Showing posts with label riskmanagement. Show all posts
Showing posts with label riskmanagement. Show all posts

2026-01-09

Boom

Image from Unsplash

Surely no one thought: come on, it’s the last time it’s allowed, let’s do something extra dangerous with fireworks. This blog is not the place for a debate for or against fireworks, but from my perspective there are a few interesting observations to be made. So here we go, blasting our way into the new year once again!

Even though it will not have been intentional, this time it was worse. Let’s start with some figures. There were 1,239 fireworks-related injuries in the Netherlands – no less than 7% more than during the previous New Year’s Eve. More than half of the victims were under the age of twenty. Many children were seriously injured when they tried to relight unexploded fireworks. About half of all victims did not even set off the fireworks themselves; they were merely bystanders. Emergency departments were 29% busier, treating 474 people. GP out-of-hours services were slightly quieter; with 765 patients, they saw 4% fewer cases than last year. One third of the injuries involved eye damage. Fourteen children lost a hand or finger(s), almost all due to illegal fireworks, which accounted for just under half of all injuries. And then there were those two fatalities, too.

All this suffering could, of course, have been easily prevented. All it would have taken is a low risk appetite. That term is very common in my profession, but not so much in daily life. Why is that? Because in a business environment you can usually reason quite rationally about the risks you are prepared to accept, whereas people who set off fireworks do not. They do not think in terms of degrees of risk; caught up in their enthusiasm, they think only about the intended effect. A child certainly does not think: oof, this is a Cobra with a short fuse, what is the likelihood I’ll lose a hand if I light it? Adults do not think in percentages either. At best, they judge it to be too dangerous and refrain from doing it. And if they do light the fireworks, they are implicitly convinced that all will go well. In that way, it is reduced to a binary decision, whereas in reality setting off fireworks still involves a very significant risk.

And what about public information campaigns? In the past, we had a slogan which translates into You’re a fool if you fool around with fireworks. It was witty (even more in Dutch) and it carried a message. Nowadays the message has to be more forceful, and we see mutilated hands on television. But if there are so many young victims, you would also expect information campaigns specifically aimed at this target group. Were there any? Yes, partially. Primary schools could order a free lesson package. That required them to take action themselves, and only about a quarter of all primary schools did so. You might also expect campaigners to use the media where young people actually are, such as TikTok and Instagram. However, there were no specific actions on those platforms. Municipalities and police forces were active there, but honestly — which teenager follows those kinds of accounts?

In my own profession, awareness is difficult as well. After all, you are conveying a message people would rather not hear. Just look at it: fireworks are beautiful and links are there to be clicked. And then along you come, telling them to be careful. Come on, it can’t be that bad, everyone does it.

With cybersecurity, things are slowly moving in the right direction. People understand that they have to be careful; they realise that criminals are lurking, ready to cause digital harm. Hmm, could the difference with fireworks safety have something to do with that? With the presence of a malicious actor? That element is missing when it comes to fireworks. That risk has just two components: the fireworks and the lighting. There is no other party, no enemy. Yes, that almost certainly has to play a role.

From the next New Year’s Eve onwards, a nationwide fireworks ban will apply in the Netherlands. I have serious doubts about whether it will work, because enforcing the ban will be difficult. Border checks in December will not stop the true fanatic, who has already stocked up much earlier. Responding whenever a bang or rocket is detected will rarely work either – how do you determine the exact location? No, if we truly want to reduce the number of victims, we will have to make sure (if necessary via TikTok!) that people – especially children – start to understand that risk management also plays an important role in our daily lives. From that perspective, the message becomes: hands off fireworks — or hands lost because of fireworks.

 

And in the big bad world…

 

2024-08-23

Alarm at the pool

 

Image from Pixabay

In the past, 100 to 150 children drowned every year in France. A significant portion of these tragic accidents occurred in private swimming pools. That is why legislation was introduced in 2004 requiring safety measures. The number of annual drownings in private swimming pools fell to 20-50.

Nowadays, French private swimming pools must have a fence, cover or alarm system. During the holidays we encountered the latter, which was intended to alert parents if a child falls into the water. The owner of the house had explained to us how it worked: hold down one button on the remote control, then press the other and voilĂ , the alarm was turned off and the pool was open for business.

If you forgot to turn it off and jumped into the water, you were treated to a loud alarm sound just a moment later. Then someone had to quickly grab the remote control and press the buttons. It soon became apparent that this did not work properly: only after several attempts did the alarm go silent. It was unclear what was wrong. A light came on on the remote control, so apparently the batteries were still good. The buttons were soft and vague to the touch, so you tended to press harder and harder. Perhaps the circuit board under the buttons had become damaged over the years. Anyway, this couldn't go on any longer.

Fortunately, there was an alternative. There was a magnet in the garage with which you had to touch the alarm box in the swimming pool to switch off the alarm. That worked flawlessly and saved us from a lot of hassle. Although sometimes things still went wrong, because if no one had been in the pool for fifteen minutes, the alarm was automatically activated. If you didn't think about that at the next refreshing dive, you were still in trouble.

The lights on the alarm didn’t really help, either. There were two of them: one red, the other green. If the green light was on, you were not allowed to swim, and if the light was red, you were all right. From the alarm’s point of view, I get it: if the alarm is on, the swimming pool is protected, and therefore the green light is on. Alarm off means unsafe, so red. But from the user's point of view, this is not convenient, because one usually crosses the road when the light is green.

No concerned neighbors showed up on the doorstep in the event of a (false) alarm. They simply lived well out of earshot. But what would this be like in a more densely built-up environment? I don’t think that the entire neighborhood would show up with swimming rings and rescue hooks at the first beep. Only if the alarm continued, a slightly irritated neighbor might perhaps come and take a look. But isn't it already too late then?

And yet the legislation appears to be quite effective. I think that a sturdy fence with a child-resistant lock works best - preventive measures prevent misery, while detective measures only signal that there is a (possible) problem. Prevention is better than cure; not being able to fall into the pool is better than having to be fished out half drowned.

I could make a clever link to my field of expertise here, but you get the idea yourself. Automatically throwing away a phishing email before it ends up in your inbox causes less hassle than clearing up the mess after you have clicked on that link. Blocking access to a rogue website is more effective than having to respond to a malware infection. Not asking your customer for data that you don't actually need is more sympathetic than having to inform your customer that their data have been leaked - yes, sometimes not doing something is also a measure.

Of course, this is not a disqualification of all those security systems that signal that something may be wrong. We really need that too. Defense in depth means that you build up protection in layers. If someone has left the pool gate open, an alarm system can still prevent a lot of grief. Just as it is very important that you recognize phishing and handle it correctly - in case the security systems fail to catch it. It's a shame that French legislation only requires one measure.

 

And in the big bad world...

 

2024-03-29

Symptom relief

 

Image from Pixabay

It's the perfect time of year to catch a cold. During the corona period we skipped this annual ritual, because having little contact with other people and hardly going anywhere, there was little chance of encountering a cold virus. But this year it’s business as usual for my family.

No matter how harmless a cold is for otherwise healthy people, we all know that it can make you quite miserable. One stumbles to the medicine cabinet to find relief. Nasal spray, cough syrup, paracetamol – all are standing by to relieve your complaints. Plus some home remedies, such as steaming, drinking tea with honey or licking popsicles.

What is so unfortunate about all these remedies is that they only treat the symptoms of the disease. The nasal spray allows you to breathe more freely for a while, the ice cream numbs your throat a little and the paracetamol helps against pain and fever. On the website of the united Dutch physicians, paracetamol is ignored completely on the page about colds ("Medication is not necessary for a cold"). Completely unnecessary side note: I’m not giving medical advice in this blog post.

Why is there no medicine or vaccine against a disease that is so common and causes a lot of discomfort? Seems like a gold mine for the pharmaceutical industry to me. But it turns out that there are so many viruses that can give you a cold that it’s simply a hopeless task. Moreover, those viruses mutate quickly; a vaccine developed today will be worthless tomorrow. By the way, research is still being done, especially because people with asthma can become very ill from a cold.

Of course, symptom relief also takes place outside the medical domain. For example in my own profession. To stay close to the common cold: how about a virus scanner? This relieves the complaints we have from viruses. Not like a nasal spray for a cold, but preventative: you either become infected or you don't. The relief lies in the number of infections you have to deal with. But it doesn’t contest the phenomenon of computer viruses as such. That is precisely why it is important to equip as many ICT resources as possible with those digital face masks.

The step from symptom relief to the placebo effect is not that big. If I have a sore throat and therefore eat a popsicle, I almost feel obliged to feel less pain for a while, while my mind really doubts the effect. That's harmless, but it gets bad when I think that a popsicle is also the right treatment for, for example, severe, persistent stomach pain. For some ailments you simply have to go to the doctor.

There are plenty of placebos in information security. For example, the security of a system does not really improve by carrying out a risk analysis. Only if you act upon the results of that analysis by taking measures, risks will be reduced. Another form of risk treatment is risk acceptance, but it is clear that this does won’t benefit the security of the system - no matter how legitimate acceptance may be in a certain case.

Compliance with regulations is another one. Quite a few organizations do all kinds of things because they have to. Meanwhile, no computer has ever become more secure because someone has written a mandatory document. Only when the content of that document comes to life we can make progress. Unfortunately, it often stops at the signing of a document – but the auditor will be proud of us! (I’m probably – hopefully! – wronging a friendly professional group with this comment.) Yes, I also do all kinds of mandatory stuff, but it’s always based on my drive to optimize security. The fact that I also get a green tick on a checklist somewhere is a bonus, but it should never be the goal.

To catch a cold, you need a virus. You won't catch a cold from sitting in a draft or going outside with wet hair. Likewise, nothing goes wrong with a computer due to potential risks. Problems only arise when a risk actually manifests itself. But just as I keep a little more distance from a sniffling family member, a list of risks relevant to your systems helps you avoid them.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

2024-01-19

Stairway to poetry

 

Image from author

The Hague, Ministry of Justice and Security. From the top floor, the 36th, you have a magnificent view of the surrounding area. Even on a meteorologically challenging day like last Monday, with alternating sun, snow showers and strong winds. If you have a meeting here, you have to accept some loss of time due to looking outside. But there is more to experience.

A stairwell in an office building is often boring, because, especially in a high-rise building, hardly anyone goes there. But there, at Turfmarkt, they wrote sayings on the risers of the stairs. The following is written on the stairs between the 35th and 36th floor: Accidents are just around the corner. Happiness is everywhere else.

For people like me, who are professionally concerned with anything that can go wrong, this puts things into perspective, perhaps even more than for 'ordinary' people. We are looking around the corner, searching and picking, while in general we see relatively little serious misery. Yes, there are regular news reports about data breaches, ransomware and DDoS attacks, and criminal phishing actions, but most of the time, they are not disruptive. Even in Ukraine, which has been suffering from war violence for two years now and where the cyber part of the war started much earlier, the digital society is still up and running. It seams unbreakable. So you might think that in general, we don’t go around that corner, but instead we go everywhere else.

Whenever something like this comes up, I like to recall the year 2000, or more precisely: the turn into the new millennium. That is almost a quarter of a century behind us, which means that there is now a working generation that has not experienced this transition. Well, guys, there was a lot of fuss going on, and that fuss had a name: the millennium bug. While you may be reading this blog on your smartphone, which is in fact a pretty powerful computer, it's hard to imagine that computer memory was a scarce resource in the last century. Today a gigabyte is the smallest unit we talk about, but back then it was kilobytes. That makes a difference of six zeros, or a factor of a million. While you can now buy a 64 GB USB thumb drive for less than a tenner, we used to have to make do with 512 KB floppy disks, which you bought in boxes of ten. The next generation, which could store 1.44 MB (more than twice as much!), felt like a major leap forward. When installing an application on your PC, you were a disk jockey: those products came on a stack of floppy that you had to insert one by one. Downloading had yet to be invented.

Storage memory was in short supply, and it was skimped on wherever possible. For example on date fields. Why would you write 1977 if 77 was sufficient? This was common even in the real world: I learned the date format 24-5-'65 at school. The apostrophe indicated the century, but you could just as easily leave it out. In computers it would save you two positions for each date. But as the turn of the century approached, a problem came into view. Suddenly 31 would no longer necessarily mean 1931, but could also be 2031. Computers would choke on this, for example if they had to sort data. Heaven and earth were moved to avert disaster. In the Netherlands, an estimated nine billion euros were spent on this, and worldwide three hundred billion dollars, according to Wikipedia.

When the gunpowder fumes from the fireworks had dissipated, it turned out that very little had gone wrong. Then there was a lot of criticism: did we spend all that money for nothing? I still get quite excited about so much naivety. Why do you think things went so well? Because of that great effort of course! It's as clear as day: there’s a problem, you solve it, danger averted. At this level of abstraction it doesn't get any harder than this.

Back to the stairs of the ministry. That saying is wrong. An accident being just around the corner means that mischief is very likely to happen. The second sentence of the stair writings, on the other hand, pretends that hardly any accidents really happen and that most things go well. The fact that things are going relatively well in the digital society is due to all the measures taken to prevent problems, and to a quick, adequate response if something does happen. The saying on the stairs should therefore read: Accidents are just around the corner. Grab a broom and sweep that corner clean.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2023-02-10

Bus drivers on strike

 

Image from Pixabay

Hilversum was the place where I had to go to last Monday. As befits a good civil servant, I prefer to travel by public transport. Regional transport was on strike this week, but the trains were running normally, it was emphatically stated. Nice. I shouldn't have been bothered by the strike. It turned out differently.

When I travel by train, I always take the city bus to the station. I am a man of definitions; For me, regional transport is transport between places and city buses run in the city – and therefore not in the region. But because I also understand that drivers who work for a carrier that serves both the region and the city are not exclusively city bus or regional bus drivers, I had my wife take me to the station a few weeks ago, when they also went on strike. That turned out not to be necessary: the city buses ran on schedule. My definitions were correct.

So they would also run last Monday, I assumed. At one point at the bus stop, a girl asked me: “Are you going to the station?” I glanced at my watch and replied, "I don't think so." She consoled me by telling me that line 231 would arrive in six minutes. However, that would be too late to catch my train, and moreover, line 231 is a regional bus…

I had to come up with an alternative. At the Mediapark in Hilversum, students of Make IT Work (a retraining program of the Amsterdam University of Applied Sciences) would soon expect me to give a guest lecture; I had to be on time. I calculated my options. I wouldn't make it to the station in time by bike; with the car I had another chance. With big, but careful steps – it was freezing – I returned home, texting my wife what my plan was, so that she wouldn't be shocked when the car suddenly disappeared. She was willing to drop me off too, but then I might have a problem on the way back. I got in and drove off. Traffic lights, that usually show me their red light, were favorable to me for once.

On the way, I pondered my parking options. There are two ways to go in the parking lot at the station: to the left and to the right. Turning left leads to the entrance of the station, turning right leads away from it. Turning right, the chance of a free space is therefore considerably greater – after all, everyone wants to be at the front. But if you park there, you have to walk further. If you turn left and you don't find a spot there, you still have to go to the other side and that means extra time loss. I took a gamble and turned left. My courage was rewarded: there was exactly one free spot, near the entrance. Moreover, it was a place that overlooked the busy road past the parking lot, which I liked very much, because a few decades ago my car was broken into in that parking lot and the radio was stolen (by the way, thanks to an attentive witness, the crooks were caught and I got my radio back). Satisfied, I walked into the station. I reached the platform at the same time as my train and I arrived at my destination in plenty of time. Incidentally, it would not have been disastrous if I had missed this train: My itinerary had a margin, the next train would also have delivered me on time.

It probably takes a fair amount of professional deformation to relate the above to my profession. Since I have quite a lot of that, my adventures from that morning became part of my lecture, its subject being risk analysis. If you look at the above account through that lens, then you realize that risk analyses are not limited to your work as an information security officer: they do not just take place if and when your agenda states that you have to do a risk analysis on that day and at that time and there will be not always a complicated, formal method. Risk analyses are carried out in daily life – usually unconsciously but it happens all the time. You do that too.

Let me explain. My initial decision to take the bus was based on historical data (during the previous strike the city buses did run), from which I deduced that the chances of a running bus were favorable. The decision not to take the bicycle, but the car, was based on the likelihood of catching my train in this way. The fact that I didn't run home but - despite my haste - just walked, had to do with the risk of slipping. Even the text to my wife was risk management driven. Left or right in the parking lot: OK, I admit, that was an irrational guess. But hey, I'm just a human who hopes for the occasional windfall. In risk analyses, the expected consequences of wrong choices also play a role, according to the old formula: Risk = Likelihood x Severity. With all the choices I made that morning, the possibility of missing my train hung over me like the sword of Damocles.

Think of me the next time you have to make decisions. Who knows, it might help you make well-founded choices.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2022-11-04

A day at the zoo

 

Image from Pixabay

Last Tuesday, accompanied by a bright autumn sun, I walked with a teammate through the Dinosaurs department of the zoo in Amersfoort. Crazy, isn't it, that a zoo, which generally collects living creatures, has also furnished a piece of forest with statues of long-extinct animals. Just as crazy as the presence of a playground, by the way. Did you come to watch animals or to seesaw?

If you think our presence there, during working hours, is even stranger, then you have to consider that zoos also have spaces that they rent out for gatherings. And so that afternoon we had a meeting of our organizational unit, the CTO Office, responsible for the optimal and effective use of technology throughout the organization. After a clear talk from our director (the chief technology officer, or CTO) we had to split up into groups to talk about a certain theme. You know the drill: the groups are composed in advance in such a way that you do not sit together with your own teammates, so that you also come into contact with other people. I was, however, in a group of which I already knew two IT architects; one through work, the other through a chat at the coffee machine. The others, a license manager and a contract manager, I knew by sight.

The theme to be discussed te was called: fast, better, safer. Technology must be made quickly available to our employees. Apparently the quality can also be improved a bit and well, the realization that it has to be safer has fortunately also penetrated the higher echelons. In many organizations this means little more than comfortably abstractly shouting that everything must become safer, leaving the workplace behind in a despairing "Yes, but how?" Because the gap between the acknowledgment that it has to be safer and the practical implementation of such an ukaze soon has canyonesque dimensions. Welcome to the field of tension between 'that is not allowed' and 'but otherwise it won't work'.

The fact that they put us to work with this theme shows both guts and the need to actually give substance to it. The first thing we wrote down was that you should not only be fast, better and safer, but also flexible. That is, as it were, the catalyst that lends a helping hand to the other three properties. Flexible in combination with safer means that you do not strive for maximum security, but for optimal security. That also means that you can be more flexible in certain situations – I am thinking of test environments, for example. However, security policies and standards do not provide for this; such documents seem to be blind to the complex environment of a large ICT organization.

This brings us to risk appetite. How much risk is an organization willing to take? A company that produces things with a short time to market will generally have a greater appetite for risk than, say, a government agency. After all, that product has to arrive in the shops quickly and then you can't afford an overly frivolous security overhead. Just look at smart devices such as baby monitors, security cameras and toasters, which turn the Internet of Things into a dangerous mess.

Our conclusion was that we need to differentiate between the risks we face. An inextricable part of this is the unambiguous determination of who is responsible for what. One of the architects wanted to keep that responsibility as low in the organization as possible. I was able to convince him that it should at least lie at the level of a department head, because otherwise self-interest might weigh too heavily: if a team has to achieve a goal, a team manager will generally accept risks more easily. However, risks tend to have a broader impact than one team and must therefore also be weighed in that broader context. Some distance from the work floor helps with this.

Yesterday I spoke to a department head who often deals with risk treatment. We have set up a process that regulates that when someone wants something that is not allowed according to the rules, but is (at that time) necessary to ensure progress, they must write down what that means and what risk the organization runs. And that form must be submitted to the head of department. Because things have been getting out of hand lately, he is actively engaging with his peers to bring about change. In many cases, taking those risks is not really necessary, provided that some effort is made to work on a robust solution. This head of department clearly takes responsibility for security, while not losing sight of the importance of the operation. Because security is also about availability.

Another zoo group, which was also discussing of the 'fast, better, safer' theme, had written down: read the Security (b)log! That is of course a great always-good action.

 

And in the big bad world…

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

Get out of jail

Image: Unsplash "Get out of jail free." If you land in jail and don’t have this Monopoly card, you can pay a fine to get out. Or y...