Tuesday, June 2, 2020

Flying-cab drivers wanted

Air taxis are coming. Until they can fly autonomously, this nascent industry will need many pilots.
Flying-cab drivers wanted

Dynamic Networks Improve Remote Decision-Making

Dynamic Networks Improve Remote Decision-Making

The idea of collective intelligence is not new. Research has long shown that in a wide range of settings, groups of people working together outperform individuals toiling alone. But how do drastic shifts in circumstances, such as people working mostly at a distance during the COVID-19 pandemic, affect the quality of collective decision-making? After all, public health decisions can be a matter of life and death, and business decisions in crisis periods can have lasting effects on the economy.

During a crisis, it’s crucial to manage the flow of ideas deliberatively and strategically so that communication pathways and decision-making are optimized. Our recently published research shows that optimal communication networks can emerge from within an organization when decision makers interact dynamically and receive frequent performance feedback. The results have practical implications for effective decision-making in times of dramatic change.

How Feedback and Network Flexibility Affect Collective Intelligence

In two web-based experiments, each involving more than 700 people recruited online, we examined how organizational structures influence collective decision systems.

In both experiments, participants were asked to estimate, in a series of 20 rounds, the strength of statistical correlations between two variables (such as height and weight) that were graphed on a scatterplot. Without the participants’ knowledge, we introduced distracting statistical noise into the graphed data and systematically varied the degree of distraction across individuals. Then, in the middle of the 20-round series, we abruptly shuffled the noise levels (thereby inducing a drastic shift). Monetary prizes were awarded for accurate performance.

Our aims were to test whether networks of participants that were dynamically structured would make more accurate estimates than either static networks or individual participants, and whether getting frequent, high-quality feedback on performance would make participants perform better.

In the first experiment, groups of 12 participants were randomly assigned to one of three conditions: (1) solo, whereby each group member did the 20 estimation rounds in isolation; (2) static network, in which each member submitted his or her estimates after collaborating with three other preassigned participants; or (3) dynamic network, in which members chose three collaborators to interact with before submitting their individual answers. In all conditions, participants received performance feedback after each round, but those assigned to the dynamic condition were also able to choose three new collaborators after getting the feedback.

In the second experiment, the 12-member groups were randomly assigned to one of four feedback scenarios: (1) solo decision-making, with no feedback given on performance after each round; (2) network decision-making, also with no performance feedback; (3) network decision-making, in which each participant received feedback only on his or her own performance; or (4) network decision-making, in which full feedback on all participants’ performance was shown to everyone. In all but the solo condition, participants could change which three collaborators they interacted with during subsequent rounds.

Our results showed that even the best-performing individuals benefited from interacting with a network of peers — and that dynamic networks, in which peers chose their collaborators, improved individuals’ performance significantly compared with static networks. We also found that when given full feedback, networks of participants deftly adapted to changes by shifting influence to people who had better information, thereby substantially reducing individual error and benefiting from collective wisdom.

Decision-Making Networks in a Crisis Period

Our experiments illustrate the importance of dynamically configuring network structures and enabling decision makers to obtain useful, recurring feedback. But how do you apply such findings to real-world decision-making, whether remote or face to face, when constrained by a worldwide pandemic? In such an environment, connections among individuals, teams, and networks of teams must be continually reorganized in response to shifting circumstances and challenges. No single network structure is optimal for every decision, a fact that is clear in a variety of organizational contexts.

Public sector. Consider the teams of advisers working with governments in creating guidelines to flatten the curve and help restart national economies. The teams are frequently reconfigured to leverage pertinent expertise and integrate data from many domains. They get timely feedback on how decisions affect daily realities (rates of infection, hospitalization, death) — and then adjust recommended public health protocols accordingly. Some team members move between levels, perhaps being part of a state-level team for a while, then federal, and then back to state. This flexibility ensures that people making big-picture decisions have input from those closer to the front lines.

Witness how Germany considered putting a brake on some of its reopening measures in response to a substantial, unexpected uptick in COVID-19 infections. Such time-sensitive decisions are not made effectively without a dynamic exchange of ideas and data. Decision makers must quickly adapt to facts reported by subject-area experts and regional officials who have the relevant information and analyses at a given moment.

Higher education. At MIT, where we’re working toward reopening the campus, the central administration first consulted medical experts and their models in order to develop a plan. Administrators then realized that they also needed input from departments and facilities managers, right at the university. That’s because they had to learn what interactions really occur during normal daily operations — for example, how many people congregate in particular places on campus for specific purposes.

The administration has now involved experts from the MIT Quest for Intelligence (including both of us) to develop a way to monitor social distancing. The effort focuses on not only epidemiologic models but also campus-sourced facilities specifications and educational (classroom, lab) logistics data. The current goal: real-time organizational sensing that flags potential problems, convenes the right advisers to address those problems, and makes adjustments in response to frequent feedback before moving on to the next dilemma, involving whatever network of experts and managers is needed.

Industry. When car manufacturer Ford decided to make face shields for health workers this past April, the company didn’t just have to involve designers and engineers. To distribute the assembled products effectively, it also needed an advanced-product expert with experience in supply chain logistics, a software designer, a logistics-savvy public relations manager, a government affairs expert, and a regional communications manager with deep experience in how people collaborate remotely. In short, the network of decision makers had to change, responding frequently to new information, in order to get the job done. Millions of face shields were eventually deployed.

During a dynamically evolving pandemic, adhering to a static organizational chart to make decisions about the future, or even the present, is simply not viable. Leaders must rethink how they structure their decision-making networks and take a more flexible approach in adapting those networks to changing circumstances and to valuable feedback from a variety of domains.

Crisis is, by definition, at odds with stasis. Recognizing the new reality — and acting accordingly — will help leaders avoid dangerous pitfalls with long-term consequences and discover opportunities for reimagining optimal performance in an altered world.


Dynamic Networks Improve Remote Decision-Making

Develop Your Cyber Resilience Plan


Imagine rushing through a crowded airport with your locked suitcase. Before you can get to your closing gate, someone steps in front of you, blocking your way. Your belongings are safe in your suitcase, but you can’t proceed with your travel plans. In this analogy, your suitcase functions like cybersecurity — protecting against the attacks you can anticipate. However, because you’re lacking cyber resilience — the ability to withstand unanticipated disruption — your travel plans are foiled nevertheless.

Cybersecurity and cyber resilience are distinct concerns, and understanding the difference is key to preparing an effective response to cyberthreats. The misconception that a cybersecurity program can substitute for cyber resilience is potentially disastrous. While cybersecurity focuses on keeping attackers out, cyber resilience aims instead to minimize the mayhem caused by attackers who do manage to penetrate networks.

As cyberthreats evolve, cybersecurity ratings are poised to become as important a factor as credit ratings, making failure to implement a professional cyber resilience program more than a reputational risk. A thoughtfully designed cyber resilience program will become not only a competitive advantage but a requirement for sustained growth.

The four-phase cyber resilience framework described here — preparation, detection, response, and recovery — can enhance an organization’s capacity to sustain operations through a cyberattack while minimizing both disruption and reputational harm. Stakeholders involved in developing such a plan may include C-level executives such as the CIO and chief information security officer (CISO), along with the security operations center and the incident response team. This article explores each of the four phases and provides examples of the types of challenges companies encounter, as well as opportunities for becoming more cyber resilient.

Phase 1: Preparation

Effective preparation is a collaborative effort of greatest importance and directly proportional to the effectiveness of the resilience plan as a whole. This first phase requires the most organizational support in terms of resources and budget and entails collaboration across the organization. Working together, senior leadership, information security experts, and business continuity managers can prepare a comprehensive plan to sustain critical capabilities and operations through a cyberattack. Necessary preparation steps include the following:

Develop cyber governance policies. Begin by defining the organization’s risk tolerance — that is, what you are willing to lose access to for the sake of sustaining operations. IT security leaders can then develop a transparent policy tailored to the organization’s risk tolerance. Plan the personnel and technical capabilities needed based on the maximum time, in hours or days, that the organization can last before using backup systems and data sources. Decide how recent backup data must be — hours, days, or weeks old — to support operations. Policies should also cover the timely reporting of suspicious activity and the frequency of monitoring threat intelligence reports, specifying when to seek assistance from private and/or federal cyber authorities when anomalies are detected.

Know your current systems, technologies, and data sources. Determining which systems are actually at risk is an ongoing, repeated process that requires prioritization of the systems and data sources to protect. To identify what’s vulnerable and create a plan for securing those high-risk elements, first prioritize critical business functions and associated systems (including data sources and vendor exchanges). Then explore how these critical assets could be affected in various breach scenarios.

Cybersecurity managers should continually update an inventory of the network’s necessary data assets and systems and document the following:

  • How any system is identified on the network and its access procedures, such as via application programming interfaces.
  • Any technologies that interface with the network, such as internet-of-things devices.
  • Data sources used by systems and technologies on the network.
  • The individuals and groups that have access to these systems.
  • Regular checks that active security controls are functioning properly and “on.”

Consistently update and test backups. It’s hard to overstate the importance of frequently updated, regularly tested backups. Teams should create documentation for backup storage locations and check regularly to ensure that the backups are occurring as scheduled.

To minimize downtime in case of attack, the IT security and business continuity teams must ensure that any media and resources needed to import the backup are readily accessible. It’s important, too, to know how long backup data retrieval and import take, and to account for physically transporting data servers or hardware if necessary. During the 2017 WannaCry ransomware attack that paralyzed organizations worldwide, for example, many companies were hamstrung by their lack of such information: not knowing the kind of media storage used for backups, where backups resided, or who handled backups (internal personnel or outsourced resources); not understanding how to effectively employ their backups; or being unsure of the integrity of backup data.

Establish a due diligence vetting process for vendors. Design vetting procedures to ensure that vendors, particularly cloud service providers, have a resilience plan for their own business continuity. Some guidelines for vendor diligence include FedRAMP, the Federal Risk and Authorization Management Program, which the U.S. government developed to hold federal vendors to a specific set of standards and can guide an organization in developing standards suited to its needs.

Embrace automation. Using artificial intelligence (AI) and machine learning in cybersecurity platforms for self-defense can significantly insulate the organization from damage, because these technologies are able to learn from what they experience as “normal” and create alerts if they detect abnormal or atypical behavior. For example, AI and machine learning may readily detect unscheduled decreased system performance or downloads of bulk sensitive data at a nonscheduled time; this would trigger a shutdown of possibly infected systems, a snapshot of the activity log, and rerouted transactions (to a backup or mirrored server) to continue operations while diagnosing the threat.

Plan for alternative workspaces. To ensure that the workforce can operate in the event of an ongoing cyberattack, determine your needs for backup mobile devices and alternative workplaces with connectivity and network access that are ready to be used if needed during recovery.

Train, train again, and train one more time. Ongoing training — of the security team, customer-facing personnel, and back-end administrators — is essential for the team to understand what procedures to follow in transitioning to a business continuity plan in the midst of a cyber event. CISOs should run tabletop exercises on stopping the attack and on remaining operational during the attack. They should also encourage departments to role-play their own critical incidents, including reverting to manual processes if technical systems are not functional. Key organizational stakeholders (departmental managers and operational personnel) and the cybersecurity team need to understand what to do when trouble hits, so the plan itself must be updated and tested at least once a year. It’s vital that all stakeholders know who to call and what to do to get the company up and running in a hurry.

Phase 2: Detection

Detection, like preparation, requires collaboration. Depending on the organization’s capacity and needs, a centralized unit, such as the security operations center, may be responsible for analyzing, assessing, and triaging cyberattacks, at which point an incident response team is activated. For most companies, this response begins at the C-level, where the CIO or CISO may assess the severity and recommend strategies to mitigate impacts on business objectives. From there, it is a cross-collaborative effort across cyber, information, operations, and business teams to implement monitoring and weigh in on real-time business impacts. The following steps are necessary for robust detection capabilities:

Develop cyberthreat awareness. Global threat intelligence and analysis enables situational awareness of potential threats, actual attacks, and best-practice mitigation techniques. Threat intelligence feeds from governmental agencies and private-sector vendors — such as FireEye, an industry leader in global threat intelligence reporting, and InfraGard, a public-private consortium sponsored by the FBI for threat intelligence sharing — are essential attack detection tools. Organizations should ingest threat information and orchestrate automatic triggers (enabled by AI and machine learning) for automatic data backup and recovery and targeted system isolation responses.

Invest in active monitoring protocols. Security information and event management software gives information security professionals a track record of the activities within their IT environments and provides insight into abnormal network activity, particularly that which could down systems or lose or corrupt data. Investing in such active monitoring protocols can be orchestrated by managed security offerings, through security-as-a-service options, or through cloud services that seek to make organizational data and systems assets undiscoverable by cyberattackers.

Act on threats early. Threat detection is most effective if acted upon fast, so create and enforce threat detection policies for employees and other organizational partners. Federal authorities like the FBI should be regarded not as a last resort but as trusted partners to determine the identity of attackers, reduce the likelihood of repeated attacks, and aid in more effective and timely responses and recovery.

Preserve and share information on attacks. From the earliest point possible in the intrusion or attempted breach, preserve relevant information, such as network web logs that can be forensically analyzed to ascertain cyberattacker techniques, tactics, and procedures. Share this data with a trusted noncommercial threat intelligence partner like the FBI to help foster a robust ecosystem of cyber resilience.

Phase 3: Response

How should the organization react to a threat or attack? Key objectives are to limit damage, improve recovery time, resume operations quickly, and help safeguard the organization from fiscal or reputational harm.

A variety of players may be involved in this step: The incident response team may carry out mitigation strategies, coordinated at the C-level, which in turn updates executive leadership on progress. Executive leadership and operations managers may keep an eye on social media outlets to gauge external stakeholder response and prepare communications related to HR and public relations (PR) for employees, customers, law enforcement, investors, and the press accordingly. Legal team members can help executive leadership determine possible legal implications and decide whether to involve law enforcement.

Response activities will fall into two basic categories:

Technical response activities. Because technical response activities will depend on the specific nature of the attack, it’s impossible to cover all possible responses here. Common technical response activities may involve notification, escalation, interaction, or approval for steps to minimize the risk of disruption to operations and prevent the attack from reaching a crisis level. To contain a breach or limit damage, procedures may involve ensuring network segmentation, isolating affected systems, disconnecting all the links from the network, turning off computers to stop the threat from spreading, and employing effective backup systems when primary systems fail.

Business response activities. To ensure that cyber incident response initiatives are carried out promptly and properly, the organization should coordinate internal and external communication, carefully determining if, when, and how the breach will be publicized and communicated to stakeholders such as partners, customers, boards, legal teams, and the media. Other response activities may include ordering audits; overseeing regulatory compliance and data assurance; and making investments to mitigate technical harm or to protect the brand, such as free credit-monitoring services or funds for customers to offset harm inflicted by a data breach.

Phase 4: Recovery

The recovery phase involves retrieving data, returning to normal operations (using alternative workplaces identified in the preparation step, if necessary), tracking activities and costs resulting from the incident, and fine-tuning future resilience plans based on lessons learned. Essential players include the CIO/CISO, to oversee recovery and forensic activities, report the incident if required, and document incident details for senior leadership. HR or PR personnel may inform internal or external stakeholders about the recovery process, the business impact, and the plan for resuming regular operations. Executive and operational managers may oversee the resumption of business operations, assess postattack business impacts or damage, file needed insurance claims, and offer feedback on the effectiveness of the plan itself. Primary recovery activities involve the following:

Data recovery. Reestablishing business operations may involve backing up, recovering, and restoring data corrupted by an attack. Cloud disaster recovery, primarily an infrastructure-as-a-service solution, backs up designated system data on a remote offsite cloud server. Ready access to cloud-based or offsite data storage is essential. Security experts may need to ascertain whether any data has been damaged or completely destroyed.

Documentation and analysis. Documenting and assessing the entire episode for lessons learned is essential for improving preparation for subsequent attacks. The organization should analyze its response with questions such as the following:

  • What happened and when? Was the incident found in a reasonable amount of time?
  • Were the right personnel available to respond? How well did staff members and management perform in dealing with the incident? Were documented procedures followed?
  • Did recovery and restoration happen as quickly as expected? Were backup files available and up to date?

Response assessment and adjustment. The organization’s risk posture, as defined in the preparation phase, should be revisited — especially after a significant security incident — to determine whether previously established plans and investments provided the desired outcomes during the attack. Questions to consider include the following:

  • Were any steps or actions taken that might have inhibited the recovery?
  • What will staff and management do differently the next time a similar incident occurs?
  • What corrective actions can prevent similar incidents in the future?
  • What additional tools or resources are needed to detect, analyze, and mitigate future incidents?

A four-phase cyber resilience plan that identifies clear roles and responsibilities, is carefully crafted to meet organizational needs, and is consistently updated to maintain data security can position an organization to face evolving cyberthreats while minimizing disruption, decreasing damage, and sustaining essential operations. Organizations must remember that cybersecurity is not the same as cyber resilience; should the first fail, the second must prevail to ensure the organization’s survival in an ever-evolving threat landscape.


Develop Your Cyber Resilience Plan

Monday, June 1, 2020

COVID-19 and student learning in the United States: The hurt could last a lifetime

New evidence shows that the shutdowns caused by COVID-19 could exacerbate existing achievement gaps.
COVID-19 and student learning in the United States: The hurt could last a lifetime

Asia wealth management post-COVID-19: Adapting and thriving in an uncertain world

Asia’s wealth managers—new entrants and incumbents alike—must reinvent themselves as agile and flexible organizations in order to succeed for the long term once the pandemic is past.
Asia wealth management post-COVID-19: Adapting and thriving in an uncertain world

Banking imperatives for managing climate risk

More than regulatory pressure is driving banks to manage climate risk. Financing a green agenda is also a commercial imperative—but specialized skills are needed to protect balance sheets.
Banking imperatives for managing climate risk

The investigator-centered approach to financial crime: Doing what matters

The investigator-centered approach to fighting financial crime fosters collaboration among banks, law-enforcement agencies, and regulators for greater effectiveness, efficiency, and social impact.
The investigator-centered approach to financial crime: Doing what matters