Categories
Compliance in current and historical events

Compliance lessons to learn from the 2017 Equifax cybersecurity breach

Equifax is one of the major US-based consumer credit reporting agencies. It operates globally and due to their nature of its business, maintains sensitive and personal information on more than 800 million individuals and more than 80 million organizations.

In September 2017, Equifax announced that it had experienced a cybersecurity intrusion in July 2017 which impacted the data of up to 200 million consumers from the US, Canada, and the UK. The handling of this breach by Equifax was widely criticized and questioned. Among the controversial aspects of it were the two month delay in publicizing it, the lack of specific information about the data compromised, the inadequate and possibly even unsafe system and support provided for impacted consumers, and the perception of possible insider trading by company executives in the days after the breach took place but before it was public.

As the problematic response to this cybersecurity incident unfolded, Equifax’s various blunders and missteps in the public handling of the situation formed a guide for worst practices in such a scenario. As the dialog around Equifax’s response has shown, poor crisis management in the public eye only compounds the consumer protection problems.

  • Companies do often have legitimate reasons for delaying notifying consumers, regulators, and the public at large about data breaches. Sometimes companies do not even know they have been breached right away. Even once they are aware, sometimes law enforcement will request that they do not disclose the breach. Different types of data may be subject to different disclosure requirements, so companies also sometimes have to take time to determine what data was involved. However, these delays still can be very problematic for consumers, who can be unknowingly at risk and make assumptions about the seriousness with which their data is stored and maintained which might be very far from reality.  Why it can take so long for companies to reveal their data breaches 
  • While Equifax was taking its time notifying consumers and regulators of the data breach, questions abound about when – and what – people on the inside knew about it. This is because only a few days after the July 29 cybersecurity intrusion, on August 1 and August 2, several executives at Equifax sold shares. These transactions were not part of scheduled trading plans, but they were not total liquidations of their positions, and the company says that the executives were unaware of the breach at the time of the trades. However, the perception of possible insider trading is hard to avoid once the timing of this activity is revealed. If they truly did not know about the cybersecurity problem, it would have been wise at least to inform key senior management of the breach and advise them to avoid trading in the stock while in possession of inside information.  Three Equifax Managers Sold Stock Before Cyber Hack Revealed
  • Despite how secret most people in the US see their financial data as being – especially social security numbers and bank account or credit card information – current privacy laws are lacking in many key areas when compared to those in other parts of the world such as the EU. Top of mind among privacy concerns, including the need for consumers to input personal data to check whether their other personal data has been compromised, is that over a month went by before Equifax notified the public of the cybersecurity incident at all. In the 40 days that went past, the data could have been used for many illicit purposes without consumers even being aware they were at risk. Laws in the US currently differ between states with regards to breach notification requirements. There is no unifying directive in the US for the standard where personal data is concerned, such as there will be next year in the US under the General Data Protection Regulation, which requires notification within a maximum of 72 hours. Perhaps a higher standard in the US such as this one would reinforce seriousness of these events to organizations and improve consumer protection and communication processes when they occur.  Equifax breach disclosure would have failed Europe’s tough new rules
  • While these data breaches are unfortunately becoming so common that the public is often less alarmed by them now than in the past, irresponsible or insufficient responses by organizations to these breach still provoke justifiable outrage and calls for change. Consumers being desensitized to the exposure of their personal data just shows how widespread the problem is and how insufficiently the interests of the consumers are guarded. However exhausted the public may seem to be with the ongoing leaks and hacks of their private data, this is no excuse for organizations affected by them to respond with the same passive, indifferent attitude. Equifax’s lack of detail and inadequate communication displayed to the public that they did not care about the invasion consumers were suffering, which is quite a different message than one of fatigue by victims who have had this experience too many times to excuse. The reputational risk suffered by such corporate carelessness is extreme, and hopefully will drive consumers to advocate for a higher standard of responsibility and responsiveness from keepers of consumer data.  The Banality of the Equifax Breach
  • As the public contends with the reality of the Equifax data breach – that subsequent hacking attempts stemming from this breach are inevitable and that companies like Equifax do not meet the standard of care for protecting this private information in their possession – what can anyone do in the future? Holding companies accountable for their poor service by taking their business elsewhere is often the only choice consumers have to voice their displeasure. In the current system individuals aren’t really able to avoid the consumer credit reporting agencies, but organizations could opt to create and use independent systems with more secure infrastructures. These corporate users could drive a technological shift that would also benefit individual consumers. Blockchain and related technologies could provide the solutions to these vexing and chronic security concerns that the existing system seems unable to address.  It’s time to build our own Equifax with blackjack and crypto

Given the ever-increasing risks surrounding cybersecurity, compliance professionals and individuals interested in cybersecurity risk management can take many cues from the above on what not to do in such a situation from Equifax. Hopefully as organizations continue to live with the risk of such intrusions, and improve their control frameworks to prevent and mitigate them, they also pay attention to the public responses in such situation, to make sure that the statements made and guidance provided are adequate and accurate.

Categories
Best Practices

Communication strategies for increasing employee engagement in compliance programs

Every compliance professional’s strategic annual plan will include seeking increased employee engagement in and attention to the organization’s compliance program. Communication strategies must be carefully devised with the goal in mind of making compliance vivid and interesting to employees. The compliance message can quickly become routine and dry: sign an attestation, request pre-approval, complete a checklist. This sort of messaging alienates employees rather than engaging them. They have only a small function in the compliance operations this way. Nothing is learned or shared, they are just doing a “tick the box” type exercise.

Instead, the true aspiration of the compliance messaging is that employees take interest, learn something new, ask questions, and feel connected to the story of the organization’s compliance program. This is accomplished via effective and appealing communication that speaks to all audiences and sets a new, compelling tone.

  • Key moment messaging: Compliance is highly relatable to current events and new stories. Therefore compliance communications should take full advantage of key moment messaging opportunities. Relate communication topics to outside events to make the objectives of the compliance program even more concrete. For example, if there is a major earthquake somewhere in the world and your office is located in Southern California, take that opportunity to engage with employees about disaster recovery and business continuity policies and procedures. Their interest will already be heightened and the necessity of the information will be at its most tangible.
  • Positive reinforcement: Start with a kudos, congratulations, or positive sentiment. Any action that needs to be taken or improvement that needs to be made based upon the communication will be much better received if the message gets off to a welcoming start. Set a productive tone by thanking employees for their participation in the last request or calling out good insights or high engagement. Then build off that encouragement to bring in the next steps needed and issue the call to action.
  • Branding: Branding and marketing are now important considerations across all business lines and functions. Compliance is not immune to this, as messages from so many sources fight among themselves for precious attention and airtime from employees. Therefore compliance professionals must carefully consider branding options that will maintain the substantive content of their communications yet be adequately branded to be appealing. Using humor or a catchy, fun theme to introduce the communication, before getting to the meat of the message, can provoke curiosity and prompt engagement. Don’t take it too far and make it a joke – but a little bit of amusement can go a long way.
  • Give visuals/shortcuts: On a similar note, think about making simple takeaways from the communication, however complex its overall message. One way to do this is to provide a visual, like an example of a new form that has to be filled as standard procedure, or a chart showing results on an initiative over previous periods and projected future results. If a visual is not applicable, try using acronyms or slogans that will work as mnemonics to help people remember your message and keep the meaning in mind.
  • Make it interactive: The best way to engage employees in compliance communications is to concretely incorporate them in it. Make the messages interactive for them. Ask an open-ended question and promote any responses received so that employees know the request for input is credible. Take a poll or offer a quiz. This way, employees can share in the mission and the effort by weighing in themselves, which allows them to personalize the message and be more likely to remember it.

To interest and appeal to all employees, compliance communications should not be generic or routine. Taking advantage of opportunities to make compliance relatable, and capitalizing on human interest or emotional connections that can be made, will help to make the mission of the compliance program much more interesting and effective.

Categories
This week preview

This week on Compliance Culture

Be sure to visit Compliance Culture this week for posts on these topics.

  • Monday: Compliance communication to encourage employee engagement
  • Tuesday: The Equifax cybersecurity breach: What not to do
  • Wednesday: Instagram and ethics
  • Thursday: Compliance culture in higher education
  • Friday: Corporate compliance and the morality of justice

Don’t miss it!

Categories
Last week round-up

Last week on Compliance Culture

Check out last week’s posts on Compliance Culture, in case you missed or want to revisit them.

Many thanks for reading!

Categories
Compliance in popular culture

The Office and culture of non-compliance

The Office is a very popular US television comedy series, based on a UK series of the same name. It follows the daily lives of the employees working in the Scranton branch office of a paper company. Filmed as a “mockumentary,” to imitate the style of a documentary, the show features many “interviews” with the employees and management. While it does address things in their private lives and personal relationships between the characters, most of the action of the show occurs in the workplace and is based around the dynamic of the characters as colleagues and employees.

In this light, the show offers many interesting insights and tropes about the experiences of working in a small or branch office, with an eccentric boss and idiosyncratic colleagues, dealing with policies from head office and the challenges of working together effectively. Scenarios relevant to compliance are touched upon often in the series, frequently showing examples of very poor management practices or problematic cultural values.

  • “Sexual Harassment” (Season 2, Episode 2): In this episode, the office’s HR personnel are providing sexual harassment refresher training and reviewing policies after an incident at corporate headquarters. Instead of setting a tone at the top to reinforce how important a respectful and safe working environment should be, and how inappropriate harassing behavior of any kind is, the manager Michael Scott has a tantrum and makes light of the importance of the policies. He never embraces his duty as a leader to model positive behavior; even when he defends one of his staff against the rude joke of another, it is accompanied by an improper comment of his own, as he misses the opportunity to step up and reinforce a culture of compliance.

 

  • “WUPHF.com” (Season 7, Episode 9): In the cold open of this episode, the power goes out in the office and the server goes down. Instead of having reliable disaster recovery procedures on hand or a controls framework that would enable business continuity in this sort of situation, the staff must resort to guessing the password as a group. Obviously this is not advisable in light of critical cybersecurity concerns which face all businesses today, especially small offices such as this one which might be assumed to have weaker controls and be targeted by intruders hoping to gain access to the larger company network.

 

Actually, the “WUPHF.com” episode, in its entirety, is another good example of poor compliance practices. Ryan Howard, with Michael’s encouragement and financial backing, claims that he has devised a web-based messaging system called WUPHF.com. In reality, Ryan is committing a fraud, in that the website does not function (despite his attempts to advertise to the contrary) and the only purpose for it is to try to sell off the domain name. Instead of uncovering and disclosing this fraud, and protecting the other investors, Michael backs Ryan. Though he later withdraws his support for Ryan, the fraud is allowed to continue because Michael does not step up and see beyond the conflict of interest posed by his personal relationship with Ryan in order to act on behalf of the investors as he could do.

 

  • Scott’s Tots (Season 6, Episode 12): In surely one of the more cringe-worthy moments for Michael Scott – that’s saying a lot – he fails to keep the promise he made years before to pay college tuition for a group of lower-income children. Upon their high school graduation, he must confess that he has not upheld the duty to them that he created with his promise. Instead, he apologies and tries to give them batteries as a conciliatory gesture. Apart from the terrible awkwardness of the concept itself (this episode aired in December 2009, deep within the global financial crisis, an uncomfortable time to try to address financial fraud humorously), it’s unfortunate, and a sign of weak leadership, that Michael doesn’t seem to acknowledge at all the reliance upon his integrity he created by making that commitment.

 

  • The Incentive (Season 8, Episode 2): In the absence of Michael Scott, his former employee and now new office branch manager Andy Bernard is proving that the apple doesn’t fall far from the tree when it comes to insufficiently ethical leadership. Andy finds himself at a loss for how to motivate his employees and decides to create a points-based incentive system to encourage their performance. Rather than appealing to their values or accepting lower performance in exchange for more sustainable and strategic efforts, Andy chooses a management method which will yield only short-term, temporary improvement or engagement.

From the above it is abundantly clear that The Office does not depict a corporate culture of compliance or a values-based approach to business strategy. Rather, it shows a company that is run, at least in the Scranton branch, with an ethos of non-compliance in the workplace.

Categories
Trends in business compliance

Round-up on ethics of design in technology

One of the most interesting and challenging inquiries in the evolving ethical code of technology has to do with design choices. Ethical decision-making and process design has direct impact on the fluid, complex process of creating the devices, interfaces, and systems that are brought to market and used by consumers on a constant basis. In such a disruptive and innovative industry, there are moral costs for every design decision: every new creation replaces or changes an existing one, and for everyone who has new access or benefits, others experience the costs of these decisions. Therefore the ethics of design as applied to technology and, of particular interest, social media, have concrete importance for everyone living in a world increasingly dominated by user experiences, communities’ terms of service, and smart devices.

  • Former Google product manager Tristan Harris has gone viral with his commentary on the ethics of design in smart phones and platforms creating apps for them. There is a balance in online design where the internet platforms go from being useful or intuitive to encouraging interruption and even obsession. Many people worry about the effect “screen time” may have on their attention span, quality of sleep, and offline interactions with people. Design techniques may actually keep people attached to their devices in a constant loop of advertisements, notifications, and links, as content providers and platforms compete to grab viewers’ attention. Alerting people to the control their devices have over their attention and time is one step, but urging more ethical choices in the design process is the next frontier for innovation reform:  Our Minds Have Been Hijacked By Our Phones.  Tristan Harris Wants To Rescue Them. 
  • The above phenomenon of addictive design has become so imbedded in the creation of app features that even the most subtle changes can have a huge impact on the consumption practices of users. But when do features go from entertaining and user-friendly to compulsive, even addictive? Refreshing an app can be like pulling the lever on a slot machine, giving the brain rewards in the form of new content to keep the loop going at the expense of other activities and priorities. These design improvements, then, may actually affect users more as manipulations:  Designers are using “dark UX” to turn you into a sleep-deprived internet addict
  • These small, ongoing redesigns are intended to make apps more readable and consumable. These periodic improvements are intended to make content more captivating and enable longer browsing – again prompting the question, what is the ethical code for the control designers wield over users with these choices? From a design ethics perspective, these small changes can be viewed as more alarming than major ones, as they are so incremental that many users do not consciously notice them and therefore “optimization” tips into “over-optimization,” meaningful interaction becoming possibly destructive:  Facebook and Instagram get redesigns for readability
  • Artificial intelligence always captures the public’s imagination – thrills and fears about the possible developing capabilities of robots and predictive algorithms that could direct and define – and perhaps threaten – human existence in the future. AI has been developing in recent years at a breakneck pace, and all indications are that this innovation will continue or multiply in the coming period. The science fiction-esque impact of AI on society will grow and bring with it all kinds of ethical concerns about the abilities of humans to define and control it in a timely and effective way:  Ethics — the next frontier for artificial intelligence
  • Social media platforms have developed into social systems, with all the dilemmas and dynamics that come along with that. These networks may face the choice between engagement and all of the thorny dialogs that come with it, and a simpler, more remote model that can be enjoyable but is less interactive and therefore, perhaps, less provocative:  ‘Link in Bio’ Keeps Instagram Nice

Queries into design ethics and choice theory in technology, especially social media, ask the questions of what human experience will evolve into in a world which is increasingly digitized and networked. The design decisions made in the creation of these devices and systems require an ethical code and a sense of social responsibility in order to define the boundaries of what are the best collective choices.

Categories
Compliance and ethics business case studies

TravelBird and setting the standard for corporate cultural values

One of the undeniable effects of the trends of globalization and increased demand for customization and specialization that have occurred in both the retail and service industries is that competition is keener than ever. In today’s crowded marketplace, organizations must get creative to set themselves apart and appeal to consumers. From a compliance perspective, of course, the most practical and sustainable way for an organization to do this is to be loud and proud about its integrity and values-based approach to business.

TravelBird, an Amsterdam-based travel agency which operates in 11 European markets, has embraced a disruptive business model and is determined about changing the way customers plan and book their vacations into a holistic experience. Founded in 2010, TravelBird refers to itself as a “scale-up,” a start-up with a strategy of cultivated and plotted growth. Its customer service ambitions are matched by its desire to create a vibrant employee experience and to have a corporate profile which is inspiring and consistent with the image it wishes to project publicly.

Towards accomplishing this goal, TravelBird has recently announced its “cultural values,” a novel spin on the corporate mission statement or business principles. These values as stated by the company are strikingly balanced and represent a thoughtful evaluation of the organizational and employee traits which embody the best alignment with a successful, sustainable business philosophy:

  • Adventurous but Responsible – Take measured business risks, even as leaps of faith, and go boldly into new product and service areas as the customer experience may demand the organization to do so. However, do this with respect for foundations such as legal and regulatory frameworks and the ethical and moral considerations that may be implied. This is the ultimate principle of sustainability that emerging enterprises, especially companies with a basis in technology, forget to make room for in their organizations. An organization which approaches its growth with this orientation is culturally better prepared to offensively weather future storms than one that defensively considers problems for the first time as they occurring.
  • Passionate but Practical – Creative and sales may drive the bottom-line survival, but compliance and other control functions inform the staying power. Design strategic choices and decision-making at the company so that it is consistent with an ambitious business profile and speaks to the passions and excitements of the employees and customers, but don’t forget to do things right from the start.
  • Candid but Compassionate – Honesty is the best policy, but it doesn’t have to be brutal or at the expense of a mature relationship-based way of doing business. Commercial relationships can be very remote and it’s easy to forget there are people on both sides of every interaction. It is important to treat each other with integrity but to also have a high standard for performance and behavior.

Customers and employees alike are highly motivated by companies that model admirable cultural conduct. Blending corporate ambition and conscience, strategy and cultural responsibility, is a powerful approach to growing and cultivating a business. Companies looking to develop directed corporate cultures should aspire to lead with this kind of message and engage in these values authentically and continually.

For TravelBird’s announcement on their cultural values: check out their LinkedIn.

Categories
Compliance in current and historical events

Must-read OCCRP investigative project reports

The Organized Crime and Corruption Reporting Project (OCCRP) is an investigative reporting organization which focuses on organized crime and corruption. The consortium operates worldwide to publish the results of cross-border investigations into criminal enterprises that are often very complex. In many cases the OCCRP reporters are “following the money” to uncover and publicize bribery, tax fraud, and other crimes that are intimately connected to banking institutions and powerful politicians or state-sponsored organizations.

  • Game of Control (2008-2009) – This investigation centered on the involvement of organized crime in owning football clubs. A deeper look at the business of football in Eastern Europe and the former Soviet Union showed a network extending all around the world that enabled criminal businesspeople to hide their illicit activities by laundering money through football clubs they own, skimming transfer fees for players, and using shell companies for tax evasion and concealment of funds. The investigation uncovered evidence of game rigging, use of stadium property for organized crime operations, and even murders of club leaders linked to Bulgarian organized crime. 
  • The Big Bet (2009) – In this report, the OCCRP looked at the expansion of the gambling industry in Eastern Europe. Countries in the region were providing incentives for the gambling industry to come to stimulate local economies and increase tax revenues for governments, but along with the casinos come all the problems of organized crime and corruption. This investigation probed into the abusive practices of governments in these countries which fail to regulate the gambling industry sufficiently and do not enforce proper taxation, instead accepting bribes to look the other way, and not ensure that the public in these countries receives their share of the benefit from the huge revenues these companies make. 
  • The Panama Papers (2016) – The Panama Papers project was one of the biggest stories in money laundering investigation of recent years. The OCCRP worked on the project in collaboration with the International Consortium of Investigative Journalists and Suddeutsche Zeitung, the German newspaper which received a cache of documents from Mossack Fonseca, an offshore services provider in Panama. These documents provided the evidence of the illicit activities concealed in offshore companies set up by Mossack Fonseca, including tax evasion, fraud, and money laundering. Many of the world’s wealthiest people – politicians and businesspeople, criminals and not – were named in these documents. These included Russian, Azerbaijanim and Ukrainian politicians and their families.
  • The Russian Laundromat (2014-2017) – The OCCRP exposed a vast financial fraud scheme enabling money laundering out of Russia and into Europe through Moldavia. More than $20.8 billion was funnelled out of Russia via this mechanism. By tracking the money down to the accounts all over the world where it ended up, the project exposed systemic bribery and activities in the gray area of the Moldovan legal and supervisory system. Some of the world’s largest banking institutions – among 732 banks in 96 countries and including Dankse Bank, Bank of China, HSBC, UBS, RBS, Nordea, Credit Suisse, Citibank, and Deustche Bank – had this illicit money in their accounts. 
  • The Azerbaijani Laundromat (2017) – The most recent of the OCCRP’s reports, like the Russian Laundromat, this details a criminal money laundering operation that used UK-registered shell companies to move $2.9 billion from from Azerbaijan into Europe. This money came from a secret slush fund of Azerbaijani elites used to bribe officials, buy luxury items, and enrich themselves while Azerbaijani human rights were under ongoing assault and citizens were deprived of funds used by their government for their own illicit purposes. Danske Bank was again mentioned as a major banking institution which processed these transactions through their accounts without sufficient due diligence controls to expose the source. This investigation is ongoing and the subsequent movement of the funds and their uses will continue to be revealed. 

OCCRP has become one of the most respected and awarded non-profit media organizations in the world in the decade it has been publishing investigative reports. This is for good reason, as its work has led to the freezing or seizure of billions of dollars of assets, arrest warrants and firings, and closures of shell or illicit companies connected to criminal enterprises. The insights of these investigations cast a powerful light on the mechanisms of corruption which still have a strong hold on business and political organizations all over the world.

Categories
Best Practices

Key compliance culture values for promoting employee integrity

Employee integrity is the cornerstone value for establishing organizational integrity, and therefore for the success of any compliance program. As fundamental as employee integrity is, it is also complex, elusive, and affected by a huge array of factors and influences. Perceptions and biases can defeat individual intentions for ethical behavior. External forces on the decision-making process and the impact of management in a complicated organizational structure and business world can defeat incentives for integrity and honesty.

What can a compliance program do to address the need for employee integrity in a world which presents so many obstacles and hindrances to developing and maintaining this trait? Compliance professionals should be the organizational standard bearers for encouraging good people to do good things and limiting access of the occasional bad people to do bad things. This message can be very simple and should focus on reinforcing positive perceptions of corporate values and leadership expectations so that employees aspire to model their own character within this.

  • Openness: Transparency and honest, active communication are crucial to the success of a compliance program. Employees must see that openness of communication and transparent reporting and sharing are highly valued. Open communication is directly linked to reduction of reputational risk and perceptions of greater honesty. Establishing a culture where employees feel it is encouraged or expected to speak up and speak out requires management to be meaningfully open, accessible, and relatable. In an environment where employees feel that all behavior and performance can be discussed openly, they will also be aware that it will all be noticed, and therefore will feel positive pressure to meet best expectations for integrity.
  • Clarity: Clarity of expectations and perceptions is essential for a culture of integrity. As with all objectives for compliance culture at an organization, norms and values must be clear and consistent across all employee populations. Communicating different or confusing messages, or giving information that impacts everyone to only some and leaving others out to hear it indirectly, is disastrous for imbedding ethical traits in an organization. Clarity promotes understanding and discussion, both of which are necessary for employees to take up the cultural objectives of the organization as their own.
  • Leadership: Tone at the top is just the first step. Leadership should be encouraged as a professional competency at all levels in the organizations, so that advocacy for the compliance culture can take root everywhere. Employees need to see leaders speaking up about the importance of integrity, but they individually also need to feel they are in the position to speak up themselves, and will be looked upon as vested with responsibility for their own integrity and choices in everyday ethical dilemmas.
  • Trust: Trust is the most simple factor for encouraging integrity in organizations, and indeed in all interactions and relationships, and it is also one of the most difficult and fraught qualities to meaningfully establish and maintain. Trust is constantly threatened and questioned. It cannot be given automatically and still have meaning, but it must be given confidently and with expectation that it will be received in return. Investments in mutual trust cannot be forced or demanded. The pain of having colleagues or managers who are not trustworthy can cause deep damage in teams and organizations and impede individual development. The only solution to this is to see trust as a reward and an ongoing evaluation, and to embrace frank and open dialogs which can help to resolve prior mistrust and discourage future violations.
  • Engagement: Engagement discussions usually focus on employees, but the quest for achieving it starts with management. Employees should see that management follows up, takes integrity seriously by individually espousing all the values, responds visibly to problems and complaints, and confronts issues boldly and confidently. Management engagement in the compliance culture should embrace professional skepticism and pursue public accountability. When employees see this, then they are empowered in turn to engage with their direct managers, peers, and direct reports to have discussions about integrity matters and to demonstrate all the traits that support ethical decision-making.

Modelling the key values of a compliance culture to create strong organizational drivers for integrity should be the focus of the conduct objectives of every compliance program. The fundamental message should be that performance and behavior linked to demonstrating integrity will be encouraged and appreciated.

Categories
This week preview

This week on Compliance Culture

Be sure to visit Compliance Culture this week for posts on these topics.

  • Monday: Promoting employee integrity
  • Tuesday: OCCRP investigative reporting highlights
  • Wednesday: TravelBird’s corporate cultural values
  • Thursday: Design ethics in technology
  • Friday: The Office and non-compliance

Don’t miss it!