On Tuesday 18th March 2014, as part of the Business Continuity Awareness Week activities, we witnessed the first ever BC Flash Blog. This is probably a new term to most readers, it is a virtual Flash Mob – but instead of a dance routine the participants wrote and published their own blog post or article.
The event featured 22 writers, from all sectors of the BC industry – and from various corners of the globe. All the articles were on the same subject, and published at the same time. In keeping with the BCAW theme, the subject was “Counting the costs, and benefits, for business continuity”, with each writer taking their own, unique, perspective on this issue.
If you haven’t already done so, you can find links to all 22 of these blogs here. If we do nothing else, we can at least pay these writers the respect of reading their work.
For those who are interested in statistics, the page with the list of articles has had over 600 views (as of the 7th April). The list is hosted on a service called List.ly that facilitates social media style interactions with the community. Readers are able to flag like/dislike; indicate which articles they have read and, perhaps just as importantly, which subjects they would like to learn more about.
To date there have been 123 of these interactions recorded – but sadly these have come from only 11 people. You do have to register with the service to interact, which may have stopped many from casting a vote. These interactions are still open, and it would provide useful feedback to guide future articles if you could visit the site and record your thoughts.
Despite the relatively low number of interactions recorded, the feedback from a number of the writers indicates a good level of hits on these articles. While not everybody had full scale analytics, reported around 100 hits on their article and another over 180 hits. This may, in part, represent the existing audience of some of these writers as much as the BCAW promotion - but that is part of the educational value to be derived from the exercise.
BC folk need to learn about tapping into, and leveraging, existing networks and communities if we want to promote our cause and our message. The extra reader base accessed by distributed, rather than centralised, blog hosting. Just as importantly, the extended reach of the Social Media networks of the various writers and the 'priceless' publicity that was generated by the Tweets and Retweets. These are lessons we can look at applying to our own BC programmes. How we can use tools like blogs and wikis in our organizations; improving our understanding (and adoption) of the various social media tools (like List.ly) and the value of debate and interaction, rather than passive consumption, in promoting a vibrant discipline.
One message that comes through very clearly in several of these articles is the passion that BC people have for the work we do. It was a joy to see that passion from old practitioners as well as from newer ones. The passion for the work and promoting the cause also spanned geography and language.
That passion means we can at times be forceful when we debate our different views and perspectives on how to count the costs – and even what constitutes benefits and value from BC. But it also drives a genuine desire to promote improvement and learning across our practices. Without debate, and passion, no field of knowledge will develop. But debate requires engagement.
I spoke about this passion, and used three of the articles as examples, in my BCAW webinar. It is recorded and can be accessed here, it also contains some instruction on how to access and engage with the List of articles.
It would be great to hear some feedback about the concept of a Flash Blog, about the articles, or even what topic you would like to see for a future Flash Blog event. You can comment here on The BC Eye, or start a discussion in one of the many Linked In groups where this post will be promoted.
My thanks to all those who contributed articles, I hope you all keep writing! Thank you also to those who take the time to read – and extra special thanks to those who make it all worthwhile by engaging and debating these ideas.
Finally, if you are wondering why we chose to have our Flash Mob write a blog post rather than demonstrate a dance routine – then this YouTube clip (featuring one of our contributors) should provide an adequate explanation.
Ken Simpson
Director of The VR Group
Showing posts with label BCAW. Show all posts
Showing posts with label BCAW. Show all posts
Friday, 11 April 2014
Tuesday, 18 March 2014
Counting the costs and benefits of business continuity, a Non-Executive Director's perspective
Essentially the Non-Executive Director's role is to provide a creative contribution to the board by providing objective criticism. So I recommend that all Non-Executive Directors consider challenging the board to count the costs involved in deploying business continuity management and balancing these costs against quantifiable benefits gained from its Business Continuity Management System and Programme.
The Good Practice Guidelines suggest that embedding BCM is hard to measure, but secretly I believe that Executive Directors deep down in their hearts and minds know full well if they are merely trying to be compliant.
In the busy world of the Executive, maybe they only have time to ask if the business is adequately covered from a risk and business continuity perspective. Is it the difference between plausible deniability and culpable liability? To paraphrase a well-known political interviewer: “Did you know there was a problem, in which case you are culpable or did you genuinely not know in which case you were incompetent, which is it?”
Apply that logic to the board and ask them if they understand the relationship between, in some cases, hundreds of thousands they spend on business continuity management believing that it will deliver benefits should it be needed, without insisting on seeing the cost benefit analysis that proves the case, only to find that in reality, plans are hardly invoked or utilised even in a real event.
I can only suggest from experience that Top Management Executives are unlikely to ask the question: “Show me the costs associated with maintaining our Business Continuity Management System/Programme and tell us how much deploying our strategy for resumption will cost if invoked and the savings, yes, savings to the business in reducing the impacts to the business over a known time scale.”
If business continuity professionals were pressed to answer this question, they would have to take a more commercial view of business continuity, they would have to truly align to risk disciplines and share common risk and impact scales and they just may invite procurement professionals to assist in quantifying response strategies and tactic and resource requirements.
This would lead to Top Management Executives having a genuine opinion, to give a mandate and possibly believing that business continuity does indeed add commercial advantage to your business.
So, I implore Non-Executive Directors and Heads of Audit Committees, challenge your Top Management Executives to prove the commercial case for undertaking business continuity management for your business.
Ask your Chief Risk Officer or their equivalent in your business:
Even as I write this, the national news talks of under spending and being under prepared for severe disruptions, they offer the costs associated with preparedness and with failure, within days or weeks of an event.
So I will say it one more time, why do we not estimate these impacts in monetary terms using the same methods as undertaken post event – but do this in advance. Why can we not offer Top Management Executives fixed and variable costs (including invocation) set against the cost of impacts over time? Let them decide their Maximum Attitude to Disruption M.A.D.
Finally, why don’t Top Management Executives ask these questions, rather than simply are we covered?
By David Window
Non Executive Director at Continuity 22301 Ltd
The Good Practice Guidelines suggest that embedding BCM is hard to measure, but secretly I believe that Executive Directors deep down in their hearts and minds know full well if they are merely trying to be compliant.
In the busy world of the Executive, maybe they only have time to ask if the business is adequately covered from a risk and business continuity perspective. Is it the difference between plausible deniability and culpable liability? To paraphrase a well-known political interviewer: “Did you know there was a problem, in which case you are culpable or did you genuinely not know in which case you were incompetent, which is it?”
Apply that logic to the board and ask them if they understand the relationship between, in some cases, hundreds of thousands they spend on business continuity management believing that it will deliver benefits should it be needed, without insisting on seeing the cost benefit analysis that proves the case, only to find that in reality, plans are hardly invoked or utilised even in a real event.
I can only suggest from experience that Top Management Executives are unlikely to ask the question: “Show me the costs associated with maintaining our Business Continuity Management System/Programme and tell us how much deploying our strategy for resumption will cost if invoked and the savings, yes, savings to the business in reducing the impacts to the business over a known time scale.”
If business continuity professionals were pressed to answer this question, they would have to take a more commercial view of business continuity, they would have to truly align to risk disciplines and share common risk and impact scales and they just may invite procurement professionals to assist in quantifying response strategies and tactic and resource requirements.
This would lead to Top Management Executives having a genuine opinion, to give a mandate and possibly believing that business continuity does indeed add commercial advantage to your business.
So, I implore Non-Executive Directors and Heads of Audit Committees, challenge your Top Management Executives to prove the commercial case for undertaking business continuity management for your business.
Ask your Chief Risk Officer or their equivalent in your business:
- How much do we spend annually on business continuity management, without an incident taking place?
- How much would you estimate we would spend on deploying our strategy and tactics during a disruption and in achieving the timescales for resumption how much cost avoidance would we achieve in monetary terms?
Even as I write this, the national news talks of under spending and being under prepared for severe disruptions, they offer the costs associated with preparedness and with failure, within days or weeks of an event.
So I will say it one more time, why do we not estimate these impacts in monetary terms using the same methods as undertaken post event – but do this in advance. Why can we not offer Top Management Executives fixed and variable costs (including invocation) set against the cost of impacts over time? Let them decide their Maximum Attitude to Disruption M.A.D.
Finally, why don’t Top Management Executives ask these questions, rather than simply are we covered?
By David Window
Non Executive Director at Continuity 22301 Ltd
Counting the costs and benefits of business continuity, the BCI Technical Director's perspective
For those of you who think BCM is expensive, try operating without it.
Business Continuity has often been treated almost as an ‘act of faith’. Common sense has suggested that well prepared companies are likely to recover from an unexpected interruption quicker than unprepared ones; that they are likely to lose much less money by being productive again more quickly.
In times of financial restraint, with organizations looking to squeeze costs wherever possible this position is hard to defend, in some cases it simply no longer works. It is not too difficult to find out how much is directly lost as a result of disruptive incidents; in fact our friends from the insurance world have facts and figures about all types of incident – the amounts claimed, the amounts paid out and the actuarial data that supports the likelihood of every type of known problem.
This does however, leave difficulties for the BCM practitioner. Given the increasing attention paid to ‘black swans’, ‘unknown-unknowns’ or generally unpredictable events (illustrated again by the Malaysian aircraft disappearance), conventional risk pricing that requires forecasting both probability and loss expectancy is meaningless. For BCM people, how can we hope to quantify the potential loss connected to brand and reputation damage, market-share loss, share value collapse and more aggressive targeting by competitors?
Even if we can argue successfully (without detailed facts and figures) that we need to protect ourselves from the potentially terminal consequences of unexpected incidents, can we make a strong enough case for BCM as the solution? It is one thing to point out a problem, it is an entirely different thing to show you have the answer. For many years the BCI and other similar bodies have conducted regular surveys that demonstrate that the cost of business disruptions is significant. This has increased in line with trends such as ‘JIT’ manufacturing, complex and extended supply chains, increased off-shoring of services and purely cost driven out-sourcing of operations.
A soon to be released global survey indicates that almost 30% of respondents have experienced business losses of over $5 million as a result of a disruptive incident. This was up from less than 20% three years ago. The challenge for BCM professionals is not so much to shout about those facts (although that approach can help sometimes) but to show why Business Continuity can help both reduce the likelihood of suffering that loss at all, but if it should happen that the loss can be dramatically mitigated.
The wider dialogue taking place about resiliency throughout industry and government actually helps our case. In some ways recovery is simply a failure to be resilient, although total protection from everything is clearly impossible. The need to balance measures that make us inherently more able to withstand rapid changes in risk (political, environment, social and technological) with our ability to adopt and response as needed is the future for BCM thinking. What value do you put on success and what cost do you put on failure? Does effective BCM make the former a more likely outcome than the latter? The answer to those questions provide the justification for Business Continuity – in my view it is a modest investment for corporate decision takers who understand the real questions.
By Lyndon Bird
Technical Director at the Business Continuity Institute
Business Continuity has often been treated almost as an ‘act of faith’. Common sense has suggested that well prepared companies are likely to recover from an unexpected interruption quicker than unprepared ones; that they are likely to lose much less money by being productive again more quickly.
In times of financial restraint, with organizations looking to squeeze costs wherever possible this position is hard to defend, in some cases it simply no longer works. It is not too difficult to find out how much is directly lost as a result of disruptive incidents; in fact our friends from the insurance world have facts and figures about all types of incident – the amounts claimed, the amounts paid out and the actuarial data that supports the likelihood of every type of known problem.
This does however, leave difficulties for the BCM practitioner. Given the increasing attention paid to ‘black swans’, ‘unknown-unknowns’ or generally unpredictable events (illustrated again by the Malaysian aircraft disappearance), conventional risk pricing that requires forecasting both probability and loss expectancy is meaningless. For BCM people, how can we hope to quantify the potential loss connected to brand and reputation damage, market-share loss, share value collapse and more aggressive targeting by competitors?
Even if we can argue successfully (without detailed facts and figures) that we need to protect ourselves from the potentially terminal consequences of unexpected incidents, can we make a strong enough case for BCM as the solution? It is one thing to point out a problem, it is an entirely different thing to show you have the answer. For many years the BCI and other similar bodies have conducted regular surveys that demonstrate that the cost of business disruptions is significant. This has increased in line with trends such as ‘JIT’ manufacturing, complex and extended supply chains, increased off-shoring of services and purely cost driven out-sourcing of operations.
A soon to be released global survey indicates that almost 30% of respondents have experienced business losses of over $5 million as a result of a disruptive incident. This was up from less than 20% three years ago. The challenge for BCM professionals is not so much to shout about those facts (although that approach can help sometimes) but to show why Business Continuity can help both reduce the likelihood of suffering that loss at all, but if it should happen that the loss can be dramatically mitigated.
The wider dialogue taking place about resiliency throughout industry and government actually helps our case. In some ways recovery is simply a failure to be resilient, although total protection from everything is clearly impossible. The need to balance measures that make us inherently more able to withstand rapid changes in risk (political, environment, social and technological) with our ability to adopt and response as needed is the future for BCM thinking. What value do you put on success and what cost do you put on failure? Does effective BCM make the former a more likely outcome than the latter? The answer to those questions provide the justification for Business Continuity – in my view it is a modest investment for corporate decision takers who understand the real questions.
By Lyndon Bird
Technical Director at the Business Continuity Institute
Monday, 1 April 2013
Meeting the Supply Chain Complexity Challenge - Part Two
![]() |
| Lee Glendon CBCI Head of Research and Advocacy |
Having identified some of the drivers of complexity in
supply chains in the first part of the roundtable report, how are organisations
dealing with the challenge?
In dealing with the challenge of multiple tiers in the
supply chain, there was common agreement on the need to gain better visibility
but divergence of approach in practice. Some organisations were looking
at better methods to manage tier two supplier relationships, while others
recommended that the best approach was to work with tier one suppliers and get
them to work with their suppliers in turn. In the case of one large
retail organisation, they worked through their supply chains to the source
applying a consistent code of expectation in terms of product quality and
integrity throughout. It was recognised that this was a very resource
intensive process. However, it was an embedded practice, so for them it was not
a case of having to justify the investment each time; an enviable position in the
eyes of most of the roundtable participants.
The discussion moved on to the challenge of managing 10’s of
thousands of suppliers and there was consensus on the need to focus efforts on
key suppliers and key supply chains. It was recommended that filters are applied
to provide focus – these filters should be based around criticality in the
sense of ‘would failure of this supply chain quickly stop my organisation from
being able to carry out its key activities, and how quickly could they be
replaced’ and secondly around risks or threats that might cause disruption,
such as the supplier’s financial profile, the health of the industry in which
they operate, their locations and consequent exposure to risks as diverse as
flooding, earthquakes and geo-political instability. These filters
help generate a ‘shorter-list’ to scrutinise. Another approach favoured
by many at the roundtable was to use procurement ‘category management’ to
breakdown suppliers into common supply groups and then perform risk profiling
on this basis.
For those suppliers identified as key to the organisation,
the favoured approach was to seek to build closer relationships at executive
and operational levels with the objective of improving communication and
co-operation and thereby reduce the number of ‘surprises’. For one
organisation, this took the form of running workshops on business continuity
and running joint exercises. Toolkits were provided free of charge and
their business continuity plans were shared to help get alignment. They
would also recommend that supplier staff joined institutes such as the BCI to
develop capability and drive programme improvement. Interestingly, one of
the unintended consequences of this deepening of the relationship, is the
difficulty of exiting such relationship, as it would mean investing a
considerable amount of time bringing on board a new supplier to get to the same
level of understanding.
Some organisations were concerned about being overly onerous
on their supply network, especially those operating in sectors where there are
a limited number of suppliers. One person noted that they had experienced
suppliers not wanting to do business because the compliance requirements did
not make it worthwhile. In such cases, purchasing organisations are
co-operating to reduce the burden on their suppliers through articulating
common requirements.
Following a good discussion on approaches to deal with the
consequences of increasing supply chain complexity, the ‘wish list’ of
participants included the need to gain a better understanding of ‘what supports
the supply chain’ and mapping out supply chain networks. Others were
looking for a more dynamic set of indicators that would flag signs of
difficulty and an impending risk event in the supply chain. Another felt
that there was a need to consider ‘profit impact’ rather than spend in
identifying key supply chains. While one delegate felt there was a need
for procurement to drive risk conversations with suppliers and ensure due
diligence had happened. In this last respect CIPS is planning to develop
a number of educational and training resources to support development of its
members to meet the challenge.
The final thought from the discussion should go to the
‘what’s the return on investment’ question when it comes to investing in supply
chain resilience. For one major organisation top management
evaluates the value of investment in resilience in terms of how well it
prevented a problem and how well the organisation come out of it.
Quite simple really.
Vision Therapy - helping you to see more risks
![]() |
| Ken Simpson, Director The VR Group Pty Ltd |
Thank you all who joined my BCAW webinar, Vision Therapy - helping
you to see more risks. I try to make my webinars as interactive as
possible, using polls and other techniques, and following up with a post such
as this to share any interesting results of the polls and pose some additional
questions for people to reflect upon.
In keeping with the theme for BCAW 2013 my
presentation argued that there are those risks we see, those we don't see
(because we are not looking or because we refuse to recognise them) and then
there are those that you cannot see - which are the Black Swan events. My argument
was that there are perhaps less Black Swans than we think and more of the
events we don't see because we don't look and recognize the threats and
vulnerabilities.
The concept of the 'Black Swan event' has
become part of the language of BC. If we want to understand this concept we
should at some point read how it was originally proposed, rather than rely on
how somebody else filtered those words. I posed this question to the audience;
Thursday, 28 March 2013
In cyberspace, no-one can hear you scream (or snore)
On Friday I presented a webinar, on scenario-based
exercising, as part of the Business Continuity Institute's Business Continuity
Awareness Week 2013. And I have to tell you, it was one of the most nerve-wracking
things I've done for a long time.
Which is a bit bizarre, really, as I do presentations all
the time, to audiences of various sizes (that's numbers of people, as opposed
to body mass). I'll admit that there are often a few butterflies just before
the start, but nothing particularly serious.
The difference with this one was the strangeness of it all.
I was effectively presenting to an empty room and it felt like I was talking to
myself - into my 'phone but with no-one on the other end. Except I wasn't,
because there was quite a decent sized audience out there, somewhere. All I
knew was that there were 76 of them. I only knew that because there was a
little green "76" on my computer screen. I didn't know who they were,
what they looked like, where they were, why they were listening or what they
were expecting.
The strangest thing was the absence of any feedback (aside
from the online polls I did in an attempt to discover some small snippet of
information about the audience). I didn't have the faintest idea whether people
were nodding in agreement, smiling, shaking their heads, falling asleep, going
off to make a cup of tea or checking their e-mails (heaven forbid). All I could
see was that little green number telling me that 76 people were at least still
logged in and all I could hear was a deafening silence on the other end of the
line. It was very disconcerting for someone who likes to see the whites
of his audience's eyes.
It didn't help that, having logged in, as instructed, well
in advance of the start time, the webinar system then insisted on telling me,
every minute, via one of those awful "press one to be ignored for a bit
longer" recorded voices, how long was left until show time, followed by a
final countdown that did nothing to ease my pre-match nerves.
Then there was the system itself. I'd had a trial run -
which was just as well really as when I tried it with a headset the sound
quality was awful and I had to revert to the 'phone's handset. Which meant I
couldn't move further than the length of its cable, and that severely curtailed
my usual habit of going for a bit of a wander when I'm presenting. And some of
the system's features weren't available on the test site so I was learning as I
went along on the day. All in all I found it just a teeny bit unnerving. I was
out of my comfort zone, I suppose.
I ended up standing up for most of the session, adopting a
sort of 1960s horror film manservant hunch over my computer screen and mouse,
along with a sort of side-to-side shamble. So it's just as well my audience
couldn’t see me either. But, after a bit of a wobbly start, I got my act
together, my nerves settled and I got on with the job in hand. In the end I
received a pretty decent score, along with some very complimentary comments, so
it can't have been that bad - it just felt like it to me at the time.
Afterwards I couldn't help thinking that there were some
parallels with exercising and testing our business continuity capability, which
was the topic of the webinar.
Monday, 25 March 2013
What’s driving supply chain complexity? Part One
![]() |
| Lee Glendon CBCI Head of Research and Advocacy |
In the BCI’s report Horizon Scan 2013, one of the key trends
of concern identified by Business Continuity professionals was “increasing
supply chain complexity”. So on Tuesday 19th March, the BCI
and the Chartered Institute of Purchasing & Supply (CIPS) convened a
roundtable of senior supply chain, risk and business continuity practitioners
from sectors as diverse as retail, manufacturing, energy, housing, construction
and telecommunications to share experiences and discuss how they were dealing
with the challenge.
If folk were hoping that complexity is something that will
stop or slowly unwind, then they would not have got much comfort from the
discussion.
Perhaps, the most important driver of complexity is the
customer and the desire of businesses to develop the right supply chain to meet
the needs of the customer. For example, the supply chain required to be
able to sell a product as “made in Italy” sets its own restrictions and risks
that need to be managed.
| BCAW Roundtable Discussion 2013 |
Many of the drivers of complexity have come about through
conscious business decisions. A number of organisations had decided to
consolidate their tier one suppliers – while this simplifies the number of
interfaces at tier one, what is has done has created many more tiers below the
immediate supplier, reducing visibility. Participants noted that they
were now experiencing disruption originating at tiers five and even six!
Another issue raised by a number of people was around the
illusion of diversity that dual-sourcing can bring. While many had
introduced dual-sourcing in terms of immediate suppliers, some had found to
their cost that at tier two or three they were reliant on a single supplier
again. This point opened up a wider discussion about how difficult it was
to understand interdependencies between suppliers and that the term supply
chain should perhaps be replaced by ‘supply chain networks’.
Some sectors were suffering from lack of communication
around changes in their extended supply chain. More than one participant
commented that their suppliers would change the location of production or the
people providing a service without informing them, so organisations would be
caught out in finding that an event, for example industrial action, in one
country affected them, even though they didn’t think they had any exposure to
the event.
Representatives from the public sector provided an
interesting contrast to their colleagues in the private sector. Their
driver of complexity was government policy which was requiring not supplier
consolidation but increasing their spend with small and medium sized
businesses, while this was sometimes managed through a large tier one supplier,
there was a need to monitor the success of this policy and provide extensive
training and development support for small businesses to work with government
entities.
The consequences of redrawing the boundaries of
organisations over many years through outsourcing were also flagged as creating
challenges in that the suppliers often had more knowledge and expertise than
the client. Some felt that too much intellectual power had been outsourced and
one organisation stated that they were now bringing back in-house some of the
higher skilled activities.
In concluding this part of the roundtable discussion, it’s
much clearer why complexity is such a taxing trend for Business Continuity
professionals and why it is so important to find an approach to manage it
effectively.
In Part 2 of this roundtable report, we’ll look at some of
the techniques that are being used to manage complexity.
Practice makes perfect or scenario-based BC Plans are a waste of time!
![]() |
| Your BC Eye Donna Monkhouse |
We are all familiar with the expression “practice makes
perfect” and never has a truer word been spoken. Practising is all about rehearsing again and
again until you have mastered the role you’ve been assigned; but, it is also
about improving your behaviour.
Today’s BCAW 2013 webinar of my choice was the one on exercising, or
rather scenario-based exercising, which was presented by Andy Osborne MBCI,
Associate Consultant at Clearview-Continuity.
The first question
Andy raised was, why bother with exercises?
Well, the short answer is that it takes a lot of time,
effort, resources and money to write a Business Continuity Plan (BCP) and if
you want to see a return on this investment, you need to make sure it
works. Simply having a BCP in place will
not save your business; what will save it is having the right people with the
right capability to deliver that plan, and the only way to develop that
capability is through practising or as Business Continuity professionals prefer
to say, through exercising.
So should a BCP be
based on particular scenarios?
Well according to Andy, “scenario-based plans are a waste of
time”. What Andy was essentially saying
with this somewhat controversial statement (at least at first glance) is that there is no way that we can think of
every possible scenario nor can we plan for every conceivable type of incident
that we may be faced with at some point in the future. More often than not, old Murphy’s Law will
kick in and you will find yourself either faced with the one scenario you
hadn’t thought of or the scenario you had in your head pans out quite
differently in reality. What is critical
here is not to plan for every
scenario, but to plan for any
scenario and the way you do this is to build the capability within your
organization to respond to any incident by getting the people involved to
rehearse again and again until they know their lines off by heart (speaking in
theatrical terms of course)!
What about scenario-based
exercises?
Scenario-based exercises, on the other hand are not a waste
of time but can be very valuable in terms of emphasising issues that no one had
thought of; highlighting your strengths and your weaknesses (remember, you are
only as strong as the weakest link); clarifying responsibilities; testing your
communications and ultimately, helping you to improve and enhance your response
capability.
Which scenarios
should you select?
It doesn’t really matter what type of scenario you select,
but what it does need to be is credible, engaging and realistic and it needs to
meet and reflect your objectives and the key issues you are hoping to address
through the exercise. So when planning
an exercise, don’t start the process by trying to think of some great
theatrical spectacular, focus in the first instance on your objectives and
issues. You can make up the most
exciting, mind-blowingly creative and fictitious incident, but if it doesn’t
meet your objectives then it will have little value and will really be a
complete waste of time!
When it comes to facilitation of a scenario-based exercise,
there are many approaches that can be taken.
It could be as simple as a desk-top exercise where you gather everyone
around the table to talk them through the plan or even walk them through it; or
it could be a bigger event involving role play and fake journalists, doctored
photos and staged radio broadcasts.
The key observation made by Andy based on his extensive
experience in the field, is that what you do will and should be decided by the
people you need to involve inasmuch as some people will feel comfortable with
role play; others will feel totally out of their comfort zone; some will react
well and others badly. You need to
understand the composition of your Incident Management Team, the intricacies of
their personalities as well as having (if possible) some insight into past
history and previous experiences and traumas so that you can at least make some
kind of pre-judgement as to how they might react to certain scenarios and
whether they are the right men or women for the job.
You also need to
consider whether they can work well together as a team and whether indeed they
know each other well enough to perform effectively as a unit, after all, you
are only as good as the sum of your parts.
Both approaches of course have their value. If you decide for the role play (which does
not involve dressing up in fancy costume), you can make this as realistic as
you like, just be sure to be aware of the fact that different people will react
in different ways. Certainly, if you
wish to include a death of a colleague in your scenario, it is wise not to use
real people’s names but safer to stick to a fictitious name instead; using real
names can have terrible emotional consequences for some of the players on your
stage. How realistic you can make it,
will of course depend on how realistic you can afford to make it, but the sky
really is the limit here. You can
involve multiple teams and use multiple locations in your scenario; there is no
right or wrong. Andy did, however,
strongly advise anyone planning to use multiple teams to first carefully
consider which teams to involve at what point otherwise you will have people
involved with nothing to do for long periods of time, which destroys the ‘engaging’
element of your scenario and will result in loss of interest and loss of
ownership and ultimately spell out a miserable failure.
So how do you get the
most out of your exercising? Here Andy’s
top tips:
- Plan and prepare for your exercise properly
- Think about the management and the coordination of the exercise
- Use experienced facilitators
- Develop an exercise plan and schedule
- Ensure you have clear objectives and measurable success criteria
- Brief all participants including the facilitators in advance as well as you can or should
- Have some independent observers on the side line as they can provide excellent, impartial feedback post-event
- Create and use post exercise critique forms and log books to capture key information and observations
- Write a report and follow up on the report’s recommendations as part of your lessons learned (after all exercising is also about improving your capability)
- Finally de-brief everyone who was involved and make sure all loose ends are firmly tied up
At this point, Andy reminded us of the 5 Ps (or 6 Ps used in
the army, but we won’t mention the sixth one here!): Proper Planning Prevents Poor Performance –
good planning breeds success; success breeds confidence, confidence in your
plan, in your team and ultimately in your organization to withstand any scenario!
The final question
that Andy put on the table was when to exercise?
The Business Continuity Management Lifecycle tells us to
exercise and test at the end of the process, but we could exercise during
strategy definition or maybe during the implementation process. In fact, Andy went one step further and made
the brave suggestion that maybe the Lifecycle should begin with exercising as
this is guaranteed to make people sit up in their seats and pay attention; it
will highlight the key issues; it will emphasise the importance of Business
Continuity and it could be key to getting buy-in especially at the top, which
as we know can be more than difficult!
This webinar certainly provided me with ample food for
thought and hopefully you have learned something too by reading this blog!
![]() |
| BCI Physical Workshop |
Dates:
Wednesday, 24th April 2013: Planning and Running an Exercise
Thursday, 25th April 2013:Invigorating your Exercise Programme
Location: Manchester
BCI Member Rates apply.
Friday, 22 March 2013
Cyber Threats and Cyber Security – are they real and can they be managed?
![]() |
| Your BC Eye
Donna Monkhouse
|
My topic of choice
for yesterday's webinar listen-into was the one on Cyber Threats and Cyber Security
by Brendan Byrne from IBM in which Brendan shared both IBM’s and other
organizations experiences from the dark world of cyber threat.
According to a recent IBM survey, the biggest threat
perceived by Business Continuity professionals is cyber-security. Some of the challenges faced include BYOD
(Bring Your Own Device) which is on the increase; the widespread use of social
media with its pros and cons; workforce mobility and the increasing use of
cloud-based solutions.
The landscape is changing for organizations all around the
globe. Big Data or Smarter Data
inevitably means more security considerations and the growing use of online
services is another cause for security concern.
The boundaries are becoming blurred as we step up the use of the innovative
technology that is advancing our way.
Supply Chain Security, as Brendan quite rightly said, is indeed only as
strong as the weakest link in the chain and the expanding use of data is
presenting more and more problems in terms of potential threats to an
organization.
According to the X-Force Research Team (just one of the jewels
in IBM’s crown) who is tasked with analysing the worldwide web on a daily
basis, scanning the horizon for new trends and new vulnerabilities, there are
over 40M spam and phishing attacks every month!
Now that is a scary figure.
KPMG’s Data Loss Barometer 2012 showed that hacking is the number one
cause of data loss and that data loss incidents have increased by 40% since
2011. There is evidence of new attack
activity as malware gets too clever for its boots. Some of the challenges faced are down to
things as apparently simple as passwords (or rather the common and widespread
use of the same password) and of course there is the challenge of BYOD and a
new concept, called APT (Advanced Persistent Threats).
One of the key messages that this webinar drove home, was
the importance of embedding cyber-security into an organization’s business
culture. It is not enough to develop a
policy and then file it away thinking that the job is done and a big fat tick
has been put in the box. With a
constantly changing landscape and new threat activity entering the “Cyber
Charts”, it is essential that organizations review, review and review again to
ensure that their policies and procedures meet the current and future security
needs of their business.
One of the key issues is that cyber threats are just getting
more and more sophisticated. Motives for
cyber-attacks range from simple curiosity, to revenge, right through to the big
stuff like espionage and political activism.
The players or actors on the cyber stage are also becoming increasingly
more educated and organised. They scale
of actor type runs from the inadvertent actor, who may cause an incident
through ignorance or lack of training; to the opportunist that just grabs the
moment to do some damage; to the “hacktivist” (remember that is the number one
cause of data loss); right through to the top of the tree with the advanced
actor, that heads up some big scam.
According to IBM research, the top three IT risks that
damage a company’s brand (its greatest asset) and reputation (as perceived by
BC professionals) are: Data Breach;
Systems Failure and Data Loss in that order.
An interesting example of a botnet was put in the room as
such to demonstrate both its apparent innocence and its inherent danger. We can all very easily download a botnet. More often than not, this just sits
harmlessly on our computers until the organiser of said botnet decides to sell
this onto another organization, which in turns uses this to collate important
and personal data and there we have it – bring this data together into one
central location and you have a hacker’s dream and the so-called Money Mule
concept kicks or trots (does a donkey trot?) into action. So we see that the end users are also part of
an organization’s security landscape.
Brendan also expanded on the IBM approach to managing cyber
threats. The IBM approach consists of two elements – the first is the
“Pre-exploit”, which is all about prediction and prevention and the second is
the “Post-exploit” which is about reaction and remediation. Every organization needs to adopt this
approach. Every organization needs an
instant handling approach and every organization needs an intelligent view of
their security position. When working
with clients, IBM has discovered that most organizations think they have an
optimised approach; but reality tells another story with the majority only
having basic measures in place.
Organizations need to aim to be proficient in order to be able to
proactively protect themselves from cyber-attacks.
Brendan listed the
essential practices as follows:
-
Build a risk awareness culture and management
system
-
Manage security incidents with greater
intelligence
-
Defend the mobile and social workplace and make
social media work for you and not against you
-
Have security-rich services by design and not as
an after-thought
-
Automate security hygiene
-
Control network access and help assure
resilience
-
Address the new complexity of cloud and
virtualisation
-
Manage third party security compliance
-
Better secure data and protect privacy
-
Manage people’s identity throughout the whole
security lifecycle
-
Cloud security will move from hype to a mature
solution and will progress
-
Advances in BYOD mobile will increase and be
more secure than laptops by 2014
-
Compliance will be a big driver for 2013 with
organizations facing potential fines of 2% of their global annual turnover
-
Data explosion will increase
And in conclusion,
Brendan left us with the top threats for individuals to consider in 2013 and
these are:
-
Cyber Security
-
Supply Chain Security
-
Big Data
-
Data Security in the cloud
-
Consumerization
Thursday, 21 March 2013
A Winning Combination with great odds
![]() |
| Your BC Eye Donna Monkhouse |
Once again your BC Eye tuned into yet another excellent webinar – just
one of the many free webinars that are being run as part of this year’s BCAW
activities to raise awareness around the value of Business Continuity.
This one discussed the rise (and not fall) of contingency planning
(widely used and known in the financial sector as the way to deal with threats)
and its continued rise to become an integral part of good Business Continuity
practice.
Based on the recently released BCI Research Report: The Winning Combination – the 3 Cs of Business Continuity: Contingency Planning, Continuity Capability and Crisis Response and hosted by our very own Lee Glendon, who heads up our
Research and Advocacy activities, this webinar showed us that by bringing the 3
Cs together we can accomplish good Business Continuity practice and ultimately
achieve the one true goal, which is organizational resilience.
![]() |
| Lee Glendon CBCI |
Lee talked about the specific role of the BC professional in Contingency
Planning, which he neatly defined as the individual who makes an action plan
actionable and the challenges a BC Manager faces as a non-financial
professional of being deemed capable of assuming responsibility for supporting
the development of a Contingency Plan.
The key thing this presentation drove home to me was that fact that
Contingency Planning, Continuity Capability and Crisis response should not be
dealt with in isolation but that they all support each other. Continuity Planning is all about the pre-plan
response for things that can be reasonably planned for; Contingency Planning is
all about dealing with specific threats or scenarios; and Crisis Response is
required when an event goes beyond reasonable planning and poses a high degree
of threat to the existence of an organization.
Together they form, as Lee stated, “a three-line defence” mechanism,
which works!
Putting this concept into a context that we can all relate to, Lee took
us through a case study that demonstrated the successful application of the
3Cs, namely, Cheltenham Races, which are organised by the British Horseracing
Authority.
He explained that the Continuity Capability was in this instance about
‘keeping the show on the road’, which meant making sure the event could happen,
like for example identifying an alternative location for the same date (not
easy to change a race date). This
included the recognition of the fact that things can go wrong and that there
will inevitably be disruptions, after all, it is the winter race programme in
the UK that we are talking about here!
Then he talked about the Contingency Planning element, which in this
case was essentially having plans at local level (i.e. for the racecourse
itself) in the event that it snowed, or there was a hard frost or security
issues. And finally he talked about the
Crisis Response, for the bigger things like injuries to the horses, cruelty to
animal campaigns that might damage the good reputation of the British
Horseracing Authority as well as our beloved (and I can say that as a Brit)
Cheltenham Races or cause a major disruption to the event.
The success of this wonderful example of the practical application of the
3 Cs was evidenced through an enhanced reputation and wide public recognition
according to the British Horseracing Association. There were lots of contributory factors
including good communications; making sure the needs of all the race
stakeholders were met; bending the rules a bit where necessary (or as Lee
referred to it, flexible policy); not having a fixed plan but having the
capability to deal with threats and incidents; as well as the continuity of
staff.
The next phase of this truly insightful webinar was about the application
of the 3 Cs to threats and risks or rather the question of how this could be
done. This is where the black swans of
this year’s BCAW 2013 theme appeared on the horizon. (Remember the main banner on the BCAW website?) Lee defined the
characteristics of these infamous black swans as: unexpected; more consequential than your white
swan (the ones you do see coming); relative in terms of knowledge (i.e. the
more knowledge, the less black the swan (!); and ones where we have a clear
understanding of what the consequences could be even if we don’t know what that
event will be exactly or how likely it is.
Here, Lee brought into play the famous “Known, Knowns” concept of
Donald Rumsfeld (2002) and linked them to the 3 Cs as follows:
Known Knowns i.e. things we know we know, which can be
dealt with using Contingency Planning;
Known Unknowns i.e. the things we know we don’t know, which
require us to build Continuity Capability;
Unknown Knowns i.e. the things we know about but don’t know
when they will happen, which if they do, will require a Crisis Response;
Unknown Unknowns i.e. the things we don’t know about nor do we
know when they will happen, which also fall under the remit of a Crisis
Response.
In conclusion, Lee brought us back to the opening topic of the webinar,
namely, Contingency Planning, which he concluded, is known, particularly in the
Financial Sector to work across strategic, financial and operational risks. What this webinar proved was that the 3 Cs
would work just as well and actually when we talk about Contingency Planning,
in essence, we are talking about the application of the 3 Cs; all we are doing
essentially is using different elements of the same structure. Which elements we ultimately use, will simply
depend on the level of our knowledge.
So Contingency Planning really is on the rise; on the rise to become an
integral part of Business Continuity and the application of the 3 Cs will help
us to build resilience.
Subscribe to:
Posts (Atom)








