Showing posts with label CIO. Show all posts
Showing posts with label CIO. Show all posts

Sunday, May 17, 2020

Program Maturity - Cyber-security and Operational Risk Maturity

The Balancing Act

In reviewing my LinkedIn notifications I was wonderfully surprised to find  an article written by Gideon T. Rasmussen, VCISO topic: Cyber-Security and Operational Risk Maturity.  As soon as I saw it I was thinking this is center to our consulting business I better pay attention. So here we go.


As Gideon T. Rasmussen comments on leveraging risk I immediately get hooked.  How can you even begin to understand your operational and situational awareness with out at first understanding your risk.  At Integris Security we advise our clients if not done within the past twelve months get a solid risk assessment done ASAP!  This risk assessment can then help you set priorities, establish tactical and strategic budgeting, technology goals and priorities and help you weigh your operational risk.  We at Integris believe this will improve the overall maturity of your cyber and operational approach.  But let's go on and see what else Rasmussen's nicely laid out article reveals.

Rasmussen's talks about U.S. Department of Commerce's,  N.I.S.T. (National Institute for Science and Technology).  For a great many of us in the IT security practice N.I.S.T. for years has been the go to "tool shed" for in-depth building blocks.  Their publications can take you from the very beginning of ....   What should I do? Where do I start? To a polished well informed presentation.   N.I.S.T. has a great many publications and they are 100% free.

The F.F.I.E.C., also provides great free guidance.  The men and women of the Northeast Chapter of the F.F.I.E.C., are your local financial services regulators.  You should get to know them, work with them and understand how they are approaching many of the same issues we all are trying to tackle every day.  Integris Security highly recommends you  review the regulators guidance and find answers to your company's compliance problems. These tools are also 100% free and incredibly useful information.

I do take issue with Rasmussen regarding this statement:
"There are no requirements for disaster recovery or business continuity. The card brands do not care if your business goes under, as long as their payment card data is secure." 
This is a nit, and can also be style but the point has to be made.  Their are literally hundreds of best practices for disaster recovery and business continuity and they should be put to use, despite the lack of attention by card brands to advise this.  Promotion of best practices is something we owe to the industry as a whole in our writings and presentations.  Taking on the Card Brands for lack of attention to Rasmussen's legitimate concerns would do better as a separate article, another a day and time in my eyes. We're talking Cyber-Security and Operational Risk Maturity.  At Integris Security we push all to stay focused.  Good practice is too important to relegate to tomorrow's news.  Let's keep it up front and worthy of continual presence and persuasion in our discussions in how to improve cyber-security and operational risk maturity.

In maturity level II, I love this discussion of controls and it reminds me of C.O.B.I.T., as well as the many information security joint forums held with ISACA in years past and their auditor/members.  You gotta love the structure that these individual professionals have developed and the principles that they follow.  This is a serious group of security professionals and we could all learn allot from them.  Rasmussen then lays out the common controls read: GAP analysis, and Risk based deployment of controls, while not much new here he provides a great review.  All solid material for a CEO and others within the organization to read and understand when weighing decisions on investment in the security program or cutting the fat off an already lean program.  These decisions will not be easy ones for sure.

My own note here:

The Cyber-Security and Operational Risk Maturity discussions can not be left alone to the operational business units, departments or divisions of your company.  These discussions need to expand and involve audit committee's at the board level and become a fluid ongoing discussions lead by the chair of the audit, technology and other important committees as the board and operational personnel try to achieve a balance of risk Vs reward and continue to build market value for the company's shareholders and investors.
 Joseph R. Concannon             

In maturity level III, Risk Management, Rasmussen covers it nicely and I smiled as he stated:
"It is necessary to tailor controls to the organization and to adapt to changes in the threat landscape."
Nicely done Gideon T. Rasmussen, these words couldn't be truer.  It also reminds me to tell our readers to remember that each organization has its own culture.  Some are very risk sensitive and others not so much so.  I often use Johnson and Johnson and Martha Steward Living as examples.  Two great companies but their approach to security was night and day.  Johnson and Johnson a security controls organization (almost war like) and Martha Steward Living a creative design firm.  The cultures were completely different at the time of my interview with security personnel.  Management of your and the company expectations are very important.  Don't get ahead of your skates or you  may get caught off balance.  Knowing the culture of your organization is key and very important.  Now that you have new security and risk management information in hand how do you operationalize it?  The best advice is work with your team and leader and try to introduce incremental improvements to improve your organizations overall security/risk posture.  This will work to your benefit for the short term tactical business operations as well as long term strategic planning for important improvements.

Your threat and vulnerability map will be constantly evolving, as targets and priorities come and go.  The risk assessment report provides you with items for your to-do list.  The report will show best practices and offer a target rich list for you to prioritize.  Rasmussen I believe understands this and covers it nicely and provides some bonus points by laying out some bullets for a prospective slide deck to communicate your findings and setting some future objectives.

The Risk Register is a platform to inform and Rasmussen points this out clearly.  Want to know more about your risk?  The Risk Register is a place you want to go to identify, define, understand impact, respond, prioritize, and take notes.  Its an invaluable tool given to us by the folks from project management.

Maturity level IV, Strong Risk Management, Rasmussen lays out a ten step program.


Rasmussen says:


1. There is appropriate separation of duties in the CISO’s reporting structure, such as reporting to the CEO, Chief Risk Officer or Board of Directors. When the CISO reports to the CIO, it is a conflict of interest  2. Cyber-security metrics, KPIs and KRIs feed into an Enterprise Risk Management program.  3.The CISO provides updates to the Board of Directors or similar executive group.  4.The cyber-security program maintains controls specific to line of business products, services and assets. 5. A process management program is in place, to include policy, an inventory and process risk analysis.  6. A fraud prevention program is in place, to include fraud risk assessments conducted by an independent third party. 7. An operational risk management function maintains a risk scenarios inventory and conducts quantitative risk analysis. 8.The organization leverages the Three Lines of Defense Model, with active support from operational management, risk management and compliance functions and internal audit. 9.  Operational functions and lines of business are required to declare self-identified audit issues, with metrics in place to demonstrate the control environment is improving continuously 10. Incident response and business continuity exercises are conducted annually to include senior executives, lines of business leaders, information technology, legal, public relations and critical suppliers
This information is a like having a great cyber-security road map.  However, just like any road map their are going to be detours, accidents, potholes and your going to need the awareness, patience and skills to work around it all.  If you follow the program laid out by Rasmussen you'll be in a better position to mitigate those great unknowns and navigate your way freely from obstructions.

At Integris Security we say: you make it, we make it secure!  We look forward to having these and many other important discussions with you and really enjoyed our read of Gideon T. Rasmussen's LinkedIn article concerning Program Maturity - Cyber-Security and Operational Risk Maturity and hope that you will too!  Their is much to learn and many experiences to endure before we can truly say we're secure.


#Cyber-Security  #HomelandSecurity  #InfraGard #ISSA #ISACA #FFIEC #NIST










Friday, October 21, 2016

Cyber Security Month: Looking for Answers Part II?


NEW YORK METRO JOINT CYBER SECURITY CONFERENCE
NY Metro Joint Cyber Security Conference
I recently attended the Third Annual New York Metro Joint Cyber Security Conference (http://nymjcsc.org/), held in mid-town Manhattan.  Security conferences are now a dime-a-dozen, but this event is unique in that it is a collaborative effort developed by a consortium of eight leading security, audit, and risk focused, NY metropolitan area, not-for-profit professional associations. Each organization brings its best to the table, creating a rare combination of expertise and diversity of talent.  

There were many informative sessions – some standing room only – but some of the greatest value was in the interaction with the other professionals.  For example, in sessions, we learned that security professionals must adopt the language of Directors to be understood by a Board.  The Internet Security Alliance is even working on metrics for Boards to use in evaluating security risks and controls.  But, after all the talk of security maturity models, cyber risk management frameworks, and “cyber balance sheets,” CISOs (Chief Information Security Officers) will tell you that Boards still “just don’t get it” and don’t seem to be that interested.  Perhaps CISOs as a group aren’t very good at explaining how greater focus on preventing and mitigating cyber threats is in the self-interests of very diverse sets of Directors.  Maybe, despite approaching the problem with the best of business concepts and lingo, CISOs just don’t have influence with Directors.  (As one CISO put it, “formulas don’t work.  Relationships do.”) Or, perhaps it’s because, as one speaker put it, there is not a single instance of a cyber breach that has been demonstrated to have a material impact on a company.  In the end, the surprising takeaway may not be that CISOs are becoming more adept at speaking the language of the Board, but that some Boards are beginning to listen at all.
This sold-out event offered excellent, high-quality presentations with plenty of actionable content.  If you weren't able to attend, you can still benefit from the recordings of many of the sessions.  They are available at http://livestream.com/internetsociety/nymjcsc/.  Presentation slides may be found at http://tinyurl.com/z3fz44d. I would highly recommend reviewing them.
And, don't forget to sign up early for next year's conference.  It's one of the best values in information security education that you'll find anywhere.  Follow www.nymjcsc.org and @NYMJCSC for details.

Phil Froehlich is Chief Operating Officer of Integris Security and a member (who listens) of the Executive Board of New York Metro InfraGard.

Cyber Security Month: Looking for Answers: Part I?


LONG ISLAND BUSINESS NEWS
LI Business New Cyber Conference
Hilton, was once again informative, invigorating and enrolling. With a number of panelists participating, including both the Integris Security CTO, Blake Cornell, and United States Congressman US District 1, Lee Zeldin, nearly 100 individuals attended the breakfast event.
Topics of interest had included Cyber Terrorism, Business Continuity, Government Legislation, Small Business Best Practices and other wide ranging topics. Some of the information shared, information that attendees can use in their day to day business operations.
A goal of Integris Security CTO, Blake Cornell, was to provide “simple and sound information that is short and sweet” further stating that “if your employees are untrained then no amount of technical information will help them understand. You can’t make them understand but you can help them understand”.

Blake Cornell is the CTO of Integris Security LLC.

Sunday, October 16, 2016

Ransomware: Osterman Research Survey for Malwarebytes

https://www.integrissecurity.com/index.php?aboutus=JosephConcannon
Joseph Concannon
Today I receive a note from a friend who said he had fallen victim to a Ransomware attack.  So I figured its a good time to review some up to date expert research.  This review is a product of Integris Security LLC and we gladly share this with the community.

First, Ransomware is a global issue effecting enormous sized companies as well as my local friend.  Ransomware is a global threat/problem.  We must recognize the size and depth of this issue.  A survey was conducted during June of 2016 that included CIO's, CTO's, CISO's and other executives.  The survey included 165 corporations in the United States as well as companies from around the world.  39% percent of the companies that were contacted were impacted by a ransomware attack in the U.S. alone.  This is truly a global problem and issue but let's keep the focus here at home.  The report shows the various priorities by country.

The FBI talks about Ransomware as a, "an insidious type of malware that encrypts, or locks, valuable digital files and demands a ransom to release them". Integris Security LLC evangelizes through its President, Joseph Concannon the value of Risk Management and the ongoing development of a solid business continuity program.  Concannon states: "this isn't a once a year review, this is a daily, weekly, monthly, quarterly and semi-annual program.  Risk Management opens the eyes of the Executive Team and Boards of Directors".

Second, it comes as no surprise that the survey results identified healthcare and financial services industry as the prime target.  Each are highly dependent upon business critical information according to Osterman Research, Inc.Cyber criminals lay and weight until they find the prime target for an attack; one which they can not recover from due to the lack of ransomware fighting software.  In Osterman's survey U.S. companies were most likely to fall victim to a ransomware attack (79% fell victim according to the survey).

Third, Ransomware ranks the fourth highest security concern for senior executives in the United States as surveyed by Osterman Research, Inc., and more:

 U.S. organizations are also more likely to place a high or very high priority on investing in education and training about ransomware for their end users; and for investing in resources, technology, and funding to address the ransomware problem.

Note well: What the Osterman Research reveals is the power play between tenured industry executives and newly appointed CIO's, CISO's, CTO's learning the mine field of budgeting.  Where do these technology executives make the push to gain budget for their projects and can they convince business unit managers to join their team?  Who pays for training and education and how does that weigh in the balance of getting things done?  Here's how its playing out so far:
Somewhat ironically, however, U.S. organizations are also the least likely to have implemented any sort of ransomware training for their end users, and are among the most likely to offer only minimal training when they actually do so.  U.S. companies rate Ransomware as a high or extremely high priority, unlike their European counterparts in Germany and the UK or Canada which consider it less of a threat. 
Yet the training dollars in the U.S. continue to lag behind.   

The survey that I am reviewing is called, "Understanding The Depth of The Global Ransomware Problem" a report promoted by a company called Malwarebytes
The perceived importance of regular, on-premises backups as a ransomware-recovery tool is quite high among U.S. and German organizations, but somewhat lower among the organizations we surveyed in Canada and the United Kingdom. However, Canadian and UK-based organizations were more likely to use regular, cloud-based backups to recover from ransomware. Other capabilities in place to address ransomware included on-premises ransomware-detection solutions (highest penetration in the U.S.), network segmentation (highest in Germany), and air gaps between data stores and the Internet (highest in Canada).
At Integris Security LLC we point out that segmentation and air gaps are important as well as on-premises backups NOT connected to the network you are backing up.  Strong passwords that are changed every 90 days.  Here are the top 15 Cyber Security Precautions to follow.  Here are some very good tips for enterprise environment security teams to review (FBI):

Here are some tips for dealing with ransomware (primarily aimed at organizations and their employees, but some are also applicable to individual users):
  • Make sure employees are aware of ransomware and of their critical roles in protecting the organization’s data.
  • Patch operating system, software, and firmware on digital devices (which may be made easier through a centralized patch management system).
  • Ensure antivirus and anti-malware solutions are set to automatically update and conduct regular scans.
  • Manage the use of privileged accounts—no users should be assigned administrative access unless absolutely needed, and only use administrator accounts when necessary.
  • Configure access controls, including file, directory, and network share permissions appropriately. If users only need read specific information, they don’t need write-access to those files or directories.
  • Disable macro scripts from office files transmitted over e-mail.
  • Implement software restriction policies or other controls to prevent programs from executing from common ransomware locations (e.g., temporary folders supporting popular Internet browsers, compression/decompression programs).
  • Back up data regularly and verify the integrity of those backups regularly.
  • Secure your backups. Make sure they aren’t connected to the computers and networks they are backing up.

For those at home we strongly recommend backup on USB stick, or other storage drive with proper security "on board" to assess the devices health each time the device is accessed.  Saving important documents to a computer is a thing of the past.  Time to think 2016 and the threats that come with the technological age we live in.  Store important documents in a safe deposit box (whether in paper or USB or storage drive or other form).  If its important, then take the extra security steps.

https://www.stopthinkconnect.org/STOP THINK CONNECT is the U.S. Department of Homeland Security Campaign promoted during Cyber Security Awareness Month (October each year).  However, the evil email attachment continues to lure an seemly endless waterfall of users into the brink.  Nothing beats education and awareness in preventing the lost of your computer to a cyber attack.  While on the computer remember you are not in your living room.  You are in the "Wild West" and everyone's your friend.  You wouldn't leave your front door open at night, so don't leave your computer open either.  
Integris Security LLC grew from our passion for protecting our nation’s critical infrastructures and years of providing industry professionals with best of breed solutions, proven best practices and top notch security education. We work tirelessly to nurture our clients’ TRUST. We will work equally diligently to EARN your trust.


Wednesday, September 28, 2016

Information Security in Corporate Valuation

What do you look at when considering the corporate valuation of a company?  Chief financial officers pour over spreadsheets, public filings and much more to get a temperature so they can inform investors, boards and others in the decision making process.  Where is Information security in this discussion?  Who is the chairman of the board's audit committee and how comprehensive are the details and reports?  How accurate and truthful are these reports and details?  Who is the chairman of the technology committee and are his/her reports accurate, timely and reflective of the needs of the company to support the basic operations of the company.
Whether your a big box company like Target, credit card processor like Hartland Payment Systems or just one of the largest email giants like YAHOO!  these and many other questions have to be answered, accurately, timely and honestly and yes, sometimes even painfully.

We have all read in the news that VERIZON is on the path to make an offer to Yahoo! with finalization next year and this latest exposure is certainly going to figure large into pricing.  Verizon
will pay a competitive price, but will not buy based on a hunch.  They will skillfully look at every single part of the Yahoo! digital empire and figure out just how much work will be needed to mend the broken system.  Information security practice will loom large as the price for Yahoo! could potentially shrink.  Information security is going to have to push its way into the board room and profit center discussions.  If not the corporate valuation is just not honest and leaves a lot to be desired when looking at the totality of the circumstances concerning corporate valuation.  Assessing a computer environment can be a very straight forward business.  But what we're seeing are limitations put on security professionals or very narrow scoping of projects which is shaving away a more wholesome look into the entire computer enterprise.  This is just a delaying tactic which is putting off the unavoidable.  Auditing should be ongoing quarter to quarter, year to year and used in helping to set budgets for the out years.  Audit chairs should be apart of the internal profit center discussions and everyone should be mindful of function over feature creep without warranted information security checks prior to implementation.  The sales guys are going to have to get involved in security the environment which they play a critical role in.

Integris Security is your trusted IT Security team that can help you as we provide tailored, high quality security solutions based on industry best practices and our principals combined experience of more than eighty years.  Call us for an appointment and free consultation.

Monday, February 9, 2015

Are You A Farmer Maybe A Network Engineer?

John Deer Tractor
While I'm not a farmer at hand I have dabbled with backyard gardening tools and have proudly planted and harvested several groupings of tomato plants and boy were they delicious.  Did I own the tools, the knowledge and the capability?  I thought so...but boy have times changed.

Today I'm reading a wired article and learning that farmers need to improvise and tinker around just as much as any one else in order to keep important and valuable machinery at work - working.  However the article which you can find here: http://www.wired.com/2015/02/new-high-tech-farm-equipment-nightmare-farmers/ tells a story which applies much further then a central Illinois corn farmer sitting on top of his combine.

The story written by Kyle Wiens of Wired brings up a great point.  Who really owns it and what does it hold for me, the owner?  A farmer in Wiens article spends over a hundred thousand for is top flight John Deer Tractor let's say and at the end of the day the question prevails, who really owns it?  You buy a top flight network appliance and we ask you, who really owns it?

While the seller wants you to buy their state of the art machinery or device, they do not release the software, hardware or for that matter everything inside which makes the machine or network device in the very first place so invaluable.  You of course get to ride it sometimes and use it for its intended purpose watch the lights bubble on/off.  You even get to clean it and shine it up with wax and polish if so inclined or just dust it off.  But if this 100,000 dollar baby decides to shut down or its circuits get glued or jammed up what you own is a 100,000 dollar shinny piece of metal and perhaps a bill for getting it towed off your lot or pulled off your network when it decides to shut down.

Like so many things today from a John Deer Tractor to a state of the art upstream protection appliance for your network the question prevails who really owns it?  The point being that you really need to be reading the fine print upon purchase, understand your operating system, learn about the configuration and understand what the long term consequences would be for owning such a machine or device.  In one case after the next we're witnessing not the lack of budget to purchase an upscale machine or network appliance but the long term ongoing problems associated with ownership, such as: maintenance, upgrades, proper configuration, segmentation, alarming and enumeration. 

While I'm not a farmer, things are rapidly changing and we'd better be changing with them or for sure the consequences will lay right in our own laps.  Failure to fully understand the value of modern day machinery/network devices, lack of service level agreements or understanding thereof, maintenance contracts whether your a farmer or network engineer machinery breaks down and so do network devices.  Of course if they are not setup and configured correctly in the first place you could say you're just throwing money out the window.  Times are changing, better be nimble and change with them.  Its not just about buying that state of the art "thing" but understanding the long term consequences of ownership can be just as expensive as "Ownership" in the first instance.  Buyer beware.

Thursday, December 18, 2014

Banks: Federal/State Rules

No holiday would be complete with out a stern warning to the banking industry from both state and federal regulators, right?  Ho, ho, ho Merry Christmas - can you please assure us that your security controls are in order!

I was going to review Governor Andrew Cuomo's Department of Financial Services as it pertained to "new" security regulations for chartered banks in New York State.  The Superintendent of the Department of Financial Services initiated a press release and letter to chartered New York financial institutions.  After reviewing the memo I concluded that if all companies implemented the items in the Superintendent's letter, the public and private industries would be in a much better place. 

Then late yesterday the FFIEC (federal financial institutions examination council)  OCC (Office of the Comptroller of Currency) spokesman Joel Anderson spoke up.  Mr Anderson responding in a interview in American Banking Magazine stated, "we already do this" and what's going on in New York is nothing new. 

This is what New York DFS said they would look for:

New Rules: NYS
  • Corporate governance, including organization and reporting structure for cyber security related issues;
  • Management of cyber security issues, including the interaction between information security and core business functions, written information security policies and procedures, and the periodic reevaluation of such policies and procedures in light of changing risks;
  • Resources devoted to information security and overall risk management;
  • The risks posed by shared infrastructure;
  • Protections against intrusion including multi-factor or adaptive authentication and server and database configurations;
  • Information security testing and monitoring, including penetration testing;
  • Incident detection and response process, including monitoring;
  • Training of information security professionals as well as all other personnel;
  • Management of third-party service providers;
  • Integration of information security into business continuity and disaster recovery policies;
  • Cyber security insurance coverage and other third party protections
These are all things we at Integris Security does.

New York State then went on to list more topics which chartered banks in NYS would be expected to furnish.  We list them here for your review:


1.  Provide the CV and job description of the current Chief lnformation Security Officer or the individual otherwise responsible for information security, describe that individual's information security training and experience, and identify all reporting lines for that individual, including all committees and managers. In addition, provide an organization chart for your institution's IT and information security functions.
2.  Describe the extent to which your institution maintains information security policies and procedures designed to address the information security goals of confidentiality, integrity, and availability. Provide copies of all such information security policies.
3.  Describe how data classification is integrated into information risk management policies and procedures.
4.  Describe your institution's vulnerability management program as applicable to servers, endpoints, mobile devices, network devices, systems, and applications.
5.  Describe the organization's patch management program including how updates, patches, and fixes are obtained and disseminated, whether processes are manual or automated, and how often they occur.
6.  Describe identity and access management systems employed by the organization for both internal and external users, including all administrative, logical, and physical controls and whether such controls are preventive, detective, or corrective in nature.
7.  Identify and describe the current use of multi-factor authentication for any systems or applications.
8.  Describe your institution's due diligence process regarding information security practices that is used in vetting, selecting, and monitoring third-party service providers.
9.  Describe all application development standards utilized by the organization, including the use of a secure software development life cycle, and the extent to which security and privacy requirements are assessed and incorporated into the initial phases of the application development process.
10. Provide a copy of, to the extent it exists in writing, or otherwise describe, the organization's incident response program, including how incidents are reported, escalated, and remediated.
11. Describe the extent to which information security is incorporated into the organization's BCP/DR plan, how and how often the BCP/DR is tested, and the results of the most recent test.
12. Describe any significant changes to the institution's IT portfolio over the last 24 months resulting from mergers, acquisitions, or the addition of new business lines.

 Analysis:

It is a positive step forward for New York State Department of Financial Services to require its chartered financial institutions to meet minimum guidelines for the security of its information technology processes.  These security baselines are critically important not just to financial services institutions but to all public and private entities.  Since NYS has published these official rules it should now become the benchmark or de facto standard by which all other organizations are measured against.  These rules are appropriate and an outstanding starting point for any one who is not sure where to start.

The federal government provides an seemingly endless amount of guidance for the protection of information technology assets.  The fed's use the NIST framework and numerous NIST publications to assist everyone involved in the security of IT assets.  The federal regulators have been the go to professionals in the banking space for establishing standards so its not unusual to hear from Mr. Anderson of OCC or any of the regulators who are apart of the FFIEC. 

What is the news with this New York letter?  The federal regulators often calibrate their examinations according asset size.  Thus larger institutions receive more intense evaluation then smaller organizations.  However, New York has a very specific set of rules in which every institution must be prepared to comply with.  This is not a little matter and could have significant cost ramifications. 

Lastly, I have for years heard from administrators, mangers and CISO's who have tried to get budget authority to make the purchases necessary to secure their environments.  I am suggesting that security personnel use the NYS standards to present to CFO's as justification for future purchases.

http://dfs.ny.gov/about/press2014/pr1412101.htm

http://dfs.ny.gov/banking/bil-2014-10-10_cyber_security.pdf

www.americanbanker.com/news/bank-technology/occ-our-cybersecurity-exams-are-plenty-detailed-too-1071708-1.html

http://www.americanbanker.com/

Tuesday, December 2, 2014

Ten Mistakes that Boards Make


Too often we are learning of executive level errors or omissions which cause massive breaches to the data or PI of millions of citizens.  Here's the "Ten Mistakes That Board Make".

         1. Not Asking Questions

2. Failing to Understand the Company and the Risks it Faces
3. Failing to Lead on Ethics and Compliance
4. Not Insisting on a Crisis-Management Plan
5. Speaking out in a Crisis Before the Facts are in
6. Relying on the Wrong Outside Counsel
7. Failing to Understand Attorney-Client Privilege
8. Underestimating Regulators
9. Giving too Much Leeway to Rainmakers
10. Getting Caught Up in the dilemma of False Options
Taken from the magazine Corporate Board Members, an article written by Randy Meyers.
Make Integris Security your Chief Risk Officer (CRO) as the independent keeper of oversight in your corporate enterprise.  It is the job/function of the CRO to keep regulator awareness at a high level and to let the business be in charge of risk management.
Integris Security LLC grew from our passion for protecting our nation’s critical infrastructures and years of providing industry professionals with best of breed solutions, proven best practices and top notch security education. We work tirelessly to nurture our clients’ TRUST. We will work equally diligently to EARN your trust.


Reference: http://operationalrisk.blogspot.com/2014/11/top-ten-mistakes-board-of-directors-risk.html
 

Tuesday, June 3, 2014

Uncertainty, risky first half of 2014...the year of the hack?

Pushing the buttons of millions of individual Americans is the fact that their accounts have been hacked according to Larry Ponemon at the Ponemon Institute in a study conducted for CNN Money.  Ponemon's study gaged that 47% of adults had their accounts hacked during 2014, which may soon become known as "the year of the hack".  That's just about half of all adults in the United States.

The facinating numbers come at the heals of the Target breach which we have been discussing on this blog and doesn't include the millions in the latest eBay Breach.  Its raining on the American Public as millions of  (PII) records are exposed.  Here are the facts and figures Ponemon and Jose Pagliery of CNN have dug up for CNN Money:

"Cyber attacks are growing so numerous that we're becoming numb to them. Researchers at IT company Unisys (UIS) say we're now experiencing "data-breach fatigue." Even the most recent numbers make for a dizzying list:

More numbing then the facts and figures presented by Ponemon Institute for CNN MONEY is the fact that the industry has not adopted better and well known security practices as a whole.  Need I go on?  For ten years industry has been digging a hole deep in the sand and sticking their preverbal heads in the hole.  See my blog post on accountability.

Let's not blame it on companies looking at profits after all isn't that why companies are in business to begin with.  However we too pause, when companies select tactical gains to satisfy quarterly earnings statements and maybe making themselves look good as opposed to the overall strategic growth and health of a company or corporation.  Read responsibility to share holders, and company employees. To some extent the risk Vs reward discussion will come up and when presented executives will nervously select profits.  Until boards reflect the knowledge, skills and abilities necessary to make both tactical and strategic management decisions we will continue to see the deep decline and clearly the never ending "year of the breach".  Operational executives will respond in kind when Boards of Directors begin to ask the thorny questions which should focus on the strategic growth of the company.  Employees will then be motivated and hear the clarion call from mount high when the CEO comes back from the board meeting and says they want more security and assurance before we can bring that function on board, who certified that code, who tested it and who is taken ownership of the relationship with the software team?

Here's hoping that the second half of 2014 is the year of Board of Directors active and attuned to what is going on not only in the front office but every office.  That function continues to thrive and work closely if not right next to the security team.  That multi-factor authentication is used not just for outsiders, but insiders as well.  That outside relationships are clearly defined and SLA's (service level agreements) are scoped out to protect both the vendor and the company.  That data which can be held in a planet sized computer terminal or a tiny smart phone is protected and preserved because we should all enjoy a level of privacy.   That when we buy the state of the art upstream gadget that detects attacks and when alarms go off and people start screaming at the top of their lungs someone will listen and will have been properly trained on the use of the gadget and that it is properly configured. All very hopeful that the year end will be better than the start.  The future is now before us.  Let's see how we do!

Good luck everyone!