Use FUD to talk risk and security: CIO

Chief information officers must use vendor-style FUD tactics to pressure boards and senior management to properly resource and prioritise operational risk management, a veteran CIO claims.

Martin Laing, CIO of Societe Generale's Australian business and a 24-year IT veteran, told delegates at an Alphawest leaders' forum last week that CIOs should "employ the tactics of the sales force of our suppliers" to drive home the threat failures in day-to-day processes present to organisations.

Laing said such operational failures could be highly damaging: "Think of the effect of not making [payments via the Society for Worldwide Interbank Financial Telecommunication (SWIFT) messaging and interface system] for a few hours, or a senior executive being caught viewing undesirable Internet sites and having that splashed across tomorrow's tabloids".

He said the finance sector's requirement of instantaneous performance and high level of interfacing between complex systems, combined with rapid change, demanded CIOs be "creative" in maintaining control over operational risk.

"We must create an internal FUD [fear, uncertainty and doubt] factor that will demonstrate what we are protecting ourselves against," Laing said.

"There is potential that our decision makers may be aware of some of the risks that exist, but this is not enough.

"We need to create the [FUD] and report on the risks and vulnerabilities that exist, and present to our board that direct action is required."

Laing put a number of questions to delegates that could help them determine whether operational risk resourcing and prioritisation was treated seriously enough by their organisations.

"Do you have a chief security officer? What is their hierarchical position?," Laing asked attendees. "Are they on the board? Do they report to the CIO, or are they still at the front desk?"

"Do you have a budget specifically for ORM, or is it hidden in your IT infrastructure costs? Do you have the correct number of resources assigned to ORM?"

He cited Gartner's recommendation that 3.5 percent of the IT budget in financial services should be dedicated to security alone -- excluding disaster recovery and business continuity planning. Yet he questioned how many financial services providers actually allocated that proportion.

"We must continually show [management] that cutting corners is no longer acceptable behaviour," he said.

IT executives had to convey to management that issues such as disaster recovery and business continuity should not just be the province of the IT department, according to Laing. Final responsibility should lie with company management.

"[It's] very important that the management responsibility for your DR/BCP [disaster recovery/business continuity process] is held outside the IT department.

"Yes, IT will be part of the management team, and should be. But IT, like every other department of your bank, [must be] seen as a contributor in addition to a participant."

Advertisement

Talkback 2 comments

    Not a security issuevealmince -- 03/08/05 (in reply to #120119787)

    If a senior executive is caught viewing undesirable Internet sites, how is that an IT security problem, or even a technology problem? It's an HR problem. Anyone who's dumb enough to surf porn at work deserves to be caught and fired. Survival of the least stupid.

    Using FUD demonstrates incompetenceAndreas -- 04/08/05

    This is a risky approach on its own. Although it may have the desired short term effect, but sooner or later it will fail to deliver. The main reason for failure is incompetency.

    Martin Laig migth be a CIO Veteran, but by resorting to FUD is just demonstarted that he is not competent to manage security and does not have the skill to provide any security metric apart from horror stories, that will demonstrate his value creation.

    If you want to get the attention of the board, then talk business and demonstrate how security and risk management will help the business to achieve the desired outcomes or leave it to the real experts.

Add your opinion


Latest Videos

Blogs

  • David Braue Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • Array Doing for AV what VoIP did for telephony
    Sydney-based start-up Audinate is making traditional analog cabling obsolete in favour of TCP/IP-based networking technology. And it's doing a pretty good job so far, with its technology used by World Youth Day and the Sydney Opera House.
  • Array WiMax in Australia: Part two
    WiMax could be the standard that drives the next phase of mobile broadband, it provides an opportunity for players wanting to establish a pure IP network to carry voice and data effectively — but is this what operators want?
  • More blogs »

Tags

Back to top

Featured