Showing posts with label enterprise. Show all posts
Showing posts with label enterprise. Show all posts

Saturday, 5 March 2011

Five Myths About Fraud

We’ve all heard so much in the news about fraud over the last several years. Not a day goes by that we don’t hear about an executive caught with his hand in the cookie jar, a company that failed to follow proper accounting rules, or a compensation structure that led someone to cheat with the numbers.

In some ways, I think people are becoming immune to fraud. The cases don’t seem as significant as they would have been five years ago. They’re not as shocking as they used to be. It is sad that fraud is becoming more commonplace. And the more we hear about fraud, the more I think companies run the risk of not taking it seriously.

Most importantly, I think people are running around with some big misconceptions about employee fraud. If they mistakenly believe their company is not at risk, they are probably not actively preventing fraud. Companies must know the truth about fraud and its perpetrators in order to actively protect themselves.

The following are five of the fraud myths that I regularly run into in my fraud investigation practice. Whether owners and executives actually utter these out loud or not, merely buying into these myths mentally can be a recipe for disaster.

1. Our company does not have an internal fraud problem.


While companies would like to believe they have good employees and adequate controls to prevent fraud, the fact of the matter is that 45 percent of companies will be significantly affected by fraud, according to one international study. A separate study estimates that the average internal fraud will cost $159,000, and that almost one-fourth of fraud cases will cost companies over $1 million each.

Companies cannot afford to ignore the risk of fraud and the likelihood that fraud is occurring internally. It is too expensive, particularly when one considers the fact that there are many indirect costs of fraud, including investigation and legal costs, employee attrition, and decreased employee morale.

Actively fighting fraud means implementing policies and procedures that prevent and detect fraud. Anti-fraud professionals who are experienced with the common methods of fraud can be invaluable to this process. Whether a company gets there with employees or outside consultants, it is important to secure company information and assets to prevent internal fraud.

2. Most people are honest and won’t commit fraud.


This is a dangerous approach to take to the business of fraud. It is true that most people are generally honest. But to rely on this instead of putting controls in place to prevent fraud is a big mistake.

While it’s wise to hire those with a track record of honesty, past behavior doesn’t necessarily predict future behavior. Almost 88 percent of employees and executives who commit fraud against their employer have never before been charged or convicted of a fraud-related offense. This means it’s nearly impossible for companies to predict who is going to commit fraud and when they are going to do it.

It is a fact that honest people can and do commit fraud. Outside pressures can cause people to behave in ways they normally would not. Things that could push someone toward fraud include addictions, divorce, overwhelming debt, and gambling problems. When pressures like this are present, it’s difficult to predict who will commit fraud.

In the end, those who commit fraud come from all walks and ways of life. From clerks to executives, no one is immune. Thieves come from all social classes and all economic backgrounds. If given a strong motivation and ample opportunity, anyone can commit fraud against her or his employer.

3. If our company follows government regulations, we will be protected against fraud.


Unfortunately, the current accounting rules and regulations do not really provide protection against fraud. Sarbanes-Oxley is probably the most widely-recognized regulation dealing with fraud. It has had some positive effects because it has forced companies to review and document their policies and procedures.

Companies have spent enormous amounts of money on implementing Sarbanes-Oxley, and it’s probably discouraging to admit that even such an extensive project isn’t really preventing fraud. The regulation forces management and the board of directors to accept responsibility for issuing accurate financial statements, however, it doesn’t really ensure that companies have fraud prevention procedures in place.

In order to effectively prevent fraud, companies must create and implement policies and procedures specifically designed to deter and detect fraud. Again, this should be accomplished with the help of an anti-fraud professional who is experienced in the methods used by corporate fraudsters. A good fraud prevention program will actively prevent and detect fraud while still complying with the applicable regulations.

4. Small frauds aren’t important enough for management to worry about.


Virtually every big fraud started out as a small fraud at one point. Whether it is a minor theft of cash or a financial statement manipulation intended to cover up a substandard quarter, what starts out as a small fraud can quickly grow into a major fraud scheme. A theft of $500 may not seem significant enough for management to devote time and effort to the problem. But what if an employee was stealing $500 a week for three years? Suddenly, there is a theft of over $75,000, which could be very material to the company.

It’s important for companies to take small frauds and ethical lapses seriously. Not only does management want to cut off frauds while they are in their early stages, they also should be sending a message to employees that dishonesty is not tolerated. A zero tolerance policy is a necessary part of any good fraud prevention program.

It may be expensive to monitor and investigate smaller thefts from the company. However, in the long run, the cost will be worthwhile because the company will have stopped frauds from growing into the hundreds of thousands and millions of dollars. Therefore, an effective fraud prevention program will contain components that help the company discover fraud early.

5. Fraud will be detected by our auditors.


History has shown us that a company’s independent auditors cannot be relied upon to find fraud. This is true primarily because audits are not designed to detect fraud. They are designed to give “reasonable assurance” that the numbers shown on the financial statements are materially accurate.

Because fraud involves the active concealment of the truth, it makes it difficult for auditors to discover. Further, auditors have a tendency to become complacent with their clients. They see the same things year after year in the audit, and they may stop paying close attention. Employees who are concealing a fraud may also be comfortable with the auditors and know what procedures are coming. If that’s the case, count on the employees to be very careful with the fraud as it relates to those expected procedures.

Auditing rules have attempted to address how auditors approach the potential for fraud within companies. While the current rules are somewhat better than those of several years ago, a traditional independent audit still cannot be relied upon to detect fraud. Executives who believe differently are setting their companies up for disaster.

The Solution


Preventing fraud in companies all comes back to active prevention techniques and educating employees about fraud. First, owners and executives must be aware that they are very much at risk of experiencing internal fraud, and that the statistics show that the losses can be expensive. Then they need to take decisive action in formulating a fraud prevention program.

Education of everyone is still a very important part of fraud prevention. No company is immune to the problem, and no employee is completely free from the possibility of committing a fraud one day. After owners and executives appreciate the true magnitude of the problem, it will be through action that fraud will be prevented at their companies.

Tracy L. Coenen, CPA, CFF is a forensic accountant and fraud investigator with Sequence Inc. in Milwaukee and Chicago. She has conducted hundreds of high-stakes investigations involving financial statement fraud, securities fraud, investment fraud, bankruptcy and receivership, and criminal defense. Tracy is the author of Expert Fraud Investigation: A Step-by-Step Guide and Essentials of Corporate Fraud, and has been qualified as an expert witness in both state and federal courts. She can be reached at tracy@sequenceinc.com or 312.498.3661. 


[InfoSecIsland]

Thursday, 3 March 2011

Private Smartphones, Tablets Threaten Office Networks

From the moment the first telecommuter logged into his work e-mail account from his personal computer, the line between work and home began to blur.

Today, thanks to mobile devices such as smartphones and tablets, we can surf the Web, send and receive e-mail and modify work documents from virtually anywhere.

Most smartphones and tablets are purchased by consumers for personal use. But many — even those on a family wireless plan — will also be used for work purposes both inside and outside the office.

This home/work overlap of mobile devices has created three major problems for the security industry as a whole.

Corporate IT teams can too easily lose control of the devices. Legal frameworks find it hard to demarcate between personal and corporate use. And security developers haven’t caught up with the new software.

Out of control


Smartphones and tablets streamline the way we communicate today. Forget about phone calls and e-mail -- these new devices make it easier to use social media, which is the way an increasing number of people, especially young adults, “talk” to each other.

However, the budgets of small or medium-size businesses often won’t cover networked mobile devices for anyone below top management levels.

So people bring their own devices to work and put them on the office network --- and, in many cases, don’t alert the IT or security departments about it.

Without knowing who’s accessing the network, or how often, it is difficult for a network administrator to make sure security policies are met.

The added risk of mobile devices is that they are easily lost or stolen. If the smartphone or tablet isn’t locked with password protection, outsiders will have access to potentially sensitive data and company e-mail messages.

IT departments do have options to protect corporate data on personal phones, said James Lyne, senior technologist at England-based security company Sophos.

“Platforms such as [Microsoft] Exchange can give administrators visibility of the types of devices users are using to access key services,” he said. “Acceptable use policies should also clearly outline users’ responsibilities: which devices are allowed, what security practices must be adhered to and how to notify IT if a device is lost or is otherwise compromised.”

If organizations don’t want employees using personal devices for business uses, devices can be restricted to services based on managed corporate assets, such as corporate-compliance software.

Many enterprises, however, will consciously allow users to mix personal and professional business on their smartphones or tablets. In these scenarios, it's critical that a security baseline is met and enforced.

No legal basis


Legal departments have their own challenges to face. Corporations have jurisdiction over company-owned devices, no matter how and where they are used. But privately owned devices aren’t as easily supervised.

In November, National Public Radio reported about a woman whose personal smartphone had been wiped clean by her employer. The remote wipe, which deleted everything on her phone, was a mistake, but the case raised the question of whether a company should have that much access to a personal device.

For corporate legal departments, it’s not clear which activities on a smartphone or tablet count as private use and which don’t.

What should legal departments be concerned about, and how should those concerns be passed along to the employee?

Lyne said mobile devices should be covered by the same compliance regulations as laptops or conventional computers. Loss of work-related data on a personal device is not acceptable.

“That said, the expectations of security controls on mobile devices are also less developed in many countries’ legal frameworks,” Lyne added. “Enterprises should make sure employees understand their obligations to manage and protect the device, but also should be conscious of the risk of data loss to their businesses. Where possible, minimize the flow of sensitive data to these device types to reduce the risk of loss.”

Hard to keep up

Mobile platforms present a new set of challenges to security, said Lyne. First of all, their presence greatly expands the number of operating systems – Android, BlackBerry, Apple’s iOS, HP’s WebOS -- that need to be protected.

“Microsoft operating systems have long been the primary focus area for security investment,” Lyne explained. “The broader set of platforms being used requires not only more coverage from solutions, but fundamentally protecting each of these devices is quite different in implementation and policy. These platforms, without standards, could increase the cost notably.”

Second, the mobility of these gadgets itself is a challenge. Each device constantly moves in and out of the network, and it almost certainly will be used for a blend of work and personal matters.

These changes in user behavior challenge conventional security policies, and will have a significant impact on the behavior of security technologies.

“The industry should not fall into the trap of trying to protect mobile devices with an identical model to the traditional computer,” Lyne said. “While security issues undoubtedly exist on these devices and we all need to recognize the likelihood of greater focus on these device by attackers, the threat vectors and protection model is different platform to platform.”

The immediate priority for businesses will be to manage the basic compliance of each mobile device.
Enterprises should know which devices are being used and ensure that password security, encryption and patching are all up to scratch.

Compliance is the key starting position for those looking to secure their mobile devices. However, as the threat evolves, so, too, will product requirements.

[SecurityNewsDaily]

Tuesday, 1 March 2011

Unmasking Security Threats in the Workplace

Corporate security risks can creep up on you from anywhere in your company. Most people think that the greatest risks reside outside of the organization, from hackers trying to get their hands on company lists and other information they can sell.

Unfortunately, there are still a lot of internal risks that need to be addressed, as employees remain a major corporate security threat as well. Keeping up to date on new threats is important, as cyber-criminals and those from within your company can move from one scheme to the next in the blink of an eye.

Knowing where to start can be difficult. In the SANS document, "The Top Cyber Security Risks," it states:

"The number of attacks is now so large and their sophistication so great, that many organizations are having trouble determining which new threats and vulnerabilities pose the greatest risk and how resources should be allocated to ensure that the most probable and damaging attacks are dealt with first."

Common Corporate Security Threats

In order to determine where to start, you need to assess the workplace and figure out which threats exist inside and outside of the organization. Then, you'll want to prioritize these risks to figure out which ones to address first. Here are some of the common security threats your company might encounter:

Human Error: Intentional or not, people are security threats. Some examples of common human errors include:
  • Misplacing information.
  • Opening spammy emails.
  • Failure to properly process information.
  • Improper disposal of documents (electronic and paper).
  • Sending email to someone other than the intended recipient (one of the dangers of auto fill!)
Disgruntled Employees: If your systems aren't secure, employees could be stealing all kinds of data before anyone notices it. There are a lot of reasons why a disgruntled employee might engage in these types of activities, including the fact that the employee see the opportunity and could use the money, or they feel the desire to take revenge on the company. Simple measures such as removing disc drives from computer towers can make a difference.

Cyber Criminals: Cyber criminals have developed a number of sneaky tactics to break into systems to get the information they want. In an article I read about a big-time cyber criminal in the NY Times, it almost seemed as if it wasn't about the information or the money, but simply the ability to hack into as many systems as possible. The tactics used by cyber criminals can be hard to catch, as many companies report that their systems had been invaded long before they knew anything was wrong.

Property Theft/ Misplacement: Information stored on laptops, USB keys and other portable devices increases security risks as these devices can be misplaced or stolen. These devices must be guarded by strong passwords and other recognition systems- facial scan, fingerprint, etc., in order to make sure information stays protected.

Insufficient Network Security: If your systems aren't properly guarded, it's easy for someone to break in. There are tons of ways that hackers weasel their way into your systems, so I recommend consulting a security or IT professional to find out which types of attacks you need to be on the lookout for. Find out which ones are most common and which ones could do the most damage, this way you can prioritize your actions.

Accessibility: When everyone has access to information in your organization, everyone could potentially steal that information. Sensitive information or information that doesn't pertain to one's job shouldn't be accessible to that employee. Clearly defined access roles make it easier to take control over sensitive information.

Social Media: The main security risk surrounding social media is personal information breaches and the sharing of confidential information over these networks. Some people post work related information in a Facebook wall post or when tweeting at someone, making the information available for a lot of people to see. There's a time and place for everything, and it's probably best not to have sensitive work related conversations with a colleague on a social media site.

Corporate security is the responsibility of everyone in the organization - not just the IT department. Security requires commitment from the upper-most levels of the organization so that the appropriate resources are available. No employee should be lazy about corporate security.

[infosecisland]