guarding against the ‘enemy within’ · friday, may 17, 2013 | 3:15 - 4:45 pm speakers: john...

20
Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within’ Effective Employee Due Diligence Before and After They Get the Keys

Upload: trantuyen

Post on 12-May-2018

216 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Friday, May 17, 2013 | 3:15 - 4:45 PM

Speakers:

John Walsh, Steve Shine, David Nanz and Kevin Tanaka

Guarding Against the ‘Enemy Within’ Effective Employee Due Diligence

Before and After They Get the Keys

Page 2: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

John F. Walsh

CEO

SightSpan Inc.

Charlotte, NC

Page 3: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

The Enemy Within

Before you hand over the keys

•Standard/Repeatable Processes •Periodic Internal Audits •Yearly review and analysis of needs •Understand the process never ends and is never complete

Page 4: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

The Enemy Within Standard Background Review

• Employment Checks

• Education Verification

• Criminal Backgrounds

Employee Surveillance

• EDD for Higher Risk Executives

• On Going Negative News Monitoring

• Transaction Monitoring

• System Access Monitoring

• Building Access Monitoring

Page 5: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

The Enemy Within – Employees

– Employee Family and Associates

– External and Internal Hackers

– Cyber Criminals

– Contractors/Consultants

– Vendors/ Partners

– Maintenance Teams

– Building Management

– Customers

Real Life Examples

Page 6: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

The Enemy Within

Corporate Security Training and Awareness: •Look – Listen – Report Approach •Proper Training and awareness programs will expand your teams exponentially and better protect your people and additional assets •Anonymous Hot Lines •Incident management

Page 7: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

The Enemy Within Relationship Ending Processes:

Staff/Vendors/Consultants/Partners

Repeatable and Defined Relationship Ending Process

• System Access Removed

• Building Access

• CP/Mobile and Communication Devices

• Home Technology Equipment

Page 8: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

The Enemy Within

Corporate Security Internal/External Threat Management

Fraud System Analytics – Thought Leadership

AML/CTF Risk Management KYE= Know your Employee

Cyber Security Internal and External System Access

The Key to Success Financial Crimes Risk Managers Working in Partnership

Page 9: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Stephen Shine Chief Regulatory Counsel

Prudential Financial

New York, NY

Page 10: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Four Elements

• Robust “On Boarding” Process

• Code of Conduct

• Ongoing Review/Monitoring

• Procedures for Reporting Wrongdoing

Page 11: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

On Boarding Process

• Interview

– Inconsistencies/Gaps in Resume

• Background Investigation

– Credit Check

– Criminal Records

– Drug Test

Page 12: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Code of Conduct

• “Set Expectations”

• Broad Policy Statement

• Detailed Code of Ethics

• Insider Trading

• Gifts and Entertainment

Page 13: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Ongoing Monitoring

• Email Review

• Trading Records

• Annual Certifications

• “Trust but Verify”

Page 14: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Procedures for Reporting Wrongdoing

• Dodd Frank Whistleblower Policy – Multiple Reporting Channels • Management

• 800 Number

• Compliance/Ethics

• Investigations

– Training of Managers

– Communication

– “Safe to Say”

Page 15: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

David Nanz Supervisory Special Agent

FBI

Miami, FL

Page 16: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Kevin Tanaka Senior Manager, Fraud Investigation and Dispute Services

Ernst & Young

New York, NY

Page 17: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Informing the Risk Assessment

RISK MANAGEMENT

PROGRAM

Top-level Commitment

Communication and Training

Internal Controls

Risk Assessment

Monitoring

Due Diligence

Investigations

Internal sources

►Business Management ►Business Operations ►Compliance ►Corporate Security ► Finance and Accounting

►Human Resources ► Internal Audit ► Information Technology ► Legal ►Operational Risk Management

External sources

►Competition ► Industry Consortiums ► Law Enforcement

►Media ►Regulatory Agencies ►Trade Publications

Page 18: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Tactical approaches to drive early detection and deterrence

Develop Threat Library ►Organization-specific

►Focused on aberrant behaviors

►Define KRIs (key risk indicators)

Conduct Data Analytics ►Leverage existing monitoring capabilities

►Identify presence of KRIs

►Develop Heat Maps / Scorecards

►Locate clusters and outliers

Perform Targeted Transaction Testing ►Unannounced ‘surprise’ audits

►Enhanced due diligence

Anticipate discovering red flags that require further investigation…

RISK MANAGEMENT

PROGRAM

Top-level Commitment

Communication and Training

Internal Controls

Risk Assessment

Monitoring

Due Diligence

Investigations

Page 19: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Developing an effective incident response plan

RISK MANAGEMENT

PROGRAM

Top-level Commitment

Communication and Training

Internal Controls

Risk Assessment

Monitoring

Due Diligence

Investigations

Intake

•Triage and case management

•Assemble multi-disciplinary investigation team

•Determine the scope and investigative work plan

Execute

•Data preservation, collection and processing

•Interviews

•Forensic accounting analysis

•Legal analysis

Reporting & Remediation

•Feedback loop is key to recalibrate overall program as necessary

Page 20: Guarding Against the ‘Enemy Within’ · Friday, May 17, 2013 | 3:15 - 4:45 PM Speakers: John Walsh, Steve Shine, David Nanz and Kevin Tanaka Guarding Against the ‘Enemy Within…

Please Proceed to Grand Ballroom West for the

Next Session