September 12, 2009 Chris Voss on FOX Discussing Annie Le Case
  By admin
 

 
Insite Security  
   
December 14, 2009 Chartis Introduces Personal Security Services For Policy Holders
  By admin
 

Chartis Introduces Personal Security Services For Policy Holders

Insurance Business Review

December 8, 2009

Chartis has introduced personal security services from its Private Client Group. Two complimentary resources, emergency preparedness services and access to Insite Security, have been introduced to supplement its group’s property and liability insurance offerings for high net worth individuals and families.

The company said that the offerings are for policyholders with complex exposures resulting from worldwide travel; private home staff; multiple residences; yacht ownership; or extensive collections of art, jewelry or cars. Emergency preparedness services reduce threats to family safety, security and personal wealth through activities such as evacuation and communication planning, home security assessments, personal liability assessments, and crisis management.

According to Chartis, the policyholders may be referred to a network of third-party vendors to assist with plan implementation. Eligible policyholders can receive a one-on-one, at-home consultation followed by an individualized report outlining potential vulnerabilities and customized solutions; proposals for long-term security; and ongoing security training for staff and family.

 
Insite Security  
   
December 14, 2009 Travel Security: Where Is the Exit?
  By admin
 
 
Insite Security  
   
December 14, 2009 Kobe Bryant Confronted with Neighbor’s Home Invasion
  By Amram Migdal
 

The LA Times reported last week that star basketball player Kobe Bryant of the Los Angeles Lakers did not attend a team shoot-around because of a home-invasion robbery at the house of a neighbor in his community. Apparently, a SWAT response resulted in the arrest of three people after a standoff at the home of one of Bryant’s Newport Beach, CA neighbors, while two suspects were still at large. Four of the suspects were apparently armed with handguns.

In this case, Bryant himself was not the target of the home invasion, although high-profile individuals are often tempting for criminals because so much information about their intended victims is available in the public domain. The home invasion took place inside a private gated community, which should prompt Bryant and the other residents to consider whether they should strengthen the security posture of their community.

 
Insite Security  
   
December 14, 2009 Where Is the Exit? Avoiding the Trouble That Awaits When Traveling
  By admin
 

Former Special Agent of the U.S. Secret Service and Emergency Medical Doctor Offer Expert Advice on Keeping Your Family and Employees Safe While Traveling

What: With the winter travel season in high gear, what dangers does travel pose for you and your family? For your employees? How would you escape a burning hotel? What would you do if an earthquake hit your vacation spot? Which medical supplies should always be with you while traveling? Security expert Christopher Falkenberg and Dr. Daniel Carlin will answer all of that and more in their latest webinar on travel security.

When: Wednesday December 9, 2009, 11:30 a.m. ET

Who: Christopher Falkenberg, Founder and President, Insite Security

Daniel Carlin, MD, CEO, WorldClinic

Where: ADVANCE REGISTRATION IS REQUIRED!

Webcast registration: To register for “Where is the Exit? Avoiding the Trouble that Awaits When Traveling” please visit https://www2.gotomeeting.com/register/244943338

Details: The Travel Security Webinar is part of a free ongoing series of security-focused educational events hosted by Insite Security. Founded by former Secret Service agent and litigator Christopher Falkenberg, Insite Security is a full-service security and risk management agency for corporations and high net worth individuals. WorldClinic, founded by Dr. Carlin, provides 24/7 personal telemedical care and consultation, detailed destination medical research, portable prescription medical kits, a 24/7 electronic medical record archive and rapid physician-to-physician second-opinion referrals for any serious or complex illness.

 
Insite Security  
   
December 14, 2009 Chartis Expands Personal Security Services for High Net Worth Clients
  By admin
 

Chartis Expands Personal Security Services for High Net Worth Clients

Insurance Journal

December 8, 2009

Chartis is offering expanded personal security services from its Private Client Group. The insurer has introduced two complimentary resources, emergency preparedness services and access to Insite Security, to supplement Private Client Group’s property and liability insurance offerings for high net worth individuals and families.

The new offerings, which are in addition to existing risk management services designed to reduce the likelihood and severity of property damage, as well as maximize safety, are designed for policyholders with complex exposures resulting from worldwide travel; private home staff; multiple residences; yacht ownership; or extensive collections of art, jewelry or cars.

Emergency preparedness services help reduce threats to family safety, security and personal wealth through activities such as evacuation and communication planning, home security assessments, personal liability assessments, and crisis management. Consultations, either by phone or in person, are conducted by Private Client Group’s specialists who have backgrounds in personal and corporate security. The consultations can cover lifestyle risks, such as how often one travels, who has access to the home and the safety of children away at school; strategies to handle an incidental house fire or community-wide emergency; and personalized emergency action plan development.

Policyholders may be referred to a network of third-party vendors to assist with plan implementation. A 24-hour emergency preparedness and response hotline is also provided.

Private Client Group also has partnered with Insite Security so that policyholders can receive a one-on-one, at-home consultation (followed by a report outlining potential vulnerabilities and customized solutions); proposals for long-term security; and ongoing security training for staff and family.

 
Insite Security  
   
December 15, 2009 Italian Prime Minister Silvio Berlusconi Assaulted; What Security Was in Place?
  By Christopher Falkenberg
 

The attack on Silvio Berlusconi reveals some weakness in Carabinieri security. First is the importance of distance. Distance equals time in an attack, and there wasn’t much distance between Berlusconi and the attacker on the rope line where he was accosted.

A more important issue is the crowding around the car and the apparent difficulty of getting the protectee into the car safely. A number of questions come to mind—was this an impromptu event? Was any security advance conducted? Was there any screening of the people in the rope-line area waiting to shake hands?

Assuming the statuette that was used as a weapon was non-metallic, it is possible that a screening process would have detected the assailant by sensing his affect. Media reports indicate the subject is mentally ill—were there signs of this illness that could have been observed by an attentive screener? How would the subject have responded to a question about his mood, his reason for being there or his attitude towards the prime minister?

I think the lesson is that effective security is concentric and redundant, relying on anticipation of emergencies and multiple layers of preparation and protection in order to prevent them.

 
Insite Security  
   
December 17, 2009 Supply Chain Security Threats: 5 Game-Changing Forces
  By admin
 

Supply Chain Security Threats: 5 Game-Changing Forces

CSO

December 16, 2009

By LAUREN GIBBONS PAUL

As any CSO knows, it’s not enough to mind your own business. You have to look after your business partners as well, across all links that connect to your supply chain—whether that chain is physical or virtual. And that goes double in times of rapid change and high stress.

“The threat environment is constantly changing,” says Ryan Brewer, CISO for the Centers for Medicare and Medicaid Services. “Sometimes it’s hard to put your finger on what’s most important.”

Who would have thought three years ago that piracy on the supply chain would be such a big concern? Sometimes the big worry is terrorism, sometimes it’s natural disasters, lately it’s malware. Here are the top five developments CSOs say have the biggest potential to wreak havoc on their supply chains.

No. 1 Game-Changing Force: ‘Black Swan’ Events

As Nassim Nicholas Taleb explained in his 2007 book of the same name, the term “black swan” refers to an event that is high-impact, hard to predict and rare. Black swans need not be negative (as in the case of 9/11) and can present times of great opportunity, but CSOs rightfully spend their time worrying about the former scenario.

When it comes to the supply chain, black swan events can include everything from disastrous weather to global pandemicto terrorist attacks. The problem is, if you prepare for the worry du jour, you may leave yourself exposed on other fronts. Case in point: avian flu. Warned that a large-scale outbreak of Asian bird flu would put supply chains at risk, global businesses braced for the worst. Executives discussed how the supply chain might be affected if the flu broke out in China. Their plans rested on transporting and storing materials in other places around the world.

Then, early this year, H1N1 flu broke out in Mexico and spread quickly to unexpected regions like Australia. “Companies had to immediately reassess their plans because they were based on specific scenarios,” says Adam Sager, senior manager of business continuity consulting at Control Risks, a security consulting firm in Washington. This was a major wake-up call. “Companies realized they needed to better prepare for unexpected events and increase their knowledge of how their organizations could be impacted. If something is emerging on a global basis, they need to act before it affects their supply chain,” says Sager.

When a crisis hits—no matter where on the globe—you need to be able to understand and assess the situation using firsthand country- and location-specific information, says Sager. And you need bi­directional communication between crisis managers and the locale where the event is occurring. Sager notes that companies are discovering gaps between their crisis plans and their operations.

“They had security management and crisis management plans in place, but the missing link was integrating them with the business so people around the world could understand management’s position regarding critical things such as uptime, issue resolution and who’s responsible,” he says. This type of information is often not conveyed to the field in advance, a crucial error. Management needs to empower local decision-makers in advance to take action quickly to mitigate damage if certain conditions are met.

The plans have to address not just key supply chain nodes and specific scenarios that could occur, but also emerging security vulnerabilities. “That is a different mind-set and way of planning,” Sager says. “The security department has to come together with the operational/financial side of the business,” looking at all aspects of the supply chain, including where the different components are located and alternative sourcing arrangements. Sager puts his clients through tabletop testing, in which executives sit in a conference room and go through a scenario point by point with the key decision-makers, reviewing how they would respond.

Marc Siegel, commissioner for the ASIS International Global Standards Initiative, is leading the charge to develop an ISO standard for supply chain resilience. ASIS has already published SPC.1, its first organizational resilience standard, which it expects will be ready by the end of the year. “We think standards are the answer for dealing with [black swans],” Siegel says. “Companies have to develop a comprehensive [supply chain resilience] strategy because their resources are limited. This allows you to look at the full picture, rather than just separate out the different things.” For example, a strategy to prevent terrorism might work against piracy or help during an earthquake as well.

Organizations need to approach risk from a holistic standpoint, Siegel adds. “The problem with the risk du jour is that the likelihood of it happening varies so greatly between organizations that it can divert your attention away from doing a comprehensive risk assessment.” In short, it can make you take your eye off the ball.

No. 2 Game-Changing Force: The Rise of Malware

Information security matters also weigh on CSOs’ minds, though they are not as visibly related to the supply chain as physical security is. An organization (and therefore its supply chain) can be brought low by an attack on its information network as surely as it can be hurt by an attack on its cargo. Many CSOs say they are worried about botnets; two of the most pressing threats related to botnets are spam/phishing attacks on employees and the possibility of a resurgence in the denial-of-service (DoS) attacks that first appeared 10 or more years ago.

Ed Amoroso, CISO of AT&T, blames rampant technological complexity for the rise in malware. “The primary root cause for almost everything we deal with—commercial customers and everything—is complexity. The computers and networks that people set up and use have become way too complicated,” says Amoroso. Since no one knows exactly where all the connection points between systems lie, it is easy for wrongdoers to exploit them. “I’ve read that 95 percent of the spam that is floating around is botnet-originated,” he adds. “It’s all about complexity—people not knowing how to stop it on an individual, corporate and information security level.”

Like Amoroso, Joonho Lee worries a lot about the advent of integrated DoS attacks. “DoS used to be about large-volume traffic hitting your network,” says Lee, an officer for the National Incident Response Team and assistant vice president at the Federal Reserve Bank of New York. “Now, there are so many different types of attacks. It’s not just flooding you with traffic anymore. It’s flooding you with traffic that you can’t block.

“We have all the DoS protections, but I’m very skeptical about them always working. If you get hit by a 40-gig-per-second pipe, it’s going to knock you out, either your network or your provider,” says Lee. “The hackers are leveraging hundreds of thousands of machines. DoS is definitely back on the horizon.”

Rena Mears, a partner in security and privacy services for Deloitte & Touche, believes the malware supply chain is itself approaching maturity. “You go back a decade, and it was a few people doing mental gymnastics. Then we moved to an era where it was monetized [via phishing and spam]. The next step was the massive quick hit—equivalent to a bank robbery. Now we are seeing something much more insidious,” says Mears. Malware and its perpetrators are growing increasingly sophisticated.

Rather than carrying out the massive hit-and-run DoS attacks of the past, today’s malware seeks to sustain itself at a relatively low level, similar to the way a parasite survives in nature. “This is more of a constant-stream-of-revenue strategy. The malware agent can live below the organization’s pain threshold, but it siphons off information to compromise intellectual property or scoop up credit card information,” Mears says.

Lee, for one, does not believe that network service providers can adequately protect against the threats posed by new-breed malware. Amoroso of AT&T acknowledges that the situation is difficult, saying only that, like other providers, AT&T has developed multiple strategies for handling new-breed DoS attacks. He believes that the increasing popularity of thin clients will help thwart these attacks because they are simpler, with fewer moving parts to attack.

No. 3 Game-Changing Force: Economic Downturn

It is axiomatic that crime increases as the economy deteriorates. A number of threats—to physical security as well as information security—have become more pressing in the past year or so. Many CSOs expect the associated threat pool to continue to widen. Although the economy is forecast to improve slowly in the coming year or two, many experts expect the reshaped landscape will not necessarily signal a return to prosperity for all, or even most, of society. Some people will be desperate and therefore prone to desperate actions.

As the economy continues to falter, more and more people are losing their jobs, which often means losing their health insurance as well. Ray Biondo, CISO at Health Care Services (which runs four Blue Cross Blue Shield plans in Illinois), fears ongoing economic problems will cause wide-scale employee layoffs, which the company has so far managed to avoid. He fears the coming of a national healthcare plan could have the same effect. Biondo finds himself worrying more about insider threats to information and physical safety than he did a few years ago.

“I worry about internal physical threats and threats to our data. People become very anxious, and data leakage becomes an issue,” says Biondo. He believes he has taken all available measures to protect information and physical security, but he remains uneasy. Chris Falkenberg foresees increased threats to personal security, including the kidnapping of business executives abroad and attacks on high-net-worth individuals. “CSOs will have to deal with these things because they have to protect their executives,” says Falkenberg, president of security services firm Insite Security. He also worries that personal kidnapping could become a problem in the United States, though the country does not have the widespread governmental corruption that typically allows such activities to take root. He believes most CSOs do not have the internal expertise to handle this type of threat.

Lee, of the Federal Reserve Bank, believes emerging threats such as malware and attacks by insiders require stronger communication between the information security and physical security groups, as well as any other departments that get involved when there is a problem, such as legal. “There needs to be better teamwork. It’s not just training,” he says. “Even if these groups do speak to each other, they usually would just offload the case onto the other side. Everyone involved needs to know the logical next steps. There needs to be recognition of joint ownership of the problem.”

No. 4 Game-Changing Force: Data Explosion

Data is now so ubiquitous and so pervasive that people lose sight of it. Even many manufacturers today are so massively involved in data, they never think of themselves as anything other than purveyors and users of information. The level of integration companies have with their processes and business partners is something they could not have contemplated just five years ago, says Mears. The explosion in both data itself and the practice of sharing data outside organizational boundaries presents a number of different kinds of risk.

Companies of all types and sizes share infinite amounts of information with business partners. This data is constantly updated and flows back and forth. “This is a two-way chain,” says Mears. “That means you are replicating data. We used to say ‘defend the perimeter.’ Many companies don’t even have a perimeter anymore.”

Data and information are assets, but executives don’t know what they have, where it all is and who is (and isn’t) protecting it. “It is very difficult to secure data when you don’t know exactly what it is and who you’re sharing it with and no one is on the hook for those decisions,” says Mears. This reality necessitates a risk-based approach to data protection. “You cannot protect all data anymore. Not all data assets are worth the same amount. You have to be sure there is a return on that data asset, just as you would with any other asset. You should provide security commensurate with the value of the information asset,” she says.

Deloitte is advising its clients to develop a more focused response to information security. In a highly integrated global environment, companies understand that their core intellectual property is at risk, but they cannot afford to protect the daily flotsam that is part of business as usual. “Data protection is now a C-suite and a board-level issue. Executives are beginning to think about how to maximize the return on their data assets,” says Mears.

No. 5 Game-Changing Force: Regulatory Burdens

Since Sept. 11, 2001, and the passage of the Sarbanes-Oxley Act in 2002, regulatory activity has been high in virtually every industry. This is certainly true in the food/beverage/agribusiness industry, due to the obvious importance of maintaining a food supply that’s safe from contamination, whether malicious or innocent. H.R. 2749, the Food Safety Enhancement Act of 2009, just passed. And Walmart made news in 2008 when it required all of its food suppliers to comply with the stringent GFSI (Global Food Safety Initiative) standard. According to Rick Shanks, this standard above all mandates traceability within the food supply chain.

“Many food processors are not prepared to deal with the level of traceability required by the regulation,” says Shanks, national managing director of Aon Risk Services, the risk advisory division of Aon Corp. Traceability requires a high level of supply chain visibility, which has not always been available. That makes it more difficult to mitigate a food contamination incident such as salmonella in peanut butter or listeria on deli slicers. “When you have a food event, you have to be able to trace it back to its source,” says Shanks. Aon recently announced a service offering that helps food processors and producers achieve the necessary visibility.

A related force reshaping supply chains in the food and beverage industry is consumers’ increasing demand for visibility into the provenance of their food. Produce and seafood have been labeled to indicate origin for a few years now. The current “locavore” trend—which emphasizes eating locally grown food—stems in part from consumers’ beliefs that food grown and consumed nearby is less likely to become contaminated. Here, supply chains are shedding links to help allay consumer fears.

 
Insite Security  
   
January 6, 2010 How can pro sports league owners, player agents and managers prevent another Plaxico Burress or Gilbert Arenas incident?
  By Christopher Falkenberg
 

For more than 4 years I was one of the most highly trained personal body guards in the world. Serving as a United States Secret Service Special Agent. It was our job to ensure that the President of the United States (POTUS) was protected from any and all physical threats.

When I was guarding President Clinton it would have been crazy for him to carry a weapon on his person, or to have an untrained member of his inner circle carry a gun. The President of the United States is arguably the most valuable individual in the entire world, and his employer, the Government of the United States, is mandated to protect this highly-valued, very public, employee and not leave it up to him to protect himself.

Reading the stories about Gilbert Arenas carrying multiple firearms into his workplace or remembering back to the Plaxico Burress incident where he accidentally shot himself at a night club, it struck me as insane that the owners of NFL, MLB or NBA teams do not, as a matter or course, provide highly professional protection services to their players when off the court/field. Owners spend tens if not hundreds of millions on their players each year and do a fabulous job of protecting their athletes (investments) and fans at sports stadiums and fields, but once their players leave “the office” the teams cease to provide protection.

Sure most teams have training seminars for athletes on how to protect themselves, their loved ones and property. But, for the most part, teams leave it up to the athletes to protect themselves. How many do this is either through hiring personal “body guards” from their close knit group of untrained friends or by buying and carrying a weapon (usually legally). These posse-based security solutions rarely solve the problem. A security professional is trained to help avoid dangerous situations, to diffuse conflicts and to keep their protectees away from danger. Having your best friend from home carry a Glock is a recipe for trouble.

Exxon/Mobile provides 24-hour security for its CEO, Rex Tillerson, why wouldn’t the New York Giants provide the same type of security for Plaxico, or the Washington Wizards for Arenas?

 
Insite Security  
   
March 1, 2010 Emergency Planning for Natural Disaster
  By Christopher Falkenberg
 

The earthquakes in Haiti and Chile, as well as other recent natural disasters, raise questions regarding disaster preparedness for travelers. Much thought is given to man-made disasters such as terrorism, but relatively little to natural and unpredictable catastrophes. It is important for the corporate security manager or other c-level executives to embrace a holistic approach to risk mitigation including natural disasters and their results.

In the recent earthquakes, steps such as redundant communication systems and basic survival supplies could have helped travelers tremendously. Issuing satellite phones, like we do for Insite’s clients travelling to remote and less developed locales, would have helped tremendously in Haiti for example. Similarly, preparing travelers with basic medical supplies and the means of contacting a physician can also be of great help in emergencies where resources are stretched. Our partnership with World Clinic (www.worldclinic.com) provides our clients with a concierge medical solution that is prepared for disasters like the earthquakes of 2010 and other disasters we’ve witnessed over the past few years.

Lastly, where possible, security advisors should consider things such as building safety, construction standards and building codes in recommending hotel choices for travelers, as a variety of emergencies, such as fire, flood or earthquake, may make these judgments very important.  Prior to the Haitian earthquake we would have scoped out the hotels our clients were planning on staying in to ensure the soundness of their construction and would have planned for and provided evacuation planning.

Travel security goes well beyond the hiring of a driver or a physical security presence when traveling overseas; it requires a deeper level of thinking and preparation than can usually be handled in-house. Working with experts in this field can help mitigate problems when they arise thanks to proper planning and the ability to execute in difficult situations.

Has anyone recently dealt with a travel emergency? Be it foreign or domestic? Feel free to post and discuss!

 
Insite Security  
   
 
 
 
Home About Us Family Security Corporate Security Investigation Services Special Services Media Center Contact Us © Insite Security, Inc. All Rights Reserved