Showing posts with label responsibility. Show all posts
Showing posts with label responsibility. Show all posts

Tuesday, March 20, 2012

PwC report identifies a ‘fundamental shift in risk management’

Economic turmoil, political upheavals and natural disasters, all combined with advancing globalization and rapid technology progress, are creating a new era of risk for businesses and causing a fundamental shift in risk management practices, according to a new PwC US 2012 annual report.

Entitled ‘Risk in Review’ the report is based on a survey of more than 1,000 executives and risk management leaders.

"2011 marked a year of reckoning, and many companies are still struggling to create an effective approach to managing the ever-widening risk landscape. Businesses are scrambling to fix weak links in their systems stemming from non-traditional risks such as social media and digital technology, to dealing with the realities of operating in today's global marketplace," said Dean Simone, leader of PwC's US Risk Assurance practice.

"In this new risk era, corporate boards and senior management have a crucial role to play to ensure they set the right culture and align their strategy to risk imperatives."

According to the report, forward-looking companies are responding by shifting their risk management focus in several fundamental ways: from internal to external, from operational to strategic and from bottom-up to top-down.

To better prepare themselves to deal with unexpected events for the upcoming year and beyond, companies installed new risk management organizational structures, have put in place a new breed of risk management leadership and have adopted innovative techniques such as scenario analysis and predictive indicators.

To address changing risk landscape, PwC recommends the following risk management approaches for 2012:

Increasing cross-communication: Place greater emphasis on communications and data sharing in 2012 and take steps to improve cross-functional and departmental communication.

Improving data quality and reporting: Enhance global economic teams to help improve data quality and put in place improved processes for reporting data. Different business units should meet periodically with different business units to review and exchange information and data as a form of early alert to possible upcoming risks to the business.

Better forecasting and scenario analysis: Leverage more sophisticated tools such as early-warning systems and contingency plans to reconfigure approaches to manage risk (i.e. set up scenario models or Monte Carlo analysis geared to the nuances of the business, run models as events unfold, etc.)

Elevating the chief risk officer (CRO): Put risk management role on the proactive offensive instead of reactive defense by giving CROs more cross-functional access and ability to effect decision-making.

Integrating risk management: Manage risk holistically by continuing to integrate risk management into decision-making processes relating to ‘traditional’ functions (i.e. strategic planning). Don't exclude new areas of risk (i.e. talent management and outsourcing), but address and integrate them into decision-making processes.

Bolstering IT: Address data privacy and security concerns and take stock of where to build better processes, practices, procedures and technical defenses. Shifting technology and heightened competition for new customers in new markets are also exposed to more risks, so it's imperative to study the setbacks and successes of peers who pioneered the use of these new technologies.

Greater board involvement: Understand the risks facing a company and have in-depth discussions with management to make sure those risks are being handled properly. The discussion should also cover potential risks that are not yet on management's radar and what the implications of those emerging risks might be.

To download a full copy of the report visit: http://www.pwc.com/riskinreview

Thursday, March 17, 2011

Corporate Social Responsibility (CSR)

Corporate Social Responsibility (CSR) has gained a lot of attention in recent years, but researchers and executives want to better understand in greater detail how today's companies are choosing to "do well by doing good."

They found that while the vast majority of companies continue to pursue traditional forms of charity, an increasing number of them are also incorporating cause-related marketing into their CSR efforts.

This seems to be on the upswing right now. Half of panelists surveyed reported cause-related marketing initiatives at their company. News reports have indicated that "cause-related marketing has become very popular", and surveys confirm it.

Unlike traditional philanthropy, which involves simple monetary donations, cause-related marketing often entails a co-branded partnership between a company and a nonprofit to promote an event or a social cause.

Companies such as American Express, Starbucks and The Gap partner with Product Red and agree to contribute a percentage of "Red" product sales to The Global Fund, a Geneva-based organization that funds programs to fight HIV and AIDS in Africa.

Such co-branding not only helps the social cause, but also creates a halo effect for the companies involved.

One counterintuitive finding of surveys indicate that most companies did not believe CSR efforts increased sales.

Despite the growing interest in cause-related marketing, less than 25% of survey respondents believe that: Pro-social actions directly affect sales and profits for our products and services.

By contrast, 75% believed that CSR directly affected brand image. They don't believe that CSR is going to help their sales in the short run, but they do think it's going to affect their brand image and corporate reputation in the long run.

Friday, October 9, 2009

Securing Access to Open Internet Accounts in the Cloud, is our responsibility

As security conscious IT and Business Management professionals, we need to be concerned and informed if our organisation is using a social networking site as part of their business model. Especially if it is disappearing into the Cloud, currently the main or prime target for all the shadowy internet 'terroristas'.
Also, we may have a little more time on our hands, now that those precious customers are thin on the ground. This is just the opportunity you need to review and strengthen your defences: check the perimeter and infrastructure by all means but you know the 'people' are the biggest risk to security.

We are all too aware that cyber-criminals can easily hijack accounts and e-mail customers on our behalf, and we take account of that through our extensive and elaborate, e-mail scanning and monitoring efforts. According to the FBI and other global law enforcement authorities, you are obliged to warn your colleagues, customers and users to make all efforts to protect themselves and the organisation whilst using an open internet connection.
The user is also responsible for the consequences of their own behaviour. It has always been thus but the rate of change of threats we are experiencing does create a lag in time between the separate actions of knowing, defending and informing. We see that lag as a risk and the criminals see it as an opportunity.

Make your people aware of threats and the emerging, changing nature of threats. Request that they think about 'secure' usage and help them do this by drawing their attention to, and take note of, the following good advice:

1.Adjust Web site privacy settings to help protect your identity.
2.Be selective when adding contacts.
3.Limit access to your profile.
4.Disable options that you rarely use.
5.Be careful what you click on.
6.Be familiar with security settings and know how to recognize if your account gets hijacked.
7.Understand the process of how to report a hijacked account to the site owner.

Although this is not a comprehensive list, neither is it a guarantee of full protection, it is important to educate our colleagues and users about the possible security risks and the issues they face. Remember, their issues, if unresolved, will quickly become our problems. If we accept and consider them the weakest link in our security chain, what are we doing about it?

Sunday, May 3, 2009

New appointment or promotion can be a day of mixed emotion

“Here is a pen and here is a pencil,
here's a laptop and here's a stencil,
here's a list of today's appointments,
and all the flies in all the ointments,
the daily woes a manager endures
take them all, 'cause now they're yours!”

based on an Ogden Nash quotation