Showing posts with label security risks. Show all posts
Showing posts with label security risks. Show all posts

The Security Outlook for 2014



               This is the time of year when we find ourselves thinking of New Year Eve’s parties, confetti, Auld Lang Syne and resolutions for the new year (usually around getting rid of the pounds we put on during Christmas). There is also the stream of news stories about the past year, the top stories and the events and people that shaped the year. It is also a good time to take a glimpse into the coming year and think about the changes, challenges and rewards that lie ahead.

               Security, and how security relates to business, is constantly changing as well, so this is a good time to reflect and plan for the future.

Information Security
Cyber risks are a global concern

               Information security will continue to be a top focus when it comes to security. With the latest breach of credit and debit cardholders who shopped at Target, there is the ongoing fear of identity theft. The investigation continues on how hackers were able to collect all that information, including PINs for debit cards. How much of this was actually used remains to be seen or if it was an inside job. However, it has garnered a lot of media attention and brought identity theft and information security back into the spotlight. It would be surprising if there were not a push for some new legislation as a result of this, including penalties to businesses that expose customers.

               Another top concern related to information security and hacking is the risk of cyber-attacks, especially on critical infrastructure such as power grids. There have been various attacks, including some coming from foreign governments, such as China and Iran. A serious attack on utilities could essentially put the United States back in the stone ages in moments and would certainly wreak havoc.

               The hidden risk is the continued shift of focus away from physical security. Protection from physical attacks should never be overlooked. There have been a number of actual attacks, including active shooters, even the recent suicide bombs in Russia. 

NSA
               The story of Edward Snowden, the wayward NSA contractor, fleeing the country with tens of thousands of confidential documents is not going to disappear any time soon. There are legal repercussions ongoing and the question of how much information the NSA (National Security Agency) can legally gather from citizens will almost certainly end up before the U.S. Supreme Court.

               In the meantime, Snowden still has tens of thousands of additional documents that could be released and we can only speculate what kind of information might be within. The revelations have re-ignited the debate between security and liberty. Benjamin Franklin is known for saying that those who value security over liberty deserve neither. In 2014, we will certainly see more debates on how to balance protection from terrorists while protecting individual privacy and our constitutional rights. There is an additional question related to security; how did the NSA, of all groups, miss the dangers of allowing a contractor, not even a full employee, access to so many confidential documents. You have to wonder what kind of background screening was done as well. That leads to the question of how the NSA can manage gathering so much information and find the true threats when probably 99% of the information is useless.

Pay Inequality

               The World Economic Forum’s annual report has identified economic disparity has one of the top risks facing the globe. It is certainly an area getting a great deal of attention, not just between poor and wealthy nations, but even within developed countries. The U.S. president routinely brings up the issue as a champion of the downtrodden, who in turn express their outrage at being poor across social media with their iPhones. 

               In truth, there is a growing problem. Historically, top executives once earned about 20 times what the average employee made. Today, it is not uncommon for top executives to earn 200 or even 500 times what the average employees earn. Worse, household income has dropped over the last few years while corporate profits have been increasing. That is a recipe for discontent and social unrest. Switzerland, a business-friendly nation, nearly passed a restriction that would have limited executive pay to only 12 times the pay of the lowest-paid employee.
 
News Photo
               The risk is disturbances or even riots, is a very real threat that could impact supply chains and disruptions of service or even strikes. We have seen a variety of businesses that boast of being ‘green’ or promoting ‘fair trade’ and it is likely that some forward thinking businesses will promote themselves for caring for employees and having more equitable pay scales.

Obamacare

               A look at business risks cannot ignore health insurance reform, a top issue in the United States, specifically the Affordable Care Act, aka Obamacare. Within the healthcare industry there is great uncertainty and talk of cost control, i.e., lay-offs. Meanwhile of the 40 million uninsured Americans, only 1 million signed up for Obamacare. Most Americans are finding that the costs are anything but affordable. 

               Certainly, health insurance is going to be a hot topic, within both politics and healthcare, but also one that impacts every business and individual with insurance. The deductibles and monthly premiums are increasing. Businesses that provide services to hospitals should be particularly wary, as the hospitals will squeeze every contract for savings. Likely, the only things that will not change are the salaries paid to the physicians.

Active Shooters


               Shootings in Colorado and at Sandy Hook Elementary have sparked debate on care for mental health patients and gun control. School security has been a particular focus. Just like after 9-11, when there was a sudden emersion of so-called terrorist experts, there is now a rush of school security experts with arrays of solutions. Training teachers how to fight armed attackers with knee strikes and elbows is becoming more commonplace, although there still seems to be reluctance to add well-trained, armed guards to schools (expense is part of the concern). Learning to fight back is great, but it would be better yet to have the right tools for the job.

               The risk is that attackers also learn from news coverage and will adapt their plans to harm as many people as possible. Schools and all organizations need to consider other potential tactics, such as explosives, chemicals or gas attacks and so forth. Terrorists have used similar methods around the world for decades, sometimes with horrific effect. Do not get tunnel vision.

All the Usual

               In 2014, we will see our share of bizarre and strange crimes. Lust and greed fuel evil people into all sorts of crazy schemes. If any involve beautiful women or tales of sex as part of it, you can expect the usual media frenzy. Oh. Don’t forget the usual celebrity stories with drugs, alcohol, rehab and relapses and whatnot. Did I mention Duck Dynasty?

               Fasten your seat belt and hold on. 2014 will certainly be another interesting year.



Eric Smith, CPP is the leading authority on organizational self-defense. He has extensive experience in law enforcement as well as security management. Eric is available for staff education and security awareness training as well as business coaching to help organizations provide safe workplaces. To learn more email Eric at businesskarate dot com.

  

If you would like to reprint this post, please contact Eric at Eric at businesskarate dot com.

Reality of Gun Violence


Once again, we’ve seen a tragic and senseless mass murder, this time in Washington D.C. at the Navy Yards. Twelve victims were left dead after Aaron Alexis walked through the building with a sawed-off shotgun picking off targets.

Too often following these horrific events, the knee jerk reaction is to focus on gun control even over how to identify warning signs.
Sponsored Link-
Friend of Foe? Learn how to deal with visitor access with this special report (click here).
 

There is a great deal of talk about active shooters and many security professionals focus on active shooter responses. Certainly, that is a critical part of a comprehensive emergency management plan and from some of these events it is clear that armed security can be a deterrent or stop the attacks before more people are hurt.

It is wise to take a step back from the hype and look at some of the data behind gun violence to keep it in perspective.

According to FBI statistics, less than 10,000 people are killed by firearms each year. That certainly sounds like a very large number. However, that is much less than many other dangers that garner little, if any, attention.

In comparison, look at the data below and think about where the greatest risks actually are.

            From a security perspective, violence is a very real concern. Understanding of risk factors and identification of red flags should be a top priority. However, be careful not to get caught up in the hype. Leave that to the media and politicians.

 

Eric Smith, CPP is the leading authority on organizational self-defense. He has extensive experience in law enforcement as well as security management. Eric is available for staff education and security awareness training as well as business coaching to help organizations provide safe workplaces. To learn more email Eric at businesskarate dot com.


If you would like to reprint this post, please contact Eric at Eric at businesskarate dot com.

Avoid Becoming a Victim with 3 Simple Tests


What do crooks look for? Why do burglars pick one house over another? What does a terrorist look for in a target? What do ordinary criminals and terrorists have in common for that matter?


Crooks and terrorists may not be so different after all. No matter how evil their intent, he (or she) must still select a target in order to carry out their plan. Robbery suspects first look for the loot before planning their heists. Burglars look for evidence that no one is home and terrorists want a big bang (literally) for their buck – high publicity.


One well-known bank robber is credited with the statement that he robbed banks because “that is where the money is.” A robber wants to gain something – that is the whole point of the crime. They want to make sure that the quick win is on hand. Many are feeding drug habits, gambling addiction or alcohol. With these kinds of cravings or obsessions, there is no time to waste. They are looking for something of value that can be turned around quickly for cash or traded for drugs.


1.      Value – The goal is some kind of gain or value. For a terrorist, the value may be high publicity, such as a famous building or critical infrastructure or large number of potential victims. For crooks, it may just be something worth stealing.

Favorite targets of robbers are convenience stores and taxi drivers. It is not too hard to figure out why – both are easy to find and convenient to the crook. In fact, two recent suspects in Denver have called the taxis to their location in order to rob the driver. It doesn’t get much more convenient than that – the victim comes to the crook. These are examples of highly visible targets. Terrorists like visibility too, but in a slightly different way. They want a target that will generate a lot of publicity and garner their group the visibility and attention. Blowing up a bomb in the middle of the desert will not get that attention, as compared to blowing up a crowded nightclub or embassy.


2.     Visible – The target must be visible; crooks have to know it is there and an attack must generate the kind of visibility a terrorist wants. Schools, landmarks or crowded venues will offer that kind of media attention and visibility.

Of course, the crook must be able to achieve their nefarious goal or at least have a hope of it. The famous gold depository at Fort Knox would be an example of something that is highly visible, of high value, but with little chance of success. A terrorist might love to steal a missile from the military, but the chances of getting to it are nil. There is virtually no vulnerability.


3.     Vulnerable – The victim must be susceptible to attack to be a worthwhile target. That is why burglars look for homes with unlocked doors or muggers wait for victims in areas of poor lighting. There is easy access and the element of surprise to help the attacker. Terrorists also need targets that are open to attack. On 9-11, it was relatively easy for terrorists to hijack planes and fly them into the WTC. Today, many of the vulnerabilities that the terrorists exploited have been eliminated.


As an individual or responsible for protecting your business, keep the 3 V’s in mind – Value, Visible and Vulnerable. Evaluate the value that criminals may see in your business. Maintain low visibility when possible to minimize the chance of becoming a target. Last, use appropriate steps to reduce your risk or vulnerability to avoid being a victim.


Eric Smith, CPP is the leading authority on organizational self-defense.  He has extensive experience in law enforcement as well as security management.  Eric is available for staff education and security awareness training as well as business coaching to help organizations provide safe workplaces.  To learn more email eric@businesskarate.com.

 

 

If you would like to reprint this post, please contact Eric at eric@businesskarate.com. 

When Risk Becomes Real

Within the security world, too often crime is nothing more than a statistic, a number.  But behind each number or report there is a victim facing very real losses with very real consequences.
I was reminded recently of what that means, unfortunately, and not for the first time.  It started at 6:30 am on a Saturday morning.  The doorbell rang and my dog starting barking.  I stumbled half-awake to the door and saw a couple of my neighbors from down the street.  They asked if I owned a black Saturn and said that someone had hit it.
Friend or Foe?-
Learn how to deal with visitor access with this special report (click here).


When I went outside, there was a Chevy Blazer parked where my car had been.  The driver was sitting behind the wheel crying.  I asked where my car was and my wife pointed down the street – into the next block.  There was my car sitting in a neighbor’s front lawn.

While waiting for the police to respond, I started to talk to the other driver.  He was really upset because he was driving his mom’s car – only because he had totaled his car when he hit another parked car the morning before a couple of blocks away.  He said that he had started a new job and was tired.  I assumed he was working nights and was surprised to find out that he worked days, which prompted the question of why he was going home at 6:30 am. 
The police arrived and immediately recognized him from the previous accident.  While they began their investigation, I called my insurance company.  Soon there were several more police officers on scene and I saw them going through roadsides with the driver and ultimately arrested him.  He had signs of using meth and admitted to it as well. 
My car would not start and looked like it was going to be totaled.  I tried to get suggestions from the insurance company on what to do with my car.  To make matters worse, we were getting ready to head out of town for almost three weeks.  What a stressful way to start out on vacation.
Accidents like this are an everyday occurrence.  No one was injured and was only a property damage accident.  Even so, it is a real loss and a real headache.  It meant trying to deal with two insurance companies and impound lots while out of town with limited email and cell phone access.  It also meant dealing with replacing my car.  I did not expect a car payment for another couple of years and it was not in the plan or budget.
There is a lesson to all security professionals dealing with crime risks – each statistic has a victim, a person behind the number.  Don’t overlook the human factor when planning and assessing risk and the impact on others.  Even on issues that are seemingly trivial or routine – because they are not to those affected directly.
PS – there is a silver lining.  I now have a new car parked in our driveway (not in the street!), one with better gas mileage and a bit more exciting than a 12-year old Saturn (RIP).

Eric Smith, CPP is the leading authority on organizational self-defense.  He has extensive experience in law enforcement as well as security management.  Eric is available for staff education and security awareness training as well as business coaching to help organizations provide safe workplaces.  To learn more visit http://www.businesskarate.com



If you would like to reprint this post, please contact Eric at eric@businesskarate.com

Corporate Spies and Protecting Proprietary Information

Secret bank accounts in Swiss banks; foreign governments; selling of top secret information and the hint of international intrigue – all combined for what could be a Hollywood thriller, except that it is all based on recent news stories. 
The Wall Street Journal and Bloomberg business news reported on the developing story of corporate espionage at Renault, the French automaker.  Three of the company executives are being charged with corporate espionage after reportedly selling information on Renault’s electric car.  According to one article, Renault has invested over $5 billion in developing electric car technology.
So far, the details are sketchy about what exactly happened.  Reports indicate that a Chinese company may have made payments into the bank accounts of at least two of the executives.  And to add to the damages, the French government is the largest shareholder of Renault bringing this to more of a spy operation between two governments than two competitors looking for an edge.
What lessons can be learned?  And I know what you are thinking…my company doesn’t deal in high-tech products; no one would care about what we do.  Wrong.  Virtually every business and organization has information that, in the wrong hands, could impact their competitiveness or damage their corporate reputation.
Let’s take a look at another big news story this week.  In Arizona, there was the shooting that left 6 people dead and several, including a congresswoman, injured.  In the aftermath, three hospital employees where the victims were being treated were fired for unauthorized access to patient health information (PHI).  It does not appear that anything was actually released, but this is a clear example of another type of proprietary information.  The information may have been accessed out of sheer curiosity or it could be that some news agency might have been willing to pay for a ‘scoop’ on a patient’s condition.  This is a risk anytime a hospital has a VIP patient or even a deceased victim.  Think of all the media attention around Michael Jackson’s death and the money that might have been paid for exclusive photos of his body.
Here are two very different industries and two very real examples of proprietary information and the potential damages.
And what if your business or company provides a service or product that is seen as a commodity…there is no value in any company information at all, right?  In this type of case, your proprietary information may be even more valuable.  As a ‘commodity’ price may be one of your strongest competitive edges, especially when bidding for a contract renewal or for new business.  If you went into a sales presentation and knew exactly what your competitor was going to present and exactly what their price model was, wouldn’t you be able to adjust your bid to guarantee winning the business?  Along these lines, wage information, benefits to employees, training topics and costs, manufacturing techniques and vendor information can all become valuable items to know about competitors.
To prevent the loss of the information, a full risk assessment should be done.  Identifying all critical information is part of that, followed by identifying how that information is exposed and what threats can take advantage of the exposure. 
The easy way to look at risk, is this: risk is what you face when a threat exploits a vulnerability to put a critical asset in jeopardy. 
The real challenge comes with protecting information.  There are so many different ways to access and steal it, as we saw not long ago with the Wikileaks scandal.  The tricky part is that for the information to be of value, the employees of an organization have to have access to it.  The executives in the Renault case were responsible for upper level management positions, including heading up new product development.  This story will be worth watching to learn more about how the theft was uncovered, leading to a five-month long investigation.
In the case of the hospital in Arizona, it is very likely that the hospital’s IT department had some measures in place to see who was accessing electronic medical records.  Since this was a high-profile incident, I imagine that more attention was given to tracking access to any related victims.  As soon as any employee other than those that “needed to know” accessed the information, the IT department quickly checked on whose credentials or log in had been used to close that avenue of potential loss.
So what were those lessons learned?  Spy-proof your business with these four steps:
1.      Identify critical information – think about what your competitors would want to know about you and what you want to know about their business
2.     Review how that information could be vulnerable.  Look at how it is stored, electronically and hard copies.  Is it on a server or specific PC that could be stolen?  Could the data be emailed off your network?
3.     Evaluate the potential threats – usually, in these cases, employees.  Do key employees face regular background checks or screening?  Consider looking at credit issues as well.  Don’t assume that because an employee is higher in the organization that they are more trustworthy.  In the Renault case, the theft occurred at the executive level, not the mail room employee.  Think past criminal intent – employee carelessness with data or falling for social engineering (obtaining info by false pretenses) are other possible threats.
4.     Take action to minimize the risk from the threats.  This sounds obvious, but is probably the biggest mistake that companies make.  A nice risk or security assessment may be done and all the documentation completed, but no follow up action is taken.  It is not in the budget, or no one is given the responsibility or worse, no one cares enough until after an incident happens.
Remember your proprietary information, no matter what form or what industry, will be of value to someone – the only question will be if it stays your valuable information or will you give it to your competitors for free?

_____________________________________________________________
Read a follow up post, "License to Fool: Renault Spy Case Takes Another Twist"