Michael Walford-Williams on Ethical Hacking of Human Controls

Michael Walford-Williams on Ethical Hacking of Human Controls

How can we assess the level of human risk we’re running in a control framework? Unlike technology, humans aren’t always reliable and how they behave under pressure may well be different to how they behave in normal situations.

My guest on this episode, Michael Walford-Willaims is a risk professional who specialises in how to plan for when things go wrong, covering areas like business continuity, operational resilience and crisis management.

Michael helps companies by testing out the human components of control frameworks to see where there might be weaknesses. He goes into organisations and tries to ethically hack them by trying to circumvent controls with human elements — that might be trying to get a fraudulent invoice paid or simply tailgating employees to see if he can get physical access to buildings.

His work serves two purposes:

Firstly it identifies potential weaknesses in controls. If he can get a fake invoice paid, then so can a fraudster. If he can get access to buildings, then so can thieves. By seeing how easy it is to bypass controls, organisations can get a better handle on their risk profile. Until you’ve actually tested the human controls, it’s impossible to know how weak or strong they actually are.

Secondly, it serves as a training exercise. Just like a fire evacuation drill, it’s better to have employees learn what to do or not do, by experiencing a simulation, than letting them learn from real-life situations.


This is human risk management in action. Of course there are ethical components to the work that Michael does — how far is it appropriate to test out your employees and what do you if you discover they are the weakest link in your security chain?

As Michael explains, we have to also think about what impact the exercise will have on those involved in it. If you think you’ve been tricked by your employer, that you’re somehow not trusted, or that your employer is prepared to deceive you and therefore the organisation is unethical, the exercise could actually make things worse. So the expertise Michael brings isn’t just about testing the proverbial fences. It’s planning exercises that don’t cross ethical lines and then using the information gleaned from them, sensitively and intelligently.

About Michael
Michael has worked for over 15 years in various aspects of risk management and compliance with a specialism in Business Continuity and Crisis Management and more recently third party risk management. He has worked in a number of countries globally having been based in London, Singapore and New York. Working in house and for the last 7 years as a consultant, Michael has worked across many industries for some of the largest organisations in the world including some of the worlds largest banks. and through his work in the field of crisis management has worked on a number of major incidents including the Japanese Tsunami and Fukushima incident, terror attacks in Mumbai, Boston and Moscow and numerous natural disasters, and technology & infrastructure failure related incidents. In 2014 Michael worked to set up one of the UK's first CrowdFunding platforms and as head of Operations and Compliance oversaw the first successful direct FCA authorisation of a platform for both Debt and Equity-based crowdfunding. Michael continues to work as a consultant as has just set up a new brand "Westbourne" to pull together a number of offerings in the risk management space.

You can contact him via LinkedIn: https://www.linkedin.com/in/michael-walford-williams-2302a78a/

Tämä jakso on lisätty Podme-palveluun avoimen RSS-syötteen kautta eikä se ole Podmen omaa tuotantoa. Siksi jakso saattaa sisältää mainontaa.

Jaksot(368)

Gerald Ashley & Paul Craven on Statistics, Spreadsheets & Scam Artists

Gerald Ashley & Paul Craven on Statistics, Spreadsheets & Scam Artists

What do Statistics, Spreadsheets & Scam Artists have in common? They're all topics that my guests on this episode, Gerald Ashley & Paul Craven discuss as they explore how we make decisions. Both Ger...

20 Touko 202146min

Professor Benjamin van Rooij on The Behavioural Code

Professor Benjamin van Rooij on The Behavioural Code

Why are many of the laws & regulations that are put in place, either ineffective or counter-productive? How can we make them more effective?That's the question that my guest on this episode, Professor...

13 Touko 20211h 7min

Hans Læssøe on Strategic Risk — Part Two

Hans Læssøe on Strategic Risk — Part Two

How can companies be better at managing the strategic risks they face in an uncertain world?This episode is part two of my discussion with Hans Læssøe on Strategic Risk. If you haven’t yet listened to...

11 Touko 202144min

Hans Læssøe on Strategic Risk — Part One

Hans Læssøe on Strategic Risk — Part One

How can companies be better at managing the strategic risks they face in an uncertain world? My guest on this episode Hans Læssøe, spent over 35 years working for Lego. He held a variety of roles with...

6 Touko 202143min

Dr Ali Fenwick on Clubhouse - what is it & why should you care?

Dr Ali Fenwick on Clubhouse - what is it & why should you care?

What is Clubhouse and why should you care? Clubhouse is a new(wish!) social media network that is focused on live audio content. The audio element isn’t the only thing that differentiates Clubhouse ...

2 Touko 202159min

Dr Grace Lordan on Thinking Big - how Behavioural Science can help us plan for the future

Dr Grace Lordan on Thinking Big - how Behavioural Science can help us plan for the future

How can Behavioural Science help us to better plan for the future? That's the subject of a new book by Dr Grace Lordan, who is my guest on this episode. In Think Big: Take Small Steps and Build the ...

29 Huhti 20211h 1min

Derek Rae on what football can teach us about decision-making

Derek Rae on what football can teach us about decision-making

What can football teach us about human decision-making? That’s what ESPN commentator and expert on the German Bundesliga Derek Rae, helps me to explore on this episode.Even if you’re not a sports fan,...

25 Huhti 202157min

Michele Wucker on You Are What You Risk

Michele Wucker on You Are What You Risk

What’s the biggest risk you’ve ever taken?The answer to that question, will tell you a lot about your own Risk Fingerprint. That’s the term that my guest Michele Wucker used to describe our individua...

21 Huhti 20211h 3min

Suosittua kategoriassa Tiede

rss-mita-tulisi-tietaa
rss-poliisin-mieli
tiedekulma-podcast
docemilia
rss-tiedetta-vai-tarinaa
utelias-mieli
rss-duodecim-lehti
rss-lapsuuden-rakentajat-podcast
rss-lihavuudesta-podcast
filocast-filosofian-perusteet
rss-duokkari-ekstra
rss-laakaripodi
rss-metsantuntijat-podcast
rss-totuuden-liepeilla