1) Risk & Security
    End user computing risks
    Hacking into online photocopiers
    CyberSecurity Awareness Month
    Culling unpopular colleagues?
2) Quantitative methods
    My recommended course book
3) Euro
    Faint stirrings of interest
4) Spreadsheets
    New Statistics on Model Error Rates
5) Off Topic
    Ig Nobel prizes 2004
    Actuary jokes
For those who read this by email: if some of the links in this newsletter wrap in your email window, or your email client cannot open PDF files, you can go to the online version of this newsletter and right-click on the links to save the files:

1)  IT Risk and Security

End user computing risks

I presented on this topic on Sep 30 to the Information System Security Association of Ireland ( The risks in end user development is getting more prominent attention in the software engineering community: "The Dangers of End-User Programming", by Warren Harrison IEEE Software, July/August 2004, pp. 5-7. Warren says "recently Iíve become uneasy thinking about where these dabblers are applying their newfound knowledge...And now weíre expecting (no, depending on) these folks to write software that not only works correctly but is secure as well?" The Sep/Oct 2004 issue of IEEE Software magazine has free access to a PDF of the letters page that includes readers' comments on these risks, "How Dangerous Are End-User Programmers?" Warren comments "Programming isnít easy or error free, even for 'professional developers'. Why pick on end users? "


Hackers use Google to access networked photocopiers
Many people don't realise that modern photocopiers have hard disks that spool image files. If configured incorrectly or left to default, networked copiers can reveal network information, such as IP addresses, login details and device information, so that it can be indexed by Google.

A post on the Open list in Ireland said "reminds me of all the laser jet printers you used to find on the internet that had no password protection. I found that <name> had such a printer sitting on their network once. Wonder how many pages of 'please change my password' it took for them to fix it :)"


October is CyberSecurity Awareness Month "Securing your personal computer plays a crucial role in protecting our nationís Internet infrastructure. The National Cyber Security Alliance (NCSA) is a public-private partnership focused on promoting cyber security and safe behavior online." Includes a list of the top ten cyber security tips for home users.


Culling unpopular colleagues?
Software Magazine September/October 2004 (Vol. 21, No. 5) pp. 28-32 Why Culling Software Colleagues Is Popular
"Cutting staff is generally seen as an unpleasant duty, to be carried out when a companyís financial position deteriorates. This article explores the observation that regular culling of staff can be popular with the workforce, because poor performers cause much more damage than is apparent to management. Using queuing theory and simulation, the author demonstrates the severe impact of poor work. In this context, the support for cutting poor staff is logical. The author recommends surveying your software developers to find out if they feel that this would improve their productivity. If so, then there is a popular mandate to implement a 'rank and remove' approach. "


Hacking Exposed: Network Security Secrets and Solutions, 4th edition Stuart McClure, Joel Scambray, George Kurtz. Explains operating systems, switch and network vulnerabilities--used by the bad guys to get in--and how to remove them. 

Hacking: The Art of Exploitation, by Jon Erickson. Describes the techniques of computer hacking, covering such topics as stack-based overflows, format string exploits, and shellcode. of Exploitation  


2) Quantitative methods

I have just started presenting a course in Quantitative Methods to the first year BA students at the Irish Management Institute. This draws upon my background in financial modelling and operations research, and some lecturing I did in the School of Management Science and Information Systems Studies (MSISS) at the Department of Statistics in Trinity College Dublin.

For the course book, I am using Louise Swift's "Quantitative Methods for Business, Management and Finance"  because it starts from the right place for mature students who have forgotten school math, and gives many examples to practice the points.  It covers Essential Maths, Describing Data, Probability, Statistics, and Business Modelling, which includes linear programming, project planning, inventory control, time value of money, quality control, and simulation. 

I can send a longer book list to anyone who requests it. My close second choice was "Quantitative approaches in business studies", by Clare Morris 6th ed 2003, very reader-friendly but slightly less detailed. 


For readers interested in quants, here are some more useful links: Paul Wilmott's site on Quantitative Finance (is there any other kind?) has forums discussing financial engineering techniques, risk modelling, derivatives, Monte Carlo simulation, and more. His book is:

Paul Wilmott on Quantitative Finance, 2 Volume Set, gets five-star reviews. Updates "Derivatives: The Theory and Practice of Financial Engineering". With essential Visual Basic code and spreadsheet explanations of the models 

Here are two online texts with free content:  Spreadsheet Modeling for Investment Decisions, online ebook by Martin Hovey of the University of South Queensland. "Spreadsheet Modelling for Investment Decisions should be treated as a supplement to finance textbooks... a valuable aid to developing workable models quickly and accurately."  Spreadsheet Modeling in Corporate Finance, online ebook by Martin Hovey of "The book is written as a supplement to your corporate finance textbook."

Financial Modeling, by Simon Benninga. A finance "cookbook" that bridges the gap between theory and practice by providing a nuts-and-bolts guide to solving common financial models with spreadsheets 


3) Euro future

I recently had a call from Elly Fiorentini of BBC Radio York to answer a question live about decimalisation. It still looks unlikely that the UK is going to do anything about the euro, even though the public service is still conscientiously updating the transition plan:  Euro Preparations - What you need to know (July 2004)
This leaflet provides a summary of the third outline National Changeover Plan. It explains how the UK would make the change from sterling to euro in the event of a decision to join.

I also hear from people in the new EU accession countries about my euro conversion book, so maybe this topic will be revisited in a couple of years!

Just to remind you, my popular online Euro currency exchange conversion calculator Convert euros, dollars, pounds, and more for EU and world currencies with today's European Central Bank rates is available for free use in an iframe if you would like to provide visitors with a currency converter service on your web site.


4) Spreadsheets

New Statistics on Model Error Rates

Usually, people quoting statistics on defect creation rates in spreadsheets refer back to Ray Panko's original researches from 1995-2000. Here is some current work that shows it's just the same now.  Financial Modelling of Project Financing Transactions; Robert J Lawrence, Jasmine Lee, Institute of Actuaries of Australia Financial Services Forum 26-27 August 2004.

They quote Tom Grossman: "experienced spreadsheet users are but amateur spreadsheet programmers." and go on to say "The risks of modelling are well understood in the project financing industry, particularly in the Australian market, and these risks are beginning to be appreciated in other industries as well. People with actuarial training are more likely to view the financial model as a dynamic rather than static model and thereby focus on the logic rather than the results based on current input assumptions."

Statistics on Model Error Rates is an appendix. "They are based on the thirty most financially significant projects that Mercer Finance & Risk Consulting reviewed during the financial year ending 30 June 2004. For the financial models related to these thirty projects the average number of unique formulae per model was 2,182 and the average number of issues raised during the initial review of these models was 151 (or, 6.9% of the number of unique formulae). The average number of versions required in order to produce a model that could be 'signed-off' was 6."

One spreadsheet needed 17 revisions to resolve 239 issues: 22MB, 4,825 Unique Formulas. The very best (in terms of issues as % of Unique Formulas) spreadsheet needed 3 revisions to resolve 49 issues: 1.9MB, 1,559 Unique Formulas.


5) Off Topic

Ig Nobel prizes 2004 The 2004 Ig Nobel Prize Winners
MEDICINE : Steven Stack of Wayne State University, Detroit, Michigan, USA and James Gundlach of Auburn University, Auburn, Alabama, USA, for their published report "The Effect of Country Music on Suicide."
PUBLIC HEALTH : Jillian Clarke of the Chicago High School for Agricultural Sciences, and then Howard University, for investigating the scientific validity of the Five-Second Rule about whether it's safe to eat food that's been dropped on the floor.
CHEMISTRY : The Coca-Cola Company of Great Britain, for using advanced technology to convert liquid from the River Thames into Dasani, a transparent form of water, which for precautionary reasons has been made unavailable to consumers.

Check the web site for the other categories!

Actuary jokes May 2004 issue of Actuary Australia

- technical analysis is astrology performed with a spreadsheet
- bank propriety derivative trading is gambling sanctioned by boards who do not understand it
- selecting an investment manager is like choosing a poker machine based on how much it has paid out in the recent past.
(Darren Wickham)

An actuary is someone who can tell you how many people will die in the next year. A Sicilian actuary can also tell you their names and addresses.
(Roger Bohlsen)


