Connect with us

E-Business

Delegate Responsibility not Accountability- Keele

Published

on

Kindly share this post

Allen Keele is a certified fraud examiner, information security manager, information systems auditor and information systems security professional, among 20 other professional and technical accreditations. He shares over 17 years of experience in information security and risk management, including nine years of conducting professional advanced business lectures and seminars across the globe. Keele spoke to hilary okeke on a range of issues.

Training on Fraud Detection and Management
In information security, one of the most important things we have is not always having information security itself but having the internal control to be sure that we have information security. I wrote the text that most people use to prepare for Certified Information Systems Auditors (CISA) exams around the world. In that context, a lot of the controls that the internal auditors monitor have to do with controlling internal breaches and abuse. So, it would make logical sense to extend my auditors knowledge and expertise and interest into internal fraud detection and management. I was shocked to find in my younger days that 90 percent of frauds can be detected through the books. So many organizations tell you that they have no fraud problem but when you take a careful look, you find that there actually is a problem. People device all kinds of means to get money out their organizations without doing anything on the book. That was very concerning to me as an auditor. Fraud in itself is a disaster for an organization. It could lead to loss of market share if made public. Organizations need to be prepared for that kind of disaster just the same way they prepare for fire. So that is why we extended our training to business continuity, disaster recovery, as well as a new perspective on fraud. There are lots of folks out there who offer training on business continuity and disaster recovery, but what we are doing that is unique in the market is that we are not trying to project our best practices; we are teaching according to the new British standard – BS 25999. It is a new international standard designed to keep your business going during the most challenging and unexpected circumstances. It provides a basis for understanding, developing, implementing and managing business continuity within your organization and gives you confidence when dealing with stakeholders both within and outside your organization. BS 25999 has been developed by a group of experts representing a cross-section of industry sectors and governmental organizations which is reflected in its applicability. The standard is suitable for any organization, large or small, from any sector. It is particularly relevant for those that operate in a high risk environment such as the finance, telecommunications, transport, utilities and public sectors, where there is need for continuity. I have had a lot of organizations tell me they went for training a couple of years ago – the British standard may have existed a couple of years ago for training, but it just got ratified recently. There was no standard prior to BS 25999. So, this is a whole new world in terms of getting the certification to prove that your organization has the ability to manage fraud and disaster. Often times, organizations do things because regulators make them. Now more than ever, you have financial regulators requiring you to prove that you have strong control against fraud but you do not even have a fraud policy.
Best Security Strategy for an Organization
The best security strategy is first, to have one. Whether it is fraud, business continuity or information security; organizations have this odd tendency to casually appoint people within the organization to handle those areas. They point to the IT or compliance person – somebody who does not understand that area, and that person has to go and figure out what controls to put in place to get things working. So the problem is that currently, there is no strategy. Nobody has stopped to think “we need to be at 95 percent for fraud capacity at all times, no matter what.” They leave it up to the discretion of people who are not actually accountable for the business. That is wrong! Maybe you have an inexpensive web server that manages your brand new e-commerce that supports 90 percent of your business but because it was not expensive, your IT manager complains that it goes down all the time and that he is going to have it replaced in two weeks. Two weeks for e-commerce? That is why we said that the most important strategy is to have one. It is not just my idea, it is ISO 27001 standard for information security, which instructs that you get a strategy in place. I have always recommended that organizations should first have the right people that are actually accountable for that decision and have them make the decisions for a change. You can delegate responsibility but you cannot delegate accountability.
Networking and Telecommunication in Auditing, Internal Control
ICT has a very important role to play in internal control because auditors control access to information which IT does too. Auditors also control how information is used and how transactions are processed. Over the years, automated control organizes business functions and that has reduced loss of money. So, IT is able to put controls in place but then again, depending on how well it is managed, there might also be some vulnerability. In detecting and managing fraud, you need asset combination. I have often asked people in my classes if their organizations are committed to preventing, detecting and minimizing fraud. And they say yes, absolutely! I ask them to show me a policy that says: “Our organization does not want fraud, and this is what we are going to do to stop it.” They have no fraud policy! Shockingly, a policy is nothing more than a statement of management that states the way things are done within an organization. If you say that controlling fraud is a good objective, where is the policy that not only says it is wrong but also says here is who should be looking for it; here is who should be investigating it and here is what we do if we find it. A fraud policy is where senior managers say “not only am I going to accept responsibility, but I will accept accountability for something going wrong.”
Legal and Ethical Issues Facing IT Auditors
The legal and ethical issues are similar for IT auditors as they are for financial auditors. As an IT auditor, it is possible that you would be dealing with irregular or illegal acts. Towards that end, you have to be careful whom you release information to – there is always tendency for you to be exposed to sensitive information about an organization that you have to protect. As you are investigating issues, you have to be sure that you do not breach privacy laws. For instance, there are laws now that protect account information for people who have bank accounts. Imagine if during the course of an IT audit, the auditor compromised your account, and your account number and access code was made public. That auditor could be in for a lot of legal hassle.

 

 


Kindly share this post

Nigeria CommunicationsWeek believes that technology makes life more exciting and helps improve the lives of people around Nigeria and indeed the world. So since 2007, we have devoted our energy to independent reportage of technology and how they affect lives.

Continue Reading
Advertisement
Comments

E-Business

Cyber Resilience a Critical Priority for Manufacturing Amid Rapid Digitalization – Report Shows

Published

on

Kindly share this post

As 60% of manufacturers race toward full digitalisation, cyber risk is increasingly manifesting as a business risk, according to a new global report by Kaspersky and VDC Strategy.

This means cybersecurity is not merely a compliance function, it is a cornerstone of production assurance, safeguarding uptime, quality, and operational continuity.

Manufacturers are modernising to deliver safer, more consistent and more cost-effective production and digitalization is moving fast: just 9% of organisations describe themselves as fully digital today, but 60% expect to get there within two years, according to the joint report by Kaspersky and VDC, titled ‘Cyber Resilience, Built for Manufacturing’.

That shift links shop-floor equipment, production lines and site operations to platforms such as Manufacturing execution systems (MES), Supervisory control and data acquisition (SCADA) and historians, turning many plants into cyber-physical systems (CPS), where a digital disruption doesn’t stay digital. It can slow production lines, quarantine work in progress, invalidate traceability records, or halt production outright.

What’s driving manufacturing digitalization?

Advertisement

Manufacturers are digitising for measurable operational gains, not novelty. Survey respondents identified the primary drivers of their digital transformation strategy as:

  • Improving production output or efficiency (24%)
  • Reducing operational or production expenses (15%)
  • Enabling new strategic opportunities (14%)
  • Improving cyber resilience (13%)

The same connected systems that unlock these gains, including MES, IIoT sensors, automated material handling, remote engineering access, also become the systems that determine whether production can be trusted to keep running.

Cyber risk is now a business risk

Cyber risk has evolved from a mere IT concern to a direct threat to revenue generation, as environments transform into cyber-physical systems. In these integrated settings, digital disruptions like malware no longer just affect data, they can cause unsafe operations, scrapped batches, and halted production on the plant floor. This shift highlights the urgent need to treat cybersecurity as a key part of operational resilience.

According to the report, nearly 60% of manufacturing organisations estimate that cyber incidents cause damages exceeding $1 million per event, with an average disruption of 15.3 hours. The most significant losses often result from production halts, missed delivery commitments, and penalties, rather than just forensic costs.

In this context, downtime links cybersecurity risks to overall business performance. Cyber incidents can reduce Overall Equipment Effectiveness (OEE), strain staffing, and disrupt supply chains. Recovery involves more than system restore, it requires re-establishing confidence in process parameters, quality records, and traceability before resuming operations.

Advertisement

Mature cybersecurity programs now incorporate OT security into governance, focusing on metrics valued by production leaders such as time to restore, backup confidence, legacy asset coverage, and safe degraded operation. This alignment ensures cybersecurity supports continuous production and resilience, not just IT compliance.

However, challenges remain due to split ownership. While 59% of organisations’ IT departments manage security policies, these often overlook plant realities. Managing many security tools (44%) and OT patching issues (38%) show that cybersecurity must be embedded into daily routines of production, engineering, and quality teams. Only through such integration can cybersecurity effectively enhance operational reliability and defend against evolving threats.

“As manufacturing environments become increasingly interconnected, cybersecurity shifts focus from merely adding protective layers to ensuring the availability, resilience, and integrity of production processes. The goal is to minimise operational impact and speed up recovery, rather than solely preventing intrusions.

“Kaspersky offers a unified ecosystem that integrates IT, OT, and IIoT security, empowering manufacturers to pursue digital transformation securely. This strategy helps maintain operational continuity and reduces long-term cybersecurity costs,” comments Andrey Strelkov, Head of Industrial Cybersecurity Product Line at Kaspersky.

To implement this strategy, manufacturing companies can leverage solutions from the Kaspersky OT Cybersecurity Ecosystem, centered around Kaspersky Industrial CyberSecurity (KICS), a native Extended Detection and Response platform designed for critical infrastructure protection. KICS enables centralised detection and response to complex attacks across the entire industrial network, ensuring comprehensive visibility and security.

Advertisement

Kindly share this post
Continue Reading

E-Business

NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

Published

on

Kindly share this post

Nigeria Data Protection Commission (NDPC) has commenced a forensic investigation into the University of Lagos (UNILAG), Lotus Bank and Hackerbella Ltd over alleged violations of data protection laws involving students’ personal information.

NDPC Probes UNILAG, Lotus Bank, Hackerbella over Alleged Students’ Data Misuse

The investigation follows public complaints alleging that students’ personal data were used to open bank accounts without a lawful basis.

Dr Vincent Olatunji, national commissioner and chief executive officer of the NDPC, directed the investigation team to conduct a comprehensive assessment of the circumstances surrounding the collection, processing, use and disclosure of the affected students’ personal data.

The investigation will also determine the respective roles and responsibilities of UNILAG, Lotus Bank and Hackerbella in the alleged processing of the data.

According to the Commission, the investigation will assess the data protection compliance obligations of the parties under the Nigeria Data Protection Act, 2023 (NDP Act), as well as potential risks posed to the rights and freedoms of the affected data subjects.

Advertisement

The NDPC said the probe would cover several areas, including Data Protection Impact Assessments (DPIAs), the lawfulness and transparency of credit scoring or profiling activities, and the use of automated decision-making systems.

It will also examine the adequacy of privacy notices, data-sharing arrangements, lawful bases for processing, data minimisation and purpose limitation.

Other areas include data retention policies and the adequacy of technical and organisational measures put in place to safeguard the rights and personal data of affected students.

The Commission reiterated that institutions entrusted with the personal data of students, staff and other members of their communities have a heightened responsibility to ensure that such information is processed lawfully, fairly, transparently and securely.

The NDPC therefore warned educational institutions that are yet to comply with its existing data protection compliance directives to take immediate steps to achieve compliance.

Advertisement

The Commission said it would continue to exercise its regulatory mandate to protect the privacy rights of Nigerians and ensure that organisations processing personal data comply with the provisions of the Nigeria Data Protection Act, 2023.

Kindly share this post
Continue Reading

E-Business

Microsoft to Unveil Next-generation AI Chip in September

Published

on

Kindly share this post

Microsoft is planning to unveil its new Maia 300 AI chip this fall, potentially as soon ​as next month, The Information reported on Monday, citing ‌people with direct knowledge of the plans.

The company introduced its Maia AI chip in November 2023 but has lagged rivals such as Alphabet and ​Amazon in scaling up its in-house chip efforts as ​it seeks to reduce its reliance on Nvidia’s costly ⁠processors.

Google began recognizing revenue from direct sales of its custom ​AI chips, called Tensor Processing Units, in the quarter ended June, ​while Amazon has also seen growing adoption of its processors, including its Trainium chips.

Microsoft has been in talks with chipmaker TSMC to secure manufacturing ​capacity for more than 300,000 units of the chip for ​delivery in 2027, according to the report. It is also looking to significantly ramp up ‌production ⁠and persuade major cloud customers such as Anthropic to adopt the chip.

Microsoft ultimately ​aims to ⁠secure capacity for more than 1 million Maia 300 chips, though component supplies and ongoing capacity ​negotiations with TSMC could constrain its plans, according ​to the ⁠report.

Advertisement

It unveiled its second-generation Maia 200 in January, built by TSMC using 3-nanometer technology.

Microsoft packed the chip with a significant amount of ⁠SRAM, ​a type of memory that can provide ​speed advantages for AI systems handling large numbers of user requests.

 

Kindly share this post
Continue Reading

Trending