Showing posts with label BCAW. Show all posts
Showing posts with label BCAW. Show all posts

Friday, 11 April 2014

Business Continuity Flash Blog

On Tuesday 18th March 2014, as part of the Business Continuity Awareness Week activities, we witnessed the first ever BC Flash Blog. This is probably a new term to most readers, it is a virtual Flash Mob – but instead of a dance routine the participants wrote and published their own blog post or article.

The event featured 22 writers, from all sectors of the BC industry – and from various corners of the globe. All the articles were on the same subject, and published at the same time. In keeping with the BCAW theme, the subject was “Counting the costs, and benefits, for business continuity”, with each writer taking their own, unique, perspective on this issue.

If you haven’t already done so, you can find links to all 22 of these blogs here. If we do nothing else, we can at least pay these writers the respect of reading their work.

For those who are interested in statistics, the page with the list of articles has had over 600 views (as of the 7th April). The list is hosted on a service called List.ly that facilitates social media style interactions with the community. Readers are able to flag like/dislike; indicate which articles they have read and, perhaps just as importantly, which subjects they would like to learn more about.

To date there have been 123 of these interactions recorded – but sadly these have come from only 11 people. You do have to register with the service to interact, which may have stopped many from casting a vote. These interactions are still open, and it would provide useful feedback to guide future articles if you could visit the site and record your thoughts.

Despite the relatively low number of interactions recorded, the feedback from a number of the writers indicates a good level of hits on these articles. While not everybody had full scale analytics, reported around 100 hits on their article and another over 180 hits. This may, in part, represent the existing audience of some of these writers as much as the BCAW promotion - but that is part of the educational value to be derived from the exercise.

BC folk need to learn about tapping into, and leveraging, existing networks and communities if we want to promote our cause and our message. The extra reader base accessed by distributed, rather than centralised, blog hosting. Just as importantly, the extended reach of the Social Media networks of the various writers and the 'priceless' publicity that was generated by the Tweets and Retweets. These are lessons we can look at applying to our own BC programmes. How we can use tools like blogs and wikis in our organizations; improving our understanding (and adoption) of the various social media tools (like List.ly) and the value of debate and interaction, rather than passive consumption, in promoting a vibrant discipline.

One message that comes through very clearly in several of these articles is the passion that BC people have for the work we do. It was a joy to see that passion from old practitioners as well as from newer ones. The passion for the work and promoting the cause also spanned geography and language.

That passion means we can at times be forceful when we debate our different views and perspectives on how to count the costs – and even what constitutes benefits and value from BC. But it also drives a genuine desire to promote improvement and learning across our practices. Without debate, and passion, no field of knowledge will develop. But debate requires engagement.

I spoke about this passion, and used three of the articles as examples, in my BCAW webinar. It is recorded and can be accessed here, it also contains some instruction on how to access and engage with the List of articles.

It would be great to hear some feedback about the concept of a Flash Blog, about the articles, or even what topic you would like to see for a future Flash Blog event. You can comment here on The BC Eye, or start a discussion in one of the many Linked In groups where this post will be promoted.

My thanks to all those who contributed articles, I hope you all keep writing! Thank you also to those who take the time to read – and extra special thanks to those who make it all worthwhile by engaging and debating these ideas.

Finally, if you are wondering why we chose to have our Flash Mob write a blog post rather than demonstrate a dance routine – then this YouTube clip (featuring one of our contributors) should provide an adequate explanation.

Ken Simpson
Director of The VR Group

Tuesday, 18 March 2014

Counting the costs and benefits of business continuity, a Non-Executive Director's perspective

Essentially the Non-Executive Director's role is to provide a creative contribution to the board by providing objective criticism. So I recommend that all Non-Executive Directors consider challenging the board to count the costs involved in deploying business continuity management and balancing these costs against quantifiable benefits gained from its Business Continuity Management System and Programme.

The Good Practice Guidelines suggest that embedding BCM is hard to measure, but secretly I believe that Executive Directors deep down in their hearts and minds know full well if they are merely trying to be compliant.

In the busy world of the Executive, maybe they only have time to ask if the business is adequately covered from a risk and business continuity perspective. Is it the difference between plausible deniability and culpable liability? To paraphrase a well-known political interviewer: “Did you know there was a problem, in which case you are culpable or did you genuinely not know in which case you were incompetent, which is it?”

Apply that logic to the board and ask them if they understand the relationship between, in some cases, hundreds of thousands they spend on business continuity management believing that it will deliver benefits should it be needed, without insisting on seeing the cost benefit analysis that proves the case, only to find that in reality, plans are hardly invoked or utilised even in a real event.

I can only suggest from experience that Top Management Executives are unlikely to ask the question: “Show me the costs associated with maintaining our Business Continuity Management System/Programme and tell us how much deploying our strategy for resumption will cost if invoked and the savings, yes, savings to the business in reducing the impacts to the business over a known time scale.”

If business continuity professionals were pressed to answer this question, they would have to take a more commercial view of business continuity, they would have to truly align to risk disciplines and share common risk and impact scales and they just may invite procurement professionals to assist in quantifying response strategies and tactic and resource requirements.

This would lead to Top Management Executives having a genuine opinion, to give a mandate and possibly believing that business continuity does indeed add commercial advantage to your business.
So, I implore Non-Executive Directors and Heads of Audit Committees, challenge your Top Management Executives to prove the commercial case for undertaking business continuity management for your business.

Ask your Chief Risk Officer or their equivalent in your business:

  • How much do we spend annually on business continuity management, without an incident taking place?
  • How much would you estimate we would spend on deploying our strategy and tactics during a disruption and in achieving the timescales for resumption how much cost avoidance would we achieve in monetary terms?

Even as I write this, the national news talks of under spending and being under prepared for severe disruptions, they offer the costs associated with preparedness and with failure, within days or weeks of an event.

So I will say it one more time, why do we not estimate these impacts in monetary terms using the same methods as undertaken post event – but do this in advance. Why can we not offer Top Management Executives fixed and variable costs (including invocation) set against the cost of impacts over time? Let them decide their Maximum Attitude to Disruption M.A.D.

Finally, why don’t Top Management Executives ask these questions, rather than simply are we covered?

By David Window
Non Executive Director at Continuity 22301 Ltd

Counting the costs and benefits of business continuity, the BCI Technical Director's perspective

For those of you who think BCM is expensive, try operating without it.

Business Continuity has often been treated almost as an ‘act of faith’. Common sense has suggested that well prepared companies are likely to recover from an unexpected interruption quicker than unprepared ones; that they are likely to lose much less money by being productive again more quickly.

In times of financial restraint, with organizations looking to squeeze costs wherever possible this position is hard to defend, in some cases it simply no longer works. It is not too difficult to find out how much is directly lost as a result of disruptive incidents; in fact our friends from the insurance world have facts and figures about all types of incident – the amounts claimed, the amounts paid out and the actuarial data that supports the likelihood of every type of known problem.

This does however, leave difficulties for the BCM practitioner. Given the increasing attention paid to ‘black swans’, ‘unknown-unknowns’ or generally unpredictable events (illustrated again by the Malaysian aircraft disappearance), conventional risk pricing that requires forecasting both probability and loss expectancy is meaningless. For BCM people, how can we hope to quantify the potential loss connected to brand and reputation damage, market-share loss, share value collapse and more aggressive targeting by competitors?

Even if we can argue successfully (without detailed facts and figures) that we need to protect ourselves from the potentially terminal consequences of unexpected incidents, can we make a strong enough case for BCM as the solution? It is one thing to point out a problem, it is an entirely different thing to show you have the answer. For many years the BCI and other similar bodies have conducted regular surveys that demonstrate that the cost of business disruptions is significant. This has increased in line with trends such as ‘JIT’ manufacturing, complex and extended supply chains, increased off-shoring of services and purely cost driven out-sourcing of operations.

A soon to be released global survey indicates that almost 30% of respondents have experienced business losses of over $5 million as a result of a disruptive incident. This was up from less than 20% three years ago. The challenge for BCM professionals is not so much to shout about those facts (although that approach can help sometimes) but to show why Business Continuity can help both reduce the likelihood of suffering that loss at all, but if it should happen that the loss can be dramatically mitigated.

The wider dialogue taking place about resiliency throughout industry and government actually helps our case. In some ways recovery is simply a failure to be resilient, although total protection from everything is clearly impossible. The need to balance measures that make us inherently more able to withstand rapid changes in risk (political, environment, social and technological) with our ability to adopt and response as needed is the future for BCM thinking. What value do you put on success and what cost do you put on failure? Does effective BCM make the former a more likely outcome than the latter? The answer to those questions provide the justification for Business Continuity – in my view it is a modest investment for corporate decision takers who understand the real questions.

By Lyndon Bird
Technical Director at the Business Continuity Institute

Monday, 1 April 2013

Meeting the Supply Chain Complexity Challenge - Part Two

 
Lee Glendon CBCI
Head of Research and Advocacy
Having identified some of the drivers of complexity in supply chains in the first part of the roundtable report, how are organisations dealing with the challenge?
 
In dealing with the challenge of multiple tiers in the supply chain, there was common agreement on the need to gain better visibility but divergence of approach in practice.  Some organisations were looking at better methods to manage tier two supplier relationships, while others recommended that the best approach was to work with tier one suppliers and get them to work with their suppliers in turn.  In the case of one large retail organisation, they worked through their supply chains to the source applying a consistent code of expectation in terms of product quality and integrity throughout.  It was recognised that this was a very resource intensive process. However, it was an embedded practice, so for them it was not a case of having to justify the investment each time; an enviable position in the eyes of most of the roundtable participants.
 
The discussion moved on to the challenge of managing 10’s of thousands of suppliers and there was consensus on the need to focus efforts on key suppliers and key supply chains.  It was recommended that filters are applied to provide focus – these filters should be based around criticality in the sense of ‘would failure of this supply chain quickly stop my organisation from being able to carry out its key activities, and how quickly could they be replaced’ and secondly around risks or threats that might cause disruption, such as the supplier’s financial profile, the health of the industry in which they operate, their locations and consequent exposure to risks as diverse as flooding, earthquakes and geo-political instability.   These filters help generate a ‘shorter-list’ to scrutinise.  Another approach favoured by many at the roundtable was to use procurement ‘category management’ to breakdown suppliers into common supply groups and then perform risk profiling on this basis.
 
For those suppliers identified as key to the organisation, the favoured approach was to seek to build closer relationships at executive and operational levels with the objective of improving communication and co-operation and thereby reduce the number of ‘surprises’.  For one organisation, this took the form of running workshops on business continuity and running joint exercises.  Toolkits were provided free of charge and their business continuity plans were shared to help get alignment.  They would also recommend that supplier staff joined institutes such as the BCI to develop capability and drive programme improvement.  Interestingly, one of the unintended consequences of this deepening of the relationship, is the difficulty of exiting such relationship, as it would mean investing a considerable amount of time bringing on board a new supplier to get to the same level of understanding.
 
Some organisations were concerned about being overly onerous on their supply network, especially those operating in sectors where there are a limited number of suppliers.  One person noted that they had experienced suppliers not wanting to do business because the compliance requirements did not make it worthwhile.  In such cases, purchasing organisations are co-operating to reduce the burden on their suppliers through articulating common requirements.  
 
Following a good discussion on approaches to deal with the consequences of increasing supply chain complexity, the ‘wish list’ of participants included the need to gain a better understanding of ‘what supports the supply chain’ and mapping out supply chain networks.  Others were looking for a more dynamic set of indicators that would flag signs of difficulty and an impending risk event in the supply chain.  Another felt that there was a need to consider ‘profit impact’ rather than spend in identifying key supply chains.  While one delegate felt there was a need for procurement to drive risk conversations with suppliers and ensure due diligence had happened.  In this last respect CIPS is planning to develop a number of educational and training resources to support development of its members to meet the challenge.
 
The final thought from the discussion should go to the ‘what’s the return on investment’ question when it comes to investing in supply chain resilience.   For one major organisation top management evaluates the value of investment in resilience in terms of how well it prevented a problem and how well the organisation come out of it.   Quite simple really. 

Vision Therapy - helping you to see more risks

Ken Simpson, Director
The VR Group Pty Ltd
Thank you all who joined my BCAW webinar, Vision Therapy - helping you to see more risks. I try to make my webinars as interactive as possible, using polls and other techniques, and following up with a post such as this to share any interesting results of the polls and pose some additional questions for people to reflect upon. 
 
In keeping with the theme for BCAW 2013 my presentation argued that there are those risks we see, those we don't see (because we are not looking or because we refuse to recognise them) and then there are those that you cannot see - which are the Black Swan events. My argument was that there are perhaps less Black Swans than we think and more of the events we don't see because we don't look and recognize the threats and vulnerabilities. 
 
The concept of the 'Black Swan event' has become part of the language of BC. If we want to understand this concept we should at some point read how it was originally proposed, rather than rely on how somebody else filtered those words. I posed this question to the audience;

Thursday, 28 March 2013

In cyberspace, no-one can hear you scream (or snore)

Andy Osborne
Consultancy Director, Acumen
Author of Practical Business
Continuity Management
On Friday I presented a webinar, on scenario-based exercising, as part of the Business Continuity Institute's Business Continuity Awareness Week 2013. And I have to tell you, it was one of the most nerve-wracking things I've done for a long time. 
 
Which is a bit bizarre, really, as I do presentations all the time, to audiences of various sizes (that's numbers of people, as opposed to body mass). I'll admit that there are often a few butterflies just before the start, but nothing particularly serious. 
 
The difference with this one was the strangeness of it all. I was effectively presenting to an empty room and it felt like I was talking to myself - into my 'phone but with no-one on the other end. Except I wasn't, because there was quite a decent sized audience out there, somewhere. All I knew was that there were 76 of them. I only knew that because there was a little green "76" on my computer screen. I didn't know who they were, what they looked like, where they were, why they were listening or what they were expecting.
 
The strangest thing was the absence of any feedback (aside from the online polls I did in an attempt to discover some small snippet of information about the audience). I didn't have the faintest idea whether people were nodding in agreement, smiling, shaking their heads, falling asleep, going off to make a cup of tea or checking their e-mails (heaven forbid). All I could see was that little green number telling me that 76 people were at least still logged in and all I could hear was a deafening silence on the other end of the line.  It was very disconcerting for someone who likes to see the whites of his audience's eyes.
 
It didn't help that, having logged in, as instructed, well in advance of the start time, the webinar system then insisted on telling me, every minute, via one of those awful "press one to be ignored for a bit longer" recorded voices, how long was left until show time, followed by a final countdown that did nothing to ease my pre-match nerves. 
 
Then there was the system itself. I'd had a trial run - which was just as well really as when I tried it with a headset the sound quality was awful and I had to revert to the 'phone's handset. Which meant I couldn't move further than the length of its cable, and that severely curtailed my usual habit of going for a bit of a wander when I'm presenting. And some of the system's features weren't available on the test site so I was learning as I went along on the day. All in all I found it just a teeny bit unnerving. I was out of my comfort zone, I suppose. 
 
I ended up standing up for most of the session, adopting a sort of 1960s horror film manservant hunch over my computer screen and mouse, along with a sort of side-to-side shamble. So it's just as well my audience couldn’t see me either. But, after a bit of a wobbly start, I got my act together, my nerves settled and I got on with the job in hand. In the end I received a pretty decent score, along with some very complimentary comments, so it can't have been that bad - it just felt like it to me at the time.
 
Afterwards I couldn't help thinking that there were some parallels with exercising and testing our business continuity capability, which was the topic of the webinar.

Monday, 25 March 2013

What’s driving supply chain complexity? Part One

Lee Glendon CBCI
Head of Research and Advocacy
In the BCI’s report Horizon Scan 2013, one of the key trends of concern identified by Business Continuity professionals was “increasing supply chain complexity”.  So on Tuesday 19th March, the BCI and the Chartered Institute of Purchasing & Supply (CIPS) convened a roundtable of senior supply chain, risk and business continuity practitioners from sectors as diverse as retail, manufacturing, energy, housing, construction and telecommunications to share experiences and discuss how they were dealing with the challenge.
 
If folk were hoping that complexity is something that will stop or slowly unwind, then they would not have got much comfort from the discussion.  
 

BCAW Roundtable Discussion 2013
Perhaps, the most important driver of complexity is the customer and the desire of businesses to develop the right supply chain to meet the needs of the customer.  For example, the supply chain required to be able to sell a product as “made in Italy” sets its own restrictions and risks that need to be managed.  
 
Many of the drivers of complexity have come about through conscious business decisions.  A number of organisations had decided to consolidate their tier one suppliers – while this simplifies the number of interfaces at tier one, what is has done has created many more tiers below the immediate supplier, reducing visibility.  Participants noted that they were now experiencing disruption originating at tiers five and even six!  
 
Another issue raised by a number of people was around the illusion of diversity that dual-sourcing can bring.  While many had introduced dual-sourcing in terms of immediate suppliers, some had found to their cost that at tier two or three they were reliant on a single supplier again.  This point opened up a wider discussion about how difficult it was to understand interdependencies between suppliers and that the term supply chain should perhaps be replaced by ‘supply chain networks’.
 
Some sectors were suffering from lack of communication around changes in their extended supply chain.  More than one participant commented that their suppliers would change the location of production or the people providing a service without informing them, so organisations would be caught out in finding that an event, for example industrial action, in one country affected them, even though they didn’t think they had any exposure to the event.
 
Representatives from the public sector provided an interesting contrast to their colleagues in the private sector.  Their driver of complexity was government policy which was requiring not supplier consolidation but increasing their spend with small and medium sized businesses, while this was sometimes managed through a large tier one supplier, there was a need to monitor the success of this policy and provide extensive training and development support for small businesses to work with government entities.
 
The consequences of redrawing the boundaries of organisations over many years through outsourcing were also flagged as creating challenges in that the suppliers often had more knowledge and expertise than the client. Some felt that too much intellectual power had been outsourced and one organisation stated that they were now bringing back in-house some of the higher skilled activities.
 
In concluding this part of the roundtable discussion, it’s much clearer why complexity is such a taxing trend for Business Continuity professionals and why it is so important to find an approach to manage it effectively. 
 
In Part 2 of this roundtable report, we’ll look at some of the techniques that are being used to manage complexity.
 

Practice makes perfect or scenario-based BC Plans are a waste of time!

Your BC Eye
Donna Monkhouse
We are all familiar with the expression “practice makes perfect” and never has a truer word been spoken.  Practising is all about rehearsing again and again until you have mastered the role you’ve been assigned; but, it is also about improving your behaviour.
Today’s BCAW 2013 webinar of my choice was the one on exercising, or rather scenario-based exercising, which was presented by Andy Osborne MBCI, Associate Consultant at Clearview-Continuity.
The first question Andy raised was, why bother with exercises?   
Well, the short answer is that it takes a lot of time, effort, resources and money to write a Business Continuity Plan (BCP) and if you want to see a return on this investment, you need to make sure it works.  Simply having a BCP in place will not save your business; what will save it is having the right people with the right capability to deliver that plan, and the only way to develop that capability is through practising or as Business Continuity professionals prefer to say, through exercising. 
So should a BCP be based on particular scenarios? 
Well according to Andy, “scenario-based plans are a waste of time”.  What Andy was essentially saying with this somewhat controversial statement (at least at first glance)  is that there is no way that we can think of every possible scenario nor can we plan for every conceivable type of incident that we may be faced with at some point in the future.  More often than not, old Murphy’s Law will kick in and you will find yourself either faced with the one scenario you hadn’t thought of or the scenario you had in your head pans out quite differently in reality.  What is critical here is not to plan for every scenario, but to plan for any scenario and the way you do this is to build the capability within your organization to respond to any incident by getting the people involved to rehearse again and again until they know their lines off by heart (speaking in theatrical terms of course)!
What about scenario-based exercises?
Scenario-based exercises, on the other hand are not a waste of time but can be very valuable in terms of emphasising issues that no one had thought of; highlighting your strengths and your weaknesses (remember, you are only as strong as the weakest link); clarifying responsibilities; testing your communications and ultimately, helping you to improve and enhance your response capability. 
Which scenarios should you select?
It doesn’t really matter what type of scenario you select, but what it does need to be is credible, engaging and realistic and it needs to meet and reflect your objectives and the key issues you are hoping to address through the exercise.  So when planning an exercise, don’t start the process by trying to think of some great theatrical spectacular, focus in the first instance on your objectives and issues.  You can make up the most exciting, mind-blowingly creative and fictitious incident, but if it doesn’t meet your objectives then it will have little value and will really be a complete waste of time!
When it comes to facilitation of a scenario-based exercise, there are many approaches that can be taken.  It could be as simple as a desk-top exercise where you gather everyone around the table to talk them through the plan or even walk them through it; or it could be a bigger event involving role play and fake journalists, doctored photos and staged radio broadcasts. 
The key observation made by Andy based on his extensive experience in the field, is that what you do will and should be decided by the people you need to involve inasmuch as some people will feel comfortable with role play; others will feel totally out of their comfort zone; some will react well and others badly.  You need to understand the composition of your Incident Management Team, the intricacies of their personalities as well as having (if possible) some insight into past history and previous experiences and traumas so that you can at least make some kind of pre-judgement as to how they might react to certain scenarios and whether they are the right men or women for the job.
 You also need to consider whether they can work well together as a team and whether indeed they know each other well enough to perform effectively as a unit, after all, you are only as good as the sum of your parts.   
Both approaches of course have their value.  If you decide for the role play (which does not involve dressing up in fancy costume), you can make this as realistic as you like, just be sure to be aware of the fact that different people will react in different ways.  Certainly, if you wish to include a death of a colleague in your scenario, it is wise not to use real people’s names but safer to stick to a fictitious name instead; using real names can have terrible emotional consequences for some of the players on your stage.  How realistic you can make it, will of course depend on how realistic you can afford to make it, but the sky really is the limit here.  You can involve multiple teams and use multiple locations in your scenario; there is no right or wrong.  Andy did, however, strongly advise anyone planning to use multiple teams to first carefully consider which teams to involve at what point otherwise you will have people involved with nothing to do for long periods of time, which destroys the ‘engaging’ element of your scenario and will result in loss of interest and loss of ownership and ultimately spell out a miserable failure.
So how do you get the most out of your exercising?  Here Andy’s top tips:
  1. Plan and prepare for your exercise properly
  2. Think about the management and the coordination of the exercise
  3. Use experienced facilitators
  4. Develop an exercise plan and schedule
  5. Ensure you have clear objectives and measurable success criteria
  6. Brief all participants including the facilitators in advance as well as you can or should
  7. Have some independent observers on the side line as they can provide excellent, impartial feedback post-event
  8. Create and use post exercise critique forms and log books to capture key information and observations
  9. Write a report and follow up on the report’s recommendations as part of your lessons learned (after all exercising is also about improving your capability)
  10. Finally de-brief everyone who was involved and make sure all loose ends are firmly tied up
At this point, Andy reminded us of the 5 Ps (or 6 Ps used in the army, but we won’t mention the sixth one here!): Proper Planning Prevents Poor Performance – good planning breeds success; success breeds confidence, confidence in your plan, in your team and ultimately in your organization to withstand any scenario! 
The final question that Andy put on the table was when to exercise? 
The Business Continuity Management Lifecycle tells us to exercise and test at the end of the process, but we could exercise during strategy definition or maybe during the implementation process.  In fact, Andy went one step further and made the brave suggestion that maybe the Lifecycle should begin with exercising as this is guaranteed to make people sit up in their seats and pay attention; it will highlight the key issues; it will emphasise the importance of Business Continuity and it could be key to getting buy-in especially at the top, which as we know can be more than difficult! 
This webinar certainly provided me with ample food for thought and hopefully you have learned something too by reading this blog!
BCI Physical Workshop
Would you like to find out more about how to plan and run an exercise programme or how you can invigorate or inject new life into an existing programme? 

The BCI is running a workshop dedicated to this topic in Manchester this month:
 



Dates:
Wednesday, 24th April 2013: Planning and Running an Exercise
Thursday, 25th April 2013:Invigorating your Exercise Programme
Location: Manchester
Type: Physical (Delegates can choose to attend both or just one of the sessions)

BOOK NOW >>

BCI Member Rates apply.

Friday, 22 March 2013

Cyber Threats and Cyber Security – are they real and can they be managed?

Your BC Eye
Donna Monkhouse
 
My  topic of choice for yesterday's webinar listen-into was the one on Cyber Threats and Cyber Security by Brendan Byrne from IBM in which Brendan shared both IBM’s and other organizations experiences from the dark world of cyber threat.
 
According to a recent IBM survey, the biggest threat perceived by Business Continuity professionals is cyber-security.  Some of the challenges faced include BYOD (Bring Your Own Device) which is on the increase; the widespread use of social media with its pros and cons; workforce mobility and the increasing use of cloud-based solutions.
 
The landscape is changing for organizations all around the globe.  Big Data or Smarter Data inevitably means more security considerations and the growing use of online services is another cause for security concern.  The boundaries are becoming blurred as we step up the use of the innovative technology that is advancing our way.  Supply Chain Security, as Brendan quite rightly said, is indeed only as strong as the weakest link in the chain and the expanding use of data is presenting more and more problems in terms of potential threats to an organization.
 
According to the X-Force Research Team (just one of the jewels in IBM’s crown) who is tasked with analysing the worldwide web on a daily basis, scanning the horizon for new trends and new vulnerabilities, there are over 40M spam and phishing attacks every month!  Now that is a scary figure.  KPMG’s Data Loss Barometer 2012 showed that hacking is the number one cause of data loss and that data loss incidents have increased by 40% since 2011.  There is evidence of new attack activity as malware gets too clever for its boots.  Some of the challenges faced are down to things as apparently simple as passwords (or rather the common and widespread use of the same password) and of course there is the challenge of BYOD and a new concept, called APT (Advanced Persistent Threats).
 
One of the key messages that this webinar drove home, was the importance of embedding cyber-security into an organization’s business culture.  It is not enough to develop a policy and then file it away thinking that the job is done and a big fat tick has been put in the box.  With a constantly changing landscape and new threat activity entering the “Cyber Charts”, it is essential that organizations review, review and review again to ensure that their policies and procedures meet the current and future security needs of their business.
 
One of the key issues is that cyber threats are just getting more and more sophisticated.  Motives for cyber-attacks range from simple curiosity, to revenge, right through to the big stuff like espionage and political activism.  The players or actors on the cyber stage are also becoming increasingly more educated and organised.  They scale of actor type runs from the inadvertent actor, who may cause an incident through ignorance or lack of training; to the opportunist that just grabs the moment to do some damage; to the “hacktivist” (remember that is the number one cause of data loss); right through to the top of the tree with the advanced actor, that heads up some big scam.
 
According to IBM research, the top three IT risks that damage a company’s brand (its greatest asset) and reputation (as perceived by BC professionals) are:  Data Breach; Systems Failure and Data Loss in that order.
 
An interesting example of a botnet was put in the room as such to demonstrate both its apparent innocence and its inherent danger.   We can all very easily download a botnet.   More often than not, this just sits harmlessly on our computers until the organiser of said botnet decides to sell this onto another organization, which in turns uses this to collate important and personal data and there we have it – bring this data together into one central location and you have a hacker’s dream and the so-called Money Mule concept kicks or trots (does a donkey trot?) into action.  So we see that the end users are also part of an organization’s security landscape.
 
Brendan also expanded on the IBM approach to managing cyber threats. The IBM approach consists of two elements – the first is the “Pre-exploit”, which is all about prediction and prevention and the second is the “Post-exploit” which is about reaction and remediation.  Every organization needs to adopt this approach.  Every organization needs an instant handling approach and every organization needs an intelligent view of their security position.  When working with clients, IBM has discovered that most organizations think they have an optimised approach; but reality tells another story with the majority only having basic measures in place.  Organizations need to aim to be proficient in order to be able to proactively protect themselves from cyber-attacks.
 
Brendan listed the essential practices as follows: 
  1. Build a risk awareness culture and management system
  2. Manage security incidents with greater intelligence
  3. Defend the mobile and social workplace and make social media work for you and not against you
  4. Have security-rich services by design and not as an after-thought
  5. Automate security hygiene
  6. Control network access and help assure resilience
  7. Address the new complexity of cloud and virtualisation
  8. Manage third party security compliance
  9. Better secure data and protect privacy
  10. Manage people’s identity throughout the whole security lifecycle
Brendan then talked about the IT Trends for 2013, which he defined as follows:
  1. Cloud security will move from hype to a mature solution and will progress
  2. Advances in BYOD mobile will increase and be more secure than laptops by 2014
  3. Compliance will be a big driver for 2013 with organizations facing potential fines of 2% of their global annual turnover
  4. Data explosion will increase

And in conclusion, Brendan left us with the top threats for individuals to consider in 2013 and these are:
  1. Cyber Security
  2. Supply Chain Security
  3. Big Data
  4. Data Security in the cloud
  5. Consumerization
So yes, cyber-threats are very real, but with the right approach to cyber-security they can be managed!


 

Thursday, 21 March 2013

A Winning Combination with great odds

Your BC Eye
Donna Monkhouse
Once again your BC Eye tuned into yet another excellent webinar – just one of the many free webinars that are being run as part of this year’s BCAW activities to raise awareness around the value of Business Continuity.
 
This one discussed the rise (and not fall) of contingency planning (widely used and known in the financial sector as the way to deal with threats) and its continued rise to become an integral part of good Business Continuity practice.   
 
Based on the recently released BCI Research Report: The Winning Combination – the 3 Cs of Business Continuity: Contingency Planning, Continuity Capability and Crisis Response and hosted by our very own Lee Glendon, who heads up our Research and Advocacy activities, this webinar showed us that by bringing the 3 Cs together we can accomplish good Business Continuity practice and ultimately achieve the one true goal, which is organizational resilience. 
 
Lee Glendon CBCI
Lee talked about the specific role of the BC professional in Contingency Planning, which he neatly defined as the individual who makes an action plan actionable and the challenges a BC Manager faces as a non-financial professional of being deemed capable of assuming responsibility for supporting the development of a Contingency Plan. 
 
The key thing this presentation drove home to me was that fact that Contingency Planning, Continuity Capability and Crisis response should not be dealt with in isolation but that they all support each other.   Continuity Planning is all about the pre-plan response for things that can be reasonably planned for; Contingency Planning is all about dealing with specific threats or scenarios; and Crisis Response is required when an event goes beyond reasonable planning and poses a high degree of threat to the existence of an organization.   Together they form, as Lee stated, “a three-line defence” mechanism, which works!
 
Putting this concept into a context that we can all relate to, Lee took us through a case study that demonstrated the successful application of the 3Cs, namely, Cheltenham Races, which are organised by the British Horseracing Authority. 
 
He explained that the Continuity Capability was in this instance about ‘keeping the show on the road’, which meant making sure the event could happen, like for example identifying an alternative location for the same date (not easy to change a race date).  This included the recognition of the fact that things can go wrong and that there will inevitably be disruptions, after all, it is the winter race programme in the UK that we are talking about here!   Then he talked about the Contingency Planning element, which in this case was essentially having plans at local level (i.e. for the racecourse itself) in the event that it snowed, or there was a hard frost or security issues.  And finally he talked about the Crisis Response, for the bigger things like injuries to the horses, cruelty to animal campaigns that might damage the good reputation of the British Horseracing Authority as well as our beloved (and I can say that as a Brit) Cheltenham Races or cause a major disruption to the event. 
 
The success of this wonderful example of the practical application of the 3 Cs was evidenced through an enhanced reputation and wide public recognition according to the British Horseracing Association.   There were lots of contributory factors including good communications; making sure the needs of all the race stakeholders were met; bending the rules a bit where necessary (or as Lee referred to it, flexible policy); not having a fixed plan but having the capability to deal with threats and incidents; as well as the continuity of staff.
 
The next phase of this truly insightful webinar was about the application of the 3 Cs to threats and risks or rather the question of how this could be done.   This is where the black swans of this year’s BCAW 2013 theme appeared on the horizon.  (Remember the main banner on the BCAW website?)  Lee defined the characteristics of these infamous black swans as:  unexpected; more consequential than your white swan (the ones you do see coming); relative in terms of knowledge (i.e. the more knowledge, the less black the swan (!); and ones where we have a clear understanding of what the consequences could be even if we don’t know what that event will be exactly or how likely it is.
 
Here, Lee brought into play the famous “Known, Knowns” concept of Donald Rumsfeld (2002) and linked them to the 3 Cs as follows:
 
Known Knowns i.e. things we know we know, which can be dealt with using Contingency Planning;
 
Known Unknowns i.e. the things we know we don’t know, which require us to build Continuity Capability;
 
Unknown Knowns i.e. the things we know about but don’t know when they will happen, which if they do, will require a Crisis Response;
 
Unknown Unknowns i.e. the things we don’t know about nor do we know when they will happen, which also fall under the remit of a Crisis Response.
 
In conclusion, Lee brought us back to the opening topic of the webinar, namely, Contingency Planning, which he concluded, is known, particularly in the Financial Sector to work across strategic, financial and operational risks.  What this webinar proved was that the 3 Cs would work just as well and actually when we talk about Contingency Planning, in essence, we are talking about the application of the 3 Cs; all we are doing essentially is using different elements of the same structure.  Which elements we ultimately use, will simply depend on the level of our knowledge. 
 
So Contingency Planning really is on the rise; on the rise to become an integral part of Business Continuity and the application of the 3 Cs will help us to build resilience.