Pages

Showing posts with label Decision Making. Show all posts
Showing posts with label Decision Making. Show all posts

Saturday, 21 December 2013

Bhimani on Internet Security

Anish Bhimani is the Managing Director and Chief Information Risk Officer of JP Morgan Chase. In this role he has global responsibility for ensuring the security, controls and resiliency of the firm's technology environment. It is always a pleasure to learn about future trends and challenges in security and privacy, in such a relaxed speech!




Monday, 16 December 2013

The critical factors for sustainable development

For some time now, an intense debate in Greece and the European Union has broken out, regarding the sustainable development model in relation to the proposed agenda. But it is clear by all sides that any development model cannot be sustainable when you disregard, science and technology. 

Through the use of the appropriate, modern technologies, sciences, structures and human resources, and when you ensure access especially in sensitive social groups, you have good chances to fulfill the main criterion to improve the living standards of your country. Moreover, the society as a whole enjoys the benefits of tiered productivity increase and thus by increasing the disposable income of a country.

Source: Article by Constantine Kalentis in Greek for apopseis.gr. The full article can be found in Greek here  

Monday, 16 September 2013

Leak of Confidential Information

The main advantage of social engineering techniques is that they can easily bypass any technological investment. The social engineering has proven to be a very effective way of penetration in an organization. 

Source: Article published by Constantine Kalentis at Communication Solutions Magazine Issue 83

Saturday, 20 July 2013

The changing role of the CIO

More than twelve years ago, I had my first meetings with CIO’s in leading organizations and businesses. I can remember at that time the vast majority had a rich technical background, sometimes with little or no knowledge of the commercial business, so frustrated from multiple tasks such as software development and ad hoc integration to resolve, that looked to me very often as a hot boiler ready to explode. The pressure resolving technical issues was monumental. Of course management couldn't ever understand the cause of frustration. Let the CIO worry about technology.

The CIO’s role was always there: Checking out new trends in technologies, making decisions on key hardware and software purchases, deciding which are worth implementing and which should be ignored. Their role was defined by the dominant technology and the IT strategy as much as by their own expertise and talent in the field.

Today it is hard to even imagine a mid or a large company without a CIO who is monitoring the situation. And his image is changed too. The CIO looks more social, collaborative, business looking and the multi skilled function is shifting the dynamics to the modern day executive table. The CIO role has become so necessary, so counted upon that they spend most of their time in the tactical execution of a task or a project at a time.

The IT sector is driven by Cloud-delivered services including both software and data. As an increasing share of the new IT expenditure is going to such services, the CIO of today balances the business needs against the stream of opportunities and risks.

Software installation and maintenance will soon be or is already replaced by systems availability, responsiveness, information security and compliance. The CIO needs to be more strategic and have a clear idea of how a current technology can increase the company’s sales and not just how to reduce costs or to improve productivity.

The CIO is also facing changing priorities, smaller budgets and the lack of internal skills. As Information Technology and technologies it supports have become more complex, the role of the CIO has become also increasingly complex. There is a clear need for integration with the marketing team, and a direct line with the CEO. The CIO’s role should continue to grow not only in influence, but with a vision for the organization, to drive organizational change and enforce corporate performance in brand new ways.

But even today the communication between IT and Business can suffer. There is a need to gap the bridge in between, making sure that both sections of the organization collaborate efficiently and effectively in order to meet corporate goals. And this is the ultimate challenge for the years ahead.

Saturday, 6 July 2013

A living legend




There are some people that I have met in person and admire in some degree, but one figure that always had tremendous impact on me is definitely the imposing Cretan Minos Zombanakis. Minos achieved the status of a true legend in the global banking scene, but that was not enough to catch my full attention. Minos Zombanakis among many other achievements, is the father of Libor in the financial community. I asked myself if it is possible for a banker to despise ill-gotten wealth in an era when morals and good manners are nonexistent. Is it possible for a man to be human and genuine in our days, when people cannot even communicate, because the monitors they stare at all day and night have made interaction impossible? My answer in these two questions is definitely yes.

His personal story is indeed an amazing adventure. Minos was born in 1926 in a small village called Kalives and he grew up in a 2nd world war Greece, and back then life in Crete was hard even for a living. The only Greek territory remaining free by May 1941 was the large and strategically important island of Crete which was held by a strong allied garrison. Crete was of course a strategic area, close to North Africa so it was a matter of time to become a bloody battleground.  Conditions in Athens were very bad too. That was a very tough starting point, for one man’s life through war, violence and hunger in the streets. Even though Minos was a young schoolboy, through his books and insightful observations managed to make his way out and see the big picture too early. In a world out of control, he had his own plans for the future. During war, the Governor of the Bank of Greece followed the Greek Government into exile.

In 1948 the Marshall plan (officially the European Recovery Plan) got into full swing in Greece, headed by Paul Porter. Minos had already gained experience participating in high level discussions between the US and Greek governments and he became an assistant Executive Director in the Bank of Greece, managing foreign exchange reserves and battling inflation in these desperate times.

But further studies were needed for someone who wanted to make a difference in his field. Back then in Kalives, Minos met a man who came back from Cambridge in the United States to his village in Crete. This man told Minos with pride that he was a waiter at Harvard – in the days when servants polished the students’ shoes, and urged Minos to consider himself as a Harvard boy.

Minos made his way to the United States; he went at the Harvard gates in order to challenge his own strengths, soon to realize how different life was in the US at that time. But there was a slight problem when he arrived. He could not be accepted because he didn't had a degree. After this huge disappointment a friend advised him to insist as much as possible and audit a few courses. After tremendous effort from the side of Minos, he was accepted to just audit the courses. But Minos was enthusiastic, smart and a fast learner, catching the attention of his professors. The board allowed him to give the exams, where he excelled. After this important step and the support of Dean Mason he was fully enrolled, able to sit for a Masters Degree at the age of 30, one of the youngest in class. After completing his studies at Harvard he went to New York to work for a Greek ship owner.

His journey to the global markets took off from that point. Through the markets of Europe, United States, Middle East and Japan Minos literally changed the financial markets with his innovations. As David Lascelles beautifully presents in his book, Minos opened up a whole new era in international finance, without even being a product of the dominant Anglo-Saxon financial establishment, or even of the new wave of Central European Jewish bankers.

A few years ago, the first time I met Minos I was in a personal turning point, a period of a great challenge in my life. I can remember I was so stressful, I thought I lost my nerve forever.  A difficult period of time that maybe many of us went through at some point in our life.  When I saw his tall figure, I thought I knew him forever. I instantly understood that he is a warm person, his mind is enormously sharp, an intellectually curious man that you know you can’t go wrong when you seek for the right advice at the right time. 

I have learned an important lesson from Minos Zombanakis. Never give in. Never give up, because life is a constant challenge. Maybe there will be many setbacks along the way. Dare to move forward. Don’t be late – don’t postpone. Don’t be afraid to challenge your quiet life. In times of great challenge, when the chips are down, a joyful voice is always coming deep inside from my head. I know this familiar voice. It is Minos. 

Sunday, 30 June 2013

Cyber crime at the age of “Monster” Economy: An ugly correlation

It is quite obvious that world economy is increasingly dependent on the information and communications technology, especially after the dynamic implementation and expansion of new technologies in the public and private sectors of commercial and social applications. The Information and Communication Technology (ICT) sector is vital for all segments of the government and the society. 

Businesses for example rely on the ICT sector both in terms of direct sales and for the efficiency of internal processes. ICT infrastructures are a critical component of innovation and are responsible for nearly 40% of productivity growth. [1] It is actually so obvious that our society considers for granted the uninterrupted use of networks and infrastructures. 

The ICT sector is also responsible for the sustainability of the National Security in various forms. But the permanent adoption of the internet and the nonstop utilization and the convergence of multiple technologies are not without a risk. And that risk cannot be explained with traditional terms or only with quantitative criteria.

Modern societies are more open and more networked than ever. The high complexity and the different possibilities of the systems create vulnerabilities and threats, easy to exploit. It is widely accepted that since 2008 with the fall and the consequences of Lehman Brothers, our world has changed dramatically. Cyber crime attacks rise globally at explosion rates. In order to understand the significance of the issue, we need to understand first, that modern tactics performing cyber terrorism activity and behavior. 

It is furthermore a necessity to shape an understanding of the topic and the danger that could cost the loss of integrity, huge financial damage or even the loss of human lives. Therefore there is a need for technologically informed political leadership, that is able to drive the decision making and deal with the problems, balancing individual privacy and freedom of the people with safety and security. The economic landscape provides extreme difficulty to take action, especially when budget reduction is extreme and affects the operational expenditure.

During the World Economic Forum estimated that there is a 10% to 20% probability of a major CII breakdown in the next 10 years, with a potential global economic cost of approximately $ 250 billion.[2] Security Experts warned at Davos, that cyber crime threat is rising sharply. Security experts and law makers are constantly addressing a wide range of vulnerabilities, unraveling a trend that is not just vandalism but organized criminality. Our active communities are based upon free will, but at the same time national security and social coherence should be a top priority and in balance.

The current economic turbulence has contributed in the decline of economic activity, high unemployment and social unrest, not only inside the European continent, but in the Western world. These negative developments can easily result with social unrest which can lead to outbursts of violence and criminality, including the multiple rises of electronic crime and cyber terrorism. 

As more and more jobs are being lost, the financial crisis magnifies negative psychology. Under this situation people can be exploited by various groups that promote acts of violence[3]. And just as street crime increases in times of financial stress, the same trend is being noticed in cyber crime, but in a far higher impact, financially and ethically as well.  

It is not a coincidence that is expected a considerable expansion in cyber crime. Economic projections expect an extremely weak growth for the following years. Governments anticipate that specific policy actions would stabilize the economy, developing the right consequences for sustainable economic growth. This process will not only take years, but it will test the limits of a vast majority of the population.

European governments ultimately respond with heavy cost reductions that could probably have a negative impact in basic governmental and military operations. This could easily endanger a decline of the efficiency and the effectiveness of network and telecommunications infrastructures as also the level of security and privacy. The truth is that nobody knows the duration and the depth of this crisis, in Europe and the Western countries. 

As Joseph Stiglitz notes “Given the complexity of the economic system, the difficulties in predicting how expectations will be altered, and the pervasive irrationalities in the market, there is no way the impact of any economic policy could be ascertained with certainty”[4].  Many distinguished economists openly compare this current crisis with the Great Depression of the 1930’s. 

The vertical decline of housing prices, the rapid loss of jobs, and the decline in business investments as also the decline in lending capacity of the banking system, created mass anger and various groups realize that the World Wide Web eliminates boundaries and lacks centralized control. Therefore it is a tool that it can be exploited in a manner so disastrous not only against an individual but also against a country.

Discussing the issue of cyber warfare we should note that at the same time the attacker is trying to develop the highest possible damage, in public or private Information Technology Infrastructures and Communication networks. The sophistication of new attack tools and their widespread availability in open networks, create a disastrous mix that it cannot be eliminated without the appropriate policies and countermeasures, as also with the agreement of centralized operational and strategic principles for Europe.

The international competition could initiate a new round of state sponsored cyber attacks in mass level, and governments understand that this threat is unlike any other traditional threat, coming from an army or a terrorist group.
It is daily news in the mainstream media these days, cases like the Political extremism coming from altered or malicious information that is targeting political parties or individuals known or unknown personalities, with the use of propaganda and harassment methods.

Under specific circumstances the spread of malicious information in mass scale, could create social unrest or even worse acts of terrorism.  At the age of the internet and fast moving information, people are ready to believe, without having too much time to think about the legitimacy of the source that is providing the information or the real intentions of the author that in many cases is unknown. Social networking is growing rapidly along with the misuse of social networking accounts. It includes the use of offensive religious comments, race messages of hatred to anyone, pedophilia and other acts of behavior that very often cannot be categorized as individual crime but as a scheme that employs many individuals with different roles.

It is worth noting the Greek based European Network and Information Security Agency (ENISA) based in Heraklion, Crete, which is the responsible body of expertise, in order to tackle Network and Information security problems, and enforce community legislation in collaboration with the European Commission. ENISA’s role is also to address, respond and especially to prevent Network and Information Security problems[5]. In 2008 ENISA’s mandate was extended ‘à l’identique’ until March 2012.[6]  It is in the positive direction policies like the Critical Information Infrastructure Protection (CIIP) launched by the European Commission, and the first pan European CIIP exercise Cyber Europe 2010[7].  

The OECD as well underlines the importance of ICTs and the Internet "to boost economic performance and social well-being, and to strengthen societies’ capacity to improve the quality of life for citizens worldwide"[8] The complexity and the extreme rising in vulnerabilities and threats should be accompanied by the proper refinancing, distribution of knowledge through International and European Union wide collaboration and further recruitment of advanced scientific personnel, on the forefront of ICT Security research. This is the only way to be ahead of a constantly growing threat of criminal and terrorist activity. There is much to be done the following years.

Cyber crime cannot be characterized as a white collar crime anymore. Traditional organized crime is already involved in various forms of Cyber crime, while at the same time the use of tools and techniques to attack to a given network are widespread over the internet. These criminal groups are able to exploit vulnerabilities of critical infrastructures and it is quite clear that traditional organized crime is developing relationships with technically skilled hackers, working under an incomplete law scheme that in many cases prohibits the arrest of these criminal actors. 

As the economy sinks it is also expected that internet will become a tool for money laundering. Illegal Online gambling for example creates the possibility to move huge amounts of capital to offshore companies, to the other side of the globe within minutes. This provides an added degree of protection against law enforcement and allows them to operate with minimal risk. The inherently transnational nature of the Internet fits perfectly into this model of activity and the effort to maximize profits within an acceptable degree of risk[9].

Hackers characterize the current state of counteraction of malefactors’ systems to security systems as a “game of network cats and mice” (Nomad 2002)[10] As with any other profession, hackers need an assortment of tools to do the job. These tools are widespread over the internet today. 

The reality though is that for the first six months of 2008, of all security breach incidents reported around the world only 23 per cent could be attributed to the activities of hackers[11].  But these percentages are also likely to increase dramatically, because of the widespread use of smart phones and laptops and the ever increasing number of users who are more mobile than ever, thus creating an easy target.

The rise of social networks misuse of social networking accounts is an ever growing problem that governmental think tanks should address and respond, as a challenge that requires a broad and cooperative response. 

Fifteen percent of all of the youth reported an unwanted sexual solicitation online in the last year; 4% reported an incident on a social networking site specifically. Thirty-three percent reported an online harassment in the last year; 9% reported an incident on a social networking site specifically. Among targeted youth, solicitations were more commonly reported via instant messaging (43%) and in chat rooms (32%), and harassment was more commonly reported in instant messaging (55%) than through social networking sites (27% and 28%, respectively)[12].

In order to tackle effectively with all these threats in a this unstable era, a serious, information security conscious  and willing political action is required, in order to address and respond effectively with specific directions all these current and growing problems that arise. Knowledge, regulation and compliance is the key for more effective governance. The collaboration between the public and the private sector should be further encouraged. 

Policy-makers and governmental agencies must consider the constantly developing cyber threats and vulnerabilities as an integral part of a complete security strategy, an issue that is far beyond the military purpose, even if tackling Cyber terrorism activities is still not an easy task to define and execute. 

There are many examples of the past that demonstrate the fact that even a whole country can go down very fast, if essential integral parts of the society, like telecommunications, the banking system, or the utilities like electrical networks become a target of such an attack. Furthermore the effects of misinformation, data-pooling or corrupted data events should never be underestimated in an open society.


References



[1] http://epp.eurostat.ec.europa.eu/ - Science and Technology/Information Society (October 29 2010)
[2] Global Risks 2008
[3] Kalentis C. (2009)Interview under title Financial Crisis and Crime,(p.p. 56-59) Value Invest, Issue 3
[6] Regulation (EC) No 1007/2008
[9] Williams Phil, Organized Crime and Cyber-Crime, Implications for Business, Cert Coordination Center
[10] Nomad 2002. Nomad Mobile Research Centre. www.nmrc.org
[11] Microsoft, Security Intelligence Report Key Findings Summary January 2008 – June 2008)
[12] Ybarra M. and Mitchell K. (2008) Official Journal of the American academy of Pediatrics,  How Risky Are Social Networking Sites? A Comparison of Places Online Where Youth Sexual Solicitation and Harassment Occurs.