Showing posts with label risk management. Show all posts
Showing posts with label risk management. Show all posts

Sunday, January 24, 2010

Drawing internal buy in for improved Risk management

After my latest posts about risk management (identity management basics and getting the best out of your data) I was asked a great question I think about every day: it's great to have a methodology and a strategy, but how do you get other people in the organization (whether inside or outside of the risk management group) to agree and work with you?

Well, trying to both shape and implement a new terminology is as hard as any other change management, and is very similar to any type of internal marketing: the right catch phrases, proper branding and the right timing and location will do wonders. None of those will work if what you're "selling" is a bad product - an inconsistent, over-complicated or over-simplified method that people cannot use will never be as easy to implement as will a coherent system that makes sense and can be fairly easily comprehended - and used.

Nevertheless, even given a good system this is no mere feat. What are the keys to success? In my experience, there are three:
  1. Ownership: what this means is that you take responsibility over the area you are looking to improve. Too many times I have seen a person or a team trying to change a process or a notion while assuming the consultant position; in most cases, they will fail, because the key for making a change is rolling up your sleeves and making something happen. "If you build it, they will come", and "They" here are the aggressive achievers in your organization, the ones that recognize something that works and are not afraid to try and learn it. Stop saying "I told you so" and start doing!
  2. Transparency: no siloed organization make a change outside of its own boundaries. Only inclusion of other teams, clear communication and eternal repetition of your messages, coupled with deliverables, can make any type of substantial difference. Don't take the traditional risk management approach - don't scare people with the horrors that might happen if they invest in a project; instead, say: "this is what might happen, this is why, and this is how I intend to solve it. Want to help?".
  3. Gradual Enablement: think of new ways to say "yes". If your system is truly innovative it will allow you to take risks others can't because you can understand and manage them better. Still - don't rush into it, because small successes are key for maintaining momentum; use pilots and rapid prototyping to prove that something can be done, and expand responsibly. This way you can prove you can stop more fraud while not hurting users - and get the charter to expand.
Is this the magic bullet? No, but these keys will put you on the road to success, because they earn you the trust of partners while delivering the results you need to fuel your system. And, if we all adopt this point of view, risk will start being a driver of innovation of payment companies - definitely a time I would love to see coming.

Monday, December 14, 2009

42% of users have a good reason to fear


Working in the risk management business, I often get these layman questions about ePayment security. They are close relatives of questions IT people are being asked about hardware purchasing; when people finally find that item they wanted to find or a bargain they can’t resist, they want to make sure they don’t get scammed. Who’s better for that than your friendly neighborhood risk management specialist? I’ve given my part to eCommerce, you should know, and if retailers felt a $3000 shift in their revenues this year – this one’s on me, guys. No need for commission this time.


Seriously, though – why are thousands and maybe hundred-thousands of interactions related to purchasing on the web really important? As I mentioned in my previous post about Square’s trust issue, good payment services instill trust (among other things); and for an industry based on users exposing themselves and their financials, trust – created, in my case, by getting a recommendation from an authority – is one of the main challenges for emerging companies.

Saturday, November 14, 2009

The A-Team: building the best risk management teams


WWII basically ended unemployment in the US. Increased wartime production and the drafting of millions of men had created so many new opportunities, that the effect of the great depression was finally countered. It was a time when millions of women would join the work force. They filled traditionally "female" jobs but also opened up many previously "male" jobs, from operating heavy machinery to traveling sales people. In a sense, it was a revolution stemming from necessity, which is often the case even when the necessity doesn't arise because of a world war; someone's next promotion might occur with the same dynamic.

It was in this atmosphere that Katharine Cook Briggs and her daughter, Isabel Briggs Myers, started working on a personality type test that would help new female workers find the right job for them, where they could be more effective. More than 60 years later, MBTI is a commonly used test to assess personality types and help people of various preferences understand each other's perspective of ideas, data, decision making and planning, among others.

Monday, November 9, 2009

Where is my mind? Way out, in the water


(As I'm writing this, EA has announced it has bought PlayFish. All the more reason for a call to the industry to stop panicking and start taking responsibility for its own faith with big fish coming to play. But read on...)

One of the many highly useful skills I learned in Officers' course was artillery aiming. There was a lot more fun stuff I could imagine doing in any given afternoon, but there's definitely nothing like it. And when you just don't have an option (and believe me, in officers' course you don't have an option), you just give it your best shot. Pun intended.


So there I was, trying to get 155 mm cannon to hit a barrel. I don't know if you know how these things go, but artillery aiming is some simple arithmetic and a lot of art. You aim the cannon one way, then course correct the other, then again - in shrinking intervals, until you hit the target (or 50m away from it, which is considered good enough). It must have taken me 5 or 6 attempts to hit the goddamn thing - the gun crew was not a group of happy campers, nor was I. But all in all, it was a good drill, and I passed the test, and got my rank of deputy lieutenant, and mom was happy.

Sunday, October 18, 2009

And now for something completely (?) different

I'm diverting from Risk per se the deal with another decision-automation question I'm wondering about.
High-tech fluctuates. It boomed on the verge of the new millennium, and did so (albeit differently) before the latest downturn. And when booming, help is required. High-tech companies don't usually post a "help wanted" sign on their office wall (though some in Israel did), and getting to a good position requires some work beyond coming from a good school. In the days of the "bubble", just knowing a few people would secure you a position somewhere in the space, but nowadays it takes a lot more than that - employers demand good grades, subject matter expertise and experience - all of which are no mere feat for new graduates.