Showing posts with label Continuity of Operations. Show all posts
Showing posts with label Continuity of Operations. Show all posts

28 September 2024

Pain or Joy: Change Management 101...

Habits are hard to change.  It takes discipline and continuous perseverance.


When was the last time you changed something that increased your revenue?  Your health.  Or your safety and security.


Change and managing change whether in the corporate ranks of your Fortune 500 Global Enterprise or back in your own personal life at home is a true challenge.


Before you even thought about what you needed to change in your business or your own life, you probably have encountered one of two experiences:

    • Pain
    • Joy

Which one of these two experiences have you recently encountered?


You see, our human behavior is quite predictable and it is usually one of these two motivators in life that will change your behavior.


Educating yourself and others you care about requires that you sometimes utilize one of these motivators in order to initiate new change.  Let’s begin with “Pain”.


These realities are exactly what the evil in our world today continues to prey on.  Those individuals who are unable or unwilling to change, and to manage change in their lives.


“It is really very simple. In the foreseeable future, we will not function as a global society without the Net and the immense digital resources and information assets of our society. The addiction is established—commerce, government, education, and our neighbors offer no option other than to require that we rely upon digital information in making decisions. But we will not function successfully if the war for control of those assets is lost. The battlefield, however, is the one on which trust is to be gained or lost—trust in the information we use, trust in the infrastructures that support us, and trust in the decisions we make in a digital world.”  Page 19 - Achieving Digital Trust | The New Rules For Business At The Speed Of Light  - Author Jeffrey Ritter


In your own digital life, these habits may be as simple as using the same password on multiple accounts that each of us rely on, each day or each week of our lives.  You know who you are.


As the continued use of “Ransomware” remains so pervasive across the globe and is utilized by so many criminal gangs and nation states, each one of us must consider our personal and business habits.


At home and at work.


It is now time to change.  It is time to change your digital habits so you may avoid the pain and continue to have even more joy in your life.


Take action.


Start a new habit now of changing the weak password on your bank accounts.  Make it 20 characters, and make it random.  Easily addressed when you "Use a Password Manager App".  Then set a reminder to change it on January 1, April 1, July 1, and October 1 of each year.


“Microsoft warns that ransomware threat actor Storm-0501 has recently switched tactics and now targets hybrid cloud environments, expanding its strategy to compromise all victim assets.


The threat actor first emerged in 2021 as a ransomware affiliate for the Sabbath ransomware operation. Later they started to deploy file-encrypting malware from Hive, BlackCat, LockBit, and Hunters International gangs. Recently, they have been observed to deploy the Embargo ransomware.


Storm-0501's recent attacks targeted hospitals, government, manufacturing, and transportation organizations, and law enforcement agencies in the United States.” BleepingComputer


After you have successfully accomplished this simple task in your business and in your own personal life, remember:


The “Pain” of doing this simple “Change Management” step in your life, will help bring you continued “Joy” for so many years to come…:)


Godspeed!

23 February 2024

CERT: Make a Difference in this World...

Since the beginning of time, weather has been unpredictable. So has man.

When was the last time you witnessed the aftermath of a natural disaster?

When was the last time you saw the devastation from the Fateh-110 family of short-range ballistic weapons?

The continuous examples of risks to our world could generally be put into two major categories, 1) those we as humans can control and 2) those natural risks that we can’t control and shall have to live with.

Our spectrum of "Operational Risks" across People, Processes, Systems and External Events is vast and endless.

Where do you as a leader in your organization spend most or your time and resources to try and mitigate risks:

  • Natural Disasters and Weather (External Events)
  • People and Processes

Why?

Do you think that you are able to make a difference with those risks that you might be able to control?

Which is it - A) controlling the weather or B) influencing human behavior. Pick one.

What might happen if we devoted more time and resources to “B”.

How might this investment have a risk reduction impact and reduction in annual loss events to your family, organization, community, college or government?

Complacency or ignorance will continue to plague us and will make the world a more dangerous place to work and live.

Just listen to your own local news for a day. What will you learn?

Now, learn what you might do to make proactive difference.

This is one great place to begin: Community Emergency Response Team CERT.

Similar to the Community concept, why not apply this just cause of continuous training and learning to a Corporation, a Church, a Synagogue, a Campus, a Club or a Cinema.

“The world is a dangerous place to live; not because of the people who are evil, but because of the people who don't do anything about it.” Albert Einstein

19 November 2022

OPS Risk: 7 Revolutions on our Horizon…

The holiday season is almost upon us. One only has to look into the mirror of 2022 to see the trajectory of our world.

Our digital globe is preparing itself for the next major breakpoint in its history of commerce and business.

Our organizations are in anarchy and the consumers of our products and services are shifting before our eyes.

You only have to look back on the past years major headlines of the Washington Post to gain some perspective on where we are headed in the next 12 months.

Social consciousness is seeping into the workplace and management is keenly aware of the accelerating change factors on the corporate doorstep for 2023-24.

Several new waves of incremental change are upon us. As providers of products and services to the consumers of the planet, whether businesses or individuals, the writing is on the walls of the corporate boardroom: Survive.

The tides of change are now upon us. Look no further than the Seven Revolutions Initiative. [See 7 Revs] The social, technological and demographic facets are enough to make anyone wonder where we are all headed in the next 20 years.

Our Critical Infrastructure industries are putting the building blocks in place to sustain a dramatic shift in who their customers are today and whom they will be tomorrow.

2023 will be another year of corporate malfeasance, seeded with wondrous accounts of incivility. Spawned by the empowered employee to become a whistle blower and a bold new generation of inside crime fighters.

Our generations of young workers and consumers on this planet will pay for something they can believe in, rather than something that is socially and morally bankrupt.

They will work all day in the global banking software development department and work late into the night, developing the next binary code to impress their peers on the other side of the world developing the latest ransomware on the Internet.

They will design the new marketing campaign for the next gas guzzling 4-wheel drive SUV by day and ride home that same evening in their brand new foreign hybrid using electric power.

2023 will be a year of heightened sensitivity to security and exponential asymmetric warfare.

Our dated processes and systems will be adjusted and tweaked to accommodate the planets morphing threats by a new force of true “Innovation Navigators.”

The Board Room Buzz will be more about how to protect those vital corporate assets and simultaneously how to survive our next crisis.

What may be most interesting, is how the governments of the world now cooperate to become more of a global partner on this front.

We sense already a growing cooperation among world leaders to deter and defend our citizens from the spread of a tyrants fear and uncertainty.

Finally, 2023 will be another year we find greater appreciation for:

  • The evening glimmer of sunlight across a body of clean water. The wave from the neighbor who lives next door or across the street.
  • Our faith in what or whomever we believe in. Those who serve, so we can remain free of threats or illness, to our loved ones and our own well-being.
  • The signs that our bodies are healthy. The hope that exists in all of us, for finding a greater peace of mind.

In 2023 and beyond, look with fresh eyes on everyday things…

29 January 2022

Cyber Reality: Quest for the Digital Castle...

On this Saturday morning the prayers are silent. For family, friends and also for the subject matter experts in business and the U.S. government.

They have been waking us up again to the reality of the Operational Risks we now face, to our ubiquitous digital-based economic infrastructure.

The message is clear to those insiders, who have been trying to defend our "Digital Castles" against tremendous odds of these seemingly invisible threats. Is it really, game over?

The short answer is yes. The current mindset should be, that every major business of valuable interest in the eyes of the enemy has already been compromised or soon to be. It is already too late. The stealth digital code is currently waiting in the shadows of your organizations hundreds or thousands of digital assets.

Whether it is the aging Dell Tower Desk Tops still running on Windows XP somewhere or the latest Android PDA/Apple IOS devices tethered to the corporate network does not matter. Your adversary has control of when and where to begin the attack on you and your organization.

So if this is the reality of the global state-of-play, in both the business world and also to government, what should the risk management strategy consist of going forward? How could we ever get to a point of advantage over those who seek to do us harm?

So internally, the prudent corporate business strategy should be for your General Counsel and the CIO of your organization to be already preparing themselves for the day that they will step before the press conference microphone to disclose the material breach of the companies intellectual capital or theft of assets.

They should already know, that it is just a matter time and not a denial that it will ever happen on their watch. If you are a Board Director and you still have not had "The Talk" with management about this stark reality, then you too are complicit in the scheme to present your stockholders and stakeholders with a false sense of confidence that you are safe and secure.

The new normal for forward thinking organizations is already being implemented for adverse events. The Crisis Management Team has already exercised the "Data Breach" scenario numerous times.

Your General Counsel and Chief Information Officer have rehearsed and practiced their testimony before opposing and adversarial questioning of your organizations information security processes.

The company subject matter experts are more than prepared to submit evidence of their best practices, industry standards compliance and previous tests of due diligence. The stage is set for the court room battles ahead:

The quest for the "Digital Castle" has been going on for years. Are you awake now or still living in a dream of denial on your state of achieving a Defensible Standard of Care…

28 August 2021

Never Forget: The Prescience of our Risks…

Historical facts and real time data will remain an empirical reminder of our mistakes in the past, of our “Lessons Learned”. Those who study the why and the how from only our past 20 years of history, will be able to adapt, can proactively improve outcomes and will over time increase our respective levels of resiliency.

“The 19 men who hijacked and crashed the four planes were all trained by al Qaeda. Three of the suspected pilots—Mohamed Atta, Marwan Al-Shehhi, and Ziad Jarrah—were part of an al Qaeda cell based in Hamburg, Germany. All four pilots took flying lessons in the United States.

Fifteen of the hijackers came from Saudi Arabia, two from the United Arab Emirates, one from Egypt, and one from Lebanon. The oldest was 33; the rest were between 20 and 29. The group also included two sets of brothers: Wail and Waleed Al-Shehri on American Flight 11, and Nawaf and Salem Al-Hazmi on American Flight 77. The hijackers began entering the United States in January 2000 to advance the plot. All 19 were in the country by early July 2001.”

Yet are we simply repeating the same behavior and forgotten our lessons of the true data?

A proactive set of activities are continuously required to sense the unforeseen. We shall continue to devote our time, new resources and growing intelligence towards the heartbeat of our emotions.

The hope is, that we do not lose sight of the foundations and the continuous requirements for our Operational Risk Management.

The prescience of our risks, are based upon the past and the history already laid down before us. The continuous ability for you to become even more reliable, more consistent and to hedge against significant loss is in your own hands.

How might you become more resilient to the change events that still lie ahead of us:

Operational risk is defined as the risk of loss resulting from inadequate or failed processes, people, and systems or from external events. These risks are further defined as follows:
* Process risk – breakdown in established processes, failure to follow processes or inadequate process mapping within business lines.
* People risk – management failure, organizational structure or other human failures, which may be exacerbated by poor training, inadequate controls, poor staffing resources, or other factors.
* Systems risk – disruption and outright system failures in both internal and outsourced operations.
* External event risk – natural disasters, terrorism, and vandalism.

The definition includes Legal risk, which is the risk of loss resulting from failure to comply with laws as well as prudent ethical standards and contractual obligations. It also includes the exposure to litigation from all aspects of an institution’s activities.

How might we gain the foresight required in an evolving physical and virtual environment with:

  • More Threats.
  • More Data.
  • More Speed.
  • More Decision Makers.
  • More Competition.

We shall “Never Forget”…

21 August 2021

Always Remember: Continuous Insight After Two Decades…

After 9/11, Business Continuity got plenty of attention, yet to this day many companies remain ill-prepared for disaster. This CFO article in 2003 reinforces the reality of this fact.

Even if you have tested your Business Continuity Plan (BCP), it doesn't mean that your own organizations suppliers and partners have:

Source: Scott Leibs, CFO Magazine September 01, 2003 "In the weeks following September 11, 2001, the New York Board of Trade (NYBOT) was praised, in these pages and elsewhere, for having invested in a disaster recovery plan that proved nearly priceless. The commodities exchange had been spending $300,000 annually for a backup facility that sat idle for years, an expense that had been questioned but that paid off: the exchange not only used the site in the days after 9/11 but continues to use the site as its de facto headquarters as it transitions to a new one in lower Manhattan this month.

That was the kind of success story that was supposed to galvanize the business-continuity market, highlighting as it did the vulnerability not only of computer systems but also of phone, power, and transportation grids. What had been seen as an issue affecting primarily a company's data center was now framed as a strategic imperative affecting every aspect of infrastructure."

Here are ten steps for consideration to Practice Continuous Continuity (C2) for Enterprise Resilience:

  1. Develop and practice a contingency plan that includes a succession plan for your executive team.
  2. Train backup employees to perform emergency tasks. The employees you count on to lead in an emergency won't always be available.
  3. Consider creating offsite crisis meeting places for top executives and operational teams.
  4. Make sure employees—as well as executives—are involved in the exercises so that they get practice in responding to an emergency and following orders in potential chaos.
  5. Make exercises realistic enough to tap into employees' emotions so that you can see how they'll react when the situation gets stressful.
  6. Practice crisis communication with employees, customers and the outside world.
  7. Invest in an alternate means of communication in case the phone networks go down, including wireless devices.
  8. Form partnerships with local emergency response groups—firefighters, police and EMTs—to establish a good working relationship. Let them become familiar with your company and site.
  9. Evaluate your company's performance during each test, and make changes to ensure constant improvement. Continuity plans should reveal weaknesses.
  10. Regularly test your continuity plan to reveal and accommodate changes. technology, personnel and facilities as they are in a constant state of change at any organization.

As part of the audit of your Continuous Continuity (C2), include the check up on your most vital 3rd party suppliers. They must be as prepared and resilient as you are. You may require that they be included in all of your scenario exercises, to make sure that you know their level of readiness...

20 March 2021

Mission Leader: Independent Resilience...

What are you and your organization working on today, to become more independent? 

Definition of independent

(1) : not dependent: such as

   a (1) : not subject to control by others

(2) : not affiliated with a larger controlling unit

   b (1) : not requiring or relying on something else : not contingent

The Continuous Continuity of your endeavors may well be determined by how much you rely on others for your own survival.

When you or your organization becomes “Interdependent” on resources, or vital capabilities that ensure your survival, then you are increasing your exposure to becoming even more vulnerable.

“Continuous Continuity” requires a mind set that is Proactive, is full of awareness and is consistently asking “What if”?

As a leader in your small group, in your business unit or in your local County, what are you doing today to become even more resilient?

You see, it is your symbiosis and the “Interdependencies” with others, that may become your ultimate and true vulnerability to Operational Risk.

“Independent Thought Leadership” requires discipline and once you commit yourself, it means that you will now be on your way to a more resilient state of being, growing within your particular ecosystem of choice.

Where are you operating today? What is your role in the “Continuous Continuity” of your Life, your Family, your Business, your Faith and your Country?

Your future depends upon your ability to become more Resilient. How will you accomplish a strategy to assist others around you, so they also will become more independent?

What will you learn today to make you stronger, smarter or more clear in your mind about how to assist others?

How might you apply this new found skill or knowledge to your life, that will ensure your own longevity and your consistent personal satisfaction?

As an independent “Mission Leader” you too will become one additional resilient component in an environment of future risks. Here is what lies ahead of you:

The 16th edition of the World Economic Forum’s Global Risks Report analyses the risks from societal fractures—manifested through persistent and emerging risks to human health, rising unemployment, widening digital divides, youth disillusionment, and geopolitical fragmentation. Businesses risk a disorderly shakeout which can exclude large cohorts of workers and companies from the markets of the future.

A “Mission Leader” then takes this knowledge onward to teach others. They apply what they have learned and accomplished, to share it with people they care about...

23 January 2021

Predictive Intelligence: Imagine the Catalyst…

 “The true sign of intelligence is not knowledge but imagination.”

— Albert Einstein

When was the last time you found yourself preparing for something that has not happened yet?

Why were you thinking about it? Was it fear?

What did you fear? Was it the potential for a significant loss event? Loss or change of what?

How will you prepare in such a way, that it gives you some assurance that the potential loss event will not occur? Or if it does, the outcomes will not be a total catastrophe:

Definition of catastrophe

  • 1 : a momentous tragic event ranging from extreme misfortune to utter overthrow or ruin.
  • 2 : utter failure.
  • 3a : a violent and sudden change in a feature of the earth.
  • b : a violent usually destructive natural event (such as a supernova).
  • 4 : the final event of the dramatic action especially of a tragedy.

How might you prepare proactively with your Team, to alleviate fear and to provide greater confidence of action?

What particular environment are you thinking about right now?

Is it Land, Sea, Air, Space or Cyberspace? Will the Catalyst for the loss event you fear, begin in plain sight? Will you see it or hear it coming? Or could it be silent and invisible?

How will you know when it has started? What indicators or changes might you measure, to give you some early warning?

Your imagination has not been exercised hard enough or long enough. You will be vulnerable and you shall experience loss at some point.

Can you imagine working along side trusted people or colleagues together to imagine your fears? Will you Understand, Decide and Act? As a team…

How might you devote a few hours per week to the people, processes, systems and external events that you fear?

Your proactive strategy will make a difference. A purposeful journey of imagination each week will increase your “Proactive and Predictive Intelligence”.

Now imagine that a person on your particular team is your Catalyst. How will you make “Trust Decisions” to imagine what they might do or how the person will make a mistake? How could the persons actions become the genesis of a real catastrophe?

Wake up. You are vulnerable today. The proactive time and the degree of effort and resources that you devote to your own Operational Risk Management (ORM) shall make all the difference.

Between a life of trusted possibilities or one full of continuous despair…it is your choice.

Onward!

08 November 2020

Supply Chain Resiliency: Operational Risk Priorities in 2021…

Global Senior Executives are evaluating the resilience of their organizations international supply chains and realize the growing Operational Risks.

Why have proactive Enterprise Risk Management teams been on high alert and how are they working the issues for over the past nine months?

These are evident clues in just one one 10-Q example:

“We rely on sole direct and indirect suppliers or a limited number of direct and indirect suppliers for some or all of these components that we do not manufacture... Many of such direct and indirect component suppliers are geographically concentrated, making our supply chain more vulnerable to regional disruptions...we have experienced and continue to experience disruptions in our supply chain due to the impact of the COVID-19 pandemic.

If our direct and indirect vendors for these components are unable to meet our cost, quality, supply and transportation requirements, continue to remain financially viable or fulfill their contractual commitments and obligations, we could experience disruption in our supply chain, including shortages in supply or increases in production costs, which would materially adversely affect our results of operations.”

Inventory Management, Supply Chain Transparency and Single Source Suppliers are just a piece of a complex mosaic for many multi-million dollar U.S. businesses.

Covid-19 catalyst “Operational Risk Management” (ORM) has been a mainstream focus for months, just as it does after every major catastrophic event.

Yet, when the implications of downstream impacts to our critical infrastructure sectors such as transportation, healthcare and the continuous ICT challenges become even more apparent, the Global Executive suites must go into action.

The concepts of “Supply Chain Resiliency” are well known, yet it is continuously surprising how many organizations in 2020 have been caught off guard or are finding themselves without substantial alternative strategies to remain operational.

This is a result of diminished due diligence and a continuous analysis with your Tier 2 and Tier 3 suppliers.  Mapping each of your key lines of business with a detailed understanding of Where, How and Who your suppliers do business with, is just the beginning.  What about your own actions on:

  • Increasing Inventory Levels
  • Pursuit of Diversified Suppliers
  • Finding New Suppliers with “Robust Supply Chain Resiliency”
  • Increasing Your Geographic Diversity of Suppliers

In a recent Interos Inc. report (https://www.interos.ai/resource-library/ ) of 450 executives surveyed in the U.S. on their “Biggest Risks”, the following results were found:

  • 76% identified COVID-19 as the biggest ongoing risk, followed by cyber threats at 44%, restricted or sanctioned entities at 36%, natural disasters at 30%, and single supplier or country concentration risks at 28%. Other risks fell below 20%.  
  • This follows roughly the same order for future risks, with 66% identifying COVID-19 as the future risk companies are preparing for, followed by cyber risks at 48%, restricted/sanctioned entities at 34%, and geopolitical events at 32% (this was the largest jump from 20% now to 32% in the future). 

If these results are even close to being a high priority, then your own “Supply Chain Resiliency” shall be a well funded and continuously measured Business Unit within your Enterprise, in 2021 and beyond…

12 July 2020

Incident Response: Leadership of Security Risk Professionals...

Leadership of Security Risk Professionals (LSRP) begins with a thorough understanding of the current state of the “Organizational Pulse” of the corporation.

Global Enterprise Business Resilience does not just happen overnight, after the CEO sends out the first Crisis-based e-mail alert.

It happens because the Organizational Pulse of the respective silos of responsibility, have been actively learning for years about their People, Processes, Systems and External Crisis Events.

Simultaneously, as the leaders of the Security and Risk domains within the enterprise “Ask”, “Listen”, and then “Clarify” or “Verify” vital information, the organization learns.

Global 500 public organizations, small private businesses and non-governmental organizations have true stories and cases that are considered a security risk crisis.

Confronting a crisis and incident response in one organization will be completely different at another, based upon the type of organization, number of employees, geographic locations and their senior executive process for dealing with a significant disrupting event.

The following question was asked at “Company A” and the top answers were:

What are the top five incidents/events that could cause a significant crisis within your organization?

  • 
Fire or Flood
Violent weather/damage to facility
  • Workplace violence
  • Industrial accident
  • Terrorism
"When the question was asked a different way, to a different group at the same company, the results were even more telling:"
What are five incidents/events that have caused your organization significant crisis in the last three years?
  • 
Counterfeit products or major disruption in the supply chain
Alleged ethics violation of Foreign Corrupt Practices Act (FCPA)
  • Geopolitical unrest in key overseas markets
  • Extended loss of personnel at a manufacturing plant due to COVID-19
  • Data Breach/intellectual property theft by a nation state
Senior executives charged with a “Duty of Care” in todays global enterprise, require new thinking, enhanced skills and relevant solutions to improve crisis leadership.

What is your current readiness factor for the potential of environmental or natural disaster, supply chain disruption, economic espionage, ethics scandal, data breach, employee kidnapping, sabotage, terrorism, workplace violence and other legal risks?

For example, the HR recruiter is more focused on the security risk of hiring a person with a criminal record of violence and substance abuse problems. The Chief Security Officer (CSO) is more focused on the physical and information security of facilities and the Chief Operating Officer (COO) may be more focused on daily operations and securing the resilience of the supply chain.

Throughout the enterprise the functions of physical security, information security, legal and financial liability have all become specialized and these same security risk professionals, have become subjected to the potential for a blindside incident.

“Leadership of Security Risk Professionals” (LSRP) is for industry practitioners to “Cross the Chasm” of crisis leadership...

18 April 2020

Single Points of Failure: Interdependencies Unknown...

Organizations such as WashingtonDCFIRST exist in our Nations Capital to address the need for a coalition of private sector companies and people to work on being proactive, not reactive.

"Defend Forward."

This requires leadership to focus on the critical interdependencies you share with your large corporate neighbor down the street or around the corner.

Do you both share the same Central Office from Verizon? Do you have the same pumping station for DC Water? Do you have a shared sub-station for power from Pepco?

If you do, then you both know some of your Single-Points-of-Failure.

While you may never be able to establish walls, or fences high enough and virtual ICS locked gates to totally protect your single-points-of-failure, you can create an architecture that deters attacks and detects changes.

And if you do have an alert or alarm go off, then you must investigate the incident no matter how insignificant it may be. Those organizations who believe that they are not in the bulls eye of some worthy adversary, should pay attention:
  • Shape behavior  - The United States must work with allies and partners to promote responsible behavior in cyberspace. 
  • Deny benefits  - The United States must deny benefits to adversaries who have long exploited cyberspace to their advantage, to American disadvantage, and at little cost to themselves. This new approach requires securing critical networks in collaboration with the private sector to promote national resilience and increase the security of the cyber ecosystem.
  • Impose costs  - The United States must maintain the capability, capacity, and credibility needed to retaliate against actors who target America in and through cyberspace.
Your competitors and even your neighbors realize that this game, is not always about eliminating threats to your own corporate assets. It's about making sure that the attackers choose a much more vulnerable target than your own...

07 March 2020

Scenario Vs. Resource Planning: All Hazards...

"Strive not to be a success, but rather to be of value" --Albert Einstein
This article by Saul Midler on Scenario Planning Vs. Resource Planning recently caught our eye and for a good reason. The link between Corporate Risk Management and Operational Risk Management is Business Continuity Management. Brilliant!

More importantly as he indicates:

"The danger of undertaking an operational risk assessment before the BIA / RDA activity is that a business case may be built to remediate the biggest operational risk without realising that impact or the consequence is low. This is essentially defining a solution before identifying a problem.

Think about 9/11 where 320 companies FAILED to return to business, 2800 workers DIED and 135,000 workers lost their jobs. By contrast a number of organizations did recover and continued operations. These include:

• Cantor Fitzgerald who lost 658 staff and resumed operations two days later;
• Marsh & McLennan with 3,200 staff over 8 floors;
• Morgan Stanley with 3,500 staff over 17 floors;
• NY Port Authority with 2,000 staff over 23 floors.

New school thinking saved these organizations. No one could possibly have thought of the scenario that two airplanes could cause structural integrity failure of both World Trade Centre skyscrapers resulting in the collapse and complete destruction of the precinct. The businesses that did survive did so because they adopted a resource loss philosophy that included office facilities, technology systems and, of course, staff.

While the scenario of airplanes being used as weapons of mass destruction is not a new concept for planning purposes, (in fact it was hypothesized long before 9/11) the fact is that organizations today have adopted an "All-Hazards" mind set. As a result of the new worldview, "Business Continuity Management" as previously mentioned, has provided a much needed conduit between Corporate Risk and Ops Risk."


What does this "All-Hazards" mentality mean for the cure to unplanned disruptions or untested scenarios? It means that you move to the proactive side of the line and away from the reactive mode that so many organizations are still coping with. The old "It will never happen" to us syndrome.

Global 500 public organizations, small private businesses and non-governmental organizations have true stories and cases that are considered a security risk crisis. Confronting a crisis in one organization will be completely different at another, based upon the type of organization, number of employees, geographic locations and their senior executive process for dealing with a significant disrupting event.

The following question was asked at “Company A” and the top answers were:

What are the top five incidents/events that could cause a significant crisis within your organization?
  • Fire or Flood
  • Violent weather/damage to facility
  • Workplace violence
  • Industrial accident
  • Terrorism 
"When the question was asked a different way, to a different group at the same company, the results were even more telling:"
What are five incidents/events that have caused your organization significant crisis in the last three years?
  • Counterfeit products or major disruption in the supply chain
  • Alleged ethics violation of Foreign Corrupt Pracctices Act (FCPA)
  • Geopolitical unrest in key overseas markets
  • Extended loss of electricity at a manufacturing plant
  • Data Breach/intellectual property theft by a nation state
The company is a multinational manufacturer of communications components. Senior executives charged with a “Duty to Care” in todays global enterprise, require new thinking, enhanced skills and relevant solutions to improve crisis leadership.

What is your current readiness factor for the potential of environmental or natural disaster, supply chain disruption, economic espionage, ethics scandal, data breach, employee kidnapping, sabotage, terrorism, workplace violence and other legal risks?

Throughout the enterprise the functions of physical security, information security, legal and financial liability have all become specialized and these same security risk professionals, have become subjected to the potential for a blindside incident.

For example, the HR recruiter is more focused on the security risk of hiring a person with a criminal record of violence and substance abuse problems.

The Chief Security Officer (CSO) is more focused on the physical and information security of facilities and the Chief Operating Officer (COO) may be more focused on daily operations and securing the resilience of the supply chain.

How will you provide your senior executives with the knowledge, skills and strategic solutions that enables global enterprise business resilience for years to come?  Leadership of Security Risk Professionals...

08 February 2020

Business Risk: Grow or Die...

In a previous issue of Corporate Board Member magazine in a PwC survey, the question is asked:

Has your board discussed what to do if the company is hit by a major Crisis?

  • No - 51%
  • Yes - 41%
  • Not Sure - 8%
What is the definition of "Crisis" in the minds eye of the Board of Directors today?

n. pl. cri·ses (-sz)

1. A crucial or decisive point or situation; a turning point.

2. An unstable condition, as in political, social, or economic affairs, involving an impending abrupt or decisive change.

3. A sudden change in the course of a disease or fever, toward either improvement or deterioration.

4. An emotionally stressful event or traumatic change in a person's life.

5. A point in a story or drama when a conflict reaches its highest tension and must be resolved.


How can these numbers be correct? Why don't these results make sense?

It does seem almost impossible that just over half of those surveyed said, that they have not discussed what their company would do in the event of a crisis.

In light of the latest corporate governance and catastrophic events any board member who would answer no, is either not attending the meetings or is so new to the board, that they haven't been part of the conversations yet.

The Pwc survey of 1,103 directors who responded have illustrated many of the risk management issues that are taking up much of the shareholders time.

They also indicate where they wish they were spending more time, as 59% hoped they could be doing more "Strategic Planning."

Is there a correlation between those who have not been part of discussions of crisis management and the wish to focus more on strategy?  We hope there is.

Our experience is that corporate management and the board need a 3rd party facilitating the mechanisms for change and towards the "Big Picture" of the future.

If management sees the board as an overzealous parent and not working on behalf of the shareholders the tension increases.

Once the board and corporate management have found a "strategic facilitator" to guide them towards a model of "Enterprise Architecture" everything becomes crystal clear.

The factions now see the blueprint for change and the path to implement the strategy and the tactics to achieve it.
The Importance Of Leadership In Uncertain Times

In an age of global unrest, strength and courage at the helm are more important than ever. As a director, it's your job to ensure your CEO has what it takes.
At the end of the day, the deliverable is to continually grow and whenever that significant crisis or "Breakpoint" occurs, the engineered resilience of the business enables its survival and the next phase of growth to begin...

08 June 2019

New Vision: Security Operations Center and CIU...

Flashback over 8 years ago when there was a convergence of thinking about the topic of a "Defensible Standard of Care" going on in the industry.

The key Operational Risk Management news from the 2011 RSA Conference was coming in, yet there were inside sources who still needed to be interviewed. What did they think was the most brilliant presentation or idea(s) presented?

This particular release caught some eyes as it addressed much of the thinking on the latest evolution of the Security Operations Center (SOC).  How much of this is still relevant today:

New Vision for Security Operations: Six Core Elements
The vision includes six core elements and prescriptive guidance for how to incorporate these elements into existing security operations. These elements include:
  • Risk planning: The new SOC will take a more information-centric approach to security risk planning and invest in understanding which organizational assets are highly valuable and essential to protect. With priorities based on GRC policies, security teams need to conduct risk assessments that focus on the “crown jewels” of the enterprise.
  • Attack modeling: Understanding attack modeling in a complex environment requires determining which systems, people and processes have access to valuable information. Once the threat surface is modeled, organizations can then determine potential attack vectors and examine defense steps to isolate compromised access points efficiently and quickly. RSA® Laboratories has developed theoretical models based on known APT techniques and employed game theory principles to identify the most efficient means of severing an attack path and optimize defense costs.
  • Virtualized environments: Virtualization will be a core capability of tomorrow's SOC – delivering a range of security benefits. For example, organizations can "sandbox" e-mail, attachments and URLs suspected of harboring malware. Anything suspicious can be launched in an isolated hypervisor and the virtual machine can be cut off from the rest of the system.
  • Self- learning, predictive analysis: To remain relevant in tomorrow's IT environment, a SOC will need to truly integrate compliance monitoring and risk management. The system should continually monitor the environment to identify typical states which can then be applied to identify problematic patterns early. Statistic-based predictive modeling will be able to help correlate various alerts. Developing such a system will require real-time behavior analysis innovations, although some of these elements are available today.
  • Automated, risk-based decision systems: A key differentiator of a more intelligent SOC will be its ability to assess risks instantly and vary responses accordingly. Similar to risk-based authentication, the SOC will employ predictive analytics to find high-risk events and then automatically initiate remediation activities. The prospect of dynamic typography is one of the most exciting areas of this type of systems automation for the cloud. To implement an APT, an attacker must understand network mapping and be able to model it. In response to this, organizations can remap their entire network infrastructure to disrupt an attacker’s reconnaissance efforts. This is akin to physically rearranging a city at frequent intervals – and the entire process can be automated so that links between systems stay intact and dependencies are handled without human intervention.
  • Continual improvement through forensic analyses and community learning: Although forensic analysis can be resource-intensive, it is an imperative element of a SOC and key to mitigating the impact of subsequent attacks. Virtualized environments can provide snapshots of the IT environment at the time of the security event providing useful information if detection of the attack was delayed. Having a way to share information about attack patterns will be the future of the SOC. This concept should be embraced in order to exchange threat information within respective industries and better predict the path of the APT and thereby determine countermeasures.
The evolution of the SOC in your enterprise may start in some unconventional places. Who is it in your organization that is responsible for the loss of corporate assets?

Who in your company is the one who determines what items are counted as losses to the bottom line?

Who does the enterprise look to when the crisis hits and people are looking for answers in minutes, not hours, or days?

Who picks up the phone to answer the call from the local FBI Field Office?

These may not be the people you think of in the CIO's office or IT department. These people however need to be part of the combined Security Operations Center solution in the company.

The Advanced Persistent Threat (APT) now requires the intersection of prudent strategy from the business leadership, the accounting or finance leadership and the risk management leadership.

If the CIO is looked upon as the key executive running a "Utility" inside the enterprise, think again.

This blog has discussed the "Corporate Intelligence Unit" in years past :

Beyond the utilization of threat assessment or management teams, enterprises are going to the next level in creating a "Corporate Intelligence Unit" (CIU). The CIU is providing the "Strategic Insight" framework and assisting the organization in "Achieving a Defensible Standard of Care."

The framework elements that encompass policy, legal, privacy, governance, litigation, security, incidents and safety surround the CIU. It includes with effective processes and procedures that provides a push / pull of information flow. Application of the correct tools, software systems and controls adds to the overall milestone of what many corporate risk managers already understand.

The best way in most cases to defend against an insider attack and prevent an insider incident is to continuously help identify the source of the incident, the person(s) responsible and to correlate information on other peers that may have been impacted by the same incident or modus operandi of the subject. "Connecting The Dots" with others in the same company or with industry sector partners, increases the overall resilience factor and hardens the vulnerabilities that are all too often being exploited for months if not years.

In retrospect, you can be more effective investigating and collecting evidence in your company to gain a "DecisionAdvantage". To pursue civil or criminal recovery of losses from these insider incidents, you may not go to law enforcement, but it's likely they will come to you once they get a whistle blower report, catch the attacker and/or they have the evidence that you were a victim.
How your organization pulls together the right people to staff and operate your "CIU" is going to depend on your culture, funding and current state of the threat.
BALTIMORE -
It has been a month since the City of Baltimore's networks were brought to a standstill by ransomware. On Tuesday, Mayor Bernard "Jack" Young and his cabinet briefed press on the status of the cleanup, which the city's director of finance has estimated will cost Baltimore $10 million—not including $8 million lost because of deferred or lost revenue while the city was unable to process payments. The recovery remains in its early stages, with less than a third of city employees issued new log-in credentials thus far and many city business functions restricted to paper-based workarounds.
Here is another thought. A thorough review of the current funding, staffing and strategy of a SOC or CIU in the enterprise, may even become a priority at the next "Board of Directors" meeting.

23 February 2019

OPS Risk: Military Lesson for Wall Street...

 "There is no avoiding the realities of the information age.  Its effects manifest differently in different sectors, but the drivers of speed and interdependence will impact us all.  Organizations that continue to use 20th-century tools in today's complex environment do so at their own peril."  Stanley A. McChrystal
Historically, privacy was almost implicit, because it was hard to find and gather information. But in the digital world, whether it's digital cameras or satellites or just what you click on, we need to have more explicit rules - not just for governments but for private companies.
Read more at: https://www.brainyquote.com/quotes/bill_gates_626047?src=t_privacy
Almost ten years ago, Air Force Brig. Gen. Mark W. Graper, the 354th Fighter Wing commander at EIELSON AIR FORCE BASE Alaska, quoted the essence of Operational Risk Management.

Corporate Executives and mid-level management should have this made into a poster for their office and hanging in every hallway:
"Summer is just around the corner, and many of us are planning for our favorite warm weather activities - fishing, hunting, hiking, motorcycling, camping and more. All of our summer plans can be fun if we keep in mind the basics of operational risk management: Accept risk when benefits outweigh the cost; accept no unnecessary risk; anticipate and manage risk by planning; make risk decisions at the right level; assess and mitigate risk. Stated more simply, have a (prudent) plan, have a backup plan and have a Wingman."
Whether you are focused on the safety and security of your personnel, the integrity and confidentiality of your information or the continuity of your business operations, consider this.

Effective "Operational Risk Management" will improve your organizations resilience factor.

The brilliance of Brig. Gen. Graper's emphasis on this subject away from the flight line or "The Office" is his understanding, that most of us will become more complacent the minute we hit the parking lot.

You see, OPS Risk is not just something being advocated in the Wall Street workplace. It should be just as pervasive at home or in our own leisure activities. Whether you are climbing "Denali" or entertaining friends around the backyard pool, you have to be continuously in OPS Risk mode, or it could bring harm to life, limb or your own reputation.

Operational Risk includes the risk of litigation and there is one item you can be certain that is a threat to your corporate integrity. Employees, partners and suppliers to your organization:

What most organizations the size and complexity of Facebook under estimate, are the speed of change and the socially "connected" market economy. The blur of business combined with the "Holistic Blindness" of what privacy risks are a threat today or this week, can bring an enterprise to it's knees and then to it's ultimate demise.

"Facebook Inc. (FB - Get Report) and the Federal Trade Commission currently are negotiating details of a settlement related to the Cambridge Analytica scandal, the Washington Post reported, citing people familiar with the matter.

The penalty imposed by the FTC likely would be a multi-billion dollar fine, which would easily be the largest fine ever issued to a tech company by the FTC. In 2012, Alphabet Inc.'s (GOOGL - Get Report) Google was fined $22.5 million by the agency for user privacy offenses.

The two sides are still negotiating the amount of the fine. If no agreement is reached, the FTC could take the issue to court, according to the Washington Post.

Facebook's privacy issues date back to 2012. Facebook settled a case with the FTC in August 2012, when the two parties reached an agreement that "Facebook must obtain consumers' consent before sharing their information beyond established privacy settings," according to a press release from the FTC published at the time the deal was made.

Facebook's privacy issues continued last March when news broke that Cambridge Analytica, a political research company, had harvested user data beyond what was acceptable. It later became evident that Facebook likely was aware of Cambridge's actions on the platform"

Whether it's collecting user data to sell to your supply chain or keeping your F-22 Raptor in the air to defeat hostiles, OPS Risk is the differentiator. Your survival depends on it...

28 July 2018

Certainty: Solutions for an Unpredictable World...

As the moon rises on a distant horizon, vital leaders across our globe are gaining new strategic foresight to continuously adapt their enterprise.

The future horizons in the mid-2000's are now on their mind and for good reason.  All of us are operating at increasing speed, in an unpredictable world:
What is the certainty that the Operational Risks in the next 20 years, will be a replay of the variety and spectrum of loss events we have witnessed in the past 18 years.  The difference is that they are accelerating.  What have we learned?  What are we doing about it?  How are we changing?  Why?

Solutions for resilience in motion in our "Unpredictable World" span the domains of people, processes, systems and external events.  Operational Risk Management (ORM) is a discipline that can be applied in most any size enterprise including government.

When you are seated around the meeting room with your leadership team, what do you see?  People who are in charge of teams, business units, departments, subsidiaries, portfolio investments and other assets of the enterprise.  You are counting on them to be prepared, to be predictive and to be proactive.  Are they?

You see, after all of the lessons learned and the After Action Reports (AAR) have been written and published, it seems to come back to the fundamentals.  It is history repeating itself.  Will our future world continue to be unpredictable?

If you said yes, then what are you doing about it?  Let's go back to that group of leaders sitting around the conference table.  Who have they engaged outside your enterprise to back them up to help them be more prepared, predictive and proactive?

The truth is, that you are behind the solutions curve.  Even your simple, yet effective Business Continuity Plan is outdated and gathering dust on the bookshelf.  The crisis team is far too preoccupied with the next news story or "Tweet," that may have an impact on the stock price.
The truth is, our unpredictable world is actually certain and we only have a limited amount of time until the next crisis, to prepare and adapt...

01 October 2011

Deepwater Energy Risk: Protecting Business Performance...

The Operational Risk professionals are applying the use of effective software tools in the Energy Sector. After all, the core disciplines of OPS Risk lie with safety and security and the current reality of deepwater drilling beyond 8,000 feet of ocean is here now.

There are few organizations that understand the risks associated with drilling and capturing precious natural resources under these demanding conditions more than the Marine Well Containment Company, (MWCC) based in Houston, TX USA. This new and quickly expanding consortium of ten energy exploration companies have banded together to address the "All Hazards" requirements as a result of the Deepwater Horizon catastrophe. Never before, have so few private sector energy companies converged to take on readiness, and managing operational risks with so much capital and mission focus.

Simultaneously, others close to the maritime risk management industry such as Lloyds Register Group have embarked on the bold mission to assist organizations like MWCC in the future quest for our insatiable thirst for energy. They too, understand the necessity for mitigation and prevention of another Macondo incident where a blowout preventer failed:

ModuSpec BV and Scandpower AS, members of the Lloyd’s Register Group, are developing a new tool with origins from the nuclear power industry that may prove highly useful to subsea engineers, offshore drilling managers, and regulators.

Operational Risk Management (ORM) is the process that evaluates the likelihood of a casualty occurring while comparing it to its associated consequences. BOP Monitor, a new tool under development by Scandpower applies ORM principles in a highly specific manner to one of the most important, and highly complex systems on board a drilling rig, the blow out preventer.

Last year’s Deepwater Horizon disaster cast an enormous spotlight on blow out preventer technology because the one sitting atop the Macondo Well failed to accomplish its mission, and millions of gallons of oil spilled into the sea. A one-in-a-million chance? Perhaps. In the decades since subsea blowout preventers have been used, countless have worked as-designed mitigating the disastrous consequences we all saw last summer. As the industry moves toward the arctic however, failure of these systems is absolutely not an option and risk management is of utmost importance to operators and coastal states.

The combination of MWCC and Lloyds Register to address the challenges ahead in deepwater drilling is a natural, in the Gulf of Mexico and beyond. Perhaps even more so, is the division Lloyds Register Quality Assurance (LRQA) who are experts in Business Assurance and protecting business performance. They are the people who go beyond the words in a regulation or international standard to apply a holistic and multi-faceted approach to your business achieving higher performance. MWCC will need that business assurance and performance management going forward if they are to work in concert with the United States regulatory agencies such as Bureau of Ocean Energy Management, Regulation Enforcement (BOEMRE).

All of the plans and processes will not be enough for those operators who are drilling in deepwater. This is exactly why exercising and testing those people, plans and processes will be a verified requirement:

Tracking and verification of exercise requirements for spill responders is an BOEMRE function that ensures that all responders have the required experience and expertise to respond to an offshore facility spill. Operators are required to conduct annual Spill Management Team “table top” exercises. These drills are required to test the Spill Management Team’s organization, communication, and decision-making in managing a response. The operator is also required to conduct an annual deployment exercise of the equipment staged at onshore locations identified in their plan. Each type of equipment staged onshore must be deployed and operated every 3 years. The operator is required to exercise their entire response plan every 3 years. Another exercise that tests the ability of the operator to communicate information in a timely manner is the required annual notification exercise required for every facility that is manned on a 24-hour basis. The operator must notify BOEMRE at least 30 days prior to these drills occurring. This notice provides an opportunity for BOEMRE to witness the exercise or to request changes in the frequency or location of the exercise, equipment to be deployed and operated, or deployment procedures or strategies. BOEMRE can also evaluate the results of these exercises and advise the owner/operator of any needed changes in response equipment, procedures or strategies.

The operational risk readiness factor is at the core of all of the exploration companies as it pertains to the Safety and Environmental Management Systems (SEMS). All of the MWCC consortium companies will already be well versed in "Operating Integrity Management Systems" yet, as all ten come together to work on a combined solution, a baseline of standards and guidelines will be paramount to their inevitable success.

Remember, all of this focus is on the prevention of another "All Hazards" incident. Much of which stems from the lack of confidence in equipment or procedures being replicated by humans, at just the right moment and if an emergency condition presents itself. That is why testing and exercising the multi-facets of the entire spectrum of threats is necessary, beyond those related just to the equipment integrity or failure:

More specifically, the goal of an offshore energy exploration and production safety regime must ensure that:

• Life, environment and property are protected in an effective, consistent, transparent and predictable way; both for those directly affected and involved in offshore operations.

• Risks are properly evaluated and all prevention and mitigation measures are identified;

• Control measures are implemented and maintained by all parties in accordance with mandatory risk assessments as well as what is prescribed by regulation;

• Conditions of safeguards, facilities, procedures, personnel and organizations are continuously monitored throughout the lifetime for proper functioning and compliance with all regulatory requirements and to assure that risks do not increase;

• Technical innovation and efficiency improvements can be implemented safely and responsibly.


And then there is the kind of risk, that many are still not thinking about in the Gulf of Mexico. The risk that exists in other offshore drilling regions of the globe today:

Gunmen attack ExxonMobil supply vessel kidnapping one, wounding another


By Dorothy Davis

Industry sources have reported that gunmen have attacked a ship supplying an ExxonMobil (NYSE:XOM) oil rig off the coast of Nigeria, kidnapping one crew member and injuring another.

Nigel Cookey-Gam, a spokesman for the ExxonMobil subsidiary Mobil Producing Nigeria (MPN) told The Associated Press that the kidnapping happened early Friday (09/30) off the coast of Nigeria's Akwa Ibom state.

"Mobil Producing Nigeria, operator of the joint venture with the Nigerian National Petroleum Corporation, confirms that in the early hours of Friday, some armed men attacked a supply vessel near one of our platforms, offshore Akwa Ibom State," Cookey-Gam offered in the official statement. “The incident has been reported to security and relevant government agencies”

According to ExxonMobil, MPN is the second largest oil producer in Nigeria having begun production of crude oil in February 1970 from the Idoho field, located off the coast of Akwa Ibom State.

Violence and extortion driven kidnappings have been prevalent in Nigeria’s oil and gas -rich southern delta since 2006 when militants kicked-off a series of attacks targeting oil companies. In 2009 a government amnesty program offering Niger Delta rebels an unconditional pardon and cash payments brought about a short period of reprieve, but has not been successful in quelling the targeted violence in mostly impoverished the region.


Deepwater Energy Risk in the next decade will be expanding off the coast of Brazil and in the Arctic:

In a warming and changing Arctic, China is stepping up its activities in the Arctic Ocean Basin. While China’s interests and policy objectives in the Arctic Ocean Basin remain unclear, Beijing is increasingly active and vocal on the international stage on issues that concern the region. To that end, China is actively seeking to develop relationships with Arctic states and participate in Arctic multilateral organizations such as the Arctic Council. The region includes a rich basket of natural resources: The U.S. Geological Survey estimates that 25 percent of the world’s undiscovered hydrocarbon resources are found in the Arctic region along with 9 percent of the world's coal along with other economically critical minerals. There is presently scarce open source information on China's Arctic policy and very few public pronouncements on the Arctic by Chinese officials.