MANAGER LIABILITY You’Re in Their Sights a STEP TOO FAR? REPUTATIONS at RISK Some Just Don’T Care
Total Page:16
File Type:pdf, Size:1020Kb
JULY 2015 | THE OFFICIAL MAGAZINE OF THE GRC INSTITUTE SCHEMES AND SCAMS You’re in their sights MANAGER LIABILITY A STEP TOO FAR? REPUTATIONS AT RISK Some just don’t care MOBILE TIME BOMBS The danger of BYODs COUNTRY SNAPshot Doing business in Indonesia RANSOMWARE RISING To pay or not to pay? FINANCIAL CRIMES Accounting scandal rocks Toshiba, CEO under fire THE GRC INSTITUTe’s 19TH ANNUAL CONFERENCE The GRC2015 conference 3 day program features inspirational leaders exploring topics across the change management spectrum at an organisational and individual level. CONFERENCE GRC2015 provides an exciting opportunity for 28–30 Oct 2015 • MelbOurne networking and professional development and exposure for commercial partners to consolidate crOwn Conference centre in the GRC marketplace. To book your seat at this exceptional event or for sponsorship opportunities please visit: www.grcconference.com.au CHANGE CATALYST GOVERNANCE • RISK • COMPLIANCE GRCI’s Graduate Certificate in Compliance Management 91517 NSW has been designed exclusively for senior governance, risk and GOVERNANCE • RISK • COMPLIANCE compliance professionals looking to further develop skills for career progression to the most senior level. Considered the benchmark accreditation GRADUATE for compliance professionals, this course is a nationally accredited qualification. CERTIFICATE GRADUATEIN This course offers you a career advantage through demonstrable skill development over COMPLIANCE an intense study period of four days. You will CERTIFICalso AbecomeTE part INof a strong network of professionals supported by GRCI, including MANAGEMENTCOMPLIANspecial eventsC Eexclusively for CCP alumni. 91517 NSW Next available certificate courses: Certified Compliance ProfessionalMA (CCP)NA GSydney,EMENT 7-11 October 2015 91517 NSW New Zealand, 10-13 November 2015 Certified ComplianceFor more informationProfessional and bookings (CCP) please visit: www.thegrcinstitute.org or email [email protected] GOVERNANCE • RISK • COMPLIANCE Contents PRESIDENT’S MESSAGE X page 5 Contact us COVER STORY READER POLL X page 6 NEWS X page 8 NEWS features X page 10 FINANCIAL CRIMES 12 NEWS X page 17 GRC Professional is the official monthly publication of GRCI in Australia, New Ransomware exacting a high toll Zealand, Hong Kong & South-East Asia. Manager liability Individuals and organisations alike are edges closer falling victim to a sophisticated new way to extort money. X page 19 GRC Institute As Britain gears for the introduction of a hard-line approach to making The rise and rise of scamming President: Alf Esteban individuals personally liable for Scams have become synonymous with Vice President: Carolyn Hanson corporate misconduct, others question the internet, but they can be countered Treasurer: Gillian Kinder by common sense. X page 20 Director: Susan Cretan the viability of trying to scare people into Director: David Morris behaving ethically. Director: Stephen Luk Fear, loathing and malicious intent Director: Lois McCowan There might be a maturing appreciation Director: Kellie Powell of the risks that can arise from gross misconduct in the workplace, and the Managing Director: hugely negative impact it can have on Martin Tolar [email protected] corporate reputation, but still some just don’t seem to care. X page 26 National Manager: Naomi Burley Mobile time bombs [email protected] BYODs are now ubiquitous in the Ph: +61 2 9290 1788 workplace, and if left unmanaged Fax: +61 2 9262 3311 can be a serious threat to business www.thegrcinstitute.org continuity. X page 30 GPO BOX 4117 Sydney NSW 2001 Australia Doing business in Indonesia In the first in a series of articles examining the risks facing organisations GRC Professional looking to embark on business Editor: activities in different parts of the Mark Phillips Asia Pacific region,GRC Professional +61 2 8245 0704 looks at Indonesia. X page 33 [email protected] Advertising: Lost privacy costing big time Naomi Burley Open-plan offices are taking a +61 2 9290 1788 heavy toll on workers’ engagement, [email protected] creativity and wellbeing – and one of the reasons is that they know Big Brother is watching. X page 37 Disclaimer: While GRCI uses its best endeavours in preparing and ensuring the accuracy of the content of this publication, it makes no representation or warranty with respect to the accuracy, applicability, fitness, legal correctness or completeness of any of the contents of this publication. Information contained in this publication is strictly for educational purposes only and should not be considered legal advice. Readers must obtain their own independent legal advice in relation to the application of any of the material published in this journal to their individual circumstances. The Institute disclaims any liability to any party for loss or any damages howsoever arising from the use of, or reliance upon, any of the material contained in this publication. 4 GRC Professional • July 2015 PRESIDENT’S MESSAGE Changes at the Institute MARtiN TOLAR, MANAGING DIRECtoR OF THE GRC INstitUTE, advised the Board in early July of his intention to resign with effect end August to pursue interests outside of the GRC sector. The Board has accepted his resignation and has implemented the agreed succession plan by promoting Naomi Burley to lead the GRC Institute through to our next phase. Martin has led the GRC Institute for the past nine years. During this time he has led our expansion internationally with over 15 per cent of members now based outside of Australia; the establishment of the GRC Institute as a Registered Training Organisation, allowing for the Associate and CCP courses to be accredited to the level of Certificate IV and Graduate Certificate respectively; the rebranding and repositioning of the then ACI to the GRC Institute, recognising the close interaction between the compliance and risk professions and the growing membership from the risk profession; and working with Standards Australia and our membership in transforming the AS/NZS 3806 Compliance Management standard to become the ISO 19600 Compliance Management standard. On behalf of the Board and members, I wish Martin the best in the next stage of his career and thank him for his efforts over the past nine years. The change in leadership at the GRC Institute has enabled the Board to undertake a full review of operations of the organisation as well as a reassessment of our strategy and direction, working closely with Naomi Burley in her upgraded role. This review is currently underway, led by our former Director and Treasurer Robert Emery. The review is anticipated shortly and any material changes to our operations and direction will be communicated to members. In the meantime, it is business as usual at the GRC Institute under Naomi’s direction. The traditional End of Financial Year networking events will be held in Sydney, Melbourne, Brisbane, Perth and Auckland in August. This is a great opportunity to meet your fellow risk and compliance professionals in a casual environment, share insights in our profession, make new friends and reacquaint with old ones. I encourage you to attend these events which are free for members and a small fee for non-members. Places are strictly limited so I recommend that you register soon to avoid disappointment. Registration forms and additional details are available in the Events section of the GRC Institute website. The EOFY Networking event is but one of the many benefits available from your membership to the GRC Institute. Existing members will have received their membership renewal notifications and I am pleased with the response to date in the level of renewals and the new member applications received. The GRC Institute Annual Conference will be held in Melbourne from 28 to 30 October at the Crown Conference Centre. The theme of this year’s conference is “Change Catalyst” and our line-up of inspirational speakers will explore topics across the change management spectrum at an organisational and individual level. The feature of our conference is on the focus of practical insights from senior practitioners in governance, risk and compliance. Back by popular demand, we will be running a change management simulation as well as a series of breakout sessions. Along with our gala dinner, graduation ceremony and annual awards presentation our conference again promises to be the must-attend event of the 2015 conference season. Additional information on GRC 2015, the 19th Annual GRC Institute Conference, is available on the website (www.grcconference.com.au). I look forward to seeing you at what will be the conference event of the year for risk and compliance professionals. Alf Esteban CCP, President, GRCI 5 Reader Poll Last month’S Poll Best from around the web Reader Poll BYODs These were the stories being discussed at the GRC Institute this month: Is manager AS WE OUTLINE IN OUR stoRY on page 31, how easy would it be for your liability a employees to grab a client list and forward it TALK ABOUT SHOOTING to themselves or others or copy it onto a USB YOURSELF IN THE FOOT! X step too far? memory stick and walk out the door? Organisations can spend years developing AS WE REpoRT ON paGE 12, THERE templates, operations manuals, procedures, TOO LATE TO SAY SORRY X is a huge divide in opinion on whether internal software and client data. Many can making managers personally liable for their take the value of this for granted and it is actions will have any real impact on ethical not until a breach occurs that management behaviour. realises that if the material is passed to the DOES MY INSURANCE This month we’re asking for your opinion opposition, they could lose vital business. COVER THIS? X on the matter, but before doing so check Hence, last month we asked whether your out our story, because as Britain gears for firm has a strict policy on Bring Your Own the introduction of a hard-line approach Devices (BYODs) into the workplace.