Integrating IT Risk into
Enterprise Risk Management
MAY 14, 2019
About Greg Smith
• Bio Statements go here
© 2019 Alagen. Confidential. All rights reserved.
Agenda
• Enterprise Risk Management
Integrating • The Challenge
IT Risk into • How to Integrate IT Risk
Enterprise
Risk • Summary
Management • Q+A
© 2018 Alagen. Confidential. All rights reserved.
Enterprise Risk Management (ERM)
“a process, effected by an entity's board of directors,
management and other personnel, applied in strategy
setting and across the enterprise, designed to identify
potential events that may affect the entity, and
manage risks to be within its risk appetite, to provide
reasonable assurance regarding the achievement
of entity objectives.”
– Committee of Sponsoring Organizations of Treadway Commission (COSO)
© 2019 Alagen. Confidential. All rights reserved.
Enterprise Risk Management
(Banking)
Credit Interest Rate Liquidity Market Regulatory Strategic Operational Reputation
Risk Risk Risk Risk Compliance Risk Risk Risk
© 2019 Alagen. Confidential. All rights reserved.
Credit Risk Interest Rate Risk
Risk that contract terms Financial risk arising from
go unmet and loans, movements in interest rates.
commitments, or investments Includes repricing, yield curve,
fail to perform as agreed. and options risks.
Liquidity Risk Market Risk
Arises from a bank’s inability Arises from changes in
to meet obligations when due the value of portfolios
without incurring of financial instruments.
unacceptable losses.
© 2019 Alagen. Confidential. All rights reserved.
Regulatory
Compliance Strategic Risk
Risk arising from violations or Arises from adverse or
nonconformance with laws, improper implementation of
rules, regulations, prescribed business decisions, lack of
practices, or ethical standards. responsiveness.
Operational Risk Reputation Risk
Arises from inadequate or The loss of customer trust
failed internal processes or has serious financial
IT systems, the misconduct or consequences.
errors of people, and adverse
external events.
Includes IT Risk
© 2019 Alagen. Confidential. All rights reserved.
Top Risks for 2019
1.
1. Existing operations
Existing operations meeting
meeting performance
performance expectations, competing
expectations,
competing“born-digital”
against against “born-digital”
[Link].
2. Succession challenges and ability to attract and retain top talent.
2. Succession challenges and ability to attract and retain top talent.
3. Regulatory changes and regulatory scrutiny.
3.
4. Regulatory
Cyber threats. changes and regulatory scrutiny.
4.
5. Cyber
Resistancethreats.
to change operations.
5.
6. Resistance
Rapid speed ofto changeinnovations
disruptive operations. and new technologies.
7. Rapid
6. Privacy/identity
speed of management
disruptiveand information and
innovations security.
new technologies.
8. Inability to use analytics and big data.
7. Privacy/identity management and information security.
9. Organization’s culture may not sufficiently encourage timely
8. Inability
identificationto and
useescalation
analytics andissues.
of risk big data.
9.
10. Organization’s
Sustaining customer culture
loyalty may not sufficiently encourage timely
and retention
identification and escalation of risk issues.
Source: Executive Perspectives on Top Risks 2019, Protiviti and North Carolina State
[Link] customer
University Poole College loyalty
of Management’s and retention
ERM Initiative
Source: Executive Perspectives on Top Risks 2019, Protiviti and North Carolina State University Poole College of
Management’s ERM Initiative
© 2019 Alagen. Confidential. All rights reserved.
Really Secure Money Went To
Bank Marketing Bank
1% likelihood of breach 30% likelihood of breach
in next 5 years in next 5 years
© 2019 Alagen. Confidential. All rights reserved.
The Challenge
IT risks are notoriously hard to quantify
Breaches: Not if, but when
Cost of financial services breach
is $206 per capita
10,000 records = $2.06 million
50,000 records = $10.3 million
100,000 records = $20.6 million
© 2019 Alagen. Confidential. All rights reserved.
Financial Statistical
Institutions Techniques
Asset Quality
Profit Margin
Return on Investment (ROI)
Return on Equity (ROE)
Operational Efficiency
Asset Turnover
Debt to Asset Ratio
Debt to Capital Ratio
IT Risk
© 2019 Alagen. Confidential. All rights reserved.
Quantitative Qualitative
Analysis Analysis
Tells part of the story
Devil is in the details
of assumptions
© 2019 Alagen. Confidential. All rights reserved.
Risk Factors
Inherent Risk – level of risk present before any action is taken to manage or mitigate the risk
Quantity of Risk – the level or volume of risk that the bank faces and is characterized as low,
moderate, or high
Quality of Risk Management – how well risks are identified, measured, controlled, and
monitored and is characterized as strong, satisfactory, or weak
Impact – the resulting effect of an event
Likelihood – how often something is expected to occur
Residual Risk or Aggregate Risk – incorporates an overall evaluation about the quantity of
risk and the quality of risk management expressed as high, moderate, or low
Risk Appetite – the type and amount of risk a bank is willing to tolerate in the pursuit of their
objectives
Direction of Risk – is an assessment of the probable movement in aggregate risk over the
next 12 months and is characterized as decreasing, stable, or increasing
Velocity of Risk – the speed of occurrence of a particular risk impacting the organization.
Some risks have an immediate impact, such as a tornado, and others are more gradual in the
onset of effect
Key Risk Indicators – measurable events that an organization believes to be valuable to track
as an early warning to possibly negative events. Examples are loan delinquency rates, computer
patching compliance levels, system downtime, etc.
© 2019 Alagen. Confidential. All rights reserved.
ERM Report
© 2019 Alagen. Confidential. All rights reserved.
ERM Process
1. Risk Assessment Methodology
2. Creation of a Risk Team
3. Identification of Threats and Types of Losses
4. Identification of Controls Used to Mitigate Risks
5. Evaluation of Controls
6. Method of Quantifying Risk
7. Rating Quality of Risk Management
8. Likelihood and Impact
9. Communication and Reporting of Risk
10. Ongoing Risk Monitoring
© 2019 Alagen. Confidential. All rights reserved.
Risk Assessment Methodology
NIST
ANSI Identify or establish
ERM framework and
use it for IT risk.
COSO
ERM
ISO
31000
© 2019 Alagen. Confidential. All rights reserved.
Creation of a Risk Team
• Long-standing
• Different backgrounds
• Meet periodically
• Goal: Assess Risk using
ERM methodology
© 2019 Alagen. Confidential. All rights reserved.
Identification of Threats
And Types of Losses
Privileged
• Categorize your data
• Identify threats:
Restricted
Confidential • Bad guys value:
IP, SSN, Cardholder Data
Company Confidential
• Resources: Verizon
Data Breach Report
• Threat modeling
Public
© 2019 Alagen. Confidential. All rights reserved.
Identification of Controls
Used to Mitigate Risk
• Technical + Non-technical
• Preventative Controls: web filtering, blocking
known outbound ports, up-to-date antivirus
• Administrative Controls: acceptable use of policy
and training program
• Detective Controls: alerting when malicious links
are clicked
© 2019 Alagen. Confidential. All rights reserved.
Evaluation of Controls
Goal: accurately rate the effectiveness of controls
as compared to an industry standard
Rating Description
1 Control effectiveness significantly exceeds all industry standards
2 Control effectiveness meets and, in some cases, exceeds industry standards
3 Control effectiveness meets industry standards
4 Control effectiveness does not meet all industry standards
5 Control effectiveness has significant deficiencies compared to industry standards
© 2019 Alagen. Confidential. All rights reserved.
Evaluation of Controls: Approaches
1 Consensus rating
• Requires true understanding of industry standard
• Requires intimate knowledge of org’s control effectiveness
• At best, it can be acceptable
• At worst, it’s just an educated guess
2 Use the rating system used by examiners:
Uniform Rating System for IT (URSIT)
• Easy to understand composite rating (1–5 scale)
• 4 components: audit, management, development + acquisition,
support + deliver
• Compliance-driven approach of correcting findings
• Not proactive
© 2019 Alagen. Confidential. All rights reserved.
3 Compare org’s inherent risk levels to FFIEC cyber
assessment tool cybersecurity maturity levels
• Quantify actual controls in place
• Variance from maturity level that corresponds to inherent risk
allows for increase / decrease of control effectiveness rating
• Fine-tuning by CAT “domains” allows
tailoring of goals
• FSSCC spreadsheet tool provides
useful graphs and analysis
© 2019 Alagen. Confidential. All rights reserved.
4 Use scenario analysis to prioritize and rate controls
based on relevant (financial services) breach data
• Gives importance to controls in the “kill chain” that stop attacks
• Ties control objectives to prevalent attack ”domains”
• Strategic planning can be tied to improvements that matter
• Attack sophistication, breach costs, and control quality can be
modeled statistically to project likelihood and impact
Domain Description
Any incident involving malware that did not fit into a more specific pattern. The majority of the
incidents that comprise this pattern are opportunistic in nature and have a financial motivation
Crimeware (CRI)
behind them. This pattern frequently affects consumers and is where “typical” malware
infections will land.
Payment Card All incidents in which a skimming device was physically implanted (tampering) on an asset that
Skimmers (PCS) reads magnetic stripe data from a payment card (e.g. ATMs, gas pumps, POS terminals, etc.).
© 2019 Alagen. Confidential. All rights reserved.
Method of Quantifying Risk
Ensure risks are ranked appropriately to guide decision making
• Requires detailed understanding of allowable limits and
standards used
• Need descriptions for high, medium, and low risk situations
High Risk Medium Risk Low Risk
Less than 65% of all critical and At least 65% of all critical and high All critical and high vulnerabilities
high vulnerabilities for servers, vulnerabilities for servers, network for servers, network devices, and
network devices, and workstations devices, and workstations are workstations are patched within 30
are patched within 30 days of the patched within 30 days of the days of the patch release
patch release. patch release.
Example of Risk ratings for a patch management program
© 2019 Alagen. Confidential. All rights reserved.
Other approaches:
• IT Risk in the context of Operational Risk
• Incorporates four components, including the FFIEC CAT
Inherent Risk Profile
High Risk High Risk
Risks from transaction-processing failures, The number, nature, and complexity of
technology changes, outsourcing, planned third-party relationships continue to
conversions, merger integration, or new expand.
products and services are high. Volume of
cyberattacks is high and increasing based High reliance on a few third parties that
on industry statistics. service multiple banking institutions.
The speed and sophistication of
Example of Risk ratings for overall program
cybersecurity threats are increasing.
FFIEC Cyber Assessment Tool (CAT)
Inherent Risk Profile is “Significant” or
“Most” as determined in the last year.
Example of Inherent Quantity of Cybersecurity
Risk ratings incorporating FFIEC CAT
© 2019 Alagen. Confidential. All rights reserved.
Rating Quality of Risk Management
Define weak, satisfactory, and strong risk management practices
Weak Risk Management Satisfactory Risk Mgmt. Strong Risk Management
No standards are defined for Appropriate standards are in place Standards are in place for patching
patching; no regular reporting of for patching; regular quarterly that are higher than industry
compliance with defined standards; reporting of compliance with standards; regular quarterly
vulnerability scanning is performed defined standards occurs to reporting of compliance with
less than quarterly; vulnerability appropriate level; vulnerability defined standards occurs to
results are inconsistent scanning is performed at least appropriate management;
quarterly; vulnerability results are vulnerability scanning is performed
generally consistent with some at least weekly; vulnerability results
occasional subpar patching levels are consistent and managed
effectively.
Example of Quality of Risk Management ratings for a patch management program
© 2019 Alagen. Confidential. All rights reserved.
Weak Risk Management Satisfactory Risk Mgmt. Strong Risk Management
Average declarative statement Average declarative statement Average control effectiveness across
(control) effectiveness across all (control) effectiveness across all all five FFIEC Cyber Assessment Tool
five FFIEC Cyber Assessment Tool five FFIEC Cyber Assessment Tool (CAT) domains is greater than “2.5”.
domains is less than“2”. domains is “2”.
Inherent Risk Profile suggested
Inherent Risk Profile suggested Inherent Risk Profile suggested maturity level is exceeded in at least
maturity level is not met for all maturity level is met in all domains three of five domains for most controls.
controls. for all controls for all controls.
Bank phishing click response rates are
Bank phishing click response rates Bank phishing click response rates formally monitored by an anti-phishing
are not formally monitored by a are formally monitored by an anti- program and click rates are below 10%.
anti-phishing program. phishing program and click rates
are below 20%.
Example of Quality of Risk Management ratings for overall program (3 components)
© 2019 Alagen. Confidential. All rights reserved.
Alternative “Top Down” approach:
• Rate how controls resist attack scenarios by comparing to a
standard, like FFIEC Cyber Assessment Tool’s declarative
statements
Sample rating system
Process or control is informal, at an initial phase of implementation, or
ad-hoc, and may not fully meet declarative statement intent. The process
may not be documented or repeatable and may be dependent on
individual heroics.
Process or control meets the specific requirements of the control
statements. Process or control is repeatable and appropriately managed;
and defined with documented policy, procedures, and standards.
Process or control meets and often exceeds the specific requirements of
the control statements; is repeatable and appropriately managed; and
defined with documented policy, procedures, and standards. Quality of
the implementation is high resulting in lower risk.
© 2019 Alagen. Confidential. All rights reserved.
• Create an aggregate rating (sum of ratings ÷ # of controls)
• Calculate residual risk value = remaining risk after inherent risk
has been reduced by your risk controls
• Good reflection of quality of overall cyber security program
• This quantitative rating can be used as a quality of risk
management value
Weak Risk Management Satisfactory Risk Mgmt. Strong Risk Management
Average control effectiveness Average control effectiveness Average control effectiveness across
across all five FFIEC Cyber across all five FFIEC Cyber all five FFIEC Cyber Assessment Tool
Assessment Tool domains is less Assessment Tool domains is “2”. domains is greater than “2.5”. Inherent
than “2”. Inherent Risk Profile Inherent Risk Profile suggested Risk Profile suggested maturity level is
suggested maturity level is not met maturity level is met in all domains. exceeded in at least three domains.
in some domains.
Example of Quality of Risk Management ratings for overall program
© 2019 Alagen. Confidential. All rights reserved.
Likelihood and Impact
Represents the probability an event might result in deliberate or
accidental impact to the organization.
• Lowest likelihood of an occurrence would be a 1.
Rating Likelihood
1 Extremely unlikely — once every 50 years
2 Unlikely — once every 10 years
3 Likely — once every 5 years
4 Probable — annually
5 Expected — monthly
Example of Likelihood Ratings for an event or category of events
© 2019 Alagen. Confidential. All rights reserved.
Impact ratings rate the relative significance of an event (like a
distributed denial of service (dDOS) attack or breach)
• Sample below shows two areas appropriate for most orgs.
• Other areas might include reputational, strategic,
regulatory/legal, and security
Rating Financial Impact Operational Impact
1 < $20k Minor operational problem with no customer impact
2 ~ $200k Temporary loss of services for less than 4 hours; limited customer impact
3 ~ $500k Temporary loss of a service for more than 4 hours; limited customer impact
4 ~ $1mil Temporary loss of a service for more than 12 hours; significant customer impact
5 ~ $5mil Temporary loss of a service for more than 36 hours; significant customer impact
Example of Impact Ratings for an operational event
© 2019 Alagen. Confidential. All rights reserved.
Communication and Reporting of Risk
Following assessment of components, a report is created
• Executive summary
• Rates the risks
• Provides context of the nature of the risk
• Documents contributing factors
• Clearly states recommendations to address any gaps
• Other relevant details
Once approved by risk team, request a verbal briefing
• Risk committee, board, CEO, or CFO
• Focus on important points, any action or funding needed
• If part of an ERM, you may only get a minute or two
Re-communicate report whenever significant incidents occur
© 2019 Alagen. Confidential. All rights reserved.
Ongoing Risk Monitoring
• IT Risk monitoring and reporting needs to occur regularly
• Keeps management and/or board informed about the true
state of IT Risk
• Ensures CISOs / IT Managers alert when processes are in
need of resources, expertise, and innovative thinking
© 2019 Alagen. Confidential. All rights reserved.
Where to Start
1. Talk with the most senior person in your organization
about the ERM framework
2. Understand the key concepts and definitions used and let
your Chief Risk Officer you’d like to contribute to the
quality of periodic evaluations
3. Do a Cyber Security Assessment
© 2019 Alagen. Confidential. All rights reserved.
Summary
Effective incorporation of IT Risks as a part of ERM:
• Provides critical intelligence about a key risk category
• Ensures company-wide awareness of security risks
• Enables appropriate prioritization and funding within
context of all organizational risks
• Improves security posture by enabling organizational
understanding and ongoing assessment of security needs
Following the outlined steps will ensure that IT security is
considered among other enterprise risks, bolstering your
institution’s enterprise risk management efforts.
© 2019 Alagen. Confidential. All rights reserved.
Questions?
Gregory Smith, CISSP
Senior Risk Advisor
[Link]@[Link]
© 2019 Alagen. Confidential. All rights reserved.
INTEGRATING IT RISK
INTO ENTERPRISE
RISK MANAGEMENT
Greg Smith, Alagen