$BlogRSDUrl$>
linking INTEGRITYIntegrity - use of values or principles to guide action in the situation at hand.Below are links and discussion related to the values of freedom, hope, trust, privacy, responsibility, safety, and well-being, within business and government situations arising in the areas of security, privacy, technology, corporate governance, sustainability, and CSR. Aligning Form and Substance to Create an Ethical Business Culture, 1.5.08![]() by Bradley Preber Published: April 09, 2008 in Knowledge@W.P. Carey Bradley Preber’s recent talk on business ethics and culture could not have been more relevant or timely. The partner-in-charge of Grant Thornton's Forensic Accounting and Investigative Services practice spoke before a group of W. P. Carey MBA Executive students the same day that an independent report commissioned by the U.S. Department of Justice found that the auditing firm KPMG is allegedly linked to fraud at New Century Financial Corp, a subprime mortgage lender. KPMG denies any wrongdoing, but the incident raised some interesting ethical questions during the discussion, part of the school’s Thought Leadership Series. The New York Times reported that "New Century Financial … engaged in 'significant improper and imprudent practices' that were condoned and enabled by auditors at the accounting firm KPMG, according to an independent report commissioned by the Justice Department." The report also pointed out that some auditors raised concerns about New Century, but were ignored because of fear that the firm would lose an important client. Preber would not speak specifically about the auditing company, adding that he thought this would be unethical because they are a competitor of his firm. But when the news was raised by students and other speakers he noted that any company that continues having pervasive and systematic behavior problems with its employees must look at its culture to see if it could be partly what drives that unethical behavior. And if the recurring problem stems from upper management then this will have repercussions for the rest of the company. Preber added that culture is a factor that can be used to predict fraud and evaluate a company's ethics. He asked his audience to consider some companies that have been in the news for ethical situations and to free associate: Prompted with Enron they offered "greed," "putting profits before people," "arrogance." When asked about Microsoft, they said "competence," "market dominance," even "innovation." PetSmart, the pet specialty retailer, fared well with the group. PetSmart had recalled contaminated pet food and replaced their customer's purchases, Preber said. "This tells customers that the company is there to look after their pets and will rectify any errors made." Culture played an important role in forming the students' impressions. Form of culture and substance of culture must align When companies take quick action, as PetSmart did, they foster an ethical business culture. But fast and appropriate reflexes are not enough. Preber argued that the form of a company's culture must align with the substance of the culture. Form, Preber said, includes standards and values that can be verbalized or written down. He stated examples such as policies and procedures, compliance officers, industry norms and laws and regulations. Substance, however, is the action that grows out of acceptance of the form, by the company, its managers and its employees. Actions could include the way employees talk about their bosses, establishment of an anonymous complaint line for employees and rewards for good behavior. If substance and form align, Preber explained, then desirable and acceptable workplace behaviors are more probable. When unethical behavior surfaces and is tolerated, it is because form and substance of culture are unaligned. "This is when attitudes deteriorate and the incentives for unethical behavior rise," Preber said. Ethics wane, the accountant thinks, when form is placed over substance. Form over substance results in rationalization, living with bad decisions, cheating and fudging the system. When asked how to avoid unethical clients, Preber suggested operating only with those that share your ethics. "It's not my job to correct clients' ethics. If their ethics don't mesh with yours, always walk away." Avoiding the gray area Marianne Jennings, a professor of legal and ethical studies in business at W. P. Carey School of Business, frets about stories like KPMG. Author of "The Seven Signs of Ethical Collapse: How to Spot Moral Meltdowns in Companies … Before It's Too Late," Jennings noted that previously, scandals only surfaced every decade. "Enron and the Sarbanes-Oxley Act of 2002 -- which tried to reform American business practices -- were only five years ago, so we are seeing scandals more frequently and the same pattern over and over," she said. Jennings pointed out that KPMG settled tax shelter fraud allegations with a fine, and just a few weeks ago paid to settle for its role in the Xerox accounting fraud. The New Century Financial issues came after these two problems. "The pattern seems to suggest that KPMG needs that exercise of seeing whether the client's values are the same as their values, or they have not yet come to grips with the importance of ethics and values over the retention of clients and keeping the revenues," Jennings commented. In her book, Jennings writes that "all unethical organizations are alike; their cultures are identical and their collapses become predictable." She identifies seven warning signs that a company culture is unethical: pressure to maintain numbers; fear and silence in the ranks and leadership; young and inexperienced executives and a bigger-than-life CEO; a weak board; conflict; pressure to produce constant innovation; and a penchant for philanthropy that assuages guilt for questionable decisions. When a sufficient number of the seven signs have infected the culture, Jennings writes, intelligent and otherwise upstanding people may do things that are at least unethical, and often illegal. Things start to become slippery, Jennings said, because that gray area can include unethical actions that are not technically illegal. "If we want change, then it is the ethics within this gray area that must be studied more." To keep out of trouble, Jennings suggested asking oneself: "Why is this area gray to you? If you are there, then you are probably already in trouble, looking for a way around a rule." Asked what professors and mentors can do to help prevent poor business behavior, Jennings said that teaching ethics has never been more important. Giving business students continual case studies showing the risks and costs of living in that gray area, and giving them the gumption to act when they feel uncomfortable is essential, she said. "Creating change means driving this home." Bottom Line:
Additional Reading: "Executive Role Models Crucial in Building Ethical Workplace Culture" Labels: ethics, leadership, risk mitigation, security (0) comments U.K. commissioner blames CEOs for data breaches, 11.7.07
CNET News.com
'The roll call of banks, retailers, government departments, public bodies and other organizations which have admitted serious security lapses is frankly horrifying,' Richard Thomas wrote in a report. 'How can laptops holding details of customer accounts be used away from the office without strong encryption? How can millions of store card transactions fall into the wrong hands?' The Information Commissioner's Office (ICO) received almost 24,000 inquiries and complaints concerning personal information, and it prosecuted 16 individuals and organizations in the past 12 months, according to its annual report for 2006 and 2007. 'Be sure you are not the business or political leader who failed to take information rights seriously.' Richard Thomas, information commissioner, United Kingdom: 'My message to those at the top of organizations is to respect the privacy of individuals and the integrity of the information held about them, to embrace data protection positively, and to be sure you are not the business or political leader who failed to take information rights seriously.' The ICO received complaints under both the Data Protection Act and the Freedom of Information Act. More than half of Data Protection Act cases required the ICO to simply provide advice and guidance, while a breach was likely to have happened in more than a third of cases, of which a further 77 percent resulted in remedial actions such as correcting an individual's record or training staff. The ICO received almost 6,000 complaints under the Freedom of Information Act and has closed more than three-fourths of those. Public awareness of data protection rights has increased to 82 percent, with more people understanding that personal information must be handled appropriately, according to the report. The information commissioner's plea follows a number of security breaches over the last year, including 12 U.K. banks found to be in breach of the Data Protection Act, following complaints about the disposal of customer information. U.K. bank Barclays is facing an ICO investigation over allegations of customer privacy breaches, and telecommunications provider Orange and retailer Littlewoods were also found to be in breach of the Data Protection Act by the ICO this year. Labels: leadership, risk mitigation, security (0) comments Control and track your car from the net, 15.4.07
Autoblog
YOU are big brother
Aside from providing a bit more convenience and protection, the major draw for some users, namely parents, is the ability to not only track the movements of the vehicle, but also be alerted via text message or email if the kiddies stray from set boundaries or operate the vehicle during certain times of the day or night (no more ditching school or sneaking into the love interest's window at 3 AM). Inilex demo. Labels: attack, car, hackers, remote security, security (0) comments Network Security Is Top of Mind for Executives, 25.3.07
(EIU research white paper entitled "Network Security: Protecting Productivity".)
AT&T Inc. announced today that network security is regarded by executives as the single most important attribute of their network, according to the results of a global survey conducted by the Economist Intelligence Unit (EIU) for AT&T. The research reveals that a majority of executives (52 percent) now believe that having a converged network gives their companies better deference against IT security breaches. Furthermore, nearly 70 percent feel that IP helps ensure business continuity following an emergency.
The EIU white paper shows that, increasingly, executives feel especially concerned about the growing volumes of customer data they hold and manipulate, and 45 percent say that the holding of sensitive customer data on their network makes them feel "extremely" vulnerable from an electronic security perspective. Another 41 percent say the process of analyzing and acting upon detailed customer data also significantly increases their vulnerability. Among the worst security threats cited by nearly half (49 percent) of executives is hackers. Protecting against viruses and worms also remains top of mind for companies but emerging as one of the most feared threats is identity theft -- mentioned by one-third of executives -- and their concerns are set to rise over the next three years. The EIU research has also highlighted the importance of the chief security officer (CSO), and although typically the CEO remains the primary decision- maker for electronic security decision (with the exception in Europe where the CIO is more likely to hold this role), the role of the CSO is rising, with 12 percent of companies confirming this as the main decision-maker. "Security is becoming more and more important in today's collaborative environment", comments Lloyd Salvage, AT&T's vice president in the U.K. "We are constantly talking to our customers and helping them to re-evaluate their requirements to ensure that their businesses are adequately protected at all times." The white paper is the second of a series of thought-leadership papers in the Network Convergence series written by AT&T in co-operation with the Economist Intelligence Unit. Subsequent papers in the series will explore how companies are addressing the challenges of managing applications integration and enterprise mobility. Survey and Research Methodology As part of the research for the paper, the Economist Intelligence Unit conducted an online worldwide survey of 395 senior executives across 51 countries and over 20 industries. The majority of respondents came from Western Europe (32%), Asia Pacific (30%), and North America (30%). Other respondents came from Eastern Europe, Latin America, the Middle East, and Africa. 63% of those polled hailed from large firms with annual revenue of more than US$500 million. The top five industry sectors represented by the survey respondents were professional services, financial services, manufacturing, IT and technology, and healthcare, biotechnology and pharmaceuticals. In addition to the survey research, the EIU conducted a series of one-to-one in-depth interviews with senior executives and analysts. Labels: risk mitigation, security (0) comments Outrunning the Regulators, 19.2.07
Strategy + Business
In banking, as in other heavily regulated industries such as utilities and health care, keeping abreast of federal regulatory requirements is of paramount importance. To avoid an endless cycle of reacting to new regulations, banks [and business in other regulated industries] must anticipate the regulatory fallout from problems such as identify theft, and implement solutions that address existing and longer-term security issues. Leaders should consider decentralized security structures to enable a faster response to new rules. Making customers aware of new security measures is also vital and can help mitigate risk. [...] Companies in heavily regulated industries, a group that includes pharmaceuticals, health care, and utilities, often act as though the regulations that besiege them are irritating trivialities. However, new requirements can offer companies an opportunity to escape the cycle. For instance, instead of maintaining an ad hoc approach to foiling invasions and complying with regulations, banks should craft an overall public-facing security strategy. Although it can be difficult to persuade senior management to invest in long-range plans, there’s no better time to do it than when they are in the shadow of an imminent regulatory deadline — especially one that is disrupting the entire organization as the company marshals its resources to deal with it. For example, in aiming to go beyond regulatory compliance and achieve security excellence, banks can institute a mechanism for self-analysis and self-improvement that allows them to anticipate their future security needs. In doing so, they will meet their current burden of compliance, lessen the impact of any future regulatory guidance, reduce their risk exposure, and address customers’ concerns about the security of online banking.[...] The second element is an effective organizational structure to manage the initiative. A common roadblock to implementing new security standards is a decentralized company, which can lead to inconsistent approaches to IT security across the enterprise, along with incomplete monitoring and accountability. However, piecemeal fixes will not work. Grafting a centralized security program onto a decentralized organization often results in the corporate equivalent of organ rejection. How might banks address this issue? They can create a hybrid centralized–decentralized model, in which critical compliance activities and governance oversight are centrally managed, while less critical functions remain with the business units. Alternatively, banks can construct enforcement mechanisms that shift the burden of compliance to the heads of the business units, rather than keep it centralized at corporate headquarters. Regardless of the specific solution, banks can manage risk exposure and regulatory compliance in a uniform fashion only if they have the requisite organizational structures in place. The final element of a robust risk-mitigation program, customer awareness, can be a key component of a company’s defense against fraud and identity theft. A well-educated bank customer can more easily spot phony come-ons, like phishing e-mails, and avoid being deceived. In fact, many banks are finding that educated consumers are their front line of defense in reporting phishing and other fraud attempts. One basic but effective measure is to advise customers to always type the bank’s Web address into their Internet browser rather than click on a link in an e-mail, because the e-mail may be fraudulent. Furthermore, making customers aware of enhanced online security is a key differentiator in the marketplace. In a 2005 survey by Deutsche Bank Research, “security offering” was far and away the most important feature to prospective online banking customers, with 87 percent calling it their top priority. A well-publicized security program could prove a significant lure to new customers in the highly competitive banking environment. Any highly regulated industry will face similar vicious cycles of its own and should be thinking about approaches for leaping ahead of regulatory requirements. The common thread is that simply responding to regulatory guidance will never be enough. Anticipatory thinking is the only way to avoid being caught in the middle of an endless series of provocation and regulation. Labels: risk mitigation, security (0) comments
Archives07.03 08.03 09.03 10.03 11.03 12.03 01.04 02.04 03.04 04.04 05.04 06.04 07.04 08.04 09.04 10.04 11.04 12.04 01.05 02.05 03.05 04.05 05.05 06.05 07.05 08.05 09.05 10.05 11.05 12.05 01.06 02.06 03.06 04.06 05.06 06.06 08.06 09.06 10.06 11.06 01.07 02.07 03.07 04.07 07.07 08.07 09.07 10.07 05.08 06.08 | |||||||