Case 3: AgregGREAT!


The Company: Klew Loess & Associates
New Idea: AgregGREAT!
Ñ  HackMeCo financial subsidiary.
Ó  Original Business Plan: Medicare Fraud Prevention
Ñ  New Idea: AgregGREAT!
Ó  Customers give us all of their financial portal login information (banks, brokerages, credit unions, credit reporting agencies), we login for them, get their information and present it in a useful way
Ó  Profit!

Some Assumptions
Ñ  There are no laws preventing the new idea
Ñ  AgregGREAT! Has been discussed generally among management & is gaining some traction internally
Ñ  The projected numbers for AgregGREAT! are 4x current revenues in 2 years
Ó  Depends on a completely new customer base, not all from USA
Ó  Depends on perception of reliability (marketing)

Questions from Business Development Team
Ñ  We’ll be logging into financial portals and scraping data. Will banks have a problem with this?
Ó  Will they start blocking us?
Ó  Do we need to read the AUP for each portal?
Ñ  We don’t understand how to deal with additional authentication stuff, but we see it in use a lot. Can this generally be solved?

Value Proposition
Ñ  Advisors often advise folks without a clear picture of their current financial position. By aggregating from all of the online portals, we know everything we need to give good advice.
Ñ  We usually get snapshots of information, widely spaced over time. This will allow frequent updates showing trends, spending habits and cash-flows
Ñ  Our current client base is limited to folks we can see in person in Seattle. This will extend our reach
Ñ  Improved quality of advice will improve our performance, providing competitive advantage
Ñ  More information on client behavior provides opportunities to introduce more services that are tailored to their needs

Prepare an Information Assurance (IA) Response to this Business Plan
Ñ  Try to NOT say anything negative about the plan
Ñ  Provide insights into both the new IA risk incurred by having everyone’s banking and other financial services credentials
Ñ  Explain how you can make these risks acceptable.

Complete the Following    
Ñ  Research the situation. Provide insights into the new IA risk incurred by having everyone’s banking and other financial services credentials. (500 words or less)
Ñ  Provide a well-supported recommendation on how you can make these risks acceptable. (500 words or less)

Comments

Post a Comment

Popular posts from this blog

API Security - A risk based approach for CISOs

2024 Year Review and thoughts

Key Steps for Building an Effective Data Protection Program: From Analysing Business Needs to Ongoing Protection