Michael Georg Speller
Metropolregion Sankt Gallen
3547 Follower:innen
500+ Kontakte
Info
As your "Advocatus Diaboli", I uncover weaknesses and vulnerabilities in your internal or…
Serviceleistungen
Artikel von Michael Georg Speller
Beiträge
Aktivitäten
-
𝗗𝗮𝘀 𝗡𝗮𝗿𝗿𝗮𝘁𝗶𝘃, 𝗱𝗮𝘀𝘀 𝗷𝗲𝘁𝘇𝘁 𝗱𝘂𝗿𝗰𝗵 𝗵ö𝗵𝗲𝗿𝗲 𝗩𝗲𝗿𝘀𝗰𝗵𝘂𝗹𝗱𝘂𝗻𝗴 𝘇𝘂𝗸ü𝗻𝗳𝘁𝗶𝗴𝗲 𝗚𝗲𝗻𝗲𝗿𝗮𝘁𝗶𝗼𝗻…
𝗗𝗮𝘀 𝗡𝗮𝗿𝗿𝗮𝘁𝗶𝘃, 𝗱𝗮𝘀𝘀 𝗷𝗲𝘁𝘇𝘁 𝗱𝘂𝗿𝗰𝗵 𝗵ö𝗵𝗲𝗿𝗲 𝗩𝗲𝗿𝘀𝗰𝗵𝘂𝗹𝗱𝘂𝗻𝗴 𝘇𝘂𝗸ü𝗻𝗳𝘁𝗶𝗴𝗲 𝗚𝗲𝗻𝗲𝗿𝗮𝘁𝗶𝗼𝗻…
Beliebt bei Michael Georg Speller
-
Yesterday I realized that Grammarly might be training AI on EVERYTHING I type. So I checked. Then I checked 4 other spell checkers. Here's why it…
Yesterday I realized that Grammarly might be training AI on EVERYTHING I type. So I checked. Then I checked 4 other spell checkers. Here's why it…
Beliebt bei Michael Georg Speller
Berufserfahrung
Ausbildung
Veröffentlichungen
-
Shit happens – this time you got hit by an ICT-related incident...
LinkedIn
We will have reported the ICT-related incident and so we have done all we ought to do as claimed by the regulator!"
Answers like these make me doubt whether internal legal departments, or internal auditors, or in general the 3rd LoD were sufficiently involved in the current hashtag#NIS2 or hashtag#DORA realization projects.
Uhm, yes - sorry to bother you again with a personal hashtag#DORA fun episode.
"What about your self-interests? - e.g. compensation of resulting…We will have reported the ICT-related incident and so we have done all we ought to do as claimed by the regulator!"
Answers like these make me doubt whether internal legal departments, or internal auditors, or in general the 3rd LoD were sufficiently involved in the current hashtag#NIS2 or hashtag#DORA realization projects.
Uhm, yes - sorry to bother you again with a personal hashtag#DORA fun episode.
"What about your self-interests? - e.g. compensation of resulting damages or prosecution of aggressors, etc.?", I continue asking and look into empty faces.
After reading my stuff, sharpen your awareness to get the most out of regulatory requirements: Your self-interest!
Do not just restart the machines and thus destroy any evidence needed during the legal aftermath.
There are more lessons to learn from regulatory requirements if you are not just ticking minimum boxes and ignoring what is not directly or explicitly addressed.
Getting compensation for damages is a part of resilience, too.
Maybe re-active, but very efficient! -
Mystery Audits to get reliable results about operational resilience for #DORA, #NIS2, #ESG, ...?
Michael Georg Speller
Leading financial institutions have discovered that mystery shopping is an effective method to evaluate service quality and reliability in B2C areas.
But why limit this approach to B2C?
Applying mystery audits in B2B areas for Operational Resilience Tests can provide more reliable and objective insights than standard procedures. -
General Contractors and 3rd Party Risks in Your Value Chain
LinkedIn
In the financial sector, general contractors play a decisive role in the successful implementation of ICT projects or in the management of ongoing operations or important functions as interim replacements for missing own staff.
Due to the special regulatory obligations in these industries, improper selection of prime or general contractors can lead to non-compliance with laws or regulations, customer claims, delays, cost overruns, litigation, lost profits, poor quality, and recourse and…In the financial sector, general contractors play a decisive role in the successful implementation of ICT projects or in the management of ongoing operations or important functions as interim replacements for missing own staff.
Due to the special regulatory obligations in these industries, improper selection of prime or general contractors can lead to non-compliance with laws or regulations, customer claims, delays, cost overruns, litigation, lost profits, poor quality, and recourse and sensitive fines. -
What´s your strategy during an audit? - bury your head in the sand or boldly present Self-Identified Issues (SII)...
LinkedIn - Pulse
In the Bible, in the second book of Samuel, you can read how the future King David reacted when he heard of King Saul's death in the battle of Mount Gilboa: He had the reporter unceremoniously slain by one of his men.
Killing the bad news bearers has generally been popular for a while. Corresponding reports can be found in ancient Greece and the Aztec ruler Montezuma is said to have ordered the execution of the messengers when the Spaniard Cortez was reported to him.
Now in 2021…In the Bible, in the second book of Samuel, you can read how the future King David reacted when he heard of King Saul's death in the battle of Mount Gilboa: He had the reporter unceremoniously slain by one of his men.
Killing the bad news bearers has generally been popular for a while. Corresponding reports can be found in ancient Greece and the Aztec ruler Montezuma is said to have ordered the execution of the messengers when the Spaniard Cortez was reported to him.
Now in 2021 over the last months, we have faced a lot of requests asking to quickly heal or somehow otherwise whitewash "things" people identified or assumed as possible regulatory issues. -
Consulting vs. Contracting - a matter of adding value or counting hours...
LinkedIn - Pulse
Working with consulting vendors often lacks efficiency due to unclear expectations and wrong governance approach - when companies hire someone to support their business, they often fail to identify exactly enough what they want to achieve.
-
8 Draft Theses on Ethical Guidelines before Outsourcing AI services
LinkedIn - Pulse
As most customers are solely concerned by the usually fined potential misuse of personal data, we developed 8 theses to think about before undertaking a "semi-blind" outsourcing driven by technical or sales departments due to some neat features.
-
New Standard Contractual Clauses (SCCs) for GDPR data transfers between EU and 3rd countries - 5 important steps
LinkedIn - Pulse
As a consequence of the Shrems II case, the so-called standard contractual clauses (SCCs), i.e. the “pre-approved clauses” issued by the European Commission had to be reworked and are in place now.
With regard to new contracts, companies will have to replace the former sets of SCCs starting a least September 27th, 2021 - nevertheless it is recommended to use the new SCC´s in current negotiations from now on. -
EU Digital Operational Resilience Act (DORA) planned for 2022
LinkedIn - Pulse
From 2022, the Digital Operational Resilience Act (DORA) should ensure uniformity and homogenize the state of different regulations in the entire EU economic area for all participants to guarantee the operational stability of operational systems in the long term by preparing companies for conceivable disruptions and threats in ICT to make incidents robust survive.
-
Turn over from STOP-LOSS to TAKE-PROFIT during supervisory audits
LinkedIn - Pulse
The costs of correcting one single finding after a supervisory audit in the banking industry vary depending on the maturity level of the audited as well as the maturity level of the project organization between 20K and 250K Euros. In some EU countries, penalties will have to be calculated on top. Any Euro you lose in the case of expensive measures or penalties will have to be earned again elsewhere in your organization.
-
Top 10 hints when to "call a bluff" during Cloud Outsourcing Negotiations
LinkedIn - Pulse
As a regulated (financial) industries customer, you should definitely "call the bluff" during contract negotiations with public cloud service providers as soon as you are facing one or more of the following 10 phrases:...
-
ESMA´s Consultation on Outsourcing to Cloud Service Providers
LinkedIn - Pulse
The ESMA (European Securities and Markets Authority) recently published its consultation on draft cloud outsourcing guidelines to help investment banks comply with financial services regulations when processes or functions of investment activities are outsourced to cloud service providers (CSPs).
-
Renewal of the German BSI's Cloud Computing Compliance Controls Catalogue (C5:2020)
LinkedIn - Pulse
The German Federal Office for Information Security (BSI) has fundamentally revised its Cloud Computing Compliance Controls Catalogue (C5:2016), which was dated from 2016. Due to its quality, the catalogue was widely accepted beyond the borders of Germany.
-
Guidelines on ICT and security risk Management released by the EBA
LinkedIn - Pulse
After about one year of work the EBA has released the 2019 Guidelines on ICT and security risk management yesterday (28th. Nov. 2019)
The final document now counts 129 pages, though the "core" is concentrated on pages 14 to 29 (section 3.1. to 3.8), whereas pages 34 to 129 are used to document the EBA´s feedback on the public consultation and give some interesting insights about the motivation and background of the different participants of the discussion.
Sprachen
-
English
Muttersprache oder zweisprachig
-
German
Muttersprache oder zweisprachig
Erhaltene Empfehlungen
3 Personen haben Michael Georg Speller empfohlen
Jetzt anmelden und ansehenWeitere Aktivitäten von Michael Georg Speller
-
Liebes LinkedIn Netzwerk, wir richten unser BANK IM BISTUM ESSEN eG Vorstandsteam für die Zukunft aus. Falls jemand jemanden kennt, der jemanden…
Liebes LinkedIn Netzwerk, wir richten unser BANK IM BISTUM ESSEN eG Vorstandsteam für die Zukunft aus. Falls jemand jemanden kennt, der jemanden…
Beliebt bei Michael Georg Speller