Showing posts with label Board of Directors. Show all posts
Showing posts with label Board of Directors. Show all posts

07 August 2026

Reputation Risk: Organizational Stewardship Revisited...

Reputation risk is becoming more of a topic of discussion these days. The loss of reputation results in several outcomes both economic and personal. The fact is that most of the time organizations are "Reacting" to a crisis, news leak or some other corporate failure.

You don't have to name names of people or companies to understand the impact that reputation has on the success or demise of an organization. What has to change to lower the severity and likelihood of loss events associated with "Reputation"?

First you have to ask yourself a couple of key questions:

  1. What is your reputation worth?
  2. Are you being Proactive or Reactive in managing and safeguarding your reputation?

The PR and marketing communications processes in your organization may have certain facets of the solution to better reputation risk management. However, these processes are designed with out the consciousness of proactive threat anticipation, detection, prevention and remediation.

What has become more clear to executives in proactive oriented companies is the requirement for a specific and strategic approach to Reputation Risk Management. This approach encompasses an emerging theme from the early nineties pioneered by author Peter Block. We call it Organizational Stewardship.

Organizational Stewardship as a core guiding principle is the cornerstone in managing an institutional reputation risk management process. It has three components that support this rekindled idea of applying the concepts of stewardship to the organization:

  • Economic Accountability
  • Information Management
  • Business Integrity

Reputation Risk Management is about the proactive monitoring and management of a portfolio of threats in the organization. Several categories include:

  1. Intellectual Property and Information Assets
  2. Demonstrations, planned boycotts and social activism
  3. Physical infrastructure including employees and suppliers
  4. Legal threats including class actions, insider trading or whistle-blowers

Microsoft closed its free Internet chat rooms in 28 countries many years ago because of threats from pedophiles and junk e-mailers. This is an example of proactive reputation risk management. Unfortunately, this has opened the door to another related threat of hackers hijacking other Social Media accounts.
"Organizational Stewardship is a guiding principle. Once it is embedded into the organization it begins to permeate the mindsets of the individuals who are responsible for the conscious reputation risk management processes. Over time, these individuals help influence the corporate mindset, philosophy and ethics to a new found level."
Someday soon the executives in the board room will realize that managing reputation is not about keeping secrets and fighting fires. 

They will realize that they need to find a proactive, preventive and relevant strategy for achieving Organizational Stewardship in their company.

07 May 2023

Volatility: Enemy #1...

Organizations implement Operational Risk solutions to lower "volatility" in earnings growth and return on capital. The focus on volatility is because no institution likes to see peaks and valleys in their earnings or their return on capital.

A steady and consistent growth curve without "Volatility" is the goal by many steadfast organizations.

Contrary to the goal of minimized "volatility" there are also those who feed off of the chaos and the large swings between these highs and lows in the marketplace and with specific companies in vital sectors of the financial economy. Will another Blueprint for Regulatory Reform be the answer?

As a hedge fund investor, can you explain what the strategy is for your investment fund? Do you know what your money is being invested in?

Does your hedge fund manager provide transparency on calculating your return on funds invested? What was the reason you invested in alternative investments to begin with?

Carrying this analogy to the operational processes within your organization, the goal is to keep the processes running smoothly. When people or systems deviate from the agreed upon "Rule Sets" then change ensues along with the volatility of the performance measures.

Errors, Omissions and systemic "glitches" are the catalysts to volatility that creates fear, uncertainty and doubt.

Do you understand the Math? When the process gets to this stage and people don't trust the rules anymore, you are on the brink of a failure and impending loss, in dollars and/or peoples lives.

Operational Risk Management is a discipline that is remerging in our corporate ranks because it has already proven that it saves lives. The regulators and inspector generals are going to raise it’s mandate within our institutional ranks once again.

The "Rule Sets" of playing business in the financial, health care and energy sectors are not the only ones being subjected to this increased scrutiny and renewed focus on OPS Risk as lessons were learned over 15 years ago:

“In March of 2008, the Department of Defense learned that four non-nuclear nose cone assemblies and their associated electrical components for a ballistic missile where mistakenly shipped to Taiwan in the fall of 2006. These items were originally shipped in March 2005 from F.E. Warren Air Force Base in Wyoming to the Defense Logistics Agency warehouse at Hill Air Force Base in Utah. There are no nuclear or fissile materials associated with these items.

Upon learning of the error, the U.S. government took immediate action to acquire positive control of the components and arranged for their safe and secure recovery to the United States. These items have been safely returned to the United States.”

After this event, lessons learned and “After-Action-Reports” were generated in the ranks of the U.S. Treasury Department and the Department of Defense all relating to the failure of People, Processes, Systems and or External events.

Operational Risk is all around us and continuously ready for prime time focus in terms of our leadership strategy execution, implementation and measurement.

Whether you utilize Operational Risk Management (ORM) in the Defense Industrial Base or in another Critical Infrastructure sector in the United States, it’s important to revisit what it is NOT:

Operational Risk is Not:

  • About avoiding risk
  • A safety only program
  • Limited to complex-high risk evolutions
  • A program -- but a process
  • Only for on-duty
  • Just for your boss
  • Just a planning tool
  • Automatic
  • Static
  • Difficult
  • Someone else’s job
  • A well kept secret
  • A fail-safe process
  • A bunch of checklists
  • Just a bullet in a briefing guide
  • “TQL”
  • Going away

The goal of Risk Management is not to eliminate risk, but to manage risk so the mission can be accomplished with minimum impact...

18 March 2023

Reliable: Who Do You Have Faith In?

When you think of the person you would recommend for a particular task or to perform defined professional services, who comes to mind?

There are many ways and words to describe a person or the business, yet if you had only one word to choose from, what would it be?

Reliable  adjective

1: suitable or fit to be relied on: DEPENDABLE

2: giving the same result on successive trials

Reliable noun

1: one that is reliable

In many cases, this is the word people really mean to use, as the basis for their recommendation.

Whether a business or a person is reliable, makes all the difference in your world, especially if you must rely on the outcomes of their service or duty.

When someone or something you pay for, does not meet a series of positive results, you begin to question your decision to utilize the service or receive the product for use.

Unfortunately for many people and businesses, this word “Reliable” is not considered or even measured on a consistent or measurable basis.

"Over the course of time in your life, think of one person or business you could say was truly reliable."

Think of this one person or business you have utilized for more than ten years that is reliable.

In any professional capacity, becoming reliable takes many years of practice and substantial learning. It requires the development of people, processes, systems and real innovation.

Now, think about someone or an entity (business, product, government agency) that you have lost faith in.

The people or businesses that you have stopped interaction with, have become “Unreliable” for your particular requirements or expectations of quality of service.

How would our world change for the better if there was more learning and focus on being “Reliable”?

How can you as a person or business become top of mind, when someone is asked “Who would you recommend” to: _________________?

You too, can become truly reliable…

31 December 2022

Twenty 23: For All Mankind…

Remember where you were 365 days ago.

2023 is now at our global doorstep. What journey will you embark on this next year to grow your skills and your knowledge?

How might you as an experiential learning enthusiast, leverage what you know to help others on your team, and in your community?

Your mission has always been to improve, to perfect and to deliver results. In 2023, what if you began looking through a different innovation lens?

Look around. What does your personal environment of your own dwelling say about you? Is there any room for change or improvement?

How would you rate your realm of relationships with family, friends and relatives this New Years Eve? Think about it…

Now transition to your community and assess whether you are in the right neighborhood, the correct city and even in the best state in the USA for your profession, and the work you are now inspired to perform.

"2023 will become a pivotal year for you in so many ways."

Our global future is bright and your next focus will be all about your contributions to a greater good in this world.

  • With over 9 billion web-enabled personal digital devices in global circulation, how we learn from the Internet and new quantum Information Technology will continue to amaze all of us.
  • Our Earth is sending us signals on regular intervals that our natural disasters are truly accelerating.
  • Will mass global population growth continuously change our supply chains for food, mining of rare earth elements and sharing our scarce fresh water?

"Look up in the early evening clear blue sky as the sun sets. See all those shining stars beyond our Moon."
“For All Mankind”
have a more meaningful 2023.

19 November 2022

OPS Risk: 7 Revolutions on our Horizon…

The holiday season is almost upon us. One only has to look into the mirror of 2022 to see the trajectory of our world.

Our digital globe is preparing itself for the next major breakpoint in its history of commerce and business.

Our organizations are in anarchy and the consumers of our products and services are shifting before our eyes.

You only have to look back on the past years major headlines of the Washington Post to gain some perspective on where we are headed in the next 12 months.

Social consciousness is seeping into the workplace and management is keenly aware of the accelerating change factors on the corporate doorstep for 2023-24.

Several new waves of incremental change are upon us. As providers of products and services to the consumers of the planet, whether businesses or individuals, the writing is on the walls of the corporate boardroom: Survive.

The tides of change are now upon us. Look no further than the Seven Revolutions Initiative. [See 7 Revs] The social, technological and demographic facets are enough to make anyone wonder where we are all headed in the next 20 years.

Our Critical Infrastructure industries are putting the building blocks in place to sustain a dramatic shift in who their customers are today and whom they will be tomorrow.

2023 will be another year of corporate malfeasance, seeded with wondrous accounts of incivility. Spawned by the empowered employee to become a whistle blower and a bold new generation of inside crime fighters.

Our generations of young workers and consumers on this planet will pay for something they can believe in, rather than something that is socially and morally bankrupt.

They will work all day in the global banking software development department and work late into the night, developing the next binary code to impress their peers on the other side of the world developing the latest ransomware on the Internet.

They will design the new marketing campaign for the next gas guzzling 4-wheel drive SUV by day and ride home that same evening in their brand new foreign hybrid using electric power.

2023 will be a year of heightened sensitivity to security and exponential asymmetric warfare.

Our dated processes and systems will be adjusted and tweaked to accommodate the planets morphing threats by a new force of true “Innovation Navigators.”

The Board Room Buzz will be more about how to protect those vital corporate assets and simultaneously how to survive our next crisis.

What may be most interesting, is how the governments of the world now cooperate to become more of a global partner on this front.

We sense already a growing cooperation among world leaders to deter and defend our citizens from the spread of a tyrants fear and uncertainty.

Finally, 2023 will be another year we find greater appreciation for:

  • The evening glimmer of sunlight across a body of clean water. The wave from the neighbor who lives next door or across the street.
  • Our faith in what or whomever we believe in. Those who serve, so we can remain free of threats or illness, to our loved ones and our own well-being.
  • The signs that our bodies are healthy. The hope that exists in all of us, for finding a greater peace of mind.

In 2023 and beyond, look with fresh eyes on everyday things…

13 August 2022

Mechanisms: For Continuous Risk Monitoring...

One of the systemic problems at large institutions including organizations like your own Fortune 500 Global company is keeping your finger on the pulse of "Risk Indicators".

Unfortunately for SVP's and other executives in the corporate hierarchy, your middle managers are creating the layer that impedes the best "Early Warning System" you may have at your disposal.

When problems surface on the front line or over in the "Cube City" in some Telephone Call or Information center on the other side of the globe, or across your new "Work-From-Home" (WFH) team, the normal agenda is for the employee to go to their direct supervisor to raise the "Red Flag" or disclose the incident. Perhaps the first behavioral response by the Middle Manager is to keep it quiet. Fix it before anyone else finds out. Keep it under wraps until damage control can be implemented.

When you are the Head of Enterprise Risk Management, you need mechanisms to bypass and eradicate the barrier holding your intelligence, incidents and overall hunches for ransom. There is no magic system or process that will solve it all. Yet, the only way to attempt at breaking through this layer of social and organizational dysfunction is to circumvent it.

A continuous risk monitoring system has to be implemented and operating anonymously 24/7 in concert with the Security Operations Center (SOC) if the upper echelons of executive management are ever going to "Feel the Pulse" of risk hotspots in the company.

These hotspots translate into true "Risk Indicators" from the sources themselves, people who know what's going wrong and know the ground truth. An internal Continuous Risk Monitoring System (CRMS) is an automated human feedback and problem identification mechanism for detecting insider risks. It allows leaders of large organizations to quickly identify problems and incidents of all kinds in their company. Call it a sophisticated whistle-blower system or even suggestion box but that is exactly what it is, on steroids.

The ideal CRMS system would emulate communication patterns in small groups which is often a major ingredient in successful teams. It would also run on the existing computers and networks of the organization or from home by logging in via an internal VPN. The soldiers on the front line know what is going on far sooner than the commanders in the Joint Operations Center just as the employee or supplier does and they need a way to communicate the issue, concern or threat in a rapid and efficient manner.

"The system provides the executives with instant or trend based intel that is actionable. It provides the "Insight" as well as the pertinent facts that you need to make more quick effective decisions."

Think about how long it takes for data and information to percolate and bubble up from the places in your organization that are considered "Current Risk Hot Spots". The point is that for far too long we have been playing the old telephone game.

You know, the one that you played as a kid sitting around the kitchen table or on the floor in a circle. One person starts and whispers into the ear of the person to there right. Just a sentence or two. By the time the message gets around to the 3rd or 4th person, now the data is dramatically different than the original. It's been interpreted, edited and sanitized.

Walk down and visit the person who is in charge of the anonymous 800# or “electronic suggestion box” or perhaps the official whistle-blower program at your organization.

Ask them for an activity log. Ask yourself how you could get this mechanism to perform better and then work with your front line to develop something that middle management can't filter, change or delete. That is when you will be well on your way to getting TrustDecisions in real time…

23 July 2022

Innovation: The Speed of Exploration...

Why does your organization encounter Operational Risk events that have caught you off balance, off guard or created substantial losses to shareholders and major stakeholders?

There are people in your organization right now that are still without the tools, the training or the methodology to solve new significant problem-sets.

More vital, is that your organization is not proactively generating new innovative ideas, new solutions and new answers to your own operational risk issues.

innovation - noun
in· no· va· tion | \ ˌi-nə-ˈvā-shən
Definition of innovation
1: a new idea, method, or device : novelty
2: the introduction of something new

To truly innovate a new product/solution, you must first do your research. Your field study. You must get out of the building and ride in the field.

Show up on the front lines of your business unannounced. This is nothing new, yet it works and it is amazing on what you will learn.

You have the awareness of why this method of discovery is the basis for better understanding the problem-set(s).

So why as the leader in your small business or Fortune 500 Global enterprise do you ignore or delegate the true innovation mechanisms in your company to just a few people.

Why have you loss sight of the mandatory Recruiting, Education, Networking and Sharing metrics by your front line teams?

Discovering, researching, prototyping, practicing, refining your methodology to more rapidly respond to threats, to your competition, to possible opportunities.

You see, you and your organization have become complacent. You have not changed your onboarding experience of new employees or new customers in over a decade.

Why is it true, that most people and organizations don’t focus on innovation and new solutions to a problem, until there is a significant loss event.

An incident that hits the local headlines. A risk event so damaging to the bottom line it could mean closing the business forever.

How might you design the methodology and the system in your enterprise to have continuous problem and threat monitoring, new innovation?

It begins with the right people working on the initial prototype together with the correct tools. It means getting senior management on board with facilitating the process to insure the prototypes are tested in the field or Area of Responsibility (AOR).

Next, those individuals who are in charge, in command, at the field level must have the resources and the authority to test, to learn and to gather new data continuously.

Your organization is slowly decaying right before your eyes. Your adversaries are winning.

It has lost its initial purpose because you have not been continuously innovating on the front lines. In the geography and in the organizations of your own neighborhood.

The next time someone in your organization sends you or presents to you a Powerpoint funding proposal with more than 5 pages, with more than 4 bullets on each page without any true graphical data, you know you have to engage.

Filling in the standard forms in your CRM or your word.docx template on a monthly basis might be OK, if it calls for truth and relevant data from the front lines, yet is it focused on the real problem-sets?

How might you and your team change the way you are working on the front lines of your organization? Soon.

Why will you engage differently, before it is too late. What is the Speed of your Exploration?

26 March 2022

Human Behavior: Witnessing Salvation…

When you accelerated through the career ranks of your organization and you achieved all of the goals and challenges in front of you for a year or two, what typically happened?

You were promoted.

Now, when you were given this new title or rank this usually included new responsibilities, new relationships to be managed and in some cases a feeling of additional power within the organization.

Then what happened to your self-esteem?

This confidence and satisfaction in oneself is a valuable topic for dialogue in developing great leaders. Especially when together we witness a leader whose behavior is unjustified and abuses their given power.

Human behavior will not ever stop surprising us, even after we think that we have seen it all:

  1. Just when we think we have witnessed all of the good in life, we see an act of kindness and good will that we never saw before. We stand there in amazement as we watch salvation in real-time.
  2. Then there is the daily news. You read a story about an act of pure evil and you ask yourself, how could another human being actually do something like that?

Whether the truth is on the front page of the Washington Post or from a witness who tells the story from their first hand experience in the room, or on the front lines, how will you act? More of #1 or #2.

The self-choice of actions you take next and the demonstrated evidence of your own behavior is an indicator of your true character. Of who you really are as a human being, operating in your organization.

Over the course of your tenure with that logo on your business card or the patch on your shoulder, never forget your true character.

You have the opportunity to continuously perform and who your colleagues will follow, that your organization is proud of each day for all of your excellent actions.

“As you build your own “Self-Esteem” and confidence and satisfaction with oneself, remember #1.”

Your team or organization as a whole, will rise together to acknowledge your kindness, empathy and yet your faithful ability to accomplish so many important milestones.

Thank you for being #1. Onward!

29 January 2022

Cyber Reality: Quest for the Digital Castle...

On this Saturday morning the prayers are silent. For family, friends and also for the subject matter experts in business and the U.S. government.

They have been waking us up again to the reality of the Operational Risks we now face, to our ubiquitous digital-based economic infrastructure.

The message is clear to those insiders, who have been trying to defend our "Digital Castles" against tremendous odds of these seemingly invisible threats. Is it really, game over?

The short answer is yes. The current mindset should be, that every major business of valuable interest in the eyes of the enemy has already been compromised or soon to be. It is already too late. The stealth digital code is currently waiting in the shadows of your organizations hundreds or thousands of digital assets.

Whether it is the aging Dell Tower Desk Tops still running on Windows XP somewhere or the latest Android PDA/Apple IOS devices tethered to the corporate network does not matter. Your adversary has control of when and where to begin the attack on you and your organization.

So if this is the reality of the global state-of-play, in both the business world and also to government, what should the risk management strategy consist of going forward? How could we ever get to a point of advantage over those who seek to do us harm?

So internally, the prudent corporate business strategy should be for your General Counsel and the CIO of your organization to be already preparing themselves for the day that they will step before the press conference microphone to disclose the material breach of the companies intellectual capital or theft of assets.

They should already know, that it is just a matter time and not a denial that it will ever happen on their watch. If you are a Board Director and you still have not had "The Talk" with management about this stark reality, then you too are complicit in the scheme to present your stockholders and stakeholders with a false sense of confidence that you are safe and secure.

The new normal for forward thinking organizations is already being implemented for adverse events. The Crisis Management Team has already exercised the "Data Breach" scenario numerous times.

Your General Counsel and Chief Information Officer have rehearsed and practiced their testimony before opposing and adversarial questioning of your organizations information security processes.

The company subject matter experts are more than prepared to submit evidence of their best practices, industry standards compliance and previous tests of due diligence. The stage is set for the court room battles ahead:

The quest for the "Digital Castle" has been going on for years. Are you awake now or still living in a dream of denial on your state of achieving a Defensible Standard of Care…

20 November 2021

Metadata: Guardians on the Front Lines...

Continuous Continuity (C2) in your particular enterprise is a priority you shall not just focus upon during our U.S. Infrastructure Security Month.

Last week here, we reviewed Ten Steps your organization can practice on a regular basis to enhance your focus on Continuous Continuity and simultaneously your overall Operational Risk Management (ORM).

Let’s circle back to a few vital areas to emphasize as we increase our production and consumption of corporate or organizational “Data”.

Of Metadata. “Data that provides information about other data”.

The details on the creation date, time and application generating these words as they were originally written, is just one small example. What about the actual platform and the browser that was used:

User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:94.0) Gecko/20100101 Firefox/94.0
Screen Resolution: 1680 x 1050 (pixels)
Browser Dimensions: 1005 x 853 (pixels)
Cookie Status: Enabled

You understand that the data you can’t see on your screen and the data you may not even care about, is present, and that the metadata is being collected by some entity somewhere.

The amount of data and the speed of data is now overwhelming our global digital world we live in the year 2021 and beyond. The question remains, So What?

If you are a seasoned General Counsel (GC) today with a Fortune 1000 organization doing business on a global basis, your Blackberry :) must be "buzzing" every few minutes. Just the legal risk alone being encountered will always be a factor of the number of deals, the number of employees and the growing number of countries you are operational.

As a corporate GC of a global enterprise, you have a fiduciary responsibility to protect the enterprise from all adversaries, such as the rogue employee, the government regulator, competitors, digital hackers, nation states and all of the plaintiff class actions.

The Rule of Law in your organization is in your hands. How you transfer the "Talking Points" on ethics, compliance and legal messages to your employees, partners, suppliers and adversaries is ever more critical.

The true effectiveness of your relationship with internal partners such as your CEO, CFO, CSO, CISO and Internal/External First Responder leadership could mean the survival of the company itself.

When was the last time you as a GC took the “Ethics," “Compliance” and "Rule of Law" program directly to your employees in face-to-face sessions?

How might you provide your employees, partners or 3rd-Party suppliers with the first hand opportunity to meet, greet and engage with the General Counsel of your particular enterprise?

By doing this, you are directly engaging with the people on the front lines, to be our "Guardians" for your company and to build trusted relationships with all of them.
Get out There.

19 December 2020

ITC: Managing Risk for Security Governance...

 In our converging world of both Information and Physical Security, there are resilient risk elements for the effective management of Information Technology & Communications (ITC).

Think of it as “Security Governance”.

Security Governance is a discipline, that all of us need to revisit and rededicate ourselves towards. The policies and codes we stand by to protect our critical assets, should not be compromised for any reasons. More importantly, security governance frameworks, must make sure that the management of a business or government entity be held accountable for their respective performance.

The stakeholders must be able to intervene in the operations of management, when these security ethics or policies are violated. Security Governance is the way that corporations or governments are directed and controlled. A significant element that is now being mandated by the Board of Directors, is the role of “Continuous Risk Management” in Security Governance.

ITC Security Governance, like Corporate Governance requires the oversight of key individuals on the Board of Directors. In the public sector, the board of directors may come from a coalition of people from the Executive, Judicial or Legislative branches.

The fundamental responsibility of management, whether in government or the corporate enterprise, is to continuously protect the assets of the organization or entity. Risk and the enterprise are inseparable. Therefore, you need a robust management system approach to continuous Security Governance, not just an annual audit.

If a corporation is to continue to survive and prosper, it must take security risks. A nation is no different. However, when the management systems do not have the correct controls in place to continuously monitor and audit enterprise security risk management, then we are exposing precious assets to the threat actors that seek to undermine, damage or destroy our livelihood.

An organization’s top management must Identify, Assess, Decide, Implement, Audit and Supervise their strategic risks. There shall be a strategic policy at the board level to focus on managing risk for security governance.

The security governance policy should mirror the deeply felt emotions of the organization or nation, to its shareholders and citizens. It should be a positive and trusting culture, capable of making certain that strategic adverse risks are identified, removed, minimized, controlled or transferred.

An enterprise is subject to a category of risk that can’t be foreseen with any degree of certainty. These risks are based upon events that “Might Happen”, but haven’t been considered by the organization. Stakeholders can’t be expected to be told about these risks because there is not enough information to validate or invalidate them.

However, what the stakeholders can demand, is a management system for continuous Security Governance that is comprehensive, proactive and relevant. The management system includes organizational structure, policies, planning activities, responsibilities, practices, procedures, processes, and growing resources.

It is this Security Governance management system that which we all should be concerned and which we seek from our executives, board members and oversight committees to provide. There should be a top management strategic policy to focus on managing risk for continuous security governance.

This risk management system should establish the foundation for ensuring that all strategic risks are identified and effectively managed. The policy should reflect the characteristics of the organization, enterprise or entity; it’s location, assets and purpose. The policy should:

1. Include a framework for governance and objectives
2. Take into account the legal, regulatory and contractual obligations
3. Establish the context for maintenance of the management system
4. Establish the criteria against what risk will be evaluated and risk assessment will   be defined

A process should be established for risk assessment that takes into consideration:

  • Impact, should the risk event be realized
  • Exposure to the risk on a spectrum from rare to continuous
  • Probability based upon the current state of management controls in place

The strategic security risks that the organization encounters will be dynamic. The management system is the mechanism by which the executives identify and assess these risks and the strategy for dealing with them. It is this system which we are concerned about and which we seek to provide in order to achieve our Security Governance.

ITC Security Governance best practices are still rapidly growing and taps the thinking of various standards organizations including OECD, BSI, NIST, ISSA, BSA, ITAA, ASIS and dozens of other bodies of influence and knowledge. However, no matter what best practices an organization attempts to standardize on, beware of the attitudes of the employees and stakeholders.

Unless these stakeholders fully acknowledge what and why, they are being asked to do things, rather than just following the rulebook, the system will fail.

The organization that embraces change and introduces a Security Governance framework that not only manages the foreseen human risks, but also the unforeseen, will have a greater chance of survival.

The role of culture in the risk for security governance, is paramount for several reasons:

1. Any changes in risk management may require changes in the culture
2. The current culture is a dramatic influence on current and future security initiatives

Internal controls can provide reasonable assurance that an organization will meet its intended goals. At the same time, it is the people (Human Factors) who will fail the company in material errors, losses, fraud and breaches of laws and regulations.

This is why the risks the organization is facing are constantly changing and therefore why a management system for continuous security governance is necessary. The management system is there to provide resiliency to the risks it encounters and to control risk accordingly rather than eliminate it forever.

The board of directors will soon realize that managing risk for ITC Security Governance, is just as important to the success and compliance of the organization as Section 404 of Sarbanes-Oxley.

In fact, without effective ITC Security Governance in place, all of the rules won’t matter and the stakeholders will again be asking themselves after a major technology failure or privacy data or intellectual property breach; how could this happen to us?

08 November 2020

Supply Chain Resiliency: Operational Risk Priorities in 2021…

Global Senior Executives are evaluating the resilience of their organizations international supply chains and realize the growing Operational Risks.

Why have proactive Enterprise Risk Management teams been on high alert and how are they working the issues for over the past nine months?

These are evident clues in just one one 10-Q example:

“We rely on sole direct and indirect suppliers or a limited number of direct and indirect suppliers for some or all of these components that we do not manufacture... Many of such direct and indirect component suppliers are geographically concentrated, making our supply chain more vulnerable to regional disruptions...we have experienced and continue to experience disruptions in our supply chain due to the impact of the COVID-19 pandemic.

If our direct and indirect vendors for these components are unable to meet our cost, quality, supply and transportation requirements, continue to remain financially viable or fulfill their contractual commitments and obligations, we could experience disruption in our supply chain, including shortages in supply or increases in production costs, which would materially adversely affect our results of operations.”

Inventory Management, Supply Chain Transparency and Single Source Suppliers are just a piece of a complex mosaic for many multi-million dollar U.S. businesses.

Covid-19 catalyst “Operational Risk Management” (ORM) has been a mainstream focus for months, just as it does after every major catastrophic event.

Yet, when the implications of downstream impacts to our critical infrastructure sectors such as transportation, healthcare and the continuous ICT challenges become even more apparent, the Global Executive suites must go into action.

The concepts of “Supply Chain Resiliency” are well known, yet it is continuously surprising how many organizations in 2020 have been caught off guard or are finding themselves without substantial alternative strategies to remain operational.

This is a result of diminished due diligence and a continuous analysis with your Tier 2 and Tier 3 suppliers.  Mapping each of your key lines of business with a detailed understanding of Where, How and Who your suppliers do business with, is just the beginning.  What about your own actions on:

  • Increasing Inventory Levels
  • Pursuit of Diversified Suppliers
  • Finding New Suppliers with “Robust Supply Chain Resiliency”
  • Increasing Your Geographic Diversity of Suppliers

In a recent Interos Inc. report (https://www.interos.ai/resource-library/ ) of 450 executives surveyed in the U.S. on their “Biggest Risks”, the following results were found:

  • 76% identified COVID-19 as the biggest ongoing risk, followed by cyber threats at 44%, restricted or sanctioned entities at 36%, natural disasters at 30%, and single supplier or country concentration risks at 28%. Other risks fell below 20%.  
  • This follows roughly the same order for future risks, with 66% identifying COVID-19 as the future risk companies are preparing for, followed by cyber risks at 48%, restricted/sanctioned entities at 34%, and geopolitical events at 32% (this was the largest jump from 20% now to 32% in the future). 

If these results are even close to being a high priority, then your own “Supply Chain Resiliency” shall be a well funded and continuously measured Business Unit within your Enterprise, in 2021 and beyond…

18 October 2020

Organizational Integrity: Leadership of Risk…

As a leader in your organization, how long have you truly demonstrated the actions you desire for those who are following you?

Countless times each day, leaders in the global race to the finish line, ignore or disavow the rules or policies they enforce for their own team.

What are you demonstrating in your organization today and this week to build “Organizational Integrity”?

How are your own behaviors in the midst of your team, showing and reinforcing the actions that will build and activate a model of “Organizational Integrity”?

integrity
noun

in· teg· ri· ty | \ in-ˈte-grə-tē

Definition of integrity

1 : firm adherence to a code of especially moral or artistic values : incorruptibility
2 : an unimpaired condition : soundness
3 : the quality or state of being complete or undivided : completeness
Why have you made the decisions that you are more privileged than the others on your team?

Is it your personal sense of ego or power as a figure of authority, that makes you feel as if the activities and rules for you, do not apply or are different than for those who are on the front lines?

They are not.  In the midst of a legal deposition or worse, the leader who is charged, explains their own behaviors.  This is now beyond the point of no return.

Even when you are behind closed doors of the “Board Room” or the “Ready Room,” are you demonstrating the same behavior and adherence to the processes, that you wish upon all those you are leading?

Leadership of your “Executive” Team or a “Squad of Specialists” in the field, requires people who truly “Walk-the-Talk” and adhere to the same standards or rules set forth for the entire organizational operations.

You already are known as a “Leader” in your area of expertise.

Yet are you known as a leader with “Integrity,” that truly demonstrates this in the middle of your operations each day?

12 July 2020

Incident Response: Leadership of Security Risk Professionals...

Leadership of Security Risk Professionals (LSRP) begins with a thorough understanding of the current state of the “Organizational Pulse” of the corporation.

Global Enterprise Business Resilience does not just happen overnight, after the CEO sends out the first Crisis-based e-mail alert.

It happens because the Organizational Pulse of the respective silos of responsibility, have been actively learning for years about their People, Processes, Systems and External Crisis Events.

Simultaneously, as the leaders of the Security and Risk domains within the enterprise “Ask”, “Listen”, and then “Clarify” or “Verify” vital information, the organization learns.

Global 500 public organizations, small private businesses and non-governmental organizations have true stories and cases that are considered a security risk crisis.

Confronting a crisis and incident response in one organization will be completely different at another, based upon the type of organization, number of employees, geographic locations and their senior executive process for dealing with a significant disrupting event.

The following question was asked at “Company A” and the top answers were:

What are the top five incidents/events that could cause a significant crisis within your organization?

  • 
Fire or Flood
Violent weather/damage to facility
  • Workplace violence
  • Industrial accident
  • Terrorism
"When the question was asked a different way, to a different group at the same company, the results were even more telling:"
What are five incidents/events that have caused your organization significant crisis in the last three years?
  • 
Counterfeit products or major disruption in the supply chain
Alleged ethics violation of Foreign Corrupt Practices Act (FCPA)
  • Geopolitical unrest in key overseas markets
  • Extended loss of personnel at a manufacturing plant due to COVID-19
  • Data Breach/intellectual property theft by a nation state
Senior executives charged with a “Duty of Care” in todays global enterprise, require new thinking, enhanced skills and relevant solutions to improve crisis leadership.

What is your current readiness factor for the potential of environmental or natural disaster, supply chain disruption, economic espionage, ethics scandal, data breach, employee kidnapping, sabotage, terrorism, workplace violence and other legal risks?

For example, the HR recruiter is more focused on the security risk of hiring a person with a criminal record of violence and substance abuse problems. The Chief Security Officer (CSO) is more focused on the physical and information security of facilities and the Chief Operating Officer (COO) may be more focused on daily operations and securing the resilience of the supply chain.

Throughout the enterprise the functions of physical security, information security, legal and financial liability have all become specialized and these same security risk professionals, have become subjected to the potential for a blindside incident.

“Leadership of Security Risk Professionals” (LSRP) is for industry practitioners to “Cross the Chasm” of crisis leadership...

08 February 2020

Business Risk: Grow or Die...

In a previous issue of Corporate Board Member magazine in a PwC survey, the question is asked:

Has your board discussed what to do if the company is hit by a major Crisis?

  • No - 51%
  • Yes - 41%
  • Not Sure - 8%
What is the definition of "Crisis" in the minds eye of the Board of Directors today?

n. pl. cri·ses (-sz)

1. A crucial or decisive point or situation; a turning point.

2. An unstable condition, as in political, social, or economic affairs, involving an impending abrupt or decisive change.

3. A sudden change in the course of a disease or fever, toward either improvement or deterioration.

4. An emotionally stressful event or traumatic change in a person's life.

5. A point in a story or drama when a conflict reaches its highest tension and must be resolved.


How can these numbers be correct? Why don't these results make sense?

It does seem almost impossible that just over half of those surveyed said, that they have not discussed what their company would do in the event of a crisis.

In light of the latest corporate governance and catastrophic events any board member who would answer no, is either not attending the meetings or is so new to the board, that they haven't been part of the conversations yet.

The Pwc survey of 1,103 directors who responded have illustrated many of the risk management issues that are taking up much of the shareholders time.

They also indicate where they wish they were spending more time, as 59% hoped they could be doing more "Strategic Planning."

Is there a correlation between those who have not been part of discussions of crisis management and the wish to focus more on strategy?  We hope there is.

Our experience is that corporate management and the board need a 3rd party facilitating the mechanisms for change and towards the "Big Picture" of the future.

If management sees the board as an overzealous parent and not working on behalf of the shareholders the tension increases.

Once the board and corporate management have found a "strategic facilitator" to guide them towards a model of "Enterprise Architecture" everything becomes crystal clear.

The factions now see the blueprint for change and the path to implement the strategy and the tactics to achieve it.
The Importance Of Leadership In Uncertain Times

In an age of global unrest, strength and courage at the helm are more important than ever. As a director, it's your job to ensure your CEO has what it takes.
At the end of the day, the deliverable is to continually grow and whenever that significant crisis or "Breakpoint" occurs, the engineered resilience of the business enables its survival and the next phase of growth to begin...

15 September 2019

Never Forget: Beyond 9/11 & Adapting Inside the Enterprise...

"Being a patriot doesn't mean prioritizing service to government above all else.  Being a patriot means knowing when to protect your country, knowing when to protect your Constitution, knowing when to protect your countrymen, from the violations of and encroachments of adversaries.  And those adversaries don't have to be foreign countries."  Ed Snowden

One could wonder whether even just one of the individuals working with your organization internally or externally has the same or similar mindset of "Ed".  The question is, what are you doing as an Operational Risk Management(ORM) leader, to be legally proactive in your "Insider Threat" approach with employees, partners and your extended supply chain?

The adversary working with you inside your company, agency or partner, doesn't always start out to bring loss events to your enterprise.  It could take years, or months to develop a real justification in the adversaries mind, yet even when the activities and behaviors are evident, they are all to often missed, never understood or just too late to interrupt:
The National Counterintelligence and Security Center (NCSC) and the National Insider Threat Task Force (NITTF) are today partnering with federal agencies across the government to launch “National Insider Threat Awareness Month” during September 2019. Throughout September, the Office of the Director of National Intelligence, the Department of Defense, the FBI, the Department of Homeland Security, the Department of State and other federal agencies will be holding events to emphasize the importance of safeguarding our nation from insider threats and to share best practices for mitigating those risks.  
How could you and your organization improve and adapt your current practices to raise the bar of excellence?  What can you do each day to make the quality and the results of your programs even better?

First, begin to understand the process by which events can trigger new behaviors in an individuals perceived stressors and lack of personal control.  Second, expand your proactive organizational toolkit, to include such proven technologies such as sentiment analysis for marketing purposes.

These same tools with the proper legal oversight and "Acceptable Use Policy" can be effective in your early warning systems.  Enterprise Risk Management also incorprates oversight and protections for privacy and civil liberties.

Here are five steps to be proactive at your organization in the U.S. this month of September 2019:
  • Create, refine and share your organizations "Insider Threat Program "(InTP) vision.
  • Educate, clarify and communicate the authorities, roles and policies of the program.
  • Validate tools, models and sources of information.
  • Plan ahead for the utilization of automated tools and human behaviors observed.
  • Seek better solutions to a continuously changing enterprise & supply chain environment.
Never Forget.  We have all heard the thought "Never Forget," when it comes to our recent anniversary of 9/11.  Yet we must simultaneously remember, that our adversary may be hiding in plain sight...

04 May 2019

Neurodiversity: Leveraging the Capital of the 4th Industrial Revolution...

"Grasping the opportunities and managing the challenges of the Fourth Industrial Revolution require a thriving civil society deeply engaged with the development, use, and governance of emerging technologies. However, how have organizations in civil society been responding to the opportunities and challenges of digital and emerging technologies in society? What is the role of civil society in using these new powerful tools or responding to Fourth Industrial Revolution challenges to accountability, transparency, and fairness?"  World Economic Forum

Is automation the current answer to all of our problems?  When will the research tell us the true impact of too much "Screen-Time" on our brains?  What will be the next terror incident in our society, that is "broadcast live" over the Internet?

These questions and more, are on the minds of community leaders in government, the R&D scientists and also the Chief Operational Risk Officer of your organization.

Our cultures, innovators and tools are on a major collision course, that will prove to be more challenging than we could ever have anticipated.  Even those working in the early days of the IBM Watson project, would probably tell you of their fears of the future.

Yet our youth across the globe, are being submerged in technology and software interfaces so early in life, that they may not learn how to think or work in manual/analog mode.  They will only have the creativity to code or to automate with software, unaware that history may have accomplished some of the same tasks without software, hundreds of years ago.

How might the older generations teach the younger generations about the way it used to be done?  Why would we even try to do this in a more manual method or process?  To provide context and generate cognitive creativity.

The truth is, that educators believe that innovation of technologies is driving their curriculum and our communities own economic development.  The impacts of automation and technology are being continuously researched in the wave of change known as the "Fourth Industrial Revolution".

These trends have significant risk implications on our workforce and the future opportunities of the vocational education and training of our future force.  This is clearly evident across our communities, business entities, military service and government policy.

The rapid adoption of digital innovation has impacted the requirements of certain knowledge workers to be more versatile.  They must be more adaptive, collaborative and have expanded skill-based capabilities for problem-solving.

Do not underestimate the importance of the soft skills and people skills for continuous development and reducing risk.  Simultaneously, we must understand the impact of advanced technologies on our workforce and the real opportunities in leveraging our neurodiversity assets.

How might we better understand the diagnostics of our own human capital, to leverage and apply the right people, with the correct technology, in the most compatible job?

What is your business, military branch or government agency doing today to cross-train and educate your employees?

When was the last time you put your STEM engineering group, through a soft-skills course on communications?  How might your business development team, become immersed in the new design for a next generation digital tool?

So what?

The Operational Risk before you is all about people and your evolving human capital.  When was the last time your Board of Directors contemplated the interaction with your Human Resources department and the workforce recruitment processes?

When was the training of new hired employees and even employees with 1, 3 and 5 years or more of tenure focused on new soft-skills?  New skills and techniques for Collaborative Dialogue, Negotiation or Management Coaching?

The human capital risks in your organization are changing rapidly and they are not always about automation and disruptive technologies.

The greatest risk to you and our society is your managements failure to recognize and apply, what you have learned about your people...

26 January 2019

Davos 2019: A War on Trust...

As the World Economic Forum Annual Meeting comes to a close in Switzerland, "Trust Decisions" are on our mind.
"The corporate, political and cultural elite gathered in Davos are expressing worries about a disturbing trend: The erosion of public trust in institutions and companies.

World Economic Forum attendees said the lack of faith in everything from governments to social media platforms is hampering innovation and contributing to widening inequality."
 Why?

Over five years ago the new rules for business and the Net were in plain sight.  Articulated in a way that most business owners, CEO's of global enterprises and even our politicians could understand.

Yet at this years Annual Meeting, trust is becoming a buzzword in the panel discussions and around the dinner tables in Davos.  How might the institutions attending the World Economic Forum, strive to build a planet where "Achieving Digital Trust," is the basis for starting a business or at ground zero of creating a new product?

In 2015, Jeffrey Ritter published his book:

"In reading this book, you will explore and acquire an entirely new portfolio of tools and strategies to help shift the momentum of that war. As in any combat or battle, to succeed, it is essential for you to understand what is at stake. What we are facing is more than a war to control information. It is a war on our ability to trust information. Yes, a war on trust." Achieving Digital Trust by Jeffrey Ritter

To presume the trustworthiness of information is now a continuous question. GDPR and other forward leaning regulations are beginning to shape the way we design our systems.

So what?

How will those citizens and consumers that are devouring information from that electronic photography and RF device in the palm of their hand, think differently in the next few years?

How will the designers and engineers of Samsung, Apple, IBM, Amazon, Google, Facebook and others architect their new software and solutions with trust embedded in all that they produce?

When will our citizens understand that not selling your data, does not actually mean that your data has not been given away for free?

The future of our institutions, governments, products and relationships must be built on trust.  As you sit across the table from your editor, your CEO, your elected official or your senior software engineer you must ask the question, how will we achieve digital trust?

What if there was a Green, Yellow, or Red banner across the top of the display screen, as a quick identifier whether the information being delivered and displayed was in compliance with the new "World Digital Trust Standard"?

Yet we know that "Green Padlocks" in front of our URL and the "Privacy Essentials" grade in the top of our browser, just isn't enough.  Especially when we know that there are U.S. DHS Emergency Directives such as 19-01 in place:

"In coordination with government and industry partners, the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) is tracking a series of incidents1 involving Domain Name System (DNS) infrastructure tampering." 


Jeffrey Ritter is correct.  It is a war on our ability to trust information.  Do you understand what is at stake in your nation state?  Your organization?  Your household?  Yes, a "War on Trust"...

28 July 2018

Certainty: Solutions for an Unpredictable World...

As the moon rises on a distant horizon, vital leaders across our globe are gaining new strategic foresight to continuously adapt their enterprise.

The future horizons in the mid-2000's are now on their mind and for good reason.  All of us are operating at increasing speed, in an unpredictable world:
What is the certainty that the Operational Risks in the next 20 years, will be a replay of the variety and spectrum of loss events we have witnessed in the past 18 years.  The difference is that they are accelerating.  What have we learned?  What are we doing about it?  How are we changing?  Why?

Solutions for resilience in motion in our "Unpredictable World" span the domains of people, processes, systems and external events.  Operational Risk Management (ORM) is a discipline that can be applied in most any size enterprise including government.

When you are seated around the meeting room with your leadership team, what do you see?  People who are in charge of teams, business units, departments, subsidiaries, portfolio investments and other assets of the enterprise.  You are counting on them to be prepared, to be predictive and to be proactive.  Are they?

You see, after all of the lessons learned and the After Action Reports (AAR) have been written and published, it seems to come back to the fundamentals.  It is history repeating itself.  Will our future world continue to be unpredictable?

If you said yes, then what are you doing about it?  Let's go back to that group of leaders sitting around the conference table.  Who have they engaged outside your enterprise to back them up to help them be more prepared, predictive and proactive?

The truth is, that you are behind the solutions curve.  Even your simple, yet effective Business Continuity Plan is outdated and gathering dust on the bookshelf.  The crisis team is far too preoccupied with the next news story or "Tweet," that may have an impact on the stock price.
The truth is, our unpredictable world is actually certain and we only have a limited amount of time until the next crisis, to prepare and adapt...

22 April 2018

Unthinkable: Adapting in New World Disorder...

Will 2018 bring more data breaches, lost laptops and insider threats than 2017?  This is why CSO's, CPO's and corporate General Counsels have their teams working overtime.

When the enemy is increasing their attacks, utilizing new strategies and leveraging the existing base of compromised organizational intellectual and data assets, the future horizon becomes ever more clear. 

The statistics don't lie.  1579 documented Data Breaches occurred in 2017. Up 44.7% according to reports by the Identity Theft Resource Center (ITRC) compared to the previous year.  It is the new normal.

The Insider Threat Program (InTP) however, remains a key focus for Operational Risk Management (ORM) professionals because human behaviors are exaggerated during periods of stress, fear and uncertainty. This means that people who may have never considered doing something to jeopardize their reputations, may now be up against a wall.

When there is no obvious exit and no way out, people will do extraordinary things to get ahead, beat the odds and hedge their own risk portfolio of life.

In Joshua Cooper Ramo's book "The Age of the Unthinkable", "Why the New World Disorder Constantly Surprises Us and What We Can Do About It" the author discusses the concept of Deep Security. His analogy of how to think about "Deep Security" is the biological immune system:
"A reactive instinct for identifying dangers, adapting to deal with them, and then moving to control and contain the risk they present."
The key word in Ramo's writing is "Adapt".  Being Adaptive.  However, prior to this there are two other very vital words that we feel are even more imperative. Instinct. Identifying. In other words, Proactive Intuition.

Ask any savvy investigator on how she solved the case and you may hear just that, "I had a hunch."

Talk with a Chief Privacy Officer in any Global 500 company.  You might get them to admit they have a sense that their organization will be the target of an "Insider data breach" incident in the coming year or two.

Do you remember signing off on reading and your acceptance of the employee handbook?  When did your organization last make changes to the Corporate Employee policies?  We would start with the updates to the following sections:
  • MEDIA CONTACT
  • SOCIAL MEDIA POLICY
  • REMOTE ACCESS POLICY
  • E-MAIL, VOICE MAIL AND COMPUTER NETWORK SYSTEM PRIVACY
  • (YOUR ORGANIZATION) RIGHT TO ACCESS INFORMATION
  • SYSTEMS USE RESTRICTED TO COMPANY BUSINESS
  • FORBIDDEN CONTENT
  • PASSWORD SECURITY AND INTEGRITY
  • INTERNET ACCEPTABLE USE POLICY
  • POLICY ON USE OF SOFTWARE
  • COMPANY PROPERTY
  • PROTECTION OF TRADE SECRETS/NON-DISCLOSURE OF COMPANY INFORMATION 
Due to the increasing complexity of IT systems, cloud computing, data networks and the hundreds or thousands of laptops and mobile devices circling the globe with company executives and employees is enough to predict that a major breach will occur.

Being adaptive and having proactive intuition in the modern enterprise does not come natural. You have to work at it and it requires a substantial investment in time and resources to make it work effectively.  Proactive Intuition.

Once you realize that all of the controls, technology and physical security are not going to keep you out of harms way, you are well on your way to reaching the clairvoyance of "The Age of the Unthinkable."