Customer -Industry Partner MeetingJune 12, 2002Kansas CityRichWilhelmVice President
The view from 80,000 feet… My background–Former . Intelligence Community Senior and White House Staff–Focus Watch & Warning; Crisis & War; Preparedness; Information/Infrastructure Protection As former Executive Director, Intelligence Community–I was able to gain unique perspectives–I have ‘guilty knowledge’……an awareness of the art of the possible cyber attacks & terrorism–Five years in private sector to understand business side My conclusions: –Security has become a key critical factor in business continuity& opportunity capture for future success–Broad corporate risk management response is most often is the key1
My Message The World Is More Complicated and So Therefore Is Risk Management We Often Look To Technology To Solve Our Most Pressing Security Problems, But It Is Most Often Leadership, Perspective , Management and Coordination Which Are Far More Important The Big Winners Will Be Firms and Agencies Which Take the Broadest View of Risk Management, Integrating Not Only Traditional Security Disciplines But Also Other Areas of Risk and Connecting Them To the Business and Its Mission 2
Risk Management:It’s a complicated worldONE EXAMPLE:The Macro View3
Recent history has proven that single events can have profound impacts and the cascading discontinuities result from unrecognized interdependencies Interdependence Risk Consequences thInterdependence Riskof September 11The risk organizations face from unanticipated occurrences at the Economyperimeters of the extended enterpriseDeepening of US recession Deepening of US recessionDecline in consuer confidence Decline in consumer confidence and buyingand buyingUS airline industry incurs ulti-billion US airline industry incurs multi-billion dollar losses•Anthrax attacksdollar lossesIndustryIndustry restructuring •Global Crossing/ Industry restructuring Qwestcollapse(., accounting, airlines)(., accounting, airlines)•Yahoo/eBaydenialof service attackLoss in confidence in security of Loss in confidence in security of •Enron/Andersen public infrastructurepublic infrastructureLLP collapseNational, state and local econoies National, state and local economies •Rogue financial trading (., •eteer 11tfalter fro touris shutdown•September 11thBarings, Daiwa, Allied Irish)falter from tourism shutdownterrrist attacksterrorist attacksDecline in key services and custoer Decline in key services and customer •FedEx package contaminationtraffic force businesses into bankruptcy•Privacytraffic force businesses into bankruptcy•Trading systemviolations•Philips ElectronicsLost revenue, arket share and outages Lost revenue, market share and . plant fire•Overspend of arket valuemarket value•IP theftUMTS licenses•NetworkClosed borders delay delivery schedules Closed borders delay delivery schedules •Lehman brokerageintrusions/•‘Code Red’ virus and increase distribution and inventory fraudand increase distribution and inventory failuresattackholding costsholding costsEnterpriseProduction lines halted with grounding of Production lines halted with grounding of air-freighted aterialsair-freighted materialsLowInterdependence ImpactHigh4
Interdependence risk is highlighted by the roles that industriesplay in providing security and continuity to the economy ...Public Infrastructure -Financial Services-Consumer Products-Shipping-Prevent Health Care-Establish Prepare contingency Detect illicit funds flows Prevent systematic contaminated material plans/ measures to respond plans for disruption to and prevent harm to contamination of key from entering to health-related attackstraffic infrastructurecapital marketsconsumer goodsshipment flowsSecurity“Chain of PrepareDetectProtectPreventRespondRecoverResponsibility”Airlines -Develop Energy -Protect Public Transportation -Telecom -Provide measures to detect against damagePrevent damage to public the ability to and prevent to critical transportation facilities recover/restoresecurity breachesinfrastructureand passengersvital communications services5
…which, while essential to growth and profitability, expose firms and agencies to risks they cannot control directlyIndirect “Threats”Indirect ControlExtended Enterprise Restrictions in flow of raw materials Changed customer preferences Regulatory restrictionsistributionDistribution Public infrastructure disruption hannelsChannels(telecom, transportation)uppliersSuppliers Adverse media exposure Adverse financial market conditionsovernentGoDirect ControlvernmentgenciesAgenciesDirect “Threats”eal stateReal Estate Lost customer relationshipstrategic Network intrusions/hackingStrategic artners Equipment/facility destructionPartners Intellectual property theftployeesEmployees Privacy violationsIntellectual Intellectual Potential ConsequencesropertyPropertyetorksNetworks Revenue growth decline Market share lossustoersCustomers Shareholder value decline Restrictions to new markets Loss of competitive advantage Eroded goodwill or brand equity Financial restructuring Legal exposure Restrictions to capitalinancial ublic Financial Public arkets Declining goodwill and brand equityInfrastructureMarketsInfrastructure Regulatory action6
Another Example:Technology and the Destructive Powerof Terrorists7
Hypothesis: The destructive power of the (cyber) terrorist doubles every 18 months (Giorgio’s Corollary to Moore’sLaw)Implicationsetter collection on Better collection on potential terrorist targets potential terrorist targets and better data ining and better data mining capabilitiescapabilitiesetter planning tools Better planning toolsFaster and ore flexible Faster and more flexible counication communication capabilitiescapabilitiesetter, faster and ore Better, faster and more available encryptionavailable encryptionccess to ultiple edia Access to multiple media coverage through internet coverage through internet streaing videostreaming videoDecreasing CostIncreasing DependencyIncreasing Destructiveness8
Cyber attacks over the past few years prove that we have a problem…and they have followed a growth pattern remarkably similar to Moore’ Statistics 1989-2001100000Cyber Incidents reported by CERT10000Number ofIncidences1000Cyber Incidentshypothesized by the corollary to Moore’slaw1001989199019911992199319941995199619971998199920002001YearThe Computer Emergency Response Team Coordination Center at CarnegieMellonUniversity tracks the number of reported hacking
Bad elements with more technological power implies potentially greater destructive capabilitiesCharney’sAssertionGiorgio’s CorollaryAsymmetric WarfareGreater Destructive Bad ElementsMore Technological PowerCapabilitiesAre highly educated Are highly educatedHave access to technologySuper coputerseapons of ass Have access to technology Super computers Weapons of mass destructiondestructionHave access to oney Better hacking software Have access to money Better hacking softwaresupply and Hack and steal ilitary supply and Hack and steal military Self propagating viruses Self propagating virusesintelligenceintelligenceHave access to governent Have access to government and ilitary intelligenceDisrupt infrastructureand military intelligence Disrupt infrastructure“There will always be some percentage of the population which is up to no good”Scott Charney(former Computer Crime and Intellectual Property Section (CCIPS)at DOJ)10
Technology was a major enabler in what could be perceived as a low tech terrorist attack35 Year old (low) technology….Enhanced by modern technologyBetter intelligence gathering Better intelligence gathering–Coputer in caves–Computer in caves–Instant counications–Instant communicationsBetter training and planning tools Better training and planning tools–Flight siulator–Flight simulator–Flight schedules through Travelocity–Flight schedules through TravelocityEase of counication Ease of communicationBetter encryption Better encryption–Hypothesized use of iages to transit –Hypothesized use of images to transmit hidden essageshidden messagesHigher edia coverage Higher media coverage–CNN coverage available worldwide –CNN coverage available worldwide through internetthrough internet11
Security:“The way we have traditionally been”Let me introduce you to some of the traditional “players”12
This is Joe. He does Physical Security. Retired policeman, maybe with some prior military experience Checks badges, knows alarms, guards the gates Knowledge of computer security limited to checking property passes when they leave the building Rules of engagement for use of weapon probably unclear Loyal, competent, but narrowly focused Likes formal rules, clear guidance13
This is Bill. He does Information Security. He’s a geek, maybe even a little bit of a nerd. Has 13 computers in his basement at home, creates his own networks there and dares hackers to break into them. Works for the CIO who may not be very influential in the organization Speaks in a technical language which is often inaccessible to the common man Tends toward informality, and prefers technical solutions over management ones Kind of lives in his own world14
This is Mary. She maintains your personnel and Personnel Securityrecords. “Checks the blocks” Processes the paper, the supreme bureaucrat, nothing gets by her Has little understanding of the jobs requiring personnel reliability background checks that she performs In a particular sense, she is very unfamiliar with computer security But loyal and competent in the world she controls15
This is Josephine. She is the Business Continuity person. Like most staff who work in this field, she is all about planning A lot of this discipline is about relocation and backup sites Recently, in the post 9/11 world, more than any other area of security, firms are beginning to worry But this field until recently was arcane and isolated 16
Some observations: These folks don’t know one another very well and don’t work together In many firms and agencies, the traditional focus of security has been in the physical area Other areas of security operate in silos, with dysfunctionalitiesoften emerging The languages and cultures of each of the disciplines are different, making clear coordination and comprehensive security approaches and solutions rare No amount of technology will overcome these discontinuities without leadership, perspective and management coordination17
Traditional Risk Framework… where risk mitigation is event-driven, imposes point solutions on business operations, and relies on corporate policies for consistency andalignmentCorporate StrategyBusiness OperationsEvent DrivenNetwork OutagesSupply chain delaysGovernment regulationOverseas ExposureBusiness partnershipsPhysicalInfoPersonnelSecuritySecuritySecurityENRONRogue financial tradingAnthrax attacks“code red” virus attackInternet denial of service attacksNetwork intrusion Business Continuity/ Phillips electronics plant fire Disaster Recovery9/11 Terrorist attacks18CatastrophicBusiness-As-Usual
A better interim state:“The way we’re moving”19
Integrated Business Assurance Framework… where risk reduction activities are dynamically linked to business operations to implement corporate strategyIntegrated Business Assurance FrameworkBusiness DriversControlsrrt trtCorporate StrategyCritical infra-structure ownershipovernanceGovernanceVehiclesVehiclesNetwork growthi rtiBusiness OperationsDependency on Scenario Scenario global infrastructurePlanningPlanningRisks Overseas exposure•Operational•Enterprise-wide focus Policies and Policies and •FinancialNew threats•Integrated across assurance domains (., ProceduresProcedures•Personnelphysical, information personnel, financial)•InformationProduct and •Tradeoffs are business impact-driven anageent and Management and operational •Market/brandperational Operational •Objective is improve resiliency of the complexity•LegalProcessesProcessesbusiness operations•Capital investmentCustomer Controls and Controls and expectationsCopliance Compliance Risk Reduction ActivitiesechanissMechanismsRegulatory pressuresiess tiity laiBusiness Continuity Planningonitoring and Monitoring and (“siess-as-sal a atastric)(“Business-as-usual and Catastrophic)Business easuring Measuring PartnersSystesSystemsDisaster Incident ShareholdersDisaster Incident Integrated Crisis Integrated Crisis Recovery Response Recovery Response TechnologyTechnologySecurityanageentSecurityManagementPlanningProceduresPlanningProceduresmcconnell_jm@
A future state:“The way we should ultimately be”21
nsikasimro lDe nOnPoCsrePCOO DomainOperating risksGiven today’s threats, agency heads and CEOs need an even more comprehensive risk management framework Risk is stove-pipedby naturewithin the traditional organizational domainsCIO DomainCEOInformation risksDomain The domains, however, CFtypically share infrastructureFkOkin sDasiservices and have complex onimciRaa ilinterdependencies and linkagesn ridskeesrra Business resilience, in today’s ahnew threat environment, S-- requires cross cutting solutions sseecthat manage risks and assures ciivvoperational efrfectivenessreeS There is need for internal and deeexternalrisk management rraaplanninghS22
n isakmsior lD eOnnPoCsrePCOO DomainOperating risks A Business Assurance/Risk Management program should reconcile, synchronize and integrate an organization’s operational effectiveness and long term viability The new enterprise dynamic would feature:CIO DomainInformation –TrustCEOAssuranceInformation risks Domain–CollaborationCInfrastructure FFOProtectioni nD–Shared informationaontmcPrivacyianailne –A common viewrisTransactional kmse Integrity–Effective securitygaRisk n–Business resilienceaManagement MServices k Enhances overall business sPersonnel iRcontinuity management and Security/ecemergency response preparednessPhysical naSecurityr Steps:uEmergency ssResponse –Realistic Vulnerability AssessmentAPreparedness ss–Risk Mitigation Plan and Continuity enPlanningiImplementationsu–Business Adaptation for Bgrowth/brand protection23
lennosrePOperationsThe leadership suite’s Assurance Domainsneed to share information and collaborate in unprecedented ways to adapt to the new operating realitiesStrategyTechnologyInsightInformationCEOFCIO inanDomaineecciaclnaarruItegratedssssA CFO deeDomainttMissionaarrgeettnIICPO naAssurceDomainCOO DomainAction24
Preparing for a new operating reality could start with one or more program elements of Integrated Business Assurance Mission Analysis and Integration:baseline assessment and negotiated understanding of economic and operational performance measures Integrated Security:blend of cyber, physical, personal activities Consolidated Risk Management:across all assurance domains (COO, CFO, CPO, CIO) Business Continuity Planning:business impact assessment Decision Support System:situational awareness using automated tools and command center engineering practices Performance Optimization:actively managing against measures for the enterprise mission, facilitates eBusinessmigration, mergers and acquisitions, new technology Indications and Warnings:forecast of political, economic and business impacts Crisis Communications:enables management of key operational, Issues Management Transformational Leadership:turning crisis into opportunity25
Summary The World Is More Complicated and So Therefore Is Risk Management We Often Look To Technology To Solve Our Most Pressing Security Problems, But It Is Most Often Leadership, Perspective and Management Coordination Which Are Far More Important The Big Winners Will Be Firms and Agencies Which Take the Broadest View of Risk Management, Integrating Not Only Traditional Security Disciplines But Also Other Areas of Risk and Connecting Them To the Business and Its Mission 26