How investigators work to combat data theft
CSO - In almost two decades of work in the financial services industry, Brad McFarland has spent most of that time heading up fraud investigations. McFarland, currently director of corporate security with The South Financial Group, a South Carolina-based financial services holding company, is also responsible for the organization's physical security and loss preventions in addition to fraud investigation.
Over the course of his career, McFarland has seen drastic changes to the emphasis and importance placed on fraud. In the past, said McFarland "Many institutions did not employ fraud investigators. Fraud was a cost of doing business."
But times have changed. Thanks not only regulatory requirements, the reputational pressures a financial firms faces in an age of rampant data leakage and identity theft have now made stopping fraud a main priority. And that means the way investigations are conducted have evolved, too. McFarland gave CSO a break down of how fraud investigators, corporate, physical and information security now come together in a combined mission to stay one step ahead of the bad guys.
See also: Fraudsters bank on business accounts: How to protect your funds online
CSO: As Director of Corporate Security you lead fraud investigations within the organization. How do you draw line between fraud and corporate security? Brad McFarland: Those processes are linked. Each security discipline must hold hands in order have an effective security program. The security program impacts fraud prevention, the safety of your employees, the security of institutional data, and customer information. A program needs to address the security of your facility and maintain or keep in-check reputational risk. As part of a global security program it is important to institute an effective training program for respective security disciplines.
I don't see any real barrier between those groups anymore. It's necessary that we maintain a strong, unified partnership to combat the issues we are seeing now across the financial services industry.
Of course professional certifications are important and they play a valuable role in expanding one's knowledge base. Certifications also have a special value in industry and they can represent advantages to employees that obtain a relevant designation.
However, from a broad perspective, there are a few basic steps that all security leaders should employ: First, and foremost, have a basic understanding of accounting principles. Assist in the implementation and utilization of sound accounting practices from a risk management perspective you should trust but verify accounting controls. Second, make sure that you are aware of the legal regulations that govern your field. Third, one simple guideline:communication. Effective communication plays a strong part in acquiring desired results. And fourth, implementation of an effective investigation processes; to include interviewing of witnesses, documentation, and analysis tools.
- 10 Hot Big Data Startups to Watch
- 11 Unique Uses for Google Glass, Demonstrated by Celebs
- How to Export Your Google Reader Account
- How to Better Engage Millennials (and Why They Aren't Really so Different)
- Telltale signs of ATM skimming
- 20 security and privacy apps for Androids and iPhones
- Big screen con artists: 7 great movies about social engineering
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Mobility Outlook Report - Smart Mobility for Better Business With Kony's enterprise mobility solutions, you mobilize quicker and smarter. The KonyOne Platform provides true 'write once, run everywhere' capability that extends your...
- Mobile Application Management and Today's Enterprise From discovery to distribution, development to deployment, mobile application management (MAM) is a must-have. But what does it take to manage your company's...
- How Application Aware Networks Make the Impossible Possible Realizing Business Value and ROI with Application-Aware Network Performance Management
- Enabling Ubiquitous Visibility in Virtualized Environments Enterprises are rapidly adopting virtualization for dynamic service delivery and service management agility. IT challenges already exist in virtual environments and will only...
- Innovation in the Cloud Managing HR and financial information in the modern business requires efficient business practices and technology.
- The Mobile Enterprise Today's mobile enterprise requires important data anywhere, anytime. And with mobile enterprise applications, IT needs to offer simple, easy-to-use apps that employees will... All Applications White Papers | Webcasts