Feeds

RBS must realise it's just an IT biz with a banking licence

Expert drills into what it'll take to prevent another bank technology fiasco

Security for virtualized datacentres

So. How can they stop that meltdown from happening again?

An ex-RBS worker told us that he feared that during the clear-up, the banking giant would plaster on more processes and more "risk management". And that seems to be what Stephen Hester has in mind - that's what he told the MPs, anyway:

The investigation will address the effectiveness of our risk management systems, including the identification of low probability/high impact events and their mitigation. It will also assess contingency planning and business resilience i.e. whether other systems within RBS Group are at risk of similar incidents.

But risk management at RBS is already unwieldy, and may in fact have contributed to the crisis, the former employee argued: "If you want to focus on the real problem that caused this it is the overly restrictive change control, as counter-intuitive as that may seem."

Our contact said in a move unrelated to the massive cock-up in July, RBS "management added another two layers of change control" - which are effective another rulebook of procedures to ensure updates to a system are formally agreed and rolled out as planned.

"I like to think I've been around the block, and I can safely say that the change management in RBS is the most complex I have ever come across - so much so I believe it is counter-productive," the source said.

That dissatisfaction with bundles of red tape was echoed by two other RBS workers who spoke to The Reg. Of course change management is an essential part of developing and maintaining an IT system, but an unwieldy rules designed by people not fully aware of the technical hurdles nor with an appreciation that the system is based on "quirky" mainframes of yore, combined with lower-skilled employees and bosses who weren't listening, seems to have created a situation where a problem, when it occurred, ballooned out of control.

Can they spare some change?

A spokesman for RBS told The Reg in response to our findings: "We're carrying out a full and detailed investigation into the causes of the incident. We plan to share the findings of this and will be happy to comment further once this is published."

Banks will need to rethink the position of IT in their businesses, said Chan: "They can get it right, it's when they apply the squeeze in the wrong place that we get these problems."

And in the case of overhauling banking systems it may take someone with bottle, a lot of money and some serious longterm thinking: as a banking expert suggested, it would be like changing all four engines on a airplane mid-flight. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Phones 4u slips into administration after EE cuts ties with Brit mobe retailer
More than 5,500 jobs could be axed if rescue mission fails
Apple CEO Tim Cook: TV is TERRIBLE and stuck in the 1970s
The iKing thinks telly is far too fiddly and ugly – basically, iTunes
Huawei ditches new Windows Phone mobe plans, blames poor sales
Giganto mobe firm slams door shut on Microsoft. OH DEAR
Phones 4u website DIES as wounded mobe retailer struggles to stay above water
Founder blames 'ruthless network partners' for implosion
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Forget silly privacy worries - help biometrics firms make MILLIONS
Beancounter reckons dabs-scanning tech is the next big moneypit
Microsoft's Office Delve wants work to be more like being on Facebook
Office Graph, social features for Office 365 going public
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.