Presentation is loading. Please wait.

Presentation is loading. Please wait.

MINISTRY OF SOCIAL AFFAIRS AND HEALTH 1 Introduction to corporate security Teemupekka Virtanen Helsinki University of Technology Telecommunication Software.

Similar presentations


Presentation on theme: "MINISTRY OF SOCIAL AFFAIRS AND HEALTH 1 Introduction to corporate security Teemupekka Virtanen Helsinki University of Technology Telecommunication Software."— Presentation transcript:

1 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 1 Introduction to corporate security Teemupekka Virtanen Helsinki University of Technology Telecommunication Software and Multimedia Laboratory teemupekka.virtanen@hut.fi

2 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 2 8. Lecture – Security of management processes Risks in business management How to protect business management processes Storage and handling of cash and valuables

3 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 3

4 4 Public interest Crimes can be noticed and solved when earned money is tried to bring back to legal economy Money laundering Police and tax officials require certain processes to prevent money laundering There are also certain rules to protect weaker participants Eg stock markets and insiders

5 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 5 The function of business management Produces information about state of an organization Takes care of property of an organization Run daily management and paperwork

6 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 6 Information production Long term information Reports, forecasts Help to see where the organization is going Help strategic decisions Short term information Cashflow Balance Prevents sudden shortage

7 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 7 Threats in reporting Reports are false A single piece of information is false Measurement system is false (systematic error) The process is false (calculations) Decisions are false Usually not a security problem

8 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 8 Data warehousing A big barrel of information Information is poured to the barrel by several sensors Intelligent agents gather information from the barrel and produce higher level information The connection between original information and the results is weak

9 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 9 Security procedures Proper management of adding information Check the validity of information before storing it Store origin and quality of information as a meta information Make calculations using several parallel algorithms Ensure the validity of software Version management Parameters

10 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 10 Bookkeeping Logs on business management Who has used money On what and when Makes reports possible Makes inspection possible Source: STUK

11 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 11 Bookkeeping systems Bookkeeping is done using computers Information comes from other systems CRM, production, billing From banks The integrity is very important Information modifying must be impossible Information must be stored several years

12 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 12 Cashflow Cashflow means money coming in and going out from a company Usually happen via bank accounts Several steps and documents are required Bid, order, invoice, receipt Documents and cashflow is a chain of documents

13 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 13 Threats in cashflow Paid a wrong invoice The invoice has been counterfeited (non-existent) The order has been counterfeited (non-existent) Paid money goes to a wrong account Paid a wrong amount of money Paid nothing when should

14 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 14 Security measurements There is a procedure how to manage orders and invoices Only authorized people can make orders Only accepted invoices are paid The chain of accepted documents Only authorized people can transfer money There are always several people in the workflow Prevention of dangerous combination Proper documentation

15 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 15 Dangerous combinations Same person has several roles in the working flow Making an order Accepting the delivery Accepting the invoice Making the payment There are no extra eyes to check if the order was valid and the invoice should be paid Nobody is allowed to pay money to the own account Changing duties The same person in the same duty makes it possible to hide things

16 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 16 Property management Prevents losses caused by Disappearing, stealing, damaging, spoiling, rottening Makes sure that the use of property is as efficient as possible Knows Where the property is located How valuable it is Who takes care of it

17 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 17 Property related crimes Embezzlement A person who appropriates the assets or other movable property of another which are in the possession of the offender Own staff Theft A person who appropriates movable property from the possession of another Own staff or outsider Fraud A person who, in order to obtain unlawful financial benefit for himself/herself or another or in order to harm another, deceives another or takes advantage of an error of another

18 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 18 Own staff Steal useful property for home usage Pens, printing paper, toilet paper “Normal” Depends on the acceptance Misuse devices Own project Own side-business Often tolerated if cause no problems Steals valuable property for sale Usually not accepted

19 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 19 Prevention methods for internal cases Bookkeeping What, where, whose Procedures Prevention of misuse Who can buy, handle and dismiss property Selection of staff Preventing clear misusage

20 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 20 Outsiders Steals valuable property if can Protection Physical security to keep outsiders away Prevention of frauds Procedures, procedures, …

21 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 21 Bureaucracy A method for a good administration Decisions do not depend on a person or time Finds the best practices and makes them as a company policy Decreases the value of a person Anybody can make a right decision by following the book Documentation is important

22 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 22 Business crimes White collar crime Crimes are made by a desk Risks are smaller than traditional crimes Better profit No violence Better changes to avoid punishment

23 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 23 Fraudy buyer Buying something without any intention to pay Buy something and leave the invoice unpaid Using false information Wrong contact information for billing Wrong credit information The invoice is sent to someone else Using false information Getting discount for false reason

24 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 24 Fraudy seller Getting wrong items The delivery is not what was agreed The price is not correct An attempt to invoice more than was agreed Sell something with no intention to deliver Get some money in advance Send false invoices No order nor delivery

25 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 25 Fraydy partner Can be as a buyer or seller Misuse of confidental information

26 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 26 Own staff Stealing incoming money Forget to store cash into account Direct money to a wrong account Modify invoices Stealing outgoing money Pay money into own account without reason Direct money to a wrong account Pay bills with a wrong account number Misuse of information Buying or selling in stock markets Bribery

27 MINISTRY OF SOCIAL AFFAIRS AND HEALTH 27 Conclusions Business management must Administrate the property Produce business information Prevent property related crimes Potential criminals are Own staff Customers Partners Authorities Crimes are prevented by good administration Processes Logging


Download ppt "MINISTRY OF SOCIAL AFFAIRS AND HEALTH 1 Introduction to corporate security Teemupekka Virtanen Helsinki University of Technology Telecommunication Software."

Similar presentations


Ads by Google