Huawei rules tech world…wins the "Best Integrated ... » Barcelona, Spain: Vigilance can Huawei, a leading global information and communications technology (... Leader’s boy’s volcanic tendency gives Ki-moon sle... » Impetuous and attention-seeking leader’s boy gazing at the enemies' location? Ban concerned ab... Bojo and MPS launch competition to design new Met ... » Vigilance can report that the Mayor of London Boris Johnson and the Metropolitan Police Service ... Fleet operators urged to buckle up as cash-for-cra... » crash-cam-print-van With cash-for-crash scheme convictions taking place all over the country, fl... Imtradex raises unobtrusive communication to a ne... » Dreieich: Covert investigations, observations and many other applications of police, security firms... Prolexic tracks more than 47 million DDoS attack B... » HOLLYWOOD, FL: Prolexic, the global leader in Distributed Denial of Service (DDoS) protection ser... LG bullet proves a popular choice with the UK ins... » Pro-Vision, the UK distributor of branded CCTV and access control equipment has recently published t... Opengear named "Cool Vendor" in the Gartner IT/OT ... » Las Vegas: Opengear, a leading provider of next-generation cellular out-of-band management solutions... Palo Alto Networks achieves rigorous common criter... » London: Palo Alto Networks firewalls have achieved Common Criteria certification at Evaluation Assur... Copy cat, copy cat sitting on the doormat - Barrac... » Last week Google announced that it is unifying storage across its products and influenced by this ne...

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

Information Security Header

You might wonder when lightning will strike your IT shop, but it’s easier to prevent than you might think. When lightning struck Knight Capital, it hopefully was a one-time event. Yet, why has this bolt struck so many times elsewhere? To prevent, leaders need to take three key lessons to heart.

 

On 1 August 2012, an installation problem in Knight’s software blasted out a gusher of erroneous stock trade orders. After trading out of all those errors, Knight suffered a pre-tax loss of about US $440 million. That’s an Olympic-sized loss that happened almost as fast as a star athlete’s stumble in London.

US Securities Exchange Commission Chairman Mary Shapiro remarked, “Reliance on computers is a fact of life not only in markets everywhere, but in virtually every facet of business. That doesn’t mean we should not endeavor to reduce the likelihood of technology errors and limit their impact when they occur.”

Endeavor how? Should we do more of the same? Recall high-profile software release errors – stock exchanges in Germany and Japan (twice), bank in Canada (twice) and a leading wireless network. These headline-grabbing failures are just a fraction of broader IT-related business risks that include: investment/portfolio, program/project and operational (operationally stable, available, protected and recoverable). What must change?

Olympic athletes change when a technique isn’t working, and so must we. Companies can change their game to better:

• Prevent incidents

• Enable faster business value creation

• Avoid the wasted time and money that too often accompany risk management

Three Lessons

First, focus on the objective. Manage IT-related risk to business performance objectives. In team sports, it’s not just about defense; it’s about more safely moving on offense. This scores in sports and creates growth in the economy. Further, with focus on performance, risk management can more deeply engage the organization, embedding in every decision and process needed to reach the objectives.

Second, learn from history. Companies caught in the frenzy of “now” ignore the methods and painful lessons of the past. For example, nearly 100 years of refined method in reducing both process and hazard risk is largely unknown in most risk management organizations. Instead, the wheel is reinvented, often drawing on post-Sarbanes-Oxley financial reporting and compliance-based approaches that structurally don’t fit in changing and complex environments such as IT. That’s like each year’s Olympic swimmers starting with the dog-paddle stroke.

Third, properly frame the problem. IT is a complex and changing system. Dependencies must be understood. Typical collections of controls and compliance bandages leave companies forever shocked and rocked by the latest incident. The expectation should be that problems (malicious, natural, accidental and volume-related) will arise and plan B must be ready (if only London Mayor Boris Johnson had one of those for his zip wire act). In short, a systematic fix for a system is needed to avoid painful surprises.

In summary, leaders must act to shift from:

• Compliance/control-driven to performance/systems-driven risk mgmt

• Reinventing the wheel to learning from history (situations and methods)

• Conducting tick-box exercises to rigorously asking "what if?"

• Compliance overlay activities to embedding risk-awareness in daily decision-making and processes.

 

***Barnier is risk advisor with ISACA, principal analyst of ValueBridge Advisors and author of The Operational Risk Handbook.

Add comment


Security code
Refresh