Top Banner
Enterprise Risk Management for Community Banks Brian T. O’Hara CISA, CISM, CRISC, CISSP CISO The Mako Group, LLC [email protected] http://www.linkedin.com/in/brianohara / Twitter: @brian_t_ohara
30

Michigan Bankers Association Best 2014 enterprise risk management ppt

Jan 25, 2017

Download

Technology

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Michigan Bankers Association Best 2014 enterprise risk management ppt

Enterprise Risk Management forCommunity Banks

Brian T. O’Hara CISA, CISM, CRISC, CISSPCISO The Mako Group, LLC

[email protected]://www.linkedin.com/in/brianohara/

Twitter: @brian_t_ohara

Page 2: Michigan Bankers Association Best 2014 enterprise risk management ppt

The Mako Group, LLC

• IT & Info Sec Auditing• IT Risk Assessments• Security Training• Vulnerability

Assessments• Social Engineering• PCI DSS 3

• FISMA Audits• Penetration Testing• Gap Assessments• SOC 1 and SOC 2• SOX 404• HIPAA• Virtual CISO

Page 3: Michigan Bankers Association Best 2014 enterprise risk management ppt

The Mako Group, LLC• 1570 Woodward Ave.

Detroit, MI 48266Phone: 313.355.0538 Email: [email protected]

• 110 West Berry Street - Suite 2400 Fort Wayne, IN 46802 Phone: 260.267.5999 Email: [email protected]

• 8555 River Road - Suite 315 Indianapolis, IN 46240 Phone: 317.941.MAKO (6256)Email: [email protected]

Page 4: Michigan Bankers Association Best 2014 enterprise risk management ppt

BIO

• CISO of The Mako Group, LLC• ISSA Fellow• Program Chair, CINT Ivy Tech NE• Adjunct Faculty Indiana Tech• CISSP - Certified Info Systems Security Prof.• CISA - Certified Information Systems Auditor • CISM - Certified Information Security Manager• CRISC - Certified Risk Info System Controls

Page 5: Michigan Bankers Association Best 2014 enterprise risk management ppt

BIO

• CAE of The Mako Group, LLC• CPA• MSA – Masters of Accountancy• ISACA Detroit Chapter• CISA - Certified Information Systems Auditor • Previously ran the Sarbanes-Oxley and FDICIA

programs for Ally Bank

Page 6: Michigan Bankers Association Best 2014 enterprise risk management ppt

What Is ERM?

• Enterprise Risk Management (“ERM”) is a strategic business discipline that supports the achievement of an organization’s objectives by addressing the full spectrum of its risks and managing the combined impact of those risks as an interrelated risk portfolio. (http://www.rims.org/erm/pages/WhatisERM.aspx)

Page 7: Michigan Bankers Association Best 2014 enterprise risk management ppt

ERM Elements?

• Tied to Bank’s Strategic Plan• Chief Risk Officer (Top Down Approach)• Correlations (non-silo)• Target Objectives• Measurable• Focus on Outcomes

Page 8: Michigan Bankers Association Best 2014 enterprise risk management ppt

ERM Principles

• Not just about Risk Mitigation– It is a management system

• Management Model that leads to action• Unified Approach• Answers Key Questions

Page 9: Michigan Bankers Association Best 2014 enterprise risk management ppt

Quiz 1

• Who Invented the World Wide Web?

• Tim Berners-Lee

Page 10: Michigan Bankers Association Best 2014 enterprise risk management ppt

ERM Key Questions

• Do we understand risk across the enterprise?• What is the reward?• Is the risk acceptable?• Is the reward great enough?• Does it link strategies?• Is it supported from the top down?• Are discussions made with input to business as

opposed to protecting lines of business?

Page 11: Michigan Bankers Association Best 2014 enterprise risk management ppt

Who Is ERM Designed For?

• Community Banks?• Size?• Complexity?• Affordability?• Value Add?

Page 12: Michigan Bankers Association Best 2014 enterprise risk management ppt

Examples

• Larger Banks• Publicly Traded Companies (SOX)• Service Providers (CORE)

Page 13: Michigan Bankers Association Best 2014 enterprise risk management ppt

ERM Value?

• Provides a more robust picture of risk• Corrects Silo Risk Mentality• Provides Greater Transparency• Delivers Effective Resource Allocation• Shifts Focus from Reactive to Proactive• Examiner Expectations

Page 14: Michigan Bankers Association Best 2014 enterprise risk management ppt

Sound ERM

• IT Risks Rolled Up• NO Risk Silos• Integrated with Business Strategy• Provides More Accurate Picture of Tolerance• More Effective Resource Allocation• Proactive v Reactive• Helps Identify Key Controls

Page 15: Michigan Bankers Association Best 2014 enterprise risk management ppt

Poor ERM

• Risk Silos• Poor View of Overall Risks• Reactive rather than Proactive• Examples– Target– TJ Max– Heartland Payment Processors

Page 16: Michigan Bankers Association Best 2014 enterprise risk management ppt

Quiz 2

• What was the first commercial web browser?

Page 17: Michigan Bankers Association Best 2014 enterprise risk management ppt

ERM Frameworks?

• COSO• RIMS• ISO• COBIT

• FFIEC Guidance• Johnson and Johnson• NIST

Page 18: Michigan Bankers Association Best 2014 enterprise risk management ppt

Risk Management Frameworks?

• CyberSecurity (Exec Order 13636)• NIST• COBIT• COSO• ISO• FFIEC Guidance

Page 19: Michigan Bankers Association Best 2014 enterprise risk management ppt

Communicating ERM Across Enterprise

• Quantitative v & Qualitative• $ to Risk to Exposure• Opportunities

Page 20: Michigan Bankers Association Best 2014 enterprise risk management ppt

How To Implement ERM

• Pick a framework• Get top management buy in• Establish Enterprise stakeholders

Page 21: Michigan Bankers Association Best 2014 enterprise risk management ppt

How to Discuss with Sr. Mgmt

• Cost• Risk• Opportunity

Page 22: Michigan Bankers Association Best 2014 enterprise risk management ppt

How to Explain

• Quantitative v Qualitative Information

Page 23: Michigan Bankers Association Best 2014 enterprise risk management ppt

Quiz 3

• Who sent the first official “email” over the internet?

• Mark Tomlinson

Page 24: Michigan Bankers Association Best 2014 enterprise risk management ppt

When is ERM not a good fit?

• Lack of Sr. Management Buy in• Size and complexity of operations• Too expensive, cost v benefit

Page 25: Michigan Bankers Association Best 2014 enterprise risk management ppt

ERM Problems

• Lack of single unifying framework• Remains reactive• Discounts insiders (relies on “experts”)• Does not calculate mitigation costs• Fails to rank risk• Lack of academic studies showing

effectiveness

Page 26: Michigan Bankers Association Best 2014 enterprise risk management ppt

Cybersecurity Framework

• NIST Creation• Fits smaller community banks• Easily tailored and scalable• Encompasses ERM key components• Provides control mappings to standards• Above and beyond examiner expectations• Affordable implementations

Page 27: Michigan Bankers Association Best 2014 enterprise risk management ppt

The Mako Group’s Approach (Hybrid)

• Guided (organization is the expert)• Holistic• Eclectic• Customized based on organization needs• Based on value added• Built to optimize resource allocation

Page 28: Michigan Bankers Association Best 2014 enterprise risk management ppt

Conclusions

• ERM is not always a good fit• Can be costly• Can add unforeseen visibility• Can add predictive value• Can still provide guiding principles

Page 29: Michigan Bankers Association Best 2014 enterprise risk management ppt

Summary

• ERM value still unclear• ERM is a holistic approach• More Complex• More about choosing pieces that work for you• Hybrid approaches using models like

Cybersecurity Framework provides best of both worlds

Page 30: Michigan Bankers Association Best 2014 enterprise risk management ppt

THANKSBrian T. O’Hara CISA, CISM, CRISC, CISSP

CISO The Mako Group, [email protected]

http://www.linkedin.com/in/brianohara/Twitter: @brian_t_ohara