increasing speed of business. Transportation, Technology and Telecommunications has spawned the reach for many U.S.-based enterprises who desire to trade products or services overseas. The Gas & Oil Industry and Energy sector have been the most scrutinized public companies for their business practices over the past three years.

Operational Risk in the Energy Sector and others could be blind-sided by the Foreign Corrupt Practices Act (FCPA) in the years to come as they race to do business in Kazakhstan and China. Here is a lesson for aggressive marketeers and business developers who will need to be wary of their business protocols and procedures when engaging in international commerce.

"So you think it's easy to stay out of jail? John MacLellan doesn't. The regional finance director of Microsoft Corp. in Asia, MacLellan is responsible for ensuring compliance with the U.S. Foreign Corrupt Practices Act (FCPA), a law that exacts strict penalties for giving or taking bribes at overseas operations. While the software giant boasts a robust internal-compliance program, recent FCPA enforcements (including actions against Titan Corp. and InVision Technologies) suggest a new urgency in the U.S. government's enforcement of the law.

Complicating MacLellan's job: in the People's Republic, it's not always clear who you're dealing with. A U.S. executive might treat a customer to a business dinner without ever knowing that one of the guests is a low-level ministry official. "We face a large number of very complex deals in China," MacLellan says. "Because of the size and influence of the government, we're exposed [to the FCPA] from the start."


The Kazakh government is getting plenty of publicity this week due to a new movie launched this past weekend named "Borat: Cultural Learnings of America for Make Benefit Glorious Nation of Kazakhstan". Simultaneosly, the country is the focus of an oil, cash and corruption probe.

"In February, the United States attorney’s office in Manhattan is scheduled to go to trial in the largest foreign bribery case brought against an American citizen. It involves a labyrinthine trail of international financial transfers, suspected money laundering and a dizzying array of domestic and overseas shell corporations. The criminal case names Mr. Nazarbayev as an unindicted co-conspirator. The defendant, James H. Giffen, a wealthy American merchant banker and a consultant to the Kazakh government, is accused of channeling more than $78 million in bribes to Mr. Nazarbayev and the head of the country’s oil ministry. The money, doled out by American companies seeking access to Kazakhstan’s vast oil reserves, went toward the Kazakh leadership’s personal use, including the purchase of expensive jewelry, speedboats, snowmobiles and fur coats, federal prosecutors say."

As American companies seek partnerships, acquisitions and IPO deals they must comply with FCPA or suffer the financial or political consequences. Even in the middle of all of the movie hype and the legal depositions the country of Kazakhstan has been elected to join the UN Economic and Social Council:

Kazakhstan says it has become the first Central Asian country to be elected a member of the UN's Economic and Social Council (ECOSOC).

The Kazakh Foreign Ministry says in a statement the vote took place at the UN General Assembly on November 2.

Kazakhstan will represent Central Asia in the 54-member UN body for the next three years. ECOSOC is the UN's central forum for discussing international economic and social issues.

Monday, October 30, 2006

Corporate Plausible Deniability: Is Now Extinct...

Skyrocketing Electronic Discovery (E-Discovery) costs force many organizations to prematurely settle cases or at least compromise their litigation strategy. Courts are increasingly issuing broad evidence preservation orders, mandating that computer data on up to several thousands of hard drives and servers be preserved.

Regulations and new legal statues have created a convergence of information security and legal issues. Effective governance strategy execution must include business drivers of legal and security factors to be successful. "Plausible Deniability" is now extinct.

Plausible deniability is the term given to the creation of loose and informal chains of command in government. In the case that assassinations, false flag or black ops or any other illegal or otherwise disrespectable and unpopular activities become public, high-ranking officials may deny any connection to or awareness of such act, or the agents used to carry out such act.

In politics and espionage, deniability refers to the ability of a "powerful player" or actor to avoid "blowback" by secretly arranging for an action to be taken on their behalf by a third party - ostensibly unconnected with the major player.

More generally, "plausible deniability" can also apply to any act which leaves little or no evidence of wrongdoing or abuse. Examples of this are the use of electricity or pain-compliance holds as a means of torture or punishment, leaving little or no tangible signs that the abuse ever took place.


Digital Forensic Services are specifically designed to perform efficient and effective enterprise computer investigations to address these concerns with best practices technology. This enables corporations to manage and retain control of these investigations while substantially reducing cost. In the context of E-Discovery, courts require that best practices are employed and that counsel take affirmative steps to monitor compliance and ensure all relevant data is located and preserved.

And as we approach the eve of Halloween there are all kinds of "Tricks and Treats" going on at the corporate digital battle front. Executives from most organizations are trying to keep their eye on those employees and places that are deemed significant risks to the organization and at the same time, cover their tracks. The HP scandal is still fresh on their minds.

The Privileged Executive

Her trick
The privileged executive feels responsible for every aspect of the organization, and compelled to control it. She wants to know everything about every department and project; demands root access to systems and applications, and sufficient rights to act on others’ behalf -- including sending email using other employees’ accounts. Naturally, she objects to logging of her own activities while demanding stringent audit of everyone else.

Your treat
Forward articles on prosecution of executives for insider trading, misusing data, and SOX violations, particularly ones that detail how malfeasance got pinned on the corner office because of too much access. Follow up a few days after each prying event by hinting to IT that it ought to look into apparent audit discrepancies, and suggesting to internal auditors they ought to look into IT control logs. Send monthly updates about how you’re working hard to make sure the execs aren’t exposed to excess risk; make plausible deniability your mantra.


New York state courts' are coming of age with respect to electronic discovery while U.S. federal courts already know the nuances associated with e-discovery. Notwithstanding the lack of a CPLR(Civil Practice Law Rules) or court rule specifically electronic disclosure, the recent court decisions reflect the courts' appreciation of:

(i) the search, production, de-duplication and privilege review costs that may be incurred by a party in addressing e-discovery requests and the importance in fairly determining who should bear such expense, including counsel's time in reviewing electronic documents for privilege,

(ii) the legal and business burden on the party producing electronic documents, taking into account, among other things, the purpose for which backup tapes were made and issues relating to their restoration,

(iii) a party's claimed relevance of and need for the requested electronically stored materials,

(iv) the process utilized by the producing party to identify, search for and gather electronic materials,

(v) the likelihood of whether yet-to-be searched for electronic materials actually exist and, if so, would they be duplicative of documents already produced,

(vi) a party's "true" justification for seeking and/or objecting to producing electronic documents, and

(vii) both sides to a dispute having the opportunity to retain appropriate expert forensic computer experts prior to a court ruling on e-discovery issues.


Digital Forensics in E-Discovery is evolving at the pace of lightning and many large organizations are already well entrenched. However, one thing is for certain. Corporate Plausible Deniability is almost certainly on the way to extinction.

Thursday, October 26, 2006

Anti-Terrorism Tools: Fido to the Rescue...

One of our most effective "Anti-Terrorism" sensors may be the nose on your favorite breed of canine. Dogs are being trained and their careers are sometimes being diverted from helping the blind, to helping the general public detect the possible signs of a terrorist event in the making.

TATP is triacetone triperoxide, one of the more common liquid peroxide explosives, the kind used in last year’s London transit system bombings and found hidden in the sneakers of the would-be shoe bomber, Richard C. Reid. Experts say peroxides have become terrorists’ explosives of choice, and government agencies are trying to detect them before they are carried onto buses, trains and airplanes.


The TSA Puppy Program has been around for several years and continues to be one of our most low tech, highly efficient tools in the counterterrorism arsenal.

Our National Explosives Detection Canine Team Program prepares dogs and handlers to serve on the front lines of America’s War on Terror. These very effective, mobile teams can quickly locate and identify dangerous materials that may present a threat to transportation systems. Just as important, they can quickly rule out the presence of dangerous materials in unattended packages, structures or vehicles, allowing the free and efficient flow of commerce.

Law enforcement officers from all over the country travel to the our Explosives Detection Canine Handler Course at Lackland Air Force Base in San Antonio, Texas where they are paired with one of our canine teammates . These dogs are bred specifically for the program by our puppy program, also at Lackland AFB. German Shepherds, Belgian Malanoises, Vizslas and other types of dogs are used in the program because of their keen noses and affinity for this type of work. In addition to providing a highly trained dog and handler training, we provide partial funding for handler salaries, care and feeding of the canines, veterinary and other costs associated with the dog once the teams return to their hometowns.

After dog and handler are paired up, the new team completes a rigorous 10-week course to learn to locate and identify a wide variety of dangerous materials while working as an effective unit. This training includes search techniques for aircraft, baggage, vehicles and transportation structures, as well as procedures for identifying dangerous materials and "alerting" or letting the handler know when these materials are present.


Deutsche Bahn, the German Railway Authority continues to test biometric technology using face recognition as a deterence and detection strategy. This testing is a result of a foiled or aborted plot to bomb German trains during the World Cup last summer. We find it hard to believe that terrorists with their pictures in the database will be the actual assailants carrying a backpack or wearing the explosives.

Let's keep our "Canine Corp" growing so we can make sure they are making their rounds in every train station in every major metro city on the planet. It's imperative if we are to keep our defenses at the highest level of detection in the days and years ahead.

Tuesday, October 24, 2006

Know Your Domain: Alias Fraud Gains Millions...

The latest Alias Fraud is a "Rogue Wave" heading towards the bow of a financial broker near you. Even in companies like E*Trade who have been advocating the use of the RSA SecureID for their clients, the losses continue. $18 Million stolen.

``Internet crimes that result in the theft of personal and financial data from consumers continue to be a significant and global problem,'' FBI spokesman Paul Bresson said. ``We work closely with our foreign law-enforcement counterparts to pursue these cases with all applicable laws.''

Bresson declined to comment on the FBI investigation. John Heine, a spokesman for the SEC, and NASD's Herb Perone also declined to comment.

Some of the losses were straight theft. In his presentation, Walsh of the SEC explained how criminals use personal information such as Social Security numbers to break into accounts. Once in control, they loot the accounts by selling securities and wiring out the proceeds far from the U.S.

`Pump and Dump'

The online version of the ``pump-and-dump'' fraud sets off few security alerts at brokerage firms because no money is withdrawn from the compromised accounts, Walsh explained.

``This is an increasingly popular variation,'' he said in Phoenix. ``If you are looking for a single `hot topic' in the world of identity theft, this is it.''

In ``alias fraud,'' a thief opens an account in an individual's name, then uses it for illegal trading or money- laundering. Because the victim's name is on the account, he or she appears responsible for the crimes.


Two-factor authentication is not a new topic to these organizations. The FFIEC has been providing guidance and now a December 31 deadline for addressing this issue. Back in August this Operational Risk Blog discussed this very topic:

One way to solve the issue is to find a company who has taken all of these technology hurdles and has found a viable solution for FFIEC compliance. See Boulder, Colorado based Authenticol to add to your short list.


The answer for the banks and financial services companies are out there. What is more difficult to address are the processes and the enterprise architecture to accomplish the goal of reduced operational risks. Whether these be external fraud by foreign transnational crime syndicates or the stealth employee walking out the door with a 2GB Jump Drive on their keyring with proprietary client information. Do you really believe that all of these hackers are just getting lucky that the trojans and key loggers they have propagated end up on the home desktop of E*Trade consumers?

"Insider Information" comes in all kinds of forms. Whether it be the stolen client information or the loose lips of a person with access to vital M & A information.

The bulk of the money allegedly made in the case by two former Goldman Sachs employees resulted from tips from an analyst with information about Wall Street deals and a grand jury member who knew about a probe of accounting fraud accusations against Bristol-Myers Squibb Co. and several of its executives, the government has said.

The case came to the attention of authorities when regulators noticed unusually high trading volume before a merger announcement and discovered that a 63-year-old retired seamstress in Croatia -- the aunt of one of the defendants -- had made more than $2 million.

The plot involving Schuster, however, showed the lengths to which those involved in the insider trading plot would go to gain an edge in the market.


In the words of one very respected and experienced investigator we recently had the company of speaking with, his wisdom is this. "Know Your Domain". In a recent survey by the Privacy Rights Clearinghouse and the National Association for Information Destruction Inc.:

Percentage of business executives who do not know what their companies do to ensure the destruction of information on obsolete computers = 77%

Friday, October 20, 2006

SOX 404: Auditors vs. Empowered Employees...

In the November/December issue of Corporate Board Member 100 Board Directors have sounded off. The PricewaterhouseCoopers Survey on "What Directors Think 2006" asked some tough questions and got some revealing answers.

How effective is your board at monitoring the company's "Risk Management Plan?

Very Effective - 12%

Effective - 47%

Somewhat Effective - 36%

Would you like to spend more, less or the same time on Sarbanes-Oxley Section 404?

The Same - 64%

Less - 33%

More - 3%


If we try to interpret what these two questions mean in relationship to each other we guess it makes sense. Almost two thirds of the Board Directors polled want to spend more time on Section 404 and at the same time are saying that they are not very effective at managing the company's risk management plan. Logical? The Board of Directors are looking for answers in the wrong places, the auditors.

The company’s external auditor must report on the reliability of management's assessment of internal control (Section 404).

Colossal and recurring external auditor failures around the world regularly demonstrate the difficulty of providing opinions on the reliability of financial statements. Positive audit opinions are regularly issued on materially false financial disclosures in spite of the fact that the U.S. has developed thousands of pages of rules on how they should be prepared to “fairly” present the company's financial status. The difficulty of providing an opinion or an assertion that internal control is “adequate” or “effective” to ensure the reliability of external financial disclosures is exponentially greater. There are very few guidelines to help auditors decide when there are “adequate” internal controls. Field research done by CARD®decisions with hundreds of groups of senior level internal audit and management personnel has consistently demonstrated that, given the exact same circumstances in a case situation, few groups and few individuals in those groups agree on the combination of control elements from a predetermined control design menu that would provide an “effective” or “adequate” level of control. This is true in spite of the fact that internal audit departments around the world routinely give opinions to clients on whether the clients’ internal controls are “adequate”. It takes very little applied research to demonstrate conclusively that audit opinions on what constitutes an “adequate” level of control involve a huge amount of highly subjective judgment. These findings suggest that reporting these highly subjective opinions on whether controls are “adequate” or "effective" to key stakeholders does not meet the goals of comparability, reliability, and repeatability, key criteria for sound assurance and audit methods.


The Basel Capital Accord II is the first breath of fresh air on the modern management systems for identifying and controlling process variability and driving down errors and rework. Although Basel has clearly recognized that a risk focus is far superior to a fixation on controls compliance, the management and the Board of Directors hasn't figured that out just yet. When they do, they will be calling in their favors from the legislators.

Really understanding and documenting the processes that feed the disclosures and reporting has to begin with each employee and manager owning it and understanding it themselves, not just internal audit or the external auditor. Only then will the employees become more aware and capable of detecting where controls need to be turned into Total Quality Management objectives.

The Board of Directors only has to look at the risk management accumen of the middle management ranks to really get an accurate "litmus test" of the effectiveness and the adequacy of the companies overall Enterprise Risk Managment (ERM) quality score. This is where the true health and the resilience of the company can be found to verify or question, SOX 404.

Tuesday, October 17, 2006

Buyer Beware: The Risk of Private Data...

Operational Risks are being found in places that a CxO would not have at the top of their list when it comes to mitigating threats to the institution. Human Resources, Information Systems, Accounting make the list near the top yet Marketing always seems to be a few steps down. This is a big mistake and a renewed interest in auditing the sales and marketing organization could open up a real "Pandora's Box".

Fidelity Federal Bank and Trust (West Palm Beach, Fla.) has been ordered to pay a $50 million settlement for buying more than half a million names and addresses from the Florida Department of Highway Safety and Motor Vehicles. The Electronic Privacy Information Center (EPIC), which filed an amicus brief in favor of the plaintiffs in the case, announced the decision in late August.

EPIC said the $4 billion-asset bank bought 565,600 names and addresses for use in direct marketing, claiming that the purchase violated the Drivers Privacy Protection Act. The federal law was enacted in 1994 to prevent the distribution of drivers' personal information.

From 2000 to 2003, Fidelity purchased the data containing the personal information of drivers living in Palm Beach, as well as Martin and Broward counties, for only $5,656, or a penny per driver record, according to papers filed in Kehoe v. Fidelity Federal Bank and Trust. The bank sought the information for car loan solicitations, according to the class-action lawsuit.


When this is one is all over you can bet that many organizations will be reexamining where they get their marketing data. The direct marketers sell and resell data on a daily basis including some companies you would not think are even in that business, namely your own state. Buying your drivers license information should be highly accurate as we are all required to report change of address to DMV shortly after we move to a new location. That is why this data is valuable to the direct marketers, fewer pieces of returned mail.

Where does your marketing department get all of the information that they use for outbound direct marketing? Via postal mail, e-mail, outbound phone calls and even personalized content on the web site each time I log in to get my latest statement. These days a valid e-mail address may be even more valuable than a phone number due to the "Do Not Call" list and the fact that people just don't answer their phone if they don't have the person calling in their personal contact list.

As an example, this one hit the in-box the other day from Equifax:

Your entire credit history in one easy-to-read report plus your FICO® credit score for only $29.95

Taking charge of your credit standing could pay big dividends when applying for a loan or negotiating an interest rate down the road. Because you are one of our most valuable customers and understand the importance of actively monitoring your credit, we are offering you our deepest discount - $10 off your 3-in-1 Credit Report with Score Power® - which includes your credit history as reported by all three credit reporting agencies plus your FICO® credit score - the score lenders use most.

When you apply for a loan, lenders can pull your credit file from any or all of the 3 major agencies, so it's important to know what information they have about you. Your 3-in-1 Credit Report allows you to see your entire credit history in one easy-to-read report. A quick and convenient way to ensure that your credit history is in order!


Where Equifax obtained this e-mail address is anybodies guess. They must have bought a list from a company that was doing a survey for a client who was selling products to people in the zip code 22102 and drive black SUV's. At the end of the day the marketing and sales organizations in your enterprise are just doing what you expect of them in generating new market share and revenues. Be careful what you wish for because all of those new found customers and sales could be erased in an instant with a well planned plaintiff class-action lawsuit.

Monday, October 09, 2006

Business Resilience: Asia Braces for a Nuclear North Korea...

What metaphor or symbol has your organization identified with to represent who you are or what you stand for? Some companies do this through their logo and others like Business Resilience Group (BRG) have done it with both.

BRG has chosen Bamboo, the Chinese symbol for resilience, as its logo as it embodies the key elements of our resilience framework and services.

Bamboo is the most versatile plant that is used for a vast range of purposes. Its leaves and shoots are used for food, and its stems can be utilized for sewing needles, writing implements, cooking utensils, furniture, for house and boat building, etc. Thus the many uses of the Bamboo plant represent its adaptiveness and are signified by the virtues of strength, uprightness, integrity and service. The Bamboo has long been regarded as a symbol of longevity due primarily to its resilience and ability to stay evergreen through the four seasons, especially during the adversity of the harsh winter months. The spiny bamboo, which signifies longevity and prosperity that lasts for generations, and the solid stemmed bamboo, which signifies a life free of illness and disease, are the varieties associated with good health.

The Bamboo is known to "bend without breaking" - like resilient organisations it exhibits Strength through flexibility.


We like the metaphor and agree that "adaptiveness" is a key attribute of a resilient organization. And the core ability to run your Information Technology (IT) department as a business is a challenge like no other. Running IT as a Business creates several questions all large enterprises are asking themselves on their respective quests to address their Business Resilience Adaptibility:

* How do IT strategic and operational plans relate to and support strategic line of business plans? Where is there conformity? Where are there gaps?

* How do IT strategic and operational plans guide IT business processes and performance improvement priorities? In other words, what does IT have to do better in the delivery of services it provides to meet the needs of the business? What is IT doing to shore up those gaps? How well is IT meeting its commitments related to service level agreements?

* How do IT project portfolios relate to strategic and operational plans? What is the cost of projects? What is the scope of the projects as it relates to the IT porfolio? How are the projects related to one another? Where are there strategies with no project support? Where are there projects with no strategy/ performance improvement objective to justify the effort?

* What are all elements of the IT technology portfolio - applications, data and infrastructure? How are all elements of the IT Portfolio related? How is this portfolio related to IT Services? What are the costs of whole categories such as Hardware, Licensing, Maintenance, Data Center, Network and Help Desk?

* What IT Portfolio elements support IT business processes, such as application development, service delivery, service support, configuration management and change management? What are the rolled up costs of these elements and how does this relate to the budgets?

* What IT Portfolio elements support the Business processes that make the Business run?

* How are current IT Portfolio elements being impacted by IT projects? Where are the dependencies?

* What is changing? What is our change profile? What are the growth patterns? What are the trends?


Yet Information Technology (IT) including communication systems is just one major facet of an organizations overall Business Resilience factor. What are you doing to simultaneosly address these components in your organization?

1. Essential functions and key personnel;
2. Vital records, communication systems and equipment;
3. Alternate work sites and relocation planning;
4. Training, testing, and exercises.


And today, this list has taken on a whole new urgency:

Outcry at N Korea 'nuclear test'

North Korea's claim that it has successfully tested a nuclear weapon has sparked international condemnation.

The White House called for a swift response from the UN Security Council, calling Pyongyang's move "provocative".

Japan and South Korea also condemned the test and even Pyongyang's closest ally China expressed its "resolute opposition", calling the move "brazen".

Diplomats say there will be an emergency Security Council meeting on the issue shortly.

The underground test, which South Korean media said took place in Gilju in Hamgyong province at 1036 (0136 GMT), has still to be confirmed.

Friday, September 29, 2006

Digital Intelligence: Pervasive Across Our Lives...

We initially wrote about the brewing Corporate Governance affair at HP to highlight that the telecom companies should be the ones getting more scrutiny. What continues to amaze us after watching all seven hours of testimony yesterday on C-SPAN Channel three is the naivete of what "information" is for sale today.

Ms. Dunn, former Chair of the HP Board has no idea what the spectrum of techniques and tools that are utilized to collect relevant information on a daily basis. In a digital world, monitoring for abnormalities and using surveillance is a standard practice to keep our institutions safe and secure. The same reason you rely on our Armed Forces and Law Enforcement is the same reason you hire them to staff the ranks of your corporate security and information assurance departments. Peace of mind.

Under questioning, Dunn was asked why she didn't recognize that investigators would have to turn to dubious means to get personal phone records. Dunn said she relied on the advice of others, including HP's outside investigator, Ron DeLia.

Dunn testifies:
"I did not know where this information could be found publicly, but I was aware that the kinds of investigations done by Mr. DeLia had previously been based solely on publicly available information," Dunn said. "I took the understanding without any question, and I understand why that might seem strange today, knowing what I know now."

Dunn was questioned by the committee, as were HP's outside lawyer Larry Sonsini and HP IT security worker Fred Adler. A number of other former HP employees and contractors refused to testify earlier Thursday, invoking their Fifth Amendment rights against self-incrimination."


Think about the information that is being collected today in your own marketing department. Hundreds of millions of dollars are spent each year with marketing consultants, advertising and branding agencies across the Global 500 on demographics, psychographics, pay per click, adwords, and the list goes on. Paying for performance means that you have to measure who, where and when people see, hear or open your marketing messages. The technologies in use today can tell you who opened the e-mail, where they are located when they open it and if they forwarded it to anyone else. You want to know how many people are listening to a certain radio station at the intersection of the 495 and the GW Parkway at 7:30AM? You want to know the phone number and identity of everyone that called your 800 number yesterday? You want to know where my vehicle is located at any time within a few meters? This is nothing new.

As our legislators try to figure out what should be unlawful when it comes to collecting information, they should first realize how many industries and companies that may be impacted by their decisions. And I know they do. Sarbanes-Oxley (SOX) was a knee jerk reaction to Enron. Let's just hope that we don't have another strait jacket put on the private sector as a result of Hewlett-Packard's public scandal.

Tuesday, September 26, 2006

Fraud: In Developed Country Operations...

Ron Connaught's "Fraud: Where The Perps are" in Corporate Board Member hit a nerve this issue.

It is not surprising that 60% of multinational companies think fraud is more likely to occur in their operations in emerging markets than in developed ones, an opinion that surfaces in Ernst & Young'’s ninth global fraud survey. But here i’s more of an eyebrow-raiser: 75% of the known cases of fraud over the past two years actually took place in those companies’ developed-country operations, according to the same survey.


We have seen other surveys from other organizations that have raised the issue of outsourcing / offshoring to emerging markets such as India and why this is such a high risk compared to other places on the globe. The misperception here highlighted by E & Y is that maybe we have lost sight of keeping our house in order even in those operations we deem to be under control.

Multinational's know that when they set up operations outside the US that they are going to be subjected to hiring a majority of that host countries people to staff the plant, call center or software development operation. The privacy laws and other legal implications of doing background investigations and verification of previous employment is difficult at best in these foreign states. This puts a tremendous burden on management to make sure that internal controls are in place to detect fraudulent behavior long before an act occurs.

A quality assurance review (QAR) is an independent look at a companies internal audit programs. Organizations who have realized that having a periodic QAR can help reduce fraud, also understand that it's good corporate governance, beyond the compliance with SOX. Supported by a QAR, an organizations IA department has a foundation to identify improvement options and provide guidance that can reduce risk and enhance the bottom line.


A Quality Assurance Review provides the audit committee, CEO and CFO with the opportunity to discover where and how fraud has found it's way into the organization even in those locations you thought were safe and sound.

Thursday, September 21, 2006

Phishing Victims: Accept Financial Responsibility?

The US President's Identity Theft Task Force has released it's interim report and the final recommendations are due in November this year. The task force is co-chaired by Alberto Gonzales, US Attorney General and Federal Trade Commission Chairman Deborah Platt Majoras.

The interim recommendations of the Identity Theft Task Force were announced following a meeting of the Task Force today at the Justice Department.

“As with any crime, victims of identity theft suffer feelings of violation and stress, but in these cases, victims have the added burden of cleaning up the mess that the identity thieves leave behind,” said Attorney General Gonzales. “The President created the Identity Theft Task Force to oversee the implementation of real and practical solutions at the federal level to defeat this ongoing intrusion into the lives of law-abiding Americans. Today’s recommendations move that process forward.”

“Conquering identity theft demands that we work as a team to develop tools that strengthen law enforcement, practices that enhance data security, and programs that help consumers in prevention and recovery,” said FTC Chairman Majoras. “Through these initiatives, we are taking solid steps toward eradicating this persistent consumer problem.”


Who pays for the loss of money stolen from your bank account as a result of ID Theft by Phishers or other Cyber Criminals using key logger trojans? Today the bank does to keep you as a customer. This is why the government and most large institutions who are the largest targets have already completed or are in the process of implementing two-factor authentication. However, will it be enough?

"The Bank of Ireland incident is one of the first public cases of a bank seeking to force phishing victims to accept financial responsibility for their losses, but it likely won't be the last. Phishing scams continue to proliferate, as Netcraft has blocked more than 100,000 URLs already in 2006, up from 41,000 in all of 2005. Financial institutions continue to cover most customer losses from unauthorized withdrawals. But after several years of intensive customer education efforts, the details of phishing cases are coming under closer scrutiny, and the effectiveness of anti-phishing efforts taken by both the customer and the bank are likely to become an issue in a larger number of cases." So, should a bank be forced to pay back a customer who has lost money to phishers? Or is it ultimately the customer's responsibility to make educated use of technology?


When bankers realize that Online Banking is an Operational Risk that requires more proactive measures you will begin to see your customer agreements modified and you will have to accept some of the risk. Examinations and investigations are going to be a standard operating procedure if you make a claim of unauthorized withdrawls or transfers from your account. The first place to look is on your own computer for the spyware that may have been utilized to steal your login and password. It won't be too much longer before the banks will be in the business of auditing your home PC to make sure that you have the correct anti-phishing, malware and virus protections. Or even to make sure you have the correct token for access to the banking site.

At some point, the consumer might have to bear more of the burden of risk management or pay the price of accepting the fact that you may have no more recourse to recover stolen funds from your account by the institution itself. But those days are still a long way off in the future. As our new generation of "Bank Robbers" already know, you don't have to wear a mask and walk through the front door any longer. All you have to do is find a few thousand unprotected machines each day and then wait for that unsuspecting consumer to hand over the keys to their bank account.

In the end, the consumer will pay for the mounting financial losses. One way or another.

Monday, September 18, 2006

A Convergent Framework of Risk Management...

Operational Risk Management has many facets in the eyes of the modern Chief Risk Officer (CRO). Last month, the High-level Principles for Business Continuity were summarized at the Basel Committee on Banking Supervision.

Recent acts of terrorism, outbreaks of Severe Acute Respiratory Syndrome and various widespread natural disasters have underlined the substantial risk of major operational disruptions to the financial system. Financial authorities and financial industry participants have a shared interest in promoting the resilience of the financial system to such disruptions.

To that end, financial authorities have been working closely with financial industry participants to establish a consensus as to what constitutes acceptable standards for business continuity. Much of this work to date has been focussed at the national level. At the international level, while there have been several regulatory and private sector initiatives on the business continuity front there has not been a concerted effort to draw together the lessons learned from major events and translate them into a set of business continuity principles that is relevant across national boundaries and financial sectors (ie banking, securities, and insurance). Furthermore, consistent with their focus on preserving the functionality of the financial system as a whole, financial authorities undertaking these initiatives have tended to give priority to critical market participants. The lessons learned from past experience, however, are applicable to a broader audience.

This paper represents an effort to address these gaps. It is intended to support international standard setting organisations and national financial authorities by providing a broad framework within which more detailed business continuity arrangements might be developed that are more closely tailored to unique sectoral and local circumstances. The principles also provide a consistent context for those arrangements and thereby promote a common base level of resilience across national boundaries.


Since 2004, The Tower Group has been shouting the need for banks to automate now in the midst of the Basel II momentum. While business performance has converged with Basel II, the key understanding needed is what do Business Performance & Basel II have to do with my survivability as a money center bank?

Basel II introduces a convergent framework of risk management and controls that will encourage banks to invest wisely in IT and improve the efficiency of their business operations. Banks that adopt effective enterprise risk management platforms will reap business benefits that go well beyond regulatory compliance.

Knowledge Management is coming to banking in a way that the bean counters never imagined. With the focus on Operational Risks, the only way to be able to correlate new threats with the current asset base is through automation.

The industry is now at the implementation phase of Basel II. Few banks have the perspective and resources to experiment and establish their own enterprise risk management models that include this new field of operational risk. Notwithstanding their attention to business continuity and reputational risk matters, most banks have still to inscribe operational risk procedures in the broader picture of business management and operational efficiency. Not only may banks improve their operational efficiency by streamlining business processes, but they also can tap important benefits in operational resilience, responsiveness and flexibility to innovate. By adopting automation models for integrated business and risk management, proactive banks may derive significant returns from a concerted enterprise approach.

Thursday, September 14, 2006

Corporate Data Policy: How good is your Inventory Management?

Stewards of corporate data have little or no understanding where their data is located. Not only this, customer and consumer information was ranked less important to protect from theft or loss of confidentiality than intellectual property and sensitive business information in this survey from the Ponemon Institute.

Vontu and Ponemon Institute conducted the first U.S. Survey: Confidential Data at Risk to better understand the nature and extent of issues that occur because companies do not have adequate control over the storage of sensitive or confidential data at rest. Our independently conducted survey queried 484 respondents who are employed in corporate IT departments within U.S.-based business or governmental organizations.

The survey focused on the following four issues:

1. How pervasive is the problem of unprotected confidential data at rest?

2. How do information security practitioners locate sensitive or confidential business information that resides (somewhere) within their organization’s IT infrastructure?

3. What technologies, practices and procedures are employed by organizations to locate and control sensitive or confidential data at rest on peripheral or temporary devices such as laptops, PDAs and memory sticks?

4. What are the issues, challenges and possible impediments to effectively locating unprotected sensitive or confidential data residing on peripheral or temporary devices?


When will customers and consumers demand that their information be put on the same level of priority as a organizations own trade secrets? In most cases, an organization will not devote resources to the confidentiality, integrity or availability of customer data unless it is demanded by regulators, laws and auditors.

Not until a state Attorney General or the SEC begins their investigations do companies realize that they are way behind in the process of identifying where their data is and where it is unsecured or exposed to the possibility of being modified, destroyed or stolen.

The four types of data considered to be most at risk in an organization are intellectual property, business confidential information, customer and consumer data, and employee data. It is interesting to note that most respondents believe the most serious kinds of data breaches involve the loss or theft of intellectual property and business confidential information.

Customer and consumer data and employee data are ranked third and fourth, respectively. The types of intellectual properties believed to be most at risk include electronic spreadsheets, competitive intelligence and source code.


And companies like Vontu are well positioned to provide some of the tools to assist organizations in protecting their valuable corporate information assets. Privacy of consumer information should not have to be legislated if an organization has an effective Governance Execution Strategy. This execution of the information inventory is in many cases left up to internal employees in the IT department. Continually under staffed and fighting fires prevents the systematic and consistent execution of day to day change controls and thereby leads to a widening exposure of vulnerable data considered valuable to the company or the consumer.

When it comes to lost or stolen laptops, servers, and backup tapes, the age old saying about an "Ounce of prevention…" applies more than ever. Implementing Data Loss Prevention has become a best practice in Fortune 1000 companies that are building strategies and processes to reduce their risk associated with lost or stolen laptops, servers, and backup tapes.

Sunday, September 10, 2006

On the Eve of 9/11: Flashback to the Future...

On the eve of 9/11/2006 we look back five years and it seems like it was yesterday. Tomorrow we might be at a church memorial services, as we will in downtown Washington, DC. Saying prayers for those who have fallen, and their families.

Yet, tomorrow will not only be full of emotions of years past. It will be prayers for the future. That our children across the globe will somehow be able to call this date in history the beginning of a new world order.

The Operational Risks we all endure on a daily basis are there in front of us. Some are more obvious and predictable. They have a history and a pattern to be analyzed and forecasted. Those risks that are low probability and have little or no historical context are the events to fear.

The new world order in front of us today is increasing complex and dynamic. Chaos seems to be a good adjective for much of what we see and hear in our daily consumption of news and media. How can any person in Moscow, Beijing, Tokyo, Sydney, LA, NYC, DC, London, Paris, Madrid, Baghdad, Kabul or Rome make sense of what the future holds for mankind?

The only certainty is that the speed of change and the age of unreason will unfold at a velocity that our children will call the "New Normal". The flashback to the future is nothing more than an accelerated version of the past. Gods Speed to all of us!

Thursday, September 07, 2006

Privacy in the Board Room: The Ethics of Surveillance...

Corporate Governance in the board room itself is blazing out of control at Hewlett Packard (HP) as a result of an internal investigation. The finger pointing, board resignations and ethics questions are all in the news. And that is just a very small story on the entire landscape of corporate digital surveillance or internal investigations. This is a business your insurance company is funding and for good reason.

The entire episode—beyond its impact on the boardroom of a $100 billion company, Dunn’s ability to continue as chairwoman and the possibility of civil lawsuits claiming privacy invasions and fraudulent misrepresentations—raises questions about corporate surveillance in a digital age. Audio and visual surveillance capabilities keep advancing, both in their ability to collect and analyze data. The Web helps distribute that data efficiently and effortlessly. But what happens when these advances outstrip the ability of companies (and, for that matter, governments) to reach consensus on ethical limits? How far will companies go to obtain information they seek for competitive gain or better management?


It will be interesting to see if the California Attorney General is going to get into the middle of the battle. Yet, there seems to be less discussion about the ability of a skilled investigator using "Social Engineering" techniques to obtain the information in question.

Hackers like Kevin Mitnick call it "social engineering." Other folks call it plain old lying. But today's private investigators have a new word for obtaining information under false pretenses; they call it "pretexting," and it's apparently big business.


We wonder about the new legislation brewing in state capitals to extend the data privacy laws and the national Gramm-Leech-Bliley Act (GLBA)to telcos, ISP's and other repositories of personal information. Bankers have been working for a decade to stop the same criminal activity of stealing information to use in a fraudulent manner. It won't be long before your phone company will be sending you those privacy disclaimers in the mail and two-factor authentication will be the norm when you log in to Verizon Wireless.

Friday, September 01, 2006

Strategy Acceleration: Surviving the Basel 7...

So what are the seven loss event categories of Operational Risk Management according to Basel:

Internal Fraud

Loss due to acts of a type intended to defraud, misappropriate property or circumvent regulations, the law or company policy, excluding diversity, discrimination events, which involves at least one internal party.

External Fraud

Losses due to acts of a type intended to defraud, misappropriate property or circumvent the law, by a third party. These activities include theft, robbery, hacking or phishing attacks.

Employment Practices and Workplace Safety

Losses arising from acts inconsistent with employment, health or safety laws or agreements, from payment of personal injury claims, or from diversity / discrimination.

Clients, Products & Business Practice

Losses arising from unintentional or negligent failure to meet a professional obligation to specific clients (including fiduciary and suitability requirements), or from the nature of design of a product.

Damage to Physical Assets

Losses arising from loss or damage to physical assets from natural disaster or other events. See disaster recovery or business continuity planning.

Business Disruption & Systems Failures

Losses arising from disruption of business or system failures. This includes loss of due to failure of computer hardware, computer software, telecommunications failure or utility outage and disruptions.

Execution, Delivery & Process Management

Losses from failed transaction processing or process management, from relations with trade suppliers and vendors. This includes Transaction Capture, Execution & Maintenance Miscommunication, Data entry, maintenance or loading error Missed deadline or responsibility, Model / system misoperation Accounting error, entity attribution error, Delivery failure, Collateral management failure Reference data maintenance, Monitoring & Reporting Failed mandatory reporting obligation, Inaccurate external report (loss incurred), Customer Intake & Documentation Client permissions / disclaimers missed Legal documents missing / incomplete, Customer / Client Account Management Unapproved access given to accounts, Incorrect client records (loss incurred), Negligent loss or damage of client assets, Trade partners, non-client vendor misperformance and vendor disputes.


Operational Risk Management in your enterprise may be centralized or decentralized based upon your organizational structure. However, one item should not be overlooked when it comes to effectively executing across these categories. Strategy Acceleration is paramount if you are going to survive.

THERE ARE 6 WAYS to ACCELERATE STRATEGY EXECUTION.

Creating strategic foxholes with your executive team. This ensures that your senior team is clear on strategic intent, aligned with what it will take to make any endeavor "executable," and committed to achieve expected results.

Identifying and implementing key levers for strategic performance improvement. This ensures that result measures are tied to the business and behavioral changes needed to produce them and establishes accountability for results.

Rapidly cascading strategic clarity, buy in, rollout plans and commitment from the executive suite to the front line. Getting everyone who is essential to strategic results executing from the same playbook.

Operationalizing a Strategy Realization Office. Putting the execution infrastructure and resources in place to manage acceleration and ongoing execution of your critical business strategies. Defining, designing and staffing the function of Strategy Execution Officer.

Applying a strategy portfolio management approach to maximize return on investment and minimize shareholder risk. Providing the mechanism for your executive team to manage priorities, timing, investment, risk, return, resources, capacity and results from your strategies.

Increasing the nimbleness of your leaders and people at all levels so they are prepared to absorb any strategic initiative needed to ensure your organization's success. Leaders from top to bottom will learn the key steps to building a nimble company - one that is capable of executing major strategic initiatives more effectively and efficiently than any of your competitors.

Tuesday, August 29, 2006

Authentication Risk: Solving the Multifactor Question...

U.S. Bankers are in crunch mode to make decisions and finish risk assessments by year end. Multifactor Authentication is the issue at hand as Operational Risk Managers wrestle with vendors and their own IT organizations.

"Less than four months remain for banks to meet the Federal Financial Institutions Examination Council's year-end deadline for Internet banking authentication, but some confusion remains over what is an acceptable solution. When the FFIEC agencies initially released the guidance on Oct. 12, 2005, many banks were left scratching their heads as the guidance explicitly states that it "does not endorse any particular type of technology." Rather, the FFIEC says, banks should assess their own risk and decide which solutions best meet their individual needs.

Adding to the confusion, bankers, vendors and experts have fixated on the term "multifactor authentication." But the FFIEC never explicitly states that multifactor authentication is the only way to comply. According to the FFIEC's guidance, "The agencies consider single-factor authentication, as the only control mechanism, to be inadequate for high-risk transactions involving access to customer information or the movement of funds to other parties."


While authenticating the person who is logging into the secure Internet banking site is important, it is equally important for the consumer's chosen banking site to be simultaneously authenticated.

Mutual Authentication

Mutual authentication is a process whereby customer identity is authenticated and the target Web site is authenticated to the customer. Currently, most financial institutions do not authenticate their Web sites to the customer before collecting sensitive information. One reason phishing attacks are successful is that unsuspecting customers cannot determine they are being directed to spoofed Web sites during the collection stage of an attack. The spoofed sites are so well constructed that casual users cannot tell they are not legitimate. Financial institutions can aid customers in differentiating legitimate sites from spoofed sites by authenticating their Web site to the customer.

Techniques for authenticating a Web site are varied. The use of digital certificates coupled with encrypted communications (e.g. Secure Socket Layer, or SSL) is one; the use of shared secrets such as digital images is another. Digital certificate authentication is generally considered one of the stronger authentication technologies, and mutual authentication provides a defense against phishing and similar attacks.


One way to solve the issue is to find a company who has taken all of these technology hurdles and has found a viable solution for FFIEC compliance. See Boulder, Colorado based Authenticol to add to your short list.

Friday, August 25, 2006

Metrics: How to Measure Change...

Identifying operational risks to corporate assets is not new. Applying the correct metrics to determine where and how you measure change is a growing arena for a new breed of enterprise risk professionals.

Measures mapping: a way to identify risk mitigation strategies and evaluate their effectiveness is a key component for any initiative on How to Use Metrics and George Campbell has some very relevant places to begin:

We are all familiar with the highway sign "Dangerous Curve, Reduce Speed Ahead." Many of the measures discussed in this story may be applied to provide the CSO and key constituents with similar caution signals. They become the earliest prompts for more in-depth analysis of trend dynamics that allow you to look at the root causes of problems, not just the symptoms.

Examples of incident trends that help diagnose risks to address include:

1. Increased frequency or severity of accident, crime or policy infraction rates

2. Reduced mean times between failures on critical equipment with increased downtime

3. Increased number or severity of negative background investigation rates in specific hiring populations

4. Excessive passwords for access to different "secure" applications, which results in shared passwords and visible posting of passwords

5. Abnormal response times to calls for service

6. Outsourcing sensitive business processes without requisite due diligence

7. Elimination or reduced testing of building evacuation plans, which leads to employee confusion and injury during real incidents

8. Degradation of timely software patch application or increased virus activity in specific client groups


As a former CSO at Fidelity Investments Mr. Campbell has hit most of the critical silos of risk accross the enterprise. Whether it be people, processes, systems or external events, one thing is certain. Without a metrics program in place, how do you measure change? Not so much if we are winning or losing the battle against internal fraud, information security breaches or stolen corporate assets. But the nature of the changes and the potential root cause of those changes.

Competitive and regulatory drivers including BSA, Patriot Act, Basel II and Sarbanes-Oxley have increased pressure on executives to understand and manage risks more effectively. Top level executive mandates include:

* Protect corporate reputation and brand integrity
* Meet current and future regulatory requirements
* Provide visibility into possible risks and limit actual losses
* Achieve a fast response and recovery from actual negative events
* Maintain / improve customer satisfaction
* Increase quality and productivity of risk management processes

But, satisfying these mandates presents three core challenges to risk and compliance officers:

* Detecting risks is not sufficient; how will you manage and respond to them?
* In the face of changing regulations and cross-departmental systems, how will you govern the process?
* With so many point solutions, how will you justify the redundant investment and effort to deliver each one?

Thursday, August 17, 2006

Asia Pacific: OPS Risk Spend on the Rise...

Operational Risk Spend in Asia Pacific is growing rapidly due to the revised Basel II accord which requires explicit assessment of operational risk, endorsements by consultants on the impacts of effective operational risk management systems, and continuous threats from the likes of terrorist attacks.

Financial Insights estimates total Asia/Pacific spending for operational risk systems at US$74 million in 2006. In the next five years, this number is projected to amplify to an inflation-adjusted US$246 million, equivalent to 3.3 times the current value or a compound annual growth rate (CAGR) of 27.2 percent.


This outlook by IDC is taking into consideration the different tiers of institutions including buy-side and sell-side along with banks plus insurers.

Operational risk management was designed to assist institutions identify matrices to determine an institution's risk tolerance, perform data monitoring and analysis to increase visibility of exposures, and create early alerts for immediate corrective action. Several industry incidences illustrated the undeniable correlation between operational risk management and sound business practices, and demonstrated that having control mechanisms in place to minimise operational risk elicits genuine paybacks through loss minimisation and reputation protection.
Consequently, the implementation of operational risk management solutions is accelerating in Asia/Pacific.

Thursday, August 10, 2006

Beyond Fear: Evidence of Aviation Plot...

The Terror Plot Exposed this morning is just one more piece of evidence that the US and UK homeland remains under attack.

The Department of Homeland Security is taking immediate steps to increase security measures in the aviation sector in coordination with heightened security precautions in the United Kingdom. Over the last few hours, British authorities have arrested a significant number of extremists engaged in a substantial plot to destroy multiple passenger aircraft flying from the United Kingdom to the United States. Currently, there is no indication, however, of plotting within the United States. We believe that these arrests have significantly disrupted the threat, but we cannot be sure that the threat has been entirely eliminated or the plot completely thwarted.

For that reason, the United States Government has raised the nation’s threat level to Severe, or Red, for commercial flights originating in the United Kingdom bound for the United States. This adjustment reflects the Critical, or highest, alert level that has been implemented in the United Kingdom.


The nature of the imminent threat and the Operational Risks associated with keeping the investigation under cover any longer prompted authorities to "Go Public" with the plot early today. While only 21 individuals have been arrested at this point in time, the weeks ahead will tell a more detailed story about links to Pakistan and possibly al-Qaida.

The era of suicide bombers is extending month by month and year by year. Vigilance in our thinking about what is possible and how effective their strategy can be, is imperative.

Terrorists have used suicide bombs for decades. As the suicide attacks in New York and London have demonstrated, this tactic has now become a threat to parts of the world previously untouched by suicide terrorism.

Suicide bombers may use a lorry, plane or other kind of vehicle as a bomb - either carrying explosives or using the fuel aboard the vehicle as a makeshift explosive - or may conceal explosives on their persons. Both kinds of attack are generally perpetrated without warning. The most likely targets are symbolic locations, key installations, VIPs or mass-casualty 'soft' targets.

When considering protective measures against suicide bombers, think in terms of:

* Denying access to anyone or anything that has not been thoroughly searched. Ensure that no one visits your protected area without your being sure of his or her identity or without proper authority. Seek further advice through your local police force's CTSA.

* Establishing your search area at a distance from the protected site, setting up regular patrols and briefing staff to look out for anyone behaving suspiciously; many bomb attacks are preceded by reconnaissance or trial runs. Ensure that such incidents are reported to the police

* Effective CCTV systems can help prevent or even deter hostile reconnaissance, and can provide crucial evidence in court

* There is no definitive physical profile for a suicide bomber, so remain vigilant and report anyone suspicious to the police.

Friday, August 04, 2006

CSO Job Security: Training To The Rescue...

Businesses Don't Get It when it comes to training employees on security technology and policy.

What's particularly alarming is that the desire for security compliance doesn't sync with the effort businesses put toward training and education, both within the IT department and throughout the workforce. Monitoring user compliance ranked as the No. 1 security priority in a survey of 966 U.S. companies polled by InformationWeek Research and Accenture. Security policies typically define who has access to data, how it can be used, where customer data can and can't be stored, any potential legislation the company is subject to if the data is breached, and whether data must be encrypted.

Still, more than half of U.S. companies surveyed say security technology and policy training would have no impact on alleviating employee-based breaches, a sentiment shared by more than half of the companies surveyed in Europe and China as part of the InformationWeek 2006 Global Security Survey. In fact, most companies surveyed worldwide admit they don't train their employees on information security policies and procedures on a regular basis, preferring instead to deliver ad hoc training.


Can you imagine being a CSO or CIO on the witness stand today? Or maybe it's just a deposition. The legal counsel for the plaintiff asks a simple question like:

Does your company have a written policy for training new employees on security technologies and controls?

Yes.

Does this written policy specify how and when a new employee shall be trained on security procedures and controls?

Yes.

Can you please state the number of formal training sessions held last year on security technology and policy at your company?


No.

Can you estimate the number of new employees trained last year according to your companies written policy?

No.

And the pain and suffering continues as the CxO realizes that the chain of evidence does not show a clear and demonstrable strategy for training employees on security controls. It does not follow the written policy of the company. Game over.

Given the increase in the number of data breaches, businesses can't allow security polices to become hampered by ambivalence and red tape. Next time, it could be your job on the line.

Tuesday, August 01, 2006

Public-Private Partnerships: Understanding Regional Interdependencies...

The Business Roundtable has released it's findings on U.S. Preparedness for A Major Cyber Catastrophe.

The Roundtable report identified major gaps in the U.S. response plans to restore the Internet:

* Inadequate Early Warning System – The U.S. lacks an early warning system to identify potential Internet attacks or determine if the disruptions are spreading rapidly.

* Unclear and Overlapping Responsibilities – Public and private organizations that would oversee recovery of the Internet have unclear or overlapping responsibilities, resulting in too many institutions with too little interaction and coordination.

* Insufficient Resources – Existing organizations and institutions charged with Internet recovery should have sufficient resources and support. For example, little of the National Cyber Security Division (NCSD)’s funding is targeted for support of cyber recovery.

In its report, the Roundtable concluded that these gaps mean that the U.S. is not sufficiently prepared for a major incident that would lead to disruption of large parts of the Internet and the economy.


Karl Brondell, who heads up the Cyber Security Working Group of the 160-member Business Roundtable, an association of CEOs at leading companies, presented a group report to the Federal Financial Management Subcommittee, saying the nation lacks coordination between the public and private sectors in the event of an internet outage.

The report, "Essential Steps Toward Strengthening America's Cyber Terrorism Preparedness," found major holes in planning, including an inadequate warning system to identify possible internet attacks, unclear responsibilities among public and private partners should an incident occur and unsatisfactory resources to recover from an attack.

The Business Roundtable is on the right track when they recommend that a public-private partnership be established to address these vital issues. What is important to remember is that this will be difficult and almost impossible to achieve on a national level. The interdependencies of our Critical Infrastructures including the Internet are a regional issue. This requires a public-private dialogue and coordination with metro areas and tri or quad state regions. Only when you have the exercises and the testing locally will each party better understand their own vulnerability. This is when each company or city realizes the necessary planning for supply chain redundancy and the criticality of logistics strategy.

The CEO's can talk and publish reports yet it will be the operational risk professionals, contingency planners and emergency managers who do the heavy lifting. They are the people who are making a difference everyday to make our country more resilient to the impact of major economic and public safety threats. These are the people who are "doing" and still not "talking".

Thursday, July 27, 2006

Critical Infrastructure Resiliency: SCADA

The SCADA and Control Systems Procurement Project provides the operational risk context and knowledge for any CISO, CIO or CTO who is procuring new software to control Critical Infrastructures. It is also a good lesson for those projects where the information assurance policies require a strict protocol for purchasing new systems and software. This project is the first of many efforts to create a more resilient infrastructure and to mitigate the risk of future attack on these vital systems in our daily public and private sector operations.

SCADA (Supervisory Control And Data Acquisition) generally refers to the systems which control our critical infrastructures -- such as electric power generators, traffic signals, dams, and other systems. Protecting our critical infrastructure and process control systems is a vital component of our nation's readiness and response efforts. The SCADA Procurement Project, established in March 2006, is a joint effort among public and private sectors focused on development of common procurement language that can be used by everyone. The goal is for federal, state and local asset owners and regulators to come together using these procurement requirements and to maximize the collective buying power to help ensure that security is integrated into SCADA systems.


This is a major step towards risk mitigation in the systems that keep our economy running on a daily basis. Without more resilient systems, our financial and healthcare sectors are at the mercy of a myriad of exploits by "Digital Adversaries".

To reduce control systems vulnerabilities, the DHS National Cyber Security Division (NCSD) established the Control Systems Security Program (CSSP) and the US-CERT Control Systems Security Center (CSSC). The CSSP coordinates efforts among federal, state, and local governments, as well as control system owners, operators, and vendors to improve control system security within and across all critical infrastructure sectors by reducing cyber security vulnerabilities and risk. The US-CERT CSSC coordinates control system incident management, provides timely situational awareness information, and manages control system vulnerability and threat reduction activities.

Monday, July 24, 2006

US National Preparedness Month: September 2006...

September 2006 is US National Preparedness month and the perfect time to manage Operational Risks both at home and your business.

The U.S. Department of Homeland Security and the American Red Cross are working with a wide variety of public and private sector organizations to educate the public about the importance of emergency preparedness. Throughout September, these organizations are providing information, hosting events and sponsoring activities that disseminate emergency preparedness messages to and encourage action in their customers, members, employees, stakeholders and communities across the nation.


1SecureAudit is pleased to be coalition partners again in 2006 to help business executives better prepare their communities for “All-Hazards”. “Our goal is to provide on-going public awareness campaigns this September through our webinar series on Corporate Emergency Response Teams and Terrorism Risk Management said Peter L. Higgins, Managing Director and Chief Risk Officer at 1SecureAudit.”

The goal of the month is to increase public awareness about the importance of preparing for emergencies and to encourage individuals to take action. Throughout September, Homeland Security will work with a wide variety of organizations, including local, state and federal government agencies and the private sector, to highlight the importance of emergency preparedness and promote individual involvement through events and activities across the nation.


In order to impact preparedness on a macro level, you have to begin the process at the micro level. Business leaders start the training, awareness and readiness at home with their own family members. Reviewing the place they will all meet in an extreme emergency when they may become separated. Establishing the single point of contact out-of-state that each family member will contact in order to check-in. This step is imperative as much of the telecom networks will be unavailable on a local level for connecting phone calls. The likelihood of reaching a designated contact out of the local area is much higher.

Once the family is prepared, then move on to the business where you work. Create your own Corporate Emergency Response Team (CERT) to create readiness exercises for your community in your building, Business Park or campus. As you roll-up your business community to the local city or county level, now you can coordinate with your public community. Do you know the station number of your local fire and EMS First Responders? Do you know the name of the Captain(s) that may be on duty the day a significant event takes place in your area? If you don't, then you should.

Once the business and local community is prepared and coordinated, then move up to the metropolitan level or state level. This is where the largest catastrophes will be coordinated with the Department of Homeland Security or other federal agencies. Does your business or local community have a seat at the Emergency Operations Center (EOC)? What measures are in place for you and your team to assist and collaborate with the state or federal authorities in times of crisis?

At the end of the day, it all comes back to managing operational risks. Making the right decisions in advance to preempt threats. Secondly, and simultaneously preparing for the time when "Mother Nature" or the "Suicide Terrorist" severely impacts our lives and our economy.