|
National accounting firm RSM Bird Cameron has recruited information
security veteran Jo Stewart-Rattray to head up its new Risk Management
Services team in Adelaide.
Jo has 20 years experience in the IT field, including as a Chief
Information Officer for a major utility. She has worked in the
information security arena for 12 years. In her most recent role, at
Vectra Corporation, Jo provided strategic advice to organisations
across industry sectors including banking and finance, utilities,
automotive manufacturing, tertiary education, retail and government.
Jo specialises in consulting in information security issues with a
particular emphasis on governance in both the commercial and
operational areas of businesses.
As RSM Bird Cameron’s Director for Information Security, Jo said her
focus was on the business side of risk management rather than the
technical element. “Information security is all about risk management,
so my role is to identify where the risk lies and to reduce it,” she
said.
“People at the coalface are doing a good job of managing risk, but
that has the effect of quarantining risk management rather than
inculcating it through the organisation. Executive management and
senior management must become more aware of the issue of risk. We need
more executive focus.”
Jo said the greatest problem with risk was its invisibility. “During the past two decades, risk has crept up on the enterprise in the stalking horse of major business trends,” she said.
“Specialisation is a disaster from the security point of view because it tends to balkanise the analysis of risk within departments rather than perceiving it as a whole-of-enterprise issue.
“We also have the risk that arises from the ‘ripple effect’ of business initiatives such as Just in Time inventory management and Supply Chain Automation. There is risk all through it. One business I worked with recognised that not ‘realising its risk’ could cost it millions of dollars within two hours. Workflows mean materials will continue arriving, irrespective of what is happening.
“Also outsourcing is sometimes justified as a way to defray risk. However one company outsourced its servers to India, then when the auditors went to inspect them, they discovered the servers had been ‘onsourced’ to Mexico and from there to Costa Rica. All these business megatrends impact on risk.”
Jo said RSM Bird Cameron was the ideal organisation to advise businesses on risk management. “An accounting firm talks to the people who pay the bills, so they understand risk,” she said.
“Unfortunately, it is often only a cataclysmic event that brings the need for risk management into sharp focus. There are many types of business risk: To people; to productivity; to reputation; to security of information; to technology and to the business itself.
“Traditionally IT helped to improve and speed up business processes: However, over the past 10 years, business processes have become embedded within IT itself. To mitigate this risk, you need the right controls in place around the right tools.
“Security is not an end in itself: It’s a balance between productivity and security. We are looking at the issue of where risk and security marry together. Senior executives need to see security as a business benefit, as an enabler rather than a constrainer.
“I have a fair bit of experience across this area, so we can help our clients to see the whole picture.”
Jo’s expertise was recently recognised with the CGEIT credential – Certified in the Governance of Enterprise Information Technology – becoming the first South Australian woman to hold the qualification. CGEIT recognises the increasing importance of IT governance, the way in which enterprises put all the pieces together to minimise risk and maximise value for the business.
Jo has a swag of other qualifications in information security: These include Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM) and she is the President of the Information Systems Audit and Control Association (ISACA) Adelaide Chapter. Jo is also the Chair of ISACA’s international Security Management Committee.
As well as underpinning her information technology and security background with her qualifications, Jo is also a highly-sought after international speaker and virtual educator.
RSM Bird Cameron offers a full range of services that go beyond their core strengths of taxation and business services to extend to a range of specialist corporate advisory services including: Assurance and advisory, taxation consulting, corporate consulting and business investigation and recovery.
Over the past 80 years, the firm has grown to cover strategic regional centres as well as major cities across Australia with 28 offices nationwide. Based on a culture of teamwork they serve a client base comprising large corporations, SMEs and government agencies across a diverse range of industry groups. RSM Bird Cameron is a core member firm of RSM International, the sixth largest accounting and consulting organisation in the world.
For more information
Jo Stewart-Rattray
Director, Information Security
RSM Bird Cameron
Tel: +61 8 8232 3000
For media assistance:
Call John Harris at Impress Media Australia on 08 8431 4000 or email
This e-mail address is being protected from spam bots, you need JavaScript enabled to view it
.
|