Sunday, August 24, 2014

Inspect v. Study: Quality of Operational Risk Management...

As this weblog reaches it's 1,060th post in the next few months, much has been documented on the course of "Operational Risk" over the past ten years. We have continuously witnessed the dawn of new threats and vulnerabilities that could only have been imagined in the last millennium.

At the same time, we could not have predicted the new found solutions, to many of the same operational risk related incidents that have plagued our institutions, governments and the planet we call Earth. Every time you think you have heard or witnessed it all and that all new future risk events will just be some variant of those that have preceded us in history, we are surprised and blind-sided. The "Black Swan" has visited us once again.

Yet one item that remains consistent over the course of risk incidents and numerous after action findings is this fact. We have not devoted enough resources in preparation and in scenario-based exercises to improve our resiliency. We remain in denial that we could ever be subjected to the 1-in-100 year event. However, there is someone named Warren Buffet who to this day, is still adding reinsurance companies to the Berkshire Hathaway portfolio. Do you think it is because Mr. Buffet is betting on more risk or less in the world over the next decade?

Risk Managers think about the "What if" more than anyone else, in many cases because they are paid to do this on behalf of their employer. Yet as human beings, we take risks every day without even thinking twice about how much risk we are taking on and what the possible outcomes could be. We just move through life in a wait and see totally reactive mode. So how do you get at least a majority percentage of the people walking around the halls of your organization to think more like a savvy risk manager? What does it take to inject a little more "What if" into the consciousness of each person and the roles and jobs that they play in your institution?

The first is to design and engineer your management system to incorporate a risk-based standard for operations. Secondly, to incorporate the applicable risk management controls to produce the rules-based behavior that you are adopting. Finally, to test the rule-sets with a continuous approach to ever so incremental improvement over time. Sounds familiar doesn't it. Plan-Do-Check-Act.

Whether you are trying to improve the awareness, implementation and/or measurement of Operational Risk on the deck of the aircraft carrier, at the FOB, on the trading or manufacturing floor or within the supply chain of the vital resources that fuels your organization, "Plan-Do-Check-Act" (PDCA) works. And you have heard it before, those who are hit by the "Black Swan" event will die or go out of business relative to the previous attention they have paid over the years to PDCA.


PLAN
Establish the objectives and processes necessary to deliver results in accordance with the expected output (the target or goals). By making the expected output the focus, it differs from other techniques in that the completeness and accuracy of the specification is also part of the improvement.
DO
Implement the new processes, often on a small scale if possible, to test possible effects. It is important to collect data for charting and analysis for the following "CHECK" step.
CHECK
Measure the new processes and compare the results (collected in "DO" above) against the expected results (targets or goals from the "PLAN") to ascertain any differences. Charting data can make this much easier to see trends in order to convert the collected data into information. Information is what you need for the next step "ACT".
ACT
Analyze the differences to determine their cause. Each will be part of either one or more of the P-D-C-A steps. Determine where to apply changes that will include improvement. When a pass through these four steps does not result in the need to improve, refine the scope to which PDCA is applied until there is a plan that involves improvement.


It's clear to the "Operational Risk" professional why PDCA has one little flaw. The "Check" could and should be replaced by "Study" to emphasize analysis over inspection as Dr. W. Edwards Deming has said. To analyze and study takes us to the core of the issue. People are always looking for expected results, not unexpected outcomes. If we are to expect "unexpected" results, perhaps the "Analyze-Study" mindset would then perpetuate the plethora of risk professionals who are still caught up on the "Check". Inspection will get you killed and it will produce more "Black Swans" in your lifetime than you would ever expect. Check = Inspection. Study = Analyze.

So we think it is safe to say, that Warren Buffet is betting on the current trend of a mentality of inspection and not study. He is investing in the future of insurance companies needing insurance to hedge their own underwriting failures. Study and analysis are the ingredients of success for the most sought after risk managers on the globe. Unfortunately, too many still have not figured out that "Check" is out and "Study" is in.

The future quality of Operational Risk Management will lie in the hands of practitioners who are analyzing and studying before they apply new changes to gain new improvements. Now think about your organization. Where are the people who are patient? How long do they take to study the business problem or assess the climate you operate in every day? When you find these individuals you need to keep them close and you will soon find that you are well on your way to a more resilient future.

Sunday, August 17, 2014

Insider Threat: CSO Priorities...

If you are the CSO of a Fortune 50 company these days you have a few top of mind Operational Risk Management (ORM) priorities. There is only so much you can do with the resources you have been given, to preempt attacks on your enterprise regardless of the origin, internal or external. The time and resources for exercising plans and testing contingencies are getting more scarce. So where and how do you apply your knowledge and priorities to gain the most effective results?

In alphabetical order, here are some of the known attack methods to bring severe economic and human losses to bear on your business and the homeland:
  • Aircraft as a weapon
  • Biological Attack: Human Disease, Livestock, Crop
  • Chemical Attack
  • Cyber Attack
  • Food or Water Contamination
  • Hostage Taking
  • Improvise Explosive Device (IED)
  • Maritime Vessel as a Weapon
  • Nuclear Attack
  • Radiological Dispersal Device
  • Standoff Weapons: Guided
  • Standoff Weapons: Unguided
  • Vehicle-Borne Improvised Explosive Device
Now one could discuss the probability of each of these threats to determine the best strategies for preparing for one vs. another. More importantly, you could group these into clusters so that investing in prevention and preemption activities and tools would impact more than one attack method. Yet as you analyze your own specific critical infrastructure assets in your enterprise, you will then see those attack methods that will have the greatest affinity for that location or type of asset.

It is well known that the private sector owns and operates a majority of these critical assets for national security, now estimated around 85%. If you look at the list of known attack methods and realize who is "perceived" to be responsible for protecting these assets, the problem becomes more clear. The private sector expectation that the government or public sector is going to protect the critical assets that the private sector owns is the going logic. How far from the truth and reality could this perception be today?

As the Chief Security Officer (CSO) of a Fortune 50 company you no doubt have already cataloged your facilities and sub-categorized the assets within each of these facilities. You have included the "Intellectual Property" (IP) considerations for each location such as key people, R&D, Engineering, Software Development and others. You understand the value of these tangible and intangible assets as it pertains to the survivability of your organization. You have already developed the systems to recognize the moves, adds and changes to these facilities and assets so the portfolio of critical infrastructure and intellectual assets is up to date in real-time.

For many of you the last big push was to make sure that the Continuity of Operations and BCP Plans or Disaster Recovery strategies are in place to provide the peace of mind for "What if" scenarios. Your off site hot back-ups and mirrored data are functioning perfectly. The exercises have told you that operating these plans when the time comes will be touch and go but you are confident that you will get through it.

Now let's go back to our original question. So where and how do you apply your knowledge and priorities to gain the most effective results?

Your worst enemy now is your perception that the government is there to protect you first and to keep your private sector assets safe before the company next door or across the street. Your complacent attitude towards sharing vital information with the public sector authorities in your city, county and region is where you have your greatest vulnerability. How can these people who serve the local, state and federal agencies know anything about what is valuable to you if you don't tell them?

You see, it doesn't matter what your adversaries utilize as the their favorite attack method to do you harm. Of course they will want to use the ones that will have the most economic impact on our nation and it's people. Yet, without the continuous exchange of information flow from the private sector to those government officials, your business is just another casualty waiting to happen.

So if the government is working on the external threat through the Department of Homeland Security (TSA), Border Patrol, Coast Guard, CERT and the FBI on Counter Terrorism, Counter Intelligence and Cyber Crime what should you the CSO at your Fortune 50 company be focused on? The Insider Threat. Pure and simple.
“An individual with the access and/or inside knowledge of a company, organization, or enterprise that would allow them to exploit the vulnerabilities of that entity’s security, systems, services, products, or facilities with the intent to cause harm.”
  • Due to a lack of hard data, threat definition remains difficult;
  • While education and awareness can be provided, cultural change remains more difficult and requires: 
  • Investment in structured programs and risk management; 
  • Corporate culture where trust does not run counter to prevention programs; and 
  • Improved workforce communication and cooperation so targeted efforts can address insider threats
  • Use of background checks varies among sectors and are not universally accepted; regulation is controversial; and
  • Multiple legal environments complicate Insider Threat mitigation strategies, not only domestically, between Federal, State, local jurisdictions, but also and more significantly, for those companies operating in multinational environments, complicating cohesive or comprehensive policy efforts.
The Insider Threat is real and requires continuous vigilance across the private sector. Secondly, the interface with your local first responders and law enforcement should be established early and often. Establish your own "Homeland Watch" mechanisms in your business park or metro area mapped to the local fire and police substations. Understand and get to know how they prioritize their response and investigations of suspicious activity and how it could impact you.

Finally, get very familiar with the NIPP. It could be your key to better understanding the mindset of the public sector and safeguarding your corporate assets.

Sunday, August 10, 2014

4th Paradigm: Predictive Risk Innovation...

21st century innovation requires new thinking, new tools and the application of a creative mind.  When it comes to innovating Operational Risk Management (ORM), take a leap towards "Predictive Intelligence".  What has been holding you back?  Is it the right combination of new thinking, new tools and the applications you haven't even thought of yet?

How could we apply the use of a High Computing Cluster (HPC) using Amazons Elastic Compute Cloud (EC2) with the right haystack of data to get the answers we seek?  Without building a new data center and for under $5K.  Think about the possibility of 10,000 plus server instances running across five data centers, with the results we seek in hours.  Utility Super Computing is here today for white hats and also even the "Black Hats."

Predictive Analytics is an art and a science, that is thriving with the use of "Fusion Infrastructure" by the hour. Why do we need to spend tens of millions of dollars on our own data center anymore, to get the rapid answers we require to run our business or to defend our nation?

Now the debate has gone beyond the infrastructure, to look at the other bottle necks.  What about the database architecture itself?  Is the traditional implementation of the disk intensive real-time Relational Database Management System (RDBMS) paradigm over?  Hadoop is here, yet requires new language learning curves and is a batch solution.  This could be one of the answers to predictive risk innovation:
MemSQL is the distributed in-memory database that provides real-time analytics on Big Data, empowering organizations to make data-driven decisions, better engage customers, and discover competitive advantages. MemSQL was built from the ground up for modern hardware to leverage dozens of cores per machine and terabytes of memory. We are entering an era that will be defined by distributed systems that scale as you need capacity and compute, all on commodity hardware.
How long will it take you to stand-up your own "Operational Risk Intelligence Center"?  One or two days or a week, with the right people and skill-sets in place.  What kinds of questions and answers will allow you to predict the future, faster than your competitor or your latest cyber adversary?
If you throw enough money at a problem there’s bound to be a solution, some think. That’s the logic of security expert Dan Geer, who this week told the Black Hat conference in Las Vegas that the U.S. government should throw a heck of a lot of greenbacks at people who discover vulnerabilities. 
How much? Ten times more than anyone else, he said in a keynote address.
Geer, chief information and security officer at In-Q-Tel, a not-for-profit venture capital company that invests in early stage companies making products aimed at U.S. intelligence agencies, maintained the U.S. should corner the market on vulnerabilities.
“Then we make them public and reduce to zero the inventory of cyber weapons that others have,” he was Geer said. “I believe that exploitable software vulnerabilities are scarce enough that if we corner the market, we can make a difference.” including eSecurity Planet and ThreatPost.com.
A number of companies have so-called bug bounty programs, including Microsoft and Google. Nor is Geer the first to say governments should open their wallets. In January, researchers at NSS Labs issued a report arguing that only drastic measures can bring cyber threats under control.
Innovation in the Operational Risk Management spectrum is on the verge of massive change. Operations Security, Fraud Analytics and Supply Chain Management are just the beginning.  The Board of Directors of the commercial enterprise, Military Strategic Commands and virtual chat rooms on the deep web, are debating these very subjects.  Application of "Utility High Performance Computing" in combination with 4th Paradigm databases, puts innovation back at the forefront of the creative mind.

Sunday, July 13, 2014

ID Analytics: Risk of the Unknown...

Operational Risk Management (ORM) has been at the top of the news in the past few weeks.  Digital media and the metadata of "Big Data" is the topic of choice.  It is a revealing look behind the curtain of what is possible these days, with the tools and capabilities that exist for exploitation and analysis.  Is too much privacy an operational risk to your personal and professional well being?  What "Trust Decisions" did you make to arrive on this page in the universe of the Internet?

In the spirit of full disclosure, if you are reading this now, we tracked how you found this blog and perhaps what search terms you used to be referred here.  Some of you, revealed their company identity. So why do we do this?  The main reason is that we want to make sure that we understand what is on your mind these days, when it comes to the global Operational Risk Management (ORM) universe. Here are a few examples in the past day or so that caught our eye:
  • management of operational risk - Latvia
  • operational risk management - Nigeria, Illinois, South Dakota, The Vanguard Group
  • common board of directors mistakes - Turkey
  • lessons learning from fail in operational risk - Malaysia
  • predictive intelligence - North America
  • rogue trader operational risk - United Kingdom
  • fund industry operation management discussion topic - Luxembourg
  • operational risk management game - Unknown
  • reputation risk management process - Unknown
  • operational risks in bank call center - Qatar
  • coso definition of operational risk - Unknown
  • black swan incident that occurs once in a lifetime - Unknown
  • ubs operational risk case analysis - Unknown
  • business resiliency definition - JP Morgan Chase
  • "operational risk" outliers - France
  • a risk effect on a daily operation - DeVry
  • examples of smart objectives risk - United Kingdom
  • black swan incident\ - South Carolina
  • black swan incident - Computer Sciences Corporation
  • what is a black swan incident - South Carolina
  • duty of care board of directors - United Kingdom
Collection of data is one thing.  Relevance and sense-making is another.  Can you imagine some of the search terms that are tracked just by Google or Bing?

What about the companies that know us the best?  Those marketing and personal data sites that keep track of where you live, how much you spend on your credit cards and where, or even the name of your pets.  How often do you give them your phone number or e-mail address at the point-of-sale (POS) to get a discount at the local retailer, gas station or pharmacy?  Believe us when we say that there are hundreds of organizations that know more about you in the private sector than some government across the world.

The trail of "digital finger prints" you leave behind everyday are vast.  A snap shot of your face at the local ATM or a snap shot of your desktop when you login to the online banking web site.  In either case, these examples are just a few of the ways that your habits, locations, preferences and lifestyle are profiled each and every day.  Where did all of this begin?  Fraud Management.  Not Homeland Security.

As a citizen traveling across the country or a consumer, you willingly give up these digital bread crumbs of your journey through life.  Your goal now, is to make sure that you are not mistaken for someone else.  After all, you or your organization have developed a profile and a reputation that is being recorded and therefore, it could be a prudent strategy to make sure that you are not mixed up with another person or organization with the same name or brand identity.

How can you do this?  Operational Risk Management (ORM) is about monitoring yourself and your organization to make sure you understand your competition (good or bad) for the same personal or business identity space.  Do you have Biometric and DNA samples of all of your key executives?  If you don't, then the question is why not?  You may have considered this in light of some of the places that your executives are traveling.  Cities and countries across the globe with the risk of kidnapping, improvised explosive devices (IED) and other risks to their lives.

As we look into the crystal ball of our digital futures, we see the scenes from movies past that have already captured our own human imagination.  A world where everyone is known and you may even choose to "opt-in" to be tracked.  After all, you are unique.  You make your own choices in life.  The risks that you face may very well be greater, for those who choose a life to remain private, anonymous and even unknown.

Sunday, July 06, 2014

4th of July: Resilience of Your Team...

The United States is celebrating the birth of the American nation this weekend.  238 years ago the formation of the Republic set the course for the country that it is today.  The Declaration of Independence was born.

A key aspect of any prudent Operational Risk Management (ORM) program is focused on people.  The risk of people and the whole dynamics of what is going on in peoples lives.  As Thomas Jefferson, John Adams, Ben Franklin, Robert Livingston and Roger Sherman toiled over the draft; what do you think was also going on in their individual lives at the time?
While political maneuvering was setting the stage for an official declaration of independence, a document explaining the decision was being written. On June 11, 1776, Congress appointed a "Committee of Five", consisting of John Adams of Massachusetts, Benjamin Franklin of Pennsylvania, Thomas Jefferson of Virginia, Robert R. Livingston of New York, and Roger Sherman of Connecticut, to draft a declaration. Because the committee left no minutes, there is some uncertainty about how the drafting process proceeded—accounts written many years later by Jefferson and Adams, although frequently cited, are contradictory and not entirely reliable.[62]What is certain is that the committee, after discussing the general outline that the document should follow, decided that Jefferson would write the first draft.[63] The committee in general, and Jefferson in particular, thought Adams should write the document, but Adams persuaded the committee to choose Jefferson and promised to consult with Jefferson personally.[2] Considering Congress's busy schedule, Jefferson probably had limited time for writing over the next seventeen days, and likely wrote the draft quickly.[64] He then consulted the others, made some changes, and then produced another copy incorporating these alterations. The committee presented this copy to the Congress on June 28, 1776. The title of the document was "A Declaration by the Representatives of the United States of America, in General Congress assembled."[65]
The ecosystem of this set of committed custodians of a new nation also included the personal lives of each one of them.  No different than the ranks of any organization who has executives and key staff members who are steering the daily direction of the enterprise.  Each individual on that team has a work life and a personal life they are managing simultaneously while doing the work of the country or the corporate business.
We hold these truths to be self-evident, that all men are created equal, that they are endowed by their Creator with certain unalienable Rights, that among these are Life, Liberty and the pursuit of Happiness, That to secure these rights, Governments are instituted among Men, deriving their just powers from the consent of the governed, That whenever any Form of Government becomes destructive of these ends, it is the Right of the People to alter or to abolish it, and to institute new Government, laying its foundation on such principles and organizing its powers in such form, as to them shall seem most likely to effect their Safety and Happiness. Prudence, indeed, will dictate that Governments long established should not be changed for light and transient causes; and accordingly all experience hath shewn, that mankind are more disposed to suffer, while evils are sufferable, than to right themselves by abolishing the forms to which they are accustomed. But when a long train of abuses and usurpations, pursuing invariably the same Object evinces a design to reduce them under absolute Despotism, it is their right, it is their duty, to throw off such Government, and to provide new Guards for their future security.
So think for a minute about your team within the enterprise.  Each person on your staff or within your division is managing and coping with life events that are occurring in real-time each day.  How much are you in tune with all those emotions and potential changes in a fellow employees life, to see how it may impact their work?

Organizations across the globe utilize Operational Risk Management (ORM) as a discipline for those safety and security events that could produce significant risks.  The same can be applied to each person and their individual ecosystem.  Each person on the team may be in different phases of their lives and need only a few pieces of the entire ORM mosaic for their personal lives.  Contingency planning however is still one of those easy exercises that most people can do on their own and in their own personal environments.

The power of the "What if" questions that you ask yourself on a daily basis is a healthy way to begin and to continuously provide effective Operational Risk Management (ORM) outcomes.  "What if" you developed a ORM college within the enterprise to educate all those new employees and existing with the skills, knowledge and capabilities available to them?  As they say "Life Happens."  Each person shall have an ecosystem of both personal and professional risks that they are encountering every day.

It could be imagined that people such as Ben Franklin had a few other items on his mind at the time.

The person to your right and to your left on the front lines of the organization, who you engage with everyday; has their own set of risks to manage in life.  A strategy for each individual to better plan, develop and deploy effective risk management individually provides the entire team with the focus they require long term.  They have been trained on using the effective continuous process for ORM:
  • Identify
  • Assess
  • Decide
  • Implement
  • Audit
  • Supervise
Imagine your organizational unit, whether it be Congress, your Family, your work out partners at Pilates or the entire executive staff all in synchronicity, with the use of Operational Risk Management. The principles of enhancing your life or your country will require a life long devotion to the rules and to the risks to a breakdown in rules of governance.  Personally or professionally.

Consider the peace of mind as your country endures the challenges to it's "Declaration of Independence" and knowing that it has a longevity of 200 plus years.  Think about the confidence and the assurance you will have about your team or family unit as each of them manage their life events and risks.  The resilience factor is strong and the safety and security of the people you care about the most, will endure.

Sunday, June 29, 2014

Trust Decisions: The Risk of a Digital Supply Chain...

Are you a business that is operating internationally?  What components of Operational Risk Management (ORM) currently intersect with your international business operations?  The safety and security of your employees who travel into countries with unstable political elements are no doubt of immediate concern.  There may even be a heightened sensitivity with whom your international business executives are meeting with and the tremendous U.S. rule-base associated with OFAC, as one example.

Fortune 500 organizations are all too familiar with these concerns, as major players in international business. The Chief Security Officers (CSO) and other key executives charged with the safety, security and integrity of employees, are focused on those who are traveling and meeting across the globe.  This is considered ORM 101.  This facet of ORM is quite mature and familiar to the Board of Directors who are charged with the Enterprise Risk Management (ERM) of the company.

What is growing more pervasive and continues to plague organizations doing business internationally is the risk of a Digital Supply Chain.  Trusted information and the confidentiality, integrity and assurance of data.  The "Genie" is out of the bottle and even the most mature and risk adverse global organizations, are continuously barraged by sudden incidents that interface with privacy and security of information.

Here is a recent example:
After a public comment period, the Federal Trade Commission has approved final orders that settle charges against 14 companies for falsely claiming to participate in the international privacy framework known as the U.S.-EU Safe Harbor. Three of the companies were also charged with similar violations related to the U.S.-Swiss Safe Harbor.
The FTC previously announced the settlements in JanuaryFebruary and May of 2014 with the following companies: 
Under the settlements, the companies are prohibited from misrepresenting the extent to which they participate in any privacy or data security program sponsored by the government or any other self-regulatory or standard-setting organization.
Consumers who want to know whether a U.S. company is a participant in the U.S-EU or U.S.-Swiss Safe Harbor program may visit http://export.gov/safeharbor to see if the company holds a current self-certification.
Under the settlements, the companies are prohibited from misrepresenting the extent to which they participate in any privacy or data security program sponsored by the government or any other self-regulatory or standard-setting organization.
So what is the real underlying issue here?  It is about "Trust Decisions".

These organizations were representing themselves as compliant with a U.S.-EU framework designed and established to protect their constituents, under the jurisdiction of the Federal Trade Commission (FTC).  The decisions to trust these organizations by an individual or business, regarding the perception that they are in compliance with a framework for privacy and security, is what is true.

How often have you ever made a "Trust Decision," based upon your knowledge that a business is displaying an official seal, mark or a sign that your information is safe and secure?  There are dozens of high profile companies operating across the globe that are in the business of selling "Trust".  Symantec, TRUSTe and GeoTrust to name a few.  The reason that a business buys one of these trusted seals or marks is because it wants to increase it's perception of trust, to the consumer or business that it is engaged with to transact business.

The business wants to display that they are compliant with the particular laws or rules associated with their industry or country.  It wants to create a sense of business assurance or peace of mind for the buyer of their products or services.  When you use one of these seals to assist in making an affirmative "Trust Decision" based upon the display of one of these badges, marks, signs or even special symbols or colors; the consumer still assumes risk of the unknown risks.  So what?

So how many consumers on a daily basis do you think visit this web site to get their free annual credit report? Green Padlock https://www.annualcreditreport.com/index.action

This is the official web site advocated by the U.S. Federal Trade Commission (FTC) for consumers to get a free annual credit report in compliance with Fair Credit Reporting Act (FCRA).  When you visit this site, you see that the URL displays a green padlock and the https: designating that the site is using secure protocols to transmit your Personal Identifiable Information (PII).  Or is it?

When you test the Annual Credit Report web site with a SSL security test service, run online by Qualys SSL Labs, https://www.ssllabs.com/ssltest/ this is their rating, on the security of Annual Credit Report.com as of 6/28/14.


Overall Rating
F
0
20
40
60
80
100
Certificate
100
Protocol Support
0
Key Exchange
80
Cipher Strength
90

This server supports SSL 2, which is obsolete and insecure. Grade set to F.
Experimental: This server is vulnerable to the OpenSSL CCS vulnerability (CVE-2014-0224), but probably not exploitable.
The server supports only older protocols, but not the current best TLS 1.2. Grade capped to B.
The server does not support Forward Secrecy with the reference browsers.  MORE INFO »
This server is not vulnerable to the Heartbleed attack.

Q: What information do I need to provide to get my free report? 
A: You need to provide your name, address, Social Security number, and date of birth. If you have moved in the last two years, you may have to provide your previous address. To maintain the security of your file, each nationwide credit reporting company may ask you for some information that only you would know, like the amount of your monthly mortgage payment. Each company may ask you for different information because the information each has in your file may come from different sources.
On a daily basis, humans are subjected to signs, marks, badges and other indicators that help them make more informed affirmative "Trust Decisions".  Whether it is the "Green Light" at the local intersection or the "Green Padlock" on the web site where we are being asked to give up our Personal Identifiable Information (PII).  The regulatory and private entities that are tasked to ensure that the signs, marks, badges and even colors are in compliance, must also look to their own level of trust of their Digital Supply Chain.

This is just one glaring example of why "Trust Decisions" are so vital to online global e-commerce.  It is also a wake-up call for any organization that is advocating trust by using a digital third party that the consumer relies on every day.  However, the FTC and other government agencies rely on private sector companies to assist them in outsourced services such as hosting Annual Credit Report. com.  The site is hosted by:

IP LocationUnited States - Massachusetts - Cambridge - Akamai Technologies Inc.

How confident are you, that your organizations digital supply chain is ensuring safe and secure "Trust Decisions" for your customers?

Sunday, June 15, 2014

TOC: The Implications of Consumer Privacy...

Operational Risks are pervasive in most every business both large and small. A small business can learn a tremendous amount from those failures by large corporate enterprises. Privacy laws in the United States are for all business owners whether they be a sole practitioner or a soon to be corporation with a $100 Billion valuation.  Operational Risk Management (ORM) is present in any serious business that makes important "Trust Decisions" on a minute-by-minute basis.

Consumer privacy and the risks associated with the protection of personal identifiable information of clients, members and customers is at stake. Learning the lessons from the organizations who have made changes and are working on a daily basis to comply with the regulatory frameworks, can be a very beneficial lesson to all.

Beyond the cost of a breach of data, Operational Risk Management (ORM) professionals understand that human behavior is the reason behind many of these incidents. Employees and supply chain insiders not clandestine hackers or malicious code sent from afar can be the major threat. So what can a Chief Privacy Officer or CISO do to mitigate the risks of employees and their behavior? All of the education and awareness campaigns may help, but the "Trust Decision" process itself is the place to begin.

Information Governance and the steps that are utilized to ingest or acquire and process that information is also paramount.  Hayley Tsukayama from the Washington Post highlights part of the issue:
Facebook came under fire Thursday from privacy advocates who say that changes to its ad network mark an unprecedented expansion of its ability to collect users' personal data. The advocates are also criticizing the Federal Trade Commission for allowing Facebook to make the changes and argue that the network's size gives it too much knowledge about its users.
Whether you are in the business of "Social Networking" like Facebook or you are the regional health care system in your state, the privacy of information of the consumer is at stake. Where that stolen information ends up in many cases, is in the hands of "Transnational Criminal Organizations" where it becomes of the lifeblood of their business operations to perpetuate their fraud schemes. These schemes are impacting the economic security of major organizations in the private sector and so the U.S. government (USG) has ramped up in the past 3 years to address the threat. Combined with other factors associated with legitimate business operations, organized digital crime syndicates have infiltrated the country and is costing the United States billions of dollars per year.

Here are several actions USG will be taking as the TOC strategy continues to be enabled:

Action

  • Implement a new Executive Order to prohibit the transactions and block the assets under U.S. jurisdiction of TOC networks and their associates that threaten critical U.S. interests.
  • Prevent or disrupt criminal involvement in emerging and strategic markets.
  • Increase awareness and provide incentives and alternatives for the private sector to reduce facilita- tion of TOC.
  • Develop a mechanism that would make unclassified data on TOC available to private sector partners.
  • Implement the Administration’s joint strategic plan on intellectual property enforcement to target, investigate, and prosecute intellectual property crimes committed by TOC.
  • Enhance domestic and foreign capabilities to combat the increasing involvement of TOC networks in cybercrime and build international capacity to forensically exploit and judicially process digital evidence.
  • Use authorities under the USA PATRIOT Act to designate foreign jurisdictions, institutions, or classes of transactions as ‘‘primary money-laundering concerns,” allowing for the introduction of various restrictive measures on financial dealings by U.S. persons with those entities.
  • Identify foreign kleptocrats who have corrupt relationships with TOC networks and target their assets for freezing, forfeiture, and repatriation to victimized governments.
  • Work with Congress to enact legislation to require disclosure of beneficial ownership information of legal entities at the time of company formation in order to enhance transparency for law enforce- ment and other purposes.
  • Support the work of the Financial Action Task Force, which sets and enforces global standards to combat both money laundering and the financing of terrorism.

The FTC is continuously working with companies like Facebook. The White House NSC is working on strategies that have a nexus with stealing consumers information to exploit the financial system. Yet all of this will be for nothing, if the private sector does not work in concert with government. Public-Private partnerships are in full swing and are making some progress.

In addition, nation state industrial intellectual property theft and economic espionage has eroded our global competitive advantage in several industry segments.  Ellen Nakashima explains:
A Washington think tank has estimated the likely annual cost of cybercrime and economic espionage to the world economy at more than $445 billion — or almost 1 percent of global income. 
The estimate by the Center for Strategic and International Studies is lower than the eye-popping $1 trillion figure cited by President Obama, but it nonetheless puts cybercrime in the ranks of drug trafficking in terms of worldwide economic harm. 
“This is a global problem and we aren’t doing enough to manage risk,” said James A. Lewis, CSIS senior fellow and co-author of the report, released Monday.
Changing peoples behavior inside your own business will require substantial oversight and continuous education. Remain vigilant at the risk of your organizations own peril!

Sunday, June 08, 2014

Algo Bots: The Risk of Human Error...

What "Trust Decisions" did you make this past week?  How fast did you make them?  The ability to manage an entire portfolio of operational risks in a daily routine is daunting.  How do you prioritize? What Operational Risk Management (ORM) process will you engage in, with so many uncertain outcomes?  Why will you sit up in bed at 3AM, to read the latest alert on your smartphone?

In October of 2012, this ORM blog discussed the topic of "Algo Bots" and "Dark Pools".  Machine language talking to other machines, to make optical network speed decisions and more precise, "Trust Decisions."  What is the risk of a low probability and high consequence incident when humans are taken out of the equation?  Dave Michaels of Bloomberg explains the current focus:
Mary Jo White’s blueprint for imposing tighter controls on high-frequency traders and some of the murky venues they inhabit stops short of a crackdown. 
The U.S. Securities & Exchange Commission’s plan, unveiled by White in a speech this week, advanced some new ideas while borrowing heavily from existing proposals and measures that already have support on Wall Street. While stock exchanges, rapid-fire traders and private trading venues known as dark pools all would come under new scrutiny, White didn’t embrace the kind of tighter restraints that have been enacted in countries such as Australia and Canada. 
White isn’t acting in a vacuum. She is responding to political pressures raised by an investigation by the New York attorney general into whether speed traders prey on slower-moving investors as well as a book by Michael Lewis, “Flash Boys,” that condemned the role of exchanges and brokers in enabling unfairness. She announced the initiatives even as she said U.S. markets aren’t rigged and serve the goals of retail and institutional investors.
As an Operational Risk Management (ORM) professional, you have to stay on the edge.  You must imagine the future and dive into the current R&D of innovation.  Being a futurist is staying on the bleeding edge of technology and this is just one facet of the risk mosaic.  The other and more human factor oriented component are the TTP's.  Tactics, Techniques and Procedures (TTP) are what you need your own "Opposition Research" team to be studying.  This is your opportunity to gather the intelligence on your competition and simultaneously look at your own vulnerabilities.  Sam Mamudi and Keri Geiger explain:
The U.S. Securities and Exchange Commission cited Wedbush Securities Inc. and Liquidnet Holdings Inc. for violations of stock market rules, taking tangible steps a day after Chairman Mary Jo White outlined her plan to improve Wall Street trading. 
Wedbush, which the SEC said is among the five biggest Nasdaq Stock Market traders, failed to vet clients who broke the law as they placed billions of dollars of transactions in the stock market, the regulator said. Two current and former Wedbush executives, Jeffrey Bell and Christina Fillhart, were also targeted in the complaint. 
Liquidnet, one of the biggest independent dark pool operators, agreed to pay a $2 million fine for not living up to client secrecy standards on its private trading platform.
So what?  The Rise of the Machine Traders:
In the beginning was Josh Levine, an idealistic programming genius who dreamed of wresting control of the market from the big exchanges that, again and again, gave the giant institutions an advantage over the little guy. Levine created a computerized trading hub named Island where small traders swapped stocks, and over time his invention morphed into a global electronic stock market that sent trillions in capital through a vast jungle of fiber-optic cables. 
By then, the market that Levine had sought to fix had turned upside down, birthing secretive exchanges called dark pools and a new species of trading machines that could think, and that seemed, ominously, to be slipping the control of their human masters. Dark Pools is the fascinating story of how global markets have been hijacked by trading robots--many so self-directed that humans can't predict what they'll do next.
So how do you mitigate the potential risk of a rogue algorithm? Some have devised a mechanism called a circuit-breaker. In other words, an alarm that something is not normal. Let's slow down until we can understand what is going on here. What are some other ways that we could potentially address the threat or the vulnerability? Was the "Flash Crash" a weak signal of a pending melt down of the complete system?

Or is this just the next natural phase of the future growth curve.  Who will you put your faith in for your next "Trust Decisions"...

Saturday, May 24, 2014

Memorial Day 2014: The Risk of Service is Understood...

It is Memorial Day weekend in the U.S. and on this final Monday of May 2014, we reflect on this past year.

In order to put it all in context, we looked back 12 months to our 2013 blog post here.  It was only a few weeks since a fellow colleague from Team Rubicon had ended his battle at home, after several tours of duty with AFSOC.  Neil had joined the ranks of those fallen heroes who survive deployment tagging and tracking the enemy in the Hindu Kush.  He was one of the 22 that day in early May that could not defeat the legacy of demons, that he fought each night as he fell deep asleep.

Memorial Day 2014, we honor Neil in Section 60 at Arlington Memorial Cemetery and all those other military members who have defended our freedoms for 238 years.  Simultaneously, we do the same for the "Stars" on the wall in Langley, Va for the officers who have done the same.

Whether you are on the front lines or inside the wire at the FOB.  Whether you are in Tampa, FL, Stuttgart, Germany or Arlington, VA.  Whether you are on your beat cruising the streets of a major metro USA city.  Whether you are watching a monitor at IAD, LAX or DFW.  Whether you are deep in analysis of Internet malware metadata or reviewing the latest GEOINT from an UAS.  We are all the same, in that the mission that gets each one of us out of bed each day.  Our countries "Operational Risk Management (ORM)."

The Operational Risk Management mission of the U.S. Homeland is vast and encompasses a spectrum of activity, both passive and kinetic.  Digital and physical.  It requires manpower and resources far beyond the capital that many developed countries of the world could to this day comprehend.  There are only a few places across the globe, where a normal citizen would say that the mission and the capital expenditures are worth every dollar and every drop of blood.

Memorial Day in the United States is exactly this:
Memorial Day is a United States federal holiday which occurs every year on the final Monday of May.[1] Memorial Day is a day of remembering the men and women who died while serving in the United States Armed Forces.[2] Formerly known as Decoration Day, it originated after the American Civil War to commemorate the Union and Confederate soldiers who died in the Civil War. By the 20th century, Memorial Day had been extended to honor all Americans who have died while in the military service[3].
So this weekend as we walk among the headstones, reflect on our colleagues who gave their service and their own lives, we will stand proud.  We understand the risks.  We know why we serve.  In the spotlight or in the shadows.  The tradition and the mission continues...

Sunday, May 04, 2014

Consumer Privacy USA: The Risk of Viceroy Tiger and Keyhole Panda...

There is a flurry of Operational Risk Management (ORM) activity around the DC beltway and across Silicon Valley in order to gain new consumer confidence.  The confidence that their personal metadata and information is being protected with encryption software and that privacy policies are in place to notify users, when their information is requested by the government.  Interesting.

Much of this wasted bandwidth is focused on competitive strategies.  If LinkedIn gets 3 or 4 stars from the EFF "Who Has Got Your Back Report" then our social media company should aspire to do the same. Transparency to the consumer end user on how data is protected and when you are notified of it being lost, leaked, hacked or handed over to law enforcement is the buzz right now.  Why?
Apple, Facebook, others defy authorities, notify users of secret data demands 
By Craig Timberg, Published: May 1 
Major U.S. technology companies have largely ended the practice of quietly complying with investigators’ demands for e-mail records and other online data, saying that users have a right to know in advance when their information is targeted for government seizure.
This increasingly defiant industry stand is giving some of the tens of thousands of Americans whose Internet data gets swept into criminal investigations each year the opportunity to fight in court to prevent disclosures. Prosecutors, however, warn that tech companies may undermine cases by tipping off criminals, giving them time to destroy vital electronic evidence before it can be gathered. 
Fueling the shift is the industry’s eagerness to distance itself from the government after last year’s disclosures about National Security Agency surveillance of online services. Apple, Microsoft, Facebook and Google all are updating their policies to expand routine notification of users about government data seizures, unless specifically gagged by a judge or other legal authority, officials at all four companies said. Yahoo announced similar changes in July. 
As this position becomes uniform across the industry, U.S. tech companies will ignore the instructions stamped on the fronts of subpoenas urging them not to alert subjects about data requests, industry lawyers say. Companies that already routinely notify users have found that investigators often drop data demands to avoid having suspects learn of inquiries.
Enterprise business are now waking up to the reality of investing in more robust Operational Risk Management (ORM) practices within their Enterprise Architecture Framework.  Areas that have been neglected in the architecture for data transport are now finally being updated.  Even the fact that the latest versions of SSL capabilities are being exposed as a result of the "Heartbleed" vulnerability, has finally motivated many to upgrade to TLS 1.2 and add Forward Secrecy.  Even LinkedIn, who gets multiple stars from EFF (and only a "B" from Qualys SSL Labs) doesn't even use TLS 1.2 nor does the average consumer even understand why Forward Secrecy is an important capability or why Google uses it within the popular Gmail service.

The privacy policies and opt-out capabilities the consumer really needs, are from the private sector companies that are currently trading your personal information.  Your browsing history. Your purchases at national retailers.  When was the last time you gave your phone number to a cashier at the register, to earn buy 1 get 1 coupons or a discount at the local gasoline pump?  Where do you think all of this activity-based behavior about you the consumer is being resold?

The marketing of privacy and security will continue to become a product or service differentiator.  The government agencies will continue to follow the law to obtain your information.  The magistrate judges will make sure of this.  The adversaries however, are becoming more productive and will find new exploits to attack your infrastructure in new ways, on vectors that you have not even thought of yet.

Who are some of the adversaries?  A few worth noting:

  • Iran:  Cutting Kitten
  • India:  Viceroy Tiger
  • China:  Comment Panda, Deep Panda, Foxy Panda, Keyhole Panda, Union Panda, Vixen Panda et al

These cyber adversaries are in many cases focused on cyber espionage and the theft of your Intellectual Property or Research and Development.  This leaves hundreds of other capable crime-ware driven organizations across the globe, who are targeting other valuable data to perpetuate their fraudulent activities.  So what have you done at the Board of Directors level and the Executive "C" Suite, to pave the way for more effective collaboration with the G-man?

Collaboration with the FBI, Secret Service, SEC, FTC, OFAC, U.S. Attorney, State Attorney General or even the local county prosecutor is a prudent and wise Operational Risk Management strategy. "Complacency"--this could be one of the greatest vulnerabilities that your share holders and stake holders have ignored.  A proactive organization has established protocols, implemented best practices and tested policies.  They are already in place to work collaboratively with local, state and federal government.  These organizations will ultimately be the marketplace front runners.
“In an era where very sophisticated and determined criminals have proven capable of successfully attacking a wide range of computer networks, we must all increase our level of vigilance. Michaels is committed to working with all appropriate parties to improve the security of payment card transactions for all consumers.”
This is just one more example of what is becoming the new normal.  The Operational Risk Management (ORM) professionals in your organization are ready and willing to support corporate executives and the Board of Directors new found enlightenment.  Your new government partners will even share information with you, on the latest modus operandi of "Keyhole Panda"...

Saturday, March 01, 2014

RSA Conference 2014: The Aftermath and the Consequences...

The 2014 RSA Conference USA is complete and yet what have we learned?  Operational Risk Management (ORM) is still top of mind from the "Board Room" to the back office.  The mitigation strategies are permeating the 3rd Party supply chain, as management realizes that operational risks really do exist with partners and suppliers.  By now the RSA attendees are reviewing their notes, connecting with people on LinkedIn and sorting the stack of business cards on their desk.  Now what.
  • Have some of the largest retailers been the victims of massive data breach hacks?  Yes.  Have those attendees of the RSA Conference who downloaded the mobile app been exposed to a potential data leak of their information.  Yes.
  • Meanwhile, Operational Risks exist far beyond Moscone and San Francisco.  Have financial institutions been fined by government regulators over alleged violations of the sale of mortgage securities, that lead to the 2008 financial crash?  Yes.  
  • Have the age old competitive intelligence tactics evolved into full blown "Industrial Espionage" funded and supported by nation states?  Yes.
  • Has the polar vortex created a vast economic risk for millions of businesses due to adverse weather? Yes.
And the Operational Risks to your organization will continue, that is for certain.  How after a week of RSA can you return to your enterprise and know where to begin?  What to change.  What new initiative to begin.  What new vulnerability to remediate.  Don't worry, the list will not be getting any shorter.  The priorities however may be changing.

So maybe it is time for a new "Consequence Assessment."  Here are the key variables for the rows of your matrix:
  1. Loss of life:  Likely fatality count.
  2. Economic damage:  Estimated costs of the attack or hazard.
  3. Psychological impact:  Considerations of change in population behavior toward social functions.
Now, the consequence levels become your columns of the matrix:
  • 0 - None or Negligible
  • 1 - Minor
  • 2 - Moderate
  • 3 - Significant
  • 4 - Catastrophic or Severe
In order to make the consequence assessment relevant and applicable to your business size, industry sector and geographic location, you now need to define each of the cells of the matrix.  So as an example, if we go to the matrix cell of Economic Damage / Moderate (2), what is your definition?  In the range of $1 billion to $10 billion.

If you are JPMorgan Chase then this may be the case for a consequence of legal liabilities, due to adverse litigation by the U.S. government in the Madoff case:
JPMorgan Chase has been fined more than $2 billion for violations of the Bank Secrecy Act tied to failure to report suspicious activity related to Bernie Madoff's decades-long, multi-billion dollar Ponzi scheme. Madoff was sentenced in 2009 to 150 years in prison for his deception. 
The fines against Chase were the result of three settlements. A settlement with the U.S. Attorney's Office for the Southern District of New York included a $1.7 billion penalty; a separate settlement with the Office of the Comptroller of the Currency included a $350 million penalty. Additionally, the Treasury Department's Financial Crimes Enforcement Network fined Chase $461 million for BSA-related violations. But FinCEN determined that its fine was satisfied by Chase's payment to the U.S. Attorney of New York.
If you are a mid-level business enterprise in the software industry that develops an "App" for consumers to file their income taxes online, then the metrics will be different for a moderate consequence of "Economic Damage." Your matrix will be entirely different and fine tuned to what is relevant in your industry sector.

The Loss of Life category will be an interesting exercise.  None or Negligible will be zero fatalities. Yet how do you define the difference between minor (1) and moderate (2).

The Psychological Impact category will span:

0 - None or Negligible = No major change in population behavior; no effects on social functioning
to
4 - Catastrophic or Severe = Loss of belief in government and institutions; widespread disregard for official instructions; widespread looting and civil unrest

Once you have designed your particular matrix for your size and type of business, the real work begins. You must now begin developing the "Use Cases."  What are the scenarios that you will apply to the exercise that will take place next with the effected stakeholders?

In a generic fashion, you will design specific and customized scenarios that address the major business revenue components of your particular enterprise.  You are imagining an attack or hazard outcome, that impacts that component of your business.  Such as these typical cases:
  • Earthquake destroys data centers
  • Tsunami overcomes nuclear reactors
  • Data hack exposes millions of customers PII
  • Infectious disease outbreak across work force
  • Government prosecutes for violations of regulatory laws
  • Employee sues company for management harassment
  • New Customer Order Management system launch encounters substantial bugs/failures
After you have cleaned off your desk from a week away at RSA, the work really begins.  Start your new "Consequence Assessment" soon.  Gather senior executives for an off-site for two days to review the new scenarios you have designed.  Get their independent feedback and perception of the variables of your matrix.  Ask your Board of Directors for the resources and budgets to address the outcomes and insights from the exercise.
“ Man must be arched and buttressed from within, else the temple will crumble to dust. ”
— Marcus Aurelius Antoninius

Saturday, February 22, 2014

Fraud Trends: Hedging Transnational Organized Crime...

The facts and the results of forensic investigations across the cyber domain are telling a significant story.  The question remains, will CxO's take the time to digest and think about what is happening within their Enterprise Risk ecosystem?  Operational Risk Management (ORM) has four key dimensions:

  • People
  • Processes
  • Systems
  • External Events

Each of these dimensions must be looked upon in a holistic and interdependent manner, realizing that they are all indeed interconnected.  One may impact another or managing risk in some but not others could bring the entire enterprise to it's knees.  This is understood.

You are no doubt utilizing a myriad of strategies to deter, detect, defend and document the Operational Risks within your specific industry and associated with the adversaries and regulations pertinent to your business.  So why is this still the state-of-play?
Companies are beginning to change how they think about cybersecurity – viewing it as a business issue, not just an IT issue. Forty-four percent of U.S. organizations that experienced fraud in the past 24 months suffered from cybercrime; and 44 percent of all U.S. respondents indicated they thought it was likely their organization would suffer from cybercrime within the next 24 months. 
Seventy-one percent of U.S. respondents indicated their perception of the risks of cybercrime increased over the past 24 months, rising 10 percent from 2011. U.S. respondents' perception of the risks of cybercrime exceeded the global average by 23 percent. Despite having more to lose, U.S. respondents were generally less aware of the cost of cybercrime: 42 percent of U.S. respondents were unaware of cybercrime's cost to their organizations, compared to 33 percent of global respondents.

Didier Lavion, PwC principal and lead author of the U.S. report, said, "U.S. corporations need to better leverage and implement the computational and analytical power of cybersecurity technologies to help combat the increasing global presence of cybercrime."  --Source:  PwC's Global Economic Crime Survey 2014

The reason that the state-of-play remains in turmoil, is the inverse of what the survey is reporting. 29% of U.S. respondents have no perception that the risks of cybercrime has increased over the past 24 months. The 29% who do not perceive this, must be in an industry group that is either not connected to the Internet, does not use mobile devices or are using paper and pencils to run their business.
So for the other 71%, the perception of the risks of cybercrime has increased.  Again, what are the business details of these respondents?  What would be interesting is to ask the question:  How many U.S. citizens have been issued a new credit or debit card last year due to fraudulent charges?  Perhaps the 29% are the unbanked population of the U.S. who are not issued cards because they do not participate in the formal banking system?  Unlikely.

Cybercrime analysis needs to go deeper.  As an example, it would be interesting to discover what percent of cyber fraud victims in 2013 currently run a Microsoft-based operating system on their computer? No doubt the highest, due to the vast installed base of Microsoft-based PC's over the years.

Executive Management of companies with over 1000 employees who do not perceive the risk of cybercrime on the rise, may have other more pressing issues.  Labor, raw materials, weather, or other factors that may be impacting their business.  It makes some sense.

Over the next decade, the tide will turn on the motivation to pursue petty cybercrime and fraud.  Not because the laws and enforcement are more effective.  Not necessarily because the fraud opportunity becomes too difficult because of the effectiveness of new technology. Not even because the Microsoft Operating System installed base, dwindles to a minority percentage.  Why?

It is because the best cyber Transnational Organized Crime (TOC) organizations will become allies with nation states or even terrorist non-state actors.  They will be paid much more handsomely and they may not even have to disclose their true identities.  The stakes and the fortunes to be made in TOC are rising.  The cyber domain is now a race for superiority.  The best of these skills and knowledge will come from the "dark side" to start, and at a high premium.  So what are you to do, if you are the CxO of a top Global 500 organization?

Pray longer.  Allocate a treasure chest to invest in your long digital war ahead.  Hedge the risk...
New threat actor: Spanish-speaking attackers targeting government institutions, energy, oil & gas companies and other high-profile victims via cross-platform malware toolkit 
Today Kaspersky Lab’s security research team announced the discovery of “The Mask” (aka Careto), an advanced Spanish-language speaking threat actor that has been involved in global cyber-espionage operations since at least 2007. What makes The Mask special is the complexity of the toolset used by the attackers. This includes an extremely sophisticated malware, a rootkit, a bootkit, Mac OS X and Linux versions and possibly versions for Android and iOS (iPad/iPhone). 
The primary targets are government institutions, diplomatic offices and embassies, energy, oil and gas companies, research organizations and activists. Victims of this targeted attack have been found in 31 countries around the world – from the Middle East and Europe to Africa and the Americas. The main objective of the attackers is to gather sensitive data from the infected systems. Several reasons make us believe this could be a nation-state sponsored campaign.

Saturday, January 25, 2014

Evidence: True or False On Privacy Apps...

What is a Chief Legal Counsel to do these days about new messenger focused Apps such as Wickr, Silent Circle, or now even Confide?  Operational Risk Management (ORM) is a constant chess match.

The ranks of the deal makers and the Executive Suite who are more concerned about so called eDiscovery and evidence coming back to haunt them, are using these new found "Privacy Apps."  Buyer beware and the CxO's should be on the look out for this new "Operational Risk" trend within the enterprise.

Regardless of whether employees are potentially circumventing corporate communication networks, or using their own personal devices, these new apps are indeed collecting potential discoverable data:
Confide, Inc. (“Confide”) is pleased to offer you the ability to send and receive encrypted messages (“Messages”) that will self-destruct after a pre-set period of time (the “Service”). We make the Service available to you through a variety of Internet-enabled devices, including smart phones and tablets (collectively, “Devices”). Portions of the Service may also be available to you through our website at getconfide.com (the “Website”).

We provide our Service to you subject to the following Terms of Use, which may be updated by us from time to time without notice to you. By accessing and using the Website or the Service, you acknowledge that you have read, understood, and agree to be legally bound by the terms and conditions of these Terms of Use and the terms and conditions of our Privacy Policy, which is hereby incorporated by reference (collectively, this “Agreement”). If you do not agree to any of these terms, then please do not access or use the Website or the Service.
And this little item in the "Privacy Policy" caught our eye:
5. Geolocational Information
Certain features and functionalities of the Service may be based on your location. In order to provide these features and functionalities, we may – with your consent – collect geolocational information from your mobile Device or wireless carrier and/or certain third-party service providers. Such information is collectively called the “Geolocational Information.” Collection of such Geolocational Information occurs only when the Service is running on your mobile Device.
So since the message is not stored on the corporate server, and it disappears from the App after it is read on the device, does that mean digital forensics on the device are useless?  The answer is, "That depends."

It depends on what you are trying to collect.  It will depend on many aspects of the Operating System (iOS/Android) and whether there is a "forensic wipe" capability for use on the device.  There are dozens of dependencies here. However, is that really the issue at hand?

Off the record communications take place on a daily basis, from "Party A" to "Party B".  Typically this is done verbally.  Now there are a myriad of new phone Apps, that are trying to mimic this same practice using encryption and self-destruct modes.  These provide secure and private communications from digital device-to-device.  What this really is about, is called evidence.
Evidence
Law. data presented to a court or jury in proof of the facts in issue and which may include the testimony of witnesses, records, documents, or objects.
It may be time for the CxO to educate the enterprise about the use of these new Apps as it pertains to corporate "Off-The-Record" conversations.  The formal or informal method for doing so should include:

1.  A review of the risk of using untested, unauthorized apps for corporate communications.

2.  A dialogue on what is evidence.

3.  A set of "Use Cases" that will illustrate to the potential end users why these apps do not circumvent eDiscovery.

Some may argue that when a subpoena is presented, that there is nothing to hand over.  Are you sure about that?
The cautionary tale that many reference is the case of Hushmail, an encrypted mail service that used to claim that "not even a Hushmail employee with access to our servers can read your encrypted email, since each message is uniquely encoded before it leaves your computer" — words that echo Wickr's own proclamations. Sell tells Mashable that Wickr's "architecture eliminates backdoors; if someone was to come to us with a subpoena, we have nothing to give them." 
As it turned out, Hushmail wasn't so impenetrable. In 2007 it was revealed that, actually, Hushmail coud eavesdrop on its users communications when presented with a court order.