Categories
Voices of Data Protection

Getting to know the Microsoft Information Protection and Compliance Customer Experience Team


In this episode we speak with Mavi Etzyon-Grizer, Director of the Microsoft Information Protection and Compliance Customer Experience (CXE) Team, who helps customers from around the world use and deploy our Microsoft Security and Compliance products. Join Bhavy and Mavi as they reflect on the one-year anniversary of the customer experience team and all of the resources, community pages and platforms that have been developed for you, based directly on your feedback to our engineering teams.

Voices of Data Protection is a show about the latest processes and solutions to help you manage your data, keep it safe, and stay compliant. We talk with industry experts, leaders, and program managers from Microsoft to learn how digital transformation is accelerating the need for compliance, how organizations are navigating this new landscape, and learn best-in-class practices and solutions to get your organization started and bring compliance to the next level. Transcripts are available for all episodes. For more infomration, visit: https://aka.ms/voicesofdataprotection
Learn More
Subscribe on: Apple Podcasts, Spotify, Google Podcast, Stitcher, Deezer

Categories
Innovation in Compliance

Comprehensive Cybersecurity Management with Jenna Waters


Jenna Waters is a Cybersecurity Consultant at True Digital Security where she specializes in information security program development, industry compliance assessments, threat intelligence, and cloud security controls. She helps clients through the challenges of cybersecurity program development and holistic security consulting, and also consults companies across varying industries. Tom Fox welcomes her to this week’s show as they discuss technological safety within industries, and what her company is doing to curb cyber attacks.
The Micro/Macro Focus
Jenna is a USN veteran, and during her time in the Navy, she worked on highly sophisticated computer information systems and with a lot of other sophisticated technologies as well. Tom asks her to elaborate on the Navy’s approach to cybersecurity as opposed to the public and private sector. Jenna iterates that the Navy, as well as any other military, federal, or law enforcement agency, is focused on a very global, or what she calls a “macro threat” environment. They are focused on protecting the country as a whole from cyber and information warfare attacks. On the other hand, the private and public sectors have a microfocus: in industries or specific business types and the risks and threats those industries or business types may face. 
“To End Security Breaches”
Tom remarks that True Digital Security strives to bring an end-to-end solution, and makes mention of the company’s statement “To end security breaches.” Jenna explains that it’s the company’s goal and that True Digital strives to be at the forefront of cybersecurity. Doing this means preventing breaches from occurring in the first place. However, in the event that breaches do happen, ensuring that attackers don’t acquire vital information is important. “Even if you suffer a minor breach, they’re just stuck because we want our clients to have a very layered defense, an in-depth approach that prevents them [attackers] from getting something valuable,” Jenna says.
Software Inventory Management
“It’s the process of keeping an updated inventory of all your software and your applications from even the smallest minutia of an application used within your IT environment,” Jenna says in response to Tom’s question about software inventory management. She adds that it’s one core aspect of overall IT asset management. It enables the recording of vital information such as software update cycles, as well as ensuring that all the critical security patches are applied. Software Inventory Management keeps records of the quantity of applications software that exist within an organization. It helps detect if there’s been a breach as the bit size of applications changes when a breach occurs. 
The Impact of COVID-19
The pandemic has not changed True Digital’s approach very much, Jenna remarks. What the company has been doing is helping clients pivot without the notice of attackers. Remote working comes with its own challenges and insecurities, and so assisting clients and pivoting in a way that helps them continue to achieve their cybersecurity compliance program and development goals is important. The rise in attacks emphasizes the need for structural and legal practices and precedents. Jenna stresses that governments of the world, as well as public and private sectors, need to come together to denounce cyber attacks and enforce actual consequences for these actions. 
Resources
Jenna Waters | LinkedIn
TrueDigitalSecurity.com
 

Categories
Daily Compliance News

March 30, 2021 the Email Anxiety edition


In today’s edition of Daily Compliance News:

  • Email anxiety. (WSJ)
  • US suspends trade deal with Myanmar. Are sanctions next? (WSJ)
  • EY drops whistleblower appeal. (BBC)
  • Do Amazon workers pee in bottles? (WaPo)
Categories
Leading the Way

Mara Senn, Investigations and Regulations in Compliance

Welcome to the latest addition to the Compliance Podcast Network, Leading the Way, a StoneTurn podcast. StoneTurn’s Leading the Way podcast series highlights the top compliance, legal and anti-fraud practitioners who are breaking down siloes and setting new standards for excellence worldwide.

In this episode, StoneTurn Partner Valerie Charles is joined by well-known compliance professional Mara Senn. Mara has been a partner in the white collar practice of a big law firm, she has worked at the Department of Justice on its anti-kleptocracy initiative, has worked at the World Bank handling allegations of corruption but in the investigation and litigation phase and is now Director & Senior Counsel, Global Compliance Investigations at Zimmer Biomet. It is a fascinating discussion of Mara’s journey through the investigation and regulatory side of compliance, some of the changes she has seen, key lessons learned and where compliance is headed down the road.

Resources
StoneTurn
Mara Senn LinkedIn Profile

Categories
Coffee and Regs

Coffee and Regs: Pension Funds & Independent Compliance Reviews


In this episode, former Chief Compliance Officers Matt Calabro and Allison Fraser sit down to discuss public pension fund independent compliance reviews. Pension fund managers have an extensive due diligence process to screen potential investment advisers for their programs. Today, this due diligence goes beyond examining an investment adviser’s investment process, research and execution capabilities to also include evaluating their operational and compliance excellence and cybersecurity controls.

 

About Our Guest Speakers:

Matt Calabro is an experienced Chief Compliance Officer, having served as CCO for registered mutual funds, investment advisers and a family of UCITS funds. Before joining CSS, Matt was Deputy CCO at Delaware Investments, where he led the daily activities of the firm’s compliance department covering advisory, fund and distribution activity. Under his leadership, Delaware implemented specific improvements in its guideline compliance, advertising review and Code of Ethics programs. Prior to Delaware, Matt spent 20 years in Raymond James’ investment advisory business, where he led mutual fund operations. While there, Matt implemented and upgraded controls, processes and technology and also served as the first full-time CCO to the mutual funds following the adoption of the Compliance Rule. Matt leverages his compliance and operations experience in the investment management industry to assist advisers and investment companies in advancing the effectiveness of their compliance programs.


Allison Fraser provides compliance consulting services to investment advisers, registered investment companies and private investment funds, including conducting annual compliance program reviews and testing, developing risk assessments and preparing for SEC examinations. She also assists clients with drafting policies and procedures and preparing regulatory filings. On behalf of, the Compliance Services division of CSS, Allison served as the Chief Compliance Officer for a family of alternative funds registered under the Investment Company Act of 1940. Prior to joining CSS, Allison served as a Senior Vice President of Compliance at Northern Trust Investments, Inc. (“NTI”), the asset management subsidiary of The Northern Trust Company. In this capacity, she managed and administered the compliance due diligence program for NTI’s Multi-Manager Solutions and Outsourced Chief Investment Officer businesses. Allison also was the Chief Compliance Officer of two registered funds of hedge funds advised by NTI as well as a member of the funds’ Pricing and Disclosure Committees.
Before joining NTI, Allison served as the Compliance Director for General Motors Asset Management, where she assisted with the administration of the compliance program for this registered investment adviser.
 
Categories
FCPA Compliance Report

Kalyan & Mir on Insider Risks


In the Episode, the hosts of the Microsoft podcast, Uncovering Hidden Risks join me. Raman Kalyan is a Director of Product Marketing on the Microsoft 365 Security and Compliance team focused primarily on the Insider Risk Management set of solutions. Talhah Mir is a Principal Product Manager on the MIP & Compliance US OPEX team.
In this podcast, they explore a broader set of issues focused on identifying the various risks organizations face as they navigate the internal and external requirements organizations must comply with. They will take you through a journey on insider risks to uncover some of the hidden security threats that Microsoft and organizations across the world are facing. They bring to the surface some of the best-in-class technology and processes to help you protect your organization and employees from risks from trusted insiders. Highlights of this podcast include:

  • Why did you start “Uncovering Hidden Risks”? What are insider risks?
  • How should a corporate compliance function or risk management function think about risks inside of an organization?
  • What are some of the tools you and your team have developed at Microsoft to help manage these risks?
  • How do manage these insider risks in the context of data privacy?
  • What are some of the communication strategies you advocate?
  • What are some examples of market solutions you have developed?

Resources 
Raman Kalyan LinkedIn Profile
Talhah Mir LinkedIn Profile
Uncovering Hidden Risks

Categories
Daily Compliance News

March 29, 2021 the VW Strikes edition


In today’s edition of Daily Compliance News:

  • FCA wants greater whistleblowing. (WSJ)
  • PIMCO CCO to step down. (WSJ)
  • VW going after previous CCO. (NYT)
  • Do Amazon workers pee in bottles? (WaPo)
Categories
Sunday Book Review

March 28, 2021, the Now Let Us Praise Famous Men edition


In today’s edition of Sunday Book Review:

Categories
Daily Compliance News

March 27, 2021 the Faustian Bargain edition


In today’s edition of Daily Compliance News:

  • Will the White-Collar ‘Faustian Bargain’ end. (FT)
  • Three cheers for the OECD. (FT)
  • The cost of Greensill? (FT)
  • Chinese tech sector in slide? (FT)
Categories
Creativity and Compliance

You’re Measuring the Wrong Things


Where does creativity fit into compliance? In more places than you think. Problem-solving, accountability, communication, and connection – they all take creativity. Join Tom Fox and Ronnie Feldman on Creativity and Compliance, part of the Compliance Podcast Network. In this episode, Ronnie goes on an extended rant about why compliance professionals are measuring the wrongs concepts around training. Some of the questions we explore are:

  • Why the typical measurement of compliance programs is BS?
  • What should compliance professionals be measuring?
  • How does Entertainment help?

Resources:
Ronnie Feldman (LinkedIn)
Learnings & Entertainments (LinkedIn)
Ronnie Feldman (Twitter)
Learnings & Entertainments (Website)
60-Second Communication & Awareness Shorts – A variety of short, customizable, quick-hitter “commercials” including songs & jingles, video shorts, newsletter graphics & Gifs, and more. Promote integrity, compliance, the Code, the helpline and the E&C team as helpful advisors and coaches.
Workplace Tonight Show! Micro-learning – a library of 1-10-minute trainings and communications wrapped in the style of a late-night variety show, that explains corporate risk topics and why employees should care.
Custom Live & Digital Programing – We’ll develop programming that fits your culture and balances the seriousness of the subject matter with a more engaging delivery.
Tales from the Hotline – check out some samples.