Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Wednesday, December 2, 2009

Thinking Cautiously about Risk Appetite

How does the current trend for Caution in Risk Management affect business potential?

Because well-considered risk taking is critical to business growth and success, not just for individual companies but also to enable or entitle the expansion of a properly functioning economy.

Food for Thought
Business-to-business lending and borrowing always involves a high degree of risk. Therefore, curtailing that appetite for risk can directly hobble entrepreneurship, deprive deserving businesses of capital, and reinforce deflation.

Take a Positive Stance
Moreover, for any business, the assessment of risk should not dwell on the potentially damaging prospects but also on the opportunities; potential rewards and gains. If you take an overly cautious stance this is more difficult to do or can create a restrictive position.

Although the need for risk taking is recognised by both businesspeople and economists, a lot of this is based on theoretical lip service and rhetoric, rather than real positive and optimistic determinations and outlooks.

Complexity
The complexity of risks in the global economy severely tests many companies, both in their judgment about how much risk to take and in their controls for tracking and managing it. What doesn’t help the situation in any way are sponsors and senior management teams who are not comfortable or practiced at discussing risk in the context of strategic decision making or in articulating those expectations to the organisation.

Positive Solution
To overcome the problem of over cautious risk taking, sponsors, senior managers and companies needs a fresh, more rigorous definition of the appropriate level of risk the organisation can accept or endure. The organisation needs to stress its structure, confirm its strengths and articulate its risk appetite.

Set the Appetite
In addition to asking how much risk to avoid and how much to accept, we need to prepare for the possible downside. Leaders should be setting a better example, by defining how much risk they want and establishing how much capital they are willing to stake against it.

Result Focus
Clearly this is only part of the algorithm, because the result of all this effort is to achieve as much potential and capital gain. The whole organisation should be involved and open to this discussion on risk appetite.

Trading on the edge
Traders and deal makers are at the sharp end of it. They, of all people need to fully understand the risk appetite of the company and the part that their individual deals might have in the corporate-wide performance, because they are the ones that have to implement it effectively.
Unshackle and empower your people, by giving them a clear framework, an appetite for risk and a plan for success.

Saturday, November 28, 2009

Risk management - Insider Trading

In 1992, a British bank sent an employee to Singapore to launch and manage its trading operations. The employee engaged in speculative derivatives trading which counted on the Japanese market remaining stable. Unfortunately for him, the Kobe earthquake in 1995 sent the Nikkei into a state of volatility. His risky trades led to $1 billion in losses for the bank.

The employee was Nick Leeson and his actions led to the fire sale of a household name in the British banking industry, Barings Bank, for just 1 GBP in 1995. The problem? Leeson simultaneously held roles as office manager, trader, and IT guy, which allowed him to hide his losses in old error accounts and avoid detection for four years.

Fast forward a decade to 2005. An employee of a global French bank is transferred from a middle-office role in compliance to a front-office role as a trader. In 2007 he begins using a bogus account portfolio to hide risky trades and significantly exceeds his trading limits. In 2008 the bank finally detects the problem but by then the losses exceed $7 billion.

The employee is the now infamous insider Jerome Kerviel who worked for Societe Generale, ranked 43rd on Fortune’s 2008 Global 500 list. The problem? While Kerviel used several ploys such as small trades in high frequency to avoid tripping alert thresholds, the fundamental problem was the same as in the Barings Bank case. Kerviel continued to have access to accounts from his previous role in the compliance and controls division which a trader should never have had.

Both incidents are classic examples of failure to enforce “separation of duties”, a common enabler of insider threats. When it comes to insider threats — or even other cyber threats -- you’ve probably heard over and over, “the clues were in the logs, if only they were picked up!”

Well, often the clues aren’t enough. Consolidation of logs is certainly the first step, but to use those clues and detect separation of duties violations or other insider threats, there are four other important technical challenges that must be addressed:

* Missing user context. Router logs may have shown traffic from Jerome Kerviel’s desktop to a server he was not supposed to access as a trader. However these logs would only contain IP addresses and the same is true for many other sources. To leverage such clues, the source IP address would need to be mapped back to Kerviel as the owner.

* Bridging user identities. As an IT manager Nick Leeson had direct access to backend servers. As a trader he had application accounts. The combination enabled him to create bogus accounts and hide his trades. In this case, accessing logs would only provide partial clues specific to each credential and the underlying application. Simply put, unless you can link log activity from separate credentials to an actual user, many insider threats will go undetected.

* Awareness of roles and privileges.
Logs probably captured Kerviel’s access to old accounts that were never de-provisioned after he transferred into the trading group. However, to detect a separation of duties violation, your log analysis solution would need to contextualize Kerviel’s actions with his current role and the associated privileges. Log analysis solutions must integrate with identity management and directory systems to make this connection.

* Infinite threat scenarios. Compliance folks often suggest that these threats could be stopped through better training and improved processes rather than relying solely on technology. But people, processes and most log analysis solutions (the relevant technology in this case) have limited success in tackling unknown threat patterns. The reality is that for every known insider threat, there are infinite variations. To overcome this limitation, log analysis needs to move past signature-based detection and into pattern-based analysis. Detecting variations and new threats is much easier if you can visualize user activity as patterns rather than in an unending list of log events.

So, as you evaluate solutions that claim to uncover the clues in your logs to curb insider threats, make sure they can connect the clues back to users, identities and roles. Solutions that can tackle those challenges while giving you visibility into user activity patterns and deviations might just prevent the next big insider threat.

Wednesday, September 16, 2009

Your Leaders are in Chains: Let loose the Hounds!

Have you got the measure of your Senior staff? Well, why are you not giving your senior people the opportunity to lead and to deliver better value on their projects. Playing safe is not the same as scoring points!

Currently, modern business-driven organisations have wrapped within them (and without them), an extensive, complex and multi-layered IT Infrastructure that is expected to take-on a more defensive exo-skeletal role than it's intended 'growth enablement' and 'capability enhancement' role, for which it is greatly suited.

The energy lost in defending and maintaining the status quo, could be better spent on more effective expansion and stronger growth.

It would appear that most organisations are favouring the 'wait and see' strategy and find themselves burning precious fuel and time simply hovering above the ground instead of plotting a new course and moving ahead, albeit at a 'steady as she goes, Captain' pace.

So it's no wonder that there is some confusion of the role of the 'gung-ho!' multi-functional, assertive Project Managers and Business Analysts in this stabilising environment that 'maintains the status quo' at all costs.

PMs and BAs alike are confused about the skills and efforts required in these circumstances and are therefore equally unsure about what value they can deliver, while confined to their seemingly passive roles.

"I think our wagons have been formed into a defensive circle for so long, we have forgotten which way is forward!"

Senior people, in particular have become very frustrated and feel restricted in their implementation of new ideas and innovative projects. They know they can deliver more: more value to the clients and more value to the organisation. Certainly more value than the situation allows and they know this because they have already proved it in the past.

There is a very real risk that career advancement paths will quickly stall, especially for senior people. Once you have learned the basic skills of project management and business analysis and have had a number of opportunities to try, fail and put it into practice successfully, what next?

The Clock is Ticking!
Unfortunately from here, it can be a downward spiral. As time flies by, more and more Senior people are moved into low level positions, where they stagnate and then they don’t have the opportunity to show what they can really do. Everybody looses. Experienced PMs and BAs are marginalised, morale suffers, projects suffer, and the company don’t get the results they want from their efforts.

One option being considered, is to come up with new titles for senior people in the PM and BA roles to differentiate them from the crowd and to accentuate the increased value that they can deliver but I fear that this is just another example of 'name magic' and the acquisition of status and respect without undergoing the arduous task of earning it.

Risks or Benefits of Letting Senior People lead
Project success rates will increase if you have Senior people running your projects. People who are abley assisted by Business System Designers who can synthesise or simulate as well as analyse and calculate, to create effective system designs and applications that users like.

When Senior Project Managers have the assertive authority and sound experience to address and resolve problems and issues as they arise, with timely and focussed solutions, then ICT and development projects stay on track and deliverables will meet company expectations.

Let’s untie our Senior project managers and business analysts and see what happens. Take the brakes off! Loosen their shackles and give them more P&L responsibility. Plot a course for your next challenge and into the future growth of your organisation.

Leveraging the talents of senior people in project management and business analysis roles is going to make a huge improvement in project success rates and will take your organisation out of a hovering status quo, with an ICT exo-skeleton and into an assertive forward-thinking leadership, that is capable of creating and managing growth, innovation and business capability. Chocks away and full steam ahead!

Wednesday, April 22, 2009

Risk Management - 5 steps to success

What does it take to get Stakeholder attention and for IT initiatives to be acknowledged and accepted in today's lean mean enterprise?

In most cases it means making a compellingly attractive business case, getting the pertinent information to the right decision makers and being sure that its written in a language they can understand.

Executive suite
IT risk management initiatives are most definitely aimed at executive attention and for good reasons. The economy has become increasingly dependent on the Internet and IT systems (the Cloud). this makes the inherent risks in these systems far more visible and potentially more significant than ever.

Risk management is a discipline with a myriad mix of interests groups and stakeholders: CIOs, CFOs, enterprise risk management teams, compliance and regulation staff, and both internal and external auditors.

Choose your words wisely
You need to aim your plan at CIO level and there are generally two types of CIOs; the executive infrastructure managers and the strategic business thinkers. The latter will succeed with their IT risk management agenda because they speak in terms of business advantages, not technology outages (Business Impact Analysis). Par example;

  • Instead of talking about a "zero day threat," consider the impact of a potential incident, in terms of potential business losses. (Quantify in general terms)
  • Instead of talking about RTOs and RPOs, speak in terms of lost revenue and customers during an outage. (Sales, turnover, throughput, etc)
  • Instead of highlighting unimplemented ISO controls, speak about the lost communication and effectiveness of employees who need to collaborate and share information both inside and outside the firewall.
  • It also doesn't hurt to point out the impact on productivity when the critical path and workflow is disrupted.

Use a High-Medium-Low spectrum of potential business loss

Part of using the right language is to help you move away from absolutes. Inevitably, a single prediction of loss will start a battle of statistics and probability debate, with the risk that your request will get lost or bound up in the process. Instead, provide stakeholders with a variety of realistic scenarios and have some good data to back it up.

Start by considering whether you are a low risk company, moderately tolerant, or highly tolerant and then you can go to work with some calculations. Be prepared to back up your recommendations with numbers. Understand that you probably won't get exactly what you are asking for, but by presenting accurate potential scenarios, you might get your mid-range goal.

Use headlines to your benefit

All of today's business leaders have been shocked by the recent headlines regarding corporate scandals and the sudden loss of freedom or career prospects that this may bring. They dread the thought of the "orange jumpsuit retirement program." and there is still a steady stream of privacy and data leakage issues that will continue to feed into the headlines.

Those held responsible, willingly or otherwise, have ranged from; unsuspecting backup administrators and employees who unwittingly left laptops in car trunks; to mid-level managers involved in publishing quarterly financial reports and executives operating with full and certain knowledge of potential breaches.

You can make good use of these "publicly displayed sacrificial offerings" to illustrate and re-enforce the real risks at stake. This will help you move away from the discussion regarding the siza, shape and probability of an incident or event and break the statistical deadlock.

Move your message up and around the chain

Identify and consider the strong players and potential champions involved. Work hard to win them over to yor way of thinking. Rememeber, IT risk management isn't an exclusively IT-driven discipline. Work with the compliance team, the IT group, the legal group, the auditors, the enterprise risk management group, and the business leaders. Create cross-company initiatives to align each of these groups. This will require as much time communicating outside of IT as inside.

Identify your milestones

Before going into an executive meeting with your precious ember of a request, identify up to three milestones you expect to meet and explain in business terms how these milestones will provide real benefits and payback to both the business and IT.

If you can, start with a proof of concept e.g. for a content filtering project. This will have much more value if users from audit, legal and a line of business are involved in choosing terms to flag, track and quarantine events. A security 'incident reporting' process may get more enthusiastic response, if users understand that increasing their awareness will help to save the company money and protect the corporate image.

Conclusion:
IT risk management will become increasingly important as key organisational stakeholders begin to see the importance and effectiveness of an ongoing program. For now, IT risk professionals and their associated colleagues can continue to work to establish a baseline program by using the right language and the right information to ensure continued support internally.