Friday, May 30, 2008

The Societe Generale report

Societe Generale (and their auditing partner PricewaterhouseCoopers) has announced the results of their investigation into how Jerome Kerviel managed to lose US$7B. Conveniently, their release came out at the same time as my article about security lessons learned appeared in IEEE Security and Privacy.

Dark Reading has a good summary of the Societe Generale report. It's nice to know that my article (which I wasn't paid for) comes to largely the same conclusions as PWC, which probably got paid US$1M or so. Of course, any competent security specialist could have figured out most of the probable causes - the only thing that I didn't know is how many of them were the actual causes, and for that the PWC report is worth reading.


