Archive

Posts Tagged ‘Fraud’

Economic crime vulnerabilities

June 14th, 2010 admin Comments off

The  key vulnerabilities of a business  to fraud and data loss are rooted in the  four sins of hubris: thinking, looking, fighting and denying.

Hubris is defined as excessive pride or self-confidence, starting with the thought that fraud and data theft won’t happen to you.  Most firms look in the wrong direction, by focussing on external threats and malware instead of trusted insiders and organized crime. They fight the wrong battle, by installing anti-virus on machines that are not vulnerable to virus attacks, and relying on firewalls for data loss prevention. By not monitoring outbound data flows they also gain plausible denial that there are issues of data loss and economic crime in the organization.

The  sins of hubris lead to a situation where the bigger you are the harder you fall (“It can’t happen to me because we have governance, IT etc..”). According to PWC 2009 Global Economic Crime Survey – bigger companies experienced more fraud.

46% of organisations experiencing economic crime had more than 1,000 employees.

The percentage of companies in the 201 – 1,000 employee range experienced almost half the number of fraud of their larger cousins. But this may be because they have fewer governance programmes in place, or what they do have are less effective.

By the way, I think the PwC have it wrong.   Smaller companies may have fewer governance programs in place, and because they have less money, these programs are probably more effective, not less effective.

Denial of data loss and economic crime also derives from incomplete understanding of the economic costs. The 2009 PwC economic crime survey points out that :

27% of those reporting fraud in the last 12 months put its costs at more than $500,000.

One quarter of respondents reporting accounting fraud estimated that it had cost them more than US$1m.

Only 17% of those who suffered asset misappropriation reported losses of more than US$1m.

The impact of economic crime is not just financial: 32% of respondents said employee morale was most affected by such incidents.

Data loss and fraud events are unpredictable, high impact events without precedent that cannot be forecasted with virus/epidemiology or  market risk models.  The assumption in these  models is that the unexpected can be predicted by extrapolating trends from past observations, especially when these statistics are assumed to represent samples from a normal distribution. Although other distributions might provide better fits to historical data, such as the fractal (for earthquakes) or LÉvy distributions (for securities returns) or EVT (for operational risk events) – in all economic crime cases, organizational  culture was at the center of losses, and more specifically, a complex interaction of culture, people and rapidly-changing technology.

It’s impossible to stave off fraud and data theft with technology or procedures alone due the complexity, but with a management that puts a priority on a business objective of protecting company assets and customers, an organization will be able to go beyond governance and security checklists and reduce their value at risk.

Economic crime and data theft  warrants a zero-tolerance culture starting in the boardroom and with the executive management leading by example with open doors and ethical behavior.

UK gets serious in the war on corruption

November 19th, 2009 admin Comments off

David Benyon from Op Risk and Compliance magazine reports

A new bribery and corruption legislation will be put before the UK parliament. Doing business using bribery would mean jail for a decade under the bill.

“The new Bribery Bill will make it far easier for companies and senior management to be prosecuted where bribes have been offered, paid or received. The new legislation will be even wider than the US Foreign Corrupt Practices Act, because it covers business-to-business transactions as well as business transactions with government or state-owned bodies,” says Neill Blundell, partner and head of the fraud group at law firm Eversheds”

Gaming the ratings

May 11th, 2009 admin Comments off

A common vulnerability in online ecommerce sites is fraudulent manipulation of user profiles in order to boost the ratings of products in online recommender systems and overall reputation of the web site.

This article – Unsupervised Retrieval of Attack Profiles in Collaborative Recommender Systems casts this problem as a problem of detecting anomalous structure in network analysis and proposes a novel mechanism for detecting this anomalous structure.

Categories: Anti-Fraud Tags: , ,

Mafia country, counterfeiting currency

January 28th, 2009 admin 1 comment

Back in the late 70s when I was a grad student in physics I gave a paper in Pisa and then in Bari.  The differences between Pisa and Bari were very clear – Pisa – Northern Italy, very European and industrialized, Bari, South of Italy, very agricultural and very Mediterranean – the one thing that stuck in my memory though was how distrustful the people in Bari were of strangers. I asked our host at the University of Bari and he said “well of course, this is Mafia country, they ARE suspicious of strangers, you never know…”

Italian police say they’ve made 96 arrests after busting a European counterfeiting and money laundering ring. Most of the arrests were made in southern Italy’s Calabria and Campania regions.

Read more…

Categories: Compliance Tags: , ,