Wednesday, September 9, 2009

Lessons from Lehman: too big banks may fail

The warning was ominous: ''Massive global wealth destruction.''

That's what Lehman Brothers Holdings executives predicted in a confidential memo prepared for government officials before they filed the biggest bankruptcy in US history.

The message didn't get through. Two dozen of the world's most powerful bankers, brought together by Treasury Secretary Henry M. Paulson Jr. and Federal Reserve Bank of New York President Timothy F. Geithner the weekend of Sept. 13, 2008, to devise a rescue plan for Lehman, were too busy saving themselves to see the larger threat.

''The discussion among the CEOs was `How do we prevent the next firm from going under?''' former Merrill Lynch & Co. Chief Executive Officer John A. Thain, who cut a deal to sell his company that weekend, said in an interview. ''There should have been much more discussion about the impact directly on the markets if Lehman went bankrupt.''

Of all the quakes of 2008 - the fall of Bear Stearns in March, the takeover of mortgage buyers Fannie Mae and Freddie Mac and the salvaging of American International Group in September - the failure to account for the effects of Lehman's demise was the most critical because its aftershocks came closest to wrecking the world economy.

The financial chieftains spent the weekend unwinding derivatives trades - bets made on whether companies will pay their debts - and trying to keep bank-to-bank loans flowing. They ignored the market for commercial paper, short-term loans used by businesses worldwide to cover everyday expenses, including payroll and utilities.

Lehman's downfall on Monday, Sept. 15, sparked a run on the $US3.6 trillion ($4.2 trillion) money market industry, which provides those loans. The panic left companies stranded with insufficient cash and ravaged the accounts of millions of people.

Within a week, the US stepped in with a $US1.6 trillion program to halt withdrawals from money market funds, part of $US13.2 trillion it has committed to beating back the worst financial crisis since the Great Depression.

''They put the entire financial system at risk, and they didn't have to,'' said Harvey R. Miller, a partner at Weil Gotshal & Manges in New York who represented Lehman in the bankruptcy, referring to government officials. ''They were warned. I told them, 'Armageddon is coming. You don't know what the consequences will be.' Their response was, 'We have it covered.'''

Paulson and Geithner, who succeeded him as Treasury secretary, both declined to comment.

Lesson left unlearnt

One year later, policy makers haven't learned the lesson of the bankruptcy, said Richard Bernstein, CEO of Richard Bernstein Capital Management LLC in New York and former chief investment strategist for Merrill Lynch.

Rather than break up institutions such as Bank of America and Citigroup, or limit their expansion, the US has given them billions of dollars in tax incentives and loan guarantees that enabled them to grow even bigger. To protect against a bank collapse touching off another freefall, President Barack Obama has proposed regulatory changes that rely on the wisdom of bankers and government overseers - the same people who created the conditions that led to Lehman's bankruptcy and were unable to foresee its consequences.

''Designating certain institutions as too big to fail, and not having a thorough regulatory process to match, practically invites another catastrophe,'' Bernstein said.

Rescue efforts exposed a financial system with so many moving parts that US regulators and the world's top bankers couldn't keep track of them all. Like the fictitious substance ice-nine in Kurt Vonnegut Jr.'s 1963 novel ''Cat's Cradle,'' a seed of which set off a chain reaction that transformed all the world's water into ice, Lehman's failure froze credit markets.

''I remember at the end of the week calling up my wife and saying, 'Jamie, go to the ATM, go to the cash machine, and take cash out,''' Mohamed El-Erian, CEO of Pacific Investment Management, the world's largest bond-fund manager, said. ''She said, 'Why?' I said, 'I don't know whether the banks are going to open tomorrow.' The system was freezing in front of our eyes.''

As with other financial institutions, Lehman's problems stemmed from borrowing too much to finance too many hard-to-sell investments, such as mortgage-backed securities, that were declining in value as a result of the deteriorating real estate market. Lehman was different because the government let it declare bankruptcy, meaning the company's creditors were wiped out as well as its stockholders.

The ensuing panic doomed the oldest US money market fund, the $US62.5 billion Reserve Primary Fund, started in 1971 by Bruce R. Bent. Reserve Primary had lent Lehman $US785 million, about 1.3 per cent of its assets, some of it in short-term loans that Lehman was now unable to repay. In a two-day run on the fund, more than 60 per cent of its money was withdrawn. Its net asset value fell below $US1 a share, or ''broke the buck,'' on Sept. 16, making investors vulnerable to losses and triggering withdrawals at other funds.

Trillions wiped out

The run on money market funds, considered the safest investments after bank deposits and the major buyers of commercial paper, sent shivers through the global economy. World stock markets lost $US2.85 trillion, or more than 6 per cent of their value, in three days.

''We did not expect how the Lehman Brothers bankruptcy would transmit through the commercial-paper market and cause all the stress in the money funds,'' said David Nason, a former assistant Treasury secretary under Paulson.

The oversight may have had something to do with who was at the meetings, said Joshua H. Rosner, managing director at New York investment research company Graham Fisher & Co. They were all bankers.

''It wasn't a mistake to let Lehman fail; it was a mistake to let them go without putting foam on the tarmac,'' Rosner said. ''If they had a variety of stakeholders in the room, those stakeholders would've told the regulators they needed to do something about commercial paper.''

Source: Sydney Morning Herald

Friday, September 4, 2009

Back in the Saddle

Risk Professionals Lost Credibility When Their Flawed Decisioning Models Led Banks Straight Down a Hole. Now They Are Examining More of the Variables, and the "Whys" Behind the same.

When SAS chief marketing officer Jim Davis told a roomful of executives in Washington last spring that he "doesn't believe business intelligence is where the future is," it went off like a little bomb in the close-knit circles of financial technology.

Not that Davis seemed to be forsaking SAS' bread-and-butter business intelligence software empire, but because he put his finger on a much broader issue: the blind adherence to enterprise data. The predictive modeling, automated credit decisioning, risk management and business decisions made with confidence behind BI-bred numbers had proved to be a disastrously unreliable guide through the storm of a financial meltdown, and there are ramifications to come for institutions' books.

What is needed, he and others believe, is a new discipline that more closely examines the raw numbers relating to customer and market activity. By adding more variables that ask "what if" instead of just "what happened," bankers and traders are looking for next-generation, deeper-diving metrics that will hopefully erase the blind spots in current data-based decisioning, and prevent future catastrophe. Thomas Davenport, author of "Competing on Analytics," management professor and former Accenture fellow, said he was once told by a former Washington Mutual chief risk officer "if they had had better model management systems, they would have seen they were producing more charge-offs in 2006 than predicted, and they could have changed their practices more rapidly."

It's a science that is still developing, but Davis is positioning SAS toward what he calls business analytics and away from the plain-vanilla query and reporting of business intelligence. SAS isn't alone: IBM just took the wraps off its "Smart Analytics System," on sale in its new Business Analytics and Optimization Services practice, and is supported by a 4,000 consultants, 200 mathematicians and a global network of analytic solution centers. One of the first customers is Sterling Savings Bank in Spokane, Wash.

This business analytics trend is an answer to more than just what's next, but also about getting more out of the data-tools investments previously made for BI-based automated decisioning and predictive modeling. It seems a more acceptable alternative to the radical solutions from those proposed by financial scholar Nassim Taleb, author of "The Black Swan," who feels the answer to bad financial modeling is to simply burn the drawing board. "Numbers don't make you risk-averse. They make you less risk-averse. The answer is to ban these products," he told NPR's Planet Money. "Anything that relies on mathematics for its survival, anything that relies on mathematical models should disappear. Because we know nothing about these probabilities, and the past is no indication of the future."

London tech consultant and mathematician Peter Thomas say that, by Taleb's logic, we should stop decision-making altogether, because all decisions are made using information from the past. Harvard economist Edward Glaeser adds: What else is there?

As much false confidence may come from reams of numbers, there won't be a wholesale abandonment of modeling anytime soon. If anything, banks look like they are doubling down on data. A recent small-scale survey from consultancy Aleri shows 70 percent of banks and brokerages think their firms needs to manage risk in real time-and invest in more data-crunching tools in order to do it.

Bank of America, for example, is looking for someone in Hong Kong to run business analytics in its Merrill Lynch unit, using Dealogic and other research tools to "data mine" banking deals within the region, ensure data integrity with an emphasis on thoroughness of sources and variables, and develop models to "create new views of the business that allow improved study of impacts in the market."

The new parameters on what those models might include are still in development, but top Merill executives lately on the rubber-chicken circuit are dropping clues. New BofA-Merrill Asia president Kim Hong recently said the firm is adding people in investment banking and key research posts across the region in a bid to exploit "inter-regional," cross-border plays for M&A clients, connecting those clients to financing, and trying to steer clients to multiple desks - the old integrated bank idea, at a time when many bank-watchers are advising a back-to-basics approach. Merrill tech and risk exec Jay Morealle told an IDC forum that he expects business intelligence to be about analysis, not reporting; it needs to be fast, intuitive and assist decision-making. Data should flow from a base of power users, not from IT, and publish back into broader systems so information can be widely shared.

On the retail banking side, the $140 billion-asset BB&T Corp. is revamping its ongoing use of SAS risk management software, working closely with SAS partner The Financial Risk Group. BB&T risk manager Mike Stevens is also trying to work more flexibility into modeling. For example, if the "affordability index" of housing prices and personal income is distorted, a correction must be taken account into the lending process, he told an SAS panel. Rather than just predicting a bad loan workout three years in the future with higher asset values, he said, you also build an assumption that asset prices could very well be lower, and the loan-to-value ratio is therefore much higher than expected. "I may then be in a negative equity position and taking a significant loss on this bad loan," he says.

There are questions whether business analytics is just a new mine for fool's gold. Neil Raden of Hired Brains thinks analytics-versus-intelligence is "all fluff." Yet others might just say that underlying assumptions, automated credit scoring and rules engines based on things like FICO scores should now reside in a big smoking hole in the ground, along with the huge marketplace of unpriceable securities built on top of them.

Michael Stefanick, SAS's global head of risk practice, believes the answer is increasing the data going into the models, and increasing the velocity of optimization - the updates of the data points. "Lenders have realized the limitations of FICO and are now basing models on a larger set of risk factors," he says. "This is where you find a more accurate view of how a customer will manage credit, and go beyond a credit snapshot."

There's a paradox pointed out by Eric Lindeen, marketing director for Zoot Enterprises of Bozeman, Mont. He points out regulatory changes and tightening of risk-based capital ratios are going to drive data-handling practices anyway. "Figuring how to do risk-based pricing up-front at a granular level is going to take a lot of system flexibility," he says. "Institutions will need to run models much more frequently and in many more situations." At the same time, he calls for simpler models with a greater degree of flexibility - conceding that complex models in a dynamic market just proved to have "virtually no predictability." The question then becomes, how to do that while making them real-time and increasing the number of risk factors?

Azhar Iqbal, an econometrician at Wells Fargo Securities in Charlotte, still mourns over a model he built in the summer of 2007 while at Wachovia that tracked U.S. light car sales. "For four or five months, we nailed it," he says. After that? "We couldn't identify why our model was totally failing." It was because the credit markets were freezing. "All my other indicators supported one thing, that retail sales should go up. But nobody was lending, so sales went down." He's still tinkering with light vehicles, looking for new variables, for an optimized proxy for credit availability as well as the propensity for its use: perhaps something like the TED (Treasuries/Eurodollars) spread. Iqbal is hunting for variables "outside the cycle," and coming up with interesting findings on the way: he and Wells Fargo senior economist Mark Vitner published a paper showing delinquency rates for consumer loans are driven more rapidly by factors other than unemployment. In other words, delinquency rates for different products, say credit cards and mortgage payments, are driven by different forces.

Wells Fargo Securities now keeps an ongoing record of every one of its operating models. If one misses three consecutive directions, it's taken off-line and evaluated - an example of model management that Davenport said was lacking at Wachovia before its demise. "Econometric theory is being re-evaluated. The lesson is, many theories broke," Davenport says. "And when that happens, you need to modify."

Source : Global Association of Risk Professionals

Thursday, September 3, 2009

Mortgage Fraud: Where's the Fix?

Mortgage Fraud: Where's the Fix?
By Peter Goldmann

In 2004, the FBI warned that mortgage fraud was growing so rapidly it could become "the next S&L crisis."

In 2005, The Bureau reported that mortgage fraud suspicious activity reports (SARs) more than doubled from 6,936 in 2003 to 17,127 in 2004.

Fast-forward to mid-2009. The FBI reported that the number of mortgage fraud SARs filed in fiscal year 2008 was 63,173, with more than $1.5 billion in losses. Through April 30, 2009, the total was already 40,901. It is true that SARs reported by the FBI reflect suspicious financial activity that occurred two to three years earlier. But industry experts say that the upward trend in SARs is set to continue for years to come, suggesting that mortgage fraud is getting worse, not better. And other, more up-to-date statistics bear this out.

According to a March 2009 report by the Mortgage Asset Research Institute (MARI), a unit of Lexis-Nexis, "fraud incidence is at an all-time high and is comprised of continuing application misrepresentations and multiple verification-oriented issues. Fewer loan originations coupled with increased fraud incidence equals new times of desperation. Industry expertise and technological advancements, when mixed with desperate people and opportunities, are catalysts for the continuation and growth of fraud."

In other words, desperate people are filing more fraudulent mortgage applications and this, coupled with industry expertise on the part of presumably dishonest mortgage brokers, appraisers and others and new technologies has created a whole new set of forces fueling a new post-meltdown boom in mortgage fraud.

What's wrong with this picture?
What is incredibly difficult to understand is why legitimate, federally insured banks that processed bad loans by the boatload in the years of the real estate bubble apparently haven't learned the tricks of the fraudsters' trade and found ways to protect themselves against these scams.

Have they not heard the age-old idiom, "Fool me once, shame on you; fool me twice, shame on me?"

In 2004 you could almost understand why banks would be victims of mortgage scammers. Before 2002, there were plenty of cases of mortgage fraud that the FBI investigated, but it was a small fraction of the number in 2008. In 2003 and 2004, the number grew, but it was still small compared to 2007 and 2008. So, maybe banks weren't prepared for the onslaught of various types of fraud involving bogus applications (such as so-called "liar’s loans"), phony appraisals, use of straw buyers to generate illegal sales among others. But between then and now, there was a little thing called the subprime mortgage meltdown which played rather more than a bit part in the drama of the financial system collapse in 2007-2008.

During the subprime mortgage period of 2004-2008 the FBI reported that the number of mortgage fraud incidents being investigated was skyrocketing. This was no doubt a product of the housing boom which fueled a feeding frenzy by dishonest and unregulated mortgage brokers, appraisers and non-bank lenders, with some help from corrupt attorneys and unscrupulous borrowers. Once Wall Street got into the act by vacuuming up every subprime mortgage they could use as collateral for securities they could sell off to big investors, the upward spiral in housing prices shifted into overdrive.

Unfortunately, along the way, a number of these players lost site of their moral compasses and the FBI's 2004 prediction about mortgage fraud became a terrifying reality.

So today, having been burned by mortgage scammers to the tune of untold billions of dollars, the "excuse" that banks don't know what to look for in the way of red flags of mortgage fraud no longer flies -- not even close. Yet mortgage fraud is getting worse.

The reason for this mind-boggling continuation of bad business as usual is probably unknowable. One banking fraud prevention manager rather bluntly sums up the problem this way: "Banks have done little to improve the control environment. The entire industry is consumed with conservatism." An executive hired by Goldman Sachs during the subprime heyday to conduct due diligence on mortgages being collateralized says that mortgage fraud is still being perpetrated in the same way it has been for the past 10 years or more. Lenders too greedy to enforce responsible lending standards are looking the other way when brokers bring them fraudulent mortgage applicants. And their incentive to scrutinize the applications is further diminished by the fact that they plan on selling off the loans anyway to the secondary market.

Whatever is still enabling mortgage fraudsters to victimize borrowers and legitimate lenders needs to be fixed -- if not by the banks themselves, then by the government. Why should investors continue to suffer at the hands of incompetent (or corrupt) mortgage lenders who after the biggest mortgage meltdown in U.S. history continue to process fraudulent loans and to eat major losses when they go bad?

The Control Issue
If we wait for Washington to generate new regulations from among the myriad proposals now sitting in various committees, the losses will continue to mount and the fraudsters will continue to make off with honest peoples' money.

So, that leaves the banking industry to its own devices. Which is what it wanted in the first place. After years of pressuring Washington to loosen regulations, now they find themselves in a position where some form of regulation is unavoidable if they are to deter crooked mortgage brokers, appraisers and non-bank lenders from continuing to rip them off.

According to MARI, "to combat fraud, the (banking) industry must pay attention to details. Mortgage bankers must act with a sense of constant vigilance to protect their pipelines from becoming tainted with preventable fraud risk by leveraging smarter technologies and acquiring more relevant information about their customers, employees and vendors. Community bankers, steadily growing their own mortgage pipelines, are learning from the mistakes of others that they must do the same. The rules have changed and the stakes have been raised. The burden of responsibility rests with the industry if it is to sustain itself and prevent further losses due to reasons other than the rise of delinquencies and foreclosures and recession-related jobless claims."

Though somewhat of an understatement, there is no clearer way of saying that to get a grip on the scourge of mortgage fraud, the institutions that are suffering the losses need to get cracking on implementing controls to protect themselves. The bad guys are not going away. If anything, as long as they see opportunities to steal in the form of lax mortgage banking controls, they will keep coming back again and again.

If you're a skeptic (like me), you probably aren’t holding your breath that an industry that is "consumed by conservatism," as our bank fraud manager so aptly put it, will ever really put into place the internal controls necessary to reduce fraud.

That means government will be forced to step in. But how? Will we need a mortgage banking variety of Sarbanes-Oxley to force banks to strengthen their anti-fraud controls? Or will simply requiring mortgage brokers and appraisers to be registered with some type of federal oversight body be enough to at least stem the bleeding?

One thing is certain: There is no shortage of controls and regulations that could be implemented and enforced to make it tougher for fraudsters to do their thing. There are five federal banking regulatory bodies and 50 state counterparts. Between them there is a plethora of anti-fraud controls that could and should be implemented. If only a fraction of them were properly implemented, we'd probably see a significant drop in mortgage fraud.

Unfortunately, as has been the case for so long in the financial services arena, this is much easier said than done.

Source: www.acfe.com

World War 3.0: 10 Critical Trends for Cybersecurity

The Internet, private networks, VPNs, and a host of other technologies are quickly weaving the planet into a single, massively complex "infosphere." These connections cannot be severed without overwhelming damage to companies and even economies. Yet, they represent unprecedented vulnerabilities to espionage and covert attack.

"Cybersecurity is the soft underbelly of this country," outgoing U.S. National Intelligence Director Mike McConnell declared in a valedictory address to reporters in mid-January. He rated this problem equal in significance to the potential development of atomic weapons by Iran.

McConnell does not worry so much that hackers or spies will steal classified information from computers owned by government or the military, or by contractors working for them on secret projects. He is afraid they will erase it and thereby deprive the United States of critical data. "It could have a debilitating effect on the country," he said.

With this concern in mind, Forecasting International undertook a study of factors likely to influence the future development of information warfare.

Real-world attacks over the Internet also are possible. In March 2007, the Department of Energy's Idaho National Laboratory conducted an experiment to determine whether a power plant could be compromised by hacking alone. The result was a diesel generator smoking and on fire due to some malicious data that could easily have been sent to it over the Internet from anywhere in the world. In January 2008, a CIA analyst told American utilities that hackers had infiltrated electric companies in several locations outside the United States. In at least one case, they had managed to shut off power to multiple cities.

We conclude that information warfare will be a significant component in most future conflicts. This position is in line with both U.S. military doctrine and white papers published by the Chinese People's Army. One study affirms that as many as 120 governments already are pursuing information warfare programs.

Repeated reports Relevant Products/Services that Chinese computer specialists have hacked into government networks in Germany, the United States, and other countries show that the threat is not limited to relatively unsophisticated lands. A 2007 estimate suggested that hackers sponsored by the Chinese government had downloaded more than 3.5 terabytes of information from NIPRNet, a U.S. government network that handles mostly unclassified material. More disturbingly, The Joint Operating Environment 2008: Challenges and Implications for the Future Joint Force (the JOE) comments that "our adversaries have often taken advantage of computer networks and the power of information technology not only to directly influence the perceptions and will of the United States, its decision-makers, and population, but also to plan and execute savage acts of terrorism."

Many factors guarantee that the role of information warfare in military planning and operations will expand greatly in the next two to three decades. These include the spread of new information technologies such as Internet telephony Relevant Products/Services, wireless broadband, and radio-frequency identification (RFID); the cost and negative publicity of real-world warfare; and the possibility that many information operations can be carried out in secret, allowing successful hackers to stage repeated intrusions into adversaries' computer networks.

10 Critical Trends for Cyberwar

Forecasting International [rates] the following as the 10 most significant trends that will shape the future of information warfare. This ranking is based largely on the responses of our expert panelists, but also on our own judgment, developed over 50 years of trend analysis and extrapolation in military and national-security contexts. In nearly all cases, these two inputs agreed.

1. Technology Increasingly Dominates Both the Economy and Society

New technologies are surpassing the previous state of the art in all fields. Laptop computers and Internet- equipped cell phones provide 24/7 access to e-mail and Web sites.

New materials are bringing stronger, lighter structures that can monitor their own wear. By 2015, artificial intelligence (AI), data mining, and virtual reality will help most organizations to assimilate data and solve problems beyond the range of today's computers. The promise of nanotechnology is just beginning to emerge.

Ultimately, speculations may prove correct that we are approaching the "Singularity's event horizon." At that time, our artifacts will be so intelligent that they can design themselves, and we will not understand how they work. Humanity will be largely a passenger in its own evolution as a technological species.

Implications for Information Warfare and Operations: The growing domination of technology is the ultimate foundation for cyberwar. Complex, often delicate technologies make the world a richer, more-efficient place. However, they also make it relatively fragile, as it becomes difficult to keep industries and support systems functioning when something disrupts computer controls and monitors, and the opportunities for disruption proliferate rapidly.

A frequently overlooked scenario is the use of infotech by organized crime, according to consulting futurist Joseph F. Coates. "It is 2015, and the Mafia electronically wipes out the records of a modest-sized bank in Texas or Nebraska, and then quietly visits a small group of large financial services organizations with a simple message: 'We did it-you could be next. This is what we want, to protect you.'"

Futures-studies scholar Stephen F. Steele notes, "Cyber systems are not simply information, but cyber cultures. Coordinated cyberattacks at multiple levels will be capable of knocking out the macro (national defense systems), meso (local power grids), and micro (starting an automobile) simultaneously."

2. Advanced Communications Technologies Are Changing the Way We Work and Live

Telecommuting is growing rapidly, thanks largely to e-mail and other high-tech forms of communication. However, the millennial generation has already abandoned e-mail for most purposes, preferring to use instant messaging and social-networking Web sites to communicate with their peers. These and other new technologies are building communities nearly as complex and involved as those existing wholly in the real world.

Implications for Information Warfare and Operations: This is one of the two or three critical trends that give information warfare and operations their significance.

As our institutions integrate their operations, their connectivity makes them more vulnerable to unauthorized access. As they redesign their operations to take advantage of the efficiencies that computers offer, they also open them to disruption by technologically sophisticated adversaries.

Disruption may not be overt or easily detected. With manufacturing systems increasingly open to direct input from customers, it might be possible to reprogram computer-controlled machine tools to deliver parts that were subtly out of spec-and to rework the specifications themselves so that the discrepancies would never be noticed. If the tampering were carried out with sufficient imagination and care on well-selected targets, the products might conceivably pass inspection, yet fail in the field. This could have significant military implications.

"The Internet is a mess, open to all kinds of uses, misuses, antisocial material, irksome intrusions from ads, identity theft, international swindles, and on and on," observes Coates. "For these reasons, as well as the potential for national-security interventions and general hell raising, it is time to plan, design, and execute over the next five to seven years a replacement for the Internet."

Infotech and business management consultant Lawrence W. Vogel calls attention to the impacts of cloud Relevant Products/Services computing Relevant Products/Services (third-party data hosting and service-oriented computing) and Web 2.0 applications (social networking and interactivity). "The cybersecurity implications associated with cloud computing, whether a public or private cloud, are significant," he says. "As more companies and the government adopt cloud computing, they become more vulnerable to disruption and cyberattacks. This could result in disruption in services and the ability to rapidly access critical software Relevant Products/Services applications. And with the widespread use of Facebook, blogs, and other social- networking applications in our personal lives, government organizations are seeking similar capabilities for communicating and interacting with their stakeholders. Once the government permits interactive, two-way communications Relevant Products/Services over government networks, the chance for cyberattacks dramatically increases."

3. The Global Economy Is Growing More Integrated

Critical factors here include the rise of multinational corporations, the relaxation of national distinctions (e.g., within the European Union), the growth of the Internet, and computerized outsourcing of jobs to low-wage countries.

Implications for Information Warfare and Operations: The Internet, private networks, virtual private networks, and a host of other technologies are quickly weaving the planet into a single, massively complex "infosphere." These nearly infinite connections cannot be severed without overwhelming damage to companies and even to national economies. Yet, they represent unprecedented vulnerabilities to espionage and covert attack. This is another major trend for information warfare and operations.

"Another thing to think about here [is that] the sheer volume of information racing through the 'infosphere' enhances the opportunity for cyberwar operators to embed encrypted information within routine data flows," says law enforcement strategic planner John Kapinos. "This could take the form of system-disabling viruses, or secret message traffic concealed within an ocean of regularly transmitted, legitimate data. Sophisticated data-monitoring programs designed to detect unusual patterns would be needed to counteract such a scheme."

Futurologist Ian D. Pearson adds that, as interactions become more complex, "it will be harder to spot points of vulnerability. Fraud and cyberterrorism will increase."

The actors in cyberwarfare now include non-state entities, points out strategic-planning consultant Frank Sowa of the Xavier Group Ltd. "Corporations in the twenty-first century are borderless and are not geopolitical," he argues. "The key to actively thwarting cyberwarfare is to recognize corporations and organized religions on the same-or even higher protocol-than geopolitical governments and borderless, non-geopolitical terror and extremist operations."

4. Research and Development Play a Growing Role in the World Economy

Total U.S. outlays on R&D have grown steadily in the past three decades. Similar trends are seen in China, Japan, the European Union, and Russia.

Implications for Information Warfare and Operations: This trend is responsible for the accelerating technological advances seen in recent decades. It is another critical factor in the development of information warfare.

The chief product of R&D is not clever new merchandise or technologies, but information. Even the most sensitive output from research results is routinely stored in computers, shipped through company intranets, and usually transmitted over the Internet. This accessibility makes it a prime target for espionage, whether industrial or military. This problem has been growing nearly as quickly as the mass of information available to prying. It will be a still greater concern for security specialists in the years ahead.

Many R&D programs promote the dissemination of research results, observes public-policy specialist Mark Callanan of the Institute for Public Administration in Dublin. "While this is of course entirely sensible for the vast majority of research, the emphasis on getting as much information out there [as possible] may pose additional security dilemmas in terms of cybercrime," he argues.

Pearson adds that "the downside is that R&D also occurs in weapons tech, so there is always a background arms race. High-capability technologies will present enormous threats to mankind in the second half of this century."

5. The Pace of Technological Change Accelerates with Each New Generation of Discoveries and Applications

In fast-moving engineering disciplines, half of the cutting-edge knowledge learned by college students in their freshman year is obsolete by the time they graduate. The design and marketing cycle-idea, invention, innovation Relevant Products/Services, imitation-is shrinking steadily. As late as the 1940s, the product cycle stretched to 30 or 40 years. Today, it seldom lasts 30 or 40 weeks.

The reason is simple: Some 80% of the scientists, engineers, technicians, and physicians who ever lived are alive today-and exchanging ideas in real time on the Internet.

Implications for Information Warfare and Operations: As new technologies arrive, industry will be forced to hire more technology specialists and to train other employees to cope with new demands. Some support functions may be moved offshore, where technically knowledgeable adversaries might have greater access to them, opening the way to disruption.

"It is important in the discussion not to neglect the large amount of information technology now obsolescent or obsolete, but [still] in place," observes Joe Coates.

The advance of machine intelligence will also have confounding implications for cybersecurity. According to knowledge theorist and futurist Bruce LaDuke, "Knowledge creation is a repeatable process that is performed by humans and could be performed by machines exclusively or in systems built to interact with humans ('man-in the-loop' systems). Artificial knowledge creation will usher in [the] Singularity, not artificial intelligence or artificial general intelligence (or technology advancing itself). Artificial intelligence has already been achieved by any computer, because intelligence is appropriately defined as knowledge stored that can be retrieved (by human or computer). The first arriver to [artificial knowledge creation] technology will drive the entire paradigm shift."

6. The United States Is Ceding Its Scientific and Technical Leadership to Other Countries

In June 2009, a U.S. National Security Agency-backed "hacking" competition pitted 4,200 programmers from all over the world in algorithm coding and other contests; of the finalists, 20 were from China, 10 were from Russia, and only two were from the United States, reports Computerworld. "We do the same thing with athletics here that they do with mathematics and science there," says Rob Hughes, president of TopCoder, the software development company that operates the annual competition. Hughes argues that the United States needs to put more emphasis-and earlier-on math and science education.

"The scientific and technical building blocks of our economic leadership are eroding at a time when many other nations are gathering strength," the National Academy of Sciences warns. "Although many people assume that the United States will always be a world leader in science and technology, this may not continue to be the case inasmuch as great minds and ideas exist throughout the world."

R&D spending is growing in raw-dollar terms, but, when measured as a percentage of the total federal budget or as a fraction of the U.S. GDP, research funding has been shrinking for the last 15 years. Only half of U.S. patents are granted to Americans, a proportion that has been declining for decades.

More than half of U.S. scientists and engineers are nearing retirement. At the rate that U.S. students are entering these fields, the retirees cannot be replaced except by recruiting foreign scientists.

Implications for Information Warfare and Operations:

To whatever extent the United States loses its leadership in science and technology, it falls behind other countries in the intellectual and personnel base required for information warfare and operations. If this trend is not reversed, the United States could find itself at a significant disadvantage in this strategically and tactically important area.

"The strength of the United States is in knowledge creation under the auspices of innovation and invention that has been applied in all kinds of technologies," argues LaDuke. "Ceding existing technology as technology converges and rises exponentially is not as significant as not creating the knowledge that is empowering future advances in technology."

Pearson adds, "The increased power of smart individuals is more of a problem, especially in NBIC [nanotech, biotech, infotech, and cognitive science] areas. Unabomberstyle activity from inconspicuous people within a community is more of a danger than hostile states or terrorist groups."

Steele warns that, "not only is the United States ceding the 'left brain' sciences, but the continuation of a linear, industrial model for education has [it] ceding a growing need for 'right brain'-creative and synergistic -- thinking."

7. Technology Is Creating a Knowledge-Dependent Global Society

More and more businesses-and entire industries-are based on the production and exchange of information and ideas rather than exclusively on manufactured goods or other tangible products. At the same time, manufacturers and sellers of physical products are able to capture and analyze much more information about buyers' needs and preferences, making the selling process more efficient and effective.

Implications for Information Warfare and Operations: Increasing dependence on technology effectively translates to growing fragility. Disrupt essential information or communications systems, and a company, government agency, or military unit could be dead in the water, or at least cut off from oversight and coordination with its partners. Telecommuting systems, for example, offer several obvious opportunities to disrupt the operations of the company or agency that depends on them.

"The 'bunker-buster' ammunition that could be brought to bear within the context of cyberwar has not yet been deployed (or at least apparently not yet in a manner that has worked well)," says Cynthia E. Ayers, a security specialist and visiting professor at the U.S. Army War College's Center for Strategic Leadership. "How knowledge-dependent populations react-or how 'new media' societies are capable of reacting-when such weapons are deployed may ultimately determine their fate. The chaos that could be caused either under a limited (homemade) EMP [electromagnetic pulse] scenario or as a result of one or more high-altitude nuclear blasts would be devastating to a Western population in many ways. The losses incurred would make the current economic downturn seem like a mere irritant."

Lt. Col. Kevin Gary Rowlatt of the Australian Army observes that "countermeasures to cyberthreats developed by us will impede our ability to work effectively, let alone efficiently. Firewalls, authentication, and encryption programs have the potential to slow the flow of information. An enemy would love to slow down some decision cycles. This approach would allow them to achieve the aim simply by presenting a threat, be it credible or virtual. We become distrustful of information contained or processed within cyber networks."

8. Militant Islam Continues to Spread and Gain Power

It has been clear for years that the Muslim lands face severe problems with religious extremists dedicated to advancing their political, social, and doctrinal views by any means necessary. The overthrow of Saddam Hussein and the American occupation of Iraq has inspired a new generation of jihadists, who have been trained and battle-hardened in the growing insurgency.

Implications for Information Warfare and Operations: Information systems are another category of attack that Muslim radicals could mount against their chosen enemies in the West. One likely source of such an attack would be India, a land with a substantial Muslim minority (about 150 million people) and strong computer and communications industries.

As Ayers observes, "It has long been noted that radical Islamists have been using the Internet to preach, recruit, glorify suicide-bombers, and perform training on a global basis. The 'e-possibilities' for Islamic militants are obviously limited only [by] the imagination, just as they are for more harmonious or legitimate activities. The cyberworld offers a wealth of opportunity to engage in the spread of Islam, followed by -- or in conjunction with -- a cyberwar that would be seen as just in the Islamic tradition."

9. International Exposure Includes A Growing Risk of Terrorist Attack

Terrorism has continued to grow around the world as the wars in Iraq and Afghanistan proceed, even as the rate of violence in Iraq itself has declined. Nothing will prevent small, local political organizations and special- interest groups from using terror to promote their causes.

On balance, the amount of terrorist activity in the world will continue to rise, not decline, in the next 10 years. In fact, terrorist attacks have risen sharply since the invasion of Iraq, both in number and in severity.

Implications for Information Warfare and Operations: Until the terrorist problem is brought under control- which will probably not happen for at least a generation-we will face a growing threat that Muslim extremists will master computer and Internet technologies and use their skills to disrupt essential communications and data. The impact will be seen in U.S. corporations, research laboratories, universities, utilities companies, and manufacturing. Cyber operations will be at best second choices for many terrorists, who prefer the newsworthy gore of attacks with bombs and firearms. However, their potential for maximum economic impact with minimum risk eventually will make them irresistible to forward-looking extremists.

"National security needs to address the freedom that big business has in moving its IT services off shore," says Rowlatt. "If a business is a major contributor to a nation's GDP, then what right does it have to expose its 'cyber underbelly' to a foreign power, which in turn, exposes the nation to unnecessary cyber risks? Look at how terrorists targeted Mumbai, the cyber center for India, which serviced many international organizations' IT needs."

10. The World's Population Will Grow To 9.2 Billion by 2050

The greatest fertility rate is found in those countries least able to support their existing people-the Palestinian Territories, Yemen, Angola, the Democratic Republic of Congo, and Uganda. In contrast, populations in most developed countries are stable or declining. The United States is a prominent exception.

Implications for Information Warfare and Operations: The world population's growth in itself is less significant than where that growth is concentrated. India already has the largest supply of English-speaking [people]," observes Francis G. Hoffman, research fellow at the Marine Corps Center for Threats and Opportunities. "The educational systems in the latter will not support the advancement of knowledge workers to any degree, and could be swamped by poor governance, lack of services, and chronic disorder. Many places in Asia will experience some of the same downsides of large population growth without adequate governance, services, and education."

Steele adds that the disparities in population growth will widen the gap between developed and developing worlds, producing "environments of anomie and alienation as a breeding ground for terrorist ideology." Moreover, increased education and technological sophistication in the developing world could compound these problems. Steele argues, "A growing proportion of the world's population (including the developing world) is gaining primary and secondary-school-equivalent education. The diffusion of cyber systems in the developing world increases opportunity for global cyberwar."

Conclusion: Lessons for Avoiding Cyberwar

Our major concern is no longer weapons of mass destruction, but weapons of mass disruption. The cost of "going nuclear" is simply too high for atomic weapons to be used by any but a rogue state unconcerned with its own survival. Cyberweapons may kill fewer people, but they can have enormous economic impact. A particularly clever opponent might even carry out a devastating attack without ever being identified or facing retribution. Information has become the battlefield of choice. It will remain so well into the future.

Lesson number one: As the world becomes more dependent on information technology, it becomes more fragile. It is possible to make any specific site or network more secure, but not the "system" as a whole. As network connections proliferate, electronic controls-for example, of petroleum refineries, chemical plants, or electrical grids-become more complex and interlinked, and the number of users grows, the opportunities to interfere with its operations expand exponentially. There is a growing possibility that even accidental missteps could cause significant harm. This damage would not necessarily be limited to data but could strike at real-world infrastructure Relevant Products/Services, with potentially devastating effects. Economic losses could be severe, and loss of life is possible.

Lesson number two: Cybercrime could be as significant as cyberwar. Four members of our panel cited profit-motive information crimes as a problem of potential importance. An information "protection racket" aimed at financial institutions could entail serious economic risks, and perhaps security risks as well. These crimes might use many of the same techniques as information warfare and could be difficult to distinguish from it. Indeed, in a world where rogue governments have supported themselves in part through counterfeiting major currencies, there may be no useful distinction. However, it is not clear that cyberwar and cybercrime will be amenable to the same countermeasures.

Lesson number three: The rise of artificial intelligence will change the nature of cyberwar. As computer systems "learn" to imitate human reasoning and skills, the nature of cyberwar will change. Instead of relying on human hackers to carry out their attacks, antagonists will automate their information warfare, relying on AI systems to probe opposing defenses, carry out attacks, and defend against enemy AI. This competition will quickly outstrip human control, or even monitoring. This is one aspect of the hypothetical "Singularity," the time when artificial intelligence exceeds our own and it becomes impossible even in theory to predict what will happen in the further future.

Lesson number four: The United States is losing its leadership in critical technologies. As other countries build up their technological capacity, the United States is allowing its own to deteriorate. As China and India turn out more scientists, engineers, doctors, and technicians, the United States has been producing fewer. As other lands spend more on research and development, the United States has been spending less. And as other countries devote more of their research budgets to fundamental science, where breakthroughs happen, the United States has focused increasingly on short-term applications. All this may put America at a serious disadvantage in future cyberwars.

In the spring of 2009, the U.S. government undertook new steps to meet this threat. The Pentagon is in the process of creating a Cyber Command center with the aim of protecting the Department of Defense's 17,000 networks and 7 million computers from attack. President Obama also announced a new "cyber czar" position within the administration. Scott Charney, former head of security at Microsoft Relevant Products/Services, is said to be on the top of the shortlist. The question of how effective any one cabinet official can be against a cyberattack remains unanswered.

"They're still trying to fight this problem within the traditional command and control structure," says Patrick Tucker, senior editor of THE FUTURIST. "How does a czar take down an international, unaffiliated network of anonymous attackers? It's like using a hammer against killer bees."

Many questions about information warfare remain to be answered. What are the most likely targets? How would they be attacked? What are the probability and potential impact of each attack? What would the consequences be in terms of human lives, economic cost, and continuing disruption? How could we tell such an attack was coming? And most importantly, what could we do to stop it? These future-critical questions urgently need further study.

Source: www.newsfactor.com

Wednesday, September 2, 2009

The Computer Forensics Show

August 31, 2009 -- Imagine the ability to view anything that ever appeared on almost any computer.

The computer forensics show is the "don't miss" event of the year for all Llitigation, Accounting and IT Professionals.

"Like it or not, every computer is a potential crime scene," says Frank Manley, Show Director of The Computer Forensics Show, which will take over the Santa Clara Convention Center in Santa Clara, CA on October 5 & 6, 2009. The special two-day event will include exhibits of the latest developments in the IT security marketplace, as well as a full conference schedule of top-flight guest speakers, discussion groups and training sessions. "Computer forensics is definitely one of the fastest growing segments of the industry," says Manley.

Computer forensics pertains to the legal evidence found on computers and digital storage media (it was a computer forensics expert who discovered that Bernie Madoff never made a trade). Increasingly, computers are being used as evidence in a wide spectrum of cases, from the millions of instances of identity and credit theft to employee and intra-company disputes. Computer forensics has become vitally important to IT security professionals, lawyers and accountants, and even the average consumer surfing the Internet -- in short, to anyone who depends on the safe and efficient storage and retrieval of data.

Today's business environment is undeniably complex, due to strict regulatory and compliance requirements, closer scrutiny and the pervasive threat of litigation. IT security is vital to any individual, company or law practice dealing with sensitive information created and stored digitally. For some companies, it is not a question if one of their computers will be used as evidence in a legal matter; it is a question of when. A sophisticated computer forensics strategy can literally save a company millions in litigations costs and, in some instances, their hard-earned reputation.

Every day brings changes to the IT security marketplace, and the Computer Forensics Show is specifically geared to showcasing the latest technological advances and trends. The show will feature exhibits as well as a comprehensive and engaging conference program with the involvement of leading edge companies: Kroll Ontrack Inc., McAfee Corporation, SanDisk Corporation, Symantec Corporation, Deloitte Financial Advisory Services LLP, Clearwell Systems Inc., HB Gary Inc., Guidance Software Inc. and EMC Corporation.

Conference events will focus in-depth on topics of interest to legal, risk management, and accounting professionals, as well as the IT sector, and feature five conference tracks including two legal tracks (emerging technologies in litigation and practice issues, records management, reporting and privacy, etc.); forensic accounting, which is the number one growth field in accounting; and two IT security tracks, which will provide practical advice for companies just beginning to encounter security issues to those with more advanced concerns.

Source: www.prweb.com.