Accendo Reliability

Your Reliability Engineering Professional Development Site

  • Home
  • About
    • Contributors
  • Reliability.fm
    • Speaking Of Reliability
    • Rooted in Reliability: The Plant Performance Podcast
    • Quality during Design
    • Critical Talks
    • Dare to Know
    • Maintenance Disrupted
    • Metal Conversations
    • The Leadership Connection
    • Practical Reliability Podcast
    • Reliability Matters
    • Reliability it Matters
    • Maintenance Mavericks Podcast
    • Women in Maintenance
    • Accendo Reliability Webinar Series
    • Asset Reliability @ Work
  • Articles
    • CRE Preparation Notes
    • on Leadership & Career
      • Advanced Engineering Culture
      • Engineering Leadership
      • Managing in the 2000s
      • Product Development and Process Improvement
    • on Maintenance Reliability
      • Aasan Asset Management
      • CMMS and Reliability
      • Conscious Asset
      • EAM & CMMS
      • Everyday RCM
      • History of Maintenance Management
      • Life Cycle Asset Management
      • Maintenance and Reliability
      • Maintenance Management
      • Plant Maintenance
      • Process Plant Reliability Engineering
      • ReliabilityXperience
      • RCM Blitz®
      • Rob’s Reliability Project
      • The Intelligent Transformer Blog
    • on Product Reliability
      • Accelerated Reliability
      • Achieving the Benefits of Reliability
      • Apex Ridge
      • Metals Engineering and Product Reliability
      • Musings on Reliability and Maintenance Topics
      • Product Validation
      • Reliability Engineering Insights
      • Reliability in Emerging Technology
    • on Risk & Safety
      • CERM® Risk Insights
      • Equipment Risk and Reliability in Downhole Applications
      • Operational Risk Process Safety
    • on Systems Thinking
      • Communicating with FINESSE
      • The RCA
    • on Tools & Techniques
      • Big Data & Analytics
      • Experimental Design for NPD
      • Innovative Thinking in Reliability and Durability
      • Inside and Beyond HALT
      • Inside FMEA
      • Integral Concepts
      • Learning from Failures
      • Progress in Field Reliability?
      • Reliability Engineering Using Python
      • Reliability Reflections
      • Testing 1 2 3
      • The Manufacturing Academy
  • eBooks
  • Resources
    • Accendo Authors
    • FMEA Resources
    • Feed Forward Publications
    • Openings
    • Books
    • Webinars
    • Journals
    • Higher Education
    • Podcasts
  • Courses
    • 14 Ways to Acquire Reliability Engineering Knowledge
    • Reliability Analysis Methods online course
    • Measurement System Assessment
    • SPC-Process Capability Course
    • Design of Experiments
    • Foundations of RCM online course
    • Quality during Design Journey
    • Reliability Engineering Statistics
    • An Introduction to Reliability Engineering
    • An Introduction to Quality Engineering
    • Process Capability Analysis course
    • Root Cause Analysis and the 8D Corrective Action Process course
    • Return on Investment online course
    • CRE Preparation Online Course
    • Quondam Courses
  • Webinars
    • Upcoming Live Events
  • Calendar
    • Call for Papers Listing
    • Upcoming Webinars
    • Webinar Calendar
  • Login
    • Member Home

by Greg Hutchins Leave a Comment

Cover Your Assets and Plausible Deniability

Cover Your Assets and Plausible Deniability

Guest Post by Ed Perkins (first posted on CERM ® RISK INSIGHTS – reposted here with permission)

In an earlier post [1] we looked whether ‘plausible deniability’ was now a dead strategy in the face of enterprise risk management (ERM) and the likely impact of the US SEC (Securities and Exchange Commission) guidance [2] regarding disclosure obligations relating to operational and cybersecurity risks and cyber incidents. The SEC noted that “a number of disclosure requirements may impose an obligation on registrants to disclose such risks and incidents.

In addition, material information regarding cybersecurity risks and cyber incidents is required to be disclosed when necessary in order to make other required disclosures, in light of the circumstances under which they are made, not misleading. Therefore, as with other operational and financial risks, registrants should review, on an ongoing basis, the adequacy of their disclosure relating to cybersecurity risks and cyber incidents.” And not just incidents are to be included, but the risk factors themselves.

The bottom line is that there is now an expectation of higher standard of duty and care. The Federal Trade Commission (FTC) has also gotten in the act, under its authority to prevent “unfair or deceptive practices”, going after firms that fail to protect customer information. [3]

Well the lawyers have figured out how to preserve a semblance a plausible deniability in this era of ERM. Enter the “privileged and confidential” risk assessment. While firms are still required to disclose their ‘significant’ operational risks, they can also conduct ‘secret’ risk assessments that are protected from disclosure under the cover of attorney-client privilege. To do this, the organization retains an outside lawyer or law firm for ‘legal advice’; the advice consists of conducting a risk assessment of the organization’s operational and cyber risks and producing a risk report. This ‘secret’ report and any information on the risks uncovered by it fall under attorney-client privilege and thus would not be subject to disclosure, even in a court of law.

The organization will still have file its ‘public’ risk disclosures, but that can occur after the organization has mitigated any serious risks found in the privileged assessment, and conducted a follow-up risk assessment for release that is not under the veil of privilege.

[1] #11 – COVER YOUR ASSETS 101 AND PLAUSIBLE DENIABILITY – ED PERKINS(http://insights.cermacademy.com/2013/04/11-cover-your-assets-101-ed-perkins/)

[2] SEC CF Disclosure Guidance: Topic No. 2 – Cybersecurity” http://www.sec.gov/divisions/corpfin/guidance/cfguidance-topic2.htm

[3] What CIOs Need to Know About the FTC Cybersecurity Ruling, WSJ – CIO Blog http://blogs.wsj.com/cio/2015/08/31/what-cios-need-to-know-about-the-ftc-cybersecurity-ruling/

Filed Under: Articles, CERM® Risk Insights, on Risk & Safety Tagged With: Risk

« Inputs to Consider When Setting Tolerances
Maintenance Planning– Make your Planner successful! »

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

CERM® Risk Insights series Article by Greg Hutchins, Editor and noted guest authors

Join Accendo

Receive information and updates about articles and many other resources offered by Accendo Reliability by becoming a member.

It’s free and only takes a minute.

Join Today

Recent Articles

  • Significance Over Success. Innovation Over Change. Anticipation Over Agility.
  • Maintenance Planning and Scheduling for World Class Reliability and Maintenance Performance
  • Self-Discipline Part 1
  • Is Safety Training Helpful?
  • FINESSE Facilitation: What Are Best Practices for Qualitative Assessment Analysis?

© 2023 FMS Reliability · Privacy Policy · Terms of Service · Cookies Policy

This site uses cookies to give you a better experience, analyze site traffic, and gain insight to products or offers that may interest you. By continuing, you consent to the use of cookies. Learn how we use cookies, how they work, and how to set your browser preferences by reading our Cookies Policy.