Building a Cyber Risk Management Program by Brian Allen
Author:Brian Allen
Language: eng
Format: epub
Publisher: O'Reilly Media
Published: 2023-12-11T00:00:00+00:00
When Multiple Risks Combine to Become a Material Risk
Beginning in late 2016, Wells Fargo, one of the largest and most important US-based financial institutions, was caught up in a huge scandal involving the creation of millions of fraudulent bank accounts for clients without their consent. Representatives of Wells Fargoâs US banking operation added new accounts to clientsâ existing onesâcreating credit card accounts for clients who had only checking or savings accountsâwithout their consent or even their knowledge, with the result that these customers incurred additional fees and charges.
Regulatory agencies, including the US. Consumer Financial Protection Bureau (CFPB), fined Wells Fargo a total of $185 million for what it clearly established was widespread fraud. Lawsuitsâmany of them still ongoingârequested damages of almost $3 billion. The bankâs CEO was forced to resign, and the company suffered severe reputational damage that continues to this day.
The Wells Fargo scandal is an excellent example of what we mean when we say that risks become material in the aggregate. The creation of each of the fraudulent accounts represented only a comparatively minor infraction. (To be clear, each was still almost certainly a criminal fraud, but its cost to each individual client was, in most cases, fairly small.) If the practice had, for example, been limited to a single bank branch, or even a single operating region, it would likely not have represented a materially relevant riskâthat is, it would likely not have needed to be disclosed to the SEC and other regulators. But the investigations into the case clearly established that the fraud was far-reaching and resulted from intense corporate pressure for branch representatives to engage in a practice called âcross-selling.â Investigations also established that Wells Fargoâs most senior management knew or should have known that widespread fraud was taking place. That made all those small fraudulent transactions âmaterial in the aggregateâ and therefore subject to the disclosure rules of the SEC and other regulatory bodies. This also turned a series of small issues into a massive problem thatâs still causing Wells Fargo, and of course its shareholders, serious damage.
Hereâs an example of how this would work in relation to cyber incidents: a series of several small breachesâthe digital equivalent of all those small fraudsâcould be material in aggregate. That could obviously be relevant to an investor whoâs considering buying or selling shares in the enterpriseâand thatâs what potentially makes it a material incident. The SEC specifically made mention in its latest cyber rule stating that the definition of a âcybersecurity incidentâ would extend to a âseries of related unauthorized occurrences.â Examples include the same malicious actor engaging in a number of smaller but continuous cyberattacks related in time and form, or a series of related attacks from multiple actors exploiting the same vulnerability and collectively impeding the companyâs business materiality.
Download
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.
Computer Vision & Pattern Recognition | Expert Systems |
Intelligence & Semantics | Machine Theory |
Natural Language Processing | Neural Networks |
Algorithms of the Intelligent Web by Haralambos Marmanis;Dmitry Babenko(8258)
Test-Driven Development with Java by Alan Mellor(6387)
Data Augmentation with Python by Duc Haba(6285)
Principles of Data Fabric by Sonia Mezzetta(6062)
Hadoop in Practice by Alex Holmes(5938)
Learn Blender Simulations the Right Way by Stephen Pearson(5922)
Microservices with Spring Boot 3 and Spring Cloud by Magnus Larsson(5810)
Jquery UI in Action : Master the concepts Of Jquery UI: A Step By Step Approach by ANMOL GOYAL(5783)
RPA Solution Architect's Handbook by Sachin Sahgal(5207)
Big Data Analysis with Python by Ivan Marin(5175)
Life 3.0: Being Human in the Age of Artificial Intelligence by Tegmark Max(5102)
The Infinite Retina by Robert Scoble Irena Cronin(4896)
Pretrain Vision and Large Language Models in Python by Emily Webber(4153)
Functional Programming in JavaScript by Mantyla Dan(4018)
The Age of Surveillance Capitalism by Shoshana Zuboff(3914)
Infrastructure as Code for Beginners by Russ McKendrick(3910)
WordPress Plugin Development Cookbook by Yannick Lefebvre(3614)
Embracing Microservices Design by Ovais Mehboob Ahmed Khan Nabil Siddiqui and Timothy Oleson(3425)
Applied Machine Learning for Healthcare and Life Sciences Using AWS by Ujjwal Ratan(3400)
