29 January 2022
Cyber Reality: Quest for the Digital Castle...
They have been waking us up again to the reality of the Operational Risks we now face, to our ubiquitous digital-based economic infrastructure.
The message is clear to those insiders, who have been trying to defend our "Digital Castles" against tremendous odds of these seemingly invisible threats. Is it really, game over?
The short answer is yes. The current mindset should be, that every major business of valuable interest in the eyes of the enemy has already been compromised or soon to be. It is already too late. The stealth digital code is currently waiting in the shadows of your organizations hundreds or thousands of digital assets.
Whether it is the aging Dell Tower Desk Tops still running on Windows XP somewhere or the latest Android PDA/Apple IOS devices tethered to the corporate network does not matter. Your adversary has control of when and where to begin the attack on you and your organization.
So if this is the reality of the global state-of-play, in both the business world and also to government, what should the risk management strategy consist of going forward? How could we ever get to a point of advantage over those who seek to do us harm?
So internally, the prudent corporate business strategy should be for your General Counsel and the CIO of your organization to be already preparing themselves for the day that they will step before the press conference microphone to disclose the material breach of the companies intellectual capital or theft of assets.
They should already know, that it is just a matter time and not a denial that it will ever happen on their watch. If you are a Board Director and you still have not had "The Talk" with management about this stark reality, then you too are complicit in the scheme to present your stockholders and stakeholders with a false sense of confidence that you are safe and secure.
The new normal for forward thinking organizations is already being implemented for adverse events. The Crisis Management Team has already exercised the "Data Breach" scenario numerous times.
Your General Counsel and Chief Information Officer have rehearsed and practiced their testimony before opposing and adversarial questioning of your organizations information security processes.
The company subject matter experts are more than prepared to submit evidence of their best practices, industry standards compliance and previous tests of due diligence. The stage is set for the court room battles ahead:
The quest for the "Digital Castle" has been going on for years. Are you awake now or still living in a dream of denial on your state of achieving a Defensible Standard of Care…
20 November 2021
Metadata: Guardians on the Front Lines...
Continuous Continuity (C2) in your particular enterprise is a priority you shall not just focus upon during our U.S. Infrastructure Security Month.
Last week here, we reviewed Ten Steps your organization can practice on a regular basis to enhance your focus on Continuous Continuity and simultaneously your overall Operational Risk Management (ORM).
Let’s circle back to a few vital areas to emphasize as we increase our production and consumption of corporate or organizational “Data”.
Of Metadata. “Data that provides information about other data”.
The details on the creation date, time and application generating these words as they were originally written, is just one small example. What about the actual platform and the browser that was used:
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:94.0) Gecko/20100101 Firefox/94.0
Screen Resolution: 1680 x 1050 (pixels)
Browser Dimensions: 1005 x 853 (pixels)
Cookie Status: Enabled
You understand that the data you can’t see on your screen and the data you may not even care about, is present, and that the metadata is being collected by some entity somewhere.
The amount of data and the speed of data is now overwhelming our global digital world we live in the year 2021 and beyond. The question remains, So What?
If you are a seasoned General Counsel (GC) today with a Fortune 1000 organization doing business on a global basis, your Blackberry :) must be "buzzing" every few minutes. Just the legal risk alone being encountered will always be a factor of the number of deals, the number of employees and the growing number of countries you are operational.
As a corporate GC of a global enterprise, you have a fiduciary responsibility to protect the enterprise from all adversaries, such as the rogue employee, the government regulator, competitors, digital hackers, nation states and all of the plaintiff class actions.
The Rule of Law in your organization is in your hands. How you transfer the "Talking Points" on ethics, compliance and legal messages to your employees, partners, suppliers and adversaries is ever more critical.
The true effectiveness of your relationship with internal partners such as your CEO, CFO, CSO, CISO and Internal/External First Responder leadership could mean the survival of the company itself.
When was the last time you as a GC took the “Ethics," “Compliance” and "Rule of Law" program directly to your employees in face-to-face sessions?
How might you provide your employees, partners or 3rd-Party suppliers with the first hand opportunity to meet, greet and engage with the General Counsel of your particular enterprise?
By doing this, you are directly engaging with the people on the front lines, to be our "Guardians" for your company and to build trusted relationships with all of them.
Get out There.
23 January 2021
Predictive Intelligence: Imagine the Catalyst…
“The true sign of intelligence is not knowledge but imagination.”
— Albert Einstein
When was the last time you found yourself preparing for something that has not happened yet?
Why were you thinking about it? Was it fear?
What did you fear? Was it the potential for a significant loss event? Loss or change of what?
How will you prepare in such a way, that it gives you some assurance that the potential loss event will not occur? Or if it does, the outcomes will not be a total catastrophe:
Definition of catastrophe
- 1 : a momentous tragic event ranging from extreme misfortune to utter overthrow or ruin.
- 2 : utter failure.
- 3a : a violent and sudden change in a feature of the earth.
- b : a violent usually destructive natural event (such as a supernova).
- 4 : the final event of the dramatic action especially of a tragedy.
How might you prepare proactively with your Team, to alleviate fear and to provide greater confidence of action?
What particular environment are you thinking about right now?
Is it Land, Sea, Air, Space or Cyberspace? Will the Catalyst for the loss event you fear, begin in plain sight? Will you see it or hear it coming? Or could it be silent and invisible?
How will you know when it has started? What indicators or changes might you measure, to give you some early warning?
Your imagination has not been exercised hard enough or long enough. You will be vulnerable and you shall experience loss at some point.
Can you imagine working along side trusted people or colleagues together to imagine your fears? Will you Understand, Decide and Act? As a team…
How might you devote a few hours per week to the people, processes, systems and external events that you fear?
Your proactive strategy will make a difference. A purposeful journey of imagination each week will increase your “Proactive and Predictive Intelligence”.
Now imagine that a person on your particular team is your Catalyst. How will you make “Trust Decisions” to imagine what they might do or how the person will make a mistake? How could the persons actions become the genesis of a real catastrophe?
Wake up. You are vulnerable today. The proactive time and the degree of effort and resources that you devote to your own Operational Risk Management (ORM) shall make all the difference.
Between a life of trusted possibilities or one full of continuous despair…it is your choice.
Onward!
18 October 2020
Organizational Integrity: Leadership of Risk…
As a leader in your organization, how long have you truly demonstrated the actions you desire for those who are following you?
Countless
times each day, leaders in the global race to the finish line, ignore
or disavow the rules or policies they enforce for their own team.
What are you demonstrating in your organization today and this week to build “Organizational Integrity”?
How
are your own behaviors in the midst of your team, showing and
reinforcing the actions that will build and activate a model of
“Organizational Integrity”?
integrityWhy have you made the decisions that you are more privileged than the others on your team?
noun
in· teg· ri· ty | \ in-ˈte-grə-tē
Definition of integrity
1 : firm adherence to a code of especially moral or artistic values : incorruptibility
2 : an unimpaired condition : soundness
3 : the quality or state of being complete or undivided : completeness
Is it your personal sense of ego or power as a figure of authority, that makes you feel as if the activities and rules for you, do not apply or are different than for those who are on the front lines?
They are not. In the midst of a legal deposition or worse, the leader who is charged, explains their own behaviors. This is now beyond the point of no return.
Even when you are behind closed doors of the “Board Room” or the “Ready Room,” are you demonstrating the same behavior and adherence to the processes, that you wish upon all those you are leading?
Leadership of your “Executive” Team or a “Squad of Specialists” in the field, requires people who truly “Walk-the-Talk” and adhere to the same standards or rules set forth for the entire organizational operations.
You already are known as a “Leader” in your area of expertise.
Yet are you known as a leader with “Integrity,” that truly demonstrates this in the middle of your operations each day?
22 April 2018
Unthinkable: Adapting in New World Disorder...
When the enemy is increasing their attacks, utilizing new strategies and leveraging the existing base of compromised organizational intellectual and data assets, the future horizon becomes ever more clear.
The statistics don't lie. 1579 documented Data Breaches occurred in 2017. Up 44.7% according to reports by the Identity Theft Resource Center (ITRC) compared to the previous year. It is the new normal.
The Insider Threat Program (InTP) however, remains a key focus for Operational Risk Management (ORM) professionals because human behaviors are exaggerated during periods of stress, fear and uncertainty. This means that people who may have never considered doing something to jeopardize their reputations, may now be up against a wall.
When there is no obvious exit and no way out, people will do extraordinary things to get ahead, beat the odds and hedge their own risk portfolio of life.
In Joshua Cooper Ramo's book "The Age of the Unthinkable", "Why the New World Disorder Constantly Surprises Us and What We Can Do About It" the author discusses the concept of Deep Security. His analogy of how to think about "Deep Security" is the biological immune system:
"A reactive instinct for identifying dangers, adapting to deal with them, and then moving to control and contain the risk they present."The key word in Ramo's writing is "Adapt". Being Adaptive. However, prior to this there are two other very vital words that we feel are even more imperative. Instinct. Identifying. In other words, Proactive Intuition.
Ask any savvy investigator on how she solved the case and you may hear just that, "I had a hunch."
Talk with a Chief Privacy Officer in any Global 500 company. You might get them to admit they have a sense that their organization will be the target of an "Insider data breach" incident in the coming year or two.
Do you remember signing off on reading and your acceptance of the employee handbook? When did your organization last make changes to the Corporate Employee policies? We would start with the updates to the following sections:
- MEDIA CONTACT
- SOCIAL MEDIA POLICY
- REMOTE ACCESS POLICY
- E-MAIL, VOICE MAIL AND COMPUTER NETWORK SYSTEM PRIVACY
- (YOUR ORGANIZATION) RIGHT TO ACCESS INFORMATION
- SYSTEMS USE RESTRICTED TO COMPANY BUSINESS
- FORBIDDEN CONTENT
- PASSWORD SECURITY AND INTEGRITY
- INTERNET ACCEPTABLE USE POLICY
- POLICY ON USE OF SOFTWARE
- COMPANY PROPERTY
- PROTECTION OF TRADE SECRETS/NON-DISCLOSURE OF COMPANY INFORMATION
Being adaptive and having proactive intuition in the modern enterprise does not come natural. You have to work at it and it requires a substantial investment in time and resources to make it work effectively. Proactive Intuition.
Once you realize that all of the controls, technology and physical security are not going to keep you out of harms way, you are well on your way to reaching the clairvoyance of "The Age of the Unthinkable."
15 April 2018
Social Strategy 140: Direct Action #Risk...
A prudent Operational Risk strategy, shall include a "Big Data" capability combined with deep social intelligence analysis. Here is a historical FLASHBACK in time, to one example of why leadership is devoting new resources and investment to these internal risk management capabilities:
New Diplomatic Avenue Emerges, in 140-Character Bursts
By SOMINI SENGUPTA October 3, 2013
UNITED NATIONS — "Countries all over the world, dictatorships and democracies alike, have in the last few years sought to tame — or plug entirely — that real-time fire hose of public opinion known as Twitter.
But on the sidelines of the General Assembly meeting over the last couple of weeks, ministers, ambassadors and heads of state of all sorts, including those who have tussled with Twitter the company, seized on Twitter the social network to spin and spread their message.
At the height of the diplomatic negotiations last week over a United Nations Security Council resolution that would require Syria to turn over its stockpile of chemical weapons, the American ambassador to the United Nations, Samantha Power, used Twitter to preempt criticism of the measure as lacking teeth because it had no automatic enforcement provision."What does this mean for the global enterprise, who circumnavigates the planet to initiate and manage daily business operations? It means that "Information Warfare" and intelligence collection and analysis for the enterprise continues, as a top strategic and operational function. It requires continuous Operational Risk strategy oversight.
The speed of business that is fueled by leaders commenting via social media, can even influence commodity traders in futures markets and operational planners in the "E-ring."
Those social tactics, visual in the landscape of our modern day quest for influence, notoriety or outcry, shall forever shape the breadth of our enterprise digital risk management spectrum...
03 February 2018
The 3rd Planet: On The Edge of a Digital Precipice...
Mobile devices in the hands of humans, has exponentially changed the transnational landscape for our communications forever. Yet this digital precipice is just inches away from a tremendous chasm in our cultural, social and legal way of life.
Every organization, now has substantial Operational Risks to manage, within the context of their group, company, enterprise, government and even family. This alone is not a revelation. However, if you are a Mother, Father, Brother or Sister, you are constantly challenged by the kinds of risks that plague anyone who dares to explore and utilize the benefits of the modern day Internet.
Our children are growing up faster, as they are exposed to the dark side of life, the evil that is present in our world. They witness violence, revenge and all of the other negative attributes of society faster than ever before.
The outcomes of mother nature and our natural disasters are always front and center. The digital controls and censors of broadcast television are no longer pervasive across the content and web sites available, to those who know how to navigate our IP-based digital oceans.
Operational Risk Management (ORM) is now each persons responsibility. It is no longer in the hands of a few people, in a few departments at your organization. It is not the role of a single person in your household, to make sure the family router is configured correctly.
If you are holding your latest "Digital Device" in your hand, or tapping away on the keyboard of your new lap top it is your decision to "Give" or to "Take."
Over a year ago, Adam Grant wrote his book. To get some context in 13 minutes, you can watch this YouTube of his Ted Talk.
We have for years been exposed to the concepts of "Pay It Forward" or even other concepts of reciprocity. The real question is: Are you a "Giver or a Taker?" You might be surprised to learn what Adam Grant's research uncovers.
So what?
The ethics and morals that are embedded in you at an early stage of your life, will most likely continue. The influence your Mother and/or Father or early childhood caregiver provided you may have made a difference. Maybe it was an old book they read to you, or someone asked you to read.
We all know that the words, content, pictures, videos and ideas on the other side of that tiny digital screen in your hand, is nothing more than a mirror, of our own human behavior. Good or deleterious.
How will you use this iPhone tool today, to be a "Giver or a Taker?" There might even be another option. Turn it off and put it in a drawer. At least for a few hours...but could you for a whole day?
When was the last time you donated your time, expertise, abilities or resources? What will you do right now, to make a difference on the third planet from the Sun...
22 October 2017
Threat Management Team: Preemptive Risk Strategy....
Assessment of threats in the workplace that include violence, sabotage, financial fraud, homicide or suicide are growing in the current economic environment and the Board of Directors are on alert. The Board has a daunting responsibility to provide the enterprise stakeholders:
- Duty to Care
- Duty to Warn
- Duty to Act
- Duty to Supervise
"Despite sound recruitment practices, any employer may encounter situations in which colleagues are worried about their safety because of the actions or statements made by a co-worker. The person at risk could be a current employee, former associate/contractor, disgruntled customer, investor or other person who makes or constitutes a threat to your most vital resource - your human capital."This (Threat Assessment) approach employs strategies that have been successful in a variety of situations, including:
- an associate being stalked by a spouse or former partner
- an employee who states that he or she is experiencing significant mental deterioration or who has thoughts of self-harm or homicide
- altercations between co-workers and/or with a supervisor that are escalating in tone and severity
- serious changes in attitude and performance with known or suspected substance abuse factors
- social networking, blog and other means of electronically threatening an individual or team
The actions that are utilized to address a growing threat by a person in the workplace takes a dedicated team, with the right tools and information at their fingertips. Making split second decisions based upon a lack of documented evidence, protocol failure to a set of written policies or just the wrong timing can open the doors for substantial and costly plaintiff suits.
Achieving a Defensible Standard of Care in the reality of today's volatile enterprises requires a sound governance strategy execution combined with new resources and tools to properly prepare for those almost certain legal challenges. Combining effective "BioPsychoSocial" subject matter expertise, along with the right people from legal, security, investigations, internal audit or corporate risk management can produce successful outcomes for "At Risk" employees and the entire enterprise.
This brings us to the next point regarding how a particular employee was allowed to get to the point of "No Return" in the workplace. Put on your thinking caps for a few minutes.
Whenever you have a Threat Management Team assembling to interdict a serious danger to the company, you immediately start to converge on the motive or reason why the person has or is acting against company policy or behaving in a threatening manner. It's natural to do so, as most people want to know what's causing the issue. Be careful. What seems to be the cause is only known as the "Proximate Cause." Do you really understand the "Root Cause" of the failure of people, processes, systems or some external events?
The analysis, investigation, documentation and presentation on what happened and why is the hard stuff. Getting to the "Truth" and getting answers to the "Root Cause" requires another team of specialty practitioners. These independent, outside risk advisory professionals should not be from any current or existing corporate supplier, auditor or management consultant. They truly need to be the independent, unbiased and diligent entity to discover the truth and to document the root cause of the incident. The goal is to eliminate the future threat and to mitigate any risks that may still be "lying in wait."
Corporate Management and Boards of Directors must continue to move to the left of the proximate cause on the risk management spectrum to be preemptive, proactive and preventive.
27 March 2017
Privacy Law: Scanning the Legal Horizon...
Once you have reached the point in your companies growth curve to consider the hiring of a CFO and even an outside "General Counsel", the regulatory engine must be established within the enterprise. Today, even the CISO in any major business across the United States has been challenged by rapidly changing digital privacy laws the past two years.
Especially in California, the CalECPA went into effect January 1, 2016 and in general is focused on law enforcement:
The landmark California Electronic Communications Privacy Act bars any state law enforcement agency or other investigative entity from compelling a business to turn over any metadata or digital communications—including emails, texts, documents stored in the cloud—without a warrant. It also requires a warrant to track the location of electronic devices like mobile phones, or to search them.The simple fact that a company is doing business in the State of California and has employees operating there, puts a significant set of requirements and compliance issues that are top of mind. This is why you see technology-oriented companies who have their Headquarters based here, developing robust guides for working within federal and state privacy laws.
A "Chief Information Security Officer" is not only charged with protecting the data within a confidentiality, integrity and assurance framework, but also working in tandem with the General Counsel and a Chief Privacy Officer. The standards and the laws have significant hurdles that also require prudent Operational Risk Management strategies.
Now take all of this into consideration as your begin to plan for implementing an "Insider Threat Program" (InTP) within your organization. The addition of a Human Resources component, Chief Information Officer and even perhaps 3rd Party Cloud supply chain vendors will all be in play.
So What?
So what is the legal profession in California focused on these days? Just take a look at the Agenda for a March 2017 event at Berkeley Law:
Cybersecurity Regulatory Enforcement
New regulators, new laws, and new norms are causing cybersecurity responsibilities to proliferate. This discussion will feature insights on how cybersecurity lawyers navigate the growing thicket of information security rules from the perspective of both companies pursued by the FTC and multinationals operating under different legal regimes. It will consider challenges posed by insider breaches and obligations arising from the General Data Protection Regulation.
Practitioners Panel
Privacy practitioners from leading law firms and major online companies will share insights on how to stay afloat in increasingly turbulent waters.
Privacy Award
BCLT is proud to bestow its annual Privacy Award this year on
Susan Freiwald, University of San Francisco Law School
Nicole Ozer, ACLU of California
in recognition of their leadership in securing passage of CalECPA, which establishes the “gold standard” of a judicial warrant for government access to communications, location data and other information about our daily lives.
Keynote: Too Close for Comfort – AI, Cloud Computing, and Privacy
Recent advances in artificial intelligence, robots, and machine learning are enabled by big data, digital cameras, and cloud computing. These advances open an enormous Pandora’s box in terms of security and privacy. Groundbreaking AI researcher Ken Goldberg will present potential responses, such as a concept for “Respectful Cameras,” a privacy-preserving system for industrial automation. He will explain why claims of an impending “Singularity” are greatly exaggerated and will propose an alternative, “Multiplicity,” where diverse groups of humans work together with diverse groups of machines to innovate and to solve complex problems.
Government Access
With digital evidence central to an increasing number of criminal and foreign intelligence investigations, government demands for access seem to steadily increase. From varying perspectives, this panel will explore emerging issues in government access to data stored with third parties.
Artificial Intelligence and the Right to an Explanation
The General Data Protection Regulation requires that organizations explain to individuals the logic behind decisions rendered by algorithms. This policy is aligned with growing efforts in the machine learning community to improve the interpretability of outputs. This panel will examine a broad range of efforts to address interpretability and potential biases in complex algorithmic systems.
Consent and Contract under EU Data Protection Law
EU privacy regulation continues to have worldwide relevance, especially affecting U.S.-based companies. This session will examine how consumer data can continue to be collected and used given the different approaches in the EU and U.S. to consensual mechanisms for authorizing personal data processing.
The CISO and the entire team of Operational Risk Management professionals at your organization, should be monitoring and creating new strategies to protect the organization. Scanning the legal horizon on what the new challenges are and how to prepare, is the sign of a sound business strategy.
19 February 2017
Problem-Solving: Transparency of Startup Operational Risks...
Startup mentality that initiates the planning, demand generation and "Go-to-Market" execution for the growth engine have higher Operational Risk exposure. Many founders and new entrepreneurs who have engineering or operational expertise, underestimate the need for substantial growth engine investment early in the startup timeline.
How many times have you attended "Demo Days" or other such events intended for the startup founders to pitch their new App or service solution, begging for a first customer? You must recognize that the new Artificial Intelligence interface, the optimized algorithm or the faster encrypted communications is not going to create a new market overnight.
Entrepreneurs require a substantial immersion into the business environment of problem-solving. It begins with the customer or client who detects that there is an area of risk that needs remediation. How do you think companies like Symantec and McAfee first started? The personal computers that were becoming so pervasive were encountering something now called malware.
Solving problems from the customers perspective requires a deep and focused process with the owners, operators and end users. It requires substantial time being embedded at the customer level or with the people who perform their daily tasks. You need to understand the risks that the customer is experiencing.
This "Diagnostic-to-Prescriptive" process is not new. Yet how many times have those "Demo Day" entrepreneurs or "Accelerator" graduates ended their pitch, with a plea for a first customer? This is a recipe for failure.
How can this be changed or addressed, in order to increase the number of successful new businesses? What should we be doing to assist these new entrepreneurs in embracing the "Operational Risks" of a customer and inventing a new solution to solve their problems?
The engineers and inventors should embrace the idea of finding customers first, who have real and risk sensitive problems they can solve. It is not enough to just change an interface, reduce the pricing and copy an App, to do the same general function. How long will it now take for Snap to begin building their own data centers and infrastructure?
Entrepreneurs that utilize the "Go-to-Market" strategy early in their growth cycle, will simultaneously increase exposure to substantial Operational Risks. Take that great idea or new "Minimum Viable Product" to an established business in the industry sector you think is going to listen. Find the right business to adopt you as a problem-solver with this new solution and take the time to learn.
Once you have lived with the same problem across several different businesses, agencies or governments, it might be time to launch the "Go-to-Market" strategy for a single industry sector or country to start. The learning phase and early adoption of a multitude of business development processes, will establish a more solid foundation for launching the new product / solution.
When you look at Snapchat and its growth cycle, it was not obvious up front, how privacy was going to be such a tremendous risk to the business. How you can pivot quickly from understanding your customers appetite for transparency, to also provide a robust privacy policy program, is just one way to build a trusted set of repeat customers.
Snapchat Transparency Reports are released twice a year. These reports provide important insight into the volume and nature of governmental requests for Snapchatters' account information and other legal notifications.
31 December 2016
2017: Navigating to Digital Trust...
You could be asking your team why you have yet to become the target of our adversaries also known as COZYBEAR, APT28 or APT29, CloudDuke, or even Energetic Bear. If you don't know who these are, then you probably already are "owned" by this adversary. It may finally be a priority, to become a participant in the "Automated Indicator Sharing" (AIS) initiative.
Where are you navigating to in 2017?
As we look across the vast landscape of our rapidly changing business and government domains, there is no turning back. There is no ability to retreat or to acquiesce, in a world so full of continuous Operational Risk.
There is no certainty. There is no true assurance. There is only the ability to solve problems faster than your adversary or competition. Some may call this resilience.
Therefore, the direction you take will forever shape your continued exposure to risks and your strategy for opportunities, that you do have control over. It is a choice and the questions by the Board of Directors, the Plaintiff Bar or the U.S. Attorney, are not going to be the most difficult ones to answer.
In 2017, any major influential organization will be getting more transparent. The metrics and the formulas (think mathematical algorithms) for counting and creating wealth will be further disclosed, the rules will change faster and more transparently. Buyers and Sellers of digital content and intelligence, will increase their levels of "Digital Trust".
How will these parties, partners and participants in a vast and exponentially expanding ocean of digital rules become more trustworthy? They will begin to better understand the DNA of their respective TrustDecisions.
The constituents of organizations, countries and ICT (Information, Communications & Technology) entities will finally realize that transparency of the rules is a vital step to trustworthiness. Better understanding the "Rules for Composing Rules" is a place to start. Jeffrey Ritter is the visionary on this topic:
To be part of the disruption, any business must look in two directions—toward the companies that supply digital information to them, and toward the companies with whom their own digital assets are shared. To succeed in creating wealth, and enriching the trust that exists throughout a company’s ecosystem, companies must evaluate how they can be more transparent with their information suppliers, and what levels of transparency to demand from those companies who are outbound recipients. What are the right metrics to show how data or content (like videos) are performing? How will the reporting occur? Are the economic exchanges properly balanced by the value of the data being shared?The negotiations have been in progress for days, months and years. The question remains; where are you navigating to in 2017 and beyond? What resources will you require to get you to your planned destination? How will you adapt along the way, as the environment you are operating in changes?
To survive the journey to your intended destination in 2017, will require bold new thinking. It will be necessary to make many sacrifices along the way, to your intended destination. On the ground, or in a virtual domain. The solution-sets that you utilize, will require new entities (change agents) to be even more effective in solving problems that arise.
These new entities (human and digital), that will solve problems more efficiently and effectively with you, are ready now. So what will you do next to adopt, embrace, espouse, endure, tolerate, and even endure the journey ahead?
May your exploration and travels in 2017 produce the intended outcomes. We wish you a productive and Happy New Year!
17 December 2016
Sprint: Accelerating into the Unknown...
"If you want to go fast, go alone. If you want to go far, go together"...
--African Proverb
You started this project to solve a large problem. A big issue in a market or with an industry. The "World's Most Innovative Companies" have been following a proven formula for decades. What is their secret Intellectual Property?
In the R & D sections of the Defense Industrial Base or the Information, Communications and Technology (ICT) sector, the lights are never turned off. The competitive world we live in requires that the proven process runs, finishes and repeats. Then it is replicated across business units, departments and subsidiaries in other countries.
What if you are now testing new ideas to save lives or reduce potential harm to a small team or even the public at large. What if you will be introducing your solution to a highly regulated market with a long process for government approvals? What if the current bureaucratic overhead to accelerate your ideas prevents you from achieving the trust you require with your beneficiaries? Answer: You pivot to this 5 Step Process:
- Map
- Sketch
- Decide
- Prototype
- Test
![]() |
| TrustDecisions | Digital Reasoning | All Rights Reserved. |
Next, you start with the target beneficiaries perspective, by starting with the end (outcomes) in mind. A "Backwards from Perfect" process or variation that seeks to understand and answers the question, Will the beneficiaries of the solution, trust our expertise? Will they utilize this solution?
The human imagination is endless. Rarely does it flourish when you want it to. So be careful to plan for the fact, that the best ideas and new breakthrough thinking will not happen in the same room with all of the stakeholders, looking at a Map or a Sketch. It just might happen as one of the participants is in the shower on Day 3, or taking an evening walk after dinner, with a colleague on Day 4.
So what?
The questions asked and process delivered, is vital to any organization who is solving big problems. Solving problems are only finally accomplished, when the beneficiary says so. When the market accepts the solution or the human using the tool achieves enough trust in it, to use it again and again. When the point in time arrives that the solution is verified and desired by enough people, then perhaps the problem has been sufficiently solved.
Until the next human decides to improve on it. Or the next human believes there is a better way. Or the environment that the solution was designed for, changes dramatically. Now it may be time to get back into that room down the hall, with all the White Boards, Post-it Notes, Markers, Timers and some Healthy Snacks.
What does the unknown future look like? At dawn, just early enough to know it is time to move forward faster than your opposition...
Begin Morning Nautical Twilight
The start of that period where, in good conditions and in the absence of other illumination, enough light is available to identify the general outlines of ground objects and conduct limited military operations. Light intensification devices are still effective and may have enhanced capabilities. At this time, the sun is 12 degrees below the eastern horizon. Also called BMNT...
20 November 2016
Intuition: Security in a World Without Borders...
On a crisp Fall morning, one week after the U.S. National Election we were lining up outside the Harry S. Truman Building outside the United States Department of State. The Bureau of Diplomatic Security - Overseas Security Advisory Council was hosting it's 31st Annual Briefing.
This years briefing was focused on "Security in a World Without Borders" and as we passed through our ID check and screening, the anticipation was high. It's private sector constituents from the Fortune Global 500 to the small U.S.-based professional services firm had one key similarity.
Leaders in attendance recognize that their business is integrated forever with a exponentially expanding system of interconnected machines. CxO's across the globe are competing for business in the era of "The Fourth Industrial Revolution" where the vulnerabilities extend beyond the Critical Assets of the enterprise.
This years keynote address was by Richard Davis, CEO of U.S. Bancorp. His talk was heartfelt by many as he recounted his rise from the days at the branch level securing the vault. Now he emphasized most of his effort was focused on Operational Risk Management (ORM). Data, Identities and Distributed Denial of Service (DDoS) were on his mind everyday now.
Beyond the threats of a Post-ISIL Levant and operating in a world of Transnational Organized Crime, the room was almost full on Day 2 for this 10:45AM panel discussion: "Developing an Insider Threat Program" and was moderated by Elena Kim-Mitchell, ODNI.
The OSAC participants on the panel were:
- Roccie S., Capital One | Financial
- Stanley B., Rolls-Royce North America | Defense Industrial Base
- Joseph L., Southern Company | Energy
The "Human Factor". The point that they all wanted to insure the audience understood clearly, is that all of the analytics software, data loss prevention (DLP) tools and sophisticated technology was not going to stop a determined and motivated adversary.
So what?
Your intuitive abilities as a human shall not be ignored or discounted. How many times have you said to yourself, "I knew something wasn't right with that person". In fact, many times we are alerted to the anomalous behavior of a co-worker because we have the human-factors of intuition that is working 24x7 in our brains.
Gavin de Becker has said it best in his book "The Gift of Fear," yet we must not forget that behavior is something that can be applied to everyone:
- We seek connection with others.
- We are saddened by loss and try to avoid it.
- We dislike rejection.
- We like recognition and attention.
- We will do more to avoid pain then we will do to seek pleasure.
- We dislike ridicule and embarrassment.
- We care what others think of us.
- We seek a degree of control over our lives.
How often have we all said, the signs were there. How many times are the clear and present indicators in the workplace being ignored? A organizations "Duty of Care" is continuously at stake. Human Factors alone, just as software systems alerts alone will continuously expose the enterprise to significant loss events. Here is just one example from the Washington Post:
The Pentagon’s Defense Security Service announced this year that contractors will be required to implement programs that are designed “to detect, deter and mitigate insider threats.” Contractors will be required to designate a senior insider threat official to oversee the program and provide training on how best to implement it.
While many details of the Martin case are not yet known, it is clear that it is not good for Booz Allen to have a second employee charged with stealing secrets from one of its most important customers, officials said.
What is the solution?
Government contractors, private sector businesses and their small and medium enterprises that are within the supply chain ecosystem for products and services, are continuously challenged. They are under the growing umbrella of a myriad of federal acquisition guidelines.
In addition, various export, civil liberties and privacy laws focused on preserving the integrity and trust of the United States in an international marketplace, are compliance mandates for your global commerce.
New solutions are required as a result of the increasing spectrum of threats from individuals in the workplace, to the cyber nexus infiltrating your trade secrets and theft of intellectual property.
The TrustDecisions “Insider Threat Program” (InTP) has been designed from the ground up with organizations operating in highly regulated “Critical Infrastructure” sectors, including Financial, Energy and the Defense Industrial Base (DIB).
Many companies have already started the establishment of an “Insider Threat Program” (InTP). Utilizing Subject Matter Experts from TrustDecisions will provide your organization with the confidence and continuous assurance that you stay on course.
“Achieving Trust” with employees, clients and suppliers is paramount in our digital 24x7x365 economy. Designing and adapting the InTP to your unique culture and the changing threat landscape is a vital strategy.
30 October 2016
Legal Risk: Tools for Trusted Governance...
Policies that are not codified in laws are different across states and global jurisdictions. The rules that people can rely on and have come to trust for hundreds of years, remain the foundation for our modern civil societies. It is when the rules are ignored, under utilized or forgotten that disruption and chaos can erupt.
A key principle in modern democracies is that the rule of law is known. Statutes, regulations, court decisions, agency deliberations, and even the minutes of Federal Reserve meetings are published and made available. The operating premise is that, if the rules are accessible, civil order and social continuity will be strengthened and the conduct of those violating the rules is more easily prosecuted. The old saying that “Ignorance of the law is no excuse” rests on an important premise—the law must be published and accessible. The Internet has made much of the content of the rule of law even more accessible. Jeffrey Ritter
The country and the jurisdiction is a key component for knowing the law. It is in the day of the Internet even more accessible. Building and achieving trust in an organization, company enterprise or governance body has several tools at their disposal to assist them in the enforcement mechanism. One of those is an independent panel or group of outsiders who are convened to discover evidence.
A Board of Directors is comprised of both individuals inside the company and outside to help guide the organization. In a private company, this "Board of Directors" make decisions on the evidence of data and make informed decisions to govern the enterprise. Some of these decisions may involve what products and services to develop or what people should be selected or released from certain duties and responsibilities.
In the public sector, there is another mechanism that can be utilized, A Grand Jury. The Fifth Amendment to the Constitution of the United States reads, "No person shall be held to answer for a capital, or otherwise infamous crime, unless on a presentment or indictment of a grand jury..."
A grand jury is a legal body that is empowered to conduct official proceedings to investigate potential criminal conduct and to determine whether criminal charges should be brought. A grand jury may compel the production of documents and may compel the sworn testimony of witnesses to appear before it. A grand jury is separate from the courts, which do not preside over its functioning.[1]
What is one example of a notable case where a Grand Jury was used in the process of the rule of law:
The second Watergate grand jury indicted seven lawyers in the White House, including former Attorney General John Mitchell and named President Nixon as a "secret, unindicted, co-conspirator." Despite evading impeachment, Nixon was still required to testify before a grand jury.An environment of trust includes a vital component of transparent and accessible rules. When there is a reason to discover the truth, we look to the governance factors of those rules. Then we look at the clear evidence, the data to determine the correct course of action in our inquiry. A Board of Directors or a Grand Jury provides guidance on whether a particular case should be referred to a legal process in a particular jurisdiction. The rules are clear. Trust is preserved.
What are the outcomes and benefits of effective Operational Risk Management (ORM):
- Reduction of operational loss.
- Lower compliance/auditing costs.
- Early detection of unlawful activities.
- Reduced exposure to future risks.
ORM includes legal risk. This is why the General Counsel of private sector companies include the GC in the team that helps to effectively govern the organization. They understand the rule of law and the requirement for transparency and factors needed to achieve integrity and trust.
Now think about your organization, your jurisdiction and the process you are utilizing to ensure more effective TrustDecisions. What can you do different? What will you do to make it better? How will you provide the best use of the rules to effectively ensure the integrity and governance of the system?
Here is just one example:
Over 60 people in the U.S. and India face conspiracy and wire fraud charges in the largest crackdown against a telephone scam ever, officials said.
Callers from centers in India posed as federal agents to threaten victims with arrest, imprisonment, fines or deportation if they didn’t pay up, according to an 81-page indictment unsealed Thursday.
At least 15,000 Americans lost more than $300 million collectively during the four-year scam, according to the feds. A Texas grand jury indicted 24 people from nine U.S. states, 32 people from India and five call centers in Ahmedabad, India, earlier this month.
09 April 2016
Trade Secrets: Gearing up for DTSA...
The attribution of cyberespionage adversaries has been gearing up since the Sony Pictures hack. The private sector has been hunting and identifying those shadow individuals and nation state special units for years. Now the lawyers can get more aggressive with civil actions.
The question remains, will another law deter the actions by global organized crime and the intelligence community of some significant nations? How will attribution and more aggressive civil actions in foreign jurisdictions make a difference?
As a global organization, can you access your database of confidential trade secrets? No different than the task of the identification of information assets that you are going to protect, you need an inventory. What are they and where are they? Everyone knows the formula for "Coca-cola" is written on a single piece of paper that is locked up in a vault in Atlanta, GA right? Or is it?
There are trade secrets across America that have been stolen by operatives working inside organizations. They may be preparing to leave the U.S. for another country outside the reach of law enforcement and the legal process for seizing the stolen property. That is going to change soon.
The EX-Parte Seizure Order is part of the Trade Secrets bill that allows a trade secret owner to obtain an order from a judge for U.S. marshals to seize back the trade secret from the alleged bad actor without prior warning. This is to protect the trade secret owner from having the alleged bad actor skip the country or destroy the evidence before it is recaptured.Now that Trade Secrets are in the same legal and enforcement category with patents and trademarks, you can predict that your legal budgets will need to be adjusted, upwards. In general, what is a Trade Secret?
The subject matter of trade secrets is usually defined in broad terms and includes sales methods, distribution methods, consumer profiles, advertising strategies, lists of suppliers and clients, and manufacturing processes. While a final determination of what information constitutes a trade secret will depend on the circumstances of each individual case, clearly unfair practices in respect of secret information include industrial or commercial espionage, breach of contract and breach of confidence.The effort to make intellectual property a "Trade Secret" is another strategy in itself. The determinations to designate something a trade secret is going to depend on the invention or the data itself. We understand. So what?
A Chinese businessman pleaded guilty Wednesday (March 23) in federal court in Los Angeles to helping two Chinese military hackers carry out a damaging series of thefts of sensitive military secrets from U.S. contractors.Our adversaries are determined. They are already here. It has been documented for years. Let the next wave of legal indictments and seizures begin. One thing is certain. The "Insider Threat" is still present and your organization can do better. The ability to effectively utilize the correct combination of controls, monitoring, technology and internal corporate culture shifts will make all the difference. What are you waiting for?
The plea by Su Bin, a Chinese citizen who ran a company in Canada, marks the first time the U.S. government has won a guilty plea from someone involved with a Chinese government campaign of economic cyberespionage.
The resolution of the case comes as the Justice Department seeks the extradition from Germany of a Syrian hacker — a member of the group calling itself the Syrian Electronic Army — on charges of conspiracy to hack U.S. government agencies and U.S. media outlets.
12 March 2016
Rugged DevOps: Reengineering for our Next Generation...
"A weather man is reluctantly sent to cover a story about a weather forecasting "rat" (as he calls it). This is his fourth year on the story, and he makes no effort to hide his frustration. On awaking the 'following' day he discovers that it's Groundhog Day again, and again, and again. First he uses this to his advantage, then comes the realization that he is doomed to spend the rest of eternity in the same place, seeing the same people do the same thing EVERY day." --Groundhog Day
We are seeing the reunification of 1990's Software Quality Assurance (SQA) thinking, combined with the rigor of new 21st century rapid software development disciplines. It is called "Rugged DevOps." Application development life cycles are getting shorter these days. That is because modern day software development life cycles are taking a more component-based approach, with the reuse of standardized software capabilities. This makes sense, as long as the use of software quality assurance tools and services are not abandoned and new tools and processes are embraced.
Welcome to "Rugged DevOps." This Forrester report, "The Seven Habits of Rugged DevOps" will give you more context:
Habit 1: Increase Trust And Transparency Between Dev, Sec, And Ops
Habit 2: Understand The Probability And Impact Of Specific Risks
Habit 3: Discard Detailed Security Road Maps In Favor Of Incremental Improvements
Habit 4: Use The Continuous Delivery Pipeline To Incrementally Improve Security Practices
Habit 5: Standardize Third-Party Software And Then Keep Current
Habit 6: Govern With Automated Audit Trails
Habit 7: Test Preparedness With Security Games
"Enabling Digital Trust of Global Enterprises" in the next decade will require software development organizations to embrace security and risk professionals simultaneously, on a more consistent and non-adversarial basis:
DevOps practices can only increase speed and quality up to a point without security and risk (S&R) pros' expertise. Old application security practices hinder speedy releases, and security vulnerabilities represent defects that can leave a company open to cyberattacks. But DevOps practitioners can leap forward with both increased speed and quality by including S&R pros in DevOps feedback loops and including security practices in the automated life cycle. These new practices are called rugged DevOps. This report presents the seven main principles of rugged DevOps so I&O pros and developers can break down barriers with S&R pros and achieve faster releases with stronger application security.Chief Information Officers (CIO), Chief Privacy Officers (CPO), Chief Legal Officers (CLO), Chief Operating Officers (COO), Chief Security Officers (CSO) and maybe the Chief Executive Officers (CEO) are now paying more attention to these issues.
Here are 9.5 million more reasons why:
In 2007, a class action lawsuit was filed in the United States District Court of the Northern District of California against Facebook on behalf of 3.6 million users of Facebook concerning its “Beacon” program. KamberLaw represented the plaintiffs in this action and Cooley LLP represented Facebook. This suit was settled in 2009 and was granted final approval by the Hon. Richard Seeborg in March 2010. As part of the settlement, the parties created the Foundation (the Digital Trust Foundation) “the purpose of which shall be to fund projects and initiatives that promote the cause of online privacy, safety, and security.” The case settled for $9.5 million, with the Foundation receiving approximately $6.7 million after attorney’s fees, payments to plaintiffs, and administrative costs. There were four objectors to the settlement, two of whom appealed the approval to the Ninth Circuit Court of Appeals and subsequently the Supreme Court. But ultimately, in November 2013, the appeals were rejected and the Foundation was funded. The Foundation will distribute more than $6 million and will close its doors once all of the grants have been distributed and completed.
The corporate Board of Directors conversations about the topic of "Digital Trust" is now ongoing and the subject of new business units. Security vs. Privacy has been a recent media frenzy between some of our technology companies and the U.S. government. Your elected officials in the U.S. House of Representatives are also on the hot seat now, to produce new relevant legislation. The courts are adding more privacy and data breach cases to the docket each week. The "Digital Equilibrium Project" is being established and will hopefully include an international set of stakeholders.
Authoring the rules that everyone understands and everyone can agree on, sets the stage or playing field for the environment of competition to engage with some sense of civility. Rules will be broken in plain sight and the referee (law enforcement, judges, courts, juries) will impose a penalty, while potentially millions of people watch live. Is it a penalty kick or just a loss of down?
Think global. Think at the speed of light. Think about the trust of e-commerce transactions where millions of people rely on our computing machines every waking minute of the day. Where Zettabytes of data are in use. The rules on the "Digital Playing Field" are vital to our future social and economic well being.
"Rugged DevOps" is another and necessary component of a safe, private and secure Internet ecosystem. Operational Risk Management (ORM) professionals are evermore concerned, with the root cause of our current Privacy vs. (soon to be "And") Security headlines. Digital Trust is hard to achieve and yet easy to forfeit. It is time for us to begin "Reengineering for our Next Generation".
10 January 2016
Privacy Engineering: Mobile Standards for Digital Trust...
Effective and standardized "Privacy Engineering" of mobile applications at organizations in Critical Infrastructure sectors such as Finance and Banking is just one example. It is soon to be a greater focus of the Federal Trade Commission (FTC) and other U.S. regulators. Why?
"Trust Decisions" are being made by consumers each day, as millions of of mobile banking customers download an application to their Android or iOS smart phones. The consumer then has immediate exposure to the quality of the software engineering, by the UX/design and developer of the software App. The standards being utilized by each organization for designing and engineering those Apps with privacy and security, may vary by who developed the application and for what particular operating system.
So what? U.S. financial institutions software engineering departments and other highly regulated industries will be a continued and concentrated focus by the Federal Trade Commission (FTC). Standards for privacy software engineering and disclosure of the rules will become even more of a critical factor. Why?
As a result, to act within the time constraints of deadlines, the presence of fiercer competition, and the looming threat of higher lost-opportunity costs, you have no choice—you must presume the trustworthiness of the information you acquire to make decisions. Deciding now requires you to acquire the information you need from the most accessible source, with zero time to ask the important questions: “Where did this information come from? Who put this report together? Has the data been confirmed to be accurate? Who actually authored the analysis? Does this bank statement reflect all of our deposits?”Is it possible to redesign mobile banking Apps, so that all Android or iOS software engineers must adhere to privacy and security engineering standards of practice? The human-based "Trust Decisions" about whether to trust an application with personal identifiable information (PII) is currently buried in legal disclosures. The privacy disclosures are written by lawyers, all different and in most cases never read, by the consumer prior to downloading the App. Opt-in or Opt-out?
Answering these types of questions is inherent to how we make good decisions. You seek information that serves as fuel for your decision. You work hard to validate that the information can be trusted. You calculate toward your decision, constantly evaluating whether the information holds up its reliability. But in today’s 24/7/365, wired decision-making landscape, there is no time to ask those questions. Those controlling the information you need understand that pressure and require you to presume their digital information is trustworthy and reliable for making your decisions. Thus, to gain control of digital information is to succeed in imposing an enormous handicap—removing your ability to challenge its trustworthiness by asking the right questions. Source: Achieving Digital Trust by Jeffrey Ritter.
The future of mobile App Privacy and Security Trust engineering for consumers will be in the hands of government regulators soon and in concert with other laws associated with information security, such as the GLBA Safeguards Rule. "Cyber Trust" indicators or other vital warning systems may be in the works. Buyer Beware is the theme.
For years consumers have been looking at FDA Nutrition Labels and other Federal oriented tools, to provide more visible and rapidly effective disclosure. Since the human being is making "Trust Decisions" on whether to download a software application to their computing device, they also may desire a method to quickly ascertain if the App is "Trustworthy."
Can they trust the application according to their particular appetite for risk? What information will be shared with 3rd parties? How will your information be used and collected while you are using or not using the application? Here is one example of how a future warning "Privacy Label" may look before a consumer is permitted to download an application to their computing device.
What does the consumer experience today? As one example, currently when you visit the App Store on an iOS mobile device such as the iPad, and then search for "Chase", the top choice is an App named Chase Mobile. When you click on the "Get" button, it changes to "Install". When you click on "Install" it prompts you to Sign In to iTunes Store. Once you sign-in, the Chase Mobile App downloads to your device, the button then changes to "Open."
When you open the Chase Mobile App, it opens the first screen to "Log On". There is a small "Privacy" button in the top left corner of the screen, however there is not an easy to understand Privacy Label that is visible before you actually "Log On" to Chase. In the case of selecting the Privacy button in the upper left corner, it then reveals dozens of pages of legal documents explaining online privacy policy and U.S. consumer privacy notices. There is however one easier to view grid, under the privacy notice that is helpful in understanding whether Chase shares personal information and whether as a consumer, you can limit this sharing.
The Critical Infrastructure sectors of the U.S. economy, that has a daily interface with consumers through mobile software Apps are now on notice. Chief Legal Counsels, Chief Information Officers, Chief Privacy Officers and Software Engineering personnel, must address the reality of human behavior and how "Trust Decisions" impact legal risk and the ultimate perception of the corporate brand.
13 December 2015
Beware of the Cowboy: Risk Driven by Fear...
"The recent conviction of Michael Coscia in the Federal District Court in Chicago in the first prosecution for “spoofing” provides more clarity to high-frequency trading firms about how they can operate. The message is to tread carefully when a strategy depends on using orders that will be quickly canceled because the government may claim they are an effort to manipulate the market by fooling others into trading.Believe it when we say that people who try to be cowboys in your organization are operating without regard to risk. Now multiply the number of cowboys by the number of people that they surround on their team, who think that this is the way to operate. It doesn't take long to find out that these are the root causes of many of the operational risks in your organization. And it starts out with the basics even in the vast private sector beyond Wall Street:
Spoofing was made illegal in the Dodd-Frank Act, which prohibits “bidding or offering with the intent to cancel the bid or offer before execution.”
These are just two of the many facets of occupational fraud that starts with a few cowboys who have little regard for managing risk and all the incentives to line their pockets with new found cash or bonuses.
- Revenue is not booked according to the rules. Products sit in the warehouse yet revenue ends up on the sales reps commission report because (s)he had a signed order.
- Assets are not valued correctly. Bank accounts are not validated to make sure they actually exist and accounts receivables are inflated.
From Leadership Lessons of the Navy SEALS
The Cowboy
"The problem with being a cowboy is that your bosses won't employ you if they can't trust you, and they can't trust you if they don't know what you'll do. And then you're stuck with the reputation.""Neither of us knows if such a thing has ever been tolerated in modern commando teams. Yes, sometimes you need to charge forward. But, there are simply too many potential casualties and too much political currency resting on commando missions to entrust one to a cowboy. Authorization for an operation depends on the accurate calculation of operational risk. This requires an assessment of proven forces ability to perform a task. All this is contrary to the cowboy philosophy of depending on experimentation, pluck, and luck in order to succeed."
--LT. CMDR. Jon Cannon
You might think that the reason is ego or just plain greed. However, the real motive may not be so clear. More than likely, the motive is fear. And that fear is something that grows until it gets to the point of creating harm, loss and destruction. You have to find the cowboys in your organization and you have to follow the mantra of quality gurus from years past, "Drive out Fear".
06 December 2015
InTP: Quality of Design in a New Age of Terror...
The FBI said Friday that it is investigating the San Bernardino, Calif., massacre as an act of terrorism, with officials revealing that the Pakistani woman who teamed with her husband in the slaughter went on Facebook afterward to pledge her allegiance to the leader of the Islamic State.The husband terrorist was employed by a county government agency in California. Just as your place of employment has a "Duty of Care" for the safety and security of it's employees, any nexus with home grown violent extremism or terrorism on a government or private sector ecosystem requires a strategic focus.
( U.S. Code Title 22 Chapter 38, Section 2656f(d) defines terrorism as: “Premeditated, politically motivated violence perpetrated against noncombatant targets by subnational groups or clandestine agents, usually intended to influence an audience.”[18])The Board of Directors or Under Secretary, in concert with Operational Risk Management (ORM) professionals within the enterprise have a fiduciary responsibility that now has a new spotlight.
The husband terrorist was a U.S. citizen working as an environmental health specialist in San Bernardino County. He was a devout Sunni Muslim. He had recently traveled to Saudi Arabia for two weeks, home of the 9/11 hijackers. When he returned, he was growing a beard and married to a devout Sunni Muslim woman he met online. Witnesses have stated that his new wife had substantial influence on his religious beliefs. Was some or all of this a potential "Red Flag" by family members or co-workers? Could she have been a clandestine agent?
The presence of an "Insider Threat" Program (InTP) is evident in hundreds of top tier Fortune 500 organizations and almost 100% of government contractors who may have "Sensitive Compartmented Information Facilities" (SCIF). U.S. Executive Order 13587 requires that an organization have an InTP in place.
This still leaves thousands of vulnerable businesses and governments agencies at the state and local levels without the resources, expertise and policy-based programs to effectively administer a lawful and effective InTP or hybrid "Insider Threat" strategy. It is imperative to assist in the continuous protection of physical and digital organizational assets, including the precious lives of all employees:
As a result, many organizations will be asking senior management about the initial implementation of an InTP or to review the effectiveness of a current InTP that is already in progress, at a Defense Industrial Base (DIB) contractor. So what?What does the current InTP in your organization, have to do with the adverse consequences that may occur? Why could those potential consequences of an InTP that has been designed incorrectly or implemented without control metrics, create substantial risk and liability to the enterprise? How can you address the Operational Risks associated with an "Insider Threat" Program?
Here are several key design areas, to mitigate the potential likelihood of unintended consequences of a failed InTP design:
- Staff or employees who utilize the InTP incorrectly with intent or by accident
- Top management loss of reputation by supporting an aggressive InTP Progam
- Collision course with formal EEOC Whistle blower protections and processes
- Friction with internal Human Resources relationships
The integrity and the credibility of the InTP is paramount, if we are to continue to utilize it as an effective tool in the Operational Risk Management (ORM) strategic plan. Managing risk on vital enterprise assets requires dedicated people, tested processes and robust systems that will not erode support.
Where are the vital process, training and systems areas that need focus or have the ability to be designed correctly from the start:
- Relationships with Management & Employees
- Investigation of Incidents and Reports
- Management Behavior after an Employee Red Flag
- Implications of the Culture of Trust
In essence, you need to have a specific executive management intervention, that does not over react. You should have a independent facilitated off-site meeting to better understand what can go wrong, why it happens and what to keep an eye on. Finally, what you can do about it.
The opportunity now is for you to strategically implement or adjust the InTP within your organization. Why you do this and how you proceed, is vital to the enterprise risk management of the company. How you and your employees behave from this point forward, will forever impact the culture of trust in your organization.
Our thoughts and prayers to all of the victims and the families impacted by this act of terrorism in the U.S. Homeland...
27 September 2015
Safe Harbor: Achieving a Defensible Standard of Care...
U.S. National Security continues to be in the center of the legal jousting between the European Union and the United States. Underlying the debate is the data flowing through the Internet from data centers in Europe owned by U.S. companies.
What are the implications of a change in the Rule of Law and the rules associated with the collection, storage and analysis of data by companies such as Facebook? How will the future of Operational Risk decisions impact the safety and security of nation states? Is "Safe Harbour" ready for legal reengineering and a new updated global data privacy architecture for the Internet of Things (IoT).
Chief Privacy Officers and General Counsel within the ranks of Amazon, Google and Facebook are on a proactive mission quest. How to keep business models fueled by advertising from erosion of data flows from outside the U.S. if precluded and if, all data from the EU must stay within the EU.
III – Conclusion 237. In the light of the foregoing, I propose that the Court should answer the questions referred by the High Court as follows:Article 28 of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, read in the light of Articles 7 and 8 of the Charter of Fundamental Rights of the European Union, must be interpreted as meaning that the existence of a decision adopted by the European Commission on the basis of Article 25(6) of Directive 95/46 does not have the effect of preventing a national supervisory authority from investigating a complaint alleging that a third country does not ensure an adequate level of protection of the personal data transferred and, where appropriate, from suspending the transfer of that data.Commission Decision 2000/520/EC of 26 July 2000 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequacy of the protection provided by the safe harbour privacy principles and related frequently asked questions issued by the Department of Commerce of the United States of America is invalid.
The Office of the Director of National Intelligence (ODNI) will be tracking the data privacy legal frameworks across the globe and the continuous changes that will be necessary to stay in compliance with U.S. laws. Henry Farrell sums this up nicely in his WP analysis:
Thus, if the court rules as expected, the U.S. has to choose between two unattractive options. The first is to refuse to make any concessions on surveillance, hence endangering the business models of big and influential U.S. e-commerce firms, and making life much harder for other big corporations that e.g. have to transfer personnel files across borders. The second is to make real concessions to the EU on spying, moving away from indiscriminate surveillance to a system that would provide real protections for European citizens.We are on the edge of many years of new business process reengineering (BPR), but this time it is not about the demise of proprietary client / server architectures and the addition of Internet Protocols. The new data privacy BPR is now just underway and it has all to do with creating the sound contractual negotiations of digital devices across borders. More importantly, the trusted business assurance questions being asked by Operational Risk Officers and the building of digital trust as data and rules are executed at the speed of light.
Achieving Digital Trust delivers to business executives, IT strategists, and innovation leaders something remarkable-a complete tool-kit of new strategies and resources that will change how they make decisions that matter, and how to build digital assets that can be trusted.
As you pick up your mobile device to access Messenger, or Wickr, the rule of law is being put in motion in nanoseconds. When you type the message to your colleague in Ireland or Germany from Detroit, your data is being processed across data centers in multiple countries. Machines executing business rules with other machines. Are the rules correct? Are they all legal?
"Achieving a Defensible Standard of Care" in the next decade will be one of our most interesting challenges. The Safe Harbor of our way of life may go beyond the simple integrity and assurance that the message simply gets delivered.
