Fin Maverick
Foundations VocabularyAccounting & ReportingEconomics & MacroQuant Methods & ProgrammingBusiness & Company AnalysisCorporate Finance & ValuationBehavioural Finance
Banking & Market InfrastructureFixed Income & RatesDerivatives & Structured ProductsPublic EquitiesTransactions & DealsPortfolio ConstructionFunds & AMCs
Private Markets & AlternativesRisk, Treasury & ControlAI & Digital FinanceStochastic Calculus & PricingWealth & Personal FinanceIndian Markets & RegulationProfessional Practice
CalculatorComparison
Frameworks
Explore Bootcamps
Equity ResearchPortfolio ManagementMutual Fund MasteryFinancial LiteracyInvestment Banking Analyst
Private Equity AnalystHedge Funds AnalystBreaking Into VCBreaking Into QuantsAI For Finance
Financial Analyst ProgramRisk Management ProgramPrivate Wealth ManagementDebt Capital MarketsDerivatives Foundation
Explore Internships
Equity Research InternMutual Fund Intern
Portfolio Management InternFinancial Literacy Intern
Explore Micro Courses

Equity Research6

Writing an Investment ThesisBuilding a Discounted Cash FlowReading an Annual Report FastReading a Sector Before a CompanySpotting Quality of Earnings Red FlagsBuilding a Revenue Forecast From Drivers

Portfolio Management3

Rebalancing: When, Why and What It CostsStrategic and Tactical Asset AllocationMeasuring Risk in a Portfolio

Mutual Fund Mastery3

Comparing Funds Without Being FooledHow a NAV Is Struck and Which Day You GetReading a Fund Factsheet Properly

Derivatives Unlocked4

Hedging a Real ExposureThe Greeks, PracticallyFutures, the Basis and What Moves ItReading an Option Payoff

AI For Finance2

Retrieval and Grounding for FinanceDocument Extraction in Finance

Breaking Into Quants4

Backtesting a StrategyHypothesis TestingCleaning Financial DataRegression for Finance

Breaking Into VC3

Sizing a MarketReading a Term Sheet as a FounderHow a Venture Round Actually Works

Financial Analyst Program4

Common Size and Trend AnalysisReading a Cash Flow StatementRatio Analysis That Says SomethingBuilding a Working Capital Schedule

Risk Management Program2

Credit Exposure and How It Is ReducedValue at Risk and What It Hides

Investment Banking Analyst3

Precedent Transactions and Why They DifferReading a Term Sheet StructurallyBuilding a Comparable Companies Table

Private Wealth Management3

Tax Aware Portfolio DecisionsBuilding a Client Risk ProfileGoal Based Planning Arithmetic

Debt Capital Markets3

Analysing an Issuer's CreditDuration and What It Does Not Tell YouBond Pricing and Yield Mechanics

Private Equity Analyst2

Fund Waterfalls and CarryThe LBO in Structure

Hedge Funds Analyst2

Short Selling MechanicsLong Short Mechanics
Courses
Explore Career Roadmaps
Investment Banking AnalystEquity Research AnalystVC AnalystPrivate Equity AnalystHedge Funds Analyst
Quant AnalystAI For FinanceFinancial Analyst ProgramPrivate Wealth ManagementDebt Capital Markets
Risk Management ProgramDerivatives FoundationPortfolio ManagementMutual Fund Mastery
PartnershipsShowdown
Log inSign up
Risk Management Program · CoreTrack
1Risk, Treasury & Financial Control
iRisk Foundations
Risk Appetite, Tolerance, Capacity…The Risk Taxonomy and UniverseRisk Register vs Risk MatrixStress TestingScenario Analysis vs Stress TestingImpact and LikelihoodLikelihoodThe Risk EventRisk Assessment
iiEnterprise Risk Management
Enterprise Risk ManagementThe Four Risk TreatmentsRisk CultureRisk MaturityRisk Monitoring
iiiRisk Governance
Risk GovernanceHow to set a…The Risk PolicyThe Risk OwnerThe Risk Committee and Its CharterThe Risk Limit FrameworkRisk EscalationHow to set a…
ivCredit and Counterparty Risk
Collateral AgreementsCollateral vs NettingProbability of DefaultExposureCounterparty ExposureConcentration Risk vs Wrong Way RiskCounterparty Risk vs Credit RiskHow to assess Counterparty ExposureHow to assess Concentration Risk
vMarket Risk
Market RiskSensitivity MeasuresThe Hedging PolicyInterest Rate Risk in the Banking BookIRRBB vs Market RiskExpected ShortfallEconomic Value of EquityVaR BacktestingOpen PositionValue at RiskValue at Risk and Expected ShortfallEconomic Value SensitivityFX ExposureValue at Risk vs Expected ShortfallEarnings at Risk vs…FX Transaction Risk vs…How to measure Interest…How to measure Foreign…
viLiquidity Risk
Liquidity Stress TestingLiquidity Gap vs Liquidity BufferMaturity MismatchThe Debt Maturity ProfileFunding ConcentrationSurvival HorizonThe Contingency Funding PlanNet Stable Funding RatioLiquidity Risk vs Funding RiskLiquidity Coverage RatioLiquidity Gap and BufferHow to run a Liquidity Gap Analysis
viiOperational Risk
Operational LossThe Loss EventRisk and Control Self AssessmentException ManagementInformation Security as a…Segregation of DutiesIssue ManagementThe Near MissRoot Cause Analysis in RiskThe Fraud TriangleCyber Risk vs Third Party RiskHow to run a…How to assess Third…
viiiRisk Reporting, Data and Model Risk
Model RiskModel Validation vs BacktestingHow to run Model ValidationData Governance in RiskModel Risk vs Data RiskKey Risk IndicatorsManagement InformationRisk ReportingRisk ScoreEarnings at RiskRisk Adjusted ReturnEarly Warning IndicatorsHow to build a KRI Dashboard
ixTreasury
Corporate TreasuryAsset Liability ManagementIntragroup FundingThe Treasury PolicyThe Treasury Management SystemThe Cash ForecastCash Pooling and ConcentrationHow to build a Cash Forecast
xFinancial Controls and Assurance
Control AssuranceThe Control LifecycleThe Assurance MapThe Audit FindingIssue RemediationInternal Financial ControlsControl Design vs Control EffectivenessHow to map Internal Financial ControlsHow to test Control…Control DeficiencyMaterial Weakness
xiOperational Resilience
Operational ResilienceBusiness Continuity and Disaster RecoveryBusiness Continuity vs Operational…Crisis ManagementDisaster RecoveryIncident Management

Information Security as a Risk Category, Not a Technology Problem

Information security protects three properties of information: that only the right people can see it, that it has not been altered, and that it is there when needed. Information security is a risk category rather than a technology problem because most of what protects those properties is a decision about who may do what, taken by people who do not work in technology at all.

Almost everybody arrives with the same habit of mind, and it has to go first. Asked what protects a bank's information, most people describe equipment. Something at the edge of the network, something that scrambles a file, something that watches traffic. All of that equipment exists, and information security is none of it. Information security is an exposure: something that can go wrong, that has a named owner, that is written into a policy, that gets measured, that is reported to a committee, and that turns up in a loss record filed under somebody else's heading. Read that way, information security stops being a specialist subject and starts behaving exactly like every other exposure in risk management.

Everything below rests on separating the asset from the machine. The asset being protected is information and the ability to act on it, not the equipment it happens to sit on. Once that separation is held, the controls stop looking technical at all. Who is allowed to do this. Who checks. Who loses access when somebody leaves. How quickly a change of circumstances reaches the systems. Each of those is a process question with a named owner, and the failures at this invented bank occurred in exactly those questions. How any given technology works is a separate subject. The exposure is the one that gets governed.

What does information security actually protect, and from what?

Start away from any bank. A household keeps a folder of papers: a school certificate, a property deed, a small ledger of who was lent what. Three separate bad things can happen to that folder and they are genuinely different bad things. A visitor can read the ledger and learn what the household would rather nobody knew. Somebody can quietly alter a figure in it, so the record still exists and is now wrong. Or the folder can be locked in a cupboard on the one morning the deed is needed at a registrar's counter. Nothing was stolen in the third case and nothing was read. The information was simply not there at the moment it was wanted.

Information securityThe protection of three properties of information: that only the right people can see it, that it has not been altered, and that it is there when needed. is the protection of exactly those three properties, and the reason to name them one at a time is that a subject with three named properties is a subject controls can be built against. A subject described as machines is a shopping list. Naming the three is what stops the whole discipline turning into an inventory of equipment. Confidentiality is that only the right people can see it. Integrity is that it has not been altered. Availability is that it is there when needed.

The three sentences have something in common. Not one of them mentions a machine. Each is a statement about the information itself and about the ability to act on it. The separation between information and machine is what everything below depends on, and it is also why the controls that follow are almost all decisions rather than devices: a list of who may see a customer record, a rule that a change leaves a trace, a check that the list is still right this month. At Vindhya Commercial Bank Limited, invented, the same three properties carry the same three questions, and the bank writes them into policy PL7, its information security policy, one of the nine policies numbered PL1 to PL9.

Unless one boundary is drawn now, the third property swallows the subject. Availability as a property is in scope: whether the information is reachable at all. Availability as a service promise, meaning how long an important business service may be down before somebody must act, is a different measurement kept in a different record and covered in the resilience subject area. The first two properties, and the access decisions that sit under all three, carry the rest of the argument.

WHAT IS ACTUALLY BEING PROTECTED AT VINDHYA COMMERCIAL BANK LIMITED, INVENTED Three properties of the information itself. Not one of them is a statement about a machine. THE ASSET IS THE INFORMATION AND THE ABILITY TO ACT ON IT CONFIDENTIALITY Only the right people can see it. The failure is somebody seeing what they had no business seeing. THE CONTROL THAT ATTACHES who may see it, and who checks that the list is still right INTEGRITY It has not been altered. The failure is a figure that moved with no record of anybody moving it. THE CONTROL THAT ATTACHES who may change it, and whether a change leaves a trace AVAILABILITY It is there when needed. The failure is the information being fine and unreachable. THE CONTROL THAT ATTACHES whether it is reachable, which the resilience material holds Every control here attaches to one of the three, and none of the three is a statement about equipment. Availability as a service promise is measured by the resilience material and is named here rather than taught. Vindhya Commercial Bank Limited, policy PL7 and every figure shown are invented.
Three properties of information, each with its own shape of failure and its own control, and not one of the three boxes describes a machine.
Try it out

What three properties does information security protect, and why does naming them matter?

Why is it a risk category rather than a technology problem?

A risk category is not a topic. A risk category is an object with a specific set of parts, and the test of whether something is one is simply whether all the parts are there. Does it have a definition that separates it from its neighbours. Does it have a named owner who can be asked about it. Does it sit somewhere in the taxonomy the institution uses to insist its list of risks is complete. Is there a policy. Is there a committee that receives it. Does it produce losses that land in the loss record. Information security passes on every part of that test, and passing every part is the whole argument.

At this invented bank the parts look like this. The definition is the three properties above. The taxonomy places it inside operational risk, at level one category TX4. Policy PL7 is the information security policy. Process PR9, access management and information security, is one of the nine processes numbered PR1 to PR9 across which the bank assesses its key controls, so the controls are counted and rated exactly as the controls over lending or settlement are. Committee G8, the information security committee, six members, receives it. Every structural part that makes credit risk a risk category is present here too. Treating information security as somebody else's technical specialism is therefore a governance decision and not a description of the subject.

The consequence is practical rather than philosophical. Treated as a technology problem, the questions asked are about equipment, and the answers come from people who can only speak about equipment. Treated as a risk category, the questions become the ones this material asks of every exposure. What is it. Who is the owner. How much of it is acceptable. Which controls sit against it. How much has it cost. Which indicator moves before it costs anything. Where is it reported and how often. Those questions are asked below, and two of the answers at this bank are uncomfortable.

Where do this bank's information security losses actually land?

Here is a question that sounds administrative and is not. If information security is a risk category, where in the loss record do its losses appear? Because the labelling scheme in use has no heading for them, the honest answer at this bank, and at a great many real ones, is that they appear nowhere as such. Operational losses at Vindhya Commercial Bank Limited are filed against seven event categories, and the seven are the Basel Committee's, published by the Bank for International Settlements at bis.org. The seven are internal fraud, external fraud, employment practices and workplace safety, clients products and business practices, damage to physical assets, business disruption and system failures, and execution delivery and process management. Read that list again looking for information security. Information security is not there.

So the losses go somewhere else. Incident I7 at this invented bank, in month 7, was a phishing campaign against internet banking customers that reached 312 customers, who were reimbursed. Gross loss Rs 1.8 crore, recovery Rs 0.3 crore, net loss Rs 1.5 crore. Incident I7 is filed in category 2, external fraud, and the classification is perfectly correct: an outsider took money by deception. The same event is also, unmistakably, a failure of the first property: people who should not have been able to act on customer information were able to act on it. One event, two true descriptions, and only one of them can be the label in the category column.

The consequence follows immediately. Total the category column at this bank and information security comes to nothing at all. There is no line to total. Read the thirteen incidents one by one and the year contained at least one, at Rs 1.5 crore net. The two readings of one record disagree, and the second reading is only available to somebody who has been told to go and read. The practical meaning of a category that exists in the taxonomy and not in the labelling scheme is this: the number has to be built by hand every time anybody asks for it.

Two smaller points sit underneath. First, an availability failure would land in category 6, business disruption and system failures, so if the third property is included the reading gets wider still. Whether the year's two category 6 incidents belong to this subject is a judgement the record does not settle. The unsettled judgement is precisely the difficulty rather than a gap in the case. Second, the loss record is not the only record, and it is not even the most informative one on this subject. The event that says the most about access management at this bank cost nothing at all, so it appears in no loss figure anywhere. The event turns on access management, and access management needs a name first.

WHERE THE LOSSES LAND: NET LOSS BY EVENT CATEGORY, Rs CRORE, INVENTED BANK Thirteen incidents, Rs 43.8 crore net for the year, sorted into seven categories. There is no eighth. NET LOSS FOR THE YEAR, Rs CRORE 1 internal fraud Rs 18.1 crore 2 external fraud Rs 6.3 crore 3 employment practices and safety Rs 1.2 crore 4 clients, products and business practices Rs 6.8 crore 5 damage to physical assets Rs 0.6 crore 6 business disruption and system failures Rs 6.4 crore 7 execution, delivery and process management Rs 4.4 crore information security NO SUCH CATEGORY EXISTS, SO THERE IS NO BAR TO DRAW The lime segment inside category 2 is incident I7, Rs 1.5 crore net, a phishing campaign that reached 312 customers. Read the category column alone and this bank recorded no information security losses at all in a year that held at least one. Net loss by category, Rs crore: 18.1, 6.3, 1.2, 6.8, 0.6, 6.4 and 4.4, which sum to the year's Rs 43.8 crore. Every figure is the invented bank's own. The seven categories are the Basel Committee's, named here and not taught.
The bars are the seven categories the bank actually files against, and the empty dashed row beneath them is the reason its information security total has to be read rather than added.
Event categoryIncidentsNet loss, Rs croreShare of the year
1 internal fraud218.141.3%
2 external fraud, holding incident I726.314.4%
3 employment practices and workplace safety11.22.7%
4 clients, products and business practices26.815.5%
5 damage to physical assets10.61.4%
6 business disruption and system failures26.414.6%
7 execution, delivery and process management34.410.0%
The year, all seven categories1343.8100.0%

Every figure is the invented bank's own at month 12. The rupee column ties exactly to Rs 43.8 crore. The seven printed shares add to 99.9 per cent rather than 100.0 because each is rounded to one decimal; the exact shares do sum to 100.0, and no share has been adjusted to force the column.

Try it out

Totalling the seven event categories in search of this bank's information security losses: what does that search find?

What is access management, and why is the leaver the hard one?

Think about the keys to a small shop with four people working in it. Somebody joins and needs a key. Somebody moves from the counter to the stockroom and needs a different key, and the counter key should come back. Somebody leaves and the key should come back on the last day. Three events, three actions. Every shopkeeper knows the third is the one that goes wrong: the first two have somebody standing there wanting something, and the third has nobody wanting anything at all.

Access managementThe process deciding who may do what in which system, and keeping those decisions current as people join, move and leave. is that shop problem at institutional scale. Access management is the process deciding who may do what in which system, and, far more importantly, keeping those decisions current as people join, move and leave. Process PR9 at this invented bank carries exactly that, alongside information security more broadly, and it is one of the nine processes across which the bank counts its key controls. Notice how little of it is technical. Access management is a set of decisions about people and duties, written down, and a set of checks that the written record still matches reality.

The three events are not equally difficult and the reason is structural rather than cultural. A joiner has a start date, a manager who wants them productive, and somebody chasing until the access is granted. There is a person in the room whose day is worse until the thing happens. A mover is harder. The new access has somebody chasing it and the old access has nobody, and the classic result is a person who accumulates the rights of every desk they ever sat at. A leaver is hardest of all. On the day the access should end there is nobody left in the building who benefits from it ending. Every incentive in the joiner case runs the right way and every incentive in the leaver case runs the wrong way, and no amount of reminding people changes that arithmetic.

So a leaverSomebody who has left the institution, whose access should end at the same moment and often does not. is somebody who has left, whose access should end at the same moment and often does not. Everything that follows is about the gap between those two moments: how long it is, what decides its length, and what would close it rather than shorten it.

Derivatives Foundation Bootcamp — Fin Maverick

What is privileged access, and why is it treated separately?

Not all keys are the same. The shop has a key to the front door and a key to the safe, and somebody with the second one can do things nobody can undo. Privileged accessAccess that can change a system rather than merely use it, which is why it is granted narrowly and reviewed separately. is the second key. Privileged access is access that can change a system rather than merely use it: create accounts, alter what a control checks, change a rate table, switch a setting off. A person using a system leaves a trail through it. A person who can change the system can, in principle, change the trail itself.

Privileged access is granted narrowly and reviewed separately for a reason of consequence rather than suspicion. An ordinary account left open after somebody leaves is an exposure with a ceiling on it. A privileged account left open has no comparable ceiling: its reach includes the arrangements that would otherwise notice. The difference between ordinary and privileged access is not how much damage is likely but how much of the institution's own ability to detect sits inside the reach of the account. An institution that reviews all its accounts on one cadence has decided, without saying so, that those two things deserve the same attention.

How long can an access failure sit open, and what decides that?

Now the worked instance, and it carries the whole argument. In month 10 at Vindhya Commercial Bank Limited, a privileged access account belonging to a leaver stayed live for 46 days. The quarterly access reviewA periodic check that the access actually granted still matches the access that should be granted. found it. An access review is a periodic check that the access actually granted still matches the access that should be granted. The account had not been used for anything. Nothing was lost, nothing was reimbursed and no customer was affected. The event is near miss N5 in this bank's register of five near misses.

Because nothing was lost, it appears in no loss record at all. Near miss N5 is not in the Rs 43.8 crore of net operational loss for the year, it is not in any of the seven event categories, and a reader who only ever sees the loss report will never know it happened. A near missAn event that could have produced a loss and did not, which therefore appears in no loss record. is an event that could have produced a loss and did not, and the only place this one exists is a register somebody chose to keep. Keeping it cost nothing. One consequence is worth sitting with: the most informative event on this subject in the whole year was free to collect.

NEAR MISS N5: A WINDOW THAT OPENED SILENTLY AND CLOSED WHEN SOMETHING LOOKED One quarterly cycle at Vindhya Commercial Bank Limited, invented. Days along the bottom. DAY 0: THE PERSON LEAVES access should end here, and does not DAY 91: THE WORST CASE a departure the day after a review waits this long WINDOW OPEN, 46 DAYS the rest of the cycle a later departure would have used day 0 day 20 day 40 day 60 day 80 day 91 DAY 46: THE QUARTERLY ACCESS REVIEW RUNS the account is found, before it had been used AVERAGE WINDOW 45.5 DAYS on a 91 day cycle The dashed average at 45.5 days and the pin at 46 days are half a day apart, so at this scale they are drawn as one line. Near miss N5, month 10, cost nothing and appears in no loss record. Only the near miss register holds it. The 46 here is a number of days. This bank's risk register separately holds 46 entries, and the two are different objects. Vindhya Commercial Bank Limited, near miss N5 and the quarterly cadence are invented.
The window opened on the day somebody left and closed only when the quarterly review looked, which is what makes its length a design choice rather than an accident.

Now the arithmetic, and it changes what the 46 days means. A detective controlA control that finds the wrong thing after it has happened, whose usefulness is bounded by how often it runs. is one that finds the wrong thing after it has happened, and its usefulness is bounded by how often it runs. A review run every c days leaves a window of at most c days. Nothing can wait longer than c days before the next look. Suppose an account becomes wrong at a point in the cycle as likely to be one day as another. The assumption is the reader's own rather than a measurement this bank made, and on it the average window is c divided by two. A quarterly cycle is about 91 days. Half of 91 is 45.5.

Near miss N5 ran 46 days. The 46 days is half a day off the average the control was designed to produce, so it is not carelessness and not an outlier: it is the design working exactly as designed. The people who ran the quarterly review found the account precisely when the cadence said they would, and the length of the window was decided long before, by whoever chose quarterly. One honest refinement separates a real argument from a neat one: on a flat assumption every length from nil to 91 days is as likely as every other, so 46 is no more probable than 12 or 80. The cadence fixes two things: the ceiling, at 91 days, and the average, at 45.5. Nothing about 46 needs explaining once those two numbers are known.

Try it out

A leaver's privileged account stayed live 46 days and was found by a quarterly access review. Before the control below is moved: was 46 days unusually long?

Because the relationship is arithmetic and not judgement, it moves in a completely predictable way. The review cycleHow often a periodic control runs, which sets both the worst case and the average length of the window it leaves open. sets both numbers at once. Weekly, meaning about every 7 days, gives a worst case of 7 days and an average of 3.5, and the review is run 52 times a year. Monthly, at about 30 days, gives 30 and 15.0, run 12 times a year. Quarterly, at about 91 days, gives 91 and 45.5, run 4 times. Half yearly, at about 182 days, gives 182 and 91.0, run twice. Both lines are straight and both start at the origin, so halving the cycle halves the window and doubles the work in the same movement.

THE WINDOW A PERIODIC REVIEW LEAVES IS SET BY ITS CADENCE AND BY NOTHING ELSE Reader's own assumption: an account becomes wrong at a point in the cycle as likely to be one day as another. AT c = 91 DAYS, THE CYCLE THIS BANK RUNS worst case window 91 days, average window 45.5 days 4 reviews a year, and near miss N5 ran 46 days WORST CASE WINDOW, EQUALS c AVERAGE WINDOW, EQUALS HALF OF c 0 90 180 270 360 0 91 182 273 365 THE ACCESS REVIEW CYCLE c, IN DAYS WINDOW, IN DAYS Both lines are straight and both pass through the origin, so halving the cycle halves the window and doubles the reviews. Every cadence here is this invented bank's own choice. No authority named sets a review frequency.
Two straight lines and one dashed guide are the whole relationship: choosing the cadence already chooses both the ceiling and the average.
Play with it

Move the review cycle and watch the window move with it

One control: c, the access review cycle in days, from 7 to 365. Three consequences shown together: the worst case window, equal to c; the average window, equal to c divided by two; and the number of reviews a year, equal to 365 divided by c, rounded to the nearest whole review. The solved points are these. At c of 7 days the worst case is 7 days, the average 3.5 days, and there are 52 reviews a year. At c of 30 days, 30 days and 15.0 days, with 12 reviews. At c of 46 days, 46 days and 23.0 days, with 8 reviews. At c of 91 days, being the quarterly cycle this invented bank actually runs, 91 days and 45.5 days, with 4 reviews, and that is the case point. At c of 182 days, 182 days and 91.0 days, with 2 reviews. At c of 365 days, 365 days and 182.5 days, with 1 review. The control starts at 91 days, reproducing the case exactly, against the 46 days near miss N5 actually ran.

EVERY 7 DAYSc = 91 DAYSEVERY 365 DAYS
THE CADENCE DIAL: WHAT A DETECTIVE REVIEW CAN AND CANNOT BUY Vindhya Commercial Bank Limited, invented. The cycle is the reader's own dial, not a requirement from anybody. WORST CASE WINDOW, EQUALS c AVERAGE WINDOW, EQUALS HALF OF c NEAR MISS N5, 46 DAYS c = 91 DAYS 0 90 180 270 360 7 91 182 273 365 THE ACCESS REVIEW CYCLE c, IN DAYS REVIEWS A YEAR, being 365 divided by c, rounded to the nearest whole review 4 reviews a year NO VALUE OF c MAKES THE WINDOW NIL. A DETECTIVE CONTROL CANNOT ACT BEFORE THE THING IT DETECTS. The window closes only by replacing the cadence with a trigger, which is a different control and not a faster review.
Worst case window
91.0 days
Average window
45.5 days
Reviews a year
4

On a review every 91 days this bank leaves a window of up to 91 days, averaging 45.5 days, and runs the review 4 times a year. Near miss N5 ran 46 days.

Educational illustration. No authority sets a review cadence. An institution chooses its own, and the choice fixes both the ceiling and the average. Three assumptions sit on screen. The average window assumes an account becomes wrong at a point in the cycle as likely to be one day as another. The assumption is the reader's own, and not a measurement anybody made at this bank. The review is assumed to find the account whenever it runs. In near miss N5 it did. The cost of a shorter cycle is real. No price for it enters the arithmetic above, so the exchange rate shown is in reviews and days rather than money. Note also that the 46 in the solved points is a review cycle of 46 days, a hypothetical setting of the dial. The 46 days of near miss N5 is a window that opened on the quarterly cycle of 91 days. The two are different objects that share a number, and the chart marks only the second.

Review cycle c, daysWorst case window, daysAverage window, daysReviews a year
7, about weekly73.552
30, about monthly3015.012
46, a dial setting and not a cadence this bank runs4623.08
91, about quarterly, which this bank runs9145.54
182, about half yearly18291.02
365, about yearly365182.51

The observed window in near miss N5 was 46 days, on the quarterly cycle in the shaded row, against that row's average of 45.5 days. The 46 in the first column of the third row is a different object: it is a review cycle of 46 days, a setting of the dial that this bank does not run, and its own average window is 23.0 days. Reviews a year is 365 divided by c rounded to the nearest whole review, so a cycle of 46 days gives 7.9 and prints as 8.

Try it out

The bank moves its access review from quarterly to monthly. What happens to the average window, and what happens to the work?

Debt Capital Markets Bootcamp — Fin Maverick Spotting Quality of Earnings Red Flags — free micro-course from Fin Maverick

What is the difference between a control that prevents and a control that finds?

Back to the shop, where the distinction is easier to see with keys than with accounts. One arrangement is that the manager counts the keys every Saturday evening and gets the missing one back on Monday. Another arrangement is that the door lock is changed at the moment somebody stops working there, so there is no missing key to count. The first arrangement can be run more often. The count can be run every evening. The count cannot, however often it runs, stop the key being outside the shop between the moment the person leaves and the moment somebody counts.

A preventive controlA control that stops the wrong thing happening at all. stops the wrong thing happening at all. A detective control finds it afterwards. Institutions need both, and neither is better than the other. A specific structural difference in what each can achieve is at issue, and the arithmetic makes that difference exact rather than rhetorical. Moving the access review from quarterly to weekly takes the average window from 45.5 days to 3.5, a fall by a factor of thirteen. The number of reviews rises from 4 a year to 52, a rise by the same factor of thirteen. The two factors are the same number and always will be. Both quantities are set by the same single dial and move in exact opposite proportion to each other.

Multiplied together, the point becomes unmissable. The average window is c divided by two and the reviews a year are 365 divided by c, so their product is 365 divided by two, being 182.5, whatever c happens to be. Quarterly: 45.5 times 4.011 is 182.5. Monthly: 15.0 times 12.167 is 182.5. Weekly: 3.5 times 52.143 is 182.5. The product does not move because it cannot move. A reader who redoes it with the rounded review counts given above gets 182, 180 and 182 rather than exactly 182.5, and the gap is the rounding of the count and not a wobble in the relationship.

The fixed product means that a detective control has a floor built into it that no amount of effort reaches. A shorter window can be bought with more work, at a completely predictable exchange rate, and a window of nothing can never be bought at any price. A preventive control does not sit on that curve at all. A feed from the joiner, mover and leaver process that removes the access at the moment somebody leaves does not shorten the window. The feed means there is no window at all: the action happens before the thing a review exists to find. The feed is a different control, not a faster version of the same one, and the difference between preventing and finding is exactly this.

THE TRADE A DETECTIVE CONTROL OFFERS, AND THE FLOOR IT CANNOT CROSS Average window times reviews a year is 182.5 at every point on this curve, so neither can reach nil. 1 2 3 4 5 # CYCLE c REVIEWS A YEAR AVG WINDOW 1 365 days 1 182.5 2 182 days 2 91.0 3 91 days, quarterly 4 45.5 4 30 days 12 15.0 5 7 days 52 3.5 Average window times reviews a year is 182.5 in every row. It never changes, so the curve never touches an axis. 0 50 100 150 0 10 20 30 40 50 REVIEWS A YEAR, being 365 divided by c AVERAGE WINDOW, IN DAYS The two costs trade against each other on a fixed product, so no cadence gives a short window and few reviews at once. Every cadence is this invented bank's own choice. Ring 3 is the quarterly cycle it actually runs.
The curve leans towards both axes and reaches neither, which is the exact arithmetic reason a control that only finds things has a floor under it.
Spotting Quality of Earnings Red Flags teaches you to test whether a reported profit is a sound base to forecast from.

Why does no review cadence ever close the window?

The answer is in one sentence and it is worth reading twice: a detective control cannot act before the thing it detects. Everything else follows. However short the cycle, something has to go wrong first and then be found, and the interval between those two events is the window. Set the cycle to a single day and the window is up to a day and averages half of one. Set it to an hour and the same structure holds at a smaller scale. The only way to reach nothing at all is to stop asking the question periodically and to attach the action to the event instead.

At this invented bank that would mean a feed from the joiner, mover and leaver process. The moment somebody's departure is recorded in the record that already exists, the access ends. Notice that this is a process design question and not a technology question. Somebody has to decide that the departure record is the trigger, somebody has to own the completeness of that record, and somebody has to decide what happens when the record is late. The control that would close the window is built out of the same material as the control that leaves it open: decisions about who does what and when.

There is one more thing this bank already has, and it is the measure that would show the trigger working. Its risk dashboard carries sixteen indicators. Eleven of them are lagging counts: losses booked, breaches recorded, issues overdue, complaints received, all of which describe a quarter that has already happened. Five are genuinely leading, meaning they move before the loss, and one of the five is the age profile of open access rights. An age profile is exactly the right shape of measure for this subject: the profile moves the day an access right starts getting old and does not wait for anybody to lose anything. A count of access incidents describes last quarter. An age profile shows what is building now.

SIXTEEN KEY RISK INDICATORS, AND THE ONE THAT BELONGS TO THIS SUBJECT Vindhya Commercial Bank Limited, invented. Five move before the loss and eleven count it afterwards. FIVE LEADING, SHADED LIME ELEVEN LAGGING, SHADED DARK 1 2 3 4 5 6 7 8 AGE PROFILE OF OPEN ACCESS RIGHTS 9 10 11 12 13 14 15 16 THE FIVE THAT MOVE BEFORE THE LOSS 1 staff attrition in the dealing room 2 the age profile of open access rights 3 the share of manual journal entries at close 4 exceptions approved by the person who raised them 5 the certificate of deposit roll rate THE ELEVEN THAT COUNT losses booked breaches recorded issues overdue complaints received Eleven of the sixteen count something that has already happened, which describes a quarter rather than warning about the next one. The dashboard, its sixteen indicators and the split into five leading and eleven lagging are this invented bank's own.
Only five of the sixteen indicators move before a loss, and the one that belongs to this subject measures age rather than counting events.
Try it out

What actually closes the window rather than shortening it?

Who governs this at the bank, and where does that committee report?

Because the shape of the arrangement is the finding, the governance of information security at Vindhya Commercial Bank Limited is worth listing plainly, part by part. Policy PL7 is the information security policy. Process PR9, access management and information security, is where the controls sit and get counted. Committee G8, the information security committee, has six members and meets quarterly. G8 reports into committee G6, the operational risk management committee, rather than into the board. G6 has eight members and meets monthly.

Neither of the next two facts is remarkable alone, so they are worth putting side by side. First, G8 meets four times a year, the fewest meetings of any of this bank's eight committees: the board itself and the two board committees each meet six times a year, three management committees meet monthly and one meets fortnightly. Second, the access review that decides the length of every access window also runs four times a year. The table that could change the cadence sits on the same cadence as the control it would be changing, and nobody chose that: it is what two independent decisions about meeting frequency happened to produce.

The reporting line matters for a different reason and it is not a criticism. Reporting into G6 is defensible and common. Information security is an operational risk and G6 is the operational risk committee, so the subject reaches a table that also sees the loss record, the near misses and the self assessment. The arrangement also means that information security reaches the highest table in the institution at second hand, through another committee, and only when that committee decides to carry it. Naming where a committee reports is part of describing a risk, not an aside. The reporting line decides who ever hears about the risk.

THE SUBJECT WITH THE FASTEST EXPOSURE SITS ON THE SLOWEST MEETING CYCLE Eight committees at Vindhya Commercial Bank Limited, invented, and how often each of them meets. MEETINGS A YEAR AT THIS INVENTED BANK G1 the board 6 meetings a year G2 board risk management committee 6 meetings a year G3 audit committee 6 meetings a year G4 asset liability management committee 12 meetings a year G5 credit risk management committee 26 meetings a year G6 operational risk management committee 12 meetings a year G7 market risk committee 12 meetings a year G8 information security committee 4 meetings a year, the fewest of the eight Committee G8 meets 4 times a year, and the access review it would change also runs 4 times a year. reports into only if G6 carries it G8 information security committee G6 operational risk management G1 the board Information security reaches the highest table in the institution at second hand, through G6, and only if G6 carries it. Neither G6 nor G8 carries an independent director. Only two of the seven bodies below the board do, and they are G2 and G3. Every committee, its size and its meeting frequency is this invented bank's own arrangement.
Eight committees and one of them meets least often, and it happens to be the one holding the subject whose exposure moves fastest.
Try it out

Where does committee G8 report, and what follows from it?

The failure: a subject governed on its own cadence, and losses that hide in somebody else's column

The first failure is structural and it is nobody's fault, and being nobody's fault is exactly what makes it worth naming. Committee G8 meets four times a year. The access review runs four times a year. On an average window of about 45.5 days, the earliest a newly opened window can be discussed at that table is roughly forty five days after it opened. Nothing can be discussed before it is found. And once that meeting has passed, the table will not sit again for about another ninety days. A subject whose exposure can change in an afternoon is governed by a body that convenes once a quarter, and then reaches the board only through another committee. Nobody decided that and nobody was careless. The arrangement is the consequence of two independent choices about meeting frequency, and that is what a structural finding looks like.

The second failure is where the losses hide, and it has already been seen. There is no information security category among the seven event categories, so every information security loss at this bank is filed as something else. Incident I7, the phishing campaign that reached 312 customers, sits in category 2, external fraud, at Rs 1.8 crore gross, Rs 0.3 crore recovered and Rs 1.5 crore net. Read the category column and this bank recorded no information security losses at all. Read the incidents and it recorded at least one, plus a near miss that cost nothing and said more than the loss did. A risk category that cannot be totalled from the loss record has to be totalled by reading it, and that reading is work somebody has to be told to do, by name, with a date.

Both failures point the same way. The subject exists in the taxonomy, in a policy and in a process, and it is absent from the two places an institution actually looks: the category column of the loss report and the agenda of the board. Neither absence is a mistake anybody made. Both are what happens when a subject is added to a structure that was designed without it.

Try it out

Committee G8 meets quarterly and the access review runs quarterly. Why is that a problem, and whose fault is it?

How somebody actually uses this, at a desk and at a kitchen table

An operational risk analyst reading a bank's own loss record has a search instruction rather than a category to look up. The category column will never say information security, so the first job is to read the thirteen incident descriptions rather than the seven totals, and to write down which of them turned on somebody being able to see, change or reach information they should not have. At this invented bank that reading finds incident I7 at Rs 1.5 crore net, and it also finds near miss N5. The near miss cost nothing at all and is the single most informative thing in the file. The second job is to ask one question of the access review: how often does it run. One answer gives both the worst case window and the average, and the answer is usually easier to obtain than any control document.

An analyst looking at a bank from outside cannot see any of this directly and is not helpless. Two things are usually visible or askable. Where does the information security committee report, and how often does it meet. A committee reporting into another committee is a different arrangement from one reporting to the board, and a body meeting four times a year is a different arrangement from one meeting monthly. Neither is wrong, and both are facts about how quickly a decision on this subject can be taken.

A household runs the same arithmetic without any of the vocabulary. The person who checks once a year which old accounts are still live has chosen an average window of about 182.5 days, whether or not they would put it that way. The person who checks every month has chosen about 15. And the household that removes a departing tenant's key on the day they leave has not shortened a window at all: it has stopped the window opening. The cadence chosen for a check is the length of exposure that has been accepted, and declining to think about the cadence still chooses one.

Risk Management Program Bootcamp — Fin Maverick

Where do an Indian bank's obligations on information security come from?

Everything above holds without reference to a jurisdiction. Three properties, a set of decisions about who may do what, a control that prevents and a control that finds, and an arithmetic relation about cadence: none of that changes with the country. The country decides what an institution is actually obliged to do. The obligation is a different question with a different answer, settled at the sources named below.

Jurisdiction, and confirm every requirement at source

Named here, stated nowhere

The operational risk framework that this subject sits inside, and the seven event categories used above, come from the Basel Committee on Banking Supervision, published by the Bank for International Settlements at bis.org. The Basel material is the origin of the framing, and of itself it obliges an Indian bank to do nothing at all.

The obligations an Indian bank must actually meet on information security, cyber security and technology risk come from the Reserve Bank of India at rbi.org.in. The requirement lives there, and its current wording is found there. Where the institution is a market intermediary rather than a bank, the equivalent source is the Securities and Exchange Board of India at sebi.gov.in.

The quarterly review cycle above is this invented bank's own choice. No authority prescribes it, so any institution that runs one has chosen the cadence and owns the window the choice leaves open. Anything that binds an institution must be confirmed at the issuing body's own site, on the day it is needed.

Try it out

Where do an Indian bank's actual obligations on information security come from?

The exposure, its owner, its controls, its measurement and its governance are on this side of the line. Cyber risk as a category, and how it differs from and overlaps with third party risk, is set out under cyber risk. Third party and outsourcing assessment is covered separately as well. How encryption works, what a firewall does and how an attack is carried out belong to the technology itself, a separate subject from the exposure. Availability as a service promise, meaning the impact tolerance, the recovery time objective and the recovery point objective, belongs to the resilience subject area, alongside continuity, crisis management and incident response. Control design, control testing, the audit finding and the deficiency rating belong to the controls and assurance subject area, where the controls named above are tested. The policy set PL1 to PL9, the committee structure G1 to G8, the risk taxonomy and the escalation route are governance objects, set out under risk governance. The near miss register is set out under near miss reporting.

Sources

SourceDocumentSite
Bank for International SettlementsThe Basel Committee on Banking Supervision publications setting out the operational risk framework and the seven event categoriesbis.org
Reserve Bank of IndiaWhat an Indian bank must actually do about information security, cyber security and technology riskrbi.org.in
Securities and Exchange Board of IndiaThe equivalent requirement where the institution is a market intermediary rather than a banksebi.gov.in

Vindhya Commercial Bank Limited is invented.
Educational material. Not advice on any investment, tax, budget or market position.

← PreviousNext →
Fin Maverick Micro CoursesExplore Micro Courses
Fin Maverick BootcampsExplore Bootcamps
Fin Maverick

Finance education that ends in a job, not a certificate that gathers dust. Built for young India.

LEARN
CalculatorsFrameworksComparisonsCareersShowdown
RESOURCES
All CoursesMicro CoursesBootcampsInternships
COMPANY
AboutJob openingPartnership
LEGAL
Privacy PolicyTerms & ConditionsContent LicenseReturn & Refund Policy
© 2026 FIN MAVERICK / BUILT FOR INDIA.DO FINANCE, DO NOT JUST READ ABOUT IT.