Skip to content
TrackPodcasts
governmentSep 10, 202612:36

An organization can have security offices, monitoring programs and compliance requirements everywhere, and still miss the whole risk picture

About this episode

A recent Federal Reserve Board audit found that insider-risk responsibilities existed across multiple offices, but no centralized program was managing those risks at the enterprise level. The findings offer lessons that extend well beyond the Federal Reserve. Here to discuss them are Chris Lyons and Joe Hackett from the Federal Reserve Board Office of Inspector General.

See Privacy Policy at https://art19.com/privacy and California Privacy Notice at https://art19.com/privacy#do-not-sell-my-info.

Get every episode summarized

Each time The Federal Drive with Terry Gerton publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

258 searchable segments. Every word is indexed and playable.

An organization can have security offices, monitoring programs and compliance requirements everywhere, and still miss the whole risk picture

The Federal Drive with Terry Gerton

0:00
12:36

Full transcript

The Federal Drive with Terry GertonAn organization can have security offices, monitoring programs and compliance requirements everywhere, and still miss the whole risk picture. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Print servers and federal environments create risk and unnecessary complexity. Every new printer, location, or policy adds strain to infrastructure that was never built for today's demands. FedRAMP High authorized printer logic eliminates print servers with a secure cloud native zero-trust solution designed for federal IT. With advanced security, centralized control, and simplified management, agencies can modernize print without added burden. See what secure serverless printing looks like. Visit VAsian.com to learn more. Federal Drive is presented by GEHA, Government Employees Health Association, proudly providing health and dental benefits to federal employees and their families. Visit GEHA.com. A recent Federal Reserve Board audit found that insider risk responsibilities existed across multiple offices, but no centralized program was managing those risks at the enterprise level. The findings offer lessons that extend well beyond the Federal Reserve, joining the Federal Drive to discuss them, Chris Lyons, and Joe Hackett from the Federal Reserve Board Office of Inspector General.

Joe, let's start this conversation with you. Because when people hear the term insider risk, they're probably thinking about espionage or spying of some sort or a rather. Your report uses a broader definition. When you're thinking about insider risk at the Federal Reserve Board, what exactly are you looking at? Well, we're thinking of a broad range of potential actors, damaging a broad range of potential assets. So we use Carnegie Mellon University's definition for an insider, which is any individual, and that may be an employee, a contractor, a consultant, or any sort of trusted external entity, who currently or used to have access to the organization's critical assets. Now, what are critical assets you may ask? I was. Those are often referred to as crown jewels of the organization, and those can be people, processes, information, technology, or facilities that are critical to executing the mission of the organization. Now, insider risk is the risk, obviously, that these insiders use this access

to those critical assets to harm the organization, and that can be either on purpose or as an accident. So put that in plain language for me with the Federal Reserve. What are those crown jewel assets that might be at risk? Well, as you can imagine, the boards involved in a lot of sensitive economic research, and interest rate decision making by the Federal Open Market Committee, are the types of information that would be really sensitive and something that we would want to make sure to protect. Obviously, there are payment systems and other technological and financial infrastructure that would be important to make sure are safe, and that's essentially critical infrastructure for our nation's economy. And as you looked at this issue, you found that the boards insider risk activities really don't effectively identify or manage those risks in advance. What convinced you that the issue was bigger than maybe a control gap or two? Well, we at our office have had a long emphasis on information security, and working to improve

that and identify ways to improve that at the Federal Reserve Board. So we came into this project looking at a big picture of the design and effectiveness of the boards insider risk management activities. And the way we did that is we wanted to do three methodologies. The first was to take leading practices from the intelligence community, from academia, and from the private sector, and use those to assess how the board is doing. We then benchmarked with a peer federal financial regulatory agency, and lastly, we looked at some recent potential insider risk incidents to see if there were any additional gaps or areas of improvement that we could see in those examples. Well, for those who obviously are listeners who work at a federal agency, you know, there are folks who are retiring that may walk out the door with some sensitive information that they shouldn't. There are staff that maybe they leave a phone on the metro. There are people who are emailing sensitive information to themselves for more

nefarious purposes. Obviously, there is a lot of foreign adversaries who are interested in obtaining information from federal employees. So does the Federal Reserve Board then have a centralized approach to this, or did you find that they didn't and should have? As of right now, they did not have a centralized approach, and that was probably the biggest finding that we had in addition to identifying critical assets, was for the board to take the different programs that it has to protect its information. And to be clear, it does have different programs to protect information at the board. Our finding was, based on these leading practices, that they should consolidate these programs and focus on all types of information, leverage expertise, and give access and information sharing to this sort of centralized hub, is how we like to think about it. And right now, they do that in all of the different bureaus or offices. To get into more specific detail, we identified four programs that are essentially doing information security or insider risk management. A handful of those focus on various types of

sensitive, unclassified information. So your personal identifiable information, various IT information, or for the board, different types of sensitive economic information. And then one program focuses in particular on protecting classified national security information, that's your secret top secret sort of thing. And what the leading practices told us is that really, if all of these programs were one singular hub, they could more effectively identify insider risks and mitigate them before they happen. Joe Hackett is a senior auditor and project leader at the Federal Reserve Board of Governors Office of the Inspector General. Chris Lyons isn't OIG manager also at the Federal Reserve Board of Office of Inspector General. Chris, let me turn to you. Joe mentioned some of these crown jewels and the fact that they could be valuable to foreign adversaries or financial actors or other people looking at the weaknesses you all identified. Where do you think the organization was maybe most dependent upon trustworthy people working there as opposed to having processes to really check this out? Yeah, I mean, we think that the lack

of centralization is where the board was really relying on some of these relationships and trust. In a setup we observed there were well-intended programs, qualified staff addressing potential insider risks. But because they were in their own silo, they had to rely on less formal relationships or processes to make decisions. So we knew early on that the board would benefit from a design where these staff were communicating more consistently and more effectively. There's also a cultural aspect to insider risk. Especially for research-oriented institutions, many staff need to be trained and made aware on insider risk issues like how their work is targeted by foreign adversaries and how that could be leveraged to harm the US. Also, I would add a couple of things here. First is that a centralized program with a standardized procedures and processes helps ensure that the staff that are conducting insider risk activities are appropriately conducting

incident response inquiries, that they're protecting and giving fair treatments to the due process rights of staff. Second is that centralization really allows the disparate elements of the organizations that may be conducting incident response across the board that Joe talked about earlier to come together and to centralize that information to provide a clear line of sight across the board into all its insider risk activities and give it a clear sense of the insider risk landscape throughout the breadth of the organization. As you think about that approach, walk us through some of the findings because they really get after how you want this to change. Well, I think two more important findings for us were first, as Joe talked about, the need to define your critical assets. What are your organization's current jewels? Why are you protecting those things?

And we asked the board to work with the system as the Federal Reserve System and the board work together to conduct the central bank's responsibilities and they protect the same information. So we asked them to work together to define those critical assets and then once you understand what your crown jewels are and why you're protecting them. Now, let's stand up a centralized tub with professional ized staff with experience in this area that is able to effectively share information from across the organization. And so those are really the key fundamental elements of an effective insider risk management program. Chris, which of those changes do you think would do the most to improve the board's ability to identify insider risks before they have an incident? Well, you bring up a really great point because I think one point of misunderstanding for folks who work in the Federal Spear is that insider risk programs are designed to mitigate an incident after it occurs.

And in truth, really effective insider risk management programs are collecting and aggregating enough information about their employees so that when they see anomalies and everyday work, they're able to potentially identify those and prevent insider risks before they occur. And that's what we want, one of the things we like the board to improve upon. I think the most important thing here is once you've established that centralized hub, it's going to be really important for the board and other agencies who conduct this work to have standard processes to share information from across the organization. So a hypothetical might be an individual is printing sensitive materials at 3 a.m. on a Tuesday night. Perhaps the next day they're traveling to a restricted country. Perhaps that individual has had recent problems in performance. Those pieces of information might be in different elements of the organization unless you try intentionally connect those dots.

You may not pick up on what might be an intentional insider risk someone trying to harm the board. So I think the idea here is to improve those tools and to better share information across the organization so that you're able to more actively not just detect a potential insider risk but prevent it before it occurs. Chris, there are a lot of other federal organizations that deal with the same kind of mix of sensitive data and maybe hybrid work arrangements and sophisticated foreign threats. Do you have any lessons here for them, especially if they believe they already have insider risk under control? Yeah, you're really an important point. I think the lesson here is that federal agency really you can't wing effective insider risk management. An ad hoc approach here simply is not commensurate with the level of threats in our increasingly connected workplace. Every workplace has a different culture. We're seeing increasing technological

threats. Every workplace has different standards. We're seeing emergence of external threats from other nation states. So each organization really needs to take a careful look at insider risk that their organization faces. They need to have a very intentional approach to how they want to manage centrally inside a risk that their organization. And a simple example that might be something Joe mentioned earlier. For example, you might have individuals who are retiring who either intentionally or unintentionally are removing sensitive information from their office when they lead the organization. So it's really important that your office has a full understanding of the types of risks that they're that it might be common at their organization, the types of risks that they face. And the second thing I would say is if you're at an agency who needs to improve in this space, you don't have to reinvent the wheel. There are a number of standards available. There are from net F, the National Insider threat task force and others. There are a number of insider

risk practitioners across federal agencies that you can leverage. And there are a lot of very informative trainings and information that are available to focus who practice this actively. And you know, the best, the folks who do this the best, they share information with one another, they have a community of practice across the federal government to get the latest lessons learned. And so as programs mature, I think they get increasingly involved in that community of practice. Joe Hackett is senior auditor and project leader at the Federal Reserve Board of Governors Office of the Inspector General, Chris Lyons is OIG manager with the Federal Reserve Board Office of Inspector General. We'll post this interview and a link to their report at federalnewsnetwork.com slash federal drive, subscribe to the federal drive wherever you get your podcasts. What does it take to drive transformational change in large mission driven organizations? In this episode of Lessons in Leadership, former Treasury fiscal assistant secretary David Lebrick sits down with WAPA CEO Shane Canfield to explore the answer to that question,

drawing on nearly four decades of public service. Lebrick shares insights on how to maintain employee trust and accountability while striving for strategic leadership and operational excellence. He discusses his biggest lessons learned from modernizing major government systems and how he worked to break down silos and build high performing teams all while staying rooted in character and integrity. Hello and welcome to the Lessons in Leadership podcast. I'm your host Shane Canfield CEO of WAPA. Today I'm joined by David Lebrick, former fiscal assistant secretary of the Treasury, the department's most senior career position where he spent nearly four decades help oversee and modernize the federal government's financial infrastructure including payments collecting, debt financing and cash management. David, welcome and thank you for being here. It's a real pleasure to be here. So let's jump right in. What does it actually take to drive transformational change inside the federal government and related, Treasury is obviously a huge organization.

What did that teach you about leadership as you drove these changes? Sure, I think one of the things that you realize at time is that change and transformational change is very difficult, but it is doable. I think sometimes we don't think that we can do big things in government and yet we can. I think over the course of my career I was enormously fortunate to work with some other really wonderful people, some of the most preeminent people in government over the course of the last 35 years. From them you learn a lot of really important lessons about leadership. I think early in my career what I would tell you is that I was very much new and my interacted with political appointees as a civil servant. You're really an advisor and I had some really wonderful experiences advising some of really great people. My second job at Treasury for example was as a special assistant to J. Powell. I knew I was not going to be the most the smartest person in the room or the expert on many things that were going on, but what I did know is that I had a

very good understanding about what it meant to navigate in government, also what it meant to advise and provide options and analysis to decision makers. As you move up in your career and you actually take on more operational responsibility you find out that you are a decision maker. When you are a decision maker I had a very good framework that I used throughout my career which is as a well-edged organization the leadership had to think about three very distinct things. One was thinking strategically about where the organization was going, not just about where it was going tomorrow and the next day but actually into the future. The second area was that you really had to be able to deliver in the operational excellence. So if you're responsible for providing a service or a product you can do that well and you can think very purposefully about that. And the third area is really about people and about how you attract good people, how you retain good people, how you incent good people and how you really treat people. And so throughout my career

I had an opportunity to see people be very effective in all three of those areas. So when it came time to do transformational change that model worked very well. I would also say that what you learn very early on is that regardless is that you as an individual it takes the ability to work collectively and collaboratively with a lot of people. And so some of the things that I did for example which were cross-government you realize that you really didn't have authority over many of the people that you were asking to do something different. But if you had character and competence you could actually have trust. And so I think when people looked and said this is someone who has capability and they have character they will actually go and reduce the friction and actually making change. And so those collaborative relationships that ability to sort of lead with purpose I think was very important with respect to really driving transformational change.

Yeah that's an amazing perspective. I just had a chance to listen in a small room to the CEO and the chairman of the board for Mariah Corporation and they're celebrating their 100th birthday next year. And many most US companies don't make it to 100 and so it was it was fascinating. Both of them were asked to what do you attribute this? And they said both of them with energy it was about their people. They focused on their people and everything came back to the employees, the people that worked there, the people that they have to motivate. Do you find something similar in government? I do. I actually take you know oftentimes you hear people say people the most important asset in an organization and there's an element of truth to that but I also think that leadership is probably the most important aspect attribute in an organization because if you have

the right leaders and you're using a framework like I mentioned you're going to be really focused on getting good people in the organization and those people will thrive. I think the thing that you find certainly in government is that federal employees are very mission driven. And they are committed and they you know there's a lot of discussion about you know what really motivates people intrinsic versus extrinsic you know motivators and I really do believe that you know when you really get a high performing organization regardless of as private sector or public sector it's going to be those intrinsic things which are going to actually drive employees to do great things. And so setting up those right working conditions to remind people how important they are to actually invest in their development to actually give them good feedback. You know one of the things that is really important in an organization is if you really care about an employee and you really want to see them develop you have to tell them not only good things you have to tell them things they have to work on and I think you need to set up an environment and we add a saying which is

feedback as a gift and and and assume noble intent intent so that when someone gives you feedback your first reaction shouldn't be defensive it should be let me let me make sure I can really understand why I'm getting feedback and what I can do about that. You know I think of a story from a book called Radical Candor which the author had gone out and spent a lot of time recruiting a new executive in the organization and thought they had a perfect match. They got to six months and the executive was struggling and they ultimately fired the executive and at the Exinterview the she had turned to the executive and he said well I really was someone who had told me earlier on what I wasn't doing well and I tell that story because I think it sort of says that if you're not giving good feedback to people you spent all this money on recruiting someone all this time and we know it takes a lot of time to bring people on board and if you're not giving them the benefit

out you're not giving regular feedback to someone about what they can do better then you potentially have a failure and you have another vacancy that you have to fill which is very costly and expensive. So I think you need to have an idea there's another element of that which is in a high performing organization if people are comfortable raising their hand when something's not going right and in my world large scale operations and what we did every day something doesn't go right it's just inevitable and the issue within a well performing high performing organization is that people will raise their hand and say we have a problem and we need to fix it and the leadership is receptive to that and says okay what do we need to do and then after the problem is solved you have an obligation to go back and do lessons learned do action learning to see hey what could we have done differently how could we have avoided that problem so that you have a learning organization it's not just that you're comfortable communicating and have trust in the organization that you can communicate openly but also that you're learning as you go along every day to improve your operations.

The very first podcast we had was Cutler Dawson who was Admiral and Navy charge of the enterprise carrier and the fleet in the beginning of Desert Storm and then he went on to run Navy Federal the world's largest credit union and it was fascinating to hear you because he talked he used an example of a problem they had on deck on air with airplanes on the carrier and it was pretty serious accident that happened his culture was exactly what you said you've got to talk whether you're at fault or not whether you're partly at fault it doesn't matter we have to have an honest conversation about this and that doesn't mean there weren't consequences but at the same time that honesty has to be front and center. It really is true and I think that I think that you raised an interesting point which I think sometimes the word accountability has a negative connotation you're going to be held accountable but also but I would have it in a

different way which is we're accountable for high performance and we're accountable to each other to make sure that we can deliver on our mission and that's a positive attribute along the way and I think when when organizations take that seriously the collaboration the teamwork the openness the feedback but they also have a culture of accountability that says we do things well we're going to actually be successful what we do and we all have a commitment to doing that I think you get really a high performing organization. You've been listening to a preview edition of Lessons in Leadership to hear the rest of this conversation and all past episodes subscribe to Lessons in Leadership wherever you get your podcasts.

More episodes

More from The Federal Drive with Terry Gerton

View all episodes →