/* ---- Google Analytics Code Below */
Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Friday, February 19, 2021

Fine Tuning Vendor Risk Management

Crucial these days. 

How to Fine-Tune Vendor Risk Management in a Virtual World  in Dark Reading by Ryan Smyth & Spencer MacDonald Managing Director / Director, FTI Technology  

Without on-site audits, many organizations lack their usual visibility to assess risk factors and validate contracts and SLA with providers.

Vendor risk management is nothing new to most security and privacy professionals. Programs for managing vendors are typically well-established and have run like clockwork for quite some time — with many firms requiring their critical vendors to allow access for periodic on-site assessments of privacy, security, and other controls. But as with so many things this year, the coronavirus pandemic has brought well-oiled vendor risk management processes to a screeching halt. Now, without the ability to conduct on-site audits, many organizations lack their usual visibility to assess risk factors and validate whether their providers are doing all they have agreed to in their contracts and service-level agreements (SLAs). 

This is particularly concerning given that vendors and third-party providers are a prime source of breaches in security, privacy and/or compliance. Risk Based Security reported that the incidence of breaches, "involving companies handling sensitive data for business partners and other clients," rose by 35% from 2017 to 2019 and exposed 4.8 billion records last year. ... '

Wednesday, November 18, 2020

Supply Chain: Its Now about Risk

Now even more so, its about risk. Measuring, predicting and addressing.

Supply Chain Risk Management - Reach the Next Level of Supply Chain Maturity

 Marcus Evans in SupplyChainBrain

Following a number of successful Supply Chain Conferences, marcus evans is now organizing the Supply Chain Risk Management: Resilience & Diversity Conference on the 18th to 20th of January 2021 Online through their Live+ digital platform. 

The unprecedented pandemic and economic freeze COVID-19 has brought about brings even more into focus the current lack of resilience of global supply chains. The global pandemic has revealed all of the risks and weaknesses plaguing the way current supply chains work, but it also represents a big opportunity for this big transformation to be pushed through much quicker than it would have been otherwise. Companies now have an unprecedented opportunity to adjust their entire supply chain to a new model, one that is more flexible, that brings in new products and an overall culture change.  ... " 

Friday, October 09, 2020

Views of Future Risks

We rarely look at risks well.   Thoughts and directions.  

A Holistic View of Future Risks  By Peter G. Neumann

Communications of the ACM, October 2020, Vol. 63 No. 10, Pages 23-27   10.1145/3417095

This column considers some challenges for the future, reflecting on what we might have learned by now—and what we systemically might need to do differently. Previous Inside Risks columns have suggested that some fundamental changes are urgently needed relating to computer system trustworthiness.a Similar conclusions would also seem to apply to natural and human issues (for example, biological pandemics, climate change, decaying infrastructures, social inequality), and—more generally—being respectful of science and evident realities. To a first approximation here, I suggest almost everything is potentially interconnected with almost everything else. Thus, we need moral, ethical, and science-based approaches that respect the interrelations.

Some commonalities across different disciplines, consequent risks, and what might need improvement are considered here. In particular, the novel coronavirus (COVID-19) has given us an opportunity to reconsider many issues relating to human health, economic well-being (of individuals, academia, and businesses), domestic and international travel, all group activities (cultural, athletic, and so forth), and long-term survival of our planet in the face of natural and technological crises. However, there are also some useful lessons that might be learned from computer viruses, malware, and inadequate system integrity, some of which are relevant to the other problems—such as computer modeling and retrospective analysis of disasters, supply-chain integrity, and protecting whistle-blowers.

A quote from Jane Goodall in an interview in April 2016 seems more broadly relevant here than in its original context: "If we carry on with business as usual, we're going to destroy ourselves." The same is true of my quote from the early crypto wars regarding export controls: "Pandora's Cat Is Out of the Barn, and the Genie Won't Go Back in the Closet." We are apparently reaching a crossroads at which we must reconsider potentially everything, and especially how it affects the future.  ..." 

Monday, May 25, 2020

Useful Plans vs the Activity of Planning

Below the intro to former IBMer  Irving Wladawsky-Berger article on planning vs plans ...  much more at the link.  I like especially the differences when you meet with different kinds of events and seek cures for them.  Resilience has to address all of them meaningfully,  risk management is one key tool.

Even When Plans Are Useless, Planning Is Indispensable

“As scientists race to develop a cure for the coronavirus, businesses are trying to assess the impact of the outbreak on their own enterprises,” wrote MIT professor Yossi Sheffi in a February 18 article in the Wall Street Journal.  “Just as scientists are confronting an unknown enemy, corporate executives are largely working blind because the coronavirus could cause supply-chain disruptions that are unlike anything we have seen in the past 70 years.”

Sheffi is Director of the MIT Center for Transportation and Logistics.  He’s written extensively on the critical need for resilience in global enterprises and their supply chains, - including The Power of Resilience and The Resilient Enterprise, - so they can better react to major unexpected events.  Covid-19 is the kind of massively disruptive event he had in mind when he wrote those books.

While learning from historical precedents is always a good idea, recent supply chain disruptions - the 2003 outbreak of SARS in Asia, the 2011 Fukushima nuclear disaster, or the 2011 Thailand floods, - were very different from our current pandemic.  Those events were much more localized, lasted a relatively short time, and they mostly impacted supply, not demand.  The impact of Covid-19 is much bigger, affecting consumer demand as well as supply chains all over the world, and likely to last quite a bit longer.  “Today’s supply chains are global and more complex than they were in 2003,” with factories all over the world affected by lockdowns and quarantines.  Apple, for example, works with suppliers in 43 countries.   ... "    (much more below in the article) 

Wednesday, October 30, 2019

Michael Goodkin on Getting Answers Faster

Recent reading inspires some thoughts.

Struck me that such methods what we are doing today.  Is faster always better?  And may be further advanced by technologies like 5G.   Depends on the risk involved and how it is managed.

The Wrong Answer Faster: The Inside Story of Making the Machine that Trades Trillions

(Michael Goodkin).   His company's original investment techniques became known as statistical and quantitative arbitrage. By 1996, these techniques accounted for most of the volume on the global exchanges and the financial derivatives market. Having resettled in Chicago, Goodkin then set out to make the market less risky by introducing computational physics to derivatives risk management.[1]

Goodkin’s most successful start-up was Numerix. Recruiting a group of academic physicists, including Mitchell Feigenbaum, winner of the MacArthur grant and the Wolf Prize in Physics for his pioneering work in Chaos Theory, Numerix was founded in 1996. The company’s initial product was a software algorithm that dramatically reduced the time required for Monte Carlo pricing of exotic financial derivatives and structured products. Numerix remains one of the leading software providers to financial market participants.[3]   .... "

Sunday, October 13, 2019

Examining Smart City Backlash

A look at how people are reacting to 'smart' and trust, and surveillance and privacy stretching that are parts of smart city plans and implementations.  Is it best to see these ideas as primarily cost saving and life improving?  Or addressing outliers like solving and preventing crime in city spaces?     Both are happening today.

https://penniur.upenn.edu/  Penn Institute for Urban Research

What’s Fueling the Smart City Backlash?

A new phase of pause and double-check assumptions seems to have gripped the three-decades-old global movement of overstressed urban centers transitioning to so-called smart cities with innovative, technology-led promises. The latest phase is marked by scattered, local-level resistance by residents to smart-city programs in big cities like Toronto and New York to small towns such as Ross, California — near San Francisco — with less than 2,500 residents.

Other cities have banned specific technologies such as facial recognition software, amid doubts over its accuracy or concerns over cities stealthily collecting such data on their citizens through video surveillance. In some cases, they see technology companies forming opaque partnerships with city-level agencies to profit from projects at their expense, using public resources such as land and development rights.

Fears over privacy intrusions in today’s digital age and unbridled development compromising the public interest have been heightened by the erosion of trust between residents, city administrations and private companies leading “smart” projects. With increased transparency, and stronger citizen engagement, the smart-city movement could regain lost credibility and continue its growth, according to experts who spoke with Knowledge@Wharton.

For the most part, residents are wary about how city governments and big technology companies involved in the projects will track and collect data about their daily activities while not compromising their privacy and security by selling data without their consent. In several cases, legislators in many U.S. states have enacted or are considering laws to ban or limit the erection of 5G cell towers because of health concerns.

Data privacy and security issues are more sensitive in some settings than others. “Smart cities mean different things to different people, but big data is intrinsic to these initiatives and thus privacy concerns arise,” notes Susan Wachter, Wharton professor of real estate and finance. “However, some initiatives such as coordinated traffic lights are high on efficiency and low on privacy issues — and they are no brainers. Others, such as tracking people — much as is done in private places such as malls — provoke a backlash because they undermine the anonymity privilege of public spaces.” ... '

Tuesday, September 10, 2019

Third Party Risk Analysis

Recorded Future writes about the topic.  We examined them for things like competitive risk.   But this topic, especially in today's realm of many technology mal-players, large and small, makes the issue of particular importance.   Below just an intro, much more at the link.

Third-Party Risk Intelligence: Past and Present
SEPTEMBER 10, 2019 • THE RECORDED FUTURE TEAM

After months of searching, budgeting, and vetting, you’ve found the perfect vendor to help take your product offering to the next level. You’re excited to start working together and you’ve initiated the onboarding process. The company has provided the requisite new vendor questionnaires and documentation, and your governance, risk, and compliance (GRC) system has assessed the company for risk and found its current risk score to be acceptable. Everything seems in order.

But what you don’t know is that your soon-to-be partner was the target of a highly stealthy and successful malware attack just nine months ago. They may have taken the appropriate steps to resolve the incident, but wouldn’t you still want to be aware of it?  .... " 

Friday, March 15, 2019

Supply Chain Risk Management

I repeat, risk is rarely well tracked and evaluated.

A practical approach to supply-chain risk management

In supply-chain risk management, organizations often don’t know where to start. We offer a practical approach.

Sent from McKinsey Insights 

Friday, May 18, 2018

Introducing Vulnerability Management

The specific term is new to me, but have worked the risk management direction for a long time.  At the link much more including the references mentioned.

We Scan and We Patch, but We Don’t Do Vulnerability Management  by Anton Chuvakin  in Gartner

Lately, we’ve been flooded with calls about vulnerability management (VM). Many of the calls seem to be from organizations of medium to low security operations maturity, that are just starting with vulnerability management [and that’s OK – a wise mentor once told me ‘always remember that ‘90% of people are not in the top 10 percentile!’” :-)]

Many of them say something similar to “we scan and we patch, but we don’t do vulnerability management.” Essentially, they are coming to a realization that I often like to summarize as “VA is easy, but VM is hard.”

Of course, we have a lot of excellent research written on this topic:

“A Guidance Framework for Developing and Implementing Vulnerability Management” (39 pages of juicy VM stuff!)
“How to Implement Enterprise Vulnerability Assessment”
“A Comparison of Vulnerability and Security Configuration Assessment Solutions”  ... "

Monday, April 02, 2018

Talk: Adversarial Risk Analysis

Of interest in particular, due to the adversarial element.   Risk analysis does not often enough consider the intelligent nature of agents that create risk.   Competitors for example, and now even intelligent agents in the form of assistants or other machine driven systems.

The OBAIS department at the Lindner College of Business, University of Cincinnati, invites you to attend the Lindner Research Excellence Seminar and Professional Development Discussion:

Research Seminar:
Date and time: Friday, April 6, 2018, 10:30AM-12:00PM 
Location: Lindner Hall 218
Speaker: Dr. David Banks, Duke University
Title: Adversarial Risk Analysis

Abstract: Adversarial Risk Analysis (ARA) is a Bayesian alternative to classical game theory. Rooted in decision theory, one builds a model for the decision-making of one's opponent, placing subjective distributions over all unknown quantities. Then one chooses the action that maximizes expected utility. This approach aligns with some perspectives in modern behavioral economics, and enables principled analysis of novel problems, such as a multiparty auction in which there is no common knowledge and different bidders have different opinion about each other.

This presentation is based on:
Rios Insua, D., Rios, J., Banks, D. L., “Adversarial Risk Analysis,” Journal of the American Statistical Association, 2009.
https://www.tandfonline.com/doi/abs/10.1198/jasa.2009.0155
Banks, D. L., Rios, J., Rios Insua, D., “Adversarial Risk Analysis,” Chapman and Hall/CRC, 2015, ISBN 9781498712392.

https://www.crcpress.com/Adversarial-Risk-Analysis/Banks-Aliaga-Insua/p/book/9781498712392

Best wishes,
Yichen Qin,  Assistant Professor
Department of Operations, Business Analytics, and Information Systems
Lindner College of Business, University of Cincinnati
Website: http://business.uc.edu/academics/departments/obais/faculty/qinyn.html
Email: qinyn@ucmail.uc.edu


Wednesday, November 15, 2017

Risk Detection is Important

Not often covered well enough, worth thinking about.  Detecting the Risk, working with business partners to understand its implications, is important.  In my observation, not often done well. 

The neglected art of risk detection by  Piotr Kaminski and Jeff Schonert in McKinsey

At the core of risk management is risk detection, an art that can be skillfully improved if banks and regulators accept new analytical methods.

The modern risk-management framework generally relies on the “three lines of defense” scheme, with the businesses, control functions, and audit as the first, second, and third line, respectively. The concept borrows from the language of military strategy, in which intelligence plays a key role. For risk management, intelligence means effective detection: to prevent the bank’s reputation, liquidity, and capital position from being harmed, the lines of defense must detect risks early.

Detection is fundamental in risk management, embedded in its activities and processes. Credit scoring, for example, is a tool for detecting potential borrower-default risk at the application stage, while customer due diligence is designed to identify high-risk customers during the onboarding process, as part of the bank’s know-your-customer (KYC) program. Risk managers are practicing the art of detection when they identify instances of fraud, spot a drifting investment strategy in an asset-management business, monitor their network’s end points to locate cyberintrusions and data theft, or identify potential rogue traders.

Most executives and risk professionals will quickly acknowledge the basic importance of detection. Yet the efficacy of detection—and the levels of “detection risk”—vary widely among risk disciplines and from bank to bank. With poor detection, threats can rise to existential proportions, as some of the world’s largest institutions have learned in recent years. Weak detection capabilities can be costly. Manual controls, for example, are not especially effective and yet they always cost more than automated controls. Poor detection can result in high levels of false positives and the needless diversion of valuable risk resources. .... " 

Tuesday, June 06, 2017

Machine Learning Engineers

Good to see the practical and operational aspect of this.  Usually assumed in other roles.Would hope this includes getting closer to business process and risk analysis. In O'Reilly

What are machine learning engineers?
A new role focused on creating data products and making data science work in production.By Ben Lorica, Mike Loukides ...

Friday, May 26, 2017

Brian Christian Talk on Algorithms and Decisions

Brian Christian spoke at our Innovation Summit last week.   Very nicely done and informative. Makes me want to read his book on the use of Algorithms.  Not so much about about to do the analytics to get to some solution,  but how that solution can be inserted into real decisions.  So its not the algorithm, but the algorithm in its solution context.  Sound familiar?  My long time hammering about also understanding and modeling the process.  How often do we avoid knowing the process before diving in with a solution?  Too often.  And we can be wrong.  I would like these risks to be better explored.

Does a nice job of using the Explore/Exploit dilemma to think about the problem.    Quoted a number of useful research efforts in this area.  We need to understand this very well before we seek to automate everything.   He suggests in his prolog:  " ... will discuss both how we can leverage insights from these fields to develop better intuitions in our own thinking, as well as how our human values and principles might translate into an era of increasingly automated decision-making.  ...  "

Thursday, December 22, 2016

Minimizing Disaster Insurance Risk

Podcast

Wharton's Howard Kunreuther discusses his report on the insurance industry surrounding catastrophic events.

Hurricane Matthew wreaked havoc in Haiti before causing massive damage to parts of the southeastern United States earlier this year. In the Carolinas, flooding damage from the storm was assessed at more than $1 billion. Insurance against a catastrophic event, such as a hurricane or earthquake, often is not purchased by consumers or purchased too late. The most common reason is that homeowners believe the odds are stacked in their favor. Howard Kunreuther, Wharton professor of operations, information and decisions and co-director of the Wharton Risk Management and Decision Processes Center, put together a report that looks at the insurance industry surrounding catastrophic events. He recently appeared on the Knowledge@Wharton show, part of Wharton Business Radio on SiriusXM channel 111 to talk about what can be done to improve coverage and minimize risks. .... " 

Thursday, February 25, 2016

Biases in High Stakes Decision Making

Talk today on a favorite topic:  Cognitive Bias.   I will post links to presentation afterwards:

" ...  Just a reminder about our Cognitive Systems Institute Group Speaker Series on Thursday, February 25, 2016 at 10:30 am ET (7:30 am PT).  Our presenter this week will be Dominique Liana Russo from Harvard University who will present "Biases in High Stakes Decision Making."   ... 

Slides.  

Please find the schedule of presenters herefor the next several calls and please sign up for making a presentation by sending a note to me (fodell@us.ibm.com).   A link to slides and a recording of each call will be available on the CSIG website (http://cognitive-science.info/community/weekly-update/).   
We encourage those who join the calls to add questions and comments to the https://www.linkedin.com/groups/Cognitive-Systems-Institute-6729452on LinkedIn and we ask that you ask questions at the end of the call.xpressive TTS ....  "

Wednesday, December 23, 2015

Changes in Managing Risk

Noting the need to connect risk directly to relevant decision process.

How Managing Risk Has Changed    (Podcast and Transcript)
The problem with many catastrophic risks isn’t just that their impacts, when they hit, are so massive. It’s also that their odds of occurring in any given short time frame are very small, so that planning for them has to be handled as a long-term priority while the proverbial sun is shining. And neither companies nor individuals are particularly apt at taking serious, long-term action to prepare for low probability, high consequence events.

Enter the Wharton Risk Management and Decision Processes Center, which was created 30 years ago to help individuals, businesses, governments and global organizations to be better prepared for those longer range, more unpredictable dangers.

Knowledge@Wharton spoke with Howard Kunreuther and Robert Meyer, co-directors of the Wharton Risk Management and Decision Processes Center, and executive director Erwann Michel-Kerjan about the center’s research and how managing risk has changed over the past few decades. ... " 

Saturday, November 14, 2015

Fail at Scale

In CACM: Reliability and the science of graceful failure.  Abstract, full article requires registration.

Tuesday, November 03, 2015

The Ultimate Assistant: Intelligently Answering your Email

In Wired:  The ultimate business application of intelligent assistants.    Could save time, promote focus, record value, link to business process.  But how well will it work?   Note that the replies will be very short, at least to start with.  You choose among the suggestions.  What are the risks of letting a Cog answer your mail?

Soon, Gmail’s AI Could Reply to Your Email for You
EVER WISHED YOUR phone could automatically reply to your email messages?

Well, Google just unveiled technology that’s at least moving in that direction. Using what’s called “deep learning”—a form of artificial intelligence that’s rapidly reinventing a wide range of online services—the company is beefing up its Inbox by Gmail app so that it can analyze the contents of an email and then suggest a few (very brief) responses. The idea is that you can rapidly respond to someone while on the go—without having to manually tap a fresh message into your smartphone keyboard.

“The network will tailor both the tone and content of the responses to the email you’re reading,” says Google product management director Alex Gawley. It gives you three of these responses, and you can then choose the one that best suits what you want to say. ... "

Thursday, October 22, 2015

Cyber Insurance Policies

In the CACM:   A good overview of the direction and providers of Cyber insurance policies.

" ... The cyber attacks carried out against Sony, Target, Home Depot, and J.P. Morgan Chase garnered a great deal of press coverage in 2014, but data breaches, denial-of-service attacks, and other acts of electronic malfeasance are hardly limited to large, multinational corporations. However, it is the high-profile nature of these breaches—as well as the staggering monetary costs associated with several of the attacks—that are driving businesses of all types and sizes to seriously look at purchasing cybersecurity insurance.

Currently, the global market for cybersecurity insurance policies is estimated at around $1.5 billion in gross written premiums, according to reinsurance giant Aon Benfield. ... "

Thursday, October 15, 2015

Considering Risk Assessments

In CWorld: Good short basic piece on basic risk assessments. Good place to start.  I would further get a professional to do the analysis that really knows the domains involved.   Start with visual methods to display the risk metrics.  Double and triple check your numbers.  You may get many numbers that vary wildly, so show them to multiple experts.  Create a risk portfolio with estimates of costs to address each risk.  Keep a log of near misses and past issues.    Do list 'black swans' and what their effects might be.