John J. O’Connor

Name: John J. O’Connor
Position: Senior manager, dispute consulting group – forensic accounting practice, Deloitte & Touche in Boston.
Background: U.S. Attorney’s office, leading investigations for Justice Enforcement Team, a multi-agency task force focusing on the enforcement of criminal restitution, basically hidden asset cases, convicted felons.
Education: Undergraduate, University of Massachusetts, Certified Public Accountant, Certified Fraud Examiner
Age: 37
Family: Married, two children
Residence: Reading, Mass.

JOHN J. O’CONNOR: “More often than not (our investigations show) a breakdown of control.”

Seifert Systems Invests in Energy Efficiency to Strengthen Operations

For manufacturers, energy is more than just another operating expense. It plays a critical role…

Learn More

PBN: What is forensic accounting?
O’CONNOR: The combination of a lot of the skills and investigative skills, applied more and more frequently now in complex business cases.

Give me an example.
Significant employee takes six or seven figures from his employer, oftentimes the auditors that are in there doing a financial statement audit are never going to find it. It’s not material to the management statement as a whole. Is it important to the organization? Absolutely, but it typically takes a combination of skills, both audit and investigative, to go in and understand the detail within the records and be able to interview people with investigative experience to elicit the information you need.

- Advertisement -

Basically we’re talking embezzlement?
Embezzlement at an individual level, but there are a number of other issues in terms of corporate manipulations, where companies can actually be manipulating their earnings in particular periods to look better for stock purposes or Wall Street purposes. There are all different types of manipulations. It could be done on an individual level or on a corporate level.

When are you usually brought into the situation, or is it that Deloitte & Touche is the accountant and uncovers the problem?
We’re brought in specifically, and typically it is after the fact, but it can work both ways. Normally we’re called specifically with the parameters being the following: We know we have a problem; we don’t know how big it is. Quantify how big it is, tell us how it happened, who did it and how we could make it never happen again. And finally, and intuitively, we don’t ever want to see this in the paper, so we’re trusting your integrity with our dirty laundry.

Do these things usually go to criminal prosecution, or are these things dealt with in making the whole?
A very sensitive issue now. There’s a fine balance between a company not wanting to go public with their information, at the same time making sure the person that took from them, if it is an individual, is punished. I would say the bulk of our cases never make the press. There are cases where we’re brought in, the company is far more concerned with the loss, from lost profits from a perception standpoint than money taken, although it does go both ways.

Are most of the cases you deal with individuals, or are they more corporate wide?
It’s a mixed bag. Three areas where we’re seeing a real rise in terms of demand involve both individuals and corporate players. We’re seeing a large rise in embezzlement, a large rise in stock manipulation, revenue recognition cases, and third we’re seeing an awful lot of computer intrusion cases, which we also provide expertise in that as well.

Who brings you in on the revenue manipulation cases?
They can come from both law enforcement and from the company themselves. Oftentimes the company themselves have had an inquiry by a regulatory agency, the SEC. It’s not a full blown investigation, but it’s an inventory. The company will bring us in to help them ensure that they have not done anything wrong again to quantify it, so they can go to the SEC proactively at that point with the facts in front of them.

How often when you are brought in to show no wrongdoing, do you actually find manipulation?
I think the majority of the cases you don’t see actual manipulation. You may see errors. You may see a bad apple trying to do something to individually benefit. More often than not you see a breakdown of controls with errors as opposed to manipulation.

Explain what you mean by computer intrusion.
We have expertise within the group to both help our clients examine situations where they have been intruded upon and also help them build the firewalls that protect themselves going forward.

What would be a typical situation?
What we’re hearing a lot of lately are denials of service. Those really aren’t intrusions. The typical case that we’re brought in on – although we help in the denials of service as well – are the situations where someone actually penetrates a computer system and accesses data they are unauthorized to access.

From the outside or from the inside?
Both. It can happen from within with employees accessing information beyond what they should be accessing and just as easy as it can happen from somebody in the next town, next state, even from the next country, accessing even as if they were sitting in the building.

What are people trying to do with this information?
Some of the people are coming in and actually looking at it, not necessarily disturbing anything. The FBI, with whom we’ve been working lately, in some of these matters, and have spoken with publicly, are seeing a large volume of hackers coming in and looking, but not necessarily tinkering with. We’re also seeing others, like the CD Universe case, where they’re actually taking financial information out and in that case holding the company hostage.

They’re not removing the information?
In that case they accessed a large number – several hundred thousand credit card files and effectively, tried to extort a hundred thousand dollars from the country.

Is this a growing problem?
Absolutely.

How big a problem is it?
It’s an enormous problem, with probably the biggest risk; the majority of companies out there don’t have the proper defense network set up to combat it. You have a lot of people with free time that are very intrigued just how vulnerable different companies are.

We all did the Y2K thing, which turned out to be a little bit of a bust, but a lot of concentration in that area, and not much in terms of protecting a company from hackers?
Nothing to the same scale. I think we’re going to see that ramping up. This rage of denial of service, really puts a spotlight on it. The denial is the ability to throw so much information at a particular company’s Web site that you effectively render it out of service.

Is this being done for fun or by people who are doing this for nefarious reasons?
In the cases we’ve done we’ve seen it both ways. In many cases it’s just a matter of fun or challenge, and in other cases we’ve some references where customers are being referred to other Web sites, presumably with the profit motive for the people they are being referred to.

In terms of computer intrusion, in terms of vulnerability, does it go by size or is it anybody?
Firms across the board are vulnerable, because everybody has a different type of information and information is always valuable to the organization, so whether it is intellectual property information you value– formulas if you’re a chemical company. If you’re in the financial services industry it is obviously account information or financial assets. If you’re a law firm it’s confidential files. It’s really unlimited. It’s not industry specific.

When we take a look at other types of fraud, again does that cross all lines?
Absolutely. We tend to get involved in the larger cases. We’re doing cases both on behalf of law enforcement and just on behalf of corporate America. We’re seeing it across the board, but clearly in those businesses with assets of substance.

How can a company better protect themselves from fraud from within?
There’s a couple of things that we see as common breakdowns, that when you do a number of these cases. One of them is just a very strong set of internal controls. It’s got to be from the top down. It’s got to be controls that are actually reviewed. It’s easy to say we have an internal audit group and we’ve segregated duties. Is anyone really understanding what’s going in. Do the people in charge of reviewing the information really understand the business environment that the company operates in. While that might sound intuitive to some, it isn’t to many in practice. And the second piece would really be a company vision. Does the company look at itself in a very, very high light or are they willing to accept a satisfactory performance from average players.

What can a company of say 50-employees, with $2 to $3 million in sales, with an owner involved in the day to day operations, do – should they look outside for the review process?
Not necessarily. They would be audited. They should get an external financial audit. The essence of a financial audit is to render an opinion on financial statements, not necessarily to look for fraud. What the company should have in place is a good review mechanism, whether it’s an internal audit group, whether it’s a management review function, that is staffed with people that A) understand the business, that B) are able and willing to look under the sheets if you will of the transactions. Not to micro-manage the transactions, but to have somewhat of an independent arm looking over the business to ensure the transactions are perfect.

What kinds of things can be done to avoid computer intrusion?
That’s a bit more complex. The computer security industry, they look one year as the equivalent of 90, or 90 days as the equivalent of one year, so it’s a very, very dynamic situation. In that case ideally external people coming in and setting up a system and then monitoring it, making sure that it is as up to date They are only going to be as secure as their investment in terms of the computer screening.

What do they do, set up firewalls basically?
They set up firewalls. They’ll try to hack into the system. When we’re brought in one of the first things we’ll do – of course we’ll get the authorization of the company, everyone will know what we’re going to do – and then we will send our experts in to effectively hack into the company. Nine times out of 10 we get in. There’s no better evidence to show someone how vulnerable they than actually getting into their system, having them come into their office in the morning, turn on their computer and seeing a little banner on their screen saying ‘good morning, we were here.’

Do you see it important to businesses of all sizes to bring people in now – as increasing publicity attracts more hackers?
I think it makes a lot of sense to get someone to come in do an assessment, someone to actually see whether – someone independent of the organization – to assess the vulnerability of your system. You may or may not have a problem. At least to the extent you do, or they show you where you’re vulnerable at least you can make a business judgment whether it’s worth your while, worth your investment to fix it or not.

How big an investment is it for a small to medium sized company?
I’d say it’s a relatively small investment for a firm that size. Obviously it’s a bigger investment for a large organization.

Once something is detected, is it a major undertaking to put up the firewalls?Typically it’s a combination of manual and automated controls. No, it’s not necessarily an enormous project, then again it’s something that in the environment that we’re in is quite dynamic. Unfortunately for the businesses and maybe fortunately for some of the companies that are out there providing the expertise, it’s a continuing process.

I understand that once we get into the investigative work, charges can get up to $300 an hour. Is that a realistic number?
Sure, and can be. That’s typically the engagements have various levels of expertise on them. The average rate tends to be far less than that. If you’re just bringing in the highest level people, sure the rates could be that.

I also understand that fraud is costing U.S. companies in excess of $400 billion a year?
That statistic might actually be on the low end.

What kind of people do you look for to work in your area?
That’s a good question. It’s a combination of audit and investigative people. We tend to look for people with analytical backgrounds, but we have a handful of very, very senior law enforcement, including, a colleague of mine, Bill McDermott. He’s the former deputy assistant director of the FBI.

In most cases do the people who are caught face jail time?
I’d like to say yes, but I think the answer to that is no. That’s largely due, as I said earlier, many of the cases we get involved in the companies don’t want the press, they don’t want their laundry aired. We respect that. If they do we can certainly help facilitate that with a number of former law enforcement people in our ranks.

So what typically happens to the perpetrator? They obviously will lose their job.
They lose their job. They could face civil action, although in many cases they don’t. They tend to pay back some of the money. But the companies again are faced with the business risk of do ‘we air this and hurt public confidence in our company. Or do we not and swallow the loss that we got and make sure that our controls are such that this will never happen to us again.’

How then is there a deterrent. Punishment is persuasive.
That’s right. It’s a very tough call. I found, and I’ve spent a lot of time working with people who have been in prison or facing prison time, typically the financial penalties are far more of a detriment than prison time, at least with the white-collar criminal. The real deterrent is going after the money, getting the money back and maybe getting a little more in terms of penalties. But you are forced into the public arena to do that oftentimes. The fact of the matter is it’s the company’s choice whether they do that or not.

With the advent of computers, the Internet, we’re seeing a growth in the number of people committing this type of crime. Are we finding a different kind of person getting involved in white-collar crime?
Certainly seeing younger people having access to a magnitude of assets they wouldn’t have had before.

Do you think these are people who would have found their way into other white- collar crime, even without the computer, or people who have been lulled in by the ease of the computer and wouldn’t otherwise have gotten involved?
I think the latter. In many cases it’s going to be people very intrigued by the computer, find themselves to be very skilled. They are willing to experiment and get into areas they probably wouldn’t have gotten into before. That’s not to say that they’re going to go and steal anything, but they may actually wreak havoc, whether they mean to or not, just by experimenting.

No posts to display