Tuesday, February 27, 2007

Whistleblower: The FCPA & Voluntary Disclosure...

Operational Risks involving people are happening everyday in your organization. It may be going on for a day, a week and sometimes years. But at some point someone has to tell someone before it gets violent or the company loses any more corporate assets.

What is the anonymous phone number at your organization to phone in the "Whistleblower" information? Who is responsible for the follow through on investigations? How can you insure against employee confidentiality and any possible reprisals?

In most cases the call is by phone and not by some other method. It is rarely a hoax and the hotline is keeping tabs on the subordinate / management battle over half of the time.
What's the best way for an employee to blow the whistle on fraud or related infractions? The most popular way seems to be via hotlines or similar reporting tools. According to a joint report from the CSO Executive Council, an organization of corporate and government security executives, and The Network (a hotline provider), almost two-thirds of the nearly 200,000 reports it studied were made via hotlines without first alerting anyone in management.

Few of those alerts prove to be false alarms. The study, which tracked incidents at 500 organizations over the past four years, found that 65 percent of the reports were serious enough to warrant investigation, while 46 percent led to some type of action being taken. Corruption and fraud accounted for 10 percent of the incidents, well behind personnel-management situations (51 percent). Company and professional-code violations accounted for 16 percent and employment-law violations 11 percent.

Compliance with an effective Whistleblower program is just the beginning of developing a culture that has a zero tolerance for the kinds of risks that make an HR manager or General Counsel have constant nightmares. This is certainly the case on the front lines where business is being transacted and deals are being cut on a global basis. Is there sufficient due diligence to determine whether any party in the transaction is not in violation of the Foreign Corrupt Practices Act (FCPA)?
By definition, FCPA crimes generally occur thousands of miles outside of the United States. Why would counsel advise a corporate client to bring such activities to the attention of the SEC or the DOJ? Is it necessary to self-report when, as a good corporate citizen, the client has investigated thoroughly, corrected the problem, and taken substantive remedial measures including firing the wrongdoers and correcting the financials?

Having the possibility of a deferred prosecution agreement is the strategy utilized more often than you would think these days. In any case, SOX requires a Whistleblower program, and the next phone call may have to do with that last big deal that closed last quarter. Why Voluntary Disclosure?
The DOJ's "Principles of Federal Prosecution of Business Organizations," commonly known as the "Thompson memorandum" and published in 2003 on the heels of SOX, also played a significant role in the surge of voluntary disclosures. The Thompson memorandum placed an "increased emphasis" on a company's cooperation with the government when considering whether to prosecute. Voluntary disclosures were an important part of that cooperation.

At the end of the day all of the auditing will never catch the people that know the system. That is why the anonymous phone number can make all the difference in mitigation of significant risks to your enterprise.

Friday, February 23, 2007

The Board Room: IT Strategy Focus...

A new survey or 400 directors published in the March/April issue of Corporate Board Member Magazine by Deloitte Consulting has some interesting insights. In regard to the use of Information Technology as important or very important to insure success in various areas of the business:

  • 69% say implementing the right IT strategy is "very important" in compliance.
  • 66% in learning about and retaining customers.
  • 57% in managing risk.
  • 50% in competitive positioning.

So how come only 14% say they are "completely and actively involved" in IT strategy?
Boards of Director's are in the dark and this won't be changing very dramatically unless you are the result of a significant incident such as T.J. Maxx:

According to The Boston Globe today, TJX Companies has stated that a data breach it revealed last month may have occurred a year earlier than investigators initially thought. The company operates the retail outlets T.J. Maxx, Marshalls and HomeGoods (2,500 stores in the United States), so the earlier date of the hacking may mean millions more customers were exposed. The company declined to give numbers, however.

TJX discovered the breach in December 2006, and it made news on Jan. 18, 2007. At that time the company reported that hackers may have made off with credit and debit information from transactions in the United States, Canada and Puerto Rico from some months in 2003 as well as transactions between May and December 2006.

Yesterday, according to the Globe, TJX said a systems review revealed that intrusions had occurred as early as July 2005, not May 2006.

This trickle of data breaches spread over time led some experts to judge the corporation’s computer systems outdated, weak and not up to card-company security standards.

Information Technology strategy and the amount of effort or time a Board of Directors spends on it is most likely determined by the CEO. If they trust the Chief Information Officer and what they are doing, then they leave it alone. This is becoming an area under greater scrutiny by Directors as these kinds of incidents occur on a more regular basis in the news. However, just because it's not in the news, doesn't mean that it's not happening today at your institution.

There is another war brewing between the banks, retailers and the credit card issuers about who is the guilty one. At the end of the day, consumers will lose. Even pressure by VISA and others to make sure merchants are in compliance with the laws around encrypting data and the storage of the data may not be enough. The retailers have already started their lobbying efforts:

As information security has become a major focus of consumers, governments and businesses alike, the care with which companies protect credit card data has become increasingly important. In many instances, the Achilles heel of data security is a lack of application controls.

Encryption alone is not the answer. With most of the encryption techniques, the same key is used to lock and unlock the data. The problem is: How do you secure these keys in the POS application? Once these keys are compromised, the "secured" data is no longer secure.

The best way to secure data is to not store data. A technology knows as “tokenization” offers a greater level of security by substituting a unique identifier (a token) for a card number, so the card data is never in the system. This token is a random unique value and has no way to be deciphered to gain knowledge of the associated card information. With tokenization, the merchant swipes the card data and sends the information through a gateway to a processor and receives back an approval. But instead of sending the card data itself back to the merchant and the POS system, it is converted to a token: a globally unique, randomized representation of credit card data that is 16 characters long. Only the token is stored in the system.

The token spans the lifetime of the transaction so it provides full support for tips, tabs and incremental authorizations. The merchant does not need the card number or data past the initial request, so storing this information is unnecessary. The entire liability to protect the card data is now on the gateway, where it should be. The primary objective of tokenization is to enable businesses to operate normally while not storing the sensitive data that is the target of data thieves. This technology also eases the burden of compliance for merchants. If no data is stored on site, the merchant has a significantly reduced PCI compliance burden.

The Board of Directors who discuss IT strategy on a regular basis perform better financially and those who don't may be paying the price.

Sunday, February 18, 2007

Economic Intelligence: Wake-up Call...

Chris Cooper plays a traitor in the movie based on the true story of Robert Hanssen. "Breach" is a wake up call for the United States to continue its counterintelligence initiatives with vigor. However, this story is written not from the perspective of Hanssen, but that of another FBI employee who assisted in his capture and prosecution.

Based on the true story, FBI upstart Eric O'Neill enters into an operational risk power game with his boss, Robert Hanssen, an agent who was ultimately convicted of selling secrets to the Soviet Union. Eric now lives in Washington, DC and is an attorney, he never became an FBI agent. His role played by Ryan Phillippe, shows the audience how even Eric was skeptical that someone like Hanssen could be a traitor.

Critical to the agency’s ability to arrest and convict Hanssen was the placement of 26-year-old special surveillance operative Eric O’Neill in Hanssen’s office. Working directly under Hanssen, O’Neill was able to provide the team of investigators with information needed to take down one of the worst spies in the history of the United States.

Shortly after being intimately involved in the Hanssen investigation, O’Neill left the FBI to study law. O’Neill also took time to work on a book based on his experiences, which ultimately led to Breach, a film about his involvement in the Hanssen case.

Counterintelligence is the number 2 priority behind Counterterrorism at the FBI.

The Cold War is not over, it has merely moved into a new arena: the global marketplace. The FBI estimates that every year billions of U.S. dollars are lost to foreign competitors who deliberately target economic intelligence in flourishing U.S. industries and technologies, and who cull intelligence out of shelved technologies by exploiting open source and classified information known as trade secrets. Foreign competitors who criminally seek economic intelligence generally operate in three ways to create their spy networks:

1. They aggressively target and recruit susceptible people (often from the same national background) working for U.S. companies and research institutions;

2. They recruit people to locate economic intelligence through operations like bribery, discreet theft, dumpster diving (in search of discarded trade secrets), and wiretapping; and,

3. They establish seemingly innocent business relationships between foreign companies and U.S. industries to gather economic intelligence including classified information.

In an effort to safeguard our nation's economic secrets, the Economic Espionage Act (EEA) was signed into law on October 11, 1996.

How to Protect Your Business from Espionage: 6 steps
1. Recognize there is a real threat.
2. Identify and valuate trade secrets.
3. Implement a definable plan for safeguarding trade secrets.
4. Secure physical trade secrets and limit access to trade secrets.
5. Confine intellectual knowledge.
6. Provide ongoing security training to employees.

Wednesday, February 14, 2007

OPS Risk: The Bishop vs. A Stolen Laptop...

Now that the news is in the mainstream media about the recent threats to financial institutions, one can only wonder how soon this case will be solved. The Bishop is being compared to the "Unabomber". Profilers believe that he is white male, a loner with dangerous beliefs that he can manipulate stocks.

The U.S. Postal Inspection Service is alerting financial firms of potential danger from a would-be letter bomber after companies in Kansas City and Denver were targeted with explosive devices and threatening notes, an agency spokeswoman said on Monday.

Working with the Securities and Exchange Commission, the Postal Inspection service is trying to obtain contact information for thousands of financial companies to warn them of the threats, said spokeswoman Wanda Shipp.

"The events may be linked, and the recipients were probably not selected at random," the postal advisory reads.

The action comes after Stratfor, a global intelligence firm, last week issued a warning that pipe bombs addressed to American Century Investment Management Inc. in Kansas City and Janus Capital Group in Denver appeared linked to someone known as "the Bishop," who has threatened at least six financial firms since 2005.

The Chief Security Officer's at these institutions have a primary duty of care to insure the safety of employees whenever threats of this magnitude take place. There is no "Radar" that can alert you to when the next incident will occur. This is why many institutions have taken a new "Operational Risk" perspective when it comes to the hazards and events that may impact the business.

A true Operational Risk perspective has it's roots in understanding exposure to risk and the likelihood of an event occuring. Yet how could one ever predict the rise of another so called Unabomber? The fact is that you don't. This is why you must have an "All Hazards" worldview operating within the culture of your organization. The threat could be an innocent looking priorty mail package with a pipe bomb or a thick brown envelope containing the latest class action law suit. You have to be operating in a complete state of preparedness for whatever the next incident brings.

What ORM Is Not . . .

  • About avoiding risk
  • A safety only program
  • Limited to complex-high risk evolutions
  • A program -- but a process
  • Only for on-duty
  • Just for your boss
  • Just a planning tool
  • Automatic
  • Static
  • Difficult
  • Someone else’s job
  • A well kept secret
  • A fail-safe process
  • A bunch of checklists
  • Just a bullet in a briefing guide
  • “TQL”
  • Going away
While this incident entering the mail room has slowed down a few institutions, there is another battle going on in a different part of each business that is a whole different type of risk. This has to do with the frequency and the pervasive spectrum of new risks across the enterprise:

The U.K.’s financial services regulator has levied a heavy fine against the nation’s largest building society over a stolen laptop containing confidential customer information.

The Financial Services Authority (FSA) fined Nationwide Building Society 980,000 (US$1.9 million [m]) for "failing to have effective systems and controls to manage its information security risks," the regulator said.

Nationwide, which has about 11 million customers, did not realize the laptop contained customer information and waited three weeks before starting an investigation, the FSA said.

The speed of change in the connected economy...

Thursday, February 08, 2007

eDiscovery: The New Digital Age...

What does Operational Risk have to do with legal liability? Digital Forensics is a growing discipline across the landscape of corporate, legal and academic institutions. The volumes of electronic information involved in new litigation and investigations calls for expert practitioners and witnesses to make sure that evidence is uncovered, preserved and presented without spoilation. The era of eDiscovery is upon us.

Analyzing the data and making sense of all of it by the investigator is getting easier yet we have a long way to go. This area of event reconstruction or forensic timeline editor is now becoming a reality:

The area of event reconstruction in computer forensics deals with analyzing and evaluating data obtained from a system and use it to determine what happened. The data recovery process is a well-covered area within computer forensics, but little work has been done on how to actually analyze and evaluate the data. Only very crude tools, such as mactimes or individual log analyzers, exist. A comprehensive event reconstruction on a system that takes into account data from various sources, such as file MAC times, system logs, firewall logs, and application data, is mostly done manually by the investigator. With storage capacities growing rapidly and systems permanently being connected to global networks more and more, it is not uncommon that the number of events recorded by a system easily goes into the hundreds of thousands.

This remains only a small facet of the real problem when it comes to finding what is relevant for litigation. In the context of legal discovery, the days of making copies and filing them in boxes is being dwarfed by the newest Federal Rules of Civil Procedure (FRCP) and the preservation of metadata. The best of breed answers to the digital discovery revolution can be found at Stratify, an emerging player in the automated eDiscovery spectrum of software solutions.

Optimize Litigation Readiness

General counsel together with their outside counsel need an effective means to manage documents and emails from key custodians and/or on specific topics in advance of litigation or regulatory discovery requests. When they receive a discovery request they need to be able to easily and quickly select sets of documents for review and analysis in their eDiscovery application.

The Stratify Legal Discovery™ service was designed to fulfill these requirements as the most easy-to-use, efficient eDiscovery solution available to law firms and corporate counsel.

Electronic Document Retention and Production has been a subject of great importance for many years inside law firms and the legal departments of the Fortune 500. The Sedona Conference has forged the way in providing guideance and some best practices to consider when embarking on this challenging mission. The question is, who is looking out for the Russell 2000 small cap company or mid-sized enterprise business? A single person may even represent the legal team, as the sole General Counsel.

Operational Risk includes legal risk, which is the risk of loss resulting from failure to comply with laws as well as prudent ethical standards and contractual obligations. It also includes exposure to litigation from all aspects of an institutions activities.

It's just a matter of time if you are in a highly regulated business sector that the time will come for your day in court. Make sure you are ready long before the phone rings or the papers are served. What is the source of the personal identifiable information that has caused this wave of consumer based fraud?

The FTC has released it's study on the methods, origins, victims and costs today of ID Theft. The odds are that the data breach may not be what puts you on the hot seat.

The US futures regulator, the Commodity Futures Trading Commission, has filed a complaint in the District Court for the Northern District of Georgia against New York-based hedge fund manager Cornerstone Capital Management and its chief executive, Joseph Profit of Atlanta.

The complaint alleges that Cornerstone and Profit violated the anti-fraud provisions of the Commodity Exchange Act and a CFTC regulation. On January 31, US district judge Richard Story issued a restraining order freezing the defendants' assets and prohibiting them from destroying documents or denying CFTC staff access to books and records.

Tuesday, February 06, 2007

Self-Regulation: NERC Get's Proactive...

Now that the power sector and electrical utilities are going public with their acceptance of converged standards, other sectors may not be far behind. Some of the regulated critical infrastructure sectors have been working towards an industry wide set of controls that must be implemented and audited. Who will be next?

The North American Electric Reliability Council's new cybersecurity standards for critical infrastructure protection have eight categories, which apply utility risk management analyses to networked systems. A thumbnail description of the main areas:

  • Critical cyberassets
  • Security Management Controls
  • Personnel and training
  • Electronic security
  • Physical security
  • Systems Security Management
  • Incident Reporting and Response Planning
  • Recovery plan
You can bet that the drafting team has pulled their language from many of the standards that have already been in practice for years. In fact, most of the launch point for this effort came from work done soon after 9/11. How soon other industry sectors decide to adopt this framework will likely be decided by the lobby shops. Politics aside, the electric utility sector has moved into a phase of self-regulation and for good reason.

The huge blackout of Aug. 14, 2003, in which a software glitch at a single electrical provider in Ohio cascaded into an event in which 50 million people in North America lost power, underscored the importance of the reliability standards discussion. But Miserendino says that the group's biggest motivator was the threat that FERC might come in and do the regulating for it. In part, he says, that's because the 2005 Energy Act made FERC responsible for electrical transmission reliability and gave the federal agency the ability to fine utilities for noncompliance.

We can only hope that other Critical Infrastructure sectors take the same initiative sooner than later. As private enterprises, you can do it your way now or face the governments perspective later.

Thursday, February 01, 2007

Future Jihad: Financing Systemic Ideology...

One only has to listen to a few stories from experts in Counterterrorism to realize that vigilance is still the mantra. Yesterday the facts and observations from Walid Phares made us ever so more aware and even more focused on the mission. Funding of the war of ideas.

His point is clear that the funding of education and systemic transfer of ideology across the globe is why we are still so vulnerable. "The class room. The news room. To the War room."
For the United States, winning the War on Terror depends on two battlefields. The first is overseas, where Washington must confront jihadi forces and help allies to win their own struggles with terrorism. This will require the United States to support democratic change abroad, both as a counterweight to jihadist lobbies and as a means of assisting Arab and Muslim democrats to win the conflict within their own societies.

The second, however, is closer to home. Homeland security planners must be thinking seriously about a duo of unsettling questions. First, are jihadists already in possession of unconventional weapons on American soil, and how can the U.S. government deter them? This crucial issue tops all other challenges, for a terrorist nuclear strike on the U.S. has the potential to transform international relations as we know them. Second, how deeply have jihadist elements infiltrated the U.S. government and federal agencies, including the Federal Bureau of Investigation, the Department of Homeland Security, the Department of Defense, and various military commands, either through sympathizers or via actual operatives?

In a recent Economist Intelligence Unit survey on Operational Risk Management the question is asked:

Which of the following types of threats receive the most attention in your organisation's consideration of Operational Risk?

  • 42% - Loss of Data
  • 36% - Systems Failure
  • 28% - Supply Chain Disruption
  • 27% - Worm or Other Malicious code attack
Unplanned downtime of systems was tied with malicious code, next was human error at 26%, human malfeasance such as theft or fraud at 20% followed by a tie for:
  • 15% - Terrorism
  • 15% - Application Failure
Why is terrorism tied for 8th on this list? Maybe it is because institutions have more confidence in our Homeland Security and the FBI than they do in their own IT department. Or could it be the frequency of the threat that puts these items so high or low on the list of concerns. One thing is certain, the financing of "Future Jihad" is not going away.

In fact, the funding mechanisms are morphing and adapting as new Anti-Money Laundering initiatives and Regulator oversight creates even more difficult avenues for terrorist financing to occur. The private sector still remains the Deputy Sheriff as new transactions take place outside the traditional banking controls of Citi, B of A and HSBC. Hedge funds, insurance companies and other broker / dealers still provide the weak link in the chain for tracking the movement of zeros and ones across a global financial grid.

This multi-dimensional problem is not something to ignore. When you really think about Terrorism, what is your definition? What is a terrorist?

The day will come when you finally realize that a terrorist is and could be increasingly responsible for the top 4 items on the EIU list. It's all a matter of your own worldview.

Tuesday, January 30, 2007

Shareholder Value: Through Integrated Risk Management...

Supply chain risk management is getting more attention these days. As institutions get their own house in order with operational risk losses they are moving outside and auditing their suppliers. The complexity of the supply chain is increasing as organizations become leaner. A recent AMR Research Study results reveal that supplier failure and continuity of supply is the number one risk factor for 28% of firms.

The Enron scandal and the emergence of Sarbanes-Oxley compliance, the 9/11 terrorist attack, SARS and avian flu threats, the Asian tsunami and Hurricanes Katrina and Rita, and high-profile business failures have forced companies to evaluate how well-prepared their organizations are to handle catastrophe and unplanned events. For other firms, strategic and execution risks are front of mind, such as hitting a launch window for a short lifecycle product.

Additional survey results include:

  • 33% of firms say they have dedicated budget line items for supply chain risk management activities.
  • 54% of firms plan to increase their budgets for risk management over the next 12 months. Of those firms, the average spending increase will be 17% year over year.
  • The top areas of application spending to support supply chain risk management are sales and operations planning, inventory optimization, business intelligence and supply chain analytics, and supply chain visibility and event management applications.
And while much of these manufacturing and distribution organizations are focused on the supply chain, in the financial sector, two international laws will affect how organizations retain, recover and report on data. BASEL II, which took effect Jan. 1, requires the worldwide banking community to uniformly capture data to allow operational risk factors to be identified and analyzed. This is just the beginning of additional financial sector scrutiny as the hedge funds exposure becomes a regulators new target zone.

Concern that booming lending to hedge funds may have led to a relaxation in credit standards has prompted US and European regulators to start the first joint investigation into whether banks and brokers are managing such risks appropriately.

The move is a sign that regulators are stepping up transatlantic co-ordination. It comes after a call by Angela Merkel, the German chancellor, for closer US-European Union co-ordination on financial regulation.

Officials from the Securities and Exchange Commission, the UK’s Financial Services Authority, the New York Federal Reserve and other European regulators met last month to discuss credit issues, according to David Cliffe, an FSA spokesman.

They want to know if the collateral required of hedge funds from their lenders is enough to cover losses, and whether margins are set at appropriate levels to help avoid systemic risk in the event of trading losses.

Operational Risks span the enterprise from the front office to the back office. From the servers room to the trading room. It's no wonder that Boards of Directors and corporate management have now realized that Enterprise Risk Management is the name of the game:

"The creation of shareholder value through the integrated management of risk."

New rules on the evidentiary discovery of clients' electronically stored information, international banking rules and more detailed interpretations of the Health Insurance Portability and Accounting Act will spur customers to put mechanisms in place to more quickly discover and retrieve archived data.

2007 is going to be another year of growth and opportunity. How you manage risk is going to be a deciding factor.

Tuesday, January 23, 2007

ORM: Automation Revolution...

The revolution has begun. There are many organizations out there evaluating the now more mature Operational Risk platforms for their institutions. Just as the dawn of Enterprise Resource Management (ERM) such as Peoplesoft, SAP and others; there will be a fight for maket share and end users will look to their trusted advisors for expert resources. How do you know what application is right for your organization?

The question remains, are you ready? Is your department and staff up to speed on what this means for the process changes necessary in your enterprise for an ORM application to succeed?

OpenPages ORM automates the process of identifying, measuring and monitoring operational risk, integrating all risk data – risk and control self assessments, loss events and key risk indicators – in a single solution. OpenPages ORM combines powerful document and process management with a monitoring and decision support system that enables organizations to analyze, manage and mitigate risk in a simple and efficient manner.

Risk self-assessment capabilities enable organizations to document and evaluate their risk frameworks, including processes, risks, events, key risk indicators and controls. Executive-level dashboard and reports provide visibility into key risk metrics and policy compliance, while business process automation capabilities provide for real-time event escalation; automated risk processes, such as loss event root-cause analysis; and, streamlined remediation of issues and action items.

With loss event tracking, risk managers can track loss incidents and near misses, recording amounts, determine root causes and ownership. OpenPages ORM provides statistical and trend analysis capabilities and enables end-users to track remedies and action plans. Key risk indicators provide capabilities for tracking risk metrics and thresholds, with automated notification when thresholds are breached. OpenPages ORM provides facilities for both manual and automatic data inputs from internal and external data sources.

With OpenPages ORM, organizations can embed operational risk management and governance into the corporate culture, making procedures more effective and efficient while providing management with peace-of-mind that the corporate brand is protected.

How do you make a decision on OpenPages, SunGard or SAS? Like the implemention of ERM platforms you end up with new challenges, both technical and human oriented. Making a choice requires at some point a consensus of the end user, the departments impacted by the decision and the costs of customization or configuration. The total project will also require:

  • Choosing the correct technology solutions with your specific business challenges.
  • Rapidly integrating new technology with the remainder of your IT infrastructure.
  • Effectively fine-tuning business processes to address your organization.
  • Continuously re-evaluating the deployment to ensure maximum ROI.
As with most large IT projects it's important to have Program Management Office (PMO) functions up and running prior to making a final purchase. And if you are a true Operational Risk Management professional, you have already performed your analysis of the threats and hazards to the successful implementation, training and launch of your new ORM system.

Friday, January 19, 2007

Investigations: Rules of Engagement...

Sarah Scalet at CSO has asked the question: What are the 10 commandments of responsible investigations?

The topic is a result of the HP scandal. What are the prudent rules of engagement to answer the original question? Who is leaking information from this Board Room to the media?

Sarah says, "I did a lot of thinking and had a lot of conversations about how to run corporate investigations in a responsible way.

By responsible, I mean not only done in a legal and ethical way (although those things, too), but also done in an effective and appropriate way. There are a lot of gray areas in investigations, and there are complicated and expensive ends to which you can take things. If we've learned anything from the mainstream media coverage of the HP debacle, it's the importance of making sure that an investigation meets the suspected crime."

In any investigation of fact finding and to find the truth there will be data leaving a trail of answers, the key is to make sure you have the correct hypothesis. If you haven't first created a sound and cohesive test plan, the results will not answer the question, hunch or theory. And that is where investigations go down a path of emotional intent as opposed to a process of factual discovery. The data collection didn't answer the emotional question so go find some information that does. This is where the real flaw lies in most investigations.

Let's take a quick quiz to make a point:

Business crime losses are typically the result of:

a. Non-violent acts committed by insiders.
b. Non-violent acts committed by outsiders.
c. Violent acts committed by insiders.
d. Violent acts committed by outsiders.

If you answered "B" then you are incorrect. The answer is "A". Insiders are the first place you begin to look when accounts are missing money, the system has been hacked or vital corporate information has fallen into the wrong hands.

From the behavioral sciences perspective it is axiomatic
that a protection program will not succeed unless it:

a. Meets the personal needs of the vast majority of the workforce.
b. Cultivates the willing cooperation of those affected by it.
c. Incorporates sufficient disciplinary sanctions to convince the workforce to follow
prescribed procedures.
d. Provides for termination of employment in the case of repeated violations of mandatory procedures.

If you answered "C" then you are wrong. The answer is "B". The willing work force, employees and society in general follow and obey the laws that they can identify with the most. In the Board Room the normal procedure is to have people sign a non-disclosure agreement. By having people submit to the act of promising not to talk about what happens behind closed doors, you are creating a forum for trouble.

The Ten Commandments of Responsible Investigations would not be necessary if transparency and policy governance was imbedded in the culture. If this was in place, people would not have as much of a motivation to break the rules. At the root of the issue, you have to go back to one of our earlier blogs on Trust.

Friday, January 12, 2007

Policy Governance: The Road to Change...

The Board of Director's at your company are talking again about Policy Governance. The reason is that change is necessary and when it's time for a new worldview, there are only a few real choices anymore. The old way hasn't worked and now it's time to start with a blank sheet of paper.

So what is Policy Governance?

Policy Governance�, an integrated board leadership paradigm created by Dr. John Carver, is a groundbreaking model of governance designed to empower boards of directors to fulfill their obligation of accountability for the organizations they govern. As a generic system, it is applicable to the governing body of any enterprise. The model enables the board to focus on the larger issues, to delegate with clarity, to control management's job without meddling, to rigorously evaluate the accomplishment of the organization; to truly lead its organization.

In contrast to the approaches typically used by boards, Policy Governance separates issues of organizational purpose (ENDS) from all other organizational issues (MEANS), placing primary importance on those Ends. Policy Governance boards demand accomplishment of purpose, and only limit the staff's available means to those which do not violate the board's pre-stated standards of prudence and ethics.

Is management clear on the mission? Is the CEO out of synch with what the Board of Directors "Ends" are and what direction they are heading in? Policy Governance may be the answer. Yet a new mindset shift or a new methodology will not get you to where you want to be without effective Governance Strategy Execution.

Reinventing your board isn't easy and putting a fence around the CEO perimeter may be even harder. The goal is to make sure that your policies are resilient and endure beyond the potential longevity of a CEO. If you can accomplish this, then it takes the personal human to human potential for conflicting personalities or styles out of the equation. You have to start high enough and in the most broad context:

The CEO shall not cause or allow any organizational practice, activity, decision or circumstance that is in violation of commonly accepted business and professional ethics and practices...

Now that you have the outer perimeter set, you can start to narrow it down and provide greater scrutiny in places you are really concerned about.

As an example, and this is not a one way street:

  1. The Board will not provide orders to people who report directly or indirectly to the CEO.
  2. The Board will not review or evaluate staff other than the CEO.
At the end of the day or the fiscal year for that matter, being on the Board of Directors requires courage and the ability to make hard decisions. Policy Governance is one way to take the change process and to make it happen like you never have in the past. And remember, John Carver and the Policy Governance model are one in the same. He is the inventor and steward for this mechanism of change in the global corporate enterprise.

Thursday, December 14, 2006

Litigation Risk: Thirsty for Justice...

The big four or five or six firms have had a big run in the post-Enron era. Micro-cap companies with $75M. in assets are still not subjected to SOX. What does the crystal ball say about post-Spitzer investigations as he takes on his new role as governor? Did SOX clarify the CFO's internal controls and give investors a better view into their risk portfolio?

On the eve of a highly anticipated Securities and Exchange Commission meeting that could bring about looser regulations for small businesses that have yet to comply with the Sarbanes-Oxley Act, a new study credits the 2002 law with cleaning up larger companies' internal controls and reducing the number of errors in financial statements.

In fact, the Glass Lewis & Co. report — released on Tuesday — says the number of restatements by larger companies fell 26 percent during the first nine months of 2006. The report's authors attribute this decline to the most contentious provision of Sarbox, Section 404, which requires management to attest that their company has adequate internal controls.


In parallel, the Department of Justice has issued the McNulty Memorandum that will provide more clear guidance on the rules for a federal prosecutor should they want to bring charges against a company. The Principles of Federal Prosecution of Business Organizations was created as a result of intense lobby efforts by business advocates in Washington, DC.

The new guidelines, which the department has dubbed the "McNulty memo," say that "prosecutors generally should not take into account whether a corporation is advancing attorneys' fees to employees or agents under investigation and indictment." The only exception, according to a footnote in the memo, is in "extremely rare" cases where the "totality of circumstances" show advancing fees to culpable employees was done with the intention to "impede a criminal investigation."

With respect to obtaining privileged information, federal prosecutors will have to go through a more rigorous approval process, similar to the process required of prosecutors seeking electronic wiretaps or subpoenas for reporters. For certain types of sensitive attorney-client information, such as the advice a defense attorney gave to the management of a corporation facing a fraud investigation, prosecutors are now required to obtain the approval of the Justice Department's No. 2 official in Washington -- currently McNulty.

For privileged factual material a company has obtained through an internal investigation into an alleged fraud, such as transcripts of interviews with culpable employees, prosecutors will need to obtain the approval of the local U.S. Attorney in their district, who can only sign off on such a request with the approval of the head of the DOJ's Criminal Division in Washington, currently Alice Fisher.


And just when KPMG thought they were being vindicated they have been served with a law suit from Fannie Mae. When the auditors start fighting against corporate management or vice-versa, the lawyers get in the middle and you can bet that hundreds of millions of dollars are at stake. In the end, there is only one winner; and it's not the investor.

Monday, December 11, 2006

Privacy: Phone Records Protection Act...

Last week, HP agreed to a $14.5 million settlement in the California civil lawsuit related to the company’s spying scandal. And this week we only have President Bush to sign the "Pretexting" bill:

The U.S. Congress has wrapped up its work for the year by passing a bill that would make it illegal to obtain a person’s phone records without permission.

The Senate late Friday passed the Consumer Telephone Records Protection Act of 2006 , spurred in part by revelations in September that Hewlett-Packard (HP) investigators had used deceptive means to gain access to phone records of reporters and company board members.

The bill, sponsored by Representative Lamar Smith, a Texas Republican, would make illegal the act of pretexting — tricking phone companies into giving up private records by pretending to be a customer. The bill, which passed by voice vote in the Senate, allows prison sentences of up to 10 years and fines of up to $500,000 for deceiving phone companies into handing over records such as phone logs.


As Jon Doak, the new Chief Ethics and Compliance Officer continues in his new role at HP it should be interesting to see how the criminal case proceeds. Corporate monitoring of it's employees and suppliers will get new oversight and the IT organization will soon be storing all e-mail meta data if it isn't already. Organizations like HP have a duty to protect their intellectual assets and trade secrets. Exactly how you implement those policies, tools and strategies calls for an effective risk assurance program that includes far more than just new awareness training.

The Private Investigation industry and Online Data Brokers who have collaborated in the past will be scrutinizing any upcoming enforcement actions to determine if the bill actually has any "teeth". Can you hear the US Attorney on the phone right now? "Set up a task force"...

Thursday, December 07, 2006

Basel II: Hedge Funds Risk...

Hedge Funds Managing Partners have been looking in the rear view mirror as they see the regulators following their every move. Oversight is not just a phenomenon here in the U.S. with the SEC and our own legislators. There is another international wave of change on the horizon:

Japanese banks may be forced to cut back their investments in hedge funds to comply with a global risk regulation.

Banks, pension funds, and insurers are among the largest Japanese investors in hedge funds. Japanese investors have quadrupled their hedge fund holdings during the past five years, to $35 billion.

The March 2007 deadline for Japanese banks to comply with Basel II, a regulation that will alter the capital reserve requirements for financial institutions, is what is causing the concern. The regulation could be especially problematic for smaller Japanese institutions, which manage more than one third of the country's $6.7 trillion of assets. Those institutions may be "incapable" of managing the associated risk under the new rules, one banking executive told Bloomberg News at a conference this week.

In some cases, banks will have to hold $1 in reserve for every $1 invested. Japanese regulators have yet to announce any guidance for complying with Basel II.


Here in the United States the pressure is building to develop more systematic compliance for hedge funds to address the growing corruption and fraud schemes.

Senate Judiciary Committee Chairman Arlen Specter, a Pennsylvania Republican, is circulating draft legislation that would require hedge funds accepting pension money to register with federal regulators. Hedge funds would also be forced to set up ethics codes and compliance programs, and allow the U.S. attorney general to reward private citizens for helping in insider trading cases.


Why all of the talk about regulation and oversight? With over 8000 hedge funds now controlling over $1 Trillion in assets it won't be long before the marketing gets pushed down to just the "high net worth" individuals. Having a place for pension fund managers to get some portfolio exposure on the other end of a risk spectrum is one thing. To move the access to these investment vehicles closer to the average consumer is now the concern.

The hedge fund industry has shown few signs of major fraud, but cases of wrongdoing may rise if more of these investment vehicles are sold to mass-market savers, international financial regulators said on Monday.

The sector does not appear to have high levels of dishonesty, but some national watchdogs fear risks of fraud could rise if these funds were to become more available to retail investors, the International Organisation of Securities Commissions (IOSCO) said in a report.

Hedge funds, traditionally a secretive industry domiciled in offshore tax havens such as the Cayman Islands, have come under growing scrutiny from central banks and regulators concerned about the sector's potential impact on financial stability.

Traditionally, hedge funds have been used only by wealthy individuals or institutions such as pension funds.

"The extent of fraud relating to hedge funds varies in the member jurisdictions ... the absolute number of fraud complaints is presently not high, although some regulators perceive a risk of greater fraud in the future as further retailisation occurs," the report said.

Thursday, November 30, 2006

Red Flags: Mobile Data Encryption Policy...

Have any of your executives been waving any "Red Flags" lately? If you are like many CISO's across the globe, you may have to change this to a "White Flag" and surrender.

IDC reports in a recent study, that the projected number of global mobile employees would grow beyond 878 million by 2009. IDC’s report, "Comply on the Fly: Keeping Pace with the Management Challenges of Mobile Data Management," explores whether businesses are implementing initiatives to provide internal controls and address data security risks from mobile device use.

A Recent IDC Report cited at the Business Performance Management (BPM) Forum reminds the CxO's to batten down the hatches on mobile devices. Blackberry is only one of a few companies (RIM) who are being subjected to greater pressure to provide encrypted data at the device level.

The IDC report contained the following information:

* Nearly half of all respondents report that a minimum of 25 percent of all mobile devices in their organization carry mission-critical applications and information.

* Forty percent of respondents have no measures at all to manage mobile data tracking, backup and archiving for regulatory compliance purposes.

* Smaller companies ($100 million in revenue and under) face a greater risk of violations, with just 32.4 percent implementing formal mobile compliance policies.

* There is disconnect between IT executives who recognize mobile device compliance and security risks, and C-level executives who see benefits, not risks.


Yet it seems that employee's will not obey or even heed the policies set forth by their enterprise to try and protect customer information and valuable intellectual property. Thousands of laptops and other PDA's are left in taxi cabs as "On The Go" executives run for their meetings, interviews or flights.

In this digital age, the value of information on these stolen or lost devices is increasing and the losses to the enterprise far exceed the replacement of the phone, PDA or laptop. The loss extends to the notification of the customers who have exposed Personal Indentifiable Information. Studies by the Ponemon Institute have calculated this amount to be $182.00 per record.

According to the study’s 2006 findings, data breaches cost companies an average of $182 per compromised record, a 31 percent increase over 2005. The Ponemon Institute analyzed 31 different incidents for the study. Total costs for each ranged from less than $1 million to more than $22 million.

The 2006 Cost of a Data Breach Study tracks a wide range of cost factors, including legal, investigative, and administrative expenses, as well as stock performance, customer defections, opportunity loss, reputation management, and costs associated with customer support such as information hotlines and credit monitoring subscriptions. "The burden companies must bear as a result of a data breach are significant, making a strong case for more strategic investments in preventative measures such as encryption and data loss prevention," said Dr. Larry Ponemon, chairman and founder of The Ponemon Institute. "Tough laws and intense public scrutiny mean the consequences of poor security are steep—and growing steeper for companies entrusted with managing stores of consumer data."


The CxO on the go now realizes the importance of encryption for all mobile devices. Unfortunately for those few who still have not reallocated the funding to accomplish this important task, may cost millions more.

In yet another instance of laptop theft potentially endangering personal data, Kaiser Permanente Colorado is notifying some 38,000 members of a possible breach of their private health information.

The information was located on a laptop stolen from the personal car of a national Kaiser Permanente employee in California, reports the Rocky Mountain News and other media outlets.


Let's see: 38,000 x $182.00 = $6,916,000.00 in operational losses.

Monday, November 27, 2006

Backdating: Culture Makes All the Difference...

Looking back upon your last stock option exercise, did you realize the price you were granted was backdated? If you did, then your ethical misbehavior is just another example of how corporate compensation is bringing the house down. The question now remains, how many more companies will be announcing that they need to restate their numbers for the latest financial period.

Affiliated Computer Services replaced CEO Mark A. King and CFO Warren D. Edwards on Monday, saying they had violated the company’s "Backdating" code of ethics for senior financial officers, as the company completed an internal investigation of its stock option-granting practices.

The Dallas-based outsourcing company named COO Lynn Blodgett as the new chief executive, and John Rexford, the company’s executive vice president of corporate development, as the new chief financial officer.

Mr. King and Mr. Edwards are just the latest of about 60 corporate executives who have been pressured to step down as companies have probed their stock option grants and the backdating of those grants to benefit executives. The options fallout has ensnared more than 150 companies so far.

The two ACS executives resigned effective Sunday and entered into separation agreements with the company.


You can bet that anyone who is now considering a new position where stock options will be part of the compensation package will question the ratio between incentive in stock and the cash bonus. Incentive compensation is the root of much of the corporate malfeasance we have all witnessed over the past five years. And if you look at where this story really begins, you have to look hard at the compensation consultants, head hunters or just plain human resources processes.

When you look at the way people are compensated, you generally can figure out what type of behavior you are trying to influence. The corporate governance of our companies continues to see new fraud, new corruption and a continuous stream of finger pointing. A Code of Ethics is easy to create and yet much more difficult to get people to follow. What would Warren have to say about it?

Warren Buffett's "Tone at the Top"

A few months ago, Warren Buffett sent this memo to managers at Berkshire Hathaway:

To: Berkshire Hathaway Managers ("The All-Stars")
From: Warren E. Buffett

Date: September 27, 2006

The five most dangerous words in business may be "Everybody else is doing it." A lot of banks and insurance companies have suffered earnings disasters after relying on that rationale.

Even worse have been the consequences from using that phrase to justify the morality of proposed actions. More than 100 companies so far have been drawn into the stock option backdating scandal and the number is sure to go higher. My guess is that a great many of the people involved would not have behaved in the manner they did except for the fact that they felt others were doing so as well. The same goes for all of the accounting gimmicks to manipulate earnings - and deceive investors - that has taken place in recent years.

You would have been happy to have as an executor of your will or your son-in-law most of the people who engaged in these ill-conceived activities. But somewhere along the line they picked up the notion - perhaps suggested to them by their auditor or consultant - that a number of well-respected managers were engaging in such practices and therefore it must be OK to do so. It's a seductive argument.

But it couldn't be more wrong. In fact, every time you hear the phrase "Everybody else is doing it" it should raise a huge red flag. Why would somebody offer such a rationale for an act if there were a good reason available? Clearly the advocate harbors at least a small doubt about the act if he utilizes this verbal crutch.

So, at Berkshire, let's start with what is legal, but always go on to what we would feel comfortable about being printed on the front page of our local paper, and never proceed forward simply on the basis of the fact that other people are doing it.

A final note: Somebody is doing something today at Berkshire that you and I would be unhappy about if we knew of it. That's inevitable: We now employ well over 200,000 people and the chances of that number getting through the day without any bad behavior occurring is nil. But we can have a huge effect in minimizing such activities by jumping on anything immediately when there is the slightest odor of impropriety. Your attitude on such matters, expressed by behavior as well as words, will be the most important factor in how the culture of your business develops. And culture, more than rule books, determines how an organization behaves. Thanks for your help on this. Berkshire's reputation is in your hands.


What kind of culture exists in your organization?

Friday, November 17, 2006

Enterprise Resilience: Investing in Intellectual Capital...

This weeks 21st Annual OSAC (Overseas Security Advisory Council) Briefing was entitled Global Resiliency: Operating in Challenging Environments.

The United States Department of State Bureau of Diplomatic Security sent a clear message that Enterprise Resilience is going to be a major theme moving forward as global firms experience extended supply chains. As this footprint becomes more expansive and spans multiple continents, so too are the operational risks. The conference was opened by Ms. Deborah Wince-Smith of the Council on Competitiveness who presented a case for why private sector CEO's should care about this strategic initiative:

There are at least four reasons why CEOs should care about integrating security and resilience into their business strategy.

1. Business risks are growing, irrespective of 9/11 and the threat of global terrorism.

2. Resilience, in the face of increasing risk, is a shareholder value issue.

3. New corporate governance rules may mandate more rigorous integrated management systems than are currently in place.

And for many firms, operational risk management is not a priority. According to recent surveys:

Only 36% of U.S. CEOs believe that risk management is a priority concern, versus 45% of European CEOs and 67% of Asian CEOs (Conference Board, 2006).

Only 25% of Directors of non-financial companies report that the Board considers all major risks to the company, versus 55% of financial industry directors (Conference Board 2006).

During the past 12 months, 1 in 5 companies surveyed suffered significant damage from a failure to manage risk and over half had experienced at least one near miss (Economist Intelligence Unit and Lloyds, 2006).

4. Industry continues to face a risk of reactive regulation for homeland security.

5. Empirical evidence from the case studies highlight missed opportunities to leverage security investments to increase efficiencies and revenues.


The conference also had keynotes from our own (DNI) Ambassador John D. Negroponte and the CEO of Archers Daniel Midland, Patricia Woertz who made a case for the "Chief Resiliency Officer". Yet the most compelling remarks and insight comes from someone who has lived on the front lines for decades. Someone who understands the threats corporations, NGO's and governments face on the new global battlefield. Henry (Hank) Crumpton is now the Ambassador-at-Large and Coordinator for Counterterrorism after joining the CIA in the early 80's. He led the CIA's Afghan campaign in the first critical months of this new strategy against "Non-State Actors."

These small, nimble and flexible attack units known as "Micro-Actors" can deliver "Macro-Impact" using cover of corporations, exploiting our modern transporation and communications networks and gaining new 4th generation weapons. We must realize the innovations and the technologies we create will be utilized against us.

Here are some words of wisdom from one of the most admired and fearless patriots of the United States:

1. We must begin investing more in our own Intellectual Capital and to better understand the enemy.

2. We must build interdependencies and strong interdependent networks. (People)

3. People need to demand more from government to build stronger partnerships.

4. The private sector needs to give more to the government. (Intelligence)

5. We need more leadership.


Resilient organizations learn and adapt. It changes and morphs as new risks evolve. Given the new revolution of protection converging with recovery, we can only pray that business leaders finally realize that this is not about mitigating losses. It is about putting on a new pair of glasses with a new prescription that is perfect. Clarity of the new lens allows people to see that new found investments can Enable Global Enterprise Business Resilience.

Sunday, November 12, 2006

Safeguards Rule: The ID Theft Battle...

Unlike Europe and other forward thinking regions of the globe, the United States is still wrestling with a national data security and privacy law. If the new democratic powerbase is successful, the ID Theft and privacy battle ground will now shift from a corporate focus to a more consumer focus.

A new ID theft task force comprised of 17 US Government agencies has been working on a strategy report that is due by February 2007. It will be highlighting "ID Theft Red Flags" or rules that need to be addressed when they occur. The Federal Trade Commission (FTC) will be gearing up enforcement on those companies who provide PII (Personal Identifiable Information) Intel such as they did this past year with ChoicePoint and others.

Organizations are being pressured to retain data longer, up to two years as a more modern FISA (Foreign Intelligence Surveillance Act) is contemplated. This will assist law enforcement and corporate security departments in evidence collection and investigative process to detect and defend our company assets and national security from "Lone Wolf" terrorists and everyday fraudsters, counterfeiters or pirates. If you are currently a consumer using Vonage, Skype or someother VOIP service, you can bet that all of your calls are going to be accessible for some time to come.

As the Federal Civil Rules on Electronic Discovery change December 1st, the records retention policies and data categorization or mapping exercises will be in full swing. If they aren't, be prepared for quick judgements and settlements from your organization if your litigation readiness factor is in the red or even the yellow zone. In terms of your 3rd Party or outsourced relationships, you can bet that a SAS 70 Type II will not be enough to ensure that your partner has been doing enough to protect your customers PII.

So what does all of this mean? SO What!


It means that the 8 Million+ small and medium enterprises in the US will be subjected to the FTC scrutiny on the SafeGuards Rule:

According to Orson Swindle, former commissioner of the U.S. Federal Trade Commission,

We're going to probably see a broadening or extension of the safeguard rule in the Gramm-Leach-Bliley Act to cover a significant number of organizations that handle sensitive information but that aren't financial services institutions. There is a new awareness that personal information is very valuable, and it needs to be protected whether we're talking about a financial institution or a university or a shoe store.


As the committee's in congress are sorted out and the first 100 hours of the new Democratic regime take hold, don't be surprised if your organization is now in the cross hairs of the governments regulatory enforcement teams. The US Attorney in your jurisdiction is ready to begin a new era to get business to invest in soundness and safety, even if you are not traditionally a highly regulated entity. You think ID Theft is just another bother?

Woe to you, friend, if that's your attitude. Data security may be dead in Congress this year, but the Federal Trade Commission is on the case, and that could mean trouble for lax companies.

"The FTC has stepped into the void," said Emilio Ciividanes, a partner in Venable LLP. "And every proposal for comprehensive legislation has the FTC playing an important role."

For one thing, the commission is now putting its finishing touches on its ID Theft Red Flags Rule, requiring that companies spot and address identity theft risks.

What would constitute a red flag? If there are multiple addresses for a credit-card holder, according to Joel Winston, associate director of the Privacy and Identity Protection division of the FTC's Bureau of Consumer Protection, speaking at DMA06 in San Francisco.

And the FTC is aggressively pursuing companies for allowing security breaches to occur or for not having protections in place. And why not? It is getting 15,000-20,000 consumer messages a week through its Identity Theft Website and telephone number.


If you are one of the millions of Small to Medium Enterprises (SME) in the United States without a full-time Chief Information Security Officer (CISO) you may be at significant risk. Especially if your General Counsel has little or a non-existent relationship with the person you have charged with keeping the networks running and the infrastructure maintained. Be forwarned. The next new hire in your organization may be a lawyer with a CISSP or even a person with a MIS and a J.D. degree. In either case, the government is going to come knocking and your reputation is on the line.

Monday, November 06, 2006

Foreign Corrupt Practices: Oil, Corruption & Borat...

Global commerce is on an upward curve of growth as the planet becomes flat or smaller based upon the increasing speed of business. Transportation, Technology and Telecommunications has spawned the reach for many U.S.-based enterprises who desire to trade products or services overseas. The Gas & Oil Industry and Energy sector have been the most scrutinized public companies for their business practices over the past three years.

Operational Risk in the Energy Sector and others could be blind-sided by the Foreign Corrupt Practices Act (FCPA) in the years to come as they race to do business in Kazakhstan and China. Here is a lesson for aggressive marketeers and business developers who will need to be wary of their business protocols and procedures when engaging in international commerce.

"So you think it's easy to stay out of jail? John MacLellan doesn't. The regional finance director of Microsoft Corp. in Asia, MacLellan is responsible for ensuring compliance with the U.S. Foreign Corrupt Practices Act (FCPA), a law that exacts strict penalties for giving or taking bribes at overseas operations. While the software giant boasts a robust internal-compliance program, recent FCPA enforcements (including actions against Titan Corp. and InVision Technologies) suggest a new urgency in the U.S. government's enforcement of the law.

Complicating MacLellan's job: in the People's Republic, it's not always clear who you're dealing with. A U.S. executive might treat a customer to a business dinner without ever knowing that one of the guests is a low-level ministry official. "We face a large number of very complex deals in China," MacLellan says. "Because of the size and influence of the government, we're exposed [to the FCPA] from the start."


The Kazakh government is getting plenty of publicity this week due to a new movie launched this past weekend named "Borat: Cultural Learnings of America for Make Benefit Glorious Nation of Kazakhstan". Simultaneosly, the country is the focus of an oil, cash and corruption probe.

"In February, the United States attorney’s office in Manhattan is scheduled to go to trial in the largest foreign bribery case brought against an American citizen. It involves a labyrinthine trail of international financial transfers, suspected money laundering and a dizzying array of domestic and overseas shell corporations. The criminal case names Mr. Nazarbayev as an unindicted co-conspirator. The defendant, James H. Giffen, a wealthy American merchant banker and a consultant to the Kazakh government, is accused of channeling more than $78 million in bribes to Mr. Nazarbayev and the head of the country’s oil ministry. The money, doled out by American companies seeking access to Kazakhstan’s vast oil reserves, went toward the Kazakh leadership’s personal use, including the purchase of expensive jewelry, speedboats, snowmobiles and fur coats, federal prosecutors say."

As American companies seek partnerships, acquisitions and IPO deals they must comply with FCPA or suffer the financial or political consequences. Even in the middle of all of the movie hype and the legal depositions the country of Kazakhstan has been elected to join the UN Economic and Social Council:

Kazakhstan says it has become the first Central Asian country to be elected a member of the UN's Economic and Social Council (ECOSOC).

The Kazakh Foreign Ministry says in a statement the vote took place at the UN General Assembly on November 2.

Kazakhstan will represent Central Asia in the 54-member UN body for the next three years. ECOSOC is the UN's central forum for discussing international economic and social issues.

Monday, October 30, 2006

Corporate Plausible Deniability: Is Now Extinct...

Skyrocketing Electronic Discovery (E-Discovery) costs force many organizations to prematurely settle cases or at least compromise their litigation strategy. Courts are increasingly issuing broad evidence preservation orders, mandating that computer data on up to several thousands of hard drives and servers be preserved.

Regulations and new legal statues have created a convergence of information security and legal issues. Effective governance strategy execution must include business drivers of legal and security factors to be successful. "Plausible Deniability" is now extinct.

Plausible deniability is the term given to the creation of loose and informal chains of command in government. In the case that assassinations, false flag or black ops or any other illegal or otherwise disrespectable and unpopular activities become public, high-ranking officials may deny any connection to or awareness of such act, or the agents used to carry out such act.

In politics and espionage, deniability refers to the ability of a "powerful player" or actor to avoid "blowback" by secretly arranging for an action to be taken on their behalf by a third party - ostensibly unconnected with the major player.

More generally, "plausible deniability" can also apply to any act which leaves little or no evidence of wrongdoing or abuse. Examples of this are the use of electricity or pain-compliance holds as a means of torture or punishment, leaving little or no tangible signs that the abuse ever took place.


Digital Forensic Services are specifically designed to perform efficient and effective enterprise computer investigations to address these concerns with best practices technology. This enables corporations to manage and retain control of these investigations while substantially reducing cost. In the context of E-Discovery, courts require that best practices are employed and that counsel take affirmative steps to monitor compliance and ensure all relevant data is located and preserved.

And as we approach the eve of Halloween there are all kinds of "Tricks and Treats" going on at the corporate digital battle front. Executives from most organizations are trying to keep their eye on those employees and places that are deemed significant risks to the organization and at the same time, cover their tracks. The HP scandal is still fresh on their minds.

The Privileged Executive

Her trick
The privileged executive feels responsible for every aspect of the organization, and compelled to control it. She wants to know everything about every department and project; demands root access to systems and applications, and sufficient rights to act on others’ behalf -- including sending email using other employees’ accounts. Naturally, she objects to logging of her own activities while demanding stringent audit of everyone else.

Your treat
Forward articles on prosecution of executives for insider trading, misusing data, and SOX violations, particularly ones that detail how malfeasance got pinned on the corner office because of too much access. Follow up a few days after each prying event by hinting to IT that it ought to look into apparent audit discrepancies, and suggesting to internal auditors they ought to look into IT control logs. Send monthly updates about how you’re working hard to make sure the execs aren’t exposed to excess risk; make plausible deniability your mantra.


New York state courts' are coming of age with respect to electronic discovery while U.S. federal courts already know the nuances associated with e-discovery. Notwithstanding the lack of a CPLR(Civil Practice Law Rules) or court rule specifically electronic disclosure, the recent court decisions reflect the courts' appreciation of:

(i) the search, production, de-duplication and privilege review costs that may be incurred by a party in addressing e-discovery requests and the importance in fairly determining who should bear such expense, including counsel's time in reviewing electronic documents for privilege,

(ii) the legal and business burden on the party producing electronic documents, taking into account, among other things, the purpose for which backup tapes were made and issues relating to their restoration,

(iii) a party's claimed relevance of and need for the requested electronically stored materials,

(iv) the process utilized by the producing party to identify, search for and gather electronic materials,

(v) the likelihood of whether yet-to-be searched for electronic materials actually exist and, if so, would they be duplicative of documents already produced,

(vi) a party's "true" justification for seeking and/or objecting to producing electronic documents, and

(vii) both sides to a dispute having the opportunity to retain appropriate expert forensic computer experts prior to a court ruling on e-discovery issues.


Digital Forensics in E-Discovery is evolving at the pace of lightning and many large organizations are already well entrenched. However, one thing is for certain. Corporate Plausible Deniability is almost certainly on the way to extinction.

Thursday, October 26, 2006

Anti-Terrorism Tools: Fido to the Rescue...

One of our most effective "Anti-Terrorism" sensors may be the nose on your favorite breed of canine. Dogs are being trained and their careers are sometimes being diverted from helping the blind, to helping the general public detect the possible signs of a terrorist event in the making.

TATP is triacetone triperoxide, one of the more common liquid peroxide explosives, the kind used in last year’s London transit system bombings and found hidden in the sneakers of the would-be shoe bomber, Richard C. Reid. Experts say peroxides have become terrorists’ explosives of choice, and government agencies are trying to detect them before they are carried onto buses, trains and airplanes.


The TSA Puppy Program has been around for several years and continues to be one of our most low tech, highly efficient tools in the counterterrorism arsenal.

Our National Explosives Detection Canine Team Program prepares dogs and handlers to serve on the front lines of America’s War on Terror. These very effective, mobile teams can quickly locate and identify dangerous materials that may present a threat to transportation systems. Just as important, they can quickly rule out the presence of dangerous materials in unattended packages, structures or vehicles, allowing the free and efficient flow of commerce.

Law enforcement officers from all over the country travel to the our Explosives Detection Canine Handler Course at Lackland Air Force Base in San Antonio, Texas where they are paired with one of our canine teammates . These dogs are bred specifically for the program by our puppy program, also at Lackland AFB. German Shepherds, Belgian Malanoises, Vizslas and other types of dogs are used in the program because of their keen noses and affinity for this type of work. In addition to providing a highly trained dog and handler training, we provide partial funding for handler salaries, care and feeding of the canines, veterinary and other costs associated with the dog once the teams return to their hometowns.

After dog and handler are paired up, the new team completes a rigorous 10-week course to learn to locate and identify a wide variety of dangerous materials while working as an effective unit. This training includes search techniques for aircraft, baggage, vehicles and transportation structures, as well as procedures for identifying dangerous materials and "alerting" or letting the handler know when these materials are present.


Deutsche Bahn, the German Railway Authority continues to test biometric technology using face recognition as a deterence and detection strategy. This testing is a result of a foiled or aborted plot to bomb German trains during the World Cup last summer. We find it hard to believe that terrorists with their pictures in the database will be the actual assailants carrying a backpack or wearing the explosives.

Let's keep our "Canine Corp" growing so we can make sure they are making their rounds in every train station in every major metro city on the planet. It's imperative if we are to keep our defenses at the highest level of detection in the days and years ahead.

Tuesday, October 24, 2006

Know Your Domain: Alias Fraud Gains Millions...

The latest Alias Fraud is a "Rogue Wave" heading towards the bow of a financial broker near you. Even in companies like E*Trade who have been advocating the use of the RSA SecureID for their clients, the losses continue. $18 Million stolen.

``Internet crimes that result in the theft of personal and financial data from consumers continue to be a significant and global problem,'' FBI spokesman Paul Bresson said. ``We work closely with our foreign law-enforcement counterparts to pursue these cases with all applicable laws.''

Bresson declined to comment on the FBI investigation. John Heine, a spokesman for the SEC, and NASD's Herb Perone also declined to comment.

Some of the losses were straight theft. In his presentation, Walsh of the SEC explained how criminals use personal information such as Social Security numbers to break into accounts. Once in control, they loot the accounts by selling securities and wiring out the proceeds far from the U.S.

`Pump and Dump'

The online version of the ``pump-and-dump'' fraud sets off few security alerts at brokerage firms because no money is withdrawn from the compromised accounts, Walsh explained.

``This is an increasingly popular variation,'' he said in Phoenix. ``If you are looking for a single `hot topic' in the world of identity theft, this is it.''

In ``alias fraud,'' a thief opens an account in an individual's name, then uses it for illegal trading or money- laundering. Because the victim's name is on the account, he or she appears responsible for the crimes.


Two-factor authentication is not a new topic to these organizations. The FFIEC has been providing guidance and now a December 31 deadline for addressing this issue. Back in August this Operational Risk Blog discussed this very topic:

One way to solve the issue is to find a company who has taken all of these technology hurdles and has found a viable solution for FFIEC compliance. See Boulder, Colorado based Authenticol to add to your short list.


The answer for the banks and financial services companies are out there. What is more difficult to address are the processes and the enterprise architecture to accomplish the goal of reduced operational risks. Whether these be external fraud by foreign transnational crime syndicates or the stealth employee walking out the door with a 2GB Jump Drive on their keyring with proprietary client information. Do you really believe that all of these hackers are just getting lucky that the trojans and key loggers they have propagated end up on the home desktop of E*Trade consumers?

"Insider Information" comes in all kinds of forms. Whether it be the stolen client information or the loose lips of a person with access to vital M & A information.

The bulk of the money allegedly made in the case by two former Goldman Sachs employees resulted from tips from an analyst with information about Wall Street deals and a grand jury member who knew about a probe of accounting fraud accusations against Bristol-Myers Squibb Co. and several of its executives, the government has said.

The case came to the attention of authorities when regulators noticed unusually high trading volume before a merger announcement and discovered that a 63-year-old retired seamstress in Croatia -- the aunt of one of the defendants -- had made more than $2 million.

The plot involving Schuster, however, showed the lengths to which those involved in the insider trading plot would go to gain an edge in the market.


In the words of one very respected and experienced investigator we recently had the company of speaking with, his wisdom is this. "Know Your Domain". In a recent survey by the Privacy Rights Clearinghouse and the National Association for Information Destruction Inc.:

Percentage of business executives who do not know what their companies do to ensure the destruction of information on obsolete computers = 77%

Friday, October 20, 2006

SOX 404: Auditors vs. Empowered Employees...

In the November/December issue of Corporate Board Member 100 Board Directors have sounded off. The PricewaterhouseCoopers Survey on "What Directors Think 2006" asked some tough questions and got some revealing answers.

How effective is your board at monitoring the company's "Risk Management Plan?

Very Effective - 12%

Effective - 47%

Somewhat Effective - 36%

Would you like to spend more, less or the same time on Sarbanes-Oxley Section 404?

The Same - 64%

Less - 33%

More - 3%


If we try to interpret what these two questions mean in relationship to each other we guess it makes sense. Almost two thirds of the Board Directors polled want to spend more time on Section 404 and at the same time are saying that they are not very effective at managing the company's risk management plan. Logical? The Board of Directors are looking for answers in the wrong places, the auditors.

The company’s external auditor must report on the reliability of management's assessment of internal control (Section 404).

Colossal and recurring external auditor failures around the world regularly demonstrate the difficulty of providing opinions on the reliability of financial statements. Positive audit opinions are regularly issued on materially false financial disclosures in spite of the fact that the U.S. has developed thousands of pages of rules on how they should be prepared to “fairly” present the company's financial status. The difficulty of providing an opinion or an assertion that internal control is “adequate” or “effective” to ensure the reliability of external financial disclosures is exponentially greater. There are very few guidelines to help auditors decide when there are “adequate” internal controls. Field research done by CARD®decisions with hundreds of groups of senior level internal audit and management personnel has consistently demonstrated that, given the exact same circumstances in a case situation, few groups and few individuals in those groups agree on the combination of control elements from a predetermined control design menu that would provide an “effective” or “adequate” level of control. This is true in spite of the fact that internal audit departments around the world routinely give opinions to clients on whether the clients’ internal controls are “adequate”. It takes very little applied research to demonstrate conclusively that audit opinions on what constitutes an “adequate” level of control involve a huge amount of highly subjective judgment. These findings suggest that reporting these highly subjective opinions on whether controls are “adequate” or "effective" to key stakeholders does not meet the goals of comparability, reliability, and repeatability, key criteria for sound assurance and audit methods.


The Basel Capital Accord II is the first breath of fresh air on the modern management systems for identifying and controlling process variability and driving down errors and rework. Although Basel has clearly recognized that a risk focus is far superior to a fixation on controls compliance, the management and the Board of Directors hasn't figured that out just yet. When they do, they will be calling in their favors from the legislators.

Really understanding and documenting the processes that feed the disclosures and reporting has to begin with each employee and manager owning it and understanding it themselves, not just internal audit or the external auditor. Only then will the employees become more aware and capable of detecting where controls need to be turned into Total Quality Management objectives.

The Board of Directors only has to look at the risk management accumen of the middle management ranks to really get an accurate "litmus test" of the effectiveness and the adequacy of the companies overall Enterprise Risk Managment (ERM) quality score. This is where the true health and the resilience of the company can be found to verify or question, SOX 404.

Tuesday, October 17, 2006

Buyer Beware: The Risk of Private Data...

Operational Risks are being found in places that a CxO would not have at the top of their list when it comes to mitigating threats to the institution. Human Resources, Information Systems, Accounting make the list near the top yet Marketing always seems to be a few steps down. This is a big mistake and a renewed interest in auditing the sales and marketing organization could open up a real "Pandora's Box".

Fidelity Federal Bank and Trust (West Palm Beach, Fla.) has been ordered to pay a $50 million settlement for buying more than half a million names and addresses from the Florida Department of Highway Safety and Motor Vehicles. The Electronic Privacy Information Center (EPIC), which filed an amicus brief in favor of the plaintiffs in the case, announced the decision in late August.

EPIC said the $4 billion-asset bank bought 565,600 names and addresses for use in direct marketing, claiming that the purchase violated the Drivers Privacy Protection Act. The federal law was enacted in 1994 to prevent the distribution of drivers' personal information.

From 2000 to 2003, Fidelity purchased the data containing the personal information of drivers living in Palm Beach, as well as Martin and Broward counties, for only $5,656, or a penny per driver record, according to papers filed in Kehoe v. Fidelity Federal Bank and Trust. The bank sought the information for car loan solicitations, according to the class-action lawsuit.


When this is one is all over you can bet that many organizations will be reexamining where they get their marketing data. The direct marketers sell and resell data on a daily basis including some companies you would not think are even in that business, namely your own state. Buying your drivers license information should be highly accurate as we are all required to report change of address to DMV shortly after we move to a new location. That is why this data is valuable to the direct marketers, fewer pieces of returned mail.

Where does your marketing department get all of the information that they use for outbound direct marketing? Via postal mail, e-mail, outbound phone calls and even personalized content on the web site each time I log in to get my latest statement. These days a valid e-mail address may be even more valuable than a phone number due to the "Do Not Call" list and the fact that people just don't answer their phone if they don't have the person calling in their personal contact list.

As an example, this one hit the in-box the other day from Equifax:

Your entire credit history in one easy-to-read report plus your FICO® credit score for only $29.95

Taking charge of your credit standing could pay big dividends when applying for a loan or negotiating an interest rate down the road. Because you are one of our most valuable customers and understand the importance of actively monitoring your credit, we are offering you our deepest discount - $10 off your 3-in-1 Credit Report with Score Power® - which includes your credit history as reported by all three credit reporting agencies plus your FICO® credit score - the score lenders use most.

When you apply for a loan, lenders can pull your credit file from any or all of the 3 major agencies, so it's important to know what information they have about you. Your 3-in-1 Credit Report allows you to see your entire credit history in one easy-to-read report. A quick and convenient way to ensure that your credit history is in order!


Where Equifax obtained this e-mail address is anybodies guess. They must have bought a list from a company that was doing a survey for a client who was selling products to people in the zip code 22102 and drive black SUV's. At the end of the day the marketing and sales organizations in your enterprise are just doing what you expect of them in generating new market share and revenues. Be careful what you wish for because all of those new found customers and sales could be erased in an instant with a well planned plaintiff class-action lawsuit.