Showing posts with label conflict of interest. Show all posts
Showing posts with label conflict of interest. Show all posts

Monday, August 11, 2008

This Year, Fraud Will Cost Businesses $994 Billion in the U.S.!

U.S. organizations lose about 7 percent of their revenues to fraud, according to the Association of Certified Fraud Examiners. When compared to the projected U.S. Gross Domestic Product for 2008 -- 7 percent equates to $994 billion.

In their just released Report to the Nation on Occupational Fraud and Abuse, the average case cost a business $175,000. In a quarter of 959 cases used to compile the study, the loss was $1 million or more. The most costly type of fraud was financial statement fraud -- more commonly known as cooking the books -- which cost organizations an average of $2 million.

Not surprisingly, smaller businesses suffered the greatest losses. I say not surprisingly, because smaller businesses normally can't afford dedicated resources to detect and prevent fraud. For small businesses, the average case studied cost about $200,000.

The most common type of fraud found in the study was corruption and the second most common was fraudulent billing. The average scheme wasn't detected for two years and the most common form of detection was from a human being tipping off management, or a business owner.

In the small business fraud model, check tampering was a common cause, also.

Businesses that had fraud controls did a lot better than businesses that didn't, according to the study. For instance, businesses that did surprise audits suffered an average loss of $70,000, while businesses that didn't suffered an average loss of $207,000. Other controls that made an impact cited in the report are anonymous hot lines, training management to detect fraud and hiring dedicated personnel to detect and resolve fraud.

According to the report, fraud perpetrators can be identified by the behaviors they display. These include living beyond their means, financial difficulties or even by trying to please their boss by making it appear that the business is doing better than it really is. Please note that in the case of larger corporations, the word "boss" can mean investors or shareholders.

Please note there are many more signs of dishonesty and recommended controls for small business owners. Another good resource to read about these subjects is put out by the National Association of Veterans' Research and Education Foundation.

The extensive report covers all type of fraud, whether they are financial, or otherwise. The three main categories it is broken down into are Corruption, Asset Misappropriation and Fraudulent statements. Corruption schemes entail bribery, conflicts of interest, illegal gratuities and economic extortion. Asset Misappropriation schemes (most common) cover cash manipulation, inventory theft, and fraudulent disbursements.

For those businesses, who can't afford hired help to deal with fraud, I guess this means a owner should check their books and accounts randomly without letting their employees know when they are going to do it. They should also diversify controls and oversight (separate key duties). No one person should have complete control over a revenue stream or valuable asset. Additionally -- there are third-party anonymous hot line services and if they are too expensive -- a creative small business owner might set up a telephone line with a voice mail and have some posters made.

So far as training management and employees on what to be aware of -- the current AFCE report is a wealth of information, also. A little awareness and knowledge of how fraud is facilitated can go a long way towards preventing it, as well as, giving your human resources the knowledge to spot and report it.

Most fraud is defeated by people, who are knowledgeable of what to look for. This is because fraud schemes rely on tricking everyone else to think nothing is going on.

On a final note, if you are a small business owner and detect fraud, I recommend leaving any legal recourse matters to someone who is familiar with how to do it. Handling these matters the wrong way can add to the problem by causing other losses, such as civil litigation or the protecting yourself against it. In any situation, where a crime is detected, the best thing to do is to contact the authorities and seek their assistance with it.

Sunday, January 13, 2008

Blogger exposes security flaws on TSA site

Since 9-11, we've spent billions upgrading security. Here is a sad report about how the TSA (Transportation Security Agency) put up a NOT very secure site with some of the money earmarked for making the nation more secure.

Even worse, it seems it wasn't the TSA didn't even discover the problem themselves. The problem was brought to light by a blogger!

Here is some commentary from the government report that examines this problem:

In October 2006, the Transportation Security Administration launched a website to help travelers whose names were erroneously listed on airline watch lists. This redress website had multiple security vulnerabilities: it was not hosted on a government domain; its homepage was not encrypted; one of its data submission pages was not encrypted; and its encrypted pages were not properly certified. These deficiencies exposed thousands of American travelers to potential identity theft.

After an internet blogger identified these security vulnerabilities in February 2007, the website was taken offline and replaced by a website hosted on a Department of Homeland Security domain.

At the request of Chairman Henry Waxman, Committee staff have been investigating how TSA could have launched a website that violated basic operating standards of web security and failed to protect travelers’ sensitive personal information. As this report describes, these security breaches can be traced to TSA’s poor acquisition practices, conflicts of interest, and inadequate oversight.

The report reveals that the contract for the website was awarded without taking competitive bids to a company by a TSA employee, who was a former employee of the company designing the site. Even worse, it took months for the security flaws to be noticed and when they were, it was a blogger that brought them to everyone's attention!
The "hat tip" on this one belongs to a Chris Soghoian, who is a Ph.D. student at the University of Indiana’s School of Informatics. He used to write on the blog, "Slight Paranoia."

The first time Chris was considered "notorious" was when he put a fake boarding pass generator on the Internet. This attracted a lot of attention in the press, as well as that of the FBI.

Chris recently moved his blog to a CNet address, which can be seen, here.

Chris recently blogged about this report and added a comment about the lack of spell check being used on the TSA site, "Furthermore, the site was filled with typos and other errors, causing some to wonder whether TSA's site had been taken over by phishers."

The official government conclusion is:

There were multiple factors that contributed to security vulnerabilities in the TSA traveler redress website. They included poor procurement practices, conflicts of interest, and weak oversight. The result of these shortcomings was that an insecure website collected sensitive personal information from American travelers for months without detection by TSA.

This led me to wonder if the TSA employees involved still have their jobs?

Much to my chagrin, I found my answer on the Committee on Government Oversight and Reforms press release on this matter:

Neither Desyne nor the Technical Lead on the traveler redress website has been sanctioned by TSA for their roles in the deployment of an insecure website. TSA continues to pay Desyne to host and maintain two major web-based information systems: TSA’s claims management system and a governmentwide traveler redress program. TSA has taken no steps to discipline the Technical Lead, who still holds a senior program management position at TSA.
Full government report (PDF version, here.