NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 CIO BlackBerry News and Tips
 CIO Research and Analysis
 CIO Microsoft
 CIO Insider
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 


Fri, Jan 25, 2008 14:42 EST

Computers Aren't as Devious, or Smart, as Us

Topic: Enterprise Management

Blog: Web 2.0 Advisor

Current Rating: 5 Comment: 1

On Thursday, January 24, a leading French Bank announced that it had uncovered $7.2 billion in losses that officials attributed to the actions of a 31-year-old "rogue trader." The trader, named Jérôme Kerviel, had "managed to evade multiple layers of computer controls and audits for as long as a year, stacking up 4.9 billion euros in losses for the bank," The New York Times reported.

Executives called Kerviel's actions "pure fraud." The loss is believed to be the biggest in history by a trader. Société Générale executives said that Kerviel had an "intimate and perverse" knowledge of the bank's auditing capabilities and back-office operations that enabled him to cover up his unauthorized trades. A French banking governor commented that Kerviel was a "computer genius" and had been able to breach "five levels of controls" at the bank.

Of course, the most pressing and interesting questions—how was he able to evade any detection by other employees or Société Générale's trading and auditing systems? if there were controls in place, how is it possible he could have done it alone, as the bank claims? and why did it take the bank so long to discover the fraud?—remain unanswered right now.

Christophe Mianné, the newly installed head of global equities and derivatives at Société Générale, told Risk magazine on Thursday that Kerviel "was very clever, but that's not an excuse, because we have to be more clever." He also notes that Société Générale executives are still "puzzled" by Kerviel's deceit. "We are almost 100 percent sure he didn't benefit [financially] at all," Mianné says.

For those in the financial services industry, this latest incident draws comparisons to the 1995 case in which Nick Leeson, a Singapore-based trader, ran up $1.4 billion in losses on more than $27 billion bad bets in the Japanese financial markets.

For what it's worth, Société Générale is no Mom-and-Pop bank. It's a highly respected institution that was founded in 1864 and has 120,000 employees and 22.5 million customers. Which makes the incident even more vexing and reprehensible: Where was the oversight? Where were the checks and balances? Where were the risk controls?

But it's not just the financial services industry that has had info-security and risk management problems (though with trillions of dollars in play every day, it's bound to bring out the best and brightest crooks). It seems that in today's interconnected world, it doesn't matter if the culprit is on the inside or outside, or if a company has the minimum or maximum level of controls—people are too devious and too clever and too resourceful, and they will always find ways to outsmart their computing counterparts.

To put together a short list of recent examples in which all types of corporate controls were lacking isn't that difficult to assemble: TJX's customer data breach, which ranks as the largest ever; HP's spying and pretexting scandal; a Transportation Security Administration hard drive containing 100,000 names, Social Security numbers, dates of birth and bank account data of current and former employees (including federal air marshals) that was stolen; a vengeful Florida woman intentionally deleting $2.5 million worth of files off her company’s computer server.

I could go on. I won't. The point is that where there's a will, there's a way, and not even the most ardent, expensive and well-thought-out info-security systems, auditing controls or encryption schemes can stop dangerous and highly capable minds.

Bruce Schneier, a cryptography and security expert, writes

You do not have flash or javascript support.
Average (2 votes)
5
 
 
Wed, Jan 30, 2008 10:39 EST
Anonymous user
Posted by: Anonymous
Rating:

People and complacency when times are good form the weakest link most times.
Societe Generale had already been warned sometime ago, by an external parter, about the unusual transactions being made by Jerome. It seems they took their time to come up with an explanation because of the size of the problem and the need to blame it on someone. In this case apparently the choice was to sell the idea that the man was some computer genius that no matter how sophisticated the IT systems were they would be no match for him. Which I dont think is the case. Given the amounts of the transactions they had to show up in some reports and most likely simply someone was sleeping on the job. Just like Kevin Mitnick was no computer genius, instead he explored the weakest point: people.
By the way, it seems that Jerome's goal was to profit through a bonus or promotion, not directly from the transactions as you also mentioned.

Post new comment

* Subject:
* Username:
* E-mail:
The content of this field is kept private and will not be shown publicly.
Homepage:
* Body:
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <img> <blockquote> <strike> <p> <br>
  • Lines and paragraphs break automatically.
More information about formatting options

* Denotes required field.

About this Blog

Kristin Burnham chronicles what matters (and what doesn't) in the world of social networking, Web 2.0 and consumer applications.

Hot Conversations

Ex-Microsofties Look Back in Anger

Posted by Shane ONeill in News | 4 comments

The Price of IT Outsourcing

Posted by Beth Bacheldor in Best Practices | 2 comments

Start a Conversation
Click to post

Got something to say? We want to hear it! Click the Post button to get started. GO»

EXPERT ADVICE
See our roster of experts.

Advice & Opinion from more than 115 of IT's most insightful thinkers.

  PARTNERS       WEBCASTS    
 

Windows 7 Webcast Series

There's a lot of buzz about Windows 7 out there. Each month in our webcast series, listen to analysts and customers discuss how Windows 7 and the Windows Optimized Desktop is impacting large companies around the world. Learn how they evaluated Windows 7, including the cost of deployment, deployment strategies, and tangible benefits.

Sponsored by Microsoft  Listen to on-demand Recordings »

 

A Framework for Better Application Delivery

The complexity of application delivery is driven in part by the evolving applications environment. Instead of approaching application delivery from a siloed fashion, this handbook looks at end-to-end guidance and discusses the impact of ignoring the WAN, Web apps that are chatty, data center consolidation, SaaS, Web 2.0 and virtualization.

Sponsored by Riverbed  Read this White Paper »

 

Microsoft® Exchange 2010 includes archiving - but is it enough?

Microsoft® Exchange 2010 includes basic email archiving. But many organizations will find that it does not meet their requirements. This paper describes why organizations need to archive, what capabilities Exchange 2010 includes and why 3rd party archiving solutions will be necessary for most organizations.

Sponsored by Google, Inc.   Read this White Paper »

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

Enterprise Capture: Your Onramp to Business Process Automation

Today more than ever companies are seeking to reduce costs and...  View Now »

 

The True Cost of Legacy Systems

How well are you maximizing existing software assets? This webcast reveals the results of a commissioned study on top migration and modernization priorities for IT leaders.   View Now »

 

How To Maximize Your Virtualization Strategy and Deployment

Join award-winning technology journalist Stan Gibson in this webcast as he discusses how to enhance your virtualization strategy with the ROI, planning, implementation and platform advice. Exploit the business benefits of virtualization and successfully expand your current deployment.   View Now »

Resource Alerts

Get instant email notification when white papers, webcasts, and case studies are added to our library. Don't just be up-to-date—be up to the minute with our new Resource Alerts.

 
NEWSLETTER

Sign-up for the Blogs & Discussion Newsletter




*Required fields

By clicking the sign-up button, you agree to the Privacy Policy.

View all newsletters »

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Manage limitless content todayread EMCs 15-minute guide to ECM.

HP Exstream. Get a Free Document Assessment for Financial Services.

Take the Netezza TwinFin TestDrive!

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Let Progress Software help your business make progress.

Best Practices to Reduce IT Operational Costs

Real-world testing ranks Trend Micro #1 against malware. See results.

Forrester: The real-world financial impact of Windows 7

Turn your desk phone and mobile phone into one with Sprint Mobile Integration.

Maximizing efficiencies with unified communications.

Stay informed with custom newsletters from Tech Dispenser

Selecting the Right Reporting Technology

An IT Leadership Action Plan for the Economic Recovery

Consolidate data centers and lower IT service costs. Learn How.

WAN optimization techniques significantly improve application performance. Read More.

The Revolution and Evolution of Private Cloud Computing

ROI of Application Delivery Controllers

Cut Costs & Green Your IT Operations with PC Power Management

Enterprise Capture: Your Onramp to Business Process Automation

Adobe® LiveCycle®solutions for intuitive user experience

Unlocking the Mainframe: Modernizing Legacy System to SOA

State of the Data Integration Market

Enhance Customer Loyalty through Higher Responsiveness

Achieving Business Agility with Application Grid

Seven Ways ITIL Can Help You in an Economic Downturn

Does your IDS really work? Find out with a free Endace Audit

Verint Systems. Discover the Power of Intelligence in Action"

CA ARCserve r12.5 is More Than Backup! Download Trial Version Today

Enterprise search helps employees get more done. Get the facts from Google.

See why ShoreTel is named best overall VoIP provider by Nemertes Research

Trend Micro ranked #1 against real-world malware. Read more.

AT&T Application Management & Hosting. Let us help you STRETCH

Microsofts new client operating system helped Pella reduce power consumption.

Efficiency goes up. Costs come down.

Dark Fiber from Sunesys Save on Unlimited Bandwidth with Fixed Costs.

Trend Micro ranked #1 against real-world malware. Read more.

Webcast: Solve Your Data Visualization Needs with Open Source BI

Webcast: Delivering the Enterprise-Ready Cloud

Ensure cost effective application delivery. Learn More.

Cloud Computing: The Impact CIOs See

What's Next for Enterprise Resource Planning?

Gartner Magic Quadrant, Application Delivery Controllers 2009

Global Research: CIOs Weigh In On Virtualization

Adobe® LiveCycle® solutions for business process automation

What's New in SOA Suite 11g?

Unleash the Power of Java with Oracle JRockit Real Time

SOA Best Practices and Design Patterns

Application Grid: Ideal Platform for IT Consolidation

Taking the Service Desk to the Next Level