Showing posts with label Cyber. Show all posts
Showing posts with label Cyber. Show all posts

21 January 2020

Convincing Boards to focus on Cyber Security is no easy task, when...

Convincing Boards to focus on Cyber Security if no easy task, when those working in the business have priorities, responsibilities and rewards specifically structured to make Cyber Security a lower priority. Convincing Boards starts from the "middle" and must work both "down" and "up", and it will not be an easy or fast process.

I recently spoke to the CRSA (Control Risk Self Assessment) Forum in London, hosted at the IRM's offices (with thanks to Carolyn Williams), and very ably organised by Paul Moxey. My desire was to highlight the challenges that management (operational to the C-suite) face, and the decisions that must be taken, many of which lead to a de-prioritisation, or even ignoring, of Information Security.

This is not to suggest that Information Security should be de-prioritised, far from it. But the purpose was to highlight the difficulties that the Risk Professional will have in gaining the internal support to both raise and then to gain resources required for effective InfoSec.

To encourage the participants to consider (and actually, engineer scenarios in which InfoSec would lose out to other priorities) I provided two "role-plays". A very quick caveat; neither case represented a real company or actual situation, but was built from a wide range of situations I have been party to or have been the Internal Auditor or Risk Manager associated with elements of the case.

Role-Play 1: "Complex project choices"

The first looked at project level issues and delivery concerns leading to a situation in which InfoSec, while critical, was actually "pushed into the long grass" by each group that considered the case.

You can "enjoy" the role-play case study here.

The constructed problem centres around the competing constraints facing any business when it comes to systems implementation. The various strains on all members of a project team, including the leadership, sponsor, and steering committee, require to balancing of resources and priorities. Sometimes individual incentives outweigh the needs of the business. While this is not acceptable, it is a reflection of the reality of motivating people, and in some cases, focusing those people on outcomes that they are responsible to deliver.

When participants received the "role-play", there were more than a few people saying "I've worked on this project".

The premise was fairly simple; the project is in its final stages but has run over budget (Quelle surprise) and over time: and the user community's level of frustration is rising to breaking point. The infrastructure model is not adequately integrated into the corporations secure environment, and the additional time and cost will push the project further over budget and time.

The groups were then asked, each playing a specific role, to provide a recommendation, as a group.

As expected (and constructed), not one of the groups said that project implementation should be delayed until security concerns were addressed. In one group, the person playing the role of the IT Infrastructure representative threatened to "call Internal Audit" to which there was a response, "So you plan to stab your colleagues in the back?"

Others proposed setting up a working group to assess and recommend addressing the security and infrastructure issues after the project, while acknowledging that this would become, in effect, a new project fight for resources against all other projects. But it wouldn't impact their ability to deliver what they were required to deliver.

The final takeaway for participants was that it will be difficult to gain the internal allies required to address security if their support will be counter to their own needs, responsibilities and rewards.

Role-Play 2: "The C-Suite and External Expectations"

Likewise, at the C-Suite level, internal and external expectations can be such that investment in Cyber Security becomes a secondary consideration behind meeting the short-term demands of shareholders, markets or owners. This Role-Play set out to demonstrate the push and pull of competing requirements, again against a backdrop of systems implementation coupled with quarterly reporting needs, in challenging market conditions.

Take a look at the Role-Play here.

The four participants (the COO, CFO, CIO and Director of Communications) each have competing priorities, yet all are also keenly interested in ensuring company success.

Read the Role-Play and decide for yourself how these individuals should respond, and challenge yourself to find a way for them to agree to invest in greater Cyber Security, or to make a recommendation to the Board to do so.

Once again, while all but one of the groups could bring themselves to abandon their roles' self-interest, they did all recommend that the CIO push Cyber Security to the top of his or her agenda for the coming quarter. The outlier group suggested that the business "take the hit" this quarter and focus on Cyber Security, while also communicating the markets that they were doing so to improve the company's ability to protect and server customers in the future (though they did not agree fully on how to avoid the potential ramifications of announcing that they would focus on Cyber Security and the potentially associated assumption that their systems were not secure).

Summing up:

In both, or either case, do you recognise your company, or a company you have worked with in the past?

If so, be assured that it is possible to convince Boards, but only once the required groundwork has been completed. In the two Role-Plays above, it is too early, and there are too many competing priorities. But there is hope in each, in that the need is recognised, and there are ways out.

Gaining Board agreement on Cyber Security requires time and planning, with careful messaging along the way. In addition, before the Board can "buy-in" to investment in Cyber Security, key stakeholders within the business must also "buy-in", as it will be their alternative expenditure and investment plans and programmes that may suffer or be put on hold to accomplish improved security.


Role Play 2: "Shareholder Expectations"


Shareholder expectation generally revolves around the meeting of targets, primarily revenue and profitability targets that ensure either a dividend flow (private companies and utilities) or sustained growth in the share price. Senior managers, "C-Suite" executives and Directors know this and know that their bonuses and futures (in this company and in any others) depend on a track record of delivering to shareholders' expectations.

Welcome to the mid-year session of the Exco as it prepares for the upcoming earnings release season. Things seem to be on track, and the 1st Qtr results were in-line with expectations. The share price has responded roughly as expected. This quarter however, could be a little more difficult. Trading conditions are worrying the Marketing director, while internal costs are not dropping as quickly as budgeted. The new system is going to be at least two months late, possibly three, pushing benefits into the 4th Qtr.

You now have to make some decisions:

1. The COO. You have numbers to make, promises to keep. The numbers that you received from your senior managers are promising, but you don't believe them "I've seen numbers like these before, and they are always overly optimistic". Your CIO is constantly late with delivery, system outages have become too frequent, and the IVRs never seem to match the problem. To compound things, someone in IT changed the “404” error page to redirect to the Dictionary.com definition for “liars”.

2. Head of Corporate Communications. When dealing with crises and missed targets in the past, your motto has been "Bad news is good news, good news is no news" and the spin spin spin. But you feel things are reaching a point where your own credibility is coming into question. If things continue as they are, you're afraid the only professional option left to you will be to apply to become the Director of Communications at the White House in Washington.
                
3. CFO. You've managed to, just, get the numbers right for the 1st Qtr results, but this quarter will take a small miracle, and missed targets have been shown to severely limit the longevity of CFOs. The numbers expected by the markets (or owners) are possible, but there better not be any down-side surprises. There are costs that can be shifted into out-quarters, and revenue that can be brought forward, if we tweak our revenue recognition policy.

4. CIO. You know that the existing systems need replacing, that infrastructure is supporting the users, but the Security guy(s) are telling you that a serious architecture review is needed (again, "review" means they know there are problems but are too afraid to tell you everything), and the company simply cannot continue to avoid significant new investment. Your proposals for Security investment themselves will increase the overall IT budget to the equivalent of 12% of revenue from the current 10% of revenue, a level that is already at the high end of the scale for this kind of business.

Time to have your conversation, and come to an agreement that the CEO will be able to defend at the next earning call/shareholders meeting.


Role Play 1: "Complex Project Choices"


Scenario: A new system is in the final stages of development, and should "go-live" in three months. Testing is ongoing with the usual bugs and use-case mistakes. The project is projected (for the third month in a role) to come in at exactly 109% of budget, thus avoiding the need to go back to the Board for authorisation for additional spend.

The COO has committed to the Board that the system will go in on schedule. Internal Audit has given an "adequate" grading on a review of the project to date.

IT infrastructure has just reported that the servers will be ready, but that they will not be within the secured domains used by other corporate systems. To do so will require a re-architecting project. However, they do not think there is a major security threat, though when pressed, they've admitted that it would be possible, under "extreme" circumstances, for a hacker to gain access to "some" data. Re-architecting the environment will take an additional 4 months, and will add £275,000 to project costs, taking the project well over the 109% of budget.

You are now meeting to "discuss" the situation. You are:

1. Project manager. If you do not get this project in on time and within the allowed budget, you lose your bonus (20% of your salary), and you probably will not get that next project. Worse, you’re regular steering committee meetings with the sponsor (and team) are becoming a nightmare of complaints about timing, internal resources being diverted to testing, costs, etc.

2. IT infrastructure. You don't completely trust your own people's assessment, as there have been breaches before when some data was stolen. You also know that the 4-month estimate is probably optimistic. A few people in your IT team know too much about your systems, hoard that information, and honestly, you would have “moved a few on” if they didn’t hoard their knowledge. Can you trust them to fix the architecture in anywhere near to estimated time or budget?

3. Operations Manager from User Community. Your people have been crying out for this system for years, budgets have been cut, headcount reduced, and people are reaching a breaking point, with absenteeism escalating. Meanwhile, the project continues to demand more of your frontline experts for “testing”.

4.  Strategic Planning. Your models show that this system is going to boost profit by 5% annually, with an immediate 2% this year, to a profit-line that is already stressed. Missing the targets is not an option, as the cost of future external funding through equity or bond issuances will be impacted by the company’s evidence of being able to meet market expectations.

So, what do you all agree to recommend and do?

29 July 2018

Old is Good, Unless You are a Computer System

Old is, by itself, I am happy to say, not bad. And the process of getting older is also not by too bad either. We build up knowledge and understanding, and sometimes we see wisdom in some (older) friends. But “old” is not good in computer systems. That accumulated “knowledge” is actually decades of bugs and bug fixes, new functionality that does not always work with the old, and ancient security holes that either have never been found, or have been too difficult to fix without breaking the rest of the system.

New-build systems, while potentially having a limited functionality set, are easier to manager, faster to build, scale more easily, and consume fewer resources to run and maintain. The “systems shop” full of geeks is a thing of the past, unless you are running a large legacy system.

Agility in the face of threats and opportunities is magnified in newer systems, while legacy systems can be overwhelmed in the face of new threats.

This does not meant to settle the Buy-vs-Build argument, but it does argue for the replacement of legacy systems with newer systems built with current technology and for modern infrastructure. After all, who speaks COBAL any longer?

On example of how to overwhelm a legacy system; regulatory reporting. FATCA created a nightmare for financial institutions having to deal with new fields and new reporting requirements. Older systems required new code, new reporting systems build or new extracts to feed reporting platforms. Meanwhile, newer systems, built with regulatory reporting as a core design requirement, found the delivery of FATCA reporting much easier. 

Newer financial institutions and those with newer systems may still refuse to open accounts for US citizens, but that is being driven by an expectation of future US Legal Imperialism.

But these new systems are able to support CRS, the “rest of the world’s” response to FATCA. Pity that the US of Amerika refuses to engage with the rest of the world and implement CRS (Common Reporting Standard). Even countries like Panama are implementing CRS, and computer systems are having to cope with the new regulatory reporting requirements.

I enjoy being older. I’m smarter, I think more deeply, and my opinions are based on decades of experience and knowledge. At least, I flatter myself with these thoughts, even though I may be hard-pressed to find much support for those assertions. But I do envy the young. I cannot run as fast any longer, or run at all for that matter. I’m not as agile, and new music simply baffles me. 

Another area where younger seems to have an advantage is in fraud and cyber-security. I’m back to talking about computer application and banking systems of course.
Remember the good old days when a dial-up network with a 48kb connection was enough? Back in those days, hacking was a different scale, and individual hackers were or became known to officials. They weren’t always caught. But sometimes that special person like Clifford Stoll will "stalk the wily hacker", ultimately leading to an arrest.


From "Stalking the Wily Hacker", Clifford Stoll, 1988

Today stalking the wily hacker is almost impossible, and the number of vectors continues to increase exponentially. Building information security in from the beginning is key to a successful financial systems application. I do not know what application Monzo, the UK challenger bank, but they certainly are talking about their agility in the face of cyber-attacks and fraud. Imagine with old systems being able to respond to apparent fraudulent activity within four hours.

“Within four-and-a-half hours, the team rolled out updates to our fraud systems to block suspicious transactions on other customers’ cards. That evening, we reached out to other banks and the US Secret Service (which is responsible for credit card fraud in the US) to ask if they had seen anything similar. At the time, they hadn’t.” Try doing that with a legacy system.

Yet for all that, and perhaps as a victim of the “Sunk Cost Fallacy”. I happily will continue to hold this particular legacy system (myself) dear and will continue to attempt upgrades.



26 January 2016

Risk Managers in Uncertain times

Over the past few weeks I have been thinking about the world as we move into 2016. Most of that thinking is not about daisies and pixey dust, but about the changes over the past few years, many of which seem to be leading either to crisis, trouble, or the slow boiling of the frogs. Personally I'm hoping for a few crises that will, although probably fairly terrible at the time, actually bring about some fundamental changes that will create real change and improvement, at least in the medium term.


What's a Risk Manager to do? Below I contrast "the Usual Suspects" that we are (or should be) watching every day as Risk Managers, and then "the Big Stuff" and implications for Risk Managers now.

We are going to see the world change through 2016 and 2017, potentially dramatically - and not necessarily positive change. That is my view. Of course, I could be very wrong, and we could see a world that "muddles along". At heart are our individual answers to the question "how do we best help our businesses manage the coming risk world?"

I am not confident, but that is my view.

So let me suggest, based on my view, the potential impacts on Risk Managers for the coming couple of years. Two years is a very short time in a world of potential regulatory change and economic cycles. Anything shorter than two years would fail to consider the potential impact of major business and economic cycles such as the current commodity depression, the US (and China) manufacturing recession, and the very serious systemic debt and migrant issues that Europe may or may not manage through the coming year.

The Usual Suspects:

Of course the world of Risk will be both immediate and longer term, local or specific as well as systemic and international. We'll start by reminding ourselves of some basic risks that have no direct link to the wider situation.

1. Cyber threats. This category of risk continues to be on the rise, and can be an existential threat to companies from a data-loss or damage perspective, while civil and regulatory sanctions continue to increase. This is a threat that has been growing, and increased access and growth in skill sets will increase the number of hackers and the breadth of tools and techniques they will use. Companies will be taken down by Cyber attacks. Companies can prepare for and attempt to limit the impact of Cyber attacks, but can do little to reduce the likelihood of such attacks (as exogenous threat likelihood is not subject to risk reduction activities on the part of the company). Reducing the impact requires planning, careful review of the potential threat (what are the data-crown jewels, and how are these protected?) and remediation where infrastructure is not adequately protected. Reputation damage limitation if an element of planned responses, and finally, consideration should be given to Cyber Insurance.

2. Fraud, Bribery and Corruption. If the economy continues to grow and unemployment continues to fall, there will be little impact on the likelihood of Fraud, internal or external, though of course these risks remain. However, if we see a degradation in economic conditions, this will probably lead to an increase in fraudulent activity, starting with external fraud and followed by an uptick in potential internal fraud. Of course, some fraud, bribery or corruption is simply due to greedy people, and has no linkage to economics. Exercise skepticism.

3. Solvency. For the insurance industry in Europe, this is the year Solvency II fully comes into effect, and insurers across the continent are getting their reporting houses in order. Yet the risk is not simply that companies may or may not be solvent, it is a question of the quality of internal processes supporting production and maintenance of the ORSA (Own Risk and Solvency Assessment). As risk managers we can learn from companies that have been through the process, such as the importance of the quality of documentation of the process, effectiveness of systems of control (nothing new there), and the ability to demonstrate how the ORSA contributes directly to business decision-making.

4. All Your Risks. Every risk on your Risk Register will remain as critical (or otherwise) through 2016 and 2017 as they are today. Some will increase in potential impact, many will eventuate in actual issues or problems. These risks will become incidents, and you will manage them through to resolution - or not. There will also be a host of issues and incidents that will result in you reviewing the Risk Register, and probably adding risks to the Register.

You can never go wrong keeping your eyes on the day-to-day risks, and ensuring that the business either has effective controls in place, or is building a control environment that can actually be monitored to indicate areas of existing or emerging risk.

Now for the Big Stuff:

A global correction may be underway, with no sign of a low for some time to come. Certainly there may be up days or weeks, but it appears that there is more likelihood of a longer down trend for the coming months. The questions now are "how far, how fast, how long, and how much stimulus"? There are no serious commentators calling for a near-term renewal of a global bull market. The IMF recently downgraded their expectations for global growth from 3.8 (July 2015 forecast) to 3.4 (January 20016) with developed economy growth downgraded from 2.4 to 2.1, the same level as 2015.

The US markets are down 15% from their highs (DJIA - 15,900 from 18,200 in 2015), and China is at 2014 levels (Shanghai is at 2750 from a high of 5100 in 2015). [as at 26 January 2016]  Where will they go?

Total global debt has continued to rise all through the supposed deleveraging after the Global Financial Crisis (GFC), increasing by $(US)57 Trillion since 2007 to almost 200 $(US) Trillion. The majority of this increase has been government debt, yet corporate debt (and personal debt) has also risen through that period. This also cannot continue without impact.

At the same time in developed countries we see a close to stagnation in growth in real incomes. Personal income in the UK has finally (May 2015) caught up with where it was before the GFC, and the strong employment growth has been reflected in falling unemployment and increased wages. The introduction of a "living wage" will also increase personal incomes (although some worry that imposed minimum wages reduce employment growth). All good news, but will the UK continue to grow as the rest of the world slows down, if the UK votes to leave the EU, or if markets continue to fall (the FTSE is now at 5800 from just over 7000 in 2015, and continues to fall). [as at 26 January 2016]

In the US, employment growth appears to be strong, at the same time that the labor participation rate continues to fall. The unemployment rate is around 5%, a level that is close enough to full employment that we should be seeing serious upward pressure on wages. Yet the continued fall in labor participation indicates that there remains a (growing) untapped pool of labor. The picture remains murky.

Recommendations for Risk Managers

The current economic situation is, in my view, as scary as it has been since the GFC. Fear has an impact on risk and companies' and individuals' perceptions of appropriate levels of acceptable risk. How do we translate this into meaningful decision-making by companies, and counsel from Risk Managers?

1. Risk Appetite. There should be no better time than now to review (or write) the Risk Appetite for the business. Risk Appetite will provide a construct for decision-making by management that is in line with the level of risk that is acceptable to the Board and through them the shareholders. Risk Appetite is not a single statement, but needs to be broken into key business activities or processes, and potentially high level business units / companies. When reviewing (or writing) the Risk Appetite, speak directly with the directors and in private companies, with the key shareholders.

2. Identify your Key Risk Indicators (KRIs). These are the indicators whose movement provides insight into the potential increase or decrease in the likelihood of the materialization of any particular risk. For example, this may include items such as average days receivables (expanding may indicate deteriorating customer business conditions), or less obvious indicators such as unplanned staff turnover rates (with falling unplanned turnover being a surrogate for a degrading jobs market for your employees).

3. Stress tests (EKRIs). Build the models, and then test them beyond what your CFO/Finance Director thinks are possible. Build in extremes such as cost of fuel for distribution networks, cost of capital, internal project huddle rates. Stress until the model breaks, then look at why the model broke. That will give you a strong indication of the most important factors to be watching on a daily basis - your External Key Risk Indicators (EKRIs). I know of a very large manufacturing company that failed to hedge fuel costs, resulting in significant business costs when oil did spike. While that may not be the case today, if cheap oil turns out to be transitory, will cost-reduction based profits evaporate?

4. Outside-In. Having built or reviewed the Risk Register, the KRIs and the EKRIs, how are the risks identified reflected in the Risk Registers and risk reporting? Is the current risk environment too inward looking, focusing on the specific risks, controls, actions and people that are within the organization and therefore "observable" to management? How strong is the monitoring of external factors, and how can this be built into risk reporting?

5. Regulation Watch. Times of crisis almost always breed new regulation, or changes to existing regulation. I'm not going to opine on the benefits or otherwise of regulation, but as Risk Managers we must ensure that our organizations has fully considered the potential impact of such changes. When SOx (Sarbanes Oxley) and the section 404 requirements were passed, who predicted $170/hour for bulk standard Internal Auditors spending thousands of hours documenting mundane financial reporting processes and identifying controls - followed then by the massive increases in compliance costs to test those controls? Something like this is in our collective futures.

These are a few of the considerations for Risk Managers today. Are these different from what Risk Managers should be doing or concerned with in good times or steady global growth? No. And that is the rub, and the message; times like today provide strong reminders of what we should be doing every day. The increased fear do however provide us with the energy to get this done.