eBusiness Enterprise Risk Management

eBusiness Enterprise Risk Management

Enterprise Risk Management Definition Enterprise Risk Management (ERM) is the capability to protect enterprise value by managing risk: - With a coordinated and systematic approach, - Organization-wide, and - Across all types of risk. - DelCreo, inc.

Business Risk Profiling: Risk Drivers

Business Impact Assessment
Detailed Risk Analysis
Level Risks That Matter
Management challenges the numbers - Make it "real" for senior management - Typical approach/ measures often do not line up with how CEO, CFO, CIO evaluate their business and make decisions

Practical Application: Hewlett-Packard ERM
World-Class
Coordination among risk functions to increase coverage and decrease cost
Enable business / ease time to market
Alignment with business strategies and objectives
Consistent and organization wide processes
World-class risk management tools
Focus on risks that impact stakeholder value
Source: Hewlett-Packard - Used with permission

eBusiness: So What? “The ‘telephone’ has too many shortcomings to be seriously considered a means of communication. ~ Western Union Internal Memo, 1876 “This wireless music box has no imaginable commercial value. Who would pay for a message sent to nobody in particular?” = David Sarnoff’s associates in response to his urgings for investment in Radio in the 1920's “Who the hell wants to hear actors talk 2" - Harry M. Warner, Warner Bros, 1927 “There is no reason for any individuals to have a computer in their home.” - Ken Olsen, President, Chairman and Founder of DEC, 1977 “Heavier-than-air flying machines are impossible.” ~ Lord Kelvin, President, Royal Society 1895 “airplanes are interesting toys but of no military value. - Marshall Ferdinand Foch, Professor of Strategy, Ecole Superiure de Guerre DelCreo, inc. ‘An Enterprise Risk Management Company

eBusiness Trends Real Time Enterprise Low Tech, High Impact High Tech, Low Cost Cyber-Activism - DelCreo, inc.

"Real Time" Enterprise
"Ciscoize" and "Dellize" Every Business
Adaptive architecture, evolvable applications
Federation NOT integration
Architecture to connect architectures
Rapid, incremental implementation
Instantaneous "financials", metrics, supply chain, customer support....

Low Tech, High Impact Terrorists have employed low tech weapons to inflict massive physical or psychological damage - Box cutters - Envelopes Infrastructure is vulnerable to unsophisticated attacks Identify assets at risk Strategic Initiatives - People - Process ~ Information Systems Physical Infrastructure Geography Organization Products - Flows (supplies, information, electricity, cash, etc.) Focus risk assessment on how the asset may be impacted - DelCreo, inc. ‘An Enterprise Risk Management Company

High Tech, Low Cost Sophisticated technologies/tools that may be employed as weapons of Mass Destruction/Interruption - Biological and chemical weapons - Technology Technologies/tools that have the ability to inflict massive damage are getting cheaper every day Sophisticated tools are increasingly affordable and are being used by competitors, customers, employees, litigation teams, etc. - DelCreo, inc.

Cyber Activism * The Internet: “a powerful tool for communicating and coordinating action.” - Collection Publication Dialogue Coordination of action Direct lobbying of decision makers - DelCreo, inc.

eRisks....Just a Few * Cyber terrorism ¢ Hactivism * Data Privacy * Critical Infrastructure Failure * Intangible Property * Third Parties - DelCreo, inc. nem 0

Cyber terrorism “The convergence of terrorism and cyberspace” Definition - “Unlawful attacks and threats of attack against computers, networks, and information stored therein when done to intimidate or coerce a government or its people in furtherance of political or social objectives” - FBI Definition Tamil guerrillas send 800 emails a day to Sri Lankan embassies to “disrupt communications” NATO computers hit with e-mail bombs and denial- of-service attacks during 1999 Kosovo conflict Pro-Palestinian and pro-Israeli deface Israeli and Palestinian sites over a one month period in October, 2000. “A DelCreo, inc. Se Risk Management Company

Hacktivism * Definition - Operations that exploit computers in ways that are unusual and often illegal to further social causes. * Methods - Virtual Sit-Ins and Blockades - E-Mail Bombs - Web Hacks and Computer Break-Ins - Computer Viruses and Worms - DelCreo, inc.

Data Privacy Credit card information Identity theft Bio-Metrics Differences in Regulations - United States - Canada - European Union - Other - DelCreo, inc.

Critical Infrastructure Failure * Today’s business system - Complex - Tightly coupled - Heavily dependent on infrastructure * Interconnectivity of infrastructure - Telecommunications - power generation and distribution - Transportation - Medical care - National defense - Other critical government services * Ripple effects of infrastructure failure 2 DelCreo, inc. ‘An Enterprise Risk Management Company

Intangible Property * Mismanagement - Lost or theft by competitors - Inability to profit - Sharing without compensation * Poor use of risk management techniques - Insurance - Continuity planning - Business Controls * Complicated by increase in # of third parties and “virtual” supply chain - DelCreo, inc.

Third Parties Risk appetite, strategy and sophistication variances Brand/reputation inequity Regulatory compliance complications Intangible property Contingency planning - DelCreo, inc.

eBusiness Risk Management Risk Strategy Risk Committees Risk, Incident and Crisis Management Risk Management Intranet Portals Enterprise Risk Management - DelCreo, inc.

Risk Strategy Accept Risk: Management decides to continue operations as is with a consensus to accept the inherent risks Transfer Risk: Management decides to transfer the risk from (for example) from one business unit to another or from one business area to a third party (i.e.. insurer) Eliminate Risk: Management decides to eliminate risk through the dissolution of a key business unit or operating area Acquire Risk: Management decides that the organization has a core competency managing this risk, and seeks to acquire additional risk of this type. Reduce Risk: Management decides to reduce current risks through improvement in controls and processes Share Risk: Management attempts to share risk through partnerships, outsourcing, or other risk sharing approaches “A DelCreo, inc. Se Risk Management Company

Silos ٠ Silos exist in: - Functions and Business Units: + Corporate and operations + Foreign and domestic - Information Systems and Databases - Processes + Risk management + Strategic planning + Legal * Create processes, systems and tools to reach across silos to provide the “big picture” * Focus corporate risk management resources on what matters the most * Leverage the “silo” expertise through better coordination for complex risks - DelCreo, inc. ‘An Enterprise Risk Management Company

Risk Committees Roles and Responsibilities Provide risk management program leadership, strategy implementation direction Develop risk classification and measurement systems Develop and implement escalation metrics and triggers Develop and monitor early warning systems, based on escalation metrics and triggers Develop and deliver organization wide risk management training Coordinates risk management activities - some functions may report to CRO, while others will be coordinated * Informal Groups * Enterprise Risk Council * Board of Directors - Audit Committee - Risk Committee - DelCreo, inc. ‘An Enterprise Risk Management Company

What is Incident and Crisis Management? Event - An internal or external action or occurrence that may or may not impact the organization's stakeholders, processes, technology, infrastructure, brand or intangible property Incident - An unexpected, negative event involving potential damage to organization’s stakeholders, processes, technology, infrastructure, brand, or Intangible property Crisis - An unexpected, negative event that threatens the lives of stakeholders or could materially impairs the organization and it’s ability to operate 2 DelCreo, inc. ‘An Enterprise Risk Management Company

Example: Objectives of an Incident & Crisis Management Program The incident and crisis management process is designed enhance our interactions with our customers. The following areas will be addressed: -Identify clear roles and responsibilities -Develop a consistent and coordinated approach -Improve communication to all stakeholders and media -Reduce incident reporting, verification and response time -Enable timely and efficient management of incidents -Leverage learnings and ensure process improvement - DelCreo, inc. ‘An Enterprise Risk Management Company

Risk, Incident and Crisis
Monitor & resolve the "critical few" with the crisis management team
Monitor & resolve quickly at most appropriate level using existing structure and processes
Risk Management and Business Controls
Assess potential impact of events and implement appropriate risk management & business controls

RISKWeb welcome
Financial Resources
Knowledge Base - Learn more about RISKWeb and Risk at HP
Knowledge Base - an at your fingertips library of risk management tools, resources, policies, guidelines and leading practices. Use it to identify, evaluate and manage risks for your specific business model, process, geography or function.
RISKWeb Forums - Collaborate in real time, Share best practices, Pool ideas and resources
Register - Register now and get a handsome leather HP card case as a Thank You

RiskWeb: Knowledge Base
Home - Knowledge Base
Define your business situation by drilling down through the index below. Discover results that are relevant to your unique business situation!
Business Model
Business Process/Activity
Risk Type
Incident management
RISK Web Forums
Business Process/Activity
Markets and customers
Product
Regulatory/Legislative
Design Products and Services
Security
Supply chain

RiskWeb: Resource Center
Things happen - natural disasters, theft, security breaches, etc. Find the information and resources that can help you prepare and respond to incidents.
Explore RISKWeb's Resource Center. These people have the experience and expertise to help you identify, evaluate and manage the risks you are likely to face. Use them.
Start by selecting a risk type, business model or process. HP people with expertise in the area you select will be drawn from the RiskWeb database.
Resource Database
Discover the breadth of HP people available to help you manage risks so you can move more confidently toward reaching your business objectives:
List of HP RiskWeb Sponsors, Business Models Served, Risk Types Addressed
Brand
Customer Facing Business-Channels
Business Partners
Customer Facing: Business-Direct-Corporate
Customer Facing: Business-Direct-Large Customer
Home - Resources
Risk at HP
RISKWeb Forums
Register

RiskWeb: Discussion Forums
RiskWeb Forums - real time collaboration
Collaborate in real time, Share best practices, Pool ideas and encourage a RISKWeb Forum if they are needed.
Register with RISKWeb Forums. Here, you can:
- Join a moderated risk-related discussion
- Post a question and get answers from other Forum members
- Submit documents that you want to share
- Get alerts when there is new information on topics you select
- Create a community around a specific topic and share files
- Find others who share similar risk management challenges
- Test ideas among colleagues
Forums Search
There are currently 0 members logged in
Today's Active Topics
General Risk Management discussion area

ERM

